globus_gssapi_gsi  12.1
globus_i_gsi_gss_utils.h
1 /*
2  * Copyright 1999-2006 University of Chicago
3  *
4  * Licensed under the Apache License, Version 2.0 (the "License");
5  * you may not use this file except in compliance with the License.
6  * You may obtain a copy of the License at
7  *
8  * http://www.apache.org/licenses/LICENSE-2.0
9  *
10  * Unless required by applicable law or agreed to in writing, software
11  * distributed under the License is distributed on an "AS IS" BASIS,
12  * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13  * See the License for the specific language governing permissions and
14  * limitations under the License.
15  */
16 
17 #ifndef GLOBUS_I_GSI_GSS_UTILS_H
18 #define GLOBUS_I_GSI_GSS_UTILS_H
19 
20 #ifndef GLOBUS_DONT_DOCUMENT_INTERNAL
21 
25 #endif
26 
27 #include "gssapi.h"
28 #include "gssapi_openssl.h"
29 
30 /* ERROR MACROS */
31 
32 #define GLOBUS_GSI_GSSAPI_ERROR_RESULT(_MIN_RESULT_, _MIN_, \
33  _ERRSTR_) \
34  if (_MIN_RESULT_ != NULL) \
35  { \
36  char * tmpstr = \
37  globus_common_create_string _ERRSTR_; \
38  *_MIN_RESULT_ = (OM_uint32) globus_i_gsi_gssapi_error_result( \
39  _MIN_, __FILE__, __func__, \
40  __LINE__, tmpstr, NULL); \
41  globus_libc_free(tmpstr); \
42  }
43 
44 #define GLOBUS_GSI_GSSAPI_OPENSSL_ERROR_RESULT(_MIN_RESULT_, \
45  _ERRORTYPE_, _ERRORSTR_) \
46  { \
47  char * tmpstr = \
48  globus_common_create_string _ERRORSTR_; \
49  *_MIN_RESULT_ = \
50  (OM_uint32) globus_i_gsi_gssapi_openssl_error_result( \
51  _ERRORTYPE_, __FILE__, __func__, __LINE__, tmpstr, NULL); \
52  globus_libc_free(tmpstr); \
53  }
54 
55 #define GLOBUS_GSI_GSSAPI_ERROR_CHAIN_RESULT(_MIN_RESULT_, _TOP_RESULT_, \
56  _ERRORTYPE_) \
57  *_MIN_RESULT_ = (OM_uint32) globus_i_gsi_gssapi_error_chain_result( \
58  (globus_result_t)_TOP_RESULT_, \
59  _ERRORTYPE_, __FILE__, \
60  __func__, __LINE__, NULL, NULL)
61 
62 #define GLOBUS_GSI_GSSAPI_LONG_ERROR_RESULT(_MIN_RESULT_, _MIN_, \
63  _ERRSTR_, _LONG_DESC_) \
64  { \
65  char * tmpstr = \
66  globus_common_create_string _ERRSTR_; \
67  *_MIN_RESULT_ = (OM_uint32) globus_i_gsi_gssapi_error_result( \
68  _MIN_, __FILE__, __func__, \
69  __LINE__, tmpstr, _LONG_DESC_); \
70  globus_libc_free(tmpstr); \
71  }
72 
73 #define GLOBUS_GSI_GSSAPI_OPENSSL_LONG_ERROR_RESULT(_MIN_RESULT_, \
74  _ERRORTYPE_, \
75  _ERRORSTR_, \
76  _LONG_DESC_) \
77  { \
78  char * tmpstr = \
79  globus_common_create_string _ERRORSTR_; \
80  *_MIN_RESULT_ = \
81  (OM_uint32) globus_i_gsi_gssapi_openssl_error_result( \
82  _ERRORTYPE_, __FILE__, __func__, \
83  __LINE__, tmpstr, _LONG_DESC_); \
84  globus_libc_free(tmpstr); \
85  }
86 
87 #define GLOBUS_GSI_GSSAPI_LONG_ERROR_CHAIN_RESULT(_MIN_RESULT_, _TOP_RESULT_, \
88  _ERRORTYPE_, _LONG_DESC_) \
89  *_MIN_RESULT_ = (OM_uint32) globus_i_gsi_gssapi_error_chain_result( \
90  (globus_result_t)_TOP_RESULT_, \
91  _ERRORTYPE_, __FILE__, \
92  __func__, __LINE__, NULL, _LONG_DESC_)
93 
94 #define GLOBUS_GSI_GSSAPI_MALLOC_ERROR(_MIN_RESULT_) \
95  { \
96  char * _tmp_str_ = \
97  globus_l_gsi_gssapi_error_strings[ \
98  GLOBUS_GSI_GSSAPI_ERROR_OUT_OF_MEMORY]; \
99  *_MIN_RESULT_ = (OM_uint32) globus_error_put( \
100  globus_error_wrap_errno_error( \
101  GLOBUS_GSI_GSSAPI_MODULE, \
102  errno, \
103  GLOBUS_GSI_GSSAPI_ERROR_OUT_OF_MEMORY, \
104  __FILE__, \
105  __func__, \
106  __LINE__, \
107  "%s", \
108  _tmp_str_)); \
109  }
110 
111 
112 /* DEBUG MACROS */
113 
114 extern int globus_i_gsi_gssapi_debug_level;
115 extern FILE * globus_i_gsi_gssapi_debug_fstream;
116 extern globus_mutex_t globus_i_gssapi_activate_mutex;
117 extern globus_bool_t globus_i_gssapi_active;
118 
119 
120 #ifdef BUILD_DEBUG
121 
122 #define GLOBUS_I_GSI_GSSAPI_DEBUG(_LEVEL_) \
123  (globus_i_gsi_gssapi_debug_level >= (_LEVEL_))
124 
125 #define GLOBUS_I_GSI_GSSAPI_DEBUG_FPRINTF(_LEVEL_, _MESSAGE_) \
126 { \
127  if (GLOBUS_I_GSI_GSSAPI_DEBUG(_LEVEL_)) \
128  { \
129  globus_libc_fprintf _MESSAGE_; \
130  } \
131 }
132 
133 #define GLOBUS_I_GSI_GSSAPI_DEBUG_FNPRINTF(_LEVEL_, _MESSAGE_) \
134 { \
135  if (GLOBUS_I_GSI_GSSAPI_DEBUG(_LEVEL_)) \
136  { \
137  char * _tmp_str_ = \
138  globus_common_create_nstring _MESSAGE_; \
139  globus_libc_fprintf(globus_i_gsi_gssapi_debug_fstream, \
140  "%s", _tmp_str_); \
141  globus_libc_free(_tmp_str_); \
142  } \
143 }
144 
145 #define GLOBUS_I_GSI_GSSAPI_DEBUG_PRINT(_LEVEL_, _MESSAGE_) \
146 { \
147  if (GLOBUS_I_GSI_GSSAPI_DEBUG(_LEVEL_)) \
148  { \
149  globus_libc_fprintf( \
150  globus_i_gsi_gssapi_debug_fstream, \
151  "%s", _MESSAGE_); \
152  } \
153 }
154 
155 #define GLOBUS_I_GSI_GSSAPI_DEBUG_PRINT_OBJECT(_LEVEL_, _TYPE_, _OBJ_) \
156 { \
157  if (GLOBUS_I_GSI_GSSAPI_DEBUG(_LEVEL_)) \
158  { \
159  _TYPE_##_print_fp( \
160  globus_i_gsi_gssapi_debug_fstream, \
161  _OBJ_); \
162  } \
163 }
164 
165 #else
166 
167 #define GLOBUS_I_GSI_GSSAPI_DEBUG(_LEVEL_) 0
168 #define GLOBUS_I_GSI_GSSAPI_DEBUG_FPRINTF(_LEVEL_, _MESSAGE_)
169 #define GLOBUS_I_GSI_GSSAPI_DEBUG_FNPRINTF(_LEVEL_, _MESSAGE_)
170 #define GLOBUS_I_GSI_GSSAPI_DEBUG_PRINT(_LEVEL_, _MESSAGE_)
171 #define GLOBUS_I_GSI_GSSAPI_DEBUG_PRINT_OBJECT(_LEVEL,_TYPE_, _OBJ_)
172 
173 #endif
174 
175 #define GLOBUS_I_GSI_GSSAPI_DEBUG_ENTER \
176  GLOBUS_I_GSI_GSSAPI_DEBUG_FPRINTF( \
177  1, (globus_i_gsi_gssapi_debug_fstream, \
178  "%s entering\n", __func__))
179 
180 #define GLOBUS_I_GSI_GSSAPI_DEBUG_EXIT \
181  GLOBUS_I_GSI_GSSAPI_DEBUG_FPRINTF( \
182  1, (globus_i_gsi_gssapi_debug_fstream, \
183  "%s exiting: major_status=%d\n", \
184  __func__, (int)major_status))
185 
186 #define GLOBUS_I_GSI_GSSAPI_INTERNAL_DEBUG_EXIT \
187  GLOBUS_I_GSI_GSSAPI_DEBUG_FPRINTF( \
188  1, (globus_i_gsi_gssapi_debug_fstream, \
189  "%s exiting\n", \
190  __func__))
191 
192 extern int globus_i_gsi_gssapi_force_tls;
193 extern const char * globus_i_gsi_gssapi_cipher_list;
194 extern globus_bool_t globus_i_gsi_gssapi_server_cipher_order;
195 
196 typedef enum
197 {
198  GLOBUS_I_GSI_GSS_DEFAULT_CONTEXT,
199  GLOBUS_I_GSI_GSS_ANON_CONTEXT
200 } globus_i_gsi_gss_context_type_t;
201 
202 OM_uint32
203 globus_i_gsi_gss_copy_name_to_name(
204  OM_uint32 * minor_status,
205  gss_name_desc ** output,
206  const gss_name_desc * input);
207 
208 OM_uint32
209 globus_i_gsi_gss_create_and_fill_context(
210  OM_uint32 * minor_status,
211  gss_ctx_id_desc ** context_handle,
212  gss_cred_id_desc * cred_handle,
213  const gss_cred_usage_t cred_usage,
214  OM_uint32 req_flags);
215 
216 OM_uint32
217 globus_i_gsi_gss_create_anonymous_cred(
218  OM_uint32 * minor_status,
219  gss_cred_id_t * output_cred_handle,
220  const gss_cred_usage_t cred_usage);
221 
222 OM_uint32
223 globus_i_gsi_gss_cred_read_bio(
224  OM_uint32 * minor_status,
225  const gss_cred_usage_t cred_usage,
226  gss_cred_id_t * cred_id_handle,
227  BIO * bp);
228 
229 OM_uint32
230 globus_i_gsi_gss_cred_read(
231  OM_uint32 * minor_status,
232  const gss_cred_usage_t cred_usage,
233  gss_cred_id_t * cred_handle,
234  const X509_NAME * desired_subject);
235 
236 OM_uint32
237 globus_i_gsi_gss_create_cred(
238  OM_uint32 * minor_status,
239  const gss_cred_usage_t cred_usage,
240  gss_cred_id_t * output_cred_handle_P,
241  globus_gsi_cred_handle_t * cred_handle);
242 
243 int globus_i_gsi_gss_verify_extensions_callback(
244  globus_gsi_callback_data_t callback_data,
245  X509_EXTENSION * extension);
246 
247 OM_uint32
248 globus_i_gsi_gss_handshake(
249  OM_uint32 * minor_status,
250  gss_ctx_id_desc * context_handle);
251 
252 OM_uint32
253 globus_i_gsi_gss_get_token(
254  OM_uint32 * minor_status,
255  const gss_ctx_id_desc * context_handle,
256  BIO * bio,
257  const gss_buffer_t output_token);
258 
259 OM_uint32
260 globus_i_gsi_gss_put_token(
261  OM_uint32 * minor_status,
262  const gss_ctx_id_desc * context_handle,
263  BIO * bio,
264  const gss_buffer_t input_token);
265 
266 OM_uint32
267 globus_i_gsi_gss_retrieve_peer(
268  OM_uint32 * minor_status,
269  gss_ctx_id_desc * context_handle,
270  const gss_cred_usage_t cred_usage);
271 
272 #if LINK_WITH_INTERNAL_OPENSSL_API
273 OM_uint32
274 globus_i_gsi_gss_SSL_write_bio(
275  OM_uint32 * minor_status,
276  gss_ctx_id_desc * context,
277  BIO * bp);
278 
279 OM_uint32
280 globus_i_gsi_gss_SSL_read_bio(
281  OM_uint32 * minor_status,
282  gss_ctx_id_desc * context,
283  BIO * bp);
284 #endif
285 
286 OM_uint32
287 globus_i_gsi_gss_get_context_goodtill(
288  OM_uint32 * minor_status,
289  gss_ctx_id_t context,
290  time_t * goodtill);
291 
292 OM_uint32
293 globus_i_gsi_gssapi_init_ssl_context(
294  OM_uint32 * minor_status,
295  gss_cred_id_t credential,
296  globus_i_gsi_gss_context_type_t anon_ctx);
297 
298 globus_result_t
299 globus_i_gsi_gssapi_openssl_error_result(
300  int error_type,
301  const char * filename,
302  const char * function_name,
303  int line_number,
304  const char * short_desc,
305  const char * long_desc);
306 
307 globus_result_t
308 globus_i_gsi_gssapi_error_result(
309  const OM_uint32 minor_status,
310  const char * filename,
311  const char * function_name,
312  int line_number,
313  const char * short_desc,
314  const char * long_desc);
315 
316 globus_result_t
317 globus_i_gsi_gssapi_error_chain_result(
318  globus_result_t chain_result,
319  int error_type,
320  const char * filename,
321  const char * function_name,
322  int line_number,
323  const char * short_desc,
324  const char * long_desc);
325 
326 globus_result_t
327 globus_i_gsi_gssapi_error_join_chains_result(
328  globus_result_t outer_error,
329  globus_result_t inner_error);
330 
331 OM_uint32
332 globus_i_gsi_gssapi_get_hostname(
333  OM_uint32 * minor_status,
334  gss_name_desc * name);
335 
336 
337 typedef enum
338 {
339  GSS_I_COMPATIBILITY_HYBRID,
340  GSS_I_COMPATIBILITY_STRICT_GT2,
341  GSS_I_COMPATIBILITY_STRICT_RFC2818
342 }
343 gss_i_name_compatibility_mode_t;
344 
345 extern gss_i_name_compatibility_mode_t gss_i_name_compatibility_mode;
346 
347 #endif /* GLOBUS_I_GSI_GSS_UTILS_H */
GSS API OpenSSL.