globus_gssapi_gsi  12.12
globus_i_gsi_gss_utils.h
1 /*
2  * Copyright 1999-2006 University of Chicago
3  *
4  * Licensed under the Apache License, Version 2.0 (the "License");
5  * you may not use this file except in compliance with the License.
6  * You may obtain a copy of the License at
7  *
8  * http://www.apache.org/licenses/LICENSE-2.0
9  *
10  * Unless required by applicable law or agreed to in writing, software
11  * distributed under the License is distributed on an "AS IS" BASIS,
12  * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13  * See the License for the specific language governing permissions and
14  * limitations under the License.
15  */
16 
17 #ifndef GLOBUS_I_GSI_GSS_UTILS_H
18 #define GLOBUS_I_GSI_GSS_UTILS_H
19 
20 #ifndef GLOBUS_DONT_DOCUMENT_INTERNAL
21 
25 #endif
26 
27 #include "gssapi.h"
28 #include "gssapi_openssl.h"
29 
30 /* ERROR MACROS */
31 
32 #define GLOBUS_GSI_GSSAPI_ERROR_RESULT(_MIN_RESULT_, _MIN_, \
33  _ERRSTR_) \
34  if (_MIN_RESULT_ != NULL) \
35  { \
36  char * tmpstr = \
37  globus_common_create_string _ERRSTR_; \
38  *_MIN_RESULT_ = (OM_uint32) globus_i_gsi_gssapi_error_result( \
39  _MIN_, __FILE__, __func__, \
40  __LINE__, tmpstr, NULL); \
41  globus_libc_free(tmpstr); \
42  }
43 
44 #define GLOBUS_GSI_GSSAPI_OPENSSL_ERROR_RESULT(_MIN_RESULT_, \
45  _ERRORTYPE_, _ERRORSTR_) \
46  { \
47  char * tmpstr = \
48  globus_common_create_string _ERRORSTR_; \
49  *_MIN_RESULT_ = \
50  (OM_uint32) globus_i_gsi_gssapi_openssl_error_result( \
51  _ERRORTYPE_, __FILE__, __func__, __LINE__, tmpstr, NULL); \
52  globus_libc_free(tmpstr); \
53  }
54 
55 #define GLOBUS_GSI_GSSAPI_ERROR_CHAIN_RESULT(_MIN_RESULT_, _TOP_RESULT_, \
56  _ERRORTYPE_) \
57  *_MIN_RESULT_ = (OM_uint32) globus_i_gsi_gssapi_error_chain_result( \
58  (globus_result_t)_TOP_RESULT_, \
59  _ERRORTYPE_, __FILE__, \
60  __func__, __LINE__, NULL, NULL)
61 
62 #define GLOBUS_GSI_GSSAPI_LONG_ERROR_RESULT(_MIN_RESULT_, _MIN_, \
63  _ERRSTR_, _LONG_DESC_) \
64  { \
65  char * tmpstr = \
66  globus_common_create_string _ERRSTR_; \
67  *_MIN_RESULT_ = (OM_uint32) globus_i_gsi_gssapi_error_result( \
68  _MIN_, __FILE__, __func__, \
69  __LINE__, tmpstr, _LONG_DESC_); \
70  globus_libc_free(tmpstr); \
71  }
72 
73 #define GLOBUS_GSI_GSSAPI_OPENSSL_LONG_ERROR_RESULT(_MIN_RESULT_, \
74  _ERRORTYPE_, \
75  _ERRORSTR_, \
76  _LONG_DESC_) \
77  { \
78  char * tmpstr = \
79  globus_common_create_string _ERRORSTR_; \
80  *_MIN_RESULT_ = \
81  (OM_uint32) globus_i_gsi_gssapi_openssl_error_result( \
82  _ERRORTYPE_, __FILE__, __func__, \
83  __LINE__, tmpstr, _LONG_DESC_); \
84  globus_libc_free(tmpstr); \
85  }
86 
87 #define GLOBUS_GSI_GSSAPI_LONG_ERROR_CHAIN_RESULT(_MIN_RESULT_, _TOP_RESULT_, \
88  _ERRORTYPE_, _LONG_DESC_) \
89  *_MIN_RESULT_ = (OM_uint32) globus_i_gsi_gssapi_error_chain_result( \
90  (globus_result_t)_TOP_RESULT_, \
91  _ERRORTYPE_, __FILE__, \
92  __func__, __LINE__, NULL, _LONG_DESC_)
93 
94 #define GLOBUS_GSI_GSSAPI_MALLOC_ERROR(_MIN_RESULT_) \
95  { \
96  char * _tmp_str_ = \
97  globus_l_gsi_gssapi_error_strings[ \
98  GLOBUS_GSI_GSSAPI_ERROR_OUT_OF_MEMORY]; \
99  *_MIN_RESULT_ = (OM_uint32) globus_error_put( \
100  globus_error_wrap_errno_error( \
101  GLOBUS_GSI_GSSAPI_MODULE, \
102  errno, \
103  GLOBUS_GSI_GSSAPI_ERROR_OUT_OF_MEMORY, \
104  __FILE__, \
105  __func__, \
106  __LINE__, \
107  "%s", \
108  _tmp_str_)); \
109  }
110 
111 
112 /* DEBUG MACROS */
113 
114 extern int globus_i_gsi_gssapi_debug_level;
115 extern FILE * globus_i_gsi_gssapi_debug_fstream;
116 extern globus_mutex_t globus_i_gssapi_activate_mutex;
117 extern globus_bool_t globus_i_gssapi_active;
118 
119 
120 #ifdef BUILD_DEBUG
121 
122 #define GLOBUS_I_GSI_GSSAPI_DEBUG(_LEVEL_) \
123  (globus_i_gsi_gssapi_debug_level >= (_LEVEL_))
124 
125 #define GLOBUS_I_GSI_GSSAPI_DEBUG_FPRINTF(_LEVEL_, _MESSAGE_) \
126 { \
127  if (GLOBUS_I_GSI_GSSAPI_DEBUG(_LEVEL_)) \
128  { \
129  globus_libc_fprintf _MESSAGE_; \
130  } \
131 }
132 
133 #define GLOBUS_I_GSI_GSSAPI_DEBUG_FNPRINTF(_LEVEL_, _MESSAGE_) \
134 { \
135  if (GLOBUS_I_GSI_GSSAPI_DEBUG(_LEVEL_)) \
136  { \
137  char * _tmp_str_ = \
138  globus_common_create_nstring _MESSAGE_; \
139  globus_libc_fprintf(globus_i_gsi_gssapi_debug_fstream, \
140  "%s", _tmp_str_); \
141  globus_libc_free(_tmp_str_); \
142  } \
143 }
144 
145 #define GLOBUS_I_GSI_GSSAPI_DEBUG_PRINT(_LEVEL_, _MESSAGE_) \
146 { \
147  if (GLOBUS_I_GSI_GSSAPI_DEBUG(_LEVEL_)) \
148  { \
149  globus_libc_fprintf( \
150  globus_i_gsi_gssapi_debug_fstream, \
151  "%s", _MESSAGE_); \
152  } \
153 }
154 
155 #define GLOBUS_I_GSI_GSSAPI_DEBUG_PRINT_OBJECT(_LEVEL_, _TYPE_, _OBJ_) \
156 { \
157  if (GLOBUS_I_GSI_GSSAPI_DEBUG(_LEVEL_)) \
158  { \
159  _TYPE_##_print_fp( \
160  globus_i_gsi_gssapi_debug_fstream, \
161  _OBJ_); \
162  } \
163 }
164 
165 #else
166 
167 #define GLOBUS_I_GSI_GSSAPI_DEBUG(_LEVEL_) 0
168 #define GLOBUS_I_GSI_GSSAPI_DEBUG_FPRINTF(_LEVEL_, _MESSAGE_)
169 #define GLOBUS_I_GSI_GSSAPI_DEBUG_FNPRINTF(_LEVEL_, _MESSAGE_)
170 #define GLOBUS_I_GSI_GSSAPI_DEBUG_PRINT(_LEVEL_, _MESSAGE_)
171 #define GLOBUS_I_GSI_GSSAPI_DEBUG_PRINT_OBJECT(_LEVEL,_TYPE_, _OBJ_)
172 
173 #endif
174 
175 #define GLOBUS_I_GSI_GSSAPI_DEBUG_ENTER \
176  GLOBUS_I_GSI_GSSAPI_DEBUG_FPRINTF( \
177  1, (globus_i_gsi_gssapi_debug_fstream, \
178  "%s entering\n", __func__))
179 
180 #define GLOBUS_I_GSI_GSSAPI_DEBUG_EXIT \
181  GLOBUS_I_GSI_GSSAPI_DEBUG_FPRINTF( \
182  1, (globus_i_gsi_gssapi_debug_fstream, \
183  "%s exiting: major_status=%d\n", \
184  __func__, (int)major_status))
185 
186 #define GLOBUS_I_GSI_GSSAPI_INTERNAL_DEBUG_EXIT \
187  GLOBUS_I_GSI_GSSAPI_DEBUG_FPRINTF( \
188  1, (globus_i_gsi_gssapi_debug_fstream, \
189  "%s exiting\n", \
190  __func__))
191 
192 extern int globus_i_gsi_gssapi_force_tls;
193 extern const char * globus_i_gsi_gssapi_cipher_list;
194 extern globus_bool_t globus_i_gsi_gssapi_server_cipher_order;
195 
196 typedef enum
197 {
198  GLOBUS_I_GSI_GSS_DEFAULT_CONTEXT,
199  GLOBUS_I_GSI_GSS_ANON_CONTEXT
200 } globus_i_gsi_gss_context_type_t;
201 
202 OM_uint32
203 globus_i_gsi_gss_copy_name_to_name(
204  OM_uint32 * minor_status,
205  gss_name_desc ** output,
206  const gss_name_desc * input);
207 
208 OM_uint32
209 globus_i_gsi_gss_create_and_fill_context(
210  OM_uint32 * minor_status,
211  gss_ctx_id_desc ** context_handle,
212  gss_OID mech,
213  gss_cred_id_desc * cred_handle,
214  const gss_cred_usage_t cred_usage,
215  OM_uint32 req_flags);
216 
217 OM_uint32
218 globus_i_gsi_gss_create_anonymous_cred(
219  OM_uint32 * minor_status,
220  gss_cred_id_t * output_cred_handle,
221  const gss_cred_usage_t cred_usage);
222 
223 OM_uint32
224 globus_i_gsi_gss_cred_read_bio(
225  OM_uint32 * minor_status,
226  const gss_cred_usage_t cred_usage,
227  gss_cred_id_t * cred_id_handle,
228  BIO * bp);
229 
230 OM_uint32
231 globus_i_gsi_gss_cred_read(
232  OM_uint32 * minor_status,
233  const gss_cred_usage_t cred_usage,
234  gss_cred_id_t * cred_handle,
235  const X509_NAME * desired_subject);
236 
237 OM_uint32
238 globus_i_gsi_gss_create_cred(
239  OM_uint32 * minor_status,
240  const gss_cred_usage_t cred_usage,
241  gss_cred_id_t * output_cred_handle_P,
242  globus_gsi_cred_handle_t * cred_handle);
243 
244 int globus_i_gsi_gss_verify_extensions_callback(
245  globus_gsi_callback_data_t callback_data,
246  X509_EXTENSION * extension);
247 
248 OM_uint32
249 globus_i_gsi_gss_handshake(
250  OM_uint32 * minor_status,
251  gss_ctx_id_desc * context_handle);
252 
253 OM_uint32
254 globus_i_gsi_gss_get_token(
255  OM_uint32 * minor_status,
256  const gss_ctx_id_desc * context_handle,
257  BIO * bio,
258  const gss_buffer_t output_token);
259 
260 OM_uint32
261 globus_i_gsi_gss_put_token(
262  OM_uint32 * minor_status,
263  const gss_ctx_id_desc * context_handle,
264  BIO * bio,
265  const gss_buffer_t input_token);
266 
267 OM_uint32
268 globus_i_gsi_gss_retrieve_peer(
269  OM_uint32 * minor_status,
270  gss_ctx_id_desc * context_handle,
271  const gss_cred_usage_t cred_usage);
272 
273 #if LINK_WITH_INTERNAL_OPENSSL_API
274 OM_uint32
275 globus_i_gsi_gss_SSL_write_bio(
276  OM_uint32 * minor_status,
277  gss_ctx_id_desc * context,
278  BIO * bp);
279 
280 OM_uint32
281 globus_i_gsi_gss_SSL_read_bio(
282  OM_uint32 * minor_status,
283  gss_ctx_id_desc * context,
284  BIO * bp);
285 #endif
286 
287 OM_uint32
288 globus_i_gsi_gss_get_context_goodtill(
289  OM_uint32 * minor_status,
290  gss_ctx_id_t context,
291  time_t * goodtill);
292 
293 OM_uint32
294 globus_i_gsi_gssapi_init_ssl_context(
295  OM_uint32 * minor_status,
296  gss_cred_id_t credential,
297  globus_i_gsi_gss_context_type_t anon_ctx);
298 
299 globus_result_t
300 globus_i_gsi_gssapi_openssl_error_result(
301  int error_type,
302  const char * filename,
303  const char * function_name,
304  int line_number,
305  const char * short_desc,
306  const char * long_desc);
307 
308 globus_result_t
309 globus_i_gsi_gssapi_error_result(
310  const OM_uint32 minor_status,
311  const char * filename,
312  const char * function_name,
313  int line_number,
314  const char * short_desc,
315  const char * long_desc);
316 
317 globus_result_t
318 globus_i_gsi_gssapi_error_chain_result(
319  globus_result_t chain_result,
320  int error_type,
321  const char * filename,
322  const char * function_name,
323  int line_number,
324  const char * short_desc,
325  const char * long_desc);
326 
327 globus_result_t
328 globus_i_gsi_gssapi_error_join_chains_result(
329  globus_result_t outer_error,
330  globus_result_t inner_error);
331 
332 OM_uint32
333 globus_i_gsi_gssapi_get_hostname(
334  OM_uint32 * minor_status,
335  gss_name_desc * name);
336 
337 
338 typedef enum
339 {
340  GSS_I_COMPATIBILITY_HYBRID,
341  GSS_I_COMPATIBILITY_STRICT_GT2,
342  GSS_I_COMPATIBILITY_STRICT_RFC2818
343 }
344 gss_i_name_compatibility_mode_t;
345 
346 extern gss_i_name_compatibility_mode_t gss_i_name_compatibility_mode;
347 
348 #endif /* GLOBUS_I_GSI_GSS_UTILS_H */
GSS API OpenSSL.