/*
- * Copyright (c) 2010, JANET(UK)
+ * Copyright (c) 2011, JANET(UK)
* All rights reserved.
*
* Redistribution and use in source and binary forms, with or without
* SUCH DAMAGE.
*/
+/*
+ * RADIUS attribute provider.
+ */
+
#ifndef _UTIL_RADIUS_H_
#define _UTIL_RADIUS_H_ 1
const gss_ctx_id_t ctx);
bool getAttributeTypes(gss_eap_attr_enumeration_cb, void *data) const;
- void setAttribute(int complete,
+ bool setAttribute(int complete,
const gss_buffer_t attr,
const gss_buffer_t value);
- void deleteAttribute(const gss_buffer_t value);
+ bool deleteAttribute(const gss_buffer_t attr);
bool getAttribute(const gss_buffer_t attr,
int *authenticated,
int *complete,
bool initFromBuffer(const gss_eap_attr_ctx *ctx,
const gss_buffer_t buffer);
- bool getAttribute(unsigned int attribute,
+ bool getAttribute(uint32_t attribute,
int *authenticated,
int *complete,
gss_buffer_t value,
gss_buffer_t display_value,
int *more) const;
+ bool getAttribute(uint16_t attribute,
+ uint16_t vendor,
+ int *authenticated,
+ int *complete,
+ gss_buffer_t value,
+ gss_buffer_t display_value,
+ int *more) const;
+ bool setAttribute(int complete,
+ uint32_t attribute,
+ const gss_buffer_t value);
+ bool deleteAttribute(uint32_t attribute);
+
+ bool getFragmentedAttribute(uint16_t attribute,
+ uint16_t vendor,
+ int *authenticated,
+ int *complete,
+ gss_buffer_t value) const;
- bool authenticated() const { return m_authenticated; }
+ bool authenticated(void) const { return m_authenticated; }
- static bool init();
- static void finalize();
+ time_t getExpiryTime(void) const;
+
+ static bool init(void);
+ static void finalize(void);
static gss_eap_attr_provider *createAttrContext(void);
private:
+ const VALUE_PAIR *getAvps(void) const {
+ return m_vps;
+ }
+
+ VALUE_PAIR *m_vps;
bool m_authenticated;
};
/* For now */
-#define PW_SAML_ASSERTION 1936
-
extern "C" {
#endif
-static inline OM_uint32
-addAvpFromBuffer(OM_uint32 *minor,
- rc_handle *rh,
- VALUE_PAIR **vp,
- int type,
- gss_buffer_t buffer)
-{
- if (rc_avpair_add(rh, vp, type, buffer->value, buffer->length, 0) == NULL) {
- return GSS_S_FAILURE;
- }
+OM_uint32
+gssEapRadiusAddAvp(OM_uint32 *minor,
+ VALUE_PAIR **vp,
+ uint16_t type,
+ uint16_t vendor,
+ const gss_buffer_t buffer);
+
+OM_uint32
+gssEapRadiusGetAvp(OM_uint32 *minor,
+ VALUE_PAIR *vps,
+ uint16_t type,
+ uint16_t vendor,
+ gss_buffer_t buffer,
+ int concat);
+
+OM_uint32
+gssEapRadiusGetRawAvp(OM_uint32 *minor,
+ VALUE_PAIR *vps,
+ uint16_t type,
+ uint16_t vendor,
+ VALUE_PAIR **vp);
+OM_uint32
+gssEapRadiusFreeAvps(OM_uint32 *minor,
+ VALUE_PAIR **vps);
- return GSS_S_COMPLETE;
-}
+OM_uint32 gssEapRadiusAttrProviderInit(OM_uint32 *minor);
+OM_uint32 gssEapRadiusAttrProviderFinalize(OM_uint32 *minor);
-static inline OM_uint32
-getBufferFromAvps(OM_uint32 *minor,
- VALUE_PAIR *vps,
- int type,
- gss_buffer_t buffer,
- int concat)
-{
- VALUE_PAIR *vp;
- unsigned char *p;
-
- buffer->length = 0;
- buffer->value = NULL;
-
- vp = rc_avpair_get(vps, type, 0);
- if (vp == NULL)
- return GSS_S_UNAVAILABLE;
-
- do {
- buffer->length += vp->lvalue;
- } while (concat && (vp = rc_avpair_get(vp->next, type, 0)) != NULL);
-
- buffer->value = GSSEAP_MALLOC(buffer->length);
- if (buffer->value == NULL) {
- *minor = ENOMEM;
- return GSS_S_FAILURE;
- }
+OM_uint32
+gssEapRadiusMapError(OM_uint32 *minor,
+ struct rs_error *err);
- p = (unsigned char *)buffer->value;
+#define RS_CONFIG_FILE SYSCONFDIR "/radsec.conf"
+#define RS_DICT_FILE DATAROOTDIR "/freeradius/dictionary"
- for (vp = rc_avpair_get(vps, type, 0);
- concat && vp != NULL;
- vp = rc_avpair_get(vp->next, type, 0)) {
- memcpy(p, vp->strvalue, vp->lvalue);
- p += vp->lvalue;
- }
+#define VENDORPEC_MS 311 /* RFC 2548 */
- *minor = 0;
- return GSS_S_COMPLETE;
-}
+#define PW_MS_MPPE_SEND_KEY 16
+#define PW_MS_MPPE_RECV_KEY 17
-OM_uint32 gssEapRadiusAttrProviderInit(OM_uint32 *minor);
-OM_uint32 gssEapRadiusAttrProviderFinalize(OM_uint32 *minor);
+#define VENDORPEC_UKERNA 25622
+
+#define PW_GSS_ACCEPTOR_SERVICE_NAME 128
+#define PW_GSS_ACCEPTOR_HOST_NAME 129
+#define PW_GSS_ACCEPTOR_SERVICE_SPECIFIC 130
+#define PW_GSS_ACCEPTOR_REALM_NAME 131
+#define PW_SAML_AAA_ASSERTION 132
+
+#define IS_RADIUS_ERROR(code) ((code) >= ERROR_TABLE_BASE_rse && \
+ (code) <= ERROR_TABLE_BASE_rse + RSE_TIMEOUT_IO)
#ifdef __cplusplus
}