2 * Copyright (c) 2011, JANET(UK)
5 * Redistribution and use in source and binary forms, with or without
6 * modification, are permitted provided that the following conditions
9 * 1. Redistributions of source code must retain the above copyright
10 * notice, this list of conditions and the following disclaimer.
12 * 2. Redistributions in binary form must reproduce the above copyright
13 * notice, this list of conditions and the following disclaimer in the
14 * documentation and/or other materials provided with the distribution.
16 * 3. Neither the name of JANET(UK) nor the names of its contributors
17 * may be used to endorse or promote products derived from this software
18 * without specific prior written permission.
20 * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS"
21 * AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
22 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
23 * ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE
24 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
25 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
26 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
27 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
28 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
29 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
33 * Copyright 1993 by OpenVision Technologies, Inc.
35 * Permission to use, copy, modify, distribute, and sell this software
36 * and its documentation for any purpose is hereby granted without fee,
37 * provided that the above copyright notice appears in all copies and
38 * that both that copyright notice and this permission notice appear in
39 * supporting documentation, and that the name of OpenVision not be used
40 * in advertising or publicity pertaining to distribution of the software
41 * without specific, written prior permission. OpenVision makes no
42 * representations about the suitability of this software for any
43 * purpose. It is provided "as is" without express or implied warranty.
45 * OPENVISION DISCLAIMS ALL WARRANTIES WITH REGARD TO THIS SOFTWARE,
46 * INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS, IN NO
47 * EVENT SHALL OPENVISION BE LIABLE FOR ANY SPECIAL, INDIRECT OR
48 * CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM LOSS OF
49 * USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR
50 * OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
51 * PERFORMANCE OF THIS SOFTWARE.
55 * Message protection services: checksum helpers.
58 #include "gssapiP_eap.h"
61 gssEapChecksum(krb5_context context,
64 #ifdef HAVE_HEIMDAL_VERSION
67 krb5_keyblock *crypto,
69 krb5_keyusage sign_usage,
70 gss_iov_buffer_desc *iov,
72 enum gss_eap_token_type toktype,
77 gss_iov_buffer_desc *header;
78 gss_iov_buffer_desc *trailer;
79 krb5_crypto_iov *kiov;
82 size_t k5_checksumlen;
87 code = krbCryptoLength(context, crypto, KRB5_CRYPTO_TYPE_CHECKSUM, &k5_checksumlen);
91 header = gssEapLocateHeaderIov(iov, iov_count, toktype);
92 GSSEAP_ASSERT(header != NULL);
94 trailer = gssEapLocateIov(iov, iov_count, GSS_IOV_BUFFER_TYPE_TRAILER);
95 GSSEAP_ASSERT(rrc != 0 || trailer != NULL);
97 if (trailer == NULL) {
98 if (rrc != k5_checksumlen)
99 return KRB5_BAD_MSIZE;
100 if (header->buffer.length != 16 + k5_checksumlen)
101 return KRB5_BAD_MSIZE;
102 } else if (trailer->buffer.length != k5_checksumlen)
103 return KRB5_BAD_MSIZE;
105 kiov_count = 2 + iov_count;
106 kiov = (krb5_crypto_iov *)GSSEAP_MALLOC(kiov_count * sizeof(krb5_crypto_iov));
110 /* Checksum over ( Data | Header ) */
113 for (j = 0; j < iov_count; j++) {
114 kiov[i].flags = gssEapMapCryptoFlag(iov[j].type);
115 kiov[i].data.length = iov[j].buffer.length;
116 kiov[i].data.data = (char *)iov[j].buffer.value;
121 kiov[i].flags = KRB5_CRYPTO_TYPE_SIGN_ONLY;
122 kiov[i].data.length = 16;
123 kiov[i].data.data = (char *)header->buffer.value;
127 kiov[i].flags = KRB5_CRYPTO_TYPE_CHECKSUM;
128 if (trailer == NULL) {
129 kiov[i].data.length = header->buffer.length - 16;
130 kiov[i].data.data = (char *)header->buffer.value + 16;
132 kiov[i].data.length = trailer->buffer.length;
133 kiov[i].data.data = (char *)trailer->buffer.value;
137 #ifdef HAVE_HEIMDAL_VERSION
139 code = krb5_verify_checksum_iov(context, crypto, sign_usage,
140 kiov, kiov_count, &type);
141 *valid = (code == 0);
143 code = krb5_create_checksum_iov(context, crypto, sign_usage,
144 kiov, kiov_count, &type);
148 krb5_boolean kvalid = FALSE;
150 code = krb5_c_verify_checksum_iov(context, type, crypto,
151 sign_usage, kiov, kiov_count, &kvalid);
155 code = krb5_c_make_checksum_iov(context, type, crypto,
156 sign_usage, kiov, kiov_count);
158 #endif /* HAVE_HEIMDAL_VERSION */
166 gssEapSign(krb5_context context,
169 #ifdef HAVE_HEIMDAL_VERSION
172 krb5_keyblock *crypto,
174 krb5_keyusage sign_usage,
175 gss_iov_buffer_desc *iov,
177 enum gss_eap_token_type toktype)
179 return gssEapChecksum(context, type, rrc, crypto,
180 sign_usage, iov, iov_count, toktype, 0, NULL);
184 gssEapVerify(krb5_context context,
187 #ifdef HAVE_HEIMDAL_VERSION
190 krb5_keyblock *crypto,
192 krb5_keyusage sign_usage,
193 gss_iov_buffer_desc *iov,
195 enum gss_eap_token_type toktype,
198 return gssEapChecksum(context, type, rrc, crypto,
199 sign_usage, iov, iov_count, toktype, 1, valid);
204 gssEapEncodeGssChannelBindings(OM_uint32 *minor,
205 gss_channel_bindings_t chanBindings,
206 gss_buffer_t encodedBindings)
208 OM_uint32 major, tmpMinor;
212 if (chanBindings != GSS_C_NO_CHANNEL_BINDINGS) {
214 length += chanBindings->initiator_address.length;
215 length += chanBindings->acceptor_address.length;
216 length += chanBindings->application_data.length;
218 encodedBindings->value = GSSEAP_MALLOC(length);
219 if (encodedBindings->value == NULL) {
221 return GSS_S_FAILURE;
224 encodedBindings->length = length;
225 p = (unsigned char *)encodedBindings->value;
227 store_uint32_be(chanBindings->initiator_addrtype, p);
228 store_buffer(&chanBindings->initiator_address, p + 4, 0);
229 p += 4 + chanBindings->initiator_address.length;
231 store_uint32_be(chanBindings->acceptor_addrtype, p);
232 store_buffer(&chanBindings->acceptor_address, p + 4, 0);
233 p += 4 + chanBindings->acceptor_address.length;
235 store_buffer(&chanBindings->application_data, p, 1);
236 p += chanBindings->application_data.length;
238 encodedBindings->length = 0;
239 encodedBindings->value = NULL;
243 return GSS_S_COMPLETE;