154925bf6Swillf /* 254925bf6Swillf * lib/kdb/kdb_ldap/ldap_principal.h 354925bf6Swillf * 454925bf6Swillf * Copyright (c) 2004-2005, Novell, Inc. 554925bf6Swillf * All rights reserved. 654925bf6Swillf * 754925bf6Swillf * Redistribution and use in source and binary forms, with or without 854925bf6Swillf * modification, are permitted provided that the following conditions are met: 954925bf6Swillf * 1054925bf6Swillf * * Redistributions of source code must retain the above copyright notice, 1154925bf6Swillf * this list of conditions and the following disclaimer. 1254925bf6Swillf * * Redistributions in binary form must reproduce the above copyright 1354925bf6Swillf * notice, this list of conditions and the following disclaimer in the 1454925bf6Swillf * documentation and/or other materials provided with the distribution. 1554925bf6Swillf * * The copyright holder's name is not used to endorse or promote products 1654925bf6Swillf * derived from this software without specific prior written permission. 1754925bf6Swillf * 1854925bf6Swillf * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" 1954925bf6Swillf * AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 2054925bf6Swillf * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE 2154925bf6Swillf * ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS BE 2254925bf6Swillf * LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR 2354925bf6Swillf * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF 2454925bf6Swillf * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS 2554925bf6Swillf * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN 2654925bf6Swillf * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) 2754925bf6Swillf * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE 2854925bf6Swillf * POSSIBILITY OF SUCH DAMAGE. 2954925bf6Swillf */ 3054925bf6Swillf 3154925bf6Swillf #ifndef _LDAP_PRINCIPAL_H 3254925bf6Swillf #define _LDAP_PRINCIPAL_H 1 3354925bf6Swillf 3454925bf6Swillf #include "ldap_tkt_policy.h" 3554925bf6Swillf 3654925bf6Swillf #define KEYHEADER 12 3754925bf6Swillf 3854925bf6Swillf #define NOOFKEYS(ptr) ((ptr[10]<<8) | ptr[11]) 3954925bf6Swillf 4054925bf6Swillf #define PRINCIPALLEN(ptr) ((ptr[0]<<8) | ptr[1]) 4154925bf6Swillf #define PRINCIPALNAME(ptr) (ptr + KEYHEADER + (NOOFKEYS(ptr) *8)) 4254925bf6Swillf 4354925bf6Swillf #define KEYBODY(ptr) PRINCIPALNAME(ptr) + PRINCIPALLEN(ptr) 4454925bf6Swillf 4554925bf6Swillf #define PKEYVER(ptr) ((ptr[2]<<8) | ptr[3]) 4654925bf6Swillf #define MKEYVER(ptr) ((ptr[4]<<8) | ptr[5]) 4754925bf6Swillf 4854925bf6Swillf #define KEYTYPE(ptr,j) ((ptr[KEYHEADER+(j*8)]<<8) | ptr[KEYHEADER+1+(j*8)]) 4954925bf6Swillf #define KEYLENGTH(ptr,j) ((ptr[KEYHEADER+2+(j*8)]<<8) | ptr[KEYHEADER+3+(j*8)]) 5054925bf6Swillf #define SALTTYPE(ptr,j) ((ptr[KEYHEADER+4+(j*8)]<<8) | ptr[KEYHEADER+5+(j*8)]) 5154925bf6Swillf #define SALTLENGTH(ptr,j) ((ptr[KEYHEADER+6+(j*8)]<<8) | ptr[KEYHEADER+7+(j*8)]) 5254925bf6Swillf 5354925bf6Swillf #define MAX_KEY_LENGTH 1024 5454925bf6Swillf #define CONTAINERDN_ARG "containerdn" 5554925bf6Swillf #define USERDN_ARG "dn" 5654925bf6Swillf #define TKTPOLICY_ARG "tktpolicy" 5754925bf6Swillf #define LINKDN_ARG "linkdn" 5854925bf6Swillf 5954925bf6Swillf /* #define FILTER "(&(objectclass=krbprincipalaux)(krbprincipalname=" */ 6054925bf6Swillf #define FILTER "(&(|(objectclass=krbprincipalaux)(objectclass=krbprincipal))(krbprincipalname=" 6154925bf6Swillf 6254925bf6Swillf #define KDB_USER_PRINCIPAL 0x01 6354925bf6Swillf #define KDB_SERVICE_PRINCIPAL 0x02 6454925bf6Swillf #define KDB_STANDALONE_PRINCIPAL_OBJECT 0x01 6554925bf6Swillf 6654925bf6Swillf /* these will be consumed only by krb5_ldap_delete_principal*/ 6754925bf6Swillf /* these will be set by krb5_ldap_get_principal and fed into the tl_data */ 6854925bf6Swillf 6954925bf6Swillf /* See also attributes_set[] in ldap_principal.c. */ 7054925bf6Swillf #define KDB_MAX_LIFE_ATTR 0x000001 7154925bf6Swillf #define KDB_MAX_RLIFE_ATTR 0x000002 7254925bf6Swillf #define KDB_TKT_FLAGS_ATTR 0x000004 7354925bf6Swillf #define KDB_PRINC_EXPIRE_TIME_ATTR 0x000008 7454925bf6Swillf #define KDB_POL_REF_ATTR 0x000010 7554925bf6Swillf #define KDB_UP_FLAG_ATTR 0x000020 7654925bf6Swillf #define KDB_PWD_POL_REF_ATTR 0x000040 7754925bf6Swillf #define KDB_PWD_EXPIRE_TIME_ATTR 0x000080 7854925bf6Swillf #define KDB_SECRET_KEY_ATTR 0x000100 7954925bf6Swillf #define KDB_LAST_PWD_CHANGE_ATTR 0x000200 8054925bf6Swillf #define KDB_EXTRA_DATA_ATTR 0x000400 8154925bf6Swillf #define KDB_LAST_SUCCESS_ATTR 0x000800 8254925bf6Swillf #define KDB_LAST_FAILED_ATTR 0x001000 8354925bf6Swillf #define KDB_FAIL_AUTH_COUNT_ATTR 0x002000 8454925bf6Swillf extern struct timeval timeout; 8554925bf6Swillf extern char *policyclass[]; 8654925bf6Swillf 8754925bf6Swillf krb5_error_code 8854925bf6Swillf krb5_ldap_put_principal(krb5_context, krb5_db_entry *, int *, char **); 8954925bf6Swillf 9054925bf6Swillf krb5_error_code 9154925bf6Swillf krb5_ldap_get_principal(krb5_context , krb5_const_principal , 9254925bf6Swillf krb5_db_entry *,int *, krb5_boolean *); 9354925bf6Swillf 9454925bf6Swillf krb5_error_code 9554925bf6Swillf krb5_ldap_delete_principal(krb5_context, krb5_const_principal, int *); 9654925bf6Swillf 9754925bf6Swillf krb5_error_code 9854925bf6Swillf krb5_ldap_free_principal(krb5_context, krb5_db_entry *, int ); 9954925bf6Swillf 100*2dd2efa5Swillf /* Solaris Kerberos: adding support for db_args */ 10154925bf6Swillf krb5_error_code 10254925bf6Swillf krb5_ldap_iterate(krb5_context, char *, krb5_error_code (*) (krb5_pointer, krb5_db_entry *), 103*2dd2efa5Swillf krb5_pointer/*, int */, char **); 10454925bf6Swillf 10554925bf6Swillf void 10654925bf6Swillf krb5_dbe_free_contents(krb5_context, krb5_db_entry *); 10754925bf6Swillf 10854925bf6Swillf krb5_error_code 10954925bf6Swillf krb5_ldap_unparse_principal_name(char *); 11054925bf6Swillf 11154925bf6Swillf krb5_error_code 11254925bf6Swillf krb5_ldap_parse_principal_name(char *, char **); 11354925bf6Swillf 11454925bf6Swillf krb5_error_code 11554925bf6Swillf krb5_decode_krbsecretkey(krb5_context, krb5_db_entry *, struct berval **); 11654925bf6Swillf 11754925bf6Swillf krb5_error_code 11854925bf6Swillf berval2tl_data(struct berval *in, krb5_tl_data **out); 11954925bf6Swillf 12054925bf6Swillf krb5_error_code 12154925bf6Swillf krb5_read_tkt_policy (krb5_context, krb5_ldap_context *, krb5_db_entry *, char *); 12254925bf6Swillf #endif 123