154925bf6Swillf /*
254925bf6Swillf  * lib/kdb/kdb_ldap/ldap_principal.h
354925bf6Swillf  *
454925bf6Swillf  * Copyright (c) 2004-2005, Novell, Inc.
554925bf6Swillf  * All rights reserved.
654925bf6Swillf  *
754925bf6Swillf  * Redistribution and use in source and binary forms, with or without
854925bf6Swillf  * modification, are permitted provided that the following conditions are met:
954925bf6Swillf  *
1054925bf6Swillf  *   * Redistributions of source code must retain the above copyright notice,
1154925bf6Swillf  *       this list of conditions and the following disclaimer.
1254925bf6Swillf  *   * Redistributions in binary form must reproduce the above copyright
1354925bf6Swillf  *       notice, this list of conditions and the following disclaimer in the
1454925bf6Swillf  *       documentation and/or other materials provided with the distribution.
1554925bf6Swillf  *   * The copyright holder's name is not used to endorse or promote products
1654925bf6Swillf  *       derived from this software without specific prior written permission.
1754925bf6Swillf  *
1854925bf6Swillf  * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS"
1954925bf6Swillf  * AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
2054925bf6Swillf  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
2154925bf6Swillf  * ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS BE
2254925bf6Swillf  * LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
2354925bf6Swillf  * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
2454925bf6Swillf  * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
2554925bf6Swillf  * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
2654925bf6Swillf  * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
2754925bf6Swillf  * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
2854925bf6Swillf  * POSSIBILITY OF SUCH DAMAGE.
2954925bf6Swillf  */
3054925bf6Swillf 
3154925bf6Swillf #ifndef _LDAP_PRINCIPAL_H
3254925bf6Swillf #define _LDAP_PRINCIPAL_H 1
3354925bf6Swillf 
3454925bf6Swillf #include "ldap_tkt_policy.h"
3554925bf6Swillf 
3654925bf6Swillf #define  KEYHEADER  12
3754925bf6Swillf 
3854925bf6Swillf #define  NOOFKEYS(ptr) 		((ptr[10]<<8) | ptr[11])
3954925bf6Swillf 
4054925bf6Swillf #define  PRINCIPALLEN(ptr) 	((ptr[0]<<8) | ptr[1])
4154925bf6Swillf #define  PRINCIPALNAME(ptr) 	(ptr + KEYHEADER + (NOOFKEYS(ptr) *8))
4254925bf6Swillf 
4354925bf6Swillf #define  KEYBODY(ptr)		PRINCIPALNAME(ptr) + PRINCIPALLEN(ptr)
4454925bf6Swillf 
4554925bf6Swillf #define  PKEYVER(ptr) 		((ptr[2]<<8) | ptr[3])
4654925bf6Swillf #define  MKEYVER(ptr) 		((ptr[4]<<8) | ptr[5])
4754925bf6Swillf 
4854925bf6Swillf #define  KEYTYPE(ptr,j) 	((ptr[KEYHEADER+(j*8)]<<8) | ptr[KEYHEADER+1+(j*8)])
4954925bf6Swillf #define  KEYLENGTH(ptr,j) 	((ptr[KEYHEADER+2+(j*8)]<<8) | ptr[KEYHEADER+3+(j*8)])
5054925bf6Swillf #define  SALTTYPE(ptr,j) 	((ptr[KEYHEADER+4+(j*8)]<<8) | ptr[KEYHEADER+5+(j*8)])
5154925bf6Swillf #define  SALTLENGTH(ptr,j) 	((ptr[KEYHEADER+6+(j*8)]<<8) | ptr[KEYHEADER+7+(j*8)])
5254925bf6Swillf 
5354925bf6Swillf #define MAX_KEY_LENGTH         1024
5454925bf6Swillf #define CONTAINERDN_ARG        "containerdn"
5554925bf6Swillf #define USERDN_ARG             "dn"
5654925bf6Swillf #define TKTPOLICY_ARG          "tktpolicy"
5754925bf6Swillf #define LINKDN_ARG             "linkdn"
5854925bf6Swillf 
5954925bf6Swillf /* #define FILTER   "(&(objectclass=krbprincipalaux)(krbprincipalname=" */
6054925bf6Swillf  #define FILTER   "(&(|(objectclass=krbprincipalaux)(objectclass=krbprincipal))(krbprincipalname="
6154925bf6Swillf 
6254925bf6Swillf #define  KDB_USER_PRINCIPAL    0x01
6354925bf6Swillf #define  KDB_SERVICE_PRINCIPAL 0x02
6454925bf6Swillf #define KDB_STANDALONE_PRINCIPAL_OBJECT 0x01
6554925bf6Swillf 
6654925bf6Swillf /* these will be consumed only by krb5_ldap_delete_principal*/
6754925bf6Swillf /* these will be set by krb5_ldap_get_principal and fed into the tl_data */
6854925bf6Swillf 
6954925bf6Swillf /* See also attributes_set[] in ldap_principal.c.  */
7054925bf6Swillf #define KDB_MAX_LIFE_ATTR                    0x000001
7154925bf6Swillf #define KDB_MAX_RLIFE_ATTR                   0x000002
7254925bf6Swillf #define KDB_TKT_FLAGS_ATTR                   0x000004
7354925bf6Swillf #define KDB_PRINC_EXPIRE_TIME_ATTR           0x000008
7454925bf6Swillf #define KDB_POL_REF_ATTR                     0x000010
7554925bf6Swillf #define KDB_UP_FLAG_ATTR                     0x000020
7654925bf6Swillf #define KDB_PWD_POL_REF_ATTR                 0x000040
7754925bf6Swillf #define KDB_PWD_EXPIRE_TIME_ATTR             0x000080
7854925bf6Swillf #define KDB_SECRET_KEY_ATTR                  0x000100
7954925bf6Swillf #define KDB_LAST_PWD_CHANGE_ATTR             0x000200
8054925bf6Swillf #define KDB_EXTRA_DATA_ATTR                  0x000400
8154925bf6Swillf #define KDB_LAST_SUCCESS_ATTR                0x000800
8254925bf6Swillf #define KDB_LAST_FAILED_ATTR                 0x001000
8354925bf6Swillf #define KDB_FAIL_AUTH_COUNT_ATTR             0x002000
8454925bf6Swillf extern struct timeval timeout;
8554925bf6Swillf extern char *policyclass[];
8654925bf6Swillf 
8754925bf6Swillf krb5_error_code
8854925bf6Swillf krb5_ldap_put_principal(krb5_context, krb5_db_entry *, int *, char **);
8954925bf6Swillf 
9054925bf6Swillf krb5_error_code
9154925bf6Swillf krb5_ldap_get_principal(krb5_context , krb5_const_principal ,
9254925bf6Swillf                         krb5_db_entry *,int *, krb5_boolean *);
9354925bf6Swillf 
9454925bf6Swillf krb5_error_code
9554925bf6Swillf krb5_ldap_delete_principal(krb5_context, krb5_const_principal, int *);
9654925bf6Swillf 
9754925bf6Swillf krb5_error_code
9854925bf6Swillf krb5_ldap_free_principal(krb5_context, krb5_db_entry *, int );
9954925bf6Swillf 
100*2dd2efa5Swillf /* Solaris Kerberos: adding support for db_args */
10154925bf6Swillf krb5_error_code
10254925bf6Swillf krb5_ldap_iterate(krb5_context, char *, krb5_error_code (*) (krb5_pointer, krb5_db_entry *),
103*2dd2efa5Swillf                   krb5_pointer/*, int */, char **);
10454925bf6Swillf 
10554925bf6Swillf void
10654925bf6Swillf krb5_dbe_free_contents(krb5_context, krb5_db_entry *);
10754925bf6Swillf 
10854925bf6Swillf krb5_error_code
10954925bf6Swillf krb5_ldap_unparse_principal_name(char *);
11054925bf6Swillf 
11154925bf6Swillf krb5_error_code
11254925bf6Swillf krb5_ldap_parse_principal_name(char *, char **);
11354925bf6Swillf 
11454925bf6Swillf krb5_error_code
11554925bf6Swillf krb5_decode_krbsecretkey(krb5_context, krb5_db_entry *, struct berval **);
11654925bf6Swillf 
11754925bf6Swillf krb5_error_code
11854925bf6Swillf berval2tl_data(struct berval *in, krb5_tl_data **out);
11954925bf6Swillf 
12054925bf6Swillf krb5_error_code
12154925bf6Swillf krb5_read_tkt_policy (krb5_context, krb5_ldap_context *, krb5_db_entry *, char *);
12254925bf6Swillf #endif
123