/*
- * Copyright (c) 2010, JANET(UK)
+ * Copyright (c) 2011, JANET(UK)
* All rights reserved.
*
* Redistribution and use in source and binary forms, with or without
gssEapAcquireCred(OM_uint32 *minor,
const gss_name_t desiredName,
const gss_buffer_t password,
- OM_uint32 timeReq,
+ OM_uint32 timeReq GSSEAP_UNUSED,
const gss_OID_set desiredMechs,
int credUsage,
gss_cred_id_t *pCred,
{
OM_uint32 major, tmpMinor;
gss_cred_id_t cred;
+#ifdef GSSEAP_DEBUG
+ gss_buffer_desc envPassword;
+#endif
/* XXX TODO validate with changed set_cred_option API */
*pCred = GSS_C_NO_CREDENTIAL;
} else {
gss_buffer_desc nameBuf = GSS_C_EMPTY_BUFFER;
gss_OID nameType = GSS_C_NO_OID;
+ char loginName[256];
if (cred->flags & CRED_FLAG_ACCEPT) {
char serviceName[5 + MAXHOSTNAMELEN] = "host@";
nameType = GSS_C_NT_HOSTBASED_SERVICE;
} else if (cred->flags & CRED_FLAG_INITIATE) {
- nameBuf.value = getlogin(); /* XXX */
- nameBuf.length = strlen((char *)nameBuf.value);
+ /* XXX FIXME temporary implementation */
+ snprintf(loginName, sizeof(loginName), "%s@", getlogin());
+ nameBuf.value = loginName;
+ nameBuf.length = strlen(loginName);
nameType = GSS_C_NT_USER_NAME;
}
if (nameBuf.length != 0) {
- major = gssEapImportName(minor, &nameBuf, nameType, &cred->name);
+ gss_OID mech = GSS_C_NO_OID;
+
+ if (cred->mechanisms != GSS_C_NO_OID_SET &&
+ cred->mechanisms->count == 1)
+ mech = &cred->mechanisms->elements[0];
+
+ major = gssEapImportName(minor, &nameBuf, nameType, mech, &cred->name);
if (GSS_ERROR(major))
goto cleanup;
}
cred->flags |= CRED_FLAG_DEFAULT_IDENTITY;
}
+#ifdef GSSEAP_DEBUG
+ if (password == GSS_C_NO_BUFFER &&
+ (cred->flags & CRED_FLAG_DEFAULT_IDENTITY) &&
+ (envPassword.value = getenv("GSSEAP_CREDS")) != NULL) {
+ envPassword.length = strlen((char *)envPassword.value);
+ major = duplicateBuffer(minor, &envPassword, &cred->password);
+ if (GSS_ERROR(major))
+ goto cleanup;
+ } else
+#endif /* GSSEAP_DEBUG */
if (password != GSS_C_NO_BUFFER) {
major = duplicateBuffer(minor, password, &cred->password);
if (GSS_ERROR(major))
&& !gssEapCanReauthP(cred, GSS_C_NO_NAME, timeReq)
#endif
major = GSS_S_CRED_UNAVAIL;
+ *minor = GSSEAP_MISSING_PASSWORD;
goto cleanup;
}