LCOV - code coverage report
Current view: top level - source3/libads - authdata.c (source / functions) Hit Total Coverage
Test: coverage report for master 2b515b7d Lines: 0 141 0.0 %
Date: 2024-02-28 12:06:22 Functions: 0 2 0.0 %

          Line data    Source code
       1             : /*
       2             :    Unix SMB/CIFS implementation.
       3             :    kerberos authorization data (PAC) utility library
       4             :    Copyright (C) Jim McDonough <jmcd@us.ibm.com> 2003
       5             :    Copyright (C) Andrew Bartlett <abartlet@samba.org> 2004-2005
       6             :    Copyright (C) Andrew Tridgell 2001
       7             :    Copyright (C) Luke Howard 2002-2003
       8             :    Copyright (C) Stefan Metzmacher 2004-2005
       9             :    Copyright (C) Guenther Deschner 2005,2007,2008
      10             : 
      11             :    This program is free software; you can redistribute it and/or modify
      12             :    it under the terms of the GNU General Public License as published by
      13             :    the Free Software Foundation; either version 3 of the License, or
      14             :    (at your option) any later version.
      15             : 
      16             :    This program is distributed in the hope that it will be useful,
      17             :    but WITHOUT ANY WARRANTY; without even the implied warranty of
      18             :    MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
      19             :    GNU General Public License for more details.
      20             : 
      21             :    You should have received a copy of the GNU General Public License
      22             :    along with this program.  If not, see <http://www.gnu.org/licenses/>.
      23             : */
      24             : 
      25             : #include "includes.h"
      26             : #include "librpc/gen_ndr/ndr_krb5pac.h"
      27             : #include "smb_krb5.h"
      28             : #include "libads/kerberos_proto.h"
      29             : #include "auth/common_auth.h"
      30             : #include "lib/param/param.h"
      31             : #include "librpc/crypto/gse.h"
      32             : #include "auth/gensec/gensec.h"
      33             : #include "auth/gensec/gensec_internal.h" /* TODO: remove this */
      34             : #include "../libcli/auth/spnego.h"
      35             : #include "lib/util/asn1.h"
      36             : 
      37             : #ifdef HAVE_KRB5
      38             : 
      39             : #include "auth/kerberos/pac_utils.h"
      40             : 
      41             : struct smb_krb5_context;
      42             : 
      43             : /*
      44             :   generate a krb5 GSS-API wrapper packet given a ticket
      45             : */
      46           0 : static DATA_BLOB spnego_gen_krb5_wrap(
      47             :         TALLOC_CTX *ctx, const DATA_BLOB ticket, const uint8_t tok_id[2])
      48             : {
      49           0 :         ASN1_DATA *data;
      50           0 :         DATA_BLOB ret = data_blob_null;
      51             : 
      52           0 :         data = asn1_init(talloc_tos(), ASN1_MAX_TREE_DEPTH);
      53           0 :         if (data == NULL) {
      54           0 :                 return data_blob_null;
      55             :         }
      56             : 
      57           0 :         if (!asn1_push_tag(data, ASN1_APPLICATION(0))) goto err;
      58           0 :         if (!asn1_write_OID(data, OID_KERBEROS5)) goto err;
      59             : 
      60           0 :         if (!asn1_write(data, tok_id, 2)) goto err;
      61           0 :         if (!asn1_write(data, ticket.data, ticket.length)) goto err;
      62           0 :         if (!asn1_pop_tag(data)) goto err;
      63             : 
      64           0 :         if (!asn1_extract_blob(data, ctx, &ret)) {
      65           0 :                 goto err;
      66             :         }
      67             : 
      68           0 :         asn1_free(data);
      69           0 :         data = NULL;
      70             : 
      71           0 :   err:
      72             : 
      73           0 :         if (data != NULL) {
      74           0 :                 if (asn1_has_error(data)) {
      75           0 :                         DEBUG(1, ("Failed to build krb5 wrapper at offset %d\n",
      76             :                                   (int)asn1_current_ofs(data)));
      77             :                 }
      78             : 
      79           0 :                 asn1_free(data);
      80             :         }
      81             : 
      82           0 :         return ret;
      83             : }
      84             : 
      85             : /*
      86             :  * Given the username/password, do a kinit, store the ticket in
      87             :  * cache_name if specified, and return the PAC_LOGON_INFO (the
      88             :  * structure containing the important user information such as
      89             :  * groups).
      90             :  */
      91           0 : NTSTATUS kerberos_return_pac(TALLOC_CTX *mem_ctx,
      92             :                              const char *name,
      93             :                              const char *pass,
      94             :                              time_t time_offset,
      95             :                              time_t *expire_time,
      96             :                              time_t *renew_till_time,
      97             :                              const char *cache_name,
      98             :                              bool request_pac,
      99             :                              bool add_netbios_addr,
     100             :                              time_t renewable_time,
     101             :                              const char *impersonate_princ_s,
     102             :                              const char *local_service,
     103             :                              char **_canon_principal,
     104             :                              char **_canon_realm,
     105             :                              struct PAC_DATA_CTR **_pac_data_ctr)
     106             : {
     107           0 :         krb5_error_code ret;
     108           0 :         NTSTATUS status = NT_STATUS_INVALID_PARAMETER;
     109           0 :         DATA_BLOB tkt = data_blob_null;
     110           0 :         DATA_BLOB tkt_wrapped = data_blob_null;
     111           0 :         DATA_BLOB ap_rep = data_blob_null;
     112           0 :         DATA_BLOB sesskey1 = data_blob_null;
     113           0 :         const char *auth_princ = NULL;
     114           0 :         const char *cc = "MEMORY:kerberos_return_pac";
     115           0 :         struct auth_session_info *session_info;
     116           0 :         struct gensec_security *gensec_server_context;
     117           0 :         const struct gensec_security_ops **backends;
     118           0 :         struct gensec_settings *gensec_settings;
     119           0 :         size_t idx = 0;
     120           0 :         struct auth4_context *auth_context;
     121           0 :         struct loadparm_context *lp_ctx;
     122           0 :         struct PAC_DATA_CTR *pac_data_ctr = NULL;
     123           0 :         char *canon_principal = NULL;
     124           0 :         char *canon_realm = NULL;
     125             : 
     126           0 :         TALLOC_CTX *tmp_ctx = talloc_new(mem_ctx);
     127           0 :         NT_STATUS_HAVE_NO_MEMORY(tmp_ctx);
     128             : 
     129           0 :         ZERO_STRUCT(tkt);
     130           0 :         ZERO_STRUCT(ap_rep);
     131           0 :         ZERO_STRUCT(sesskey1);
     132             : 
     133           0 :         if (!name || !pass) {
     134           0 :                 status = NT_STATUS_INVALID_PARAMETER;
     135           0 :                 goto out;
     136             :         }
     137             : 
     138           0 :         if (_canon_principal != NULL) {
     139           0 :                 *_canon_principal = NULL;
     140             :         }
     141             : 
     142           0 :         if (_canon_realm != NULL) {
     143           0 :                 *_canon_realm = NULL;
     144             :         }
     145             : 
     146           0 :         if (cache_name) {
     147           0 :                 cc = cache_name;
     148             :         }
     149             : 
     150           0 :         if (!strchr_m(name, '@')) {
     151           0 :                 auth_princ = talloc_asprintf(mem_ctx, "%s@%s", name,
     152             :                         lp_realm());
     153             :         } else {
     154           0 :                 auth_princ = name;
     155             :         }
     156           0 :         NT_STATUS_HAVE_NO_MEMORY(auth_princ);
     157             : 
     158           0 :         ret = kerberos_kinit_password_ext(auth_princ,
     159             :                                           pass,
     160             :                                           time_offset,
     161             :                                           expire_time,
     162             :                                           renew_till_time,
     163             :                                           cc,
     164             :                                           request_pac,
     165             :                                           add_netbios_addr,
     166             :                                           renewable_time,
     167             :                                           tmp_ctx,
     168             :                                           &canon_principal,
     169             :                                           &canon_realm,
     170             :                                           &status);
     171           0 :         if (ret) {
     172           0 :                 DEBUG(1,("kinit failed for '%s' with: %s (%d)\n",
     173             :                         auth_princ, error_message(ret), ret));
     174             :                 /* status already set */
     175           0 :                 goto out;
     176             :         }
     177             : 
     178           0 :         DEBUG(10,("got TGT for %s in %s\n", auth_princ, cc));
     179           0 :         if (expire_time) {
     180           0 :                 DEBUGADD(10,("\tvalid until: %s (%d)\n",
     181             :                         http_timestring(talloc_tos(), *expire_time),
     182             :                         (int)*expire_time));
     183             :         }
     184           0 :         if (renew_till_time) {
     185           0 :                 DEBUGADD(10,("\trenewable till: %s (%d)\n",
     186             :                         http_timestring(talloc_tos(), *renew_till_time),
     187             :                         (int)*renew_till_time));
     188             :         }
     189             : 
     190             :         /* we cannot continue with krb5 when UF_DONT_REQUIRE_PREAUTH is set,
     191             :          * in that case fallback to NTLM - gd */
     192             : 
     193           0 :         if (expire_time && renew_till_time &&
     194           0 :             (*expire_time == 0) && (*renew_till_time == 0)) {
     195           0 :                 status = NT_STATUS_INVALID_LOGON_TYPE;
     196           0 :                 goto out;
     197             :         }
     198             : 
     199           0 :         ret = ads_krb5_cli_get_ticket(mem_ctx,
     200             :                                       local_service,
     201             :                                       time_offset,
     202             :                                       &tkt,
     203             :                                       &sesskey1,
     204             :                                       0,
     205             :                                       cc,
     206             :                                       NULL,
     207             :                                       impersonate_princ_s);
     208           0 :         if (ret) {
     209           0 :                 DEBUG(1,("failed to get ticket for %s: %s\n",
     210             :                         local_service, error_message(ret)));
     211           0 :                 if (impersonate_princ_s) {
     212           0 :                         DEBUGADD(1,("tried S4U2SELF impersonation as: %s\n",
     213             :                                 impersonate_princ_s));
     214             :                 }
     215           0 :                 status = krb5_to_nt_status(ret);
     216           0 :                 goto out;
     217             :         }
     218             : 
     219             :         /* wrap that up in a nice GSS-API wrapping */
     220           0 :         tkt_wrapped = spnego_gen_krb5_wrap(tmp_ctx, tkt, TOK_ID_KRB_AP_REQ);
     221           0 :         if (tkt_wrapped.data == NULL) {
     222           0 :                 status = NT_STATUS_NO_MEMORY;
     223           0 :                 goto out;
     224             :         }
     225             : 
     226           0 :         auth_context = auth4_context_for_PAC_DATA_CTR(tmp_ctx);
     227           0 :         if (auth_context == NULL) {
     228           0 :                 status = NT_STATUS_NO_MEMORY;
     229           0 :                 goto out;
     230             :         }
     231             : 
     232           0 :         lp_ctx = loadparm_init_s3(tmp_ctx, loadparm_s3_helpers());
     233           0 :         if (lp_ctx == NULL) {
     234           0 :                 status = NT_STATUS_INVALID_SERVER_STATE;
     235           0 :                 DEBUG(10, ("loadparm_init_s3 failed\n"));
     236           0 :                 goto out;
     237             :         }
     238             : 
     239           0 :         gensec_settings = lpcfg_gensec_settings(tmp_ctx, lp_ctx);
     240           0 :         if (gensec_settings == NULL) {
     241           0 :                 status = NT_STATUS_NO_MEMORY;
     242           0 :                 DEBUG(10, ("lpcfg_gensec_settings failed\n"));
     243           0 :                 goto out;
     244             :         }
     245             : 
     246           0 :         backends = talloc_zero_array(gensec_settings,
     247             :                                      const struct gensec_security_ops *, 2);
     248           0 :         if (backends == NULL) {
     249           0 :                 status = NT_STATUS_NO_MEMORY;
     250           0 :                 goto out;
     251             :         }
     252           0 :         gensec_settings->backends = backends;
     253             : 
     254           0 :         gensec_init();
     255             : 
     256           0 :         backends[idx++] = &gensec_gse_krb5_security_ops;
     257             : 
     258           0 :         status = gensec_server_start(tmp_ctx, gensec_settings,
     259             :                                         auth_context, &gensec_server_context);
     260             : 
     261           0 :         if (!NT_STATUS_IS_OK(status)) {
     262           0 :                 DEBUG(1, (__location__ "Failed to start server-side GENSEC to validate a Kerberos ticket: %s\n", nt_errstr(status)));
     263           0 :                 goto out;
     264             :         }
     265             : 
     266           0 :         talloc_unlink(tmp_ctx, lp_ctx);
     267           0 :         talloc_unlink(tmp_ctx, gensec_settings);
     268           0 :         talloc_unlink(tmp_ctx, auth_context);
     269             : 
     270             :         /* Session info is not complete, do not pass to auth log */
     271           0 :         gensec_want_feature(gensec_server_context, GENSEC_FEATURE_NO_AUTHZ_LOG);
     272             : 
     273           0 :         status = gensec_start_mech_by_oid(gensec_server_context, GENSEC_OID_KERBEROS5);
     274           0 :         if (!NT_STATUS_IS_OK(status)) {
     275           0 :                 DEBUG(1, (__location__ "Failed to start server-side GENSEC krb5 to validate a Kerberos ticket: %s\n", nt_errstr(status)));
     276           0 :                 goto out;
     277             :         }
     278             : 
     279             :         /* Do a client-server update dance */
     280           0 :         status = gensec_update(gensec_server_context, tmp_ctx, tkt_wrapped, &ap_rep);
     281           0 :         if (!NT_STATUS_IS_OK(status)) {
     282           0 :                 DEBUG(1, ("gensec_update() failed: %s\n", nt_errstr(status)));
     283           0 :                 goto out;
     284             :         }
     285             : 
     286             :         /* Now return the PAC information to the callers.  We ignore
     287             :          * the session_info and instead pick out the PAC via the
     288             :          * private_data on the auth_context */
     289           0 :         status = gensec_session_info(gensec_server_context, tmp_ctx, &session_info);
     290           0 :         if (!NT_STATUS_IS_OK(status)) {
     291           0 :                 DEBUG(1, ("Unable to obtain PAC via gensec_session_info\n"));
     292           0 :                 goto out;
     293             :         }
     294             : 
     295           0 :         pac_data_ctr = auth4_context_get_PAC_DATA_CTR(auth_context, mem_ctx);
     296           0 :         if (pac_data_ctr == NULL) {
     297           0 :                 DEBUG(1,("no PAC\n"));
     298           0 :                 status = NT_STATUS_INVALID_PARAMETER;
     299           0 :                 goto out;
     300             :         }
     301             : 
     302           0 :         *_pac_data_ctr = talloc_move(mem_ctx, &pac_data_ctr);
     303           0 :         if (_canon_principal != NULL) {
     304           0 :                 *_canon_principal = talloc_move(mem_ctx, &canon_principal);
     305             :         }
     306           0 :         if (_canon_realm != NULL) {
     307           0 :                 *_canon_realm = talloc_move(mem_ctx, &canon_realm);
     308             :         }
     309             : 
     310           0 : out:
     311           0 :         talloc_free(tmp_ctx);
     312           0 :         if (cc != cache_name) {
     313           0 :                 ads_kdestroy(cc);
     314             :         }
     315             : 
     316           0 :         data_blob_free(&tkt);
     317           0 :         data_blob_free(&ap_rep);
     318           0 :         data_blob_free(&sesskey1);
     319             : 
     320           0 :         return status;
     321             : }
     322             : 
     323             : #endif

Generated by: LCOV version 1.14