xref: /illumos-gate/usr/src/cmd/gss/gssd/gssdtest.c (revision 0ab8aa70)
17c478bd9Sstevel@tonic-gate /*
27c478bd9Sstevel@tonic-gate  * CDDL HEADER START
37c478bd9Sstevel@tonic-gate  *
47c478bd9Sstevel@tonic-gate  * The contents of this file are subject to the terms of the
57c478bd9Sstevel@tonic-gate  * Common Development and Distribution License, Version 1.0 only
67c478bd9Sstevel@tonic-gate  * (the "License").  You may not use this file except in compliance
77c478bd9Sstevel@tonic-gate  * with the License.
87c478bd9Sstevel@tonic-gate  *
97c478bd9Sstevel@tonic-gate  * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
107c478bd9Sstevel@tonic-gate  * or http://www.opensolaris.org/os/licensing.
117c478bd9Sstevel@tonic-gate  * See the License for the specific language governing permissions
127c478bd9Sstevel@tonic-gate  * and limitations under the License.
137c478bd9Sstevel@tonic-gate  *
147c478bd9Sstevel@tonic-gate  * When distributing Covered Code, include this CDDL HEADER in each
157c478bd9Sstevel@tonic-gate  * file and include the License file at usr/src/OPENSOLARIS.LICENSE.
167c478bd9Sstevel@tonic-gate  * If applicable, add the following below this CDDL HEADER, with the
177c478bd9Sstevel@tonic-gate  * fields enclosed by brackets "[]" replaced with your own identifying
187c478bd9Sstevel@tonic-gate  * information: Portions Copyright [yyyy] [name of copyright owner]
197c478bd9Sstevel@tonic-gate  *
207c478bd9Sstevel@tonic-gate  * CDDL HEADER END
217c478bd9Sstevel@tonic-gate  */
227c478bd9Sstevel@tonic-gate /*
23d7c57852SGary Mills  * Copyright 2017 Gary Mills
247c478bd9Sstevel@tonic-gate  * Copyright 2003 Sun Microsystems, Inc.  All rights reserved.
257c478bd9Sstevel@tonic-gate  * Use is subject to license terms.
267c478bd9Sstevel@tonic-gate  */
277c478bd9Sstevel@tonic-gate 
287c478bd9Sstevel@tonic-gate /*
297c478bd9Sstevel@tonic-gate  * Test client for gssd.  This program is not shipped on the binary
307c478bd9Sstevel@tonic-gate  * release.
317c478bd9Sstevel@tonic-gate  */
327c478bd9Sstevel@tonic-gate 
337c478bd9Sstevel@tonic-gate #include <stdio.h>
347c478bd9Sstevel@tonic-gate #include <strings.h>
357c478bd9Sstevel@tonic-gate #include <ctype.h>
367c478bd9Sstevel@tonic-gate #include <stdlib.h>
377c478bd9Sstevel@tonic-gate #include <gssapi/gssapi.h>
387c478bd9Sstevel@tonic-gate #include <gssapi/gssapi_ext.h>
397c478bd9Sstevel@tonic-gate #include "gssd.h"
407c478bd9Sstevel@tonic-gate #include <rpc/rpc.h>
417c478bd9Sstevel@tonic-gate 
427c478bd9Sstevel@tonic-gate #define	_KERNEL
437c478bd9Sstevel@tonic-gate #include <gssapi/gssapi.h>
447c478bd9Sstevel@tonic-gate #undef	_KERNEL
457c478bd9Sstevel@tonic-gate 
467c478bd9Sstevel@tonic-gate int gss_major_code;
477c478bd9Sstevel@tonic-gate int gss_minor_code;
487c478bd9Sstevel@tonic-gate 
497c478bd9Sstevel@tonic-gate int init_sec_context_phase = 0;
507c478bd9Sstevel@tonic-gate int accept_sec_context_phase = 0;
517c478bd9Sstevel@tonic-gate 
527c478bd9Sstevel@tonic-gate gss_ctx_id_t    initiator_context_handle;
537c478bd9Sstevel@tonic-gate gss_ctx_id_t    acceptor_context_handle;
547c478bd9Sstevel@tonic-gate gss_cred_id_t   acceptor_credentials;
557c478bd9Sstevel@tonic-gate gss_buffer_desc init_token_buffer;
567c478bd9Sstevel@tonic-gate gss_buffer_desc accept_token_buffer;
577c478bd9Sstevel@tonic-gate gss_buffer_desc delete_token_buffer;
587c478bd9Sstevel@tonic-gate gss_buffer_desc message_buffer;
597c478bd9Sstevel@tonic-gate gss_buffer_desc msg_token;
607c478bd9Sstevel@tonic-gate 
617c478bd9Sstevel@tonic-gate #define	LOOP_COUNTER  100
627c478bd9Sstevel@tonic-gate #define	GSS_KRB5_MECH_OID "1.2.840.113554.1.2.2"
637c478bd9Sstevel@tonic-gate #define	GSS_DUMMY_MECH_OID "1.3.6.1.4.1.42.2.26.1.2"
647c478bd9Sstevel@tonic-gate #ifdef _KERNEL
657c478bd9Sstevel@tonic-gate #define	OCTAL_MACRO "%03o."
667c478bd9Sstevel@tonic-gate #define	MALLOC(n) kmem_alloc((n), KM_SLEEP)
677c478bd9Sstevel@tonic-gate #define	CALLOC(n, s) kmem_zalloc((n)*(s), KM_SLEEP)
687c478bd9Sstevel@tonic-gate #define	FREE(x, n) kmem_free((x), (n))
697c478bd9Sstevel@tonic-gate #define	memcpy(dst, src, n) bcopy((src), (dst), (n))
707c478bd9Sstevel@tonic-gate #define	fprintf(s, m) printf(m)
717c478bd9Sstevel@tonic-gate #define	isspace(s) ((s) == ' ' || (s) == '\t' || (s) == '\n' || \
727c478bd9Sstevel@tonic-gate 		(s) == '\r' || (s) == '\v' || (s) == '\f')
737c478bd9Sstevel@tonic-gate 
strdup(const char * s)747c478bd9Sstevel@tonic-gate static char *strdup(const char *s)
757c478bd9Sstevel@tonic-gate {
767c478bd9Sstevel@tonic-gate 	int len = strlen(s);
777c478bd9Sstevel@tonic-gate 	char *new = MALLOC(len+1);
787c478bd9Sstevel@tonic-gate 	strcpy(new, s);
797c478bd9Sstevel@tonic-gate 	return (new);
807c478bd9Sstevel@tonic-gate }
817c478bd9Sstevel@tonic-gate 
827c478bd9Sstevel@tonic-gate #else /* !_KERNEL */
837c478bd9Sstevel@tonic-gate #define	OCTAL_MACRO "%03.3o."
847c478bd9Sstevel@tonic-gate #define	MALLOC(n) malloc(n)
857c478bd9Sstevel@tonic-gate #define	CALLOC(n, s) calloc((n), (s))
867c478bd9Sstevel@tonic-gate #define	FREE(x, n) free(x)
877c478bd9Sstevel@tonic-gate #endif /* _KERNEL */
887c478bd9Sstevel@tonic-gate 
897c478bd9Sstevel@tonic-gate static gss_OID gss_str2oid(char *);
907c478bd9Sstevel@tonic-gate static char * gss_oid2str(gss_OID);
917c478bd9Sstevel@tonic-gate static void instructs();
927c478bd9Sstevel@tonic-gate static void usage();
937c478bd9Sstevel@tonic-gate static int parse_input_line(char *, int *, char ***);
947c478bd9Sstevel@tonic-gate extern uid_t getuid();
957c478bd9Sstevel@tonic-gate 
967c478bd9Sstevel@tonic-gate static void _gss_init_sec_context(int, char **);
977c478bd9Sstevel@tonic-gate static void _gss_acquire_cred(int, char **);
987c478bd9Sstevel@tonic-gate static void _gss_add_cred(int, char **);
997c478bd9Sstevel@tonic-gate static void _gss_sign(int, char **);
1007c478bd9Sstevel@tonic-gate static void _gss_release_cred(int, char **);
1017c478bd9Sstevel@tonic-gate static void _gss_accept_sec_context(int, char **);
1027c478bd9Sstevel@tonic-gate static void _gss_process_context_token(int, char **);
1037c478bd9Sstevel@tonic-gate static void _gss_delete_sec_context(int, char **);
1047c478bd9Sstevel@tonic-gate static void _gss_context_time(int, char **);
1057c478bd9Sstevel@tonic-gate static void _gss_verify(int, char **);
1067c478bd9Sstevel@tonic-gate static void _gss_seal(int, char **);
1077c478bd9Sstevel@tonic-gate static void _gss_unseal(int, char **);
1087c478bd9Sstevel@tonic-gate static void _gss_display_status(int, char **);
1097c478bd9Sstevel@tonic-gate static void _gss_indicate_mechs(int, char **);
1107c478bd9Sstevel@tonic-gate static void _gss_inquire_cred(int, char **);
1117c478bd9Sstevel@tonic-gate static void _gssd_expname_to_unix_cred(int, char **);
1127c478bd9Sstevel@tonic-gate static void _gssd_name_to_unix_cred(int, char **);
1137c478bd9Sstevel@tonic-gate static void _gssd_get_group_info(int, char **);
1147c478bd9Sstevel@tonic-gate 
1157c478bd9Sstevel@tonic-gate static int do_gssdtest(char *buf);
1167c478bd9Sstevel@tonic-gate 
1177c478bd9Sstevel@tonic-gate 
1187c478bd9Sstevel@tonic-gate #ifndef _KERNEL
read_line(char * buf,int size)1197c478bd9Sstevel@tonic-gate static int read_line(char *buf, int size)
1207c478bd9Sstevel@tonic-gate {
1217c478bd9Sstevel@tonic-gate 	int len;
1227c478bd9Sstevel@tonic-gate 
1237c478bd9Sstevel@tonic-gate 	/* read the next line. If cntl-d, return with zero char count */
1247c478bd9Sstevel@tonic-gate 	printf(gettext("\n> "));
1257c478bd9Sstevel@tonic-gate 
1267c478bd9Sstevel@tonic-gate 	if (fgets(buf, size, stdin) == NULL)
1277c478bd9Sstevel@tonic-gate 		return (0);
1287c478bd9Sstevel@tonic-gate 
1297c478bd9Sstevel@tonic-gate 	len = strlen(buf);
1307c478bd9Sstevel@tonic-gate 	buf[--len] = '\0';
1317c478bd9Sstevel@tonic-gate 	return (len);
1327c478bd9Sstevel@tonic-gate }
1337c478bd9Sstevel@tonic-gate 
1347c478bd9Sstevel@tonic-gate int
main()1357c478bd9Sstevel@tonic-gate main()
1367c478bd9Sstevel@tonic-gate {
1377c478bd9Sstevel@tonic-gate 	char buf[512];
1387c478bd9Sstevel@tonic-gate 	int len, ret;
1397c478bd9Sstevel@tonic-gate 
1407c478bd9Sstevel@tonic-gate 	/* Print out usage and instructions to start off the session */
1417c478bd9Sstevel@tonic-gate 
1427c478bd9Sstevel@tonic-gate 	instructs();
1437c478bd9Sstevel@tonic-gate 	usage();
1447c478bd9Sstevel@tonic-gate 
1457c478bd9Sstevel@tonic-gate 	/*
1467c478bd9Sstevel@tonic-gate 	 * Loop, repeatedly calling parse_input_line() to get the
1477c478bd9Sstevel@tonic-gate 	 * next line and parse it into argc and argv. Act on the
1487c478bd9Sstevel@tonic-gate 	 * arguements found on the line.
1497c478bd9Sstevel@tonic-gate 	 */
1507c478bd9Sstevel@tonic-gate 
1517c478bd9Sstevel@tonic-gate 	do {
1527c478bd9Sstevel@tonic-gate 		len = read_line(buf, 512);
1537c478bd9Sstevel@tonic-gate 		if (len)
1547c478bd9Sstevel@tonic-gate 			ret = do_gssdtest(buf);
1557c478bd9Sstevel@tonic-gate 	} while (len && !ret);
1567c478bd9Sstevel@tonic-gate 
1577c478bd9Sstevel@tonic-gate 	return (0);
1587c478bd9Sstevel@tonic-gate }
1597c478bd9Sstevel@tonic-gate #endif /* !_KERNEL */
1607c478bd9Sstevel@tonic-gate 
1617c478bd9Sstevel@tonic-gate static int
do_gssdtest(char * buf)1627c478bd9Sstevel@tonic-gate do_gssdtest(char *buf)
1637c478bd9Sstevel@tonic-gate {
1647c478bd9Sstevel@tonic-gate 	int argc, seal_argc;
1657c478bd9Sstevel@tonic-gate 	int i;
1667c478bd9Sstevel@tonic-gate 	char **argv, **argv_array;
1677c478bd9Sstevel@tonic-gate 
1687c478bd9Sstevel@tonic-gate 	char *cmd;
1697c478bd9Sstevel@tonic-gate 	char *seal_ini_array [] = { "initiator", " Hello"};
1707c478bd9Sstevel@tonic-gate 	char *seal_acc_array [] = { "acceptor", " Hello"};
1717c478bd9Sstevel@tonic-gate 	char *unseal_acc_array [] = {"acceptor"};
1727c478bd9Sstevel@tonic-gate 	char *unseal_ini_array [] = {"initiator"};
1737c478bd9Sstevel@tonic-gate 	char *delet_acc_array [] = {"acceptor"};
1747c478bd9Sstevel@tonic-gate 	char *delet_ini_array [] = {"initiator"};
1757c478bd9Sstevel@tonic-gate 
1767c478bd9Sstevel@tonic-gate 	argv = 0;
1777c478bd9Sstevel@tonic-gate 
1787c478bd9Sstevel@tonic-gate 	if (parse_input_line(buf, &argc, &argv) == 0) {
1797c478bd9Sstevel@tonic-gate 		printf(gettext("\n"));
1807c478bd9Sstevel@tonic-gate 		return (1);
1817c478bd9Sstevel@tonic-gate 	}
1827c478bd9Sstevel@tonic-gate 
1837c478bd9Sstevel@tonic-gate 	if (argc == 0) {
1847c478bd9Sstevel@tonic-gate 		usage();
1857c478bd9Sstevel@tonic-gate 		/*LINTED*/
1867c478bd9Sstevel@tonic-gate 		FREE(argv_array, (argc+1)*sizeof (char *));
1877c478bd9Sstevel@tonic-gate 		return (0);
1887c478bd9Sstevel@tonic-gate 	}
1897c478bd9Sstevel@tonic-gate 
1907c478bd9Sstevel@tonic-gate 	/*
1917c478bd9Sstevel@tonic-gate 	 * remember argv_array address, which is memory calloc'd by
1927c478bd9Sstevel@tonic-gate 	 * parse_input_line, so it can be free'd at the end of the loop.
1937c478bd9Sstevel@tonic-gate 	 */
1947c478bd9Sstevel@tonic-gate 
1957c478bd9Sstevel@tonic-gate 	argv_array = argv;
1967c478bd9Sstevel@tonic-gate 
1977c478bd9Sstevel@tonic-gate 	cmd = argv[0];
1987c478bd9Sstevel@tonic-gate 
1997c478bd9Sstevel@tonic-gate 	argc--;
2007c478bd9Sstevel@tonic-gate 	argv++;
2017c478bd9Sstevel@tonic-gate 
2027c478bd9Sstevel@tonic-gate 	if (strcmp(cmd, "gss_loop") == 0 ||
2037c478bd9Sstevel@tonic-gate 	    strcmp(cmd, "loop") == 0) {
2047c478bd9Sstevel@tonic-gate 
2057c478bd9Sstevel@tonic-gate 		if (argc < 1) {
2067c478bd9Sstevel@tonic-gate 			usage();
2077c478bd9Sstevel@tonic-gate 			FREE(argv_array, (argc+2) * sizeof (char *));
2087c478bd9Sstevel@tonic-gate 			return (0);
2097c478bd9Sstevel@tonic-gate 		}
2107c478bd9Sstevel@tonic-gate 		for (i = 0; i < LOOP_COUNTER; i++) {
2117c478bd9Sstevel@tonic-gate 			printf(gettext("Loop Count is %d \n"), i);
2127c478bd9Sstevel@tonic-gate 			/*
2137c478bd9Sstevel@tonic-gate 			 * if (i > 53)
214*0ab8aa70SToomas Soome 			 *	printf ("Loop counter is greater than 55\n");
2157c478bd9Sstevel@tonic-gate 			 */
2167c478bd9Sstevel@tonic-gate 			_gss_acquire_cred(argc, argv);
2177c478bd9Sstevel@tonic-gate 			_gss_init_sec_context(argc, argv);
2187c478bd9Sstevel@tonic-gate 			_gss_accept_sec_context(0, argv);
2197c478bd9Sstevel@tonic-gate 			_gss_init_sec_context(argc, argv);
220694c35faSJosef 'Jeff' Sipek 
2217c478bd9Sstevel@tonic-gate 			seal_argc = 2;
2227c478bd9Sstevel@tonic-gate 			_gss_seal(seal_argc, seal_ini_array);
2237c478bd9Sstevel@tonic-gate 			seal_argc = 1;
2247c478bd9Sstevel@tonic-gate 			_gss_unseal(seal_argc, unseal_acc_array);
2257c478bd9Sstevel@tonic-gate 			seal_argc = 2;
2267c478bd9Sstevel@tonic-gate 			_gss_seal(seal_argc, seal_acc_array);
2277c478bd9Sstevel@tonic-gate 			seal_argc = 1;
2287c478bd9Sstevel@tonic-gate 			_gss_unseal(seal_argc, unseal_ini_array);
2297c478bd9Sstevel@tonic-gate 			seal_argc = 2;
2307c478bd9Sstevel@tonic-gate 			_gss_sign(seal_argc, seal_ini_array);
2317c478bd9Sstevel@tonic-gate 			seal_argc = 1;
2327c478bd9Sstevel@tonic-gate 			_gss_verify(seal_argc, unseal_acc_array);
2337c478bd9Sstevel@tonic-gate 			seal_argc = 2;
2347c478bd9Sstevel@tonic-gate 			_gss_sign(seal_argc, seal_acc_array);
2357c478bd9Sstevel@tonic-gate 			seal_argc = 1;
2367c478bd9Sstevel@tonic-gate 			_gss_verify(seal_argc, unseal_ini_array);
2377c478bd9Sstevel@tonic-gate 			_gss_delete_sec_context(argc, delet_acc_array);
2387c478bd9Sstevel@tonic-gate 			_gss_delete_sec_context(argc, delet_ini_array);
2397c478bd9Sstevel@tonic-gate 		}
2407c478bd9Sstevel@tonic-gate 	}
2417c478bd9Sstevel@tonic-gate 	if (strcmp(cmd, "gss_all") == 0 ||
2427c478bd9Sstevel@tonic-gate 	    strcmp(cmd, "all") == 0) {
2437c478bd9Sstevel@tonic-gate 		_gss_acquire_cred(argc, argv);
2447c478bd9Sstevel@tonic-gate 		_gss_init_sec_context(argc, argv);
2457c478bd9Sstevel@tonic-gate 		_gss_accept_sec_context(0, argv);
2467c478bd9Sstevel@tonic-gate 		_gss_init_sec_context(argc, argv);
247694c35faSJosef 'Jeff' Sipek 
2487c478bd9Sstevel@tonic-gate 		seal_argc = 2;
2497c478bd9Sstevel@tonic-gate 		_gss_seal(seal_argc, seal_acc_array);
2507c478bd9Sstevel@tonic-gate 		seal_argc = 1;
2517c478bd9Sstevel@tonic-gate 		_gss_unseal(seal_argc, unseal_ini_array);
2527c478bd9Sstevel@tonic-gate 		seal_argc = 2;
2537c478bd9Sstevel@tonic-gate 		_gss_seal(seal_argc, seal_ini_array);
2547c478bd9Sstevel@tonic-gate 		seal_argc = 1;
2557c478bd9Sstevel@tonic-gate 		_gss_unseal(seal_argc, unseal_acc_array);
2567c478bd9Sstevel@tonic-gate 		seal_argc = 2;
2577c478bd9Sstevel@tonic-gate 		_gss_sign(seal_argc, seal_ini_array);
2587c478bd9Sstevel@tonic-gate 		seal_argc = 1;
2597c478bd9Sstevel@tonic-gate 		_gss_verify(seal_argc, unseal_acc_array);
2607c478bd9Sstevel@tonic-gate 		seal_argc = 2;
2617c478bd9Sstevel@tonic-gate 		_gss_sign(seal_argc, seal_acc_array);
2627c478bd9Sstevel@tonic-gate 		seal_argc = 1;
2637c478bd9Sstevel@tonic-gate 		_gss_verify(seal_argc, unseal_ini_array);
2647c478bd9Sstevel@tonic-gate 
2657c478bd9Sstevel@tonic-gate 	}
2667c478bd9Sstevel@tonic-gate 	if (strcmp(cmd, "gss_acquire_cred") == 0 ||
2677c478bd9Sstevel@tonic-gate 	    strcmp(cmd, "acquire") == 0) {
2687c478bd9Sstevel@tonic-gate 		_gss_acquire_cred(argc, argv);
2697c478bd9Sstevel@tonic-gate 		if (argc == 1)
2707c478bd9Sstevel@tonic-gate 			_gss_add_cred(argc, argv);
2717c478bd9Sstevel@tonic-gate 	}
2727c478bd9Sstevel@tonic-gate 
2737c478bd9Sstevel@tonic-gate 	else if (strcmp(cmd, "gss_release_cred") == 0 ||
2747c478bd9Sstevel@tonic-gate 		strcmp(cmd, "release") == 0)
2757c478bd9Sstevel@tonic-gate 		_gss_release_cred(argc, argv);
2767c478bd9Sstevel@tonic-gate 	else if (strcmp(cmd, "gss_init_sec_context") == 0 ||
2777c478bd9Sstevel@tonic-gate 		strcmp(cmd, "init") == 0)
2787c478bd9Sstevel@tonic-gate 		_gss_init_sec_context(argc, argv);
2797c478bd9Sstevel@tonic-gate 	else if (strcmp(cmd, "gss_accept_sec_context") == 0 ||
2807c478bd9Sstevel@tonic-gate 		strcmp(cmd, "accept") == 0)
2817c478bd9Sstevel@tonic-gate 		_gss_accept_sec_context(argc, argv);
2827c478bd9Sstevel@tonic-gate 	else if (strcmp(cmd, "gss_process_context_token") == 0 ||
2837c478bd9Sstevel@tonic-gate 		strcmp(cmd, "process") == 0)
2847c478bd9Sstevel@tonic-gate 		_gss_process_context_token(argc, argv);
2857c478bd9Sstevel@tonic-gate 	else if (strcmp(cmd, "gss_delete_sec_context") == 0 ||
2867c478bd9Sstevel@tonic-gate 		strcmp(cmd, "delete") == 0)
2877c478bd9Sstevel@tonic-gate 		_gss_delete_sec_context(argc, argv);
2887c478bd9Sstevel@tonic-gate 	else if (strcmp(cmd, "gss_context_time") == 0 ||
2897c478bd9Sstevel@tonic-gate 		strcmp(cmd, "time") == 0)
2907c478bd9Sstevel@tonic-gate 		_gss_context_time(argc, argv);
2917c478bd9Sstevel@tonic-gate 	else if (strcmp(cmd, "gss_sign") == 0 ||
2927c478bd9Sstevel@tonic-gate 		strcmp(cmd, "sign") == 0)
2937c478bd9Sstevel@tonic-gate 		_gss_sign(argc, argv);
2947c478bd9Sstevel@tonic-gate 	else if (strcmp(cmd, "gss_verify") == 0 ||
2957c478bd9Sstevel@tonic-gate 		strcmp(cmd, "verify") == 0)
2967c478bd9Sstevel@tonic-gate 		_gss_verify(argc, argv);
2977c478bd9Sstevel@tonic-gate 	else if (strcmp(cmd, "gss_seal") == 0 ||
2987c478bd9Sstevel@tonic-gate 		strcmp(cmd, "seal") == 0)
2997c478bd9Sstevel@tonic-gate 		_gss_seal(argc, argv);
3007c478bd9Sstevel@tonic-gate 	else if (strcmp(cmd, "gss_unseal") == 0 ||
3017c478bd9Sstevel@tonic-gate 		strcmp(cmd, "unseal") == 0)
3027c478bd9Sstevel@tonic-gate 		_gss_unseal(argc, argv);
3037c478bd9Sstevel@tonic-gate 	else if (strcmp(cmd, "gss_display_status") == 0||
3047c478bd9Sstevel@tonic-gate 		strcmp(cmd, "status") == 0)
3057c478bd9Sstevel@tonic-gate 		_gss_display_status(argc, argv);
3067c478bd9Sstevel@tonic-gate 	else if (strcmp(cmd, "gss_indicate_mechs") == 0 ||
3077c478bd9Sstevel@tonic-gate 		strcmp(cmd, "indicate") == 0)
3087c478bd9Sstevel@tonic-gate 		_gss_indicate_mechs(argc, argv);
3097c478bd9Sstevel@tonic-gate 	else if (strcmp(cmd, "gss_inquire_cred") == 0 ||
3107c478bd9Sstevel@tonic-gate 		strcmp(cmd, "inquire") == 0)
3117c478bd9Sstevel@tonic-gate 		_gss_inquire_cred(argc, argv);
3127c478bd9Sstevel@tonic-gate 	else if (strcmp(cmd, "expname2unixcred") == 0 ||
3137c478bd9Sstevel@tonic-gate 		strcmp(cmd, "gsscred_expname_to_unix_cred") == 0)
3147c478bd9Sstevel@tonic-gate 		_gssd_expname_to_unix_cred(argc, argv);
3157c478bd9Sstevel@tonic-gate 	else if (strcmp(cmd, "name2unixcred") == 0 ||
3167c478bd9Sstevel@tonic-gate 		strcmp(cmd, "gsscred_name_to_unix_cred") == 0)
3177c478bd9Sstevel@tonic-gate 		_gssd_name_to_unix_cred(argc, argv);
3187c478bd9Sstevel@tonic-gate 	else if (strcmp(cmd, "grpinfo") == 0 ||
3197c478bd9Sstevel@tonic-gate 		strcmp(cmd, "gss_get_group_info") == 0)
3207c478bd9Sstevel@tonic-gate 		_gssd_get_group_info(argc, argv);
3217c478bd9Sstevel@tonic-gate 	else if (strcmp(cmd, "exit") == 0) {
3227c478bd9Sstevel@tonic-gate 		printf(gettext("\n"));
3237c478bd9Sstevel@tonic-gate 		FREE(argv_array, (argc+2) * sizeof (char *));
3247c478bd9Sstevel@tonic-gate 		return (1);
3257c478bd9Sstevel@tonic-gate 	} else
3267c478bd9Sstevel@tonic-gate 		usage();
3277c478bd9Sstevel@tonic-gate 
3287c478bd9Sstevel@tonic-gate 	/* free argv array */
3297c478bd9Sstevel@tonic-gate 
3307c478bd9Sstevel@tonic-gate 	FREE(argv_array, (argc+2) * sizeof (char *));
3317c478bd9Sstevel@tonic-gate 	return (0);
3327c478bd9Sstevel@tonic-gate }
3337c478bd9Sstevel@tonic-gate 
3347c478bd9Sstevel@tonic-gate static void
_gss_acquire_cred(argc,argv)3357c478bd9Sstevel@tonic-gate _gss_acquire_cred(argc, argv)
3367c478bd9Sstevel@tonic-gate int argc;
3377c478bd9Sstevel@tonic-gate char **argv;
3387c478bd9Sstevel@tonic-gate {
3397c478bd9Sstevel@tonic-gate 
3407c478bd9Sstevel@tonic-gate 	OM_UINT32 status, minor_status;
3417c478bd9Sstevel@tonic-gate 	gss_buffer_desc name;
3427c478bd9Sstevel@tonic-gate 	gss_name_t desired_name = (gss_name_t) 0;
3437c478bd9Sstevel@tonic-gate 	OM_uint32 time_req;
3447c478bd9Sstevel@tonic-gate 	gss_OID_set_desc desired_mechs_desc;
3457c478bd9Sstevel@tonic-gate 	gss_OID_set desired_mechs = &desired_mechs_desc;
3467c478bd9Sstevel@tonic-gate 	int cred_usage;
3477c478bd9Sstevel@tonic-gate 	gss_OID_set actual_mechs = GSS_C_NULL_OID_SET;
3487c478bd9Sstevel@tonic-gate 	gss_OID_set inquire_mechs = GSS_C_NULL_OID_SET;
3497c478bd9Sstevel@tonic-gate 	OM_UINT32 time_rec;
3507c478bd9Sstevel@tonic-gate 	char * string;
3517c478bd9Sstevel@tonic-gate 	char * inq_string;
3527c478bd9Sstevel@tonic-gate 	uid_t uid;
3537c478bd9Sstevel@tonic-gate 	gss_OID mech_type;
3547c478bd9Sstevel@tonic-gate 
3557c478bd9Sstevel@tonic-gate 	/*
3567c478bd9Sstevel@tonic-gate 	 * First set up the command line independent input arguments.
3577c478bd9Sstevel@tonic-gate 	 */
3587c478bd9Sstevel@tonic-gate 
3597c478bd9Sstevel@tonic-gate 	time_req = (OM_uint32) 0;
3607c478bd9Sstevel@tonic-gate 	cred_usage = GSS_C_ACCEPT;
3617c478bd9Sstevel@tonic-gate 	uid = getuid();
3627c478bd9Sstevel@tonic-gate 
3637c478bd9Sstevel@tonic-gate 	/* Parse the command line for the variable input arguments */
3647c478bd9Sstevel@tonic-gate 
3657c478bd9Sstevel@tonic-gate 	if (argc == 0) {
3667c478bd9Sstevel@tonic-gate 		usage();
3677c478bd9Sstevel@tonic-gate 		return;
3687c478bd9Sstevel@tonic-gate 	}
3697c478bd9Sstevel@tonic-gate 
3707c478bd9Sstevel@tonic-gate 	/*
3717c478bd9Sstevel@tonic-gate 	 * Get the name of the principal.
3727c478bd9Sstevel@tonic-gate 	 */
3737c478bd9Sstevel@tonic-gate 
3747c478bd9Sstevel@tonic-gate 	name.length = strlen(argv[0])+1;
3757c478bd9Sstevel@tonic-gate 	name.value = argv[0];
3767c478bd9Sstevel@tonic-gate 
3777c478bd9Sstevel@tonic-gate 	/*
3787c478bd9Sstevel@tonic-gate 	 * Now convert the string given by the first argument into internal
3797c478bd9Sstevel@tonic-gate 	 * form suitable for input to gss_acquire_cred()
3807c478bd9Sstevel@tonic-gate 	 */
3817c478bd9Sstevel@tonic-gate 
3827c478bd9Sstevel@tonic-gate 	if ((status = gss_import_name(&minor_status, &name,
3837c478bd9Sstevel@tonic-gate 		(gss_OID)GSS_C_NT_HOSTBASED_SERVICE, &desired_name))
3847c478bd9Sstevel@tonic-gate 		!= GSS_S_COMPLETE) {
3857c478bd9Sstevel@tonic-gate 		printf(gettext(
3867c478bd9Sstevel@tonic-gate 			"could not parse desired name: err (octal) %o (%s)\n"),
3877c478bd9Sstevel@tonic-gate 			status, gettext("gss_acquire_cred error"));
3887c478bd9Sstevel@tonic-gate 		return;
3897c478bd9Sstevel@tonic-gate 	}
3907c478bd9Sstevel@tonic-gate 
3917c478bd9Sstevel@tonic-gate 	argc--;
3927c478bd9Sstevel@tonic-gate 	argv++;
3937c478bd9Sstevel@tonic-gate 
3947c478bd9Sstevel@tonic-gate 	/*
3957c478bd9Sstevel@tonic-gate 	 * The next argument is an OID in dotted decimal form.
3967c478bd9Sstevel@tonic-gate 	 */
3977c478bd9Sstevel@tonic-gate 
3987c478bd9Sstevel@tonic-gate 	if (argc == 0) {
3997c478bd9Sstevel@tonic-gate 		printf(gettext("Assuming Kerberos V5 as the mechanism\n"));
4007c478bd9Sstevel@tonic-gate 		printf(gettext(
4017c478bd9Sstevel@tonic-gate 			"The mech OID 1.2.840.113554.1.2.2 will be used\n"));
4027c478bd9Sstevel@tonic-gate 		mech_type = gss_str2oid((char *)GSS_KRB5_MECH_OID);
4037c478bd9Sstevel@tonic-gate 	} else
4047c478bd9Sstevel@tonic-gate 		mech_type = gss_str2oid(argv[0]);
4057c478bd9Sstevel@tonic-gate 
4067c478bd9Sstevel@tonic-gate 	if (mech_type == 0 || mech_type->length == 0) {
4077c478bd9Sstevel@tonic-gate 		printf(gettext("improperly formated mechanism OID\n"));
4087c478bd9Sstevel@tonic-gate 		return;
4097c478bd9Sstevel@tonic-gate 	}
4107c478bd9Sstevel@tonic-gate 
4117c478bd9Sstevel@tonic-gate 	/*
4127c478bd9Sstevel@tonic-gate 	 * set up desired_mechs so it points to mech_type.
4137c478bd9Sstevel@tonic-gate 	 */
4147c478bd9Sstevel@tonic-gate 
4157c478bd9Sstevel@tonic-gate 	desired_mechs = (gss_OID_set) MALLOC(sizeof (gss_OID_desc));
4167c478bd9Sstevel@tonic-gate 
4177c478bd9Sstevel@tonic-gate 	desired_mechs->count = 1;
4187c478bd9Sstevel@tonic-gate 	desired_mechs->elements = mech_type;
4197c478bd9Sstevel@tonic-gate 
4207c478bd9Sstevel@tonic-gate 	status = kgss_acquire_cred(
4217c478bd9Sstevel@tonic-gate 				&minor_status,
4227c478bd9Sstevel@tonic-gate 				desired_name,
4237c478bd9Sstevel@tonic-gate 				time_req,
4247c478bd9Sstevel@tonic-gate 				desired_mechs,
4257c478bd9Sstevel@tonic-gate 				cred_usage,
4267c478bd9Sstevel@tonic-gate 				&acceptor_credentials,
4277c478bd9Sstevel@tonic-gate 				&actual_mechs,
4287c478bd9Sstevel@tonic-gate 				&time_rec,
4297c478bd9Sstevel@tonic-gate 				uid);
4307c478bd9Sstevel@tonic-gate 
4317c478bd9Sstevel@tonic-gate 	/* store major and minor status for gss_display_status() call */
4327c478bd9Sstevel@tonic-gate 
4337c478bd9Sstevel@tonic-gate 	gss_major_code = status;
4347c478bd9Sstevel@tonic-gate 	gss_minor_code = minor_status;
4357c478bd9Sstevel@tonic-gate 
4367c478bd9Sstevel@tonic-gate 	if (status == GSS_S_COMPLETE) {
4377c478bd9Sstevel@tonic-gate 		/* process returned values */
4387c478bd9Sstevel@tonic-gate 
4397c478bd9Sstevel@tonic-gate 		printf(gettext("\nacquire succeeded\n\n"));
4407c478bd9Sstevel@tonic-gate 
4417c478bd9Sstevel@tonic-gate 		/*
4427c478bd9Sstevel@tonic-gate 		 * print out the actual mechs returned  NB: Since only one
4437c478bd9Sstevel@tonic-gate 		 * mechanism is specified in desired_mechs, only one
4447c478bd9Sstevel@tonic-gate 		 * can be returned in actual_mechs. Consequently,
4457c478bd9Sstevel@tonic-gate 		 * actual_mechs->elements points to an array of only one
4467c478bd9Sstevel@tonic-gate 		 * element.
4477c478bd9Sstevel@tonic-gate 		 */
4487c478bd9Sstevel@tonic-gate 
4497c478bd9Sstevel@tonic-gate 		if ((string = gss_oid2str(actual_mechs->elements)) == 0) {
4507c478bd9Sstevel@tonic-gate 			printf(gettext("actual mechs == NULL\n\n"));
4517c478bd9Sstevel@tonic-gate 		} else {
4527c478bd9Sstevel@tonic-gate 			printf(gettext("actual mechs  = %s\n\n"), string);
4537c478bd9Sstevel@tonic-gate 			FREE(string, (actual_mechs->elements->length+1)*4+1);
4547c478bd9Sstevel@tonic-gate 		}
4557c478bd9Sstevel@tonic-gate 
4567c478bd9Sstevel@tonic-gate 		if (cred_usage == GSS_C_BOTH)
4577c478bd9Sstevel@tonic-gate 			printf(gettext("GSS_C_BOTH\n\n"));
4587c478bd9Sstevel@tonic-gate 
4597c478bd9Sstevel@tonic-gate 		if (cred_usage == GSS_C_INITIATE)
4607c478bd9Sstevel@tonic-gate 			printf(gettext("GSS_C_INITIATE\n\n"));
4617c478bd9Sstevel@tonic-gate 
4627c478bd9Sstevel@tonic-gate 		if (cred_usage == GSS_C_ACCEPT)
4637c478bd9Sstevel@tonic-gate 			printf(gettext("GSS_C_ACCEPT\n\n"));
4647c478bd9Sstevel@tonic-gate 		status = kgss_inquire_cred(
4657c478bd9Sstevel@tonic-gate 				&minor_status,
4667c478bd9Sstevel@tonic-gate 				acceptor_credentials,
4677c478bd9Sstevel@tonic-gate 				NULL,
4687c478bd9Sstevel@tonic-gate 				&time_req,
4697c478bd9Sstevel@tonic-gate 				&cred_usage,
4707c478bd9Sstevel@tonic-gate 				&inquire_mechs,
4717c478bd9Sstevel@tonic-gate 				uid);
4727c478bd9Sstevel@tonic-gate 
4737c478bd9Sstevel@tonic-gate 		if (status != GSS_S_COMPLETE)
4747c478bd9Sstevel@tonic-gate 			printf(gettext("server ret err (octal) %o (%s)\n"),
4757c478bd9Sstevel@tonic-gate 			status, gettext("gss_inquire_cred error"));
4767c478bd9Sstevel@tonic-gate 		else {
4777c478bd9Sstevel@tonic-gate 			if ((inq_string =
4787c478bd9Sstevel@tonic-gate 				gss_oid2str(inquire_mechs->elements)) == 0) {
4797c478bd9Sstevel@tonic-gate 				printf(gettext
4807c478bd9Sstevel@tonic-gate 					("mechs from inquire == NULL\n\n"));
4817c478bd9Sstevel@tonic-gate 			} else {
4827c478bd9Sstevel@tonic-gate 				printf(gettext
4837c478bd9Sstevel@tonic-gate 					("mechs from inquiry  = %s\n\n"),
4847c478bd9Sstevel@tonic-gate 					inq_string);
4857c478bd9Sstevel@tonic-gate 				FREE(inq_string,
4867c478bd9Sstevel@tonic-gate 				(inquire_mechs->elements->length+1)*4+1);
4877c478bd9Sstevel@tonic-gate 			}
4887c478bd9Sstevel@tonic-gate 			printf(gettext("inquire_cred successful \n\n"));
4897c478bd9Sstevel@tonic-gate 		}
4907c478bd9Sstevel@tonic-gate 
4917c478bd9Sstevel@tonic-gate 	} else {
4927c478bd9Sstevel@tonic-gate 		printf(gettext("server ret err (octal) %o (%s)\n"),
4937c478bd9Sstevel@tonic-gate 			status, gettext("gss_acquire_cred error"));
4947c478bd9Sstevel@tonic-gate 	}
4957c478bd9Sstevel@tonic-gate 
4967c478bd9Sstevel@tonic-gate 	/* free allocated memory */
4977c478bd9Sstevel@tonic-gate 
4987c478bd9Sstevel@tonic-gate 	/* actual mechs is allocated by clnt_stubs. Release it here */
4997c478bd9Sstevel@tonic-gate 	if (actual_mechs != GSS_C_NULL_OID_SET)
5007c478bd9Sstevel@tonic-gate 		gss_release_oid_set_and_oids(&minor_status, &actual_mechs);
5017c478bd9Sstevel@tonic-gate 	if (inquire_mechs != GSS_C_NULL_OID_SET)
5027c478bd9Sstevel@tonic-gate 		gss_release_oid_set_and_oids(&minor_status, &inquire_mechs);
5037c478bd9Sstevel@tonic-gate 
5047c478bd9Sstevel@tonic-gate 	gss_release_name(&minor_status, &desired_name);
5057c478bd9Sstevel@tonic-gate 
5067c478bd9Sstevel@tonic-gate 	/* mech_type and desired_mechs are allocated above. Release it here */
5077c478bd9Sstevel@tonic-gate 
5087c478bd9Sstevel@tonic-gate 	FREE(mech_type->elements, mech_type->length);
5097c478bd9Sstevel@tonic-gate 	FREE(mech_type, sizeof (gss_OID_desc));
5107c478bd9Sstevel@tonic-gate 	FREE(desired_mechs, sizeof (gss_OID_desc));
5117c478bd9Sstevel@tonic-gate }
5127c478bd9Sstevel@tonic-gate 
5137c478bd9Sstevel@tonic-gate static void
_gss_add_cred(argc,argv)5147c478bd9Sstevel@tonic-gate _gss_add_cred(argc, argv)
5157c478bd9Sstevel@tonic-gate int argc;
5167c478bd9Sstevel@tonic-gate char **argv;
5177c478bd9Sstevel@tonic-gate {
5187c478bd9Sstevel@tonic-gate 
5197c478bd9Sstevel@tonic-gate 	OM_UINT32 status, minor_status;
5207c478bd9Sstevel@tonic-gate 	gss_buffer_desc name;
5217c478bd9Sstevel@tonic-gate 	gss_name_t desired_name = (gss_name_t) 0;
5227c478bd9Sstevel@tonic-gate 	OM_uint32 time_req;
5237c478bd9Sstevel@tonic-gate 	OM_uint32 initiator_time_req;
5247c478bd9Sstevel@tonic-gate 	OM_uint32 acceptor_time_req;
5257c478bd9Sstevel@tonic-gate 	int cred_usage;
5267c478bd9Sstevel@tonic-gate 	gss_OID_set actual_mechs = GSS_C_NULL_OID_SET;
5277c478bd9Sstevel@tonic-gate 	gss_OID_set inquire_mechs = GSS_C_NULL_OID_SET;
5287c478bd9Sstevel@tonic-gate 	char * string;
5297c478bd9Sstevel@tonic-gate 	uid_t uid;
5307c478bd9Sstevel@tonic-gate 	gss_OID mech_type;
5317c478bd9Sstevel@tonic-gate 	int i;
5327c478bd9Sstevel@tonic-gate 
5337c478bd9Sstevel@tonic-gate 	/*
5347c478bd9Sstevel@tonic-gate 	 * First set up the command line independent input arguments.
5357c478bd9Sstevel@tonic-gate 	 */
5367c478bd9Sstevel@tonic-gate 
5377c478bd9Sstevel@tonic-gate 	initiator_time_req = (OM_uint32) 0;
5387c478bd9Sstevel@tonic-gate 	acceptor_time_req = (OM_uint32) 0;
5397c478bd9Sstevel@tonic-gate 	cred_usage = GSS_C_ACCEPT;
5407c478bd9Sstevel@tonic-gate 	uid = getuid();
5417c478bd9Sstevel@tonic-gate 
5427c478bd9Sstevel@tonic-gate 	/* Parse the command line for the variable input arguments */
5437c478bd9Sstevel@tonic-gate 
5447c478bd9Sstevel@tonic-gate 	if (argc == 0) {
5457c478bd9Sstevel@tonic-gate 		usage();
5467c478bd9Sstevel@tonic-gate 		return;
5477c478bd9Sstevel@tonic-gate 	}
5487c478bd9Sstevel@tonic-gate 
5497c478bd9Sstevel@tonic-gate 	/*
5507c478bd9Sstevel@tonic-gate 	 * Get the name of the principal.
5517c478bd9Sstevel@tonic-gate 	 */
5527c478bd9Sstevel@tonic-gate 
5537c478bd9Sstevel@tonic-gate 	name.length = strlen(argv[0])+1;
5547c478bd9Sstevel@tonic-gate 	name.value = argv[0];
5557c478bd9Sstevel@tonic-gate 
5567c478bd9Sstevel@tonic-gate 	/*
5577c478bd9Sstevel@tonic-gate 	 * Now convert the string given by the first argument into internal
5587c478bd9Sstevel@tonic-gate 	 * form suitable for input to gss_acquire_cred()
5597c478bd9Sstevel@tonic-gate 	 */
5607c478bd9Sstevel@tonic-gate 
5617c478bd9Sstevel@tonic-gate 	if ((status = gss_import_name(&minor_status, &name,
5627c478bd9Sstevel@tonic-gate 		(gss_OID)GSS_C_NT_HOSTBASED_SERVICE, &desired_name))
5637c478bd9Sstevel@tonic-gate 		!= GSS_S_COMPLETE) {
5647c478bd9Sstevel@tonic-gate 		printf(gettext(
5657c478bd9Sstevel@tonic-gate 			"could not parse desired name: err (octal) %o (%s)\n"),
5667c478bd9Sstevel@tonic-gate 			status, gettext("gss_acquire_cred error"));
5677c478bd9Sstevel@tonic-gate 		return;
5687c478bd9Sstevel@tonic-gate 	}
5697c478bd9Sstevel@tonic-gate 
5707c478bd9Sstevel@tonic-gate 	argc--;
5717c478bd9Sstevel@tonic-gate 	argv++;
5727c478bd9Sstevel@tonic-gate 
5737c478bd9Sstevel@tonic-gate 	/*
5747c478bd9Sstevel@tonic-gate 	 * The next argument is an OID in dotted decimal form.
5757c478bd9Sstevel@tonic-gate 	 */
5767c478bd9Sstevel@tonic-gate 
5777c478bd9Sstevel@tonic-gate 	if (argc == 0) {
5787c478bd9Sstevel@tonic-gate 		printf(gettext("Assuming dummy  as the mechanism\n"));
5797c478bd9Sstevel@tonic-gate 		printf(gettext(
5807c478bd9Sstevel@tonic-gate 			"The mech OID 1.3.6.1.4.1.42.2.26.1.2 will be used\n"));
5817c478bd9Sstevel@tonic-gate 		mech_type = gss_str2oid((char *)GSS_DUMMY_MECH_OID);
5827c478bd9Sstevel@tonic-gate 	} else
5837c478bd9Sstevel@tonic-gate 		mech_type = gss_str2oid(argv[0]);
5847c478bd9Sstevel@tonic-gate 
5857c478bd9Sstevel@tonic-gate 	if (mech_type == 0 || mech_type->length == 0) {
5867c478bd9Sstevel@tonic-gate 		printf(gettext("improperly formated mechanism OID\n"));
5877c478bd9Sstevel@tonic-gate 		return;
5887c478bd9Sstevel@tonic-gate 	}
5897c478bd9Sstevel@tonic-gate 
5907c478bd9Sstevel@tonic-gate 	/*
5917c478bd9Sstevel@tonic-gate 	 * set up desired_mechs so it points to mech_type.
5927c478bd9Sstevel@tonic-gate 	 */
5937c478bd9Sstevel@tonic-gate 
5947c478bd9Sstevel@tonic-gate 	status = kgss_add_cred(
5957c478bd9Sstevel@tonic-gate 				&minor_status,
5967c478bd9Sstevel@tonic-gate 				acceptor_credentials,
5977c478bd9Sstevel@tonic-gate 				desired_name,
5987c478bd9Sstevel@tonic-gate 				mech_type,
5997c478bd9Sstevel@tonic-gate 				cred_usage,
6007c478bd9Sstevel@tonic-gate 				initiator_time_req,
6017c478bd9Sstevel@tonic-gate 				acceptor_time_req,
6027c478bd9Sstevel@tonic-gate 				&actual_mechs,
6037c478bd9Sstevel@tonic-gate 				NULL,
6047c478bd9Sstevel@tonic-gate 				NULL,
6057c478bd9Sstevel@tonic-gate 				uid);
6067c478bd9Sstevel@tonic-gate 
6077c478bd9Sstevel@tonic-gate 	/* store major and minor status for gss_display_status() call */
6087c478bd9Sstevel@tonic-gate 
6097c478bd9Sstevel@tonic-gate 	gss_major_code = status;
6107c478bd9Sstevel@tonic-gate 	gss_minor_code = minor_status;
6117c478bd9Sstevel@tonic-gate 	if (status == GSS_S_COMPLETE) {
6127c478bd9Sstevel@tonic-gate 		/* process returned values */
6137c478bd9Sstevel@tonic-gate 
6147c478bd9Sstevel@tonic-gate 		printf(gettext("\nadd  succeeded\n\n"));
6157c478bd9Sstevel@tonic-gate 		if (actual_mechs) {
6167c478bd9Sstevel@tonic-gate 			for (i = 0; i < actual_mechs->count; i++) {
6177c478bd9Sstevel@tonic-gate 				if ((string =
6187c478bd9Sstevel@tonic-gate 					gss_oid2str
6197c478bd9Sstevel@tonic-gate 					(&actual_mechs->elements[i])) == 0) {
6207c478bd9Sstevel@tonic-gate 					printf(gettext
6217c478bd9Sstevel@tonic-gate 					("actual mechs == NULL\n\n"));
6227c478bd9Sstevel@tonic-gate 				} else {
6237c478bd9Sstevel@tonic-gate 					printf(gettext
6247c478bd9Sstevel@tonic-gate 					("actual mechs  = %s\n\n"), string);
6257c478bd9Sstevel@tonic-gate 					FREE(string,
6267c478bd9Sstevel@tonic-gate 					(actual_mechs->elements->length+1)*4+1);
6277c478bd9Sstevel@tonic-gate 				}
6287c478bd9Sstevel@tonic-gate 			}
6297c478bd9Sstevel@tonic-gate 		}
6307c478bd9Sstevel@tonic-gate 		/*
6317c478bd9Sstevel@tonic-gate 		 * Try adding the cred again for the same mech
6327c478bd9Sstevel@tonic-gate 		 * We should get GSS_S_DUPLICATE_ELEMENT
6337c478bd9Sstevel@tonic-gate 		 * if not return an error
6347c478bd9Sstevel@tonic-gate 		 */
6357c478bd9Sstevel@tonic-gate 		status = kgss_add_cred(
6367c478bd9Sstevel@tonic-gate 				&minor_status,
6377c478bd9Sstevel@tonic-gate 				acceptor_credentials,
6387c478bd9Sstevel@tonic-gate 				desired_name,
6397c478bd9Sstevel@tonic-gate 				mech_type,
6407c478bd9Sstevel@tonic-gate 				cred_usage,
6417c478bd9Sstevel@tonic-gate 				initiator_time_req,
6427c478bd9Sstevel@tonic-gate 				acceptor_time_req,
6437c478bd9Sstevel@tonic-gate 				NULL, /*  &actual_mechs, */
6447c478bd9Sstevel@tonic-gate 				NULL,
6457c478bd9Sstevel@tonic-gate 				NULL,
6467c478bd9Sstevel@tonic-gate 				uid);
6477c478bd9Sstevel@tonic-gate 		if (status != GSS_S_DUPLICATE_ELEMENT) {
6487c478bd9Sstevel@tonic-gate 			printf(gettext("Expected duplicate element, Got "
6497c478bd9Sstevel@tonic-gate 			" (octal) %o (%s)\n"),
6507c478bd9Sstevel@tonic-gate 			status, gettext("gss_add_cred error"));
6517c478bd9Sstevel@tonic-gate 		}
6527c478bd9Sstevel@tonic-gate 		status = kgss_inquire_cred(
6537c478bd9Sstevel@tonic-gate 				&minor_status,
6547c478bd9Sstevel@tonic-gate 				acceptor_credentials,
6557c478bd9Sstevel@tonic-gate 				NULL,
6567c478bd9Sstevel@tonic-gate 				&time_req,
6577c478bd9Sstevel@tonic-gate 				&cred_usage,
6587c478bd9Sstevel@tonic-gate 				&inquire_mechs,
6597c478bd9Sstevel@tonic-gate 				uid);
6607c478bd9Sstevel@tonic-gate 
6617c478bd9Sstevel@tonic-gate 		if (status != GSS_S_COMPLETE)
6627c478bd9Sstevel@tonic-gate 			printf(gettext("server ret err (octal) %o (%s)\n"),
6637c478bd9Sstevel@tonic-gate 			status, gettext("gss_inquire_cred error"));
6647c478bd9Sstevel@tonic-gate 		else {
6657c478bd9Sstevel@tonic-gate 			for (i = 0; i < inquire_mechs->count; i++) {
6667c478bd9Sstevel@tonic-gate 				if ((string =
6677c478bd9Sstevel@tonic-gate 					gss_oid2str
6687c478bd9Sstevel@tonic-gate 					(&inquire_mechs->elements[i])) == 0) {
6697c478bd9Sstevel@tonic-gate 					printf(gettext
6707c478bd9Sstevel@tonic-gate 					("inquire_mechs mechs == NULL\n\n"));
6717c478bd9Sstevel@tonic-gate 				} else {
6727c478bd9Sstevel@tonic-gate 					printf(gettext
6737c478bd9Sstevel@tonic-gate 					("inquire_cred mechs  = %s\n\n"),
6747c478bd9Sstevel@tonic-gate 						string);
6757c478bd9Sstevel@tonic-gate 					FREE(string,
6767c478bd9Sstevel@tonic-gate 					(inquire_mechs->elements->length+1)*4
6777c478bd9Sstevel@tonic-gate 					+1);
6787c478bd9Sstevel@tonic-gate 				}
6797c478bd9Sstevel@tonic-gate 			}
6807c478bd9Sstevel@tonic-gate 			printf(gettext("inquire_cred successful \n\n"));
6817c478bd9Sstevel@tonic-gate 		}
6827c478bd9Sstevel@tonic-gate 
6837c478bd9Sstevel@tonic-gate 	} else {
6847c478bd9Sstevel@tonic-gate 		printf(gettext("server ret err (octal) %o (%s)\n"),
6857c478bd9Sstevel@tonic-gate 			status, gettext("gss_acquire_cred error"));
6867c478bd9Sstevel@tonic-gate 	}
6877c478bd9Sstevel@tonic-gate 
6887c478bd9Sstevel@tonic-gate 	/* Let us do inquire_cred_by_mech for both mechanisms */
6897c478bd9Sstevel@tonic-gate 	status = kgss_inquire_cred_by_mech(
6907c478bd9Sstevel@tonic-gate 			&minor_status,
6917c478bd9Sstevel@tonic-gate 			acceptor_credentials,
6927c478bd9Sstevel@tonic-gate 			mech_type,
6937c478bd9Sstevel@tonic-gate 			uid);
6947c478bd9Sstevel@tonic-gate 	if (status != GSS_S_COMPLETE)
6957c478bd9Sstevel@tonic-gate 		printf(gettext("server ret err (octal) %o (%s)\n"),
6967c478bd9Sstevel@tonic-gate 		status, gettext("gss_inquire_cred_by_mech"));
6977c478bd9Sstevel@tonic-gate 	else
6987c478bd9Sstevel@tonic-gate 		printf(gettext("gss_inquire_cred_by_mech successful"));
6997c478bd9Sstevel@tonic-gate 
7007c478bd9Sstevel@tonic-gate 
7017c478bd9Sstevel@tonic-gate 	FREE(mech_type->elements, mech_type->length);
7027c478bd9Sstevel@tonic-gate 	FREE(mech_type, sizeof (gss_OID_desc));
7037c478bd9Sstevel@tonic-gate 	mech_type = gss_str2oid((char *)GSS_KRB5_MECH_OID);
7047c478bd9Sstevel@tonic-gate 	status = kgss_inquire_cred_by_mech(
7057c478bd9Sstevel@tonic-gate 			&minor_status,
7067c478bd9Sstevel@tonic-gate 			acceptor_credentials,
7077c478bd9Sstevel@tonic-gate 			mech_type,
7087c478bd9Sstevel@tonic-gate 			uid);
7097c478bd9Sstevel@tonic-gate 	if (status != GSS_S_COMPLETE)
7107c478bd9Sstevel@tonic-gate 		printf(gettext("server ret err (octal) %o (%s)\n"),
7117c478bd9Sstevel@tonic-gate 			status, gettext
7127c478bd9Sstevel@tonic-gate 			("gss_inquire_cred_by_mech for dummy mech error"));
7137c478bd9Sstevel@tonic-gate 
7147c478bd9Sstevel@tonic-gate 	/* free allocated memory */
7157c478bd9Sstevel@tonic-gate 
7167c478bd9Sstevel@tonic-gate 	/* actual mechs is allocated by clnt_stubs. Release it here */
7177c478bd9Sstevel@tonic-gate 	if (actual_mechs != GSS_C_NULL_OID_SET)
7187c478bd9Sstevel@tonic-gate 		gss_release_oid_set_and_oids(&minor_status, &actual_mechs);
7197c478bd9Sstevel@tonic-gate 	if (inquire_mechs != GSS_C_NULL_OID_SET)
7207c478bd9Sstevel@tonic-gate 		gss_release_oid_set_and_oids(&minor_status, &inquire_mechs);
7217c478bd9Sstevel@tonic-gate 
7227c478bd9Sstevel@tonic-gate 	gss_release_name(&minor_status, &desired_name);
7237c478bd9Sstevel@tonic-gate 
7247c478bd9Sstevel@tonic-gate 	/* mech_type and desired_mechs are allocated above. Release it here */
7257c478bd9Sstevel@tonic-gate 
7267c478bd9Sstevel@tonic-gate 	FREE(mech_type->elements, mech_type->length);
7277c478bd9Sstevel@tonic-gate 	FREE(mech_type, sizeof (gss_OID_desc));
7287c478bd9Sstevel@tonic-gate }
7297c478bd9Sstevel@tonic-gate 
7307c478bd9Sstevel@tonic-gate /*ARGSUSED*/
7317c478bd9Sstevel@tonic-gate static void
_gss_release_cred(argc,argv)7327c478bd9Sstevel@tonic-gate _gss_release_cred(argc, argv)
7337c478bd9Sstevel@tonic-gate int argc;
7347c478bd9Sstevel@tonic-gate char **argv;
7357c478bd9Sstevel@tonic-gate {
7367c478bd9Sstevel@tonic-gate 	OM_UINT32 status;
7377c478bd9Sstevel@tonic-gate 	OM_UINT32 minor_status;
7387c478bd9Sstevel@tonic-gate 	uid_t uid;
7397c478bd9Sstevel@tonic-gate 
7407c478bd9Sstevel@tonic-gate 	/* set up input arguments here */
7417c478bd9Sstevel@tonic-gate 
7427c478bd9Sstevel@tonic-gate 	if (argc != 0) {
7437c478bd9Sstevel@tonic-gate 		usage();
7447c478bd9Sstevel@tonic-gate 		return;
7457c478bd9Sstevel@tonic-gate 	}
7467c478bd9Sstevel@tonic-gate 
7477c478bd9Sstevel@tonic-gate 	uid = getuid();
7487c478bd9Sstevel@tonic-gate 
7497c478bd9Sstevel@tonic-gate 	status = kgss_release_cred(
7507c478bd9Sstevel@tonic-gate 				&minor_status,
7517c478bd9Sstevel@tonic-gate 				&acceptor_credentials,
7527c478bd9Sstevel@tonic-gate 				uid);
7537c478bd9Sstevel@tonic-gate 
7547c478bd9Sstevel@tonic-gate 	/* store major and minor status for gss_display_status() call */
7557c478bd9Sstevel@tonic-gate 
7567c478bd9Sstevel@tonic-gate 	gss_major_code = status;
7577c478bd9Sstevel@tonic-gate 	gss_minor_code = minor_status;
7587c478bd9Sstevel@tonic-gate 
7597c478bd9Sstevel@tonic-gate 	if (status == GSS_S_COMPLETE) {
7607c478bd9Sstevel@tonic-gate 		printf(gettext("\nrelease succeeded\n\n"));
7617c478bd9Sstevel@tonic-gate 	} else {
7627c478bd9Sstevel@tonic-gate 		printf(gettext("server ret err (octal) %o (%s)\n"),
7637c478bd9Sstevel@tonic-gate 			status, gettext("gss_release_cred error"));
7647c478bd9Sstevel@tonic-gate 	}
7657c478bd9Sstevel@tonic-gate }
7667c478bd9Sstevel@tonic-gate 
7677c478bd9Sstevel@tonic-gate static void
_gss_init_sec_context(argc,argv)7687c478bd9Sstevel@tonic-gate _gss_init_sec_context(argc, argv)
7697c478bd9Sstevel@tonic-gate int argc;
7707c478bd9Sstevel@tonic-gate char **argv;
7717c478bd9Sstevel@tonic-gate {
7727c478bd9Sstevel@tonic-gate 
7737c478bd9Sstevel@tonic-gate 	OM_uint32 status;
7747c478bd9Sstevel@tonic-gate 
7757c478bd9Sstevel@tonic-gate 	OM_uint32 minor_status;
7767c478bd9Sstevel@tonic-gate 	gss_cred_id_t claimant_cred_handle;
7777c478bd9Sstevel@tonic-gate 	gss_name_t target_name = (gss_name_t) 0;
7787c478bd9Sstevel@tonic-gate 	gss_OID mech_type = (gss_OID) 0;
7797c478bd9Sstevel@tonic-gate 	int req_flags;
7807c478bd9Sstevel@tonic-gate 	OM_uint32 time_req;
7817c478bd9Sstevel@tonic-gate 	gss_channel_bindings_t input_chan_bindings;
7827c478bd9Sstevel@tonic-gate 	gss_buffer_t input_token;
7837c478bd9Sstevel@tonic-gate 	gss_buffer_desc context_token;
7847c478bd9Sstevel@tonic-gate 	gss_OID actual_mech_type;
7857c478bd9Sstevel@tonic-gate 	int ret_flags;
7867c478bd9Sstevel@tonic-gate 	OM_uint32 time_rec;
7877c478bd9Sstevel@tonic-gate 	uid_t uid;
7887c478bd9Sstevel@tonic-gate 	char * string;
7897c478bd9Sstevel@tonic-gate 	gss_buffer_desc name;
7907c478bd9Sstevel@tonic-gate 
7917c478bd9Sstevel@tonic-gate 	/*
7927c478bd9Sstevel@tonic-gate 	 * If this is the first phase of the context establishment,
7937c478bd9Sstevel@tonic-gate 	 * clear initiator_context_handle and indicate next phase.
7947c478bd9Sstevel@tonic-gate 	 */
7957c478bd9Sstevel@tonic-gate 
7967c478bd9Sstevel@tonic-gate 	if (init_sec_context_phase == 0) {
7977c478bd9Sstevel@tonic-gate 		initiator_context_handle = GSS_C_NO_CONTEXT;
7987c478bd9Sstevel@tonic-gate 		input_token = GSS_C_NO_BUFFER;
7997c478bd9Sstevel@tonic-gate 		init_sec_context_phase = 1;
8007c478bd9Sstevel@tonic-gate 	} else
8017c478bd9Sstevel@tonic-gate 		input_token = &init_token_buffer;
8027c478bd9Sstevel@tonic-gate 
8037c478bd9Sstevel@tonic-gate 	/*
8047c478bd9Sstevel@tonic-gate 	 * First set up the non-variable command line independent input
8057c478bd9Sstevel@tonic-gate 	 * arguments
8067c478bd9Sstevel@tonic-gate 	 */
8077c478bd9Sstevel@tonic-gate 
8087c478bd9Sstevel@tonic-gate 	claimant_cred_handle = GSS_C_NO_CREDENTIAL;
8097c478bd9Sstevel@tonic-gate 
8107c478bd9Sstevel@tonic-gate 	req_flags = GSS_C_MUTUAL_FLAG;
8117c478bd9Sstevel@tonic-gate 	time_req = (OM_uint32) 0;
8127c478bd9Sstevel@tonic-gate 	input_chan_bindings = GSS_C_NO_CHANNEL_BINDINGS;
8137c478bd9Sstevel@tonic-gate 	uid = getuid();
8147c478bd9Sstevel@tonic-gate 
8157c478bd9Sstevel@tonic-gate 	/* Now parse the command line for the remaining input arguments */
8167c478bd9Sstevel@tonic-gate 
8177c478bd9Sstevel@tonic-gate 	if (argc == 0) {
8187c478bd9Sstevel@tonic-gate 		usage();
8197c478bd9Sstevel@tonic-gate 		return;
8207c478bd9Sstevel@tonic-gate 	}
8217c478bd9Sstevel@tonic-gate 
8227c478bd9Sstevel@tonic-gate 	/*
8237c478bd9Sstevel@tonic-gate 	 * Get the name of the target.
8247c478bd9Sstevel@tonic-gate 	 */
8257c478bd9Sstevel@tonic-gate 
8267c478bd9Sstevel@tonic-gate 	name.length = strlen(argv[0])+1;
8277c478bd9Sstevel@tonic-gate 	name.value = argv[0];
8287c478bd9Sstevel@tonic-gate 
8297c478bd9Sstevel@tonic-gate 	/*
8307c478bd9Sstevel@tonic-gate 	 * Now convert the string given by the first argument into a target
8317c478bd9Sstevel@tonic-gate 	 * name suitable for input to gss_init_sec_context()
8327c478bd9Sstevel@tonic-gate 	 */
8337c478bd9Sstevel@tonic-gate 
8347c478bd9Sstevel@tonic-gate 	if ((status = gss_import_name(&minor_status, &name,
8357c478bd9Sstevel@tonic-gate 		/* GSS_C_NULL_OID, &target_name)) */
8367c478bd9Sstevel@tonic-gate 		(gss_OID)GSS_C_NT_HOSTBASED_SERVICE, &target_name))
8377c478bd9Sstevel@tonic-gate 		!= GSS_S_COMPLETE) {
8387c478bd9Sstevel@tonic-gate 		printf(gettext(
8397c478bd9Sstevel@tonic-gate 			"could not parse target name: err (octal) %o (%s)\n"),
8407c478bd9Sstevel@tonic-gate 			status,
8417c478bd9Sstevel@tonic-gate 			gettext("gss_init_sec_context error"));
8427c478bd9Sstevel@tonic-gate 		if (input_token != GSS_C_NO_BUFFER)
8437c478bd9Sstevel@tonic-gate 			gss_release_buffer(&minor_status, &init_token_buffer);
8447c478bd9Sstevel@tonic-gate 		init_sec_context_phase = 0;
8457c478bd9Sstevel@tonic-gate 		return;
8467c478bd9Sstevel@tonic-gate 	}
8477c478bd9Sstevel@tonic-gate 
8487c478bd9Sstevel@tonic-gate 	argc--;
8497c478bd9Sstevel@tonic-gate 	argv++;
8507c478bd9Sstevel@tonic-gate 
8517c478bd9Sstevel@tonic-gate 	if (argc == 0) {
8527c478bd9Sstevel@tonic-gate 		printf(gettext("Assuming Kerberos V5 as the mechanism\n"));
8537c478bd9Sstevel@tonic-gate 		printf(gettext(
8547c478bd9Sstevel@tonic-gate 			"The mech OID 1.2.840.113554.1.2.2 will be used\n"));
8557c478bd9Sstevel@tonic-gate 		mech_type = gss_str2oid((char *)GSS_KRB5_MECH_OID);
8567c478bd9Sstevel@tonic-gate 	} else {
8577c478bd9Sstevel@tonic-gate 		mech_type = gss_str2oid(argv[0]);
8587c478bd9Sstevel@tonic-gate 	}
8597c478bd9Sstevel@tonic-gate 
8607c478bd9Sstevel@tonic-gate 	if (mech_type == 0 || mech_type->length == 0) {
8617c478bd9Sstevel@tonic-gate 		printf(gettext("improperly formated mechanism OID\n"));
8627c478bd9Sstevel@tonic-gate 		if (input_token != GSS_C_NO_BUFFER)
8637c478bd9Sstevel@tonic-gate 			gss_release_buffer(&minor_status, &init_token_buffer);
8647c478bd9Sstevel@tonic-gate 		init_sec_context_phase = 0;
8657c478bd9Sstevel@tonic-gate 		return;
8667c478bd9Sstevel@tonic-gate 	}
8677c478bd9Sstevel@tonic-gate 
8687c478bd9Sstevel@tonic-gate 	/* call kgss_init_sec_context */
8697c478bd9Sstevel@tonic-gate 
8707c478bd9Sstevel@tonic-gate 	status = kgss_init_sec_context(&minor_status,
8717c478bd9Sstevel@tonic-gate 				claimant_cred_handle,
8727c478bd9Sstevel@tonic-gate 				&initiator_context_handle,
8737c478bd9Sstevel@tonic-gate 				target_name,
8747c478bd9Sstevel@tonic-gate 				mech_type,
8757c478bd9Sstevel@tonic-gate 				req_flags,
8767c478bd9Sstevel@tonic-gate 				time_req,
8777c478bd9Sstevel@tonic-gate 				input_chan_bindings,
8787c478bd9Sstevel@tonic-gate 				input_token,
8797c478bd9Sstevel@tonic-gate 				&actual_mech_type,
8807c478bd9Sstevel@tonic-gate 				&accept_token_buffer,
8817c478bd9Sstevel@tonic-gate 				&ret_flags,
8827c478bd9Sstevel@tonic-gate 				&time_rec,
8837c478bd9Sstevel@tonic-gate 				uid);
8847c478bd9Sstevel@tonic-gate 
8857c478bd9Sstevel@tonic-gate 	/* store major and minor status for gss_display_status() call */
8867c478bd9Sstevel@tonic-gate 	gss_major_code = status;
8877c478bd9Sstevel@tonic-gate 	gss_minor_code = minor_status;
8887c478bd9Sstevel@tonic-gate 
8897c478bd9Sstevel@tonic-gate 	if (status != GSS_S_COMPLETE &&
8907c478bd9Sstevel@tonic-gate 	    status != GSS_S_CONTINUE_NEEDED) {
8917c478bd9Sstevel@tonic-gate 
8927c478bd9Sstevel@tonic-gate 		printf(gettext("server ret err (octal) %o (%s)\n"),
8937c478bd9Sstevel@tonic-gate 			status, "gss_init_sec_context error");
8947c478bd9Sstevel@tonic-gate 		init_sec_context_phase = 0;
8957c478bd9Sstevel@tonic-gate 		if (status == GSS_S_NO_CRED)
8967c478bd9Sstevel@tonic-gate 			printf(gettext(" : no credentials"));
8977c478bd9Sstevel@tonic-gate 		if (input_token != GSS_C_NO_BUFFER)
8987c478bd9Sstevel@tonic-gate 			gss_release_buffer(&minor_status, &init_token_buffer);
8997c478bd9Sstevel@tonic-gate 		if (status != GSS_S_FAILURE && minor_status != 0xffffffff)
9007c478bd9Sstevel@tonic-gate 			status = kgss_delete_sec_context(&minor_status,
9017c478bd9Sstevel@tonic-gate 					&initiator_context_handle,
9027c478bd9Sstevel@tonic-gate 					&msg_token);
9037c478bd9Sstevel@tonic-gate 		return;
9047c478bd9Sstevel@tonic-gate 
9057c478bd9Sstevel@tonic-gate 	} else if (status == GSS_S_COMPLETE) {
9067c478bd9Sstevel@tonic-gate 
9077c478bd9Sstevel@tonic-gate 		/* process returned values */
9087c478bd9Sstevel@tonic-gate 
9097c478bd9Sstevel@tonic-gate 		printf(gettext("\ninit succeeded\n\n"));
9107c478bd9Sstevel@tonic-gate 
9117c478bd9Sstevel@tonic-gate 		/* print out the actual mechanism type */
9127c478bd9Sstevel@tonic-gate 
9137c478bd9Sstevel@tonic-gate 		if ((string = gss_oid2str(actual_mech_type)) == 0) {
9147c478bd9Sstevel@tonic-gate 
9157c478bd9Sstevel@tonic-gate 			printf(gettext(
9167c478bd9Sstevel@tonic-gate 				"gssapi internal err : actual "
9177c478bd9Sstevel@tonic-gate 				"mech type null\n"));
9187c478bd9Sstevel@tonic-gate 			init_sec_context_phase = 0;
9197c478bd9Sstevel@tonic-gate 			if (input_token != GSS_C_NO_BUFFER)
9207c478bd9Sstevel@tonic-gate 				gss_release_buffer(&minor_status,
9217c478bd9Sstevel@tonic-gate 						&init_token_buffer);
9227c478bd9Sstevel@tonic-gate 			gss_release_buffer(&minor_status, &accept_token_buffer);
9237c478bd9Sstevel@tonic-gate 			status = kgss_delete_sec_context(&minor_status,
9247c478bd9Sstevel@tonic-gate 					&initiator_context_handle,
9257c478bd9Sstevel@tonic-gate 					&msg_token);
9267c478bd9Sstevel@tonic-gate 			return;
9277c478bd9Sstevel@tonic-gate 		} else {
9287c478bd9Sstevel@tonic-gate 			printf(gettext("actual mech type = %s\n\n"), string);
9297c478bd9Sstevel@tonic-gate 			FREE(string, (actual_mech_type->length+1)*4+1);
9307c478bd9Sstevel@tonic-gate 		}
9317c478bd9Sstevel@tonic-gate 
9327c478bd9Sstevel@tonic-gate 		/* print out value of ret_flags and time_req */
9337c478bd9Sstevel@tonic-gate 
9347c478bd9Sstevel@tonic-gate 		if (ret_flags & GSS_C_DELEG_FLAG)
9357c478bd9Sstevel@tonic-gate 			printf(gettext("GSS_C_DELEG_FLAG = True\n"));
9367c478bd9Sstevel@tonic-gate 		else
9377c478bd9Sstevel@tonic-gate 			printf(gettext("GSS_C_DELEG_FLAG = False\n"));
9387c478bd9Sstevel@tonic-gate 
9397c478bd9Sstevel@tonic-gate 		if (ret_flags & GSS_C_MUTUAL_FLAG)
9407c478bd9Sstevel@tonic-gate 			printf(gettext("GSS_C_MUTUAL_FLAG = True\n"));
9417c478bd9Sstevel@tonic-gate 		else
9427c478bd9Sstevel@tonic-gate 			printf(gettext("GSS_C_MUTUAL_FLAG = False\n"));
9437c478bd9Sstevel@tonic-gate 
9447c478bd9Sstevel@tonic-gate 		if (ret_flags & GSS_C_REPLAY_FLAG)
9457c478bd9Sstevel@tonic-gate 			printf(gettext("GSS_C_REPLAY_FLAG = True\n"));
9467c478bd9Sstevel@tonic-gate 		else
9477c478bd9Sstevel@tonic-gate 			printf(gettext("GSS_C_REPLAY_FLAG = False\n"));
9487c478bd9Sstevel@tonic-gate 
9497c478bd9Sstevel@tonic-gate 		if (ret_flags & GSS_C_SEQUENCE_FLAG)
9507c478bd9Sstevel@tonic-gate 			printf(gettext("GSS_C_SEQUENCE_FLAG = True\n"));
9517c478bd9Sstevel@tonic-gate 		else
9527c478bd9Sstevel@tonic-gate 			printf(gettext("GSS_C_SEQUENCE_FLAG = False\n"));
9537c478bd9Sstevel@tonic-gate 
9547c478bd9Sstevel@tonic-gate 		if (ret_flags & GSS_C_CONF_FLAG)
9557c478bd9Sstevel@tonic-gate 			printf(gettext("GSS_C_CONF_FLAG = True\n"));
9567c478bd9Sstevel@tonic-gate 		else
9577c478bd9Sstevel@tonic-gate 			printf(gettext("GSS_C_CONF_FLAG = False\n"));
9587c478bd9Sstevel@tonic-gate 
9597c478bd9Sstevel@tonic-gate 		if (ret_flags & GSS_C_INTEG_FLAG)
9607c478bd9Sstevel@tonic-gate 			printf(gettext("GSS_C_INTEG_FLAG = True\n\n"));
9617c478bd9Sstevel@tonic-gate 		else
9627c478bd9Sstevel@tonic-gate 			printf(gettext("GSS_C_INTEG_FLAG = False\n\n"));
9637c478bd9Sstevel@tonic-gate 
9647c478bd9Sstevel@tonic-gate 		printf(gettext("time_req = %u seconds\n\n"), time_rec);
9657c478bd9Sstevel@tonic-gate 
9667c478bd9Sstevel@tonic-gate 		/* free allocated memory */
9677c478bd9Sstevel@tonic-gate 
9687c478bd9Sstevel@tonic-gate 		FREE(mech_type->elements, mech_type->length);
9697c478bd9Sstevel@tonic-gate 		FREE(mech_type, sizeof (gss_OID_desc));
9707c478bd9Sstevel@tonic-gate 
9717c478bd9Sstevel@tonic-gate 		/* these two were malloc'd by kgss_init_sec_context() */
9727c478bd9Sstevel@tonic-gate 
9737c478bd9Sstevel@tonic-gate 		FREE(actual_mech_type->elements, actual_mech_type->length);
9747c478bd9Sstevel@tonic-gate 		FREE(actual_mech_type, sizeof (gss_OID_desc));
9757c478bd9Sstevel@tonic-gate 
9767c478bd9Sstevel@tonic-gate 		gss_release_name(&minor_status, &target_name);
9777c478bd9Sstevel@tonic-gate 
9787c478bd9Sstevel@tonic-gate 		if (input_token != GSS_C_NO_BUFFER)
9797c478bd9Sstevel@tonic-gate 			gss_release_buffer(&minor_status, &init_token_buffer);
9807c478bd9Sstevel@tonic-gate 
9817c478bd9Sstevel@tonic-gate 		/*
9827c478bd9Sstevel@tonic-gate 		 * if status == GSS_S_COMPLETE, reset the phase to 0 and
9837c478bd9Sstevel@tonic-gate 		 * release token in accept_token_buffer
9847c478bd9Sstevel@tonic-gate 		 */
9857c478bd9Sstevel@tonic-gate 
9867c478bd9Sstevel@tonic-gate 		init_sec_context_phase = 0;
9877c478bd9Sstevel@tonic-gate 	/* Save and restore the context */
9887c478bd9Sstevel@tonic-gate 	status = kgss_export_sec_context(&minor_status,
9897c478bd9Sstevel@tonic-gate 					&initiator_context_handle,
9907c478bd9Sstevel@tonic-gate 					&context_token);
9917c478bd9Sstevel@tonic-gate 	if (status != GSS_S_COMPLETE) {
9927c478bd9Sstevel@tonic-gate 		printf(gettext("server ret err (octal) %o (%s)\n"),
9937c478bd9Sstevel@tonic-gate 			status, gettext("gss_export_sec_context_error"));
9947c478bd9Sstevel@tonic-gate 		return;
9957c478bd9Sstevel@tonic-gate 	}
9967c478bd9Sstevel@tonic-gate 	status = kgss_import_sec_context(&minor_status,
9977c478bd9Sstevel@tonic-gate 					&context_token,
9987c478bd9Sstevel@tonic-gate 					&initiator_context_handle);
9997c478bd9Sstevel@tonic-gate 	if (status != GSS_S_COMPLETE) {
10007c478bd9Sstevel@tonic-gate 		printf(gettext("server ret err (octal) %o (%s)\n"),
10017c478bd9Sstevel@tonic-gate 			status, gettext("gss_import_sec_context_error"));
10027c478bd9Sstevel@tonic-gate 		return;
10037c478bd9Sstevel@tonic-gate 	}
10047c478bd9Sstevel@tonic-gate 	(void) gss_release_buffer(&minor_status, &context_token);
10057c478bd9Sstevel@tonic-gate 
10067c478bd9Sstevel@tonic-gate 	/* gss_export & gss_import secxc_context worked, return */
10077c478bd9Sstevel@tonic-gate 	printf(gettext("\nexport and import of contexts succeeded\n"));
10087c478bd9Sstevel@tonic-gate 	printf(gettext("\ninit completed"));
10097c478bd9Sstevel@tonic-gate 
10107c478bd9Sstevel@tonic-gate 	} else {
10117c478bd9Sstevel@tonic-gate 		printf(gettext("\nfirst phase of init succeeded"));
10127c478bd9Sstevel@tonic-gate 		printf(gettext("\ninit must be called again\n\n"));
10137c478bd9Sstevel@tonic-gate 	}
10147c478bd9Sstevel@tonic-gate 
10157c478bd9Sstevel@tonic-gate }
10167c478bd9Sstevel@tonic-gate 
10177c478bd9Sstevel@tonic-gate /*ARGSUSED*/
10187c478bd9Sstevel@tonic-gate static void
_gss_accept_sec_context(argc,argv)10197c478bd9Sstevel@tonic-gate _gss_accept_sec_context(argc, argv)
10207c478bd9Sstevel@tonic-gate int argc;
10217c478bd9Sstevel@tonic-gate char **argv;
10227c478bd9Sstevel@tonic-gate {
10237c478bd9Sstevel@tonic-gate 	OM_UINT32 status;
10247c478bd9Sstevel@tonic-gate 
10257c478bd9Sstevel@tonic-gate 	OM_uint32 minor_status;
10267c478bd9Sstevel@tonic-gate 	gss_channel_bindings_t input_chan_bindings;
10277c478bd9Sstevel@tonic-gate 	gss_OID mech_type;
10287c478bd9Sstevel@tonic-gate 	int ret_flags;
10297c478bd9Sstevel@tonic-gate 	OM_uint32 time_rec;
10307c478bd9Sstevel@tonic-gate 	gss_cred_id_t delegated_cred_handle;
10317c478bd9Sstevel@tonic-gate 	uid_t uid;
10327c478bd9Sstevel@tonic-gate 	char *string;
10337c478bd9Sstevel@tonic-gate 	gss_buffer_desc src_name, src_name_string;
10347c478bd9Sstevel@tonic-gate 	gss_buffer_desc output_token;
10357c478bd9Sstevel@tonic-gate 	gss_name_t gss_name;
10367c478bd9Sstevel@tonic-gate 	gss_buffer_desc context_token;
10377c478bd9Sstevel@tonic-gate 
10387c478bd9Sstevel@tonic-gate 	/*
10397c478bd9Sstevel@tonic-gate 	 * If this is the first phase of the context establishment,
10407c478bd9Sstevel@tonic-gate 	 * clear acceptor_context_handle and indicate next phase.
10417c478bd9Sstevel@tonic-gate 	 */
10427c478bd9Sstevel@tonic-gate 
10437c478bd9Sstevel@tonic-gate 	if (accept_sec_context_phase == 0) {
10447c478bd9Sstevel@tonic-gate 		acceptor_context_handle = GSS_C_NO_CONTEXT;
10457c478bd9Sstevel@tonic-gate 		accept_sec_context_phase = 1;
10467c478bd9Sstevel@tonic-gate 	}
10477c478bd9Sstevel@tonic-gate 
10487c478bd9Sstevel@tonic-gate 	/* Now set up the other command line independent input arguments */
10497c478bd9Sstevel@tonic-gate 
10507c478bd9Sstevel@tonic-gate 	input_chan_bindings = GSS_C_NO_CHANNEL_BINDINGS;
10517c478bd9Sstevel@tonic-gate 
10527c478bd9Sstevel@tonic-gate 	uid = (uid_t) getuid();
10537c478bd9Sstevel@tonic-gate 
10547c478bd9Sstevel@tonic-gate 	if (argc != 0) {
10557c478bd9Sstevel@tonic-gate 		usage();
10567c478bd9Sstevel@tonic-gate 		return;
10577c478bd9Sstevel@tonic-gate 	}
10587c478bd9Sstevel@tonic-gate 
10597c478bd9Sstevel@tonic-gate 	status = kgss_accept_sec_context(&minor_status,
10607c478bd9Sstevel@tonic-gate 					&acceptor_context_handle,
10617c478bd9Sstevel@tonic-gate 					acceptor_credentials,
10627c478bd9Sstevel@tonic-gate 					&accept_token_buffer,
10637c478bd9Sstevel@tonic-gate 					input_chan_bindings,
10647c478bd9Sstevel@tonic-gate 					&src_name,
10657c478bd9Sstevel@tonic-gate 					&mech_type,
10667c478bd9Sstevel@tonic-gate 					&init_token_buffer,
10677c478bd9Sstevel@tonic-gate 					&ret_flags,
10687c478bd9Sstevel@tonic-gate 					&time_rec,
10697c478bd9Sstevel@tonic-gate 					&delegated_cred_handle,
10707c478bd9Sstevel@tonic-gate 					uid);
10717c478bd9Sstevel@tonic-gate 
10727c478bd9Sstevel@tonic-gate 	/* store major and minor status for gss_display_status() call */
10737c478bd9Sstevel@tonic-gate 
10747c478bd9Sstevel@tonic-gate 	gss_major_code = status;
10757c478bd9Sstevel@tonic-gate 	gss_minor_code = minor_status;
10767c478bd9Sstevel@tonic-gate 
10777c478bd9Sstevel@tonic-gate 	if (status != GSS_S_COMPLETE && status != GSS_S_CONTINUE_NEEDED) {
10787c478bd9Sstevel@tonic-gate 		printf(gettext("server ret err (octal) %o (%s)\n"),
10797c478bd9Sstevel@tonic-gate 			status, gettext("gss_accept_sec_context error"));
10807c478bd9Sstevel@tonic-gate 		gss_release_buffer(&minor_status, &accept_token_buffer);
10817c478bd9Sstevel@tonic-gate 		return;
10827c478bd9Sstevel@tonic-gate 	} else if (status == GSS_S_COMPLETE) {
10837c478bd9Sstevel@tonic-gate 
10847c478bd9Sstevel@tonic-gate 		/* process returned values */
10857c478bd9Sstevel@tonic-gate 
10867c478bd9Sstevel@tonic-gate 		printf(gettext("\naccept succeeded\n\n"));
10877c478bd9Sstevel@tonic-gate 
10887c478bd9Sstevel@tonic-gate 		/*
10897c478bd9Sstevel@tonic-gate 		 * convert the exported name returned in src_name into
10907c478bd9Sstevel@tonic-gate 		 * a string and print it.
10917c478bd9Sstevel@tonic-gate 		 */
10927c478bd9Sstevel@tonic-gate 		if ((status = gss_import_name(&minor_status, &src_name,
10937c478bd9Sstevel@tonic-gate 			(gss_OID) GSS_C_NT_EXPORT_NAME, &gss_name))
10947c478bd9Sstevel@tonic-gate 			!= GSS_S_COMPLETE) {
10957c478bd9Sstevel@tonic-gate 			printf(gettext(
10967c478bd9Sstevel@tonic-gate 				"could not import src name 0x%x\n"), status);
10977c478bd9Sstevel@tonic-gate 			accept_sec_context_phase = 0;
10987c478bd9Sstevel@tonic-gate 			status = kgss_delete_sec_context(&minor_status,
10997c478bd9Sstevel@tonic-gate 					&acceptor_context_handle,
11007c478bd9Sstevel@tonic-gate 					&output_token);
11017c478bd9Sstevel@tonic-gate 			gss_release_buffer(&minor_status, &accept_token_buffer);
11027c478bd9Sstevel@tonic-gate 			if (status == GSS_S_CONTINUE_NEEDED)
11037c478bd9Sstevel@tonic-gate 				gss_release_buffer(&minor_status,
11047c478bd9Sstevel@tonic-gate 						&init_token_buffer);
11057c478bd9Sstevel@tonic-gate 			gss_release_buffer(&minor_status, &src_name);
11067c478bd9Sstevel@tonic-gate 			return;
11077c478bd9Sstevel@tonic-gate 		}
11087c478bd9Sstevel@tonic-gate 
11097c478bd9Sstevel@tonic-gate 		memset(&src_name_string, 0, sizeof (src_name_string));
11107c478bd9Sstevel@tonic-gate 		if ((status = gss_display_name(&minor_status, gss_name,
11117c478bd9Sstevel@tonic-gate 			&src_name_string, NULL)) != GSS_S_COMPLETE) {
11127c478bd9Sstevel@tonic-gate 			printf(gettext("could not display src name: "
11137c478bd9Sstevel@tonic-gate 				"err (octal) %o (%s)\n"), status,
11147c478bd9Sstevel@tonic-gate 				"gss_init_sec_context error");
11157c478bd9Sstevel@tonic-gate 			accept_sec_context_phase = 0;
11167c478bd9Sstevel@tonic-gate 			status = kgss_delete_sec_context(&minor_status,
11177c478bd9Sstevel@tonic-gate 					&acceptor_context_handle,
11187c478bd9Sstevel@tonic-gate 					&output_token);
11197c478bd9Sstevel@tonic-gate 			gss_release_buffer(&minor_status, &accept_token_buffer);
11207c478bd9Sstevel@tonic-gate 			if (status == GSS_S_CONTINUE_NEEDED)
11217c478bd9Sstevel@tonic-gate 				gss_release_buffer(&minor_status,
11227c478bd9Sstevel@tonic-gate 						&init_token_buffer);
11237c478bd9Sstevel@tonic-gate 			gss_release_buffer(&minor_status, &src_name);
11247c478bd9Sstevel@tonic-gate 			return;
11257c478bd9Sstevel@tonic-gate 		}
11267c478bd9Sstevel@tonic-gate 		printf(gettext("src name = %s\n"), src_name_string.value);
11277c478bd9Sstevel@tonic-gate 		gss_release_name(&minor_status, &gss_name);
11287c478bd9Sstevel@tonic-gate 		gss_release_buffer(&minor_status, &src_name_string);
11297c478bd9Sstevel@tonic-gate 		gss_release_buffer(&minor_status, &src_name);
11307c478bd9Sstevel@tonic-gate 
11317c478bd9Sstevel@tonic-gate 		/* print out the mechanism type */
11327c478bd9Sstevel@tonic-gate 
11337c478bd9Sstevel@tonic-gate 		if ((string = gss_oid2str(mech_type)) == 0) {
11347c478bd9Sstevel@tonic-gate 
11357c478bd9Sstevel@tonic-gate 			printf(gettext(
11367c478bd9Sstevel@tonic-gate 				"gssapi internal err :"
11377c478bd9Sstevel@tonic-gate 				" actual mech type null\n"));
11387c478bd9Sstevel@tonic-gate 			accept_sec_context_phase = 0;
11397c478bd9Sstevel@tonic-gate 			status = kgss_delete_sec_context(&minor_status,
11407c478bd9Sstevel@tonic-gate 					&acceptor_context_handle,
11417c478bd9Sstevel@tonic-gate 					&output_token);
11427c478bd9Sstevel@tonic-gate 			gss_release_buffer(&minor_status, &accept_token_buffer);
11437c478bd9Sstevel@tonic-gate 			if (status == GSS_S_CONTINUE_NEEDED)
11447c478bd9Sstevel@tonic-gate 				gss_release_buffer(&minor_status,
11457c478bd9Sstevel@tonic-gate 						&init_token_buffer);
11467c478bd9Sstevel@tonic-gate 			return;
11477c478bd9Sstevel@tonic-gate 		} else {
11487c478bd9Sstevel@tonic-gate 
11497c478bd9Sstevel@tonic-gate 			printf(gettext("actual mech type = %s\n\n"), string);
11507c478bd9Sstevel@tonic-gate 			FREE(string, (mech_type->length+1)*4+1);
11517c478bd9Sstevel@tonic-gate 		}
11527c478bd9Sstevel@tonic-gate 
11537c478bd9Sstevel@tonic-gate 	/* Save and restore the context */
11547c478bd9Sstevel@tonic-gate 	status = kgss_export_sec_context(&minor_status,
11557c478bd9Sstevel@tonic-gate 					&initiator_context_handle,
11567c478bd9Sstevel@tonic-gate 					&context_token);
11577c478bd9Sstevel@tonic-gate 	if (status != GSS_S_COMPLETE) {
11587c478bd9Sstevel@tonic-gate 		printf(gettext("server ret err (octal) %o (%s)\n"),
11597c478bd9Sstevel@tonic-gate 			status, gettext("gss_export_sec_context_error"));
11607c478bd9Sstevel@tonic-gate 		return;
11617c478bd9Sstevel@tonic-gate 	}
11627c478bd9Sstevel@tonic-gate 	status = kgss_import_sec_context(&minor_status,
11637c478bd9Sstevel@tonic-gate 					&context_token,
11647c478bd9Sstevel@tonic-gate 					&initiator_context_handle);
11657c478bd9Sstevel@tonic-gate 	if (status != GSS_S_COMPLETE) {
11667c478bd9Sstevel@tonic-gate 		printf(gettext("server ret err (octal) %o (%s)\n"),
11677c478bd9Sstevel@tonic-gate 			status, gettext("gss_import_sec_context_error"));
11687c478bd9Sstevel@tonic-gate 		return;
11697c478bd9Sstevel@tonic-gate 	}
11707c478bd9Sstevel@tonic-gate 	(void) gss_release_buffer(&minor_status, &context_token);
11717c478bd9Sstevel@tonic-gate 
11727c478bd9Sstevel@tonic-gate 	/* gss_export & gss_import secxc_context worked, return */
11737c478bd9Sstevel@tonic-gate 
11747c478bd9Sstevel@tonic-gate 	/* print out value of ret_flags and time_req */
11757c478bd9Sstevel@tonic-gate 
11767c478bd9Sstevel@tonic-gate 		if (ret_flags & GSS_C_DELEG_FLAG)
11777c478bd9Sstevel@tonic-gate 			printf(gettext("GSS_C_DELEG_FLAG = True\n"));
11787c478bd9Sstevel@tonic-gate 		else
11797c478bd9Sstevel@tonic-gate 			printf(gettext("GSS_C_DELEG_FLAG = False\n"));
11807c478bd9Sstevel@tonic-gate 
11817c478bd9Sstevel@tonic-gate 		if (ret_flags & GSS_C_MUTUAL_FLAG)
11827c478bd9Sstevel@tonic-gate 			printf(gettext("GSS_C_MUTUAL_FLAG = True\n"));
11837c478bd9Sstevel@tonic-gate 		else
11847c478bd9Sstevel@tonic-gate 			printf(gettext("GSS_C_MUTUAL_FLAG = False\n"));
11857c478bd9Sstevel@tonic-gate 
11867c478bd9Sstevel@tonic-gate 		if (ret_flags & GSS_C_REPLAY_FLAG)
11877c478bd9Sstevel@tonic-gate 			printf(gettext("GSS_C_REPLAY_FLAG = True\n"));
11887c478bd9Sstevel@tonic-gate 		else
11897c478bd9Sstevel@tonic-gate 			printf(gettext("GSS_C_REPLAY_FLAG = False\n"));
11907c478bd9Sstevel@tonic-gate 
11917c478bd9Sstevel@tonic-gate 		if (ret_flags & GSS_C_SEQUENCE_FLAG)
11927c478bd9Sstevel@tonic-gate 			printf(gettext("GSS_C_SEQUENCE_FLAG = True\n"));
11937c478bd9Sstevel@tonic-gate 		else
11947c478bd9Sstevel@tonic-gate 			printf(gettext("GSS_C_SEQUENCE_FLAG = False\n"));
11957c478bd9Sstevel@tonic-gate 
11967c478bd9Sstevel@tonic-gate 		if (ret_flags & GSS_C_CONF_FLAG)
11977c478bd9Sstevel@tonic-gate 			printf(gettext("GSS_C_CONF_FLAG = True\n"));
11987c478bd9Sstevel@tonic-gate 		else
11997c478bd9Sstevel@tonic-gate 			printf(gettext("GSS_C_CONF_FLAG = False\n"));
12007c478bd9Sstevel@tonic-gate 
12017c478bd9Sstevel@tonic-gate 		if (ret_flags & GSS_C_INTEG_FLAG)
12027c478bd9Sstevel@tonic-gate 			printf(gettext("GSS_C_INTEG_FLAG = True\n\n"));
12037c478bd9Sstevel@tonic-gate 		else
1204