| 1 | /*
 | 
|---|
| 2 |  * Copyright (c) 1997 - 2004 Kungliga Tekniska Högskolan
 | 
|---|
| 3 |  * (Royal Institute of Technology, Stockholm, Sweden).
 | 
|---|
| 4 |  * All rights reserved.
 | 
|---|
| 5 |  *
 | 
|---|
| 6 |  * Redistribution and use in source and binary forms, with or without
 | 
|---|
| 7 |  * modification, are permitted provided that the following conditions
 | 
|---|
| 8 |  * are met:
 | 
|---|
| 9 |  *
 | 
|---|
| 10 |  * 1. Redistributions of source code must retain the above copyright
 | 
|---|
| 11 |  *    notice, this list of conditions and the following disclaimer.
 | 
|---|
| 12 |  *
 | 
|---|
| 13 |  * 2. Redistributions in binary form must reproduce the above copyright
 | 
|---|
| 14 |  *    notice, this list of conditions and the following disclaimer in the
 | 
|---|
| 15 |  *    documentation and/or other materials provided with the distribution.
 | 
|---|
| 16 |  *
 | 
|---|
| 17 |  * 3. Neither the name of the Institute nor the names of its contributors
 | 
|---|
| 18 |  *    may be used to endorse or promote products derived from this software
 | 
|---|
| 19 |  *    without specific prior written permission.
 | 
|---|
| 20 |  *
 | 
|---|
| 21 |  * THIS SOFTWARE IS PROVIDED BY THE INSTITUTE AND CONTRIBUTORS ``AS IS'' AND
 | 
|---|
| 22 |  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
 | 
|---|
| 23 |  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
 | 
|---|
| 24 |  * ARE DISCLAIMED.  IN NO EVENT SHALL THE INSTITUTE OR CONTRIBUTORS BE LIABLE
 | 
|---|
| 25 |  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
 | 
|---|
| 26 |  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
 | 
|---|
| 27 |  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
 | 
|---|
| 28 |  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
 | 
|---|
| 29 |  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
 | 
|---|
| 30 |  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
 | 
|---|
| 31 |  * SUCH DAMAGE.
 | 
|---|
| 32 |  */
 | 
|---|
| 33 | 
 | 
|---|
| 34 | #include "kuser_locl.h"
 | 
|---|
| 35 | 
 | 
|---|
| 36 | static char *etype_str;
 | 
|---|
| 37 | static int version_flag;
 | 
|---|
| 38 | static int help_flag;
 | 
|---|
| 39 | 
 | 
|---|
| 40 | static void
 | 
|---|
| 41 | print_and_decode_tkt (krb5_context context,
 | 
|---|
| 42 |                       krb5_data *ticket,
 | 
|---|
| 43 |                       krb5_principal server,
 | 
|---|
| 44 |                       krb5_enctype enctype)
 | 
|---|
| 45 | {
 | 
|---|
| 46 |     krb5_error_code ret;
 | 
|---|
| 47 |     krb5_crypto crypto;
 | 
|---|
| 48 |     krb5_data dec_data;
 | 
|---|
| 49 |     size_t len;
 | 
|---|
| 50 |     EncTicketPart decr_part;
 | 
|---|
| 51 |     krb5_keyblock key;
 | 
|---|
| 52 |     Ticket tkt;
 | 
|---|
| 53 | 
 | 
|---|
| 54 |     ret = decode_Ticket (ticket->data, ticket->length, &tkt, &len);
 | 
|---|
| 55 |     if (ret)
 | 
|---|
| 56 |         krb5_err (context, 1, ret, "decode_Ticket");
 | 
|---|
| 57 | 
 | 
|---|
| 58 |     ret = krb5_string_to_key (context, enctype, "foo", server, &key);
 | 
|---|
| 59 |     if (ret)
 | 
|---|
| 60 |         krb5_err (context, 1, ret, "krb5_string_to_key");
 | 
|---|
| 61 | 
 | 
|---|
| 62 |     ret = krb5_crypto_init(context, &key, 0, &crypto);
 | 
|---|
| 63 |     if (ret)
 | 
|---|
| 64 |         krb5_err (context, 1, ret, "krb5_crypto_init");
 | 
|---|
| 65 | 
 | 
|---|
| 66 |     ret = krb5_decrypt_EncryptedData (context, crypto, KRB5_KU_TICKET,
 | 
|---|
| 67 |                                       &tkt.enc_part, &dec_data);
 | 
|---|
| 68 |     krb5_crypto_destroy (context, crypto);
 | 
|---|
| 69 |     if (ret)
 | 
|---|
| 70 |         krb5_err (context, 1, ret, "krb5_decrypt_EncryptedData");
 | 
|---|
| 71 |     ret = decode_EncTicketPart (dec_data.data, dec_data.length,
 | 
|---|
| 72 |                                 &decr_part, &len);
 | 
|---|
| 73 |     krb5_data_free (&dec_data);
 | 
|---|
| 74 |     if (ret)
 | 
|---|
| 75 |         krb5_err (context, 1, ret, "krb5_decode_EncTicketPart");
 | 
|---|
| 76 |     free_EncTicketPart(&decr_part);
 | 
|---|
| 77 | }
 | 
|---|
| 78 | 
 | 
|---|
| 79 | struct getargs args[] = {
 | 
|---|
| 80 |     { "enctype",        'e', arg_string, &etype_str,
 | 
|---|
| 81 |       "encryption type to use", "enctype"},
 | 
|---|
| 82 |     { "version",        0,   arg_flag, &version_flag },
 | 
|---|
| 83 |     { "help",           0,   arg_flag, &help_flag }
 | 
|---|
| 84 | };
 | 
|---|
| 85 | 
 | 
|---|
| 86 | static void
 | 
|---|
| 87 | usage (int ret)
 | 
|---|
| 88 | {
 | 
|---|
| 89 |     arg_printusage (args,
 | 
|---|
| 90 |                     sizeof(args)/sizeof(*args),
 | 
|---|
| 91 |                     NULL,
 | 
|---|
| 92 |                     "service");
 | 
|---|
| 93 |     exit (ret);
 | 
|---|
| 94 | }
 | 
|---|
| 95 | 
 | 
|---|
| 96 | int
 | 
|---|
| 97 | main(int argc, char **argv)
 | 
|---|
| 98 | {
 | 
|---|
| 99 |     krb5_error_code ret;
 | 
|---|
| 100 |     krb5_context context;
 | 
|---|
| 101 |     krb5_ccache cache;
 | 
|---|
| 102 |     krb5_creds in, *out;
 | 
|---|
| 103 |     int optidx = 0;
 | 
|---|
| 104 | 
 | 
|---|
| 105 |     setprogname (argv[0]);
 | 
|---|
| 106 | 
 | 
|---|
| 107 |     ret = krb5_init_context (&context);
 | 
|---|
| 108 |     if (ret)
 | 
|---|
| 109 |         errx(1, "krb5_init_context failed: %d", ret);
 | 
|---|
| 110 | 
 | 
|---|
| 111 |     if(getarg(args, sizeof(args) / sizeof(args[0]), argc, argv, &optidx))
 | 
|---|
| 112 |         usage(1);
 | 
|---|
| 113 | 
 | 
|---|
| 114 |     if (help_flag)
 | 
|---|
| 115 |         usage (0);
 | 
|---|
| 116 | 
 | 
|---|
| 117 |     if(version_flag) {
 | 
|---|
| 118 |         print_version(NULL);
 | 
|---|
| 119 |         exit(0);
 | 
|---|
| 120 |     }
 | 
|---|
| 121 | 
 | 
|---|
| 122 |     argc -= optidx;
 | 
|---|
| 123 |     argv += optidx;
 | 
|---|
| 124 | 
 | 
|---|
| 125 |     if (argc != 1)
 | 
|---|
| 126 |         usage (1);
 | 
|---|
| 127 | 
 | 
|---|
| 128 |     ret = krb5_cc_default(context, &cache);
 | 
|---|
| 129 |     if (ret)
 | 
|---|
| 130 |         krb5_err (context, 1, ret, "krb5_cc_default");
 | 
|---|
| 131 | 
 | 
|---|
| 132 |     memset(&in, 0, sizeof(in));
 | 
|---|
| 133 | 
 | 
|---|
| 134 |     if (etype_str) {
 | 
|---|
| 135 |         krb5_enctype enctype;
 | 
|---|
| 136 | 
 | 
|---|
| 137 |         ret = krb5_string_to_enctype(context, etype_str, &enctype);
 | 
|---|
| 138 |         if (ret)
 | 
|---|
| 139 |             krb5_errx (context, 1, "unrecognized enctype: %s", etype_str);
 | 
|---|
| 140 |         in.session.keytype = enctype;
 | 
|---|
| 141 |     }
 | 
|---|
| 142 | 
 | 
|---|
| 143 |     ret = krb5_cc_get_principal(context, cache, &in.client);
 | 
|---|
| 144 |     if (ret)
 | 
|---|
| 145 |         krb5_err (context, 1, ret, "krb5_cc_get_principal");
 | 
|---|
| 146 | 
 | 
|---|
| 147 |     ret = krb5_parse_name(context, argv[0], &in.server);
 | 
|---|
| 148 |     if (ret)
 | 
|---|
| 149 |         krb5_err (context, 1, ret, "krb5_parse_name %s", argv[0]);
 | 
|---|
| 150 | 
 | 
|---|
| 151 |     in.times.endtime = 0;
 | 
|---|
| 152 |     ret = krb5_get_credentials(context, 0, cache, &in, &out);
 | 
|---|
| 153 |     if (ret)
 | 
|---|
| 154 |         krb5_err (context, 1, ret, "krb5_get_credentials");
 | 
|---|
| 155 | 
 | 
|---|
| 156 |     print_and_decode_tkt (context, &out->ticket, out->server,
 | 
|---|
| 157 |                           out->session.keytype);
 | 
|---|
| 158 | 
 | 
|---|
| 159 |     krb5_free_cred_contents(context, out);
 | 
|---|
| 160 |     return 0;
 | 
|---|
| 161 | }
 | 
|---|