2 * Copyright (c) 2010, JANET(UK)
5 * Redistribution and use in source and binary forms, with or without
6 * modification, are permitted provided that the following conditions
9 * 1. Redistributions of source code must retain the above copyright
10 * notice, this list of conditions and the following disclaimer.
12 * 2. Redistributions in binary form must reproduce the above copyright
13 * notice, this list of conditions and the following disclaimer in the
14 * documentation and/or other materials provided with the distribution.
16 * 3. Neither the name of JANET(UK) nor the names of its contributors
17 * may be used to endorse or promote products derived from this software
18 * without specific prior written permission.
20 * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS"
21 * AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
22 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
23 * ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE
24 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
25 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
26 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
27 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
28 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
29 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
33 #include "gssapiP_eap.h"
40 static gss_eap_attr_create_provider gssEapAttrFactories[ATTR_TYPE_MAX + 1];
41 static gss_buffer_desc gssEapAttrPrefixes[ATTR_TYPE_MAX + 1];
44 * Register a provider for a particular type and prefix
47 gss_eap_attr_ctx::registerProvider(unsigned int type,
49 gss_eap_attr_create_provider factory)
51 assert(type <= ATTR_TYPE_MAX);
53 assert(gssEapAttrFactories[type] == NULL);
55 gssEapAttrFactories[type] = factory;
57 gssEapAttrPrefixes[type].value = (void *)prefix;
58 gssEapAttrPrefixes[type].length = strlen(prefix);
60 gssEapAttrPrefixes[type].value = NULL;
61 gssEapAttrPrefixes[type].length = 0;
66 * Unregister a provider
69 gss_eap_attr_ctx::unregisterProvider(unsigned int type)
71 assert(type <= ATTR_TYPE_MAX);
73 gssEapAttrFactories[type] = NULL;
74 gssEapAttrPrefixes[type].value = NULL;
75 gssEapAttrPrefixes[type].length = 0;
79 * Create an attribute context, that manages instances of providers
81 gss_eap_attr_ctx::gss_eap_attr_ctx(void)
83 for (unsigned int i = ATTR_TYPE_MIN; i <= ATTR_TYPE_MAX; i++) {
84 gss_eap_attr_provider *provider;
86 if (gssEapAttrFactories[i] != NULL) {
87 provider = (gssEapAttrFactories[i])();
92 m_providers[i] = provider;
97 * Convert an attribute prefix to a type
100 gss_eap_attr_ctx::attributePrefixToType(const gss_buffer_t prefix)
104 for (i = ATTR_TYPE_MIN; i < ATTR_TYPE_MAX; i++) {
105 if (bufferEqual(&gssEapAttrPrefixes[i], prefix))
109 return ATTR_TYPE_LOCAL;
113 * Convert a type to an attribute prefix
116 gss_eap_attr_ctx::attributeTypeToPrefix(unsigned int type)
118 if (type < ATTR_TYPE_MIN || type >= ATTR_TYPE_MAX)
119 return GSS_C_NO_BUFFER;
121 return &gssEapAttrPrefixes[type];
125 * Initialize a context from an existing context.
128 gss_eap_attr_ctx::initFromExistingContext(const gss_eap_attr_ctx *manager)
132 for (unsigned int i = ATTR_TYPE_MIN; i <= ATTR_TYPE_MAX; i++) {
133 gss_eap_attr_provider *provider = m_providers[i];
135 if (provider == NULL)
138 ret = provider->initFromExistingContext(this,
139 manager->m_providers[i]);
148 * Initialize a context from a GSS credential and context.
151 gss_eap_attr_ctx::initFromGssContext(const gss_cred_id_t cred,
152 const gss_ctx_id_t ctx)
156 for (unsigned int i = ATTR_TYPE_MIN; i <= ATTR_TYPE_MAX; i++) {
157 gss_eap_attr_provider *provider = m_providers[i];
159 if (provider == NULL)
162 ret = provider->initFromGssContext(this, cred, ctx);
171 * Initialize a context from an exported context or name token
174 gss_eap_attr_ctx::initFromBuffer(const gss_buffer_t buffer)
177 gss_eap_attr_provider *primaryProvider = getPrimaryProvider();
179 ret = primaryProvider->initFromBuffer(this, buffer);
183 for (unsigned int i = ATTR_TYPE_MIN; i <= ATTR_TYPE_MAX; i++) {
184 gss_eap_attr_provider *provider = m_providers[i];
186 if (provider == primaryProvider)
189 ret = provider->initFromGssContext(this,
199 gss_eap_attr_ctx::~gss_eap_attr_ctx(void)
201 for (unsigned int i = ATTR_TYPE_MIN; i <= ATTR_TYPE_MAX; i++)
202 delete m_providers[i];
206 * Locate provider for a given type
208 gss_eap_attr_provider *
209 gss_eap_attr_ctx::getProvider(unsigned int type) const
211 assert(type >= ATTR_TYPE_MIN && type <= ATTR_TYPE_MAX);
212 return m_providers[type];
216 * Locate provider for a given prefix
218 gss_eap_attr_provider *
219 gss_eap_attr_ctx::getProvider(const gss_buffer_t prefix) const
223 type = attributePrefixToType(prefix);
225 return m_providers[type];
229 * Get primary provider. Only the primary provider is serialised when
230 * gss_export_sec_context() or gss_export_name_composite() is called.
232 gss_eap_attr_provider *
233 gss_eap_attr_ctx::getPrimaryProvider(void) const
235 return m_providers[ATTR_TYPE_RADIUS];
242 gss_eap_attr_ctx::setAttribute(int complete,
243 const gss_buffer_t attr,
244 const gss_buffer_t value)
246 gss_buffer_desc suffix = GSS_C_EMPTY_BUFFER;
248 gss_eap_attr_provider *provider;
250 decomposeAttributeName(attr, &type, &suffix);
252 provider = m_providers[type];
253 if (provider != NULL) {
254 provider->setAttribute(complete,
255 (type == ATTR_TYPE_LOCAL) ? attr : &suffix,
258 /* XXX TODO throw exception */
263 * Delete an attrbiute
266 gss_eap_attr_ctx::deleteAttribute(const gss_buffer_t attr)
268 gss_buffer_desc suffix = GSS_C_EMPTY_BUFFER;
270 gss_eap_attr_provider *provider;
272 decomposeAttributeName(attr, &type, &suffix);
274 provider = m_providers[type];
275 if (provider != NULL)
276 provider->deleteAttribute(type == ATTR_TYPE_LOCAL ? attr : &suffix);
280 * Enumerate attribute types with callback
283 gss_eap_attr_ctx::getAttributeTypes(gss_eap_attr_enumeration_cb cb, void *data) const
288 for (i = ATTR_TYPE_MIN; i <= ATTR_TYPE_MAX; i++) {
289 gss_eap_attr_provider *provider = m_providers[i];
291 if (provider == NULL)
294 ret = provider->getAttributeTypes(cb, data);
302 struct eap_gss_get_attr_types_args {
304 gss_buffer_set_t attrs;
308 addAttribute(const gss_eap_attr_provider *provider,
309 const gss_buffer_t attribute,
312 eap_gss_get_attr_types_args *args = (eap_gss_get_attr_types_args *)data;
313 gss_buffer_desc qualified;
314 OM_uint32 major, minor;
316 if (args->type != ATTR_TYPE_LOCAL) {
317 gss_eap_attr_ctx::composeAttributeName(args->type, attribute, &qualified);
318 major = gss_add_buffer_set_member(&minor, &qualified, &args->attrs);
319 gss_release_buffer(&minor, &qualified);
321 major = gss_add_buffer_set_member(&minor, attribute, &args->attrs);
324 return GSS_ERROR(major) == false;
328 * Enumerate attribute types, output is buffer set
331 gss_eap_attr_ctx::getAttributeTypes(gss_buffer_set_t *attrs)
333 eap_gss_get_attr_types_args args;
334 OM_uint32 major, minor;
338 major = gss_create_empty_buffer_set(&minor, attrs);
339 if (GSS_ERROR(major)) {
340 throw new std::bad_alloc;
346 for (i = ATTR_TYPE_MIN; i <= ATTR_TYPE_MAX; i++) {
347 gss_eap_attr_provider *provider = m_providers[i];
351 if (provider == NULL)
354 ret = provider->getAttributeTypes(addAttribute, (void *)&args);
360 gss_release_buffer_set(&minor, attrs);
366 * Get attribute with given name
369 gss_eap_attr_ctx::getAttribute(const gss_buffer_t attr,
373 gss_buffer_t display_value,
376 gss_buffer_desc suffix = GSS_C_EMPTY_BUFFER;
378 gss_eap_attr_provider *provider;
381 decomposeAttributeName(attr, &type, &suffix);
383 provider = m_providers[type];
384 if (provider == NULL)
387 ret = provider->getAttribute(type == ATTR_TYPE_LOCAL ? attr : &suffix,
388 authenticated, complete,
389 value, display_value, more);
395 * Map attribute context to C++ object
398 gss_eap_attr_ctx::mapToAny(int authenticated,
399 gss_buffer_t type_id) const
402 gss_eap_attr_provider *provider;
403 gss_buffer_desc suffix;
405 decomposeAttributeName(type_id, &type, &suffix);
407 provider = m_providers[type];
408 if (provider == NULL)
409 return (gss_any_t)NULL;
411 return provider->mapToAny(authenticated, &suffix);
415 * Release mapped context
418 gss_eap_attr_ctx::releaseAnyNameMapping(gss_buffer_t type_id,
419 gss_any_t input) const
422 gss_eap_attr_provider *provider;
423 gss_buffer_desc suffix;
425 decomposeAttributeName(type_id, &type, &suffix);
427 provider = m_providers[type];
428 if (provider != NULL)
429 provider->releaseAnyNameMapping(&suffix, input);
433 * Export attribute context to buffer
436 gss_eap_attr_ctx::exportToBuffer(gss_buffer_t buffer) const
438 getPrimaryProvider()->exportToBuffer(buffer);
442 * Return soonest expiry time of providers
445 gss_eap_attr_ctx::getExpiryTime(void) const
448 time_t expiryTime = 0;
450 for (i = ATTR_TYPE_MIN; i <= ATTR_TYPE_MAX; i++) {
451 gss_eap_attr_provider *provider = m_providers[i];
452 time_t providerExpiryTime;
454 if (provider == NULL)
457 providerExpiryTime = provider->getExpiryTime();
458 if (providerExpiryTime == 0)
461 if (expiryTime == 0 || providerExpiryTime < expiryTime)
462 expiryTime = providerExpiryTime;
469 * Map C++ exception to GSS status
472 mapException(OM_uint32 *minor, std::exception &e)
474 OM_uint32 major = GSS_S_FAILURE;
476 /* XXX TODO implement other mappings */
477 if (typeid(e) == typeid(std::bad_alloc))
483 /* rethrow for now for debugging */
491 * Decompose attribute name into prefix and suffix
494 gss_eap_attr_ctx::decomposeAttributeName(const gss_buffer_t attribute,
501 for (i = 0; i < attribute->length; i++) {
502 if (((char *)attribute->value)[i] == ' ') {
503 p = (char *)attribute->value + i + 1;
508 prefix->value = attribute->value;
511 if (p != NULL && *p != '\0') {
512 suffix->length = attribute->length - 1 - prefix->length;
516 suffix->value = NULL;
521 * Decompose attribute name into type and suffix
524 gss_eap_attr_ctx::decomposeAttributeName(const gss_buffer_t attribute,
528 gss_buffer_desc prefix = GSS_C_EMPTY_BUFFER;
530 decomposeAttributeName(attribute, &prefix, suffix);
531 *type = attributePrefixToType(&prefix);
535 * Compose attribute name from prefix, suffix; returns C++ string
538 gss_eap_attr_ctx::composeAttributeName(const gss_buffer_t prefix,
539 const gss_buffer_t suffix)
543 if (prefix == GSS_C_NO_BUFFER || prefix->length == 0)
546 str.append((const char *)prefix->value, prefix->length);
548 if (suffix != GSS_C_NO_BUFFER) {
550 str.append((const char *)suffix->value, suffix->length);
557 * Compose attribute name from type, suffix; returns C++ string
560 gss_eap_attr_ctx::composeAttributeName(unsigned int type,
561 const gss_buffer_t suffix)
563 const gss_buffer_t prefix = attributeTypeToPrefix(type);
565 return composeAttributeName(prefix, suffix);
569 * Compose attribute name from prefix, suffix; returns GSS buffer
572 gss_eap_attr_ctx::composeAttributeName(const gss_buffer_t prefix,
573 const gss_buffer_t suffix,
574 gss_buffer_t attribute)
576 std::string str = composeAttributeName(prefix, suffix);
578 if (str.length() != 0) {
579 return duplicateBuffer(str, attribute);
581 attribute->length = 0;
582 attribute->value = NULL;
587 * Compose attribute name from type, suffix; returns GSS buffer
590 gss_eap_attr_ctx::composeAttributeName(unsigned int type,
591 const gss_buffer_t suffix,
592 gss_buffer_t attribute)
594 gss_buffer_t prefix = attributeTypeToPrefix(type);
596 return composeAttributeName(prefix, suffix, attribute);
603 gssEapInquireName(OM_uint32 *minor,
607 gss_buffer_set_t *attrs)
609 if (name->attrCtx == NULL)
610 return GSS_S_UNAVAILABLE;
613 if (!name->attrCtx->getAttributeTypes(attrs))
614 return GSS_S_UNAVAILABLE;
615 } catch (std::exception &e) {
616 return mapException(minor, e);
619 return GSS_S_COMPLETE;
623 gssEapGetNameAttribute(OM_uint32 *minor,
629 gss_buffer_t display_value,
640 if (display_value != NULL) {
641 display_value->length = 0;
642 display_value->value = NULL;
645 if (name->attrCtx == NULL)
646 return GSS_S_UNAVAILABLE;
649 if (!name->attrCtx->getAttribute(attr, authenticated, complete,
650 value, display_value, more))
651 return GSS_S_UNAVAILABLE;
652 } catch (std::exception &e) {
653 return mapException(minor, e);
656 return GSS_S_COMPLETE;
660 gssEapDeleteNameAttribute(OM_uint32 *minor,
664 if (name->attrCtx == NULL)
665 return GSS_S_UNAVAILABLE;
668 name->attrCtx->deleteAttribute(attr);
669 } catch (std::exception &ex) {
670 return mapException(minor, ex);
673 return GSS_S_COMPLETE;
677 gssEapSetNameAttribute(OM_uint32 *minor,
683 if (name->attrCtx == NULL)
684 return GSS_S_UNAVAILABLE;
687 name->attrCtx->setAttribute(complete, attr, value);
688 } catch (std::exception &ex) {
689 return mapException(minor, ex);
692 return GSS_S_COMPLETE;
696 gssEapExportAttrContext(OM_uint32 *minor,
700 if (name->attrCtx == NULL) {
702 buffer->value = NULL;
704 return GSS_S_COMPLETE;
708 name->attrCtx->exportToBuffer(buffer);
709 } catch (std::exception &e) {
710 return mapException(minor, e);
713 return GSS_S_COMPLETE;
717 gssEapImportAttrContext(OM_uint32 *minor,
721 gss_eap_attr_ctx *ctx = NULL;
723 assert(name->attrCtx == NULL);
725 if (buffer->length != 0) {
727 ctx = new gss_eap_attr_ctx();
729 if (!ctx->initFromBuffer(buffer)) {
731 return GSS_S_DEFECTIVE_TOKEN;
734 } catch (std::exception &e) {
736 return mapException(minor, e);
740 return GSS_S_COMPLETE;
744 gssEapDuplicateAttrContext(OM_uint32 *minor,
748 gss_eap_attr_ctx *ctx = NULL;
750 assert(out->attrCtx == NULL);
753 if (in->attrCtx != NULL) {
754 ctx = new gss_eap_attr_ctx();
755 if (!ctx->initFromExistingContext(in->attrCtx)) {
757 return GSS_S_FAILURE;
761 } catch (std::exception &e) {
763 return mapException(minor, e);
766 return GSS_S_COMPLETE;
770 gssEapMapNameToAny(OM_uint32 *minor,
773 gss_buffer_t type_id,
776 if (name->attrCtx == NULL)
777 return GSS_S_UNAVAILABLE;
780 *output = name->attrCtx->mapToAny(authenticated, type_id);
781 } catch (std::exception &e) {
782 return mapException(minor, e);
785 return GSS_S_COMPLETE;
789 gssEapReleaseAnyNameMapping(OM_uint32 *minor,
791 gss_buffer_t type_id,
794 if (name->attrCtx == NULL)
795 return GSS_S_UNAVAILABLE;
799 name->attrCtx->releaseAnyNameMapping(type_id, *input);
801 } catch (std::exception &e) {
802 return mapException(minor, e);
805 return GSS_S_COMPLETE;
809 gssEapReleaseAttrContext(OM_uint32 *minor,
812 if (name->attrCtx != NULL)
813 delete name->attrCtx;
815 return GSS_S_COMPLETE;
819 gssEapAttrProvidersInit(OM_uint32 *minor)
822 if (gss_eap_radius_attr_provider::init() &&
823 gss_eap_saml_assertion_provider::init() &&
824 gss_eap_saml_attr_provider::init() &&
825 gss_eap_shib_attr_provider::init())
826 return GSS_S_COMPLETE;
827 } catch (std::exception &e) {
828 return mapException(minor, e);
831 return GSS_S_FAILURE;
835 gssEapAttrProvidersFinalize(OM_uint32 *minor)
838 gss_eap_shib_attr_provider::finalize();
839 gss_eap_saml_attr_provider::finalize();
840 gss_eap_saml_assertion_provider::finalize();
841 gss_eap_radius_attr_provider::finalize();
842 } catch (std::exception &e) {
843 return mapException(minor, e);
846 return GSS_S_COMPLETE;
850 * Public accessor for initialisng a context from a GSS context. Also
851 * sets expiry time on GSS context as a side-effect.
853 struct gss_eap_attr_ctx *
854 gssEapCreateAttrContext(gss_cred_id_t gssCred,
857 gss_eap_attr_ctx *ctx;
859 assert(gssCtx != GSS_C_NO_CONTEXT);
861 ctx = new gss_eap_attr_ctx();
862 if (!ctx->initFromGssContext(gssCred, gssCtx)) {
867 gssCtx->expiryTime = ctx->getExpiryTime();