From 4f5791ebd03eaec1c7da0865a383175b05102712 Mon Sep 17 00:00:00 2001 From: Daniel Baumann Date: Sun, 5 May 2024 19:47:29 +0200 Subject: Adding upstream version 2:4.17.12+dfsg. Signed-off-by: Daniel Baumann --- source4/kdc/kdc-glue.c | 65 ++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 65 insertions(+) create mode 100644 source4/kdc/kdc-glue.c (limited to 'source4/kdc/kdc-glue.c') diff --git a/source4/kdc/kdc-glue.c b/source4/kdc/kdc-glue.c new file mode 100644 index 0000000..671e506 --- /dev/null +++ b/source4/kdc/kdc-glue.c @@ -0,0 +1,65 @@ +/* + Unix SMB/CIFS implementation. + + PAC Glue between Samba and the KDC + + Copyright (C) Andrew Bartlett 2005-2009 + Copyright (C) Simo Sorce 2010 + + This program is free software; you can redistribute it and/or modify + it under the terms of the GNU General Public License as published by + the Free Software Foundation; either version 3 of the License, or + (at your option) any later version. + + This program is distributed in the hope that it will be useful, + but WITHOUT ANY WARRANTY; without even the implied warranty of + MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the + GNU General Public License for more details. + + + You should have received a copy of the GNU General Public License + along with this program. If not, see . +*/ + +#include "includes.h" +#include "system/kerberos.h" +#include "auth/kerberos/kerberos.h" +#include +#include "kdc/samba_kdc.h" +#include "kdc/pac-glue.h" +#include "librpc/gen_ndr/ndr_krb5pac.h" +#include "auth/kerberos/pac_utils.h" +#include "kdc/kdc-glue.h" + +int kdc_check_pac(krb5_context context, + DATA_BLOB srv_sig, + struct PAC_SIGNATURE_DATA *kdc_sig, + hdb_entry *ent) +{ + krb5_enctype etype; + int ret; + krb5_keyblock keyblock; + Key *key; + + if (kdc_sig->type == CKSUMTYPE_HMAC_MD5) { + etype = ENCTYPE_ARCFOUR_HMAC; + } else { + ret = krb5_cksumtype_to_enctype(context, + kdc_sig->type, + &etype); + if (ret != 0) { + return ret; + } + } + + ret = hdb_enctype2key(context, ent, NULL, etype, &key); + + if (ret != 0) { + return ret; + } + + keyblock = key->key; + + return check_pac_checksum(srv_sig, kdc_sig, + context, &keyblock); +} -- cgit v1.2.3