For now, configure default realm using eap_gss appdefault
authorLuke Howard <lukeh@padl.com>
Thu, 17 Mar 2011 22:56:32 +0000 (09:56 +1100)
committerLuke Howard <lukeh@padl.com>
Thu, 17 Mar 2011 23:05:00 +0000 (10:05 +1100)
util_krb.c
util_name.c

index 836fef1..2176d9b 100644 (file)
@@ -54,6 +54,38 @@ createKrbContextKey(void)
     GSSEAP_KEY_CREATE(&krbContextKey, destroyKrbContext);
 }
 
+static krb5_error_code
+initKrbContext(krb5_context *pKrbContext)
+{
+    krb5_context krbContext;
+    krb5_error_code code;
+    char *defaultRealm = NULL;
+
+    *pKrbContext = NULL;
+
+    code = krb5_init_context(&krbContext);
+    if (code != 0)
+        goto cleanup;
+
+    krb5_appdefault_string(krbContext, "eap_gss",
+                           NULL, "default_realm", "", &defaultRealm);
+
+    code = krb5_set_default_realm(krbContext, defaultRealm);
+    if (code != 0)
+        goto cleanup;
+
+    *pKrbContext = krbContext;
+
+cleanup:
+    if (code != 0 && krbContext != NULL)
+        krb5_free_context(krbContext);
+
+    if (defaultRealm != NULL)
+        GSSEAP_FREE(defaultRealm);
+
+    return code;
+}
+
 OM_uint32
 gssEapKerberosInit(OM_uint32 *minor, krb5_context *context)
 {
@@ -63,7 +95,7 @@ gssEapKerberosInit(OM_uint32 *minor, krb5_context *context)
 
     *context = GSSEAP_GETSPECIFIC(krbContextKey);
     if (*context == NULL) {
-        *minor = krb5_init_context(context);
+        *minor = initKrbContext(context);
         if (*minor == 0) {
             if (GSSEAP_SETSPECIFIC(krbContextKey, *context) != 0) {
                 *minor = errno;
index daa059f..c8c29c4 100644 (file)
@@ -196,19 +196,17 @@ importUserName(OM_uint32 *minor,
     OM_uint32 major;
     krb5_context krbContext;
     krb5_principal krbPrinc;
-    char *nameString, *realm;
+    char *nameString, *realm = NULL;
     int flags = 0;
+    krb5_error_code code;
 
     GSSEAP_KRB_INIT(&krbContext);
 
-    realm = getenv("GSSEAP_DEFAULT_REALM");
-    if (realm != NULL) {
-        *minor = krb5_set_default_realm(krbContext, realm);
-        if (*minor != 0)
-            return GSS_S_FAILURE;
-    } else {
+    code = krb5_get_default_realm(krbContext, &realm);
+    if (code != 0 || realm == NULL)
         flags |= KRB5_PRINCIPAL_PARSE_REQUIRE_REALM;
-    }
+    else
+        krb5_free_default_realm(krbContext, realm);
 
     if (nameBuffer == GSS_C_NO_BUFFER) {
         *minor = krb5_copy_principal(krbContext,