globus_gssapi_gsi  13.1
globus_i_gsi_gss_utils.h
1 /*
2  * Copyright 1999-2006 University of Chicago
3  *
4  * Licensed under the Apache License, Version 2.0 (the "License");
5  * you may not use this file except in compliance with the License.
6  * You may obtain a copy of the License at
7  *
8  * http://www.apache.org/licenses/LICENSE-2.0
9  *
10  * Unless required by applicable law or agreed to in writing, software
11  * distributed under the License is distributed on an "AS IS" BASIS,
12  * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13  * See the License for the specific language governing permissions and
14  * limitations under the License.
15  */
16 
17 #ifndef GLOBUS_I_GSI_GSS_UTILS_H
18 #define GLOBUS_I_GSI_GSS_UTILS_H
19 
20 #ifndef GLOBUS_DONT_DOCUMENT_INTERNAL
21 
25 #endif
26 
27 #include "gssapi.h"
28 #include "gssapi_openssl.h"
29 
30 /* ERROR MACROS */
31 
32 #define GLOBUS_GSI_GSSAPI_ERROR_RESULT(_MIN_RESULT_, _MIN_, \
33  _ERRSTR_) \
34  if (_MIN_RESULT_ != NULL) \
35  { \
36  char * tmpstr = \
37  globus_common_create_string _ERRSTR_; \
38  *_MIN_RESULT_ = (OM_uint32) globus_i_gsi_gssapi_error_result( \
39  _MIN_, __FILE__, __func__, \
40  __LINE__, tmpstr, NULL); \
41  globus_libc_free(tmpstr); \
42  }
43 
44 #define GLOBUS_GSI_GSSAPI_OPENSSL_ERROR_RESULT(_MIN_RESULT_, \
45  _ERRORTYPE_, _ERRORSTR_) \
46  { \
47  char * tmpstr = \
48  globus_common_create_string _ERRORSTR_; \
49  *_MIN_RESULT_ = \
50  (OM_uint32) globus_i_gsi_gssapi_openssl_error_result( \
51  _ERRORTYPE_, __FILE__, __func__, __LINE__, tmpstr, NULL); \
52  globus_libc_free(tmpstr); \
53  }
54 
55 #define GLOBUS_GSI_GSSAPI_ERROR_CHAIN_RESULT(_MIN_RESULT_, _TOP_RESULT_, \
56  _ERRORTYPE_) \
57  *_MIN_RESULT_ = (OM_uint32) globus_i_gsi_gssapi_error_chain_result( \
58  (globus_result_t)_TOP_RESULT_, \
59  _ERRORTYPE_, __FILE__, \
60  __func__, __LINE__, NULL, NULL)
61 
62 #define GLOBUS_GSI_GSSAPI_LONG_ERROR_RESULT(_MIN_RESULT_, _MIN_, \
63  _ERRSTR_, _LONG_DESC_) \
64  { \
65  char * tmpstr = \
66  globus_common_create_string _ERRSTR_; \
67  *_MIN_RESULT_ = (OM_uint32) globus_i_gsi_gssapi_error_result( \
68  _MIN_, __FILE__, __func__, \
69  __LINE__, tmpstr, _LONG_DESC_); \
70  globus_libc_free(tmpstr); \
71  }
72 
73 #define GLOBUS_GSI_GSSAPI_OPENSSL_LONG_ERROR_RESULT(_MIN_RESULT_, \
74  _ERRORTYPE_, \
75  _ERRORSTR_, \
76  _LONG_DESC_) \
77  { \
78  char * tmpstr = \
79  globus_common_create_string _ERRORSTR_; \
80  *_MIN_RESULT_ = \
81  (OM_uint32) globus_i_gsi_gssapi_openssl_error_result( \
82  _ERRORTYPE_, __FILE__, __func__, \
83  __LINE__, tmpstr, _LONG_DESC_); \
84  globus_libc_free(tmpstr); \
85  }
86 
87 #define GLOBUS_GSI_GSSAPI_LONG_ERROR_CHAIN_RESULT(_MIN_RESULT_, _TOP_RESULT_, \
88  _ERRORTYPE_, _LONG_DESC_) \
89  *_MIN_RESULT_ = (OM_uint32) globus_i_gsi_gssapi_error_chain_result( \
90  (globus_result_t)_TOP_RESULT_, \
91  _ERRORTYPE_, __FILE__, \
92  __func__, __LINE__, NULL, _LONG_DESC_)
93 
94 #define GLOBUS_GSI_GSSAPI_MALLOC_ERROR(_MIN_RESULT_) \
95  { \
96  char * _tmp_str_ = \
97  globus_l_gsi_gssapi_error_strings[ \
98  GLOBUS_GSI_GSSAPI_ERROR_OUT_OF_MEMORY]; \
99  *_MIN_RESULT_ = (OM_uint32) globus_error_put( \
100  globus_error_wrap_errno_error( \
101  GLOBUS_GSI_GSSAPI_MODULE, \
102  errno, \
103  GLOBUS_GSI_GSSAPI_ERROR_OUT_OF_MEMORY, \
104  __FILE__, \
105  __func__, \
106  __LINE__, \
107  "%s", \
108  _tmp_str_)); \
109  }
110 
111 
112 /* DEBUG MACROS */
113 
114 extern int globus_i_gsi_gssapi_debug_level;
115 extern FILE * globus_i_gsi_gssapi_debug_fstream;
116 extern globus_mutex_t globus_i_gssapi_activate_mutex;
117 extern globus_bool_t globus_i_gssapi_active;
118 
119 
120 #ifdef BUILD_DEBUG
121 
122 #define GLOBUS_I_GSI_GSSAPI_DEBUG(_LEVEL_) \
123  (globus_i_gsi_gssapi_debug_level >= (_LEVEL_))
124 
125 #define GLOBUS_I_GSI_GSSAPI_DEBUG_FPRINTF(_LEVEL_, _MESSAGE_) \
126 { \
127  if (GLOBUS_I_GSI_GSSAPI_DEBUG(_LEVEL_)) \
128  { \
129  globus_libc_fprintf _MESSAGE_; \
130  } \
131 }
132 
133 #define GLOBUS_I_GSI_GSSAPI_DEBUG_FNPRINTF(_LEVEL_, _MESSAGE_) \
134 { \
135  if (GLOBUS_I_GSI_GSSAPI_DEBUG(_LEVEL_)) \
136  { \
137  char * _tmp_str_ = \
138  globus_common_create_nstring _MESSAGE_; \
139  globus_libc_fprintf(globus_i_gsi_gssapi_debug_fstream, \
140  "%s", _tmp_str_); \
141  globus_libc_free(_tmp_str_); \
142  } \
143 }
144 
145 #define GLOBUS_I_GSI_GSSAPI_DEBUG_PRINT(_LEVEL_, _MESSAGE_) \
146 { \
147  if (GLOBUS_I_GSI_GSSAPI_DEBUG(_LEVEL_)) \
148  { \
149  globus_libc_fprintf( \
150  globus_i_gsi_gssapi_debug_fstream, \
151  "%s", _MESSAGE_); \
152  } \
153 }
154 
155 #define GLOBUS_I_GSI_GSSAPI_DEBUG_PRINT_OBJECT(_LEVEL_, _TYPE_, _OBJ_) \
156 { \
157  if (GLOBUS_I_GSI_GSSAPI_DEBUG(_LEVEL_)) \
158  { \
159  _TYPE_##_print_fp( \
160  globus_i_gsi_gssapi_debug_fstream, \
161  _OBJ_); \
162  } \
163 }
164 
165 #else
166 
167 #define GLOBUS_I_GSI_GSSAPI_DEBUG(_LEVEL_) 0
168 #define GLOBUS_I_GSI_GSSAPI_DEBUG_FPRINTF(_LEVEL_, _MESSAGE_)
169 #define GLOBUS_I_GSI_GSSAPI_DEBUG_FNPRINTF(_LEVEL_, _MESSAGE_)
170 #define GLOBUS_I_GSI_GSSAPI_DEBUG_PRINT(_LEVEL_, _MESSAGE_)
171 #define GLOBUS_I_GSI_GSSAPI_DEBUG_PRINT_OBJECT(_LEVEL,_TYPE_, _OBJ_)
172 
173 #endif
174 
175 #define GLOBUS_I_GSI_GSSAPI_DEBUG_ENTER \
176  GLOBUS_I_GSI_GSSAPI_DEBUG_FPRINTF( \
177  1, (globus_i_gsi_gssapi_debug_fstream, \
178  "%s entering\n", __func__))
179 
180 #define GLOBUS_I_GSI_GSSAPI_DEBUG_EXIT \
181  GLOBUS_I_GSI_GSSAPI_DEBUG_FPRINTF( \
182  1, (globus_i_gsi_gssapi_debug_fstream, \
183  "%s exiting: major_status=%d\n", \
184  __func__, (int)major_status))
185 
186 #define GLOBUS_I_GSI_GSSAPI_INTERNAL_DEBUG_EXIT \
187  GLOBUS_I_GSI_GSSAPI_DEBUG_FPRINTF( \
188  1, (globus_i_gsi_gssapi_debug_fstream, \
189  "%s exiting\n", \
190  __func__))
191 
192 extern int globus_i_gsi_gssapi_min_tls_protocol;
193 extern int globus_i_gsi_gssapi_max_tls_protocol;
194 extern const char * globus_i_gsi_gssapi_cipher_list;
195 extern globus_bool_t globus_i_gsi_gssapi_server_cipher_order;
196 
197 typedef enum
198 {
199  GLOBUS_I_GSI_GSS_DEFAULT_CONTEXT,
200  GLOBUS_I_GSI_GSS_ANON_CONTEXT
201 } globus_i_gsi_gss_context_type_t;
202 
203 OM_uint32
204 globus_i_gsi_gss_copy_name_to_name(
205  OM_uint32 * minor_status,
206  gss_name_desc ** output,
207  const gss_name_desc * input);
208 
209 OM_uint32
210 globus_i_gsi_gss_create_and_fill_context(
211  OM_uint32 * minor_status,
212  gss_ctx_id_desc ** context_handle,
213  gss_OID mech,
214  const gss_name_t target_name,
215  gss_cred_id_desc * cred_handle,
216  const gss_cred_usage_t cred_usage,
217  OM_uint32 req_flags);
218 
219 OM_uint32
220 globus_i_gsi_gss_create_anonymous_cred(
221  OM_uint32 * minor_status,
222  gss_cred_id_t * output_cred_handle,
223  const gss_cred_usage_t cred_usage);
224 
225 OM_uint32
226 globus_i_gsi_gss_cred_read_bio(
227  OM_uint32 * minor_status,
228  const gss_cred_usage_t cred_usage,
229  gss_cred_id_t * cred_id_handle,
230  BIO * bp);
231 
232 OM_uint32
233 globus_i_gsi_gss_cred_read(
234  OM_uint32 * minor_status,
235  const gss_cred_usage_t cred_usage,
236  gss_cred_id_t * cred_handle,
237  const X509_NAME * desired_subject);
238 
239 OM_uint32
240 globus_i_gsi_gss_create_cred(
241  OM_uint32 * minor_status,
242  const gss_cred_usage_t cred_usage,
243  gss_cred_id_t * output_cred_handle_P,
244  globus_gsi_cred_handle_t * cred_handle);
245 
246 int globus_i_gsi_gss_verify_extensions_callback(
247  globus_gsi_callback_data_t callback_data,
248  X509_EXTENSION * extension);
249 
250 OM_uint32
251 globus_i_gsi_gss_handshake(
252  OM_uint32 * minor_status,
253  gss_ctx_id_desc * context_handle);
254 
255 OM_uint32
256 globus_i_gsi_gss_get_token(
257  OM_uint32 * minor_status,
258  const gss_ctx_id_desc * context_handle,
259  BIO * bio,
260  const gss_buffer_t output_token);
261 
262 OM_uint32
263 globus_i_gsi_gss_put_token(
264  OM_uint32 * minor_status,
265  const gss_ctx_id_desc * context_handle,
266  BIO * bio,
267  const gss_buffer_t input_token);
268 
269 OM_uint32
270 globus_i_gsi_gss_retrieve_peer(
271  OM_uint32 * minor_status,
272  gss_ctx_id_desc * context_handle,
273  const gss_cred_usage_t cred_usage);
274 
275 #if LINK_WITH_INTERNAL_OPENSSL_API
276 OM_uint32
277 globus_i_gsi_gss_SSL_write_bio(
278  OM_uint32 * minor_status,
279  gss_ctx_id_desc * context,
280  BIO * bp);
281 
282 OM_uint32
283 globus_i_gsi_gss_SSL_read_bio(
284  OM_uint32 * minor_status,
285  gss_ctx_id_desc * context,
286  BIO * bp);
287 #endif
288 
289 OM_uint32
290 globus_i_gsi_gss_get_context_goodtill(
291  OM_uint32 * minor_status,
292  gss_ctx_id_t context,
293  time_t * goodtill);
294 
295 OM_uint32
296 globus_i_gsi_gssapi_init_ssl_context(
297  OM_uint32 * minor_status,
298  gss_cred_id_t credential,
299  globus_i_gsi_gss_context_type_t anon_ctx);
300 
301 globus_result_t
302 globus_i_gsi_gssapi_openssl_error_result(
303  int error_type,
304  const char * filename,
305  const char * function_name,
306  int line_number,
307  const char * short_desc,
308  const char * long_desc);
309 
310 globus_result_t
311 globus_i_gsi_gssapi_error_result(
312  const OM_uint32 minor_status,
313  const char * filename,
314  const char * function_name,
315  int line_number,
316  const char * short_desc,
317  const char * long_desc);
318 
319 globus_result_t
320 globus_i_gsi_gssapi_error_chain_result(
321  globus_result_t chain_result,
322  int error_type,
323  const char * filename,
324  const char * function_name,
325  int line_number,
326  const char * short_desc,
327  const char * long_desc);
328 
329 globus_result_t
330 globus_i_gsi_gssapi_error_join_chains_result(
331  globus_result_t outer_error,
332  globus_result_t inner_error);
333 
334 OM_uint32
335 globus_i_gsi_gssapi_get_hostname(
336  OM_uint32 * minor_status,
337  gss_name_desc * name);
338 
339 OM_uint32
340 globus_i_gss_read_vhost_cred_dir(
341  OM_uint32 *minor_status,
342  const char *dirname,
343  gss_cred_id_t **output_credentials_array,
344  size_t *output_credentials_array_count);
345 
346 typedef enum
347 {
348  GSS_I_COMPATIBILITY_HYBRID,
349  GSS_I_COMPATIBILITY_STRICT_GT2,
350  GSS_I_COMPATIBILITY_STRICT_RFC2818
351 }
352 gss_i_name_compatibility_mode_t;
353 
354 extern gss_i_name_compatibility_mode_t gss_i_name_compatibility_mode;
355 
356 #endif /* GLOBUS_I_GSI_GSS_UTILS_H */
GSS API OpenSSL.