]> git.decadent.org.uk Git - nfs-utils.git/blob - utils/gssd/krb5_util.h
gssd: Allow GSSAPI to try to acquire credentials first.
[nfs-utils.git] / utils / gssd / krb5_util.h
1 #ifndef KRB5_UTIL_H
2 #define KRB5_UTIL_H
3
4 #include <krb5.h>
5
6 #ifdef HAVE_LIBTIRPC
7 #include <rpc/auth_gss.h>
8 #else
9 #include "gss_oids.h"
10 #endif
11
12 /*
13  * List of principals from our keytab that we
14  * will try to use to obtain credentials
15  * (known as a principal list entry (ple))
16  */
17 struct gssd_k5_kt_princ {
18         struct gssd_k5_kt_princ *next;
19         krb5_principal princ;
20         char *ccname;
21         char *realm;
22         krb5_timestamp endtime;
23 };
24
25
26 int gssd_setup_krb5_user_gss_ccache(uid_t uid, char *servername,
27                                      char *dirname);
28 int  gssd_get_krb5_machine_cred_list(char ***list);
29 void gssd_free_krb5_machine_cred_list(char **list);
30 void gssd_setup_krb5_machine_gss_ccache(char *servername);
31 void gssd_destroy_krb5_machine_creds(void);
32 int  gssd_refresh_krb5_machine_credential(char *hostname,
33                                           struct gssd_k5_kt_princ *ple, 
34                                           char *service,
35                                           char *tgtname);
36 char *gssd_k5_err_msg(krb5_context context, krb5_error_code code);
37 void gssd_k5_get_default_realm(char **def_realm);
38
39 int gssd_acquire_user_cred(uid_t uid, gss_cred_id_t *gss_cred);
40
41 #ifdef HAVE_SET_ALLOWABLE_ENCTYPES
42 extern int limit_to_legacy_enctypes;
43 int limit_krb5_enctypes(struct rpc_gss_sec *sec);
44 #endif
45
46 /*
47  * Hide away some of the MIT vs. Heimdal differences
48  * here with macros...
49  */
50
51 #ifdef HAVE_KRB5
52 #define k5_free_unparsed_name(ctx, name)        krb5_free_unparsed_name((ctx), (name))
53 #define k5_free_default_realm(ctx, realm)       krb5_free_default_realm((ctx), (realm))
54 #define k5_free_kt_entry(ctx, kte)              krb5_free_keytab_entry_contents((ctx),(kte))
55 #else   /* Heimdal */
56 #define k5_free_unparsed_name(ctx, name)        free(name)
57 #define k5_free_default_realm(ctx, realm)       free(realm)
58 #define k5_free_kt_entry(ctx, kte)              krb5_kt_free_entry((ctx),(kte))
59 #undef USE_GSS_KRB5_CCACHE_NAME
60 #define USE_GSS_KRB5_CCACHE_NAME 1
61 #endif
62
63 #endif /* KRB5_UTIL_H */