154925bfwillf/*
254925bfwillf * lib/kdb/kdb_ldap/ldap_principal.h
354925bfwillf *
454925bfwillf * Copyright (c) 2004-2005, Novell, Inc.
554925bfwillf * All rights reserved.
654925bfwillf *
754925bfwillf * Redistribution and use in source and binary forms, with or without
854925bfwillf * modification, are permitted provided that the following conditions are met:
954925bfwillf *
1054925bfwillf *   * Redistributions of source code must retain the above copyright notice,
1154925bfwillf *       this list of conditions and the following disclaimer.
1254925bfwillf *   * Redistributions in binary form must reproduce the above copyright
1354925bfwillf *       notice, this list of conditions and the following disclaimer in the
1454925bfwillf *       documentation and/or other materials provided with the distribution.
1554925bfwillf *   * The copyright holder's name is not used to endorse or promote products
1654925bfwillf *       derived from this software without specific prior written permission.
1754925bfwillf *
1854925bfwillf * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS"
1954925bfwillf * AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
2054925bfwillf * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
2154925bfwillf * ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS BE
2254925bfwillf * LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
2354925bfwillf * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
2454925bfwillf * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
2554925bfwillf * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
2654925bfwillf * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
2754925bfwillf * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
2854925bfwillf * POSSIBILITY OF SUCH DAMAGE.
2954925bfwillf */
3054925bfwillf
3154925bfwillf#ifndef _LDAP_PRINCIPAL_H
3254925bfwillf#define _LDAP_PRINCIPAL_H 1
3354925bfwillf
3454925bfwillf#pragma ident	"%Z%%M%	%I%	%E% SMI"
3554925bfwillf
3654925bfwillf#include "ldap_tkt_policy.h"
3754925bfwillf
3854925bfwillf#define  KEYHEADER  12
3954925bfwillf
4054925bfwillf#define  NOOFKEYS(ptr) 		((ptr[10]<<8) | ptr[11])
4154925bfwillf
4254925bfwillf#define  PRINCIPALLEN(ptr) 	((ptr[0]<<8) | ptr[1])
4354925bfwillf#define  PRINCIPALNAME(ptr) 	(ptr + KEYHEADER + (NOOFKEYS(ptr) *8))
4454925bfwillf
4554925bfwillf#define  KEYBODY(ptr)		PRINCIPALNAME(ptr) + PRINCIPALLEN(ptr)
4654925bfwillf
4754925bfwillf#define  PKEYVER(ptr) 		((ptr[2]<<8) | ptr[3])
4854925bfwillf#define  MKEYVER(ptr) 		((ptr[4]<<8) | ptr[5])
4954925bfwillf
5054925bfwillf#define  KEYTYPE(ptr,j) 	((ptr[KEYHEADER+(j*8)]<<8) | ptr[KEYHEADER+1+(j*8)])
5154925bfwillf#define  KEYLENGTH(ptr,j) 	((ptr[KEYHEADER+2+(j*8)]<<8) | ptr[KEYHEADER+3+(j*8)])
5254925bfwillf#define  SALTTYPE(ptr,j) 	((ptr[KEYHEADER+4+(j*8)]<<8) | ptr[KEYHEADER+5+(j*8)])
5354925bfwillf#define  SALTLENGTH(ptr,j) 	((ptr[KEYHEADER+6+(j*8)]<<8) | ptr[KEYHEADER+7+(j*8)])
5454925bfwillf
5554925bfwillf#define MAX_KEY_LENGTH         1024
5654925bfwillf#define CONTAINERDN_ARG        "containerdn"
5754925bfwillf#define USERDN_ARG             "dn"
5854925bfwillf#define TKTPOLICY_ARG          "tktpolicy"
5954925bfwillf#define LINKDN_ARG             "linkdn"
6054925bfwillf
6154925bfwillf/* #define FILTER   "(&(objectclass=krbprincipalaux)(krbprincipalname=" */
6254925bfwillf #define FILTER   "(&(|(objectclass=krbprincipalaux)(objectclass=krbprincipal))(krbprincipalname="
6354925bfwillf
6454925bfwillf#define  KDB_USER_PRINCIPAL    0x01
6554925bfwillf#define  KDB_SERVICE_PRINCIPAL 0x02
6654925bfwillf#define KDB_STANDALONE_PRINCIPAL_OBJECT 0x01
6754925bfwillf
6854925bfwillf/* these will be consumed only by krb5_ldap_delete_principal*/
6954925bfwillf/* these will be set by krb5_ldap_get_principal and fed into the tl_data */
7054925bfwillf
7154925bfwillf/* See also attributes_set[] in ldap_principal.c.  */
7254925bfwillf#define KDB_MAX_LIFE_ATTR                    0x000001
7354925bfwillf#define KDB_MAX_RLIFE_ATTR                   0x000002
7454925bfwillf#define KDB_TKT_FLAGS_ATTR                   0x000004
7554925bfwillf#define KDB_PRINC_EXPIRE_TIME_ATTR           0x000008
7654925bfwillf#define KDB_POL_REF_ATTR                     0x000010
7754925bfwillf#define KDB_UP_FLAG_ATTR                     0x000020
7854925bfwillf#define KDB_PWD_POL_REF_ATTR                 0x000040
7954925bfwillf#define KDB_PWD_EXPIRE_TIME_ATTR             0x000080
8054925bfwillf#define KDB_SECRET_KEY_ATTR                  0x000100
8154925bfwillf#define KDB_LAST_PWD_CHANGE_ATTR             0x000200
8254925bfwillf#define KDB_EXTRA_DATA_ATTR                  0x000400
8354925bfwillf#define KDB_LAST_SUCCESS_ATTR                0x000800
8454925bfwillf#define KDB_LAST_FAILED_ATTR                 0x001000
8554925bfwillf#define KDB_FAIL_AUTH_COUNT_ATTR             0x002000
8654925bfwillfextern struct timeval timeout;
8754925bfwillfextern char *policyclass[];
8854925bfwillf
8954925bfwillfkrb5_error_code
9054925bfwillfkrb5_ldap_put_principal(krb5_context, krb5_db_entry *, int *, char **);
9154925bfwillf
9254925bfwillfkrb5_error_code
93