1*c19800e8SDoug Rabson2008-08-14 Love Hornquist Astrand <[email protected]> 21c43270aSJacques Vidrine 3*c19800e8SDoug Rabson * krb5/accept_sec_context.c: If there is a initiator subkey, copy 4*c19800e8SDoug Rabson that to acceptor subkey to match windows behavior. From Metze. 5*c19800e8SDoug Rabson 6*c19800e8SDoug Rabson2008-08-02 Love Hörnquist Åstrand <[email protected]> 7*c19800e8SDoug Rabson 8*c19800e8SDoug Rabson * ntlm/init_sec_context.c: Catch error 9*c19800e8SDoug Rabson 10*c19800e8SDoug Rabson * krb5/inquire_sec_context_by_oid.c: Catch store failure. 11*c19800e8SDoug Rabson 12*c19800e8SDoug Rabson * mech/gss_canonicalize_name.c: Not init m, return never 13*c19800e8SDoug Rabson used (overwritten later). 14*c19800e8SDoug Rabson 15*c19800e8SDoug Rabson2008-07-25 Love Hörnquist Åstrand <[email protected]> 16*c19800e8SDoug Rabson 17*c19800e8SDoug Rabson * ntlm/init_sec_context.c: Use krb5_cc_get_config. 18*c19800e8SDoug Rabson 19*c19800e8SDoug Rabson2008-07-25 Love Hörnquist Åstrand <[email protected]> 20*c19800e8SDoug Rabson 21*c19800e8SDoug Rabson * krb5/init_sec_context.c: Match the orignal patch I got from 22*c19800e8SDoug Rabson metze, seems that DCE-STYLE is even more weirer then what I though 23*c19800e8SDoug Rabson when I merged the patch. 24*c19800e8SDoug Rabson 25*c19800e8SDoug Rabson2008-06-02 Love Hörnquist Åstrand <[email protected]> 26*c19800e8SDoug Rabson 27*c19800e8SDoug Rabson * krb5/init_sec_context.c: Don't add asn1 wrapping to token when 28*c19800e8SDoug Rabson using DCE_STYLE. Patch from Stefan Metzmacher. 29*c19800e8SDoug Rabson 30*c19800e8SDoug Rabson2008-05-27 Love Hörnquist Åstrand <[email protected]> 31*c19800e8SDoug Rabson 32*c19800e8SDoug Rabson * ntlm/init_sec_context.c: use krb5_get_error_message 33*c19800e8SDoug Rabson 34*c19800e8SDoug Rabson2008-05-05 Love Hörnquist Åstrand <[email protected]> 35*c19800e8SDoug Rabson 36*c19800e8SDoug Rabson * spnego/spnego_locl.h: Add back "mech/utils.h", its needed for 37*c19800e8SDoug Rabson oid/buffer functions. 38*c19800e8SDoug Rabson 39*c19800e8SDoug Rabson2008-05-02 Love Hörnquist Åstrand <[email protected]> 40*c19800e8SDoug Rabson 41*c19800e8SDoug Rabson * spnego: Changes from doug barton to make spnego indepedant of 42*c19800e8SDoug Rabson the heimdal version of the plugin system. 43*c19800e8SDoug Rabson 44*c19800e8SDoug Rabson2008-04-27 Love Hörnquist Åstrand <[email protected]> 45*c19800e8SDoug Rabson 46*c19800e8SDoug Rabson * krb5: use DES_set_key_unchecked() 47*c19800e8SDoug Rabson 48*c19800e8SDoug Rabson2008-04-17 Love Hörnquist Åstrand <[email protected]> 49*c19800e8SDoug Rabson 50*c19800e8SDoug Rabson * add __declspec() for windows. 51*c19800e8SDoug Rabson 52*c19800e8SDoug Rabson2008-04-15 Love Hörnquist Åstrand <[email protected]> 53*c19800e8SDoug Rabson 54*c19800e8SDoug Rabson * krb5/import_sec_context.c: Use tmp to read ac->flags value to 55*c19800e8SDoug Rabson avoid warning. 56*c19800e8SDoug Rabson 57*c19800e8SDoug Rabson2008-04-07 Love Hörnquist Åstrand <[email protected]> 58*c19800e8SDoug Rabson 59*c19800e8SDoug Rabson * mech/gss_mech_switch.c: Use unsigned where appropriate. 60*c19800e8SDoug Rabson 61*c19800e8SDoug Rabson2008-03-14 Love Hörnquist Åstrand <[email protected]> 62*c19800e8SDoug Rabson 63*c19800e8SDoug Rabson * test_context.c: Add test for gsskrb5_register_acceptor_identity. 64*c19800e8SDoug Rabson 65*c19800e8SDoug Rabson2008-03-09 Love Hörnquist Åstrand <[email protected]> 66*c19800e8SDoug Rabson 67*c19800e8SDoug Rabson * krb5/init_sec_context.c (init_auth): use right variable to 68*c19800e8SDoug Rabson detect if we want to free or not. 69*c19800e8SDoug Rabson 70*c19800e8SDoug Rabson2008-02-26 Love Hörnquist Åstrand <[email protected]> 71*c19800e8SDoug Rabson 72*c19800e8SDoug Rabson * Makefile.am: add missing \ 73*c19800e8SDoug Rabson 74*c19800e8SDoug Rabson * Makefile.am: reshuffle depenencies 75*c19800e8SDoug Rabson 76*c19800e8SDoug Rabson * Add flag to krb5 to not add GSS-API INT|CONF to the negotiation 77*c19800e8SDoug Rabson 78*c19800e8SDoug Rabson2008-02-21 Love Hörnquist Åstrand <[email protected]> 79*c19800e8SDoug Rabson 80*c19800e8SDoug Rabson * make the SPNEGO mech store the error itself instead, works for 81*c19800e8SDoug Rabson everything except other stackable mechs 82*c19800e8SDoug Rabson 83*c19800e8SDoug Rabson2008-02-18 Love Hörnquist Åstrand <[email protected]> 84*c19800e8SDoug Rabson 85*c19800e8SDoug Rabson * spnego/init_sec_context.c (spnego_reply): if the reply token was 86*c19800e8SDoug Rabson of length 0, make it the same as no token. Pointed out by Zeqing 87*c19800e8SDoug Rabson Xia. 88*c19800e8SDoug Rabson 89*c19800e8SDoug Rabson * krb5/acquire_cred.c (acquire_initiator_cred): handle the 90*c19800e8SDoug Rabson credential cache better, use destroy/close when appriate and for 91*c19800e8SDoug Rabson all cases. Thanks to Michael Allen for point out the memory-leak 92*c19800e8SDoug Rabson that I also fixed. 93*c19800e8SDoug Rabson 94*c19800e8SDoug Rabson2008-02-03 Love Hörnquist Åstrand <[email protected]> 95*c19800e8SDoug Rabson 96*c19800e8SDoug Rabson * spnego/accept_sec_context.c: Make error reporting somewhat more 97*c19800e8SDoug Rabson correct for SPNEGO. 98*c19800e8SDoug Rabson 99*c19800e8SDoug Rabson2008-01-27 Love Hörnquist Åstrand <[email protected]> 100*c19800e8SDoug Rabson 101*c19800e8SDoug Rabson * test_common.c: Improve the error message. 102*c19800e8SDoug Rabson 103*c19800e8SDoug Rabson2008-01-24 Love Hörnquist Åstrand <[email protected]> 104*c19800e8SDoug Rabson 105*c19800e8SDoug Rabson * ntlm/accept_sec_context.c: Avoid free-ing type1 message before 106*c19800e8SDoug Rabson its allocated. 107*c19800e8SDoug Rabson 108*c19800e8SDoug Rabson2008-01-13 Love Hörnquist Åstrand <[email protected]> 109*c19800e8SDoug Rabson 110*c19800e8SDoug Rabson * test_ntlm.c: Test source name (and make the acceptor in ntlm gss 111*c19800e8SDoug Rabson mech useful). 112*c19800e8SDoug Rabson 113*c19800e8SDoug Rabson2007-12-30 Love Hörnquist Åstrand <[email protected]> 114*c19800e8SDoug Rabson 115*c19800e8SDoug Rabson * ntlm/init_sec_context.c: Don't confuse target name and source 116*c19800e8SDoug Rabson name, make regressiont tests pass again. 117*c19800e8SDoug Rabson 118*c19800e8SDoug Rabson2007-12-29 Love Hörnquist Åstrand <[email protected]> 119*c19800e8SDoug Rabson 120*c19800e8SDoug Rabson * ntlm: clean up name handling 121*c19800e8SDoug Rabson 122*c19800e8SDoug Rabson2007-12-04 Love Hörnquist Åstrand <[email protected]> 123*c19800e8SDoug Rabson 124*c19800e8SDoug Rabson * ntlm/init_sec_context.c: Use credential if it was passed in. 125*c19800e8SDoug Rabson 126*c19800e8SDoug Rabson * ntlm/acquire_cred.c: Check if there is initial creds with 127*c19800e8SDoug Rabson _gss_ntlm_get_user_cred(). 128*c19800e8SDoug Rabson 129*c19800e8SDoug Rabson * ntlm/init_sec_context.c: Add _gss_ntlm_get_user_info() that 130*c19800e8SDoug Rabson return the user info so it can be used by external modules. 131*c19800e8SDoug Rabson 132*c19800e8SDoug Rabson * ntlm/inquire_cred.c: use the right error code. 133*c19800e8SDoug Rabson 134*c19800e8SDoug Rabson * ntlm/inquire_cred.c: Return GSS_C_NO_CREDENTIAL if there is no 135*c19800e8SDoug Rabson credential, ntlm have (not yet) a default credential. 136*c19800e8SDoug Rabson 137*c19800e8SDoug Rabson * mech/gss_release_oid_set.c: Avoid trying to deref NULL, from 138*c19800e8SDoug Rabson Phil Fisher. 139*c19800e8SDoug Rabson 140*c19800e8SDoug Rabson2007-12-03 Love Hörnquist Åstrand <[email protected]> 141*c19800e8SDoug Rabson 142*c19800e8SDoug Rabson * test_acquire_cred.c: Always try to fetch cred (even with 143*c19800e8SDoug Rabson GSS_C_NO_NAME). 144*c19800e8SDoug Rabson 145*c19800e8SDoug Rabson2007-08-09 Love Hörnquist Åstrand <[email protected]> 146*c19800e8SDoug Rabson 147*c19800e8SDoug Rabson * mech/gss_krb5.c: Readd gss_krb5_get_tkt_flags. 148*c19800e8SDoug Rabson 149*c19800e8SDoug Rabson2007-08-08 Love Hörnquist Åstrand <[email protected]> 150*c19800e8SDoug Rabson 151*c19800e8SDoug Rabson * spnego/compat.c (_gss_spnego_internal_delete_sec_context): 152*c19800e8SDoug Rabson release ctx->target_name too From Rafal Malinowski. 153*c19800e8SDoug Rabson 154*c19800e8SDoug Rabson2007-07-26 Love Hörnquist Åstrand <[email protected]> 155*c19800e8SDoug Rabson 156*c19800e8SDoug Rabson * mech/gss_mech_switch.c: Don't try to do dlopen if system doesn't 157*c19800e8SDoug Rabson have dlopen. From Rune of Chalmers. 158*c19800e8SDoug Rabson 159*c19800e8SDoug Rabson2007-07-10 Love Hörnquist Åstrand <[email protected]> 160*c19800e8SDoug Rabson 161*c19800e8SDoug Rabson * mech/gss_duplicate_name.c: New signature of _gss_find_mn. 162*c19800e8SDoug Rabson 163*c19800e8SDoug Rabson * mech/gss_init_sec_context.c: New signature of _gss_find_mn. 164*c19800e8SDoug Rabson 165*c19800e8SDoug Rabson * mech/gss_acquire_cred.c: New signature of _gss_find_mn. 166*c19800e8SDoug Rabson 167*c19800e8SDoug Rabson * mech/name.h: New signature of _gss_find_mn. 168*c19800e8SDoug Rabson 169*c19800e8SDoug Rabson * mech/gss_canonicalize_name.c: New signature of _gss_find_mn. 170*c19800e8SDoug Rabson 171*c19800e8SDoug Rabson * mech/gss_compare_name.c: New signature of _gss_find_mn. 172*c19800e8SDoug Rabson 173*c19800e8SDoug Rabson * mech/gss_add_cred.c: New signature of _gss_find_mn. 174*c19800e8SDoug Rabson 175*c19800e8SDoug Rabson * mech/gss_names.c (_gss_find_mn): Return an error code for 176*c19800e8SDoug Rabson caller. 177*c19800e8SDoug Rabson 178*c19800e8SDoug Rabson * spnego/accept_sec_context.c: remove checks that are done by the 179*c19800e8SDoug Rabson previous function. 180*c19800e8SDoug Rabson 181*c19800e8SDoug Rabson * Makefile.am: New library version. 182*c19800e8SDoug Rabson 183*c19800e8SDoug Rabson2007-07-04 Love Hörnquist Åstrand <[email protected]> 184*c19800e8SDoug Rabson 185*c19800e8SDoug Rabson * mech/gss_oid_to_str.c: Refuse to print GSS_C_NULL_OID, from 186*c19800e8SDoug Rabson Rafal Malinowski. 187*c19800e8SDoug Rabson 188*c19800e8SDoug Rabson * spnego/spnego.asn1: Indent and make NegTokenInit and 189*c19800e8SDoug Rabson NegTokenResp extendable. 190*c19800e8SDoug Rabson 191*c19800e8SDoug Rabson2007-06-21 Love Hörnquist Åstrand <[email protected]> 192*c19800e8SDoug Rabson 193*c19800e8SDoug Rabson * ntlm/inquire_cred.c: Implement _gss_ntlm_inquire_cred. 194*c19800e8SDoug Rabson 195*c19800e8SDoug Rabson * mech/gss_display_status.c: Provide message for GSS_S_COMPLETE. 196*c19800e8SDoug Rabson 197*c19800e8SDoug Rabson * mech/context.c: If the canned string is "", its no use to the 198*c19800e8SDoug Rabson user, make it fall back to the default error string. 199*c19800e8SDoug Rabson 200*c19800e8SDoug Rabson2007-06-20 Love Hörnquist Åstrand <[email protected]> 201*c19800e8SDoug Rabson 202*c19800e8SDoug Rabson * mech/gss_display_name.c (gss_display_name): no name -> 203*c19800e8SDoug Rabson fail. From Rafal Malinswski. 204*c19800e8SDoug Rabson 205*c19800e8SDoug Rabson * spnego/accept_sec_context.c: Wrap name in a spnego_name instead 206*c19800e8SDoug Rabson of just a copy of the underlaying object. From Rafal Malinswski. 207*c19800e8SDoug Rabson 208*c19800e8SDoug Rabson * spnego/accept_sec_context.c: Handle underlaying mech not 209*c19800e8SDoug Rabson returning mn. 210*c19800e8SDoug Rabson 211*c19800e8SDoug Rabson * mech/gss_accept_sec_context.c: Handle underlaying mech not 212*c19800e8SDoug Rabson returning mn. 213*c19800e8SDoug Rabson 214*c19800e8SDoug Rabson * spnego/accept_sec_context.c: Make sure src_name is always set to 215*c19800e8SDoug Rabson GSS_C_NO_NAME when returning. 216*c19800e8SDoug Rabson 217*c19800e8SDoug Rabson * krb5/acquire_cred.c (acquire_acceptor_cred): don't claim 218*c19800e8SDoug Rabson everything is well on failure. From Phil Fisher. 219*c19800e8SDoug Rabson 220*c19800e8SDoug Rabson * mech/gss_duplicate_name.c: catch error (and ignore it) 221*c19800e8SDoug Rabson 222*c19800e8SDoug Rabson * ntlm/init_sec_context.c: Use heim_ntlm_calculate_ntlm2_sess. 223*c19800e8SDoug Rabson 224*c19800e8SDoug Rabson * mech/gss_accept_sec_context.c: Only wrap the delegated cred if 225*c19800e8SDoug Rabson we got a delegated mech cred. From Rafal Malinowski. 226*c19800e8SDoug Rabson 227*c19800e8SDoug Rabson * spnego/accept_sec_context.c: Only wrap the delegated cred if we 228*c19800e8SDoug Rabson are going to return it to the consumer. From Rafal Malinowski. 229*c19800e8SDoug Rabson 230*c19800e8SDoug Rabson * spnego/accept_sec_context.c: Fixed memory leak pointed out by 231*c19800e8SDoug Rabson Rafal Malinowski, also while here moved to use NegotiationToken 232*c19800e8SDoug Rabson for decoding. 233*c19800e8SDoug Rabson 234*c19800e8SDoug Rabson2007-06-18 Love Hörnquist Åstrand <[email protected]> 235*c19800e8SDoug Rabson 236*c19800e8SDoug Rabson * krb5/prf.c (_gsskrb5_pseudo_random): add missing break. 237*c19800e8SDoug Rabson 238*c19800e8SDoug Rabson * krb5/release_name.c: Set *minor_status unconditionallty, its 239*c19800e8SDoug Rabson done later anyway. 240*c19800e8SDoug Rabson 241*c19800e8SDoug Rabson * spnego/accept_sec_context.c: Init get_mic to 0. 242*c19800e8SDoug Rabson 243*c19800e8SDoug Rabson * mech/gss_set_cred_option.c: Free memory in failure case, found 244*c19800e8SDoug Rabson by beam. 245*c19800e8SDoug Rabson 246*c19800e8SDoug Rabson * mech/gss_inquire_context.c: Handle mech_type being NULL. 247*c19800e8SDoug Rabson 248*c19800e8SDoug Rabson * mech/gss_inquire_cred_by_mech.c: Handle cred_name being NULL. 249*c19800e8SDoug Rabson 250*c19800e8SDoug Rabson * mech/gss_krb5.c: Free memory in error case, found by beam. 251*c19800e8SDoug Rabson 252*c19800e8SDoug Rabson2007-06-12 Love Hörnquist Åstrand <[email protected]> 253*c19800e8SDoug Rabson 254*c19800e8SDoug Rabson * ntlm/inquire_context.c: Use ctx->gssflags for flags. 255*c19800e8SDoug Rabson 256*c19800e8SDoug Rabson * krb5/display_name.c: Use KRB5_PRINCIPAL_UNPARSE_DISPLAY, this is 257*c19800e8SDoug Rabson not ment for machine consumption. 258*c19800e8SDoug Rabson 259*c19800e8SDoug Rabson2007-06-09 Love Hörnquist Åstrand <[email protected]> 260*c19800e8SDoug Rabson 261*c19800e8SDoug Rabson * ntlm/digest.c (kdc_alloc): free memory on failure, pointed out 262*c19800e8SDoug Rabson by Rafal Malinowski. 263*c19800e8SDoug Rabson 264*c19800e8SDoug Rabson * ntlm/digest.c (kdc_destroy): free context when done, pointed out 265*c19800e8SDoug Rabson by Rafal Malinowski. 266*c19800e8SDoug Rabson 267*c19800e8SDoug Rabson * spnego/context_stubs.c (_gss_spnego_display_name): if input_name 268*c19800e8SDoug Rabson is null, fail. From Rafal Malinowski. 269*c19800e8SDoug Rabson 270*c19800e8SDoug Rabson2007-06-04 Love Hörnquist Åstrand <[email protected]> 271*c19800e8SDoug Rabson 272*c19800e8SDoug Rabson * ntlm/digest.c: Free memory when done. 273*c19800e8SDoug Rabson 274*c19800e8SDoug Rabson2007-06-02 Love Hörnquist Åstrand <[email protected]> 275*c19800e8SDoug Rabson 276*c19800e8SDoug Rabson * test_ntlm.c: Test both with and without keyex. 277*c19800e8SDoug Rabson 278*c19800e8SDoug Rabson * ntlm/digest.c: If we didn't set session key, don't expect one 279*c19800e8SDoug Rabson back. 280*c19800e8SDoug Rabson 281*c19800e8SDoug Rabson * test_ntlm.c: Set keyex flag and calculate session key. 282*c19800e8SDoug Rabson 283*c19800e8SDoug Rabson2007-05-31 Love Hörnquist Åstrand <[email protected]> 284*c19800e8SDoug Rabson 285*c19800e8SDoug Rabson * spnego/accept_sec_context.c: Use the return value before is 286*c19800e8SDoug Rabson overwritten by later calls. From Rafal Malinowski 287*c19800e8SDoug Rabson 288*c19800e8SDoug Rabson * krb5/release_cred.c: Give an minor_status argument to 289*c19800e8SDoug Rabson gss_release_oid_set. From Rafal Malinowski 290*c19800e8SDoug Rabson 291*c19800e8SDoug Rabson2007-05-30 Love Hörnquist Åstrand <[email protected]> 292*c19800e8SDoug Rabson 293*c19800e8SDoug Rabson * ntlm/accept_sec_context.c: Catch errors and return the up the 294*c19800e8SDoug Rabson stack. 295*c19800e8SDoug Rabson 296*c19800e8SDoug Rabson * test_kcred.c: more testing of lifetimes 297*c19800e8SDoug Rabson 298*c19800e8SDoug Rabson2007-05-17 Love Hörnquist Åstrand <[email protected]> 299*c19800e8SDoug Rabson 300*c19800e8SDoug Rabson * Makefile.am: Drop the gss oid_set function for the krb5 mech, 301*c19800e8SDoug Rabson use the mech glue versions instead. Pointed out by Rafal 302*c19800e8SDoug Rabson Malinowski. 303*c19800e8SDoug Rabson 304*c19800e8SDoug Rabson * krb5: Use gss oid_set functions from mechglue 305*c19800e8SDoug Rabson 306*c19800e8SDoug Rabson2007-05-14 Love Hörnquist Åstrand <[email protected]> 307*c19800e8SDoug Rabson 308*c19800e8SDoug Rabson * ntlm/accept_sec_context.c: Set session key only if we are 309*c19800e8SDoug Rabson returned a session key. Found by David Love. 310*c19800e8SDoug Rabson 311*c19800e8SDoug Rabson2007-05-13 Love Hörnquist Åstrand <[email protected]> 312*c19800e8SDoug Rabson 313*c19800e8SDoug Rabson * krb5/prf.c: switched MIN to min to make compile on solaris, 314*c19800e8SDoug Rabson pointed out by David Love. 315*c19800e8SDoug Rabson 316*c19800e8SDoug Rabson2007-05-09 Love Hörnquist Åstrand <[email protected]> 317*c19800e8SDoug Rabson 318*c19800e8SDoug Rabson * krb5/inquire_cred_by_mech.c: Fill in all of the variables if 319*c19800e8SDoug Rabson they are passed in. Pointed out by Phil Fisher. 320*c19800e8SDoug Rabson 321*c19800e8SDoug Rabson2007-05-08 Love Hörnquist Åstrand <[email protected]> 322*c19800e8SDoug Rabson 323*c19800e8SDoug Rabson * krb5/inquire_cred.c: Fix copy and paste error, bug spotted by 324*c19800e8SDoug Rabson from Phil Fisher. 325*c19800e8SDoug Rabson 326*c19800e8SDoug Rabson * mech: dont keep track of gc_usage, just figure it out at 327*c19800e8SDoug Rabson gss_inquire_cred() time 328*c19800e8SDoug Rabson 329*c19800e8SDoug Rabson * mech/gss_mech_switch.c (add_builtin): ok for 330*c19800e8SDoug Rabson __gss_mech_initialize() to return NULL 331*c19800e8SDoug Rabson 332*c19800e8SDoug Rabson * test_kcred.c: more correct tests 333*c19800e8SDoug Rabson 334*c19800e8SDoug Rabson * spnego/cred_stubs.c (gss_inquire_cred*): wrap the name with a 335*c19800e8SDoug Rabson spnego_name. 336*c19800e8SDoug Rabson 337*c19800e8SDoug Rabson * ntlm/inquire_cred.c: make ntlm gss_inquire_cred fail for now, 338*c19800e8SDoug Rabson need to find default cred and friends. 339*c19800e8SDoug Rabson 340*c19800e8SDoug Rabson * krb5/inquire_cred_by_mech.c: reimplement 341*c19800e8SDoug Rabson 342*c19800e8SDoug Rabson2007-05-07 Love Hörnquist Åstrand <[email protected]> 343*c19800e8SDoug Rabson 344*c19800e8SDoug Rabson * ntlm/acquire_cred.c: drop unused variable. 345*c19800e8SDoug Rabson 346*c19800e8SDoug Rabson * ntlm/acquire_cred.c: Reimplement. 347*c19800e8SDoug Rabson 348*c19800e8SDoug Rabson * Makefile.am: add ntlm/digest.c 349*c19800e8SDoug Rabson 350*c19800e8SDoug Rabson * ntlm: split out backend ntlm server processing 351*c19800e8SDoug Rabson 352*c19800e8SDoug Rabson2007-04-24 Love Hörnquist Åstrand <[email protected]> 353*c19800e8SDoug Rabson 354*c19800e8SDoug Rabson * ntlm/delete_sec_context.c (_gss_ntlm_delete_sec_context): free 355*c19800e8SDoug Rabson credcache when done 356*c19800e8SDoug Rabson 357*c19800e8SDoug Rabson2007-04-22 Love Hörnquist Åstrand <[email protected]> 358*c19800e8SDoug Rabson 359*c19800e8SDoug Rabson * ntlm/init_sec_context.c: ntlm-key credential entry is prefix with @ 360*c19800e8SDoug Rabson 361*c19800e8SDoug Rabson * ntlm/init_sec_context.c (get_user_ccache): pick up the ntlm 362*c19800e8SDoug Rabson creds from the krb5 credential cache. 363*c19800e8SDoug Rabson 364*c19800e8SDoug Rabson2007-04-21 Love Hörnquist Åstrand <[email protected]> 365*c19800e8SDoug Rabson 366*c19800e8SDoug Rabson * ntlm/delete_sec_context.c: free the key stored in the context 367*c19800e8SDoug Rabson 368*c19800e8SDoug Rabson * ntlm/ntlm.h: switch password for a key 369*c19800e8SDoug Rabson 370*c19800e8SDoug Rabson * test_oid.c: Switch oid to one that is exported. 371*c19800e8SDoug Rabson 372*c19800e8SDoug Rabson2007-04-20 Love Hörnquist Åstrand <[email protected]> 373*c19800e8SDoug Rabson 374*c19800e8SDoug Rabson * ntlm/init_sec_context.c: move where hash is calculated to make 375*c19800e8SDoug Rabson it easier to add ccache support. 376*c19800e8SDoug Rabson 377*c19800e8SDoug Rabson * Makefile.am: Add version-script.map to EXTRA_DIST. 378*c19800e8SDoug Rabson 379*c19800e8SDoug Rabson2007-04-19 Love Hörnquist Åstrand <[email protected]> 380*c19800e8SDoug Rabson 381*c19800e8SDoug Rabson * Makefile.am: Unconfuse newer versions of automake that doesn't 382*c19800e8SDoug Rabson know the diffrence between depenences and setting variables. foo: 383*c19800e8SDoug Rabson vs foo=. 384*c19800e8SDoug Rabson 385*c19800e8SDoug Rabson * test_ntlm.c: delete sec context when done. 386*c19800e8SDoug Rabson 387*c19800e8SDoug Rabson * version-script.map: export more symbols. 388*c19800e8SDoug Rabson 389*c19800e8SDoug Rabson * Makefile.am: add version script if ld supports it 390*c19800e8SDoug Rabson 391*c19800e8SDoug Rabson * version-script.map: add version script if ld supports it 392*c19800e8SDoug Rabson 393*c19800e8SDoug Rabson2007-04-18 Love Hörnquist Åstrand <[email protected]> 394*c19800e8SDoug Rabson 395*c19800e8SDoug Rabson * Makefile.am: test_acquire_cred need test_common.[ch] 396*c19800e8SDoug Rabson 397*c19800e8SDoug Rabson * test_acquire_cred.c: add more test options. 398*c19800e8SDoug Rabson 399*c19800e8SDoug Rabson * krb5/external.c: add GSS_KRB5_CCACHE_NAME_X 400*c19800e8SDoug Rabson 401*c19800e8SDoug Rabson * gssapi/gssapi_krb5.h: add GSS_KRB5_CCACHE_NAME_X 402*c19800e8SDoug Rabson 403*c19800e8SDoug Rabson * krb5/set_sec_context_option.c: refactor code, implement 404*c19800e8SDoug Rabson GSS_KRB5_CCACHE_NAME_X 405*c19800e8SDoug Rabson 406*c19800e8SDoug Rabson * mech/gss_krb5.c: reimplement gss_krb5_ccache_name 407*c19800e8SDoug Rabson 408*c19800e8SDoug Rabson2007-04-17 Love Hörnquist Åstrand <[email protected]> 409*c19800e8SDoug Rabson 410*c19800e8SDoug Rabson * spnego/cred_stubs.c: Need to import spnego name before we can 411*c19800e8SDoug Rabson use it as a gss_name_t. 412*c19800e8SDoug Rabson 413*c19800e8SDoug Rabson * test_acquire_cred.c: use this test as part of the regression 414*c19800e8SDoug Rabson suite. 415*c19800e8SDoug Rabson 416*c19800e8SDoug Rabson * mech/gss_acquire_cred.c (gss_acquire_cred): dont init 417*c19800e8SDoug Rabson cred->gc_mc every time in the loop. 418*c19800e8SDoug Rabson 419*c19800e8SDoug Rabson2007-04-15 Love Hörnquist Åstrand <[email protected]> 420*c19800e8SDoug Rabson 421*c19800e8SDoug Rabson * Makefile.am: add test_common.h 422*c19800e8SDoug Rabson 423*c19800e8SDoug Rabson2007-02-16 Love Hörnquist Åstrand <[email protected]> 424*c19800e8SDoug Rabson 425*c19800e8SDoug Rabson * gss_acquire_cred.3: Add link for 426*c19800e8SDoug Rabson gsskrb5_register_acceptor_identity. 427*c19800e8SDoug Rabson 428*c19800e8SDoug Rabson2007-02-08 Love Hörnquist Åstrand <[email protected]> 429*c19800e8SDoug Rabson 430*c19800e8SDoug Rabson * krb5/copy_ccache.c: Try to leak less memory in the failure case. 431*c19800e8SDoug Rabson 432*c19800e8SDoug Rabson2007-01-31 Love Hörnquist Åstrand <[email protected]> 433*c19800e8SDoug Rabson 434*c19800e8SDoug Rabson * mech/gss_display_status.c: Use right printf formater. 435*c19800e8SDoug Rabson 436*c19800e8SDoug Rabson * test_*.[ch]: split out the error printing function and try to 437*c19800e8SDoug Rabson return better errors 438*c19800e8SDoug Rabson 439*c19800e8SDoug Rabson2007-01-30 Love Hörnquist Åstrand <[email protected]> 440*c19800e8SDoug Rabson 441*c19800e8SDoug Rabson * krb5/init_sec_context.c: revert 1.75: (init_auth): only turn on 442*c19800e8SDoug Rabson GSS_C_CONF_FLAG and GSS_C_INT_FLAG if the caller requseted it. 443*c19800e8SDoug Rabson 444*c19800e8SDoug Rabson This is because Kerberos always support INT|CONF, matches behavior 445*c19800e8SDoug Rabson with MS and MIT. The creates problems for the GSS-SPNEGO mech. 446*c19800e8SDoug Rabson 447*c19800e8SDoug Rabson2007-01-24 Love Hörnquist Åstrand <[email protected]> 448*c19800e8SDoug Rabson 449*c19800e8SDoug Rabson * krb5/prf.c: constrain desired_output_len 450*c19800e8SDoug Rabson 451*c19800e8SDoug Rabson * krb5/external.c (krb5_mech): add _gsskrb5_pseudo_random 452*c19800e8SDoug Rabson 453*c19800e8SDoug Rabson * mech/gss_pseudo_random.c: Catch error from underlaying mech on 454*c19800e8SDoug Rabson failure. 455*c19800e8SDoug Rabson 456*c19800e8SDoug Rabson * Makefile.am: Add krb5/prf.c 457*c19800e8SDoug Rabson 458*c19800e8SDoug Rabson * krb5/prf.c: gss_pseudo_random for krb5 459*c19800e8SDoug Rabson 460*c19800e8SDoug Rabson * test_context.c: Checks for gss_pseudo_random. 461*c19800e8SDoug Rabson 462*c19800e8SDoug Rabson * krb5/gkrb5_err.et: add KG_INPUT_TOO_LONG 463*c19800e8SDoug Rabson 464*c19800e8SDoug Rabson * Makefile.am: Add mech/gss_pseudo_random.c 465*c19800e8SDoug Rabson 466*c19800e8SDoug Rabson * gssapi/gssapi.h: try to load pseudo_random 467*c19800e8SDoug Rabson 468*c19800e8SDoug Rabson * mech/gss_mech_switch.c: try to load pseudo_random 469*c19800e8SDoug Rabson 470*c19800e8SDoug Rabson * mech/gss_pseudo_random.c: Add gss_pseudo_random. 471*c19800e8SDoug Rabson 472*c19800e8SDoug Rabson * gssapi_mech.h: Add hook for gm_pseudo_random. 473*c19800e8SDoug Rabson 474*c19800e8SDoug Rabson2007-01-17 Love Hörnquist Åstrand <[email protected]> 475*c19800e8SDoug Rabson 476*c19800e8SDoug Rabson * test_context.c: Don't assume bufer from gss_display_status is 477*c19800e8SDoug Rabson ok. 478*c19800e8SDoug Rabson 479*c19800e8SDoug Rabson * mech/gss_wrap_size_limit.c: Reset out variables. 480*c19800e8SDoug Rabson 481*c19800e8SDoug Rabson * mech/gss_wrap.c: Reset out variables. 482*c19800e8SDoug Rabson 483*c19800e8SDoug Rabson * mech/gss_verify_mic.c: Reset out variables. 484*c19800e8SDoug Rabson 485*c19800e8SDoug Rabson * mech/gss_utils.c: Reset out variables. 486*c19800e8SDoug Rabson 487*c19800e8SDoug Rabson * mech/gss_release_oid_set.c: Reset out variables. 488*c19800e8SDoug Rabson 489*c19800e8SDoug Rabson * mech/gss_release_cred.c: Reset out variables. 490*c19800e8SDoug Rabson 491*c19800e8SDoug Rabson * mech/gss_release_buffer.c: Reset variables. 492*c19800e8SDoug Rabson 493*c19800e8SDoug Rabson * mech/gss_oid_to_str.c: Reset out variables. 494*c19800e8SDoug Rabson 495*c19800e8SDoug Rabson * mech/gss_inquire_sec_context_by_oid.c: Fix reset out variables. 496*c19800e8SDoug Rabson 497*c19800e8SDoug Rabson * mech/gss_mech_switch.c: Reset out variables. 498*c19800e8SDoug Rabson 499*c19800e8SDoug Rabson * mech/gss_inquire_sec_context_by_oid.c: Reset out variables. 500*c19800e8SDoug Rabson 501*c19800e8SDoug Rabson * mech/gss_inquire_names_for_mech.c: Reset out variables. 502*c19800e8SDoug Rabson 503*c19800e8SDoug Rabson * mech/gss_inquire_cred_by_oid.c: Reset out variables. 504*c19800e8SDoug Rabson 505*c19800e8SDoug Rabson * mech/gss_inquire_cred_by_oid.c: Reset out variables. 506*c19800e8SDoug Rabson 507*c19800e8SDoug Rabson * mech/gss_inquire_cred_by_mech.c: Reset out variables. 508*c19800e8SDoug Rabson 509*c19800e8SDoug Rabson * mech/gss_inquire_cred.c: Reset out variables, fix memory leak. 510*c19800e8SDoug Rabson 511*c19800e8SDoug Rabson * mech/gss_inquire_context.c: Reset out variables. 512*c19800e8SDoug Rabson 513*c19800e8SDoug Rabson * mech/gss_init_sec_context.c: Zero out outbuffer on failure. 514*c19800e8SDoug Rabson 515*c19800e8SDoug Rabson * mech/gss_import_name.c: Reset out variables. 516*c19800e8SDoug Rabson 517*c19800e8SDoug Rabson * mech/gss_import_name.c: Reset out variables. 518*c19800e8SDoug Rabson 519*c19800e8SDoug Rabson * mech/gss_get_mic.c: Reset out variables. 520*c19800e8SDoug Rabson 521*c19800e8SDoug Rabson * mech/gss_export_name.c: Reset out variables. 522*c19800e8SDoug Rabson 523*c19800e8SDoug Rabson * mech/gss_encapsulate_token.c: Reset out variables. 524*c19800e8SDoug Rabson 525*c19800e8SDoug Rabson * mech/gss_duplicate_oid.c: Reset out variables. 526*c19800e8SDoug Rabson 527*c19800e8SDoug Rabson * mech/gss_duplicate_oid.c: Reset out variables. 528*c19800e8SDoug Rabson 529*c19800e8SDoug Rabson * mech/gss_duplicate_name.c: Reset out variables. 530*c19800e8SDoug Rabson 531*c19800e8SDoug Rabson * mech/gss_display_status.c: Reset out variables. 532*c19800e8SDoug Rabson 533*c19800e8SDoug Rabson * mech/gss_display_name.c: Reset out variables. 534*c19800e8SDoug Rabson 535*c19800e8SDoug Rabson * mech/gss_delete_sec_context.c: Reset out variables using propper 536*c19800e8SDoug Rabson macros. 537*c19800e8SDoug Rabson 538*c19800e8SDoug Rabson * mech/gss_decapsulate_token.c: Reset out variables using propper 539*c19800e8SDoug Rabson macros. 540*c19800e8SDoug Rabson 541*c19800e8SDoug Rabson * mech/gss_add_cred.c: Reset out variables. 542*c19800e8SDoug Rabson 543*c19800e8SDoug Rabson * mech/gss_acquire_cred.c: Reset out variables. 544*c19800e8SDoug Rabson 545*c19800e8SDoug Rabson * mech/gss_accept_sec_context.c: Reset out variables using propper 546*c19800e8SDoug Rabson macros. 547*c19800e8SDoug Rabson 548*c19800e8SDoug Rabson * mech/gss_init_sec_context.c: Reset out variables. 549*c19800e8SDoug Rabson 550*c19800e8SDoug Rabson * mech/mech_locl.h (_mg_buffer_zero): new macro that zaps a 551*c19800e8SDoug Rabson gss_buffer_t 552*c19800e8SDoug Rabson 553*c19800e8SDoug Rabson2007-01-16 Love Hörnquist Åstrand <[email protected]> 554*c19800e8SDoug Rabson 555*c19800e8SDoug Rabson * mech: sprinkel _gss_mg_error 556*c19800e8SDoug Rabson 557*c19800e8SDoug Rabson * mech/gss_display_status.c (gss_display_status): use 558*c19800e8SDoug Rabson _gss_mg_get_error to fetch the error from underlaying mech, if it 559*c19800e8SDoug Rabson failes, let do the regular dance for GSS-CODE version and a 560*c19800e8SDoug Rabson generic print-the-error code for MECH-CODE. 561*c19800e8SDoug Rabson 562*c19800e8SDoug Rabson * mech/gss_oid_to_str.c: Don't include the NUL in the length of 563*c19800e8SDoug Rabson the string. 564*c19800e8SDoug Rabson 565*c19800e8SDoug Rabson * mech/context.h: Protoypes for _gss_mg_. 566*c19800e8SDoug Rabson 567*c19800e8SDoug Rabson * mech/context.c: Glue to catch the error from the lower gss-api 568*c19800e8SDoug Rabson layer and save that for later so gss_display_status() can show the 569*c19800e8SDoug Rabson error. 570*c19800e8SDoug Rabson 571*c19800e8SDoug Rabson * gss.c: Detect NTLM. 572*c19800e8SDoug Rabson 573*c19800e8SDoug Rabson2007-01-11 Love Hörnquist Åstrand <[email protected]> 574*c19800e8SDoug Rabson 575*c19800e8SDoug Rabson * mech/gss_accept_sec_context.c: spelling 576*c19800e8SDoug Rabson 577*c19800e8SDoug Rabson2007-01-04 Love Hörnquist Åstrand <[email protected]> 578*c19800e8SDoug Rabson 579*c19800e8SDoug Rabson * Makefile.am: Include build (private) prototypes header files. 580*c19800e8SDoug Rabson 581*c19800e8SDoug Rabson * Makefile.am (ntlmsrc): add ntlm/ntlm-private.h 582*c19800e8SDoug Rabson 583*c19800e8SDoug Rabson2006-12-28 Love Hörnquist Åstrand <[email protected]> 584*c19800e8SDoug Rabson 585*c19800e8SDoug Rabson * ntlm/accept_sec_context.c: Pass signseal argument to 586*c19800e8SDoug Rabson _gss_ntlm_set_key. 587*c19800e8SDoug Rabson 588*c19800e8SDoug Rabson * ntlm/init_sec_context.c: Pass signseal argument to 589*c19800e8SDoug Rabson _gss_ntlm_set_key. 590*c19800e8SDoug Rabson 591*c19800e8SDoug Rabson * ntlm/crypto.c (_gss_ntlm_set_key): add signseal argument 592*c19800e8SDoug Rabson 593*c19800e8SDoug Rabson * test_ntlm.c: add ntlmv2 test 594*c19800e8SDoug Rabson 595*c19800e8SDoug Rabson * ntlm/ntlm.h: break out struct ntlmv2_key; 596*c19800e8SDoug Rabson 597*c19800e8SDoug Rabson * ntlm/crypto.c (_gss_ntlm_set_key): set ntlm v2 keys. 598*c19800e8SDoug Rabson 599*c19800e8SDoug Rabson * ntlm/accept_sec_context.c: Set dummy ntlmv2 keys and Check TI. 600*c19800e8SDoug Rabson 601*c19800e8SDoug Rabson * ntlm/ntlm.h: NTLMv2 keys. 602*c19800e8SDoug Rabson 603*c19800e8SDoug Rabson * ntlm/crypto.c: NTLMv2 sign and verify. 604*c19800e8SDoug Rabson 605*c19800e8SDoug Rabson2006-12-20 Love Hörnquist Åstrand <[email protected]> 606*c19800e8SDoug Rabson 607*c19800e8SDoug Rabson * ntlm/accept_sec_context.c: Don't send targetinfo now. 608*c19800e8SDoug Rabson 609*c19800e8SDoug Rabson * ntlm/init_sec_context.c: Build ntlmv2 answer buffer. 610*c19800e8SDoug Rabson 611*c19800e8SDoug Rabson * ntlm/init_sec_context.c: Leak less memory. 612*c19800e8SDoug Rabson 613*c19800e8SDoug Rabson * ntlm/init_sec_context.c: Announce that we support key exchange. 614*c19800e8SDoug Rabson 615*c19800e8SDoug Rabson * ntlm/init_sec_context.c: Add NTLM_NEG_NTLM2_SESSION, NTLMv2 616*c19800e8SDoug Rabson session security (disable because missing sign and seal). 617*c19800e8SDoug Rabson 618*c19800e8SDoug Rabson2006-12-19 Love Hörnquist Åstrand <[email protected]> 619*c19800e8SDoug Rabson 620*c19800e8SDoug Rabson * ntlm/accept_sec_context.c: split RC4 send and recv keystreams 621*c19800e8SDoug Rabson 622*c19800e8SDoug Rabson * ntlm/init_sec_context.c: split RC4 send and recv keystreams 623*c19800e8SDoug Rabson 624*c19800e8SDoug Rabson * ntlm/ntlm.h: split RC4 send and recv keystreams 625*c19800e8SDoug Rabson 626*c19800e8SDoug Rabson * ntlm/crypto.c: Implement SEAL. 627*c19800e8SDoug Rabson 628*c19800e8SDoug Rabson * ntlm/crypto.c: move gss_wrap/gss_unwrap here 629*c19800e8SDoug Rabson 630*c19800e8SDoug Rabson * test_context.c: request INT and CONF from the gss layer, test 631*c19800e8SDoug Rabson get and verify MIC. 632*c19800e8SDoug Rabson 633*c19800e8SDoug Rabson * ntlm/ntlm.h: add crypto bits. 634*c19800e8SDoug Rabson 635*c19800e8SDoug Rabson * ntlm/accept_sec_context.c: Save session master key. 636*c19800e8SDoug Rabson 637*c19800e8SDoug Rabson * Makefile.am: Move get and verify mic to the same file (crypto.c) 638*c19800e8SDoug Rabson since they share code. 639*c19800e8SDoug Rabson 640*c19800e8SDoug Rabson * ntlm/crypto.c: Move get and verify mic to the same file since 641*c19800e8SDoug Rabson they share code, implement NTLM v1 and dummy signatures. 642*c19800e8SDoug Rabson 643*c19800e8SDoug Rabson * ntlm/init_sec_context.c: pass on GSS_C_CONF_FLAG and 644*c19800e8SDoug Rabson GSS_C_INTEG_FLAG, save the session master key 645*c19800e8SDoug Rabson 646*c19800e8SDoug Rabson * spnego/accept_sec_context.c: try using gss_accept_sec_context() 647*c19800e8SDoug Rabson on the opportunistic token instead of guessing the acceptor name 648*c19800e8SDoug Rabson and do gss_acquire_cred, this make SPNEGO work like before. 649*c19800e8SDoug Rabson 650*c19800e8SDoug Rabson2006-12-18 Love Hörnquist Åstrand <[email protected]> 651*c19800e8SDoug Rabson 652*c19800e8SDoug Rabson * ntlm/init_sec_context.c: Calculate the NTLM version 1 "master" 653*c19800e8SDoug Rabson key. 654*c19800e8SDoug Rabson 655*c19800e8SDoug Rabson * spnego/accept_sec_context.c: Resurect negHints for the acceptor 656*c19800e8SDoug Rabson sends first packet. 657*c19800e8SDoug Rabson 658*c19800e8SDoug Rabson * Makefile.am: Add "windows" versions of the NegTokenInitWin and 659*c19800e8SDoug Rabson friends. 660*c19800e8SDoug Rabson 661*c19800e8SDoug Rabson * test_context.c: add --wrapunwrap flag 662*c19800e8SDoug Rabson 663*c19800e8SDoug Rabson * spnego/compat.c: move _gss_spnego_indicate_mechtypelist() to 664*c19800e8SDoug Rabson compat.c, use the sequence types of MechTypeList, make 665*c19800e8SDoug Rabson add_mech_type() static. 666*c19800e8SDoug Rabson 667*c19800e8SDoug Rabson * spnego/accept_sec_context.c: move 668*c19800e8SDoug Rabson _gss_spnego_indicate_mechtypelist() to compat.c 669*c19800e8SDoug Rabson 670*c19800e8SDoug Rabson * Makefile.am: Generate sequence code for MechTypeList 671*c19800e8SDoug Rabson 672*c19800e8SDoug Rabson * spnego: check that the generated acceptor mechlist is acceptable too 673*c19800e8SDoug Rabson 674*c19800e8SDoug Rabson * spnego/init_sec_context.c: Abstract out the initiator filter 675*c19800e8SDoug Rabson function, it will be needed for the acceptor too. 676*c19800e8SDoug Rabson 677*c19800e8SDoug Rabson * spnego/accept_sec_context.c: Abstract out the initiator filter 678*c19800e8SDoug Rabson function, it will be needed for the acceptor too. Remove negHints. 679*c19800e8SDoug Rabson 680*c19800e8SDoug Rabson * test_context.c: allow asserting return mech 681*c19800e8SDoug Rabson 682*c19800e8SDoug Rabson * ntlm/accept_sec_context.c: add _gss_ntlm_allocate_ctx 683*c19800e8SDoug Rabson 684*c19800e8SDoug Rabson * ntlm/acquire_cred.c: Check that the KDC seem to there and 685*c19800e8SDoug Rabson answering us, we can't do better then that wen checking if we will 686*c19800e8SDoug Rabson accept the credential. 687*c19800e8SDoug Rabson 688*c19800e8SDoug Rabson * ntlm/get_mic.c: return GSS_S_UNAVAILABLE 689*c19800e8SDoug Rabson 690*c19800e8SDoug Rabson * mech/utils.h: add _gss_free_oid, reverse of _gss_copy_oid 691*c19800e8SDoug Rabson 692*c19800e8SDoug Rabson * mech/gss_utils.c: add _gss_free_oid, reverse of _gss_copy_oid 693*c19800e8SDoug Rabson 694*c19800e8SDoug Rabson * spnego/spnego.asn1: Its very sad, but NegHints its are not part 695*c19800e8SDoug Rabson of the NegTokenInit, this makes SPNEGO acceptor life a lot harder. 696*c19800e8SDoug Rabson 697*c19800e8SDoug Rabson * spnego: try harder to handle names better. handle missing 698*c19800e8SDoug Rabson acceptor and initator creds better (ie dont propose/accept mech 699*c19800e8SDoug Rabson that there are no credentials for) split NegTokenInit and 700*c19800e8SDoug Rabson NegTokenResp in acceptor 701*c19800e8SDoug Rabson 702*c19800e8SDoug Rabson2006-12-16 Love Hörnquist Åstrand <[email protected]> 703*c19800e8SDoug Rabson 704*c19800e8SDoug Rabson * ntlm/import_name.c: Allocate the buffer from the right length. 705*c19800e8SDoug Rabson 706*c19800e8SDoug Rabson2006-12-15 Love Hörnquist Åstrand <[email protected]> 707*c19800e8SDoug Rabson 708*c19800e8SDoug Rabson * ntlm/init_sec_context.c (init_sec_context): Tell the other side 709*c19800e8SDoug Rabson what domain we think we are talking to. 710*c19800e8SDoug Rabson 711*c19800e8SDoug Rabson * ntlm/delete_sec_context.c: free username and password 712*c19800e8SDoug Rabson 713*c19800e8SDoug Rabson * ntlm/release_name.c (_gss_ntlm_release_name): free name. 714*c19800e8SDoug Rabson 715*c19800e8SDoug Rabson * ntlm/import_name.c (_gss_ntlm_import_name): add support for 716*c19800e8SDoug Rabson GSS_C_NT_HOSTBASED_SERVICE names 717*c19800e8SDoug Rabson 718*c19800e8SDoug Rabson * ntlm/ntlm.h: Add ntlm_name. 719*c19800e8SDoug Rabson 720*c19800e8SDoug Rabson * test_context.c: allow testing of ntlm. 721*c19800e8SDoug Rabson 722*c19800e8SDoug Rabson * gssapi_mech.h: add __gss_ntlm_initialize 723*c19800e8SDoug Rabson 724*c19800e8SDoug Rabson * ntlm/accept_sec_context.c (handle_type3): verify that the kdc 725*c19800e8SDoug Rabson approved of the ntlm exchange too 726*c19800e8SDoug Rabson 727*c19800e8SDoug Rabson * mech/gss_mech_switch.c: Add the builtin ntlm mech 728*c19800e8SDoug Rabson 729*c19800e8SDoug Rabson * test_ntlm.c: NTLM test app. 730*c19800e8SDoug Rabson 731*c19800e8SDoug Rabson * mech/gss_accept_sec_context.c: Add detection of NTLMSSP. 732*c19800e8SDoug Rabson 733*c19800e8SDoug Rabson * gssapi/gssapi.h: add ntlm mech oid 734*c19800e8SDoug Rabson 735*c19800e8SDoug Rabson * ntlm/external.c: Switch OID to the ms ntlmssp oid 736*c19800e8SDoug Rabson 737*c19800e8SDoug Rabson * Makefile.am: Add ntlm gss-api module. 738*c19800e8SDoug Rabson 739*c19800e8SDoug Rabson * ntlm/accept_sec_context.c: Catch more error errors. 740*c19800e8SDoug Rabson 741*c19800e8SDoug Rabson * ntlm/accept_sec_context.c: Check after a credential to use. 742*c19800e8SDoug Rabson 743*c19800e8SDoug Rabson2006-12-14 Love Hörnquist Åstrand <[email protected]> 744*c19800e8SDoug Rabson 745*c19800e8SDoug Rabson * krb5/set_sec_context_option.c (GSS_KRB5_SET_DEFAULT_REALM_X): 746*c19800e8SDoug Rabson don't fail on success. Bug report from Stefan Metzmacher. 747*c19800e8SDoug Rabson 748*c19800e8SDoug Rabson2006-12-13 Love Hörnquist Åstrand <[email protected]> 749*c19800e8SDoug Rabson 750*c19800e8SDoug Rabson * krb5/init_sec_context.c (init_auth): only turn on 751*c19800e8SDoug Rabson GSS_C_CONF_FLAG and GSS_C_INT_FLAG if the caller requseted it. 752*c19800e8SDoug Rabson From Stefan Metzmacher. 753*c19800e8SDoug Rabson 754*c19800e8SDoug Rabson2006-12-11 Love Hörnquist Åstrand <[email protected]> 755*c19800e8SDoug Rabson 756*c19800e8SDoug Rabson * Makefile.am (libgssapi_la_OBJECTS): depends on gssapi_asn1.h 757*c19800e8SDoug Rabson spnego_asn1.h. 758*c19800e8SDoug Rabson 759*c19800e8SDoug Rabson2006-11-20 Love Hörnquist Åstrand <[email protected]> 760*c19800e8SDoug Rabson 761*c19800e8SDoug Rabson * krb5/acquire_cred.c: Make krb5_get_init_creds_opt_free take a 762*c19800e8SDoug Rabson context argument. 763*c19800e8SDoug Rabson 764*c19800e8SDoug Rabson2006-11-16 Love Hörnquist Åstrand <[email protected]> 765*c19800e8SDoug Rabson 766*c19800e8SDoug Rabson * test_context.c: Test that token keys are the same, return 767*c19800e8SDoug Rabson actual_mech. 768*c19800e8SDoug Rabson 769*c19800e8SDoug Rabson2006-11-15 Love Hörnquist Åstrand <[email protected]> 770*c19800e8SDoug Rabson 771*c19800e8SDoug Rabson * spnego/spnego_locl.h: Make bitfields unsigned, add maybe_open. 772*c19800e8SDoug Rabson 773*c19800e8SDoug Rabson * spnego/accept_sec_context.c: Use ASN.1 encoder functions to 774*c19800e8SDoug Rabson encode CHOICE structure now that we can handle it. 775*c19800e8SDoug Rabson 776*c19800e8SDoug Rabson * spnego/init_sec_context.c: Use ASN.1 encoder functions to encode 777*c19800e8SDoug Rabson CHOICE structure now that we can handle it. 778*c19800e8SDoug Rabson 779*c19800e8SDoug Rabson * spnego/accept_sec_context.c (_gss_spnego_accept_sec_context): 780*c19800e8SDoug Rabson send back ad accept_completed when the security context is ->open, 781*c19800e8SDoug Rabson w/o this the client doesn't know that the server have completed 782*c19800e8SDoug Rabson the transaction. 783*c19800e8SDoug Rabson 784*c19800e8SDoug Rabson * test_context.c: Add delegate flag and check that the delegated 785*c19800e8SDoug Rabson cred works. 786*c19800e8SDoug Rabson 787*c19800e8SDoug Rabson * spnego/init_sec_context.c: Keep track of the opportunistic token 788*c19800e8SDoug Rabson in the inital message, it might be a complete gss-api context, in 789*c19800e8SDoug Rabson that case we'll get back accept_completed without any token. With 790*c19800e8SDoug Rabson this change, krb5 w/o mutual authentication works. 791*c19800e8SDoug Rabson 792*c19800e8SDoug Rabson * spnego/accept_sec_context.c: Use ASN.1 encoder functions to 793*c19800e8SDoug Rabson encode CHOICE structure now that we can handle it. 794*c19800e8SDoug Rabson 795*c19800e8SDoug Rabson * spnego/accept_sec_context.c: Filter out SPNEGO from the out 796*c19800e8SDoug Rabson supported mechs list and make sure we don't select that for the 797*c19800e8SDoug Rabson preferred mechamism. 798*c19800e8SDoug Rabson 799*c19800e8SDoug Rabson2006-11-14 Love Hörnquist Åstrand <[email protected]> 800*c19800e8SDoug Rabson 801*c19800e8SDoug Rabson * mech/gss_init_sec_context.c (_gss_mech_cred_find): break out the 802*c19800e8SDoug Rabson cred finding to its own function 803*c19800e8SDoug Rabson 804*c19800e8SDoug Rabson * krb5/wrap.c: Better error strings, from Andrew Bartlet. 805*c19800e8SDoug Rabson 806*c19800e8SDoug Rabson2006-11-13 Love Hörnquist Åstrand <[email protected]> 807*c19800e8SDoug Rabson 808*c19800e8SDoug Rabson * test_context.c: Create our own krb5_context. 809*c19800e8SDoug Rabson 810*c19800e8SDoug Rabson * krb5: Switch from using a specific error message context in the 811*c19800e8SDoug Rabson TLS to have a whole krb5_context in TLS. This have some 812*c19800e8SDoug Rabson interestion side-effekts for the configruration setting options 813*c19800e8SDoug Rabson since they operate on per-thread basis now. 814*c19800e8SDoug Rabson 815*c19800e8SDoug Rabson * mech/gss_set_cred_option.c: When calling ->gm_set_cred_option 816*c19800e8SDoug Rabson and checking for success, use GSS_S_COMPLETE. From Andrew Bartlet. 817*c19800e8SDoug Rabson 818*c19800e8SDoug Rabson2006-11-12 Love Hörnquist Åstrand <[email protected]> 819*c19800e8SDoug Rabson 820*c19800e8SDoug Rabson * Makefile.am: Help solaris make even more. 821*c19800e8SDoug Rabson 822*c19800e8SDoug Rabson * Makefile.am: Help solaris make. 823*c19800e8SDoug Rabson 824*c19800e8SDoug Rabson2006-11-09 Love Hörnquist Åstrand <[email protected]> 825*c19800e8SDoug Rabson 826*c19800e8SDoug Rabson * Makefile.am: remove include $(srcdir)/Makefile-digest.am for now 827*c19800e8SDoug Rabson 828*c19800e8SDoug Rabson * mech/gss_accept_sec_context.c: Try better guessing what is mech 829*c19800e8SDoug Rabson we are going to select by looking harder at the input_token, idea 830*c19800e8SDoug Rabson from Luke Howard's mechglue branch. 831*c19800e8SDoug Rabson 832*c19800e8SDoug Rabson * Makefile.am: libgssapi_la_OBJECTS: add depency on gkrb5_err.h 833*c19800e8SDoug Rabson 834*c19800e8SDoug Rabson * gssapi/gssapi_krb5.h: add GSS_KRB5_SET_ALLOWABLE_ENCTYPES_X 835*c19800e8SDoug Rabson 836*c19800e8SDoug Rabson * mech/gss_krb5.c: implement gss_krb5_set_allowable_enctypes 837*c19800e8SDoug Rabson 838*c19800e8SDoug Rabson * gssapi/gssapi.h: GSS_KRB5_S_ 839*c19800e8SDoug Rabson 840*c19800e8SDoug Rabson * krb5/gsskrb5_locl.h: Include <gkrb5_err.h>. 841*c19800e8SDoug Rabson 842*c19800e8SDoug Rabson * gssapi/gssapi_krb5.h: Add gss_krb5_set_allowable_enctypes. 843*c19800e8SDoug Rabson 844*c19800e8SDoug Rabson * Makefile.am: Build and install gkrb5_err.h 845*c19800e8SDoug Rabson 846*c19800e8SDoug Rabson * krb5/gkrb5_err.et: Move the GSS_KRB5_S error here. 847*c19800e8SDoug Rabson 848*c19800e8SDoug Rabson2006-11-08 Love Hörnquist Åstrand <[email protected]> 849*c19800e8SDoug Rabson 850*c19800e8SDoug Rabson * mech/gss_krb5.c: Add gsskrb5_set_default_realm. 851*c19800e8SDoug Rabson 852*c19800e8SDoug Rabson * krb5/set_sec_context_option.c: Support 853*c19800e8SDoug Rabson GSS_KRB5_SET_DEFAULT_REALM_X. 854*c19800e8SDoug Rabson 855*c19800e8SDoug Rabson * gssapi/gssapi_krb5.h: add GSS_KRB5_SET_DEFAULT_REALM_X 856*c19800e8SDoug Rabson 857*c19800e8SDoug Rabson * krb5/external.c: add GSS_KRB5_SET_DEFAULT_REALM_X 858*c19800e8SDoug Rabson 859*c19800e8SDoug Rabson2006-11-07 Love Hörnquist Åstrand <[email protected]> 860*c19800e8SDoug Rabson 861*c19800e8SDoug Rabson * test_context.c: rename krb5_[gs]et_time_wrap to 862*c19800e8SDoug Rabson krb5_[gs]et_max_time_skew 863*c19800e8SDoug Rabson 864*c19800e8SDoug Rabson * krb5/copy_ccache.c: _gsskrb5_extract_authz_data_from_sec_context 865*c19800e8SDoug Rabson no longer used, bye bye 866*c19800e8SDoug Rabson 867*c19800e8SDoug Rabson * mech/gss_krb5.c: No depenency of the krb5 gssapi mech. 868*c19800e8SDoug Rabson 869*c19800e8SDoug Rabson * mech/gss_krb5.c (gsskrb5_extract_authtime_from_sec_context): use 870*c19800e8SDoug Rabson _gsskrb5_decode_om_uint32. From Andrew Bartlet. 871*c19800e8SDoug Rabson 872*c19800e8SDoug Rabson * mech/gss_krb5.c: Add dummy gss_krb5_set_allowable_enctypes for 873*c19800e8SDoug Rabson now. 874*c19800e8SDoug Rabson 875*c19800e8SDoug Rabson * spnego/spnego_locl.h: Include <roken.h> for compatiblity. 876*c19800e8SDoug Rabson 877*c19800e8SDoug Rabson * krb5/arcfour.c: Use IS_DCE_STYLE flag. There is no padding in 878*c19800e8SDoug Rabson DCE-STYLE, don't try to use to. From Andrew Bartlett. 879*c19800e8SDoug Rabson 880*c19800e8SDoug Rabson * test_context.c: test wrap/unwrap, add flag for dce-style and 881*c19800e8SDoug Rabson mutual auth, also support multi-roundtrip sessions 882*c19800e8SDoug Rabson 883*c19800e8SDoug Rabson * krb5/gsskrb5_locl.h: Add IS_DCE_STYLE macro. 884*c19800e8SDoug Rabson 885*c19800e8SDoug Rabson * krb5/accept_sec_context.c (gsskrb5_acceptor_start): use 886*c19800e8SDoug Rabson krb5_rd_req_ctx 887*c19800e8SDoug Rabson 888*c19800e8SDoug Rabson * mech/gss_krb5.c (gsskrb5_get_subkey): return the per message 889*c19800e8SDoug Rabson token subkey 890*c19800e8SDoug Rabson 891*c19800e8SDoug Rabson * krb5/inquire_sec_context_by_oid.c: check if there is any key at 892*c19800e8SDoug Rabson all 893*c19800e8SDoug Rabson 894*c19800e8SDoug Rabson2006-11-06 Love Hörnquist Åstrand <[email protected]> 895*c19800e8SDoug Rabson 896*c19800e8SDoug Rabson * krb5/inquire_sec_context_by_oid.c: Set more error strings, use 897*c19800e8SDoug Rabson right enum for acceptor subkey. From Andrew Bartlett. 898*c19800e8SDoug Rabson 899*c19800e8SDoug Rabson2006-11-04 Love Hörnquist Åstrand <[email protected]> 900*c19800e8SDoug Rabson 901*c19800e8SDoug Rabson * test_context.c: Test gsskrb5_extract_service_keyblock, needed in 902*c19800e8SDoug Rabson PAC valication. From Andrew Bartlett 903*c19800e8SDoug Rabson 904*c19800e8SDoug Rabson * mech/gss_krb5.c: Add gsskrb5_extract_authz_data_from_sec_context 905*c19800e8SDoug Rabson and keyblock extraction functions. 906*c19800e8SDoug Rabson 907*c19800e8SDoug Rabson * gssapi/gssapi_krb5.h: Add extraction of keyblock function, from 908*c19800e8SDoug Rabson Andrew Bartlett. 909*c19800e8SDoug Rabson 910*c19800e8SDoug Rabson * krb5/external.c: Add GSS_KRB5_GET_SERVICE_KEYBLOCK_X 911*c19800e8SDoug Rabson 912*c19800e8SDoug Rabson2006-11-03 Love Hörnquist Åstrand <[email protected]> 913*c19800e8SDoug Rabson 914*c19800e8SDoug Rabson * test_context.c: Rename various routines and constants from 915*c19800e8SDoug Rabson canonize to canonicalize. From Andrew Bartlett 916*c19800e8SDoug Rabson 917*c19800e8SDoug Rabson * mech/gss_krb5.c: Rename various routines and constants from 918*c19800e8SDoug Rabson canonize to canonicalize. From Andrew Bartlett 919*c19800e8SDoug Rabson 920*c19800e8SDoug Rabson * krb5/set_sec_context_option.c: Rename various routines and 921*c19800e8SDoug Rabson constants from canonize to canonicalize. From Andrew Bartlett 922*c19800e8SDoug Rabson 923*c19800e8SDoug Rabson * krb5/external.c: Rename various routines and constants from 924*c19800e8SDoug Rabson canonize to canonicalize. From Andrew Bartlett 925*c19800e8SDoug Rabson 926*c19800e8SDoug Rabson * gssapi/gssapi_krb5.h: Rename various routines and constants from 927*c19800e8SDoug Rabson canonize to canonicalize. From Andrew Bartlett 928*c19800e8SDoug Rabson 929*c19800e8SDoug Rabson2006-10-25 Love Hörnquist Åstrand <[email protected]> 930*c19800e8SDoug Rabson 931*c19800e8SDoug Rabson * krb5/accept_sec_context.c (gsskrb5_accept_delegated_token): need 932*c19800e8SDoug Rabson to free ccache 933*c19800e8SDoug Rabson 934*c19800e8SDoug Rabson2006-10-24 Love Hörnquist Åstrand <[email protected]> 935*c19800e8SDoug Rabson 936*c19800e8SDoug Rabson * test_context.c (loop): free target_name 937*c19800e8SDoug Rabson 938*c19800e8SDoug Rabson * mech/gss_accept_sec_context.c: SLIST_INIT the ->gc_mc' 939*c19800e8SDoug Rabson 940*c19800e8SDoug Rabson * mech/gss_acquire_cred.c : SLIST_INIT the ->gc_mc' 941*c19800e8SDoug Rabson 942*c19800e8SDoug Rabson * krb5/init_sec_context.c: Avoid leaking memory. 943*c19800e8SDoug Rabson 944*c19800e8SDoug Rabson * mech/gss_buffer_set.c (gss_release_buffer_set): don't leak the 945*c19800e8SDoug Rabson ->elements memory. 946*c19800e8SDoug Rabson 947*c19800e8SDoug Rabson * test_context.c: make compile 948*c19800e8SDoug Rabson 949*c19800e8SDoug Rabson * krb5/cfx.c (_gssapi_verify_mic_cfx): always free crypto context. 950*c19800e8SDoug Rabson 951*c19800e8SDoug Rabson * krb5/set_cred_option.c (import_cred): free sp 952*c19800e8SDoug Rabson 953*c19800e8SDoug Rabson2006-10-22 Love Hörnquist Åstrand <[email protected]> 954*c19800e8SDoug Rabson 955*c19800e8SDoug Rabson * mech/gss_add_oid_set_member.c: Use old implementation of 956*c19800e8SDoug Rabson gss_add_oid_set_member, it leaks less memory. 957*c19800e8SDoug Rabson 958*c19800e8SDoug Rabson * krb5/test_cfx.c: free krb5_crypto. 959*c19800e8SDoug Rabson 960*c19800e8SDoug Rabson * krb5/test_cfx.c: free krb5_context 961*c19800e8SDoug Rabson 962*c19800e8SDoug Rabson * mech/gss_release_name.c (gss_release_name): free input_name 963*c19800e8SDoug Rabson it-self. 964*c19800e8SDoug Rabson 965*c19800e8SDoug Rabson2006-10-21 Love Hörnquist Åstrand <[email protected]> 966*c19800e8SDoug Rabson 967*c19800e8SDoug Rabson * test_context.c: Call setprogname. 968*c19800e8SDoug Rabson 969*c19800e8SDoug Rabson * mech/gss_krb5.c: Add gsskrb5_extract_authtime_from_sec_context. 970*c19800e8SDoug Rabson 971*c19800e8SDoug Rabson * gssapi/gssapi_krb5.h: add 972*c19800e8SDoug Rabson gsskrb5_extract_authtime_from_sec_context 973*c19800e8SDoug Rabson 974*c19800e8SDoug Rabson2006-10-20 Love Hörnquist Åstrand <[email protected]> 975*c19800e8SDoug Rabson 976*c19800e8SDoug Rabson * krb5/inquire_sec_context_by_oid.c: Add get_authtime. 977*c19800e8SDoug Rabson 978*c19800e8SDoug Rabson * krb5/external.c: add GSS_KRB5_GET_AUTHTIME_X 979*c19800e8SDoug Rabson 980*c19800e8SDoug Rabson * gssapi/gssapi_krb5.h: add GSS_KRB5_GET_AUTHTIME_X 981*c19800e8SDoug Rabson 982*c19800e8SDoug Rabson * krb5/set_sec_context_option.c: Implement GSS_KRB5_SEND_TO_KDC_X. 983*c19800e8SDoug Rabson 984*c19800e8SDoug Rabson * mech/gss_krb5.c: Add gsskrb5_set_send_to_kdc 985*c19800e8SDoug Rabson 986*c19800e8SDoug Rabson * gssapi/gssapi_krb5.h: Add GSS_KRB5_SEND_TO_KDC_X and 987*c19800e8SDoug Rabson gsskrb5_set_send_to_kdc 988*c19800e8SDoug Rabson 989*c19800e8SDoug Rabson * krb5/external.c: add GSS_KRB5_SEND_TO_KDC_X 990*c19800e8SDoug Rabson 991*c19800e8SDoug Rabson * Makefile.am: more files 992*c19800e8SDoug Rabson 993*c19800e8SDoug Rabson2006-10-19 Love Hörnquist Åstrand <[email protected]> 994*c19800e8SDoug Rabson 995*c19800e8SDoug Rabson * Makefile.am: remove spnego/gssapi_spnego.h, its now in gssapi/ 996*c19800e8SDoug Rabson 997*c19800e8SDoug Rabson * test_context.c: Allow specifing mech. 998*c19800e8SDoug Rabson 999*c19800e8SDoug Rabson * krb5/external.c: add GSS_SASL_DIGEST_MD5_MECHANISM (for now) 1000*c19800e8SDoug Rabson 1001*c19800e8SDoug Rabson * gssapi/gssapi.h: Rename GSS_DIGEST_MECHANISM to 1002*c19800e8SDoug Rabson GSS_SASL_DIGEST_MD5_MECHANISM 1003*c19800e8SDoug Rabson 1004*c19800e8SDoug Rabson2006-10-18 Love Hörnquist Åstrand <[email protected]> 1005*c19800e8SDoug Rabson 1006*c19800e8SDoug Rabson * mech/gssapi.asn1: Make it into a heim_any_set, its doesn't 1007*c19800e8SDoug Rabson except a tag. 1008*c19800e8SDoug Rabson 1009*c19800e8SDoug Rabson * mech/gssapi.asn1: GSSAPIContextToken is IMPLICIT SEQUENCE 1010*c19800e8SDoug Rabson 1011*c19800e8SDoug Rabson * gssapi/gssapi_krb5.h: add GSS_KRB5_GET_ACCEPTOR_SUBKEY_X 1012*c19800e8SDoug Rabson 1013*c19800e8SDoug Rabson * krb5/external.c: Add GSS_KRB5_GET_ACCEPTOR_SUBKEY_X. 1014*c19800e8SDoug Rabson 1015*c19800e8SDoug Rabson * gssapi/gssapi_krb5.h: add GSS_KRB5_GET_INITIATOR_SUBKEY_X and 1016*c19800e8SDoug Rabson GSS_KRB5_GET_SUBKEY_X 1017*c19800e8SDoug Rabson 1018*c19800e8SDoug Rabson * krb5/external.c: add GSS_KRB5_GET_INITIATOR_SUBKEY_X, 1019*c19800e8SDoug Rabson GSS_KRB5_GET_SUBKEY_X 1020*c19800e8SDoug Rabson 1021*c19800e8SDoug Rabson2006-10-17 Love Hörnquist Åstrand <[email protected]> 1022*c19800e8SDoug Rabson 1023*c19800e8SDoug Rabson * test_context.c: Support switching on name type oid's 1024*c19800e8SDoug Rabson 1025*c19800e8SDoug Rabson * test_context.c: add test for dns canon flag 1026*c19800e8SDoug Rabson 1027*c19800e8SDoug Rabson * mech/gss_krb5.c: Add gsskrb5_set_dns_canonlize. 1028*c19800e8SDoug Rabson 1029*c19800e8SDoug Rabson * gssapi/gssapi_krb5.h: remove gss_krb5_compat_des3_mic 1030*c19800e8SDoug Rabson 1031*c19800e8SDoug Rabson * gssapi/gssapi_krb5.h: Add gsskrb5_set_dns_canonlize. 1032*c19800e8SDoug Rabson 1033*c19800e8SDoug Rabson * krb5/set_sec_context_option.c: implement 1034*c19800e8SDoug Rabson GSS_KRB5_SET_DNS_CANONIZE_X 1035*c19800e8SDoug Rabson 1036*c19800e8SDoug Rabson * gssapi/gssapi_krb5.h: add GSS_KRB5_SET_DNS_CANONIZE_X 1037*c19800e8SDoug Rabson 1038*c19800e8SDoug Rabson * krb5/external.c: add GSS_KRB5_SET_DNS_CANONIZE_X 1039*c19800e8SDoug Rabson 1040*c19800e8SDoug Rabson * mech/gss_krb5.c: add bits to make lucid context work 1041*c19800e8SDoug Rabson 1042*c19800e8SDoug Rabson2006-10-14 Love Hörnquist Åstrand <[email protected]> 1043*c19800e8SDoug Rabson 1044*c19800e8SDoug Rabson * mech/gss_oid_to_str.c: Prefix der primitives with der_. 1045*c19800e8SDoug Rabson 1046*c19800e8SDoug Rabson * krb5/inquire_sec_context_by_oid.c: Prefix der primitives with 1047*c19800e8SDoug Rabson der_. 1048*c19800e8SDoug Rabson 1049*c19800e8SDoug Rabson * krb5/encapsulate.c: Prefix der primitives with der_. 1050*c19800e8SDoug Rabson 1051*c19800e8SDoug Rabson * mech/gss_oid_to_str.c: New der_print_heim_oid signature. 1052*c19800e8SDoug Rabson 1053*c19800e8SDoug Rabson2006-10-12 Love Hörnquist Åstrand <[email protected]> 1054*c19800e8SDoug Rabson 1055*c19800e8SDoug Rabson * Makefile.am: add test_context 1056*c19800e8SDoug Rabson 1057*c19800e8SDoug Rabson * krb5/inquire_sec_context_by_oid.c: Make it work. 1058*c19800e8SDoug Rabson 1059*c19800e8SDoug Rabson * test_oid.c: Test lucid oid. 1060*c19800e8SDoug Rabson 1061*c19800e8SDoug Rabson * gssapi/gssapi.h: Add OM_uint64_t. 1062*c19800e8SDoug Rabson 1063*c19800e8SDoug Rabson * krb5/inquire_sec_context_by_oid.c: Add lucid interface. 1064*c19800e8SDoug Rabson 1065*c19800e8SDoug Rabson * krb5/external.c: Add lucid interface, renumber oids to my 1066*c19800e8SDoug Rabson delegated space. 1067*c19800e8SDoug Rabson 1068*c19800e8SDoug Rabson * mech/gss_krb5.c: Add lucid interface. 1069*c19800e8SDoug Rabson 1070*c19800e8SDoug Rabson * gssapi/gssapi_krb5.h: Add lucid interface. 1071*c19800e8SDoug Rabson 1072*c19800e8SDoug Rabson * spnego/spnego_locl.h: Maybe include <netdb.h>. 1073*c19800e8SDoug Rabson 1074*c19800e8SDoug Rabson2006-10-09 Love Hörnquist Åstrand <[email protected]> 1075*c19800e8SDoug Rabson 1076*c19800e8SDoug Rabson * mech/gss_mech_switch.c: define RTLD_LOCAL to 0 if not defined. 1077*c19800e8SDoug Rabson 1078*c19800e8SDoug Rabson2006-10-08 Love Hörnquist Åstrand <[email protected]> 1079*c19800e8SDoug Rabson 1080*c19800e8SDoug Rabson * Makefile.am: install gssapi_krb5.H and gssapi_spnego.h 1081*c19800e8SDoug Rabson 1082*c19800e8SDoug Rabson * gssapi/gssapi_krb5.h: Move krb5 stuff to <gssapi/gssapi_krb5.h>. 1083*c19800e8SDoug Rabson 1084*c19800e8SDoug Rabson * gssapi/gssapi.h: Move krb5 stuff to <gssapi/gssapi_krb5.h>. 1085*c19800e8SDoug Rabson 1086*c19800e8SDoug Rabson * Makefile.am: Drop some -I no longer needed. 1087*c19800e8SDoug Rabson 1088*c19800e8SDoug Rabson * gssapi/gssapi_spnego.h: Move gssapi_spengo.h over here. 1089*c19800e8SDoug Rabson 1090*c19800e8SDoug Rabson * krb5: reference all include files using 'krb5/' 1091*c19800e8SDoug Rabson 1092*c19800e8SDoug Rabson2006-10-07 Love Hörnquist Åstrand <[email protected]> 1093*c19800e8SDoug Rabson 1094*c19800e8SDoug Rabson * gssapi.h: Add file inclusion protection. 1095*c19800e8SDoug Rabson 1096*c19800e8SDoug Rabson * gssapi/gssapi.h: Correct header file inclusion protection. 1097*c19800e8SDoug Rabson 1098*c19800e8SDoug Rabson * gssapi/gssapi.h: Move the gssapi.h from lib/gssapi/ to 1099*c19800e8SDoug Rabson lib/gssapi/gssapi/ to please automake. 1100*c19800e8SDoug Rabson 1101*c19800e8SDoug Rabson * spnego/spnego_locl.h: Maybe include <sys/types.h>. 1102*c19800e8SDoug Rabson 1103*c19800e8SDoug Rabson * mech/mech_locl.h: Include <roken.h>. 1104*c19800e8SDoug Rabson 1105*c19800e8SDoug Rabson * Makefile.am: split build files into dist_ and noinst_ SOURCES 1106*c19800e8SDoug Rabson 1107*c19800e8SDoug Rabson2006-10-06 Love Hörnquist Åstrand <[email protected]> 1108*c19800e8SDoug Rabson 1109*c19800e8SDoug Rabson * gss.c: #if 0 out unused code. 1110*c19800e8SDoug Rabson 1111*c19800e8SDoug Rabson * mech/gss_mech_switch.c: Cast argument to ctype(3) functions 1112*c19800e8SDoug Rabson to (unsigned char). 1113*c19800e8SDoug Rabson 1114*c19800e8SDoug Rabson2006-10-05 Love Hörnquist Åstrand <[email protected]> 1115*c19800e8SDoug Rabson 1116*c19800e8SDoug Rabson * mech/name.h: remove <sys/queue.h> 1117*c19800e8SDoug Rabson 1118*c19800e8SDoug Rabson * mech/mech_switch.h: remove <sys/queue.h> 1119*c19800e8SDoug Rabson 1120*c19800e8SDoug Rabson * mech/cred.h: remove <sys/queue.h> 1121*c19800e8SDoug Rabson 1122*c19800e8SDoug Rabson2006-10-02 Love Hörnquist Åstrand <[email protected]> 1123*c19800e8SDoug Rabson 1124*c19800e8SDoug Rabson * krb5/arcfour.c: Thinker more with header lengths. 1125*c19800e8SDoug Rabson 1126*c19800e8SDoug Rabson * krb5/arcfour.c: Improve the calcucation of header 1127*c19800e8SDoug Rabson lengths. DCE-STYLE data is also padded so remove if (1 || ...) 1128*c19800e8SDoug Rabson code. 1129*c19800e8SDoug Rabson 1130*c19800e8SDoug Rabson * krb5/wrap.c (_gsskrb5_wrap_size_limit): use 1131*c19800e8SDoug Rabson _gssapi_wrap_size_arcfour for arcfour 1132*c19800e8SDoug Rabson 1133*c19800e8SDoug Rabson * krb5/arcfour.c: Move _gssapi_wrap_size_arcfour here. 1134*c19800e8SDoug Rabson 1135*c19800e8SDoug Rabson * Makefile.am: Split all mech to diffrent mechsrc variables. 1136*c19800e8SDoug Rabson 1137*c19800e8SDoug Rabson * spnego/context_stubs.c: Make internal function static (and 1138*c19800e8SDoug Rabson rename). 1139*c19800e8SDoug Rabson 1140*c19800e8SDoug Rabson2006-10-01 Love Hörnquist Åstrand <[email protected]> 1141*c19800e8SDoug Rabson 1142*c19800e8SDoug Rabson * krb5/inquire_cred.c: Fix "if (x) lock(y)" bug. From Harald 1143*c19800e8SDoug Rabson Barth. 1144*c19800e8SDoug Rabson 1145*c19800e8SDoug Rabson * spnego/spnego_locl.h: Include <sys/param.h> for MAXHOSTNAMELEN. 1146*c19800e8SDoug Rabson 1147*c19800e8SDoug Rabson2006-09-25 Love Hörnquist Åstrand <[email protected]> 1148*c19800e8SDoug Rabson 1149*c19800e8SDoug Rabson * krb5/arcfour.c: Add wrap support, interrop with itself but not 1150*c19800e8SDoug Rabson w2k3s-sp1 1151*c19800e8SDoug Rabson 1152*c19800e8SDoug Rabson * krb5/gsskrb5_locl.h: move the arcfour specific stuff to the 1153*c19800e8SDoug Rabson arcfour header. 1154*c19800e8SDoug Rabson 1155*c19800e8SDoug Rabson * krb5/arcfour.c: Support DCE-style unwrap, tested with 1156*c19800e8SDoug Rabson w2k3server-sp1. 1157*c19800e8SDoug Rabson 1158*c19800e8SDoug Rabson * mech/gss_accept_sec_context.c (gss_accept_sec_context): if the 1159*c19800e8SDoug Rabson token doesn't start with [APPLICATION 0] SEQUENCE, lets assume its 1160*c19800e8SDoug Rabson a DCE-style kerberos 5 connection. XXX this needs to be made 1161*c19800e8SDoug Rabson better in cause we get another GSS-API protocol violating 1162*c19800e8SDoug Rabson protocol. It should be possible to detach the Kerberos DCE-style 1163*c19800e8SDoug Rabson since it starts with a AP-REQ PDU, but that have to wait for now. 1164*c19800e8SDoug Rabson 1165*c19800e8SDoug Rabson2006-09-22 Love Hörnquist Åstrand <[email protected]> 1166*c19800e8SDoug Rabson 1167*c19800e8SDoug Rabson * gssapi.h: Add GSS_C flags from 1168*c19800e8SDoug Rabson draft-brezak-win2k-krb-rc4-hmac-04.txt. 1169*c19800e8SDoug Rabson 1170*c19800e8SDoug Rabson * krb5/delete_sec_context.c: Free service_keyblock and fwd_data, 1171*c19800e8SDoug Rabson indent. 1172*c19800e8SDoug Rabson 1173*c19800e8SDoug Rabson * krb5/accept_sec_context.c: Merge of the acceptor part from the 1174*c19800e8SDoug Rabson samba patch by Stefan Metzmacher and Andrew Bartlet. 1175*c19800e8SDoug Rabson 1176*c19800e8SDoug Rabson * krb5/init_sec_context.c: Add GSS_C_DCE_STYLE. 1177*c19800e8SDoug Rabson 1178*c19800e8SDoug Rabson * krb5/{init_sec_context.c,gsskrb5_locl.h}: merge most of the 1179*c19800e8SDoug Rabson initiator part from the samba patch by Stefan Metzmacher and 1180*c19800e8SDoug Rabson Andrew Bartlet (still missing DCE/RPC support) 1181*c19800e8SDoug Rabson 1182*c19800e8SDoug Rabson2006-08-28 Love Hörnquist Åstrand <[email protected]> 1183*c19800e8SDoug Rabson 1184*c19800e8SDoug Rabson * gss.c (help): use sl_slc_help(). 1185*c19800e8SDoug Rabson 1186*c19800e8SDoug Rabson2006-07-22 Love Hörnquist Åstrand <[email protected]> 1187*c19800e8SDoug Rabson 1188*c19800e8SDoug Rabson * gss-commands.in: rename command to supported-mechanisms 1189*c19800e8SDoug Rabson 1190*c19800e8SDoug Rabson * Makefile.am: Make gss objects depend on the slc built 1191*c19800e8SDoug Rabson gss-commands.h 1192*c19800e8SDoug Rabson 1193*c19800e8SDoug Rabson2006-07-20 Love Hörnquist Åstrand <[email protected]> 1194*c19800e8SDoug Rabson 1195*c19800e8SDoug Rabson * gss-commands.in: add slc commands for gss 1196*c19800e8SDoug Rabson 1197*c19800e8SDoug Rabson * krb5/gsskrb5_locl.h: Remove dup prototype of _gsskrb5_init() 1198*c19800e8SDoug Rabson 1199*c19800e8SDoug Rabson * Makefile.am: Add test_cfx 1200*c19800e8SDoug Rabson 1201*c19800e8SDoug Rabson * krb5/external.c: add GSS_KRB5_REGISTER_ACCEPTOR_IDENTITY_X 1202*c19800e8SDoug Rabson 1203*c19800e8SDoug Rabson * krb5/set_sec_context_option.c: catch 1204*c19800e8SDoug Rabson GSS_KRB5_REGISTER_ACCEPTOR_IDENTITY_X 1205*c19800e8SDoug Rabson 1206*c19800e8SDoug Rabson * krb5/accept_sec_context.c: reimplement 1207*c19800e8SDoug Rabson gsskrb5_register_acceptor_identity 1208*c19800e8SDoug Rabson 1209*c19800e8SDoug Rabson * mech/gss_krb5.c: implement gsskrb5_register_acceptor_identity 1210*c19800e8SDoug Rabson 1211*c19800e8SDoug Rabson * mech/gss_inquire_mechs_for_name.c: call _gss_load_mech 1212*c19800e8SDoug Rabson 1213*c19800e8SDoug Rabson * mech/gss_inquire_cred.c (gss_inquire_cred): call _gss_load_mech 1214*c19800e8SDoug Rabson 1215*c19800e8SDoug Rabson * mech/gss_mech_switch.c: Make _gss_load_mech() atomic and run 1216*c19800e8SDoug Rabson only once, this have the side effect that _gss_mechs and 1217*c19800e8SDoug Rabson _gss_mech_oids is only initialized once, so if just the users of 1218*c19800e8SDoug Rabson these two global variables calls _gss_load_mech() first, it will 1219*c19800e8SDoug Rabson act as a barrier and make sure the variables are never changed and 1220*c19800e8SDoug Rabson we don't need to lock them. 1221*c19800e8SDoug Rabson 1222*c19800e8SDoug Rabson * mech/utils.h: no need to mark functions extern. 1223*c19800e8SDoug Rabson 1224*c19800e8SDoug Rabson * mech/name.h: no need to mark _gss_find_mn extern. 1225*c19800e8SDoug Rabson 1226*c19800e8SDoug Rabson2006-07-19 Love Hörnquist Åstrand <[email protected]> 1227*c19800e8SDoug Rabson 1228*c19800e8SDoug Rabson * krb5/cfx.c: Redo the wrap length calculations. 1229*c19800e8SDoug Rabson 1230*c19800e8SDoug Rabson * krb5/test_cfx.c: test max_wrap_size in cfx.c 1231*c19800e8SDoug Rabson 1232*c19800e8SDoug Rabson * mech/gss_display_status.c: Handle more error codes. 1233*c19800e8SDoug Rabson 1234*c19800e8SDoug Rabson2006-07-07 Love Hörnquist Åstrand <[email protected]> 1235*c19800e8SDoug Rabson 1236*c19800e8SDoug Rabson * mech/mech_locl.h: Include <krb5-types.h> and "mechqueue.h" 1237*c19800e8SDoug Rabson 1238*c19800e8SDoug Rabson * mech/mechqueue.h: Add SLIST macros. 1239*c19800e8SDoug Rabson 1240*c19800e8SDoug Rabson * krb5/inquire_context.c: Don't free return values on success. 1241*c19800e8SDoug Rabson 1242*c19800e8SDoug Rabson * krb5/inquire_cred.c (_gsskrb5_inquire_cred): When cred provided 1243*c19800e8SDoug Rabson is the default cred, acquire the acceptor cred and initator cred 1244*c19800e8SDoug Rabson in two diffrent steps and then query them for the information, 1245*c19800e8SDoug Rabson this way, the code wont fail if there are no keytab, but there is 1246*c19800e8SDoug Rabson a credential cache. 1247*c19800e8SDoug Rabson 1248*c19800e8SDoug Rabson * mech/gss_inquire_cred.c: move the check if we found any cred 1249*c19800e8SDoug Rabson where it matter for both cases 1250*c19800e8SDoug Rabson (default cred and provided cred) 1251*c19800e8SDoug Rabson 1252*c19800e8SDoug Rabson * mech/gss_init_sec_context.c: If the desired mechanism can't 1253*c19800e8SDoug Rabson convert the name to a MN, fail with GSS_S_BAD_NAME rather then a 1254*c19800e8SDoug Rabson NULL de-reference. 1255*c19800e8SDoug Rabson 1256*c19800e8SDoug Rabson2006-07-06 Love Hörnquist Åstrand <[email protected]> 1257*c19800e8SDoug Rabson 1258*c19800e8SDoug Rabson * spnego/external.c: readd gss_spnego_inquire_names_for_mech 1259*c19800e8SDoug Rabson 1260*c19800e8SDoug Rabson * spnego/spnego_locl.h: reimplement 1261*c19800e8SDoug Rabson gss_spnego_inquire_names_for_mech add support function 1262*c19800e8SDoug Rabson _gss_spnego_supported_mechs 1263*c19800e8SDoug Rabson 1264*c19800e8SDoug Rabson * spnego/context_stubs.h: reimplement 1265*c19800e8SDoug Rabson gss_spnego_inquire_names_for_mech add support function 1266*c19800e8SDoug Rabson _gss_spnego_supported_mechs 1267*c19800e8SDoug Rabson 1268*c19800e8SDoug Rabson * spnego/context_stubs.c: drop gss_spnego_indicate_mechs 1269*c19800e8SDoug Rabson 1270*c19800e8SDoug Rabson * mech/gss_indicate_mechs.c: if the underlaying mech doesn't 1271*c19800e8SDoug Rabson support gss_indicate_mechs, use the oid in the mechswitch 1272*c19800e8SDoug Rabson structure 1273*c19800e8SDoug Rabson 1274*c19800e8SDoug Rabson * spnego/external.c: let the mech glue layer implement 1275*c19800e8SDoug Rabson gss_indicate_mechs 1276*c19800e8SDoug Rabson 1277*c19800e8SDoug Rabson * spnego/cred_stubs.c (gss_spnego_acquire_cred): don't care about 1278*c19800e8SDoug Rabson desired_mechs, get our own list with indicate_mechs and remove 1279*c19800e8SDoug Rabson ourself. 1280*c19800e8SDoug Rabson 1281*c19800e8SDoug Rabson2006-07-05 Love Hörnquist Åstrand <[email protected]> 1282*c19800e8SDoug Rabson 1283*c19800e8SDoug Rabson * spnego/external.c: remove gss_spnego_inquire_names_for_mech, let 1284*c19800e8SDoug Rabson the mechglue layer implement it 1285*c19800e8SDoug Rabson 1286*c19800e8SDoug Rabson * spnego/context_stubs.c: remove gss_spnego_inquire_names_for_mech, let 1287*c19800e8SDoug Rabson the mechglue layer implement it 1288*c19800e8SDoug Rabson 1289*c19800e8SDoug Rabson * spnego/spnego_locl.c: remove gss_spnego_inquire_names_for_mech, let 1290*c19800e8SDoug Rabson the mechglue layer implement it 1291*c19800e8SDoug Rabson 1292*c19800e8SDoug Rabson2006-07-01 Love Hörnquist Åstrand <[email protected]> 1293*c19800e8SDoug Rabson 1294*c19800e8SDoug Rabson * mech/gss_set_cred_option.c: fix argument to gss_release_cred 1295*c19800e8SDoug Rabson 1296*c19800e8SDoug Rabson2006-06-30 Love Hörnquist Åstrand <[email protected]> 1297*c19800e8SDoug Rabson 1298*c19800e8SDoug Rabson * krb5/init_sec_context.c: Make work on compilers that are 1299*c19800e8SDoug Rabson somewhat more picky then gcc4 (like gcc2.95) 1300*c19800e8SDoug Rabson 1301*c19800e8SDoug Rabson * krb5/init_sec_context.c (do_delegation): use KDCOptions2int to 1302*c19800e8SDoug Rabson convert fwd_flags to an integer, since otherwise int2KDCOptions in 1303*c19800e8SDoug Rabson krb5_get_forwarded_creds wont do the right thing. 1304*c19800e8SDoug Rabson 1305*c19800e8SDoug Rabson * mech/gss_set_cred_option.c (gss_set_cred_option): free memory on 1306*c19800e8SDoug Rabson failure 1307*c19800e8SDoug Rabson 1308*c19800e8SDoug Rabson * krb5/set_sec_context_option.c (_gsskrb5_set_sec_context_option): 1309*c19800e8SDoug Rabson init global kerberos context 1310*c19800e8SDoug Rabson 1311*c19800e8SDoug Rabson * krb5/set_cred_option.c (_gsskrb5_set_cred_option): init global 1312*c19800e8SDoug Rabson kerberos context 1313*c19800e8SDoug Rabson 1314*c19800e8SDoug Rabson * mech/gss_accept_sec_context.c: Insert the delegated sub cred on 1315*c19800e8SDoug Rabson the delegated cred handle, not cred handle 1316*c19800e8SDoug Rabson 1317*c19800e8SDoug Rabson * mech/gss_accept_sec_context.c (gss_accept_sec_context): handle 1318*c19800e8SDoug Rabson the case where ret_flags == NULL 1319*c19800e8SDoug Rabson 1320*c19800e8SDoug Rabson * mech/gss_mech_switch.c (add_builtin): set 1321*c19800e8SDoug Rabson _gss_mech_switch->gm_mech_oid 1322*c19800e8SDoug Rabson 1323*c19800e8SDoug Rabson * mech/gss_set_cred_option.c (gss_set_cred_option): laod mechs 1324*c19800e8SDoug Rabson 1325*c19800e8SDoug Rabson * test_cred.c (gss_print_errors): don't try to print error when 1326*c19800e8SDoug Rabson gss_display_status failed 1327*c19800e8SDoug Rabson 1328*c19800e8SDoug Rabson * Makefile.am: Add mech/gss_release_oid.c 1329*c19800e8SDoug Rabson 1330*c19800e8SDoug Rabson * mech/gss_release_oid.c: Add gss_release_oid, reverse of 1331*c19800e8SDoug Rabson gss_duplicate_oid 1332*c19800e8SDoug Rabson 1333*c19800e8SDoug Rabson * spnego/compat.c: preferred_mech_type was allocated with 1334*c19800e8SDoug Rabson gss_duplicate_oid in one place and assigned static varianbles a 1335*c19800e8SDoug Rabson the second place. change that static assignement to 1336*c19800e8SDoug Rabson gss_duplicate_oid and bring back gss_release_oid. 1337*c19800e8SDoug Rabson 1338*c19800e8SDoug Rabson * spnego/compat.c (_gss_spnego_delete_sec_context): don't release 1339*c19800e8SDoug Rabson preferred_mech_type and negotiated_mech_type, they where never 1340*c19800e8SDoug Rabson allocated from the begining. 1341*c19800e8SDoug Rabson 1342*c19800e8SDoug Rabson2006-06-29 Love Hörnquist Åstrand <[email protected]> 1343*c19800e8SDoug Rabson 1344*c19800e8SDoug Rabson * mech/gss_import_name.c (gss_import_name): avoid 1345*c19800e8SDoug Rabson type-punned/strict aliasing rules 1346*c19800e8SDoug Rabson 1347*c19800e8SDoug Rabson * mech/gss_add_cred.c: avoid type-punned/strict aliasing rules 1348*c19800e8SDoug Rabson 1349*c19800e8SDoug Rabson * gssapi.h: Make gss_name_t an opaque type. 1350*c19800e8SDoug Rabson 1351*c19800e8SDoug Rabson * krb5: make gss_name_t an opaque type 1352*c19800e8SDoug Rabson 1353*c19800e8SDoug Rabson * krb5/set_cred_option.c: Add 1354*c19800e8SDoug Rabson 1355*c19800e8SDoug Rabson * mech/gss_set_cred_option.c (gss_set_cred_option): support the 1356*c19800e8SDoug Rabson case where *cred_handle == NULL 1357*c19800e8SDoug Rabson 1358*c19800e8SDoug Rabson * mech/gss_krb5.c (gss_krb5_import_cred): make sure cred is 1359*c19800e8SDoug Rabson GSS_C_NO_CREDENTIAL on failure. 1360*c19800e8SDoug Rabson 1361*c19800e8SDoug Rabson * mech/gss_acquire_cred.c (gss_acquire_cred): if desired_mechs is 1362*c19800e8SDoug Rabson NO_OID_SET, there is a need to load the mechs, so always do that. 1363*c19800e8SDoug Rabson 1364*c19800e8SDoug Rabson2006-06-28 Love Hörnquist Åstrand <[email protected]> 1365*c19800e8SDoug Rabson 1366*c19800e8SDoug Rabson * krb5/inquire_cred_by_oid.c: Reimplement GSS_KRB5_COPY_CCACHE_X 1367*c19800e8SDoug Rabson to instead pass a fullname to the credential, then resolve and 1368*c19800e8SDoug Rabson copy out the content, and then close the cred. 1369*c19800e8SDoug Rabson 1370*c19800e8SDoug Rabson * mech/gss_krb5.c: Reimplement GSS_KRB5_COPY_CCACHE_X to instead 1371*c19800e8SDoug Rabson pass a fullname to the credential, then resolve and copy out the 1372*c19800e8SDoug Rabson content, and then close the cred. 1373*c19800e8SDoug Rabson 1374*c19800e8SDoug Rabson * krb5/inquire_cred_by_oid.c: make "work", GSS_KRB5_COPY_CCACHE_X 1375*c19800e8SDoug Rabson interface needs to be re-done, currently its utterly broken. 1376*c19800e8SDoug Rabson 1377*c19800e8SDoug Rabson * mech/gss_set_cred_option.c: Make work. 1378*c19800e8SDoug Rabson 1379*c19800e8SDoug Rabson * krb5/external.c: Add _gsskrb5_set_{sec_context,cred}_option 1380*c19800e8SDoug Rabson 1381*c19800e8SDoug Rabson * mech/gss_krb5.c (gss_krb5_import_cred): implement 1382*c19800e8SDoug Rabson 1383*c19800e8SDoug Rabson * Makefile.am: Add gss_set_{sec_context,cred}_option and sort 1384*c19800e8SDoug Rabson 1385*c19800e8SDoug Rabson * mech/gss_set_{sec_context,cred}_option.c: add 1386*c19800e8SDoug Rabson 1387*c19800e8SDoug Rabson * gssapi.h: Add GSS_KRB5_IMPORT_CRED_X 1388*c19800e8SDoug Rabson 1389*c19800e8SDoug Rabson * test_*.c: make compile again 1390*c19800e8SDoug Rabson 1391*c19800e8SDoug Rabson * Makefile.am: Add lib dependencies and test programs 1392*c19800e8SDoug Rabson 1393*c19800e8SDoug Rabson * spnego: remove dependency on libkrb5 1394*c19800e8SDoug Rabson 1395*c19800e8SDoug Rabson * mech: Bug fixes, cleanup, compiler warnings, restructure code. 1396*c19800e8SDoug Rabson 1397*c19800e8SDoug Rabson * spnego: Rename gss_context_id_t and gss_cred_id_t to local names 1398*c19800e8SDoug Rabson 1399*c19800e8SDoug Rabson * krb5: repro copy the krb5 files here 1400*c19800e8SDoug Rabson 1401*c19800e8SDoug Rabson * mech: import Doug Rabson mechglue from freebsd 1402*c19800e8SDoug Rabson 1403*c19800e8SDoug Rabson * spnego: Import Luke Howard's SPNEGO from the mechglue branch 1404*c19800e8SDoug Rabson 1405*c19800e8SDoug Rabson2006-06-22 Love Hörnquist Åstrand <[email protected]> 1406*c19800e8SDoug Rabson 1407*c19800e8SDoug Rabson * gssapi.h: Add oid_to_str. 1408*c19800e8SDoug Rabson 1409*c19800e8SDoug Rabson * Makefile.am: add oid_to_str and test_oid 1410*c19800e8SDoug Rabson 1411*c19800e8SDoug Rabson * oid_to_str.c: Add gss_oid_to_str 1412*c19800e8SDoug Rabson 1413*c19800e8SDoug Rabson * test_oid.c: Add test for gss_oid_to_str() 1414*c19800e8SDoug Rabson 1415*c19800e8SDoug Rabson2006-05-13 Love Hörnquist Åstrand <[email protected]> 1416*c19800e8SDoug Rabson 1417*c19800e8SDoug Rabson * verify_mic.c: Less pointer signedness warnings. 1418*c19800e8SDoug Rabson 1419*c19800e8SDoug Rabson * unwrap.c: Less pointer signedness warnings. 1420*c19800e8SDoug Rabson 1421*c19800e8SDoug Rabson * arcfour.c: Less pointer signedness warnings. 1422*c19800e8SDoug Rabson 1423*c19800e8SDoug Rabson * gssapi_locl.h: Use const void * to instead of unsigned char * to 1424*c19800e8SDoug Rabson avoid pointer signedness warnings. 1425*c19800e8SDoug Rabson 1426*c19800e8SDoug Rabson * encapsulate.c: Use const void * to instead of unsigned char * to 1427*c19800e8SDoug Rabson avoid pointer signedness warnings. 1428*c19800e8SDoug Rabson 1429*c19800e8SDoug Rabson * decapsulate.c: Use const void * to instead of unsigned char * to 1430*c19800e8SDoug Rabson avoid pointer signedness warnings. 1431*c19800e8SDoug Rabson 1432*c19800e8SDoug Rabson * decapsulate.c: Less pointer signedness warnings. 1433*c19800e8SDoug Rabson 1434*c19800e8SDoug Rabson * cfx.c: Less pointer signedness warnings. 1435*c19800e8SDoug Rabson 1436*c19800e8SDoug Rabson * init_sec_context.c: Less pointer signedness warnings (partly by 1437*c19800e8SDoug Rabson using the new asn.1 CHOICE decoder) 1438*c19800e8SDoug Rabson 1439*c19800e8SDoug Rabson * import_sec_context.c: Less pointer signedness warnings. 1440*c19800e8SDoug Rabson 1441*c19800e8SDoug Rabson2006-05-09 Love Hörnquist Åstrand <[email protected]> 1442*c19800e8SDoug Rabson 1443*c19800e8SDoug Rabson * accept_sec_context.c (gsskrb5_is_cfx): always set is_cfx. From 1444*c19800e8SDoug Rabson Andrew Abartlet. 1445*c19800e8SDoug Rabson 1446*c19800e8SDoug Rabson2006-05-08 Love Hörnquist Åstrand <[email protected]> 1447*c19800e8SDoug Rabson 1448*c19800e8SDoug Rabson * get_mic.c (mic_des3): make sure message_buffer doesn't point to 1449*c19800e8SDoug Rabson free()ed memory on failure. Pointed out by IBM checker. 1450*c19800e8SDoug Rabson 1451*c19800e8SDoug Rabson2006-05-05 Love Hörnquist Åstrand <[email protected]> 1452*c19800e8SDoug Rabson 1453*c19800e8SDoug Rabson * Rename u_intXX_t to uintXX_t 1454*c19800e8SDoug Rabson 1455*c19800e8SDoug Rabson2006-05-04 Love Hörnquist Åstrand <[email protected]> 1456*c19800e8SDoug Rabson 1457*c19800e8SDoug Rabson * cfx.c: Less pointer signedness warnings. 1458*c19800e8SDoug Rabson 1459*c19800e8SDoug Rabson * arcfour.c: Avoid pointer signedness warnings. 1460*c19800e8SDoug Rabson 1461*c19800e8SDoug Rabson * gssapi_locl.h (gssapi_decode_*): make data argument const void * 1462*c19800e8SDoug Rabson 1463*c19800e8SDoug Rabson * 8003.c (gssapi_decode_*): make data argument const void * 1464*c19800e8SDoug Rabson 1465*c19800e8SDoug Rabson2006-04-12 Love Hörnquist Åstrand <[email protected]> 1466*c19800e8SDoug Rabson 1467*c19800e8SDoug Rabson * export_sec_context.c: Export sequence order element. From Wynn 1468*c19800e8SDoug Rabson Wilkes <[email protected]>. 1469*c19800e8SDoug Rabson 1470*c19800e8SDoug Rabson * import_sec_context.c: Import sequence order element. From Wynn 1471*c19800e8SDoug Rabson Wilkes <[email protected]>. 1472*c19800e8SDoug Rabson 1473*c19800e8SDoug Rabson * sequence.c (_gssapi_msg_order_import,_gssapi_msg_order_export): 1474*c19800e8SDoug Rabson New functions, used by {import,export}_sec_context. From Wynn 1475*c19800e8SDoug Rabson Wilkes <[email protected]>. 1476*c19800e8SDoug Rabson 1477*c19800e8SDoug Rabson * test_sequence.c: Add test for import/export sequence. 1478*c19800e8SDoug Rabson 1479*c19800e8SDoug Rabson2006-04-09 Love Hörnquist Åstrand <[email protected]> 1480*c19800e8SDoug Rabson 1481*c19800e8SDoug Rabson * add_cred.c: Check that cred != GSS_C_NO_CREDENTIAL, this is a 1482*c19800e8SDoug Rabson standard conformance failure, but much better then a crash. 1483*c19800e8SDoug Rabson 1484*c19800e8SDoug Rabson2006-04-02 Love Hörnquist Åstrand <[email protected]> 1485*c19800e8SDoug Rabson 1486*c19800e8SDoug Rabson * get_mic.c (get_mic*)_: make sure message_token is cleaned on 1487*c19800e8SDoug Rabson error, found by IBM checker. 1488*c19800e8SDoug Rabson 1489*c19800e8SDoug Rabson * wrap.c (wrap*): Reset output_buffer on error, found by IBM 1490*c19800e8SDoug Rabson checker. 1491*c19800e8SDoug Rabson 1492*c19800e8SDoug Rabson2006-02-15 Love Hörnquist Åstrand <[email protected]> 1493*c19800e8SDoug Rabson 1494*c19800e8SDoug Rabson * import_name.c: Accept both GSS_C_NT_HOSTBASED_SERVICE and 1495*c19800e8SDoug Rabson GSS_C_NT_HOSTBASED_SERVICE_X as nametype for hostbased names. 1496*c19800e8SDoug Rabson 1497*c19800e8SDoug Rabson2006-01-16 Love Hörnquist Åstrand <[email protected]> 1498*c19800e8SDoug Rabson 1499*c19800e8SDoug Rabson * delete_sec_context.c (gss_delete_sec_context): if the context 1500*c19800e8SDoug Rabson handle is GSS_C_NO_CONTEXT, don't fall over. 1501*c19800e8SDoug Rabson 1502*c19800e8SDoug Rabson2005-12-12 Love Hörnquist Åstrand <[email protected]> 1503*c19800e8SDoug Rabson 1504*c19800e8SDoug Rabson * gss_acquire_cred.3: Replace gss_krb5_import_ccache with 1505*c19800e8SDoug Rabson gss_krb5_import_cred and add more references 1506*c19800e8SDoug Rabson 1507*c19800e8SDoug Rabson2005-12-05 Love Hörnquist Åstrand <[email protected]> 1508*c19800e8SDoug Rabson 1509*c19800e8SDoug Rabson * gssapi.h: Change gss_krb5_import_ccache to gss_krb5_import_cred, 1510*c19800e8SDoug Rabson it can handle keytabs too. 1511*c19800e8SDoug Rabson 1512*c19800e8SDoug Rabson * add_cred.c (gss_add_cred): avoid deadlock 1513*c19800e8SDoug Rabson 1514*c19800e8SDoug Rabson * context_time.c (gssapi_lifetime_left): define the 0 lifetime as 1515*c19800e8SDoug Rabson GSS_C_INDEFINITE. 1516*c19800e8SDoug Rabson 1517*c19800e8SDoug Rabson2005-12-01 Love Hörnquist Åstrand <[email protected]> 1518*c19800e8SDoug Rabson 1519*c19800e8SDoug Rabson * acquire_cred.c (acquire_acceptor_cred): only check if principal 1520*c19800e8SDoug Rabson exists if we got called with principal as an argument. 1521*c19800e8SDoug Rabson 1522*c19800e8SDoug Rabson * acquire_cred.c (acquire_acceptor_cred): check that the acceptor 1523*c19800e8SDoug Rabson exists in the keytab before returning ok. 1524*c19800e8SDoug Rabson 1525*c19800e8SDoug Rabson2005-11-29 Love Hörnquist Åstrand <[email protected]> 1526*c19800e8SDoug Rabson 1527*c19800e8SDoug Rabson * copy_ccache.c (gss_krb5_import_cred): fix buglet, from Andrew 1528*c19800e8SDoug Rabson Bartlett. 1529*c19800e8SDoug Rabson 1530*c19800e8SDoug Rabson2005-11-25 Love Hörnquist Åstrand <[email protected]> 1531*c19800e8SDoug Rabson 1532*c19800e8SDoug Rabson * test_kcred.c: Rename gss_krb5_import_ccache to 1533*c19800e8SDoug Rabson gss_krb5_import_cred. 1534*c19800e8SDoug Rabson 1535*c19800e8SDoug Rabson * copy_ccache.c: Rename gss_krb5_import_ccache to 1536*c19800e8SDoug Rabson gss_krb5_import_cred and let it grow code to handle keytabs too. 1537*c19800e8SDoug Rabson 1538*c19800e8SDoug Rabson2005-11-02 Love Hörnquist Åstrand <[email protected]> 1539*c19800e8SDoug Rabson 1540*c19800e8SDoug Rabson * init_sec_context.c: Change sematics of ok-as-delegate to match 1541*c19800e8SDoug Rabson windows if 1542*c19800e8SDoug Rabson [gssapi]realm/ok-as-delegate=true is set, otherwise keep old 1543*c19800e8SDoug Rabson sematics. 1544*c19800e8SDoug Rabson 1545*c19800e8SDoug Rabson * release_cred.c (gss_release_cred): use 1546*c19800e8SDoug Rabson GSS_CF_DESTROY_CRED_ON_RELEASE to decide if the cache should be 1547*c19800e8SDoug Rabson krb5_cc_destroy-ed 1548*c19800e8SDoug Rabson 1549*c19800e8SDoug Rabson * acquire_cred.c (acquire_initiator_cred): 1550*c19800e8SDoug Rabson GSS_CF_DESTROY_CRED_ON_RELEASE on created credentials. 1551*c19800e8SDoug Rabson 1552*c19800e8SDoug Rabson * accept_sec_context.c (gsskrb5_accept_delegated_token): rewrite 1553*c19800e8SDoug Rabson to use gss_krb5_import_ccache 1554*c19800e8SDoug Rabson 1555*c19800e8SDoug Rabson2005-11-01 Love Hörnquist Åstrand <[email protected]> 1556*c19800e8SDoug Rabson 1557*c19800e8SDoug Rabson * arcfour.c: Remove signedness warnings. 1558*c19800e8SDoug Rabson 1559*c19800e8SDoug Rabson2005-10-31 Love Hörnquist Åstrand <[email protected]> 1560*c19800e8SDoug Rabson 1561*c19800e8SDoug Rabson * gss_acquire_cred.3: Document that gss_krb5_import_ccache is copy 1562*c19800e8SDoug Rabson by reference. 1563*c19800e8SDoug Rabson 1564*c19800e8SDoug Rabson * copy_ccache.c (gss_krb5_import_ccache): Instead of making a copy 1565*c19800e8SDoug Rabson of the ccache, make a reference by getting the name and resolving 1566*c19800e8SDoug Rabson the name. This way the cache is shared, this flipp side is of 1567*c19800e8SDoug Rabson course that if someone calls krb5_cc_destroy the cache is lost for 1568*c19800e8SDoug Rabson everyone. 1569*c19800e8SDoug Rabson 1570*c19800e8SDoug Rabson * test_kcred.c: Remove memory leaks. 1571*c19800e8SDoug Rabson 1572*c19800e8SDoug Rabson2005-10-26 Love Hörnquist Åstrand <[email protected]> 1573*c19800e8SDoug Rabson 1574*c19800e8SDoug Rabson * Makefile.am: build test_kcred 1575*c19800e8SDoug Rabson 1576*c19800e8SDoug Rabson * gss_acquire_cred.3: Document gss_krb5_import_ccache 1577*c19800e8SDoug Rabson 1578*c19800e8SDoug Rabson * gssapi.3: Sort and add gss_krb5_import_ccache. 1579*c19800e8SDoug Rabson 1580*c19800e8SDoug Rabson * acquire_cred.c (_gssapi_krb5_ccache_lifetime): break out code 1581*c19800e8SDoug Rabson used to extract lifetime from a credential cache 1582*c19800e8SDoug Rabson 1583*c19800e8SDoug Rabson * gssapi_locl.h: Add _gssapi_krb5_ccache_lifetime, used to extract 1584*c19800e8SDoug Rabson lifetime from a credential cache. 1585*c19800e8SDoug Rabson 1586*c19800e8SDoug Rabson * gssapi.h: add gss_krb5_import_ccache, reverse of 1587*c19800e8SDoug Rabson gss_krb5_copy_ccache 1588*c19800e8SDoug Rabson 1589*c19800e8SDoug Rabson * copy_ccache.c: add gss_krb5_import_ccache, reverse of 1590*c19800e8SDoug Rabson gss_krb5_copy_ccache 1591*c19800e8SDoug Rabson 1592*c19800e8SDoug Rabson * test_kcred.c: test gss_krb5_import_ccache 1593*c19800e8SDoug Rabson 1594*c19800e8SDoug Rabson2005-10-21 Love Hörnquist Åstrand <[email protected]> 1595*c19800e8SDoug Rabson 1596*c19800e8SDoug Rabson * acquire_cred.c (acquire_initiator_cred): use krb5_cc_cache_match 1597*c19800e8SDoug Rabson to find a matching creditial cache, if that failes, fallback to 1598*c19800e8SDoug Rabson the default cache. 1599*c19800e8SDoug Rabson 1600*c19800e8SDoug Rabson2005-10-12 Love Hörnquist Åstrand <[email protected]> 1601*c19800e8SDoug Rabson 1602*c19800e8SDoug Rabson * gssapi_locl.h: Add gssapi_krb5_set_status and 1603*c19800e8SDoug Rabson gssapi_krb5_clear_status 1604*c19800e8SDoug Rabson 1605*c19800e8SDoug Rabson * init_sec_context.c (spnego_reply): Don't pass back raw Kerberos 1606*c19800e8SDoug Rabson errors, use GSS-API errors instead. From Michael B Allen. 1607*c19800e8SDoug Rabson 1608*c19800e8SDoug Rabson * display_status.c: Add gssapi_krb5_clear_status, 1609*c19800e8SDoug Rabson gssapi_krb5_set_status for handling error messages. 1610*c19800e8SDoug Rabson 1611*c19800e8SDoug Rabson2005-08-23 Love Hörnquist Åstrand <[email protected]> 1612*c19800e8SDoug Rabson 1613*c19800e8SDoug Rabson * external.c: Use rk_UNCONST to avoid const warning. 1614*c19800e8SDoug Rabson 1615*c19800e8SDoug Rabson * display_status.c: Constify strings to avoid warnings. 1616*c19800e8SDoug Rabson 1617*c19800e8SDoug Rabson2005-08-11 Love Hörnquist Åstrand <[email protected]> 1618*c19800e8SDoug Rabson 1619*c19800e8SDoug Rabson * init_sec_context.c: avoid warnings, update (c) 1620*c19800e8SDoug Rabson 1621*c19800e8SDoug Rabson2005-07-13 Love Hörnquist Åstrand <[email protected]> 1622*c19800e8SDoug Rabson 1623*c19800e8SDoug Rabson * init_sec_context.c (spnego_initial): use NegotiationToken 1624*c19800e8SDoug Rabson encoder now that we have one with the new asn1. compiler. 1625*c19800e8SDoug Rabson 1626*c19800e8SDoug Rabson * Makefile.am: the new asn.1 compiler includes the modules name in 1627*c19800e8SDoug Rabson the depend file 1628*c19800e8SDoug Rabson 1629*c19800e8SDoug Rabson2005-06-16 Love Hörnquist Åstrand <[email protected]> 1630*c19800e8SDoug Rabson 1631*c19800e8SDoug Rabson * decapsulate.c: use rk_UNCONST 1632*c19800e8SDoug Rabson 1633*c19800e8SDoug Rabson * ccache_name.c: rename to avoid shadowing 1634*c19800e8SDoug Rabson 1635*c19800e8SDoug Rabson * gssapi_locl.h: give kret in GSSAPI_KRB5_INIT a more unique name 1636*c19800e8SDoug Rabson 1637*c19800e8SDoug Rabson * process_context_token.c: use rk_UNCONST to unconstify 1638*c19800e8SDoug Rabson 1639*c19800e8SDoug Rabson * test_cred.c: rename optind to optidx 1640*c19800e8SDoug Rabson 1641*c19800e8SDoug Rabson2005-05-30 Love Hörnquist Åstrand <[email protected]> 1642*c19800e8SDoug Rabson 1643*c19800e8SDoug Rabson * init_sec_context.c (init_auth): honor ok-as-delegate if local 1644*c19800e8SDoug Rabson configuration approves 1645*c19800e8SDoug Rabson 1646*c19800e8SDoug Rabson * gssapi_locl.h: prototype for _gss_check_compat 1647*c19800e8SDoug Rabson 1648*c19800e8SDoug Rabson * compat.c: export check_compat as _gss_check_compat 1649*c19800e8SDoug Rabson 1650*c19800e8SDoug Rabson2005-05-29 Love Hörnquist Åstrand <[email protected]> 1651*c19800e8SDoug Rabson 1652*c19800e8SDoug Rabson * init_sec_context.c: Prefix Der_class with ASN1_C_ to avoid 1653*c19800e8SDoug Rabson problems with system headerfiles that pollute the name space. 1654*c19800e8SDoug Rabson 1655*c19800e8SDoug Rabson * accept_sec_context.c: Prefix Der_class with ASN1_C_ to avoid 1656*c19800e8SDoug Rabson problems with system headerfiles that pollute the name space. 1657*c19800e8SDoug Rabson 1658*c19800e8SDoug Rabson2005-05-17 Love Hörnquist Åstrand <[email protected]> 1659*c19800e8SDoug Rabson 1660*c19800e8SDoug Rabson * init_sec_context.c (init_auth): set 1661*c19800e8SDoug Rabson KRB5_AUTH_CONTEXT_CLEAR_FORWARDED_CRED (for java compatibility), 1662*c19800e8SDoug Rabson also while here, use krb5_auth_con_addflags 1663*c19800e8SDoug Rabson 1664*c19800e8SDoug Rabson2005-05-06 Love Hörnquist Åstrand <[email protected]> 1665*c19800e8SDoug Rabson 1666*c19800e8SDoug Rabson * arcfour.c (_gssapi_wrap_arcfour): fix calculating the encap 1667*c19800e8SDoug Rabson length. From: Tom Maher <[email protected]> 1668*c19800e8SDoug Rabson 1669*c19800e8SDoug Rabson2005-05-02 Dave Love <[email protected]> 1670*c19800e8SDoug Rabson 1671*c19800e8SDoug Rabson * test_cred.c (main): Call setprogname. 1672*c19800e8SDoug Rabson 1673*c19800e8SDoug Rabson2005-04-27 Love Hörnquist Åstrand <[email protected]> 1674*c19800e8SDoug Rabson 1675*c19800e8SDoug Rabson * prefix all sequence symbols with _, they are not part of the 1676*c19800e8SDoug Rabson GSS-API api. By comment from Wynn Wilkes <[email protected]> 1677*c19800e8SDoug Rabson 1678*c19800e8SDoug Rabson2005-04-10 Love Hörnquist Åstrand <[email protected]> 1679*c19800e8SDoug Rabson 1680*c19800e8SDoug Rabson * accept_sec_context.c: break out the processing of the delegated 1681*c19800e8SDoug Rabson credential to a separate function to make error handling easier, 1682*c19800e8SDoug Rabson move the credential handling to after other setup is done 1683*c19800e8SDoug Rabson 1684*c19800e8SDoug Rabson * test_sequence.c: make less verbose in case of success 1685*c19800e8SDoug Rabson 1686*c19800e8SDoug Rabson * Makefile.am: add test_sequence to TESTS 1687*c19800e8SDoug Rabson 1688*c19800e8SDoug Rabson2005-04-01 Love Hörnquist Åstrand <[email protected]> 1689*c19800e8SDoug Rabson 1690*c19800e8SDoug Rabson * 8003.c (gssapi_krb5_verify_8003_checksum): check that cksum 1691*c19800e8SDoug Rabson isn't NULL From: Nicolas Pouvesle <[email protected]> 1692*c19800e8SDoug Rabson 1693*c19800e8SDoug Rabson2005-03-21 Love Hörnquist Åstrand <[email protected]> 1694*c19800e8SDoug Rabson 1695*c19800e8SDoug Rabson * Makefile.am: use $(LIB_roken) 1696*c19800e8SDoug Rabson 1697*c19800e8SDoug Rabson2005-03-16 Love Hörnquist Åstrand <[email protected]> 1698*c19800e8SDoug Rabson 1699*c19800e8SDoug Rabson * display_status.c (gssapi_krb5_set_error_string): pass in the 1700*c19800e8SDoug Rabson krb5_context to krb5_free_error_string 1701*c19800e8SDoug Rabson 1702*c19800e8SDoug Rabson2005-03-15 Love Hörnquist Åstrand <[email protected]> 1703*c19800e8SDoug Rabson 1704*c19800e8SDoug Rabson * display_status.c (gssapi_krb5_set_error_string): don't misuse 1705*c19800e8SDoug Rabson the krb5_get_error_string api 1706*c19800e8SDoug Rabson 1707*c19800e8SDoug Rabson2005-03-01 Love Hörnquist Åstrand <[email protected]> 1708*c19800e8SDoug Rabson 1709*c19800e8SDoug Rabson * compat.c (_gss_DES3_get_mic_compat): don't unlock mutex 1710*c19800e8SDoug Rabson here. Bug reported by Stefan Metzmacher <[email protected]> 1711*c19800e8SDoug Rabson 1712*c19800e8SDoug Rabson2005-02-21 Luke Howard <[email protected]> 1713*c19800e8SDoug Rabson 1714*c19800e8SDoug Rabson * init_sec_context.c: don't call krb5_get_credentials() with 1715*c19800e8SDoug Rabson KRB5_TC_MATCH_KEYTYPE, it can lead to the credentials cache 1716*c19800e8SDoug Rabson growing indefinitely as no key is found with KEYTYPE_NULL 1717*c19800e8SDoug Rabson 1718*c19800e8SDoug Rabson * compat.c: remove GSS_C_EXPECTING_MECH_LIST_MIC_FLAG, it is 1719*c19800e8SDoug Rabson no longer used (however the mechListMIC behaviour is broken, 1720*c19800e8SDoug Rabson rfc2478bis support requires the code in the mechglue branch) 1721*c19800e8SDoug Rabson 1722*c19800e8SDoug Rabson * init_sec_context.c: remove GSS_C_EXPECTING_MECH_LIST_MIC_FLAG 1723*c19800e8SDoug Rabson 1724*c19800e8SDoug Rabson * gssapi.h: remove GSS_C_EXPECTING_MECH_LIST_MIC_FLAG 1725*c19800e8SDoug Rabson 1726*c19800e8SDoug Rabson2005-01-05 Luke Howard <[email protected]> 1727*c19800e8SDoug Rabson 1728*c19800e8SDoug Rabson * 8003.c: use symbolic name for checksum type 1729*c19800e8SDoug Rabson 1730*c19800e8SDoug Rabson * accept_sec_context.c: allow client to indicate 1731*c19800e8SDoug Rabson that subkey should be used 1732*c19800e8SDoug Rabson 1733*c19800e8SDoug Rabson * acquire_cred.c: plug leak 1734*c19800e8SDoug Rabson 1735*c19800e8SDoug Rabson * get_mic.c: use gss_krb5_get_subkey() instead 1736*c19800e8SDoug Rabson of gss_krb5_get_{local,remote}key(), support 1737*c19800e8SDoug Rabson KEYTYPE_ARCFOUR_56 1738*c19800e8SDoug Rabson 1739*c19800e8SDoug Rabson * gssapi_local.c: use gss_krb5_get_subkey(), 1740*c19800e8SDoug Rabson support KEYTYPE_ARCFOUR_56 1741*c19800e8SDoug Rabson 1742*c19800e8SDoug Rabson * import_sec_context.c: plug leak 1743*c19800e8SDoug Rabson 1744*c19800e8SDoug Rabson * unwrap.c: use gss_krb5_get_subkey(), 1745*c19800e8SDoug Rabson support KEYTYPE_ARCFOUR_56 1746*c19800e8SDoug Rabson 1747*c19800e8SDoug Rabson * verify_mic.c: use gss_krb5_get_subkey(), 1748*c19800e8SDoug Rabson support KEYTYPE_ARCFOUR_56 1749*c19800e8SDoug Rabson 1750*c19800e8SDoug Rabson * wrap.c: use gss_krb5_get_subkey(), 1751*c19800e8SDoug Rabson support KEYTYPE_ARCFOUR_56 1752*c19800e8SDoug Rabson 1753*c19800e8SDoug Rabson2004-11-30 Love Hörnquist Åstrand <[email protected]> 1754*c19800e8SDoug Rabson 1755*c19800e8SDoug Rabson * inquire_cred.c: Reverse order of HEIMDAL_MUTEX_unlock and 1756*c19800e8SDoug Rabson gss_release_cred to avoid deadlock, from Luke Howard 1757*c19800e8SDoug Rabson <[email protected]>. 1758*c19800e8SDoug Rabson 1759*c19800e8SDoug Rabson2004-09-06 Love Hörnquist Åstrand <[email protected]> 1760*c19800e8SDoug Rabson 1761*c19800e8SDoug Rabson * gss_acquire_cred.3: gss_krb5_extract_authz_data_from_sec_context 1762*c19800e8SDoug Rabson was renamed to gsskrb5_extract_authz_data_from_sec_context 1763*c19800e8SDoug Rabson 1764*c19800e8SDoug Rabson2004-08-07 Love Hörnquist Åstrand <[email protected]> 1765*c19800e8SDoug Rabson 1766*c19800e8SDoug Rabson * unwrap.c: mutex buglet, From: Luke Howard <[email protected]> 1767*c19800e8SDoug Rabson 1768*c19800e8SDoug Rabson * arcfour.c: mutex buglet, From: Luke Howard <[email protected]> 1769*c19800e8SDoug Rabson 1770*c19800e8SDoug Rabson2004-05-06 Love Hörnquist Åstrand <[email protected]> 1771*c19800e8SDoug Rabson 1772*c19800e8SDoug Rabson * gssapi.3: spelling from Josef El-Rayes <[email protected]> while 1773*c19800e8SDoug Rabson here, write some text about the SPNEGO situation 1774*c19800e8SDoug Rabson 1775*c19800e8SDoug Rabson2004-04-08 Love Hörnquist Åstrand <[email protected]> 1776*c19800e8SDoug Rabson 1777*c19800e8SDoug Rabson * cfx.c: s/CTXAcceptorSubkey/CFXAcceptorSubkey/ 1778*c19800e8SDoug Rabson 1779*c19800e8SDoug Rabson2004-04-07 Love Hörnquist Åstrand <[email protected]> 1780*c19800e8SDoug Rabson 1781*c19800e8SDoug Rabson * gssapi.h: add GSS_C_EXPECTING_MECH_LIST_MIC_FLAG From: Luke 1782*c19800e8SDoug Rabson Howard <[email protected]> 1783*c19800e8SDoug Rabson 1784*c19800e8SDoug Rabson * init_sec_context.c (spnego_reply): use 1785*c19800e8SDoug Rabson _gss_spnego_require_mechlist_mic to figure out if we need to check 1786*c19800e8SDoug Rabson MechListMIC; From: Luke Howard <[email protected]> 1787*c19800e8SDoug Rabson 1788*c19800e8SDoug Rabson * accept_sec_context.c (send_accept): use 1789*c19800e8SDoug Rabson _gss_spnego_require_mechlist_mic to figure out if we need to send 1790*c19800e8SDoug Rabson MechListMIC; From: Luke Howard <[email protected]> 1791*c19800e8SDoug Rabson 1792*c19800e8SDoug Rabson * gssapi_locl.h: add _gss_spnego_require_mechlist_mic 1793*c19800e8SDoug Rabson From: Luke Howard <[email protected]> 1794*c19800e8SDoug Rabson 1795*c19800e8SDoug Rabson * compat.c: add _gss_spnego_require_mechlist_mic for compatibility 1796*c19800e8SDoug Rabson with MS SPNEGO, From: Luke Howard <[email protected]> 1797*c19800e8SDoug Rabson 1798*c19800e8SDoug Rabson2004-04-05 Love Hörnquist Åstrand <[email protected]> 1799*c19800e8SDoug Rabson 1800*c19800e8SDoug Rabson * accept_sec_context.c (gsskrb5_is_cfx): krb5_keyblock->keytype is 1801*c19800e8SDoug Rabson an enctype, not keytype 18021c43270aSJacques Vidrine 18031c43270aSJacques Vidrine * accept_sec_context.c: use ASN1_MALLOC_ENCODE 1804*c19800e8SDoug Rabson 18051c43270aSJacques Vidrine * init_sec_context.c: avoid the malloc loop and just allocate the 1806*c19800e8SDoug Rabson propper amount of data 1807*c19800e8SDoug Rabson 1808*c19800e8SDoug Rabson * init_sec_context.c (spnego_initial): handle mech_token better 1809*c19800e8SDoug Rabson 1810*c19800e8SDoug Rabson2004-03-19 Love Hörnquist Åstrand <[email protected]> 1811*c19800e8SDoug Rabson 1812*c19800e8SDoug Rabson * gssapi.h: add gss_krb5_get_tkt_flags 1813*c19800e8SDoug Rabson 1814*c19800e8SDoug Rabson * Makefile.am: add ticket_flags.c 1815*c19800e8SDoug Rabson 1816*c19800e8SDoug Rabson * ticket_flags.c: Get ticket-flags from acceptor ticket From: Luke 1817*c19800e8SDoug Rabson Howard <[email protected]> 1818*c19800e8SDoug Rabson 1819*c19800e8SDoug Rabson * gss_acquire_cred.3: document gss_krb5_get_tkt_flags 1820*c19800e8SDoug Rabson 1821*c19800e8SDoug Rabson2004-03-14 Love Hörnquist Åstrand <[email protected]> 18221c43270aSJacques Vidrine 18231c43270aSJacques Vidrine * acquire_cred.c (gss_acquire_cred): check usage before even 18241c43270aSJacques Vidrine bothering to process it, add both keytab and initial tgt if 1825*c19800e8SDoug Rabson requested 1826*c19800e8SDoug Rabson 1827*c19800e8SDoug Rabson * wrap.c: support cfx, try to handle acceptor asserted subkey 1828*c19800e8SDoug Rabson 1829*c19800e8SDoug Rabson * unwrap.c: support cfx, try to handle acceptor asserted subkey 1830*c19800e8SDoug Rabson 1831*c19800e8SDoug Rabson * verify_mic.c: support cfx 1832*c19800e8SDoug Rabson 1833*c19800e8SDoug Rabson * get_mic.c: support cfx 1834*c19800e8SDoug Rabson 1835*c19800e8SDoug Rabson * test_sequence.c: handle changed signature of 1836*c19800e8SDoug Rabson gssapi_msg_order_create 1837*c19800e8SDoug Rabson 1838*c19800e8SDoug Rabson * import_sec_context.c: handle acceptor asserted subkey 1839*c19800e8SDoug Rabson 1840*c19800e8SDoug Rabson * init_sec_context.c: handle acceptor asserted subkey 1841*c19800e8SDoug Rabson 1842*c19800e8SDoug Rabson * accept_sec_context.c: handle acceptor asserted subkey 1843*c19800e8SDoug Rabson 1844*c19800e8SDoug Rabson * sequence.c: add dummy use_64 argument to gssapi_msg_order_create 1845*c19800e8SDoug Rabson 1846*c19800e8SDoug Rabson * gssapi_locl.h: add partial support for CFX 1847*c19800e8SDoug Rabson 1848*c19800e8SDoug Rabson * Makefile.am (noinst_PROGRAMS) += test_cred 1849*c19800e8SDoug Rabson 1850*c19800e8SDoug Rabson * test_cred.c: gssapi credential testing 1851*c19800e8SDoug Rabson 1852*c19800e8SDoug Rabson * test_acquire_cred.c: fix comment 1853*c19800e8SDoug Rabson 1854*c19800e8SDoug Rabson2004-03-07 Love Hörnquist Åstrand <[email protected]> 1855*c19800e8SDoug Rabson 1856*c19800e8SDoug Rabson * arcfour.h: drop structures for message formats, no longer used 1857*c19800e8SDoug Rabson 1858*c19800e8SDoug Rabson * arcfour.c: comment describing message formats 1859*c19800e8SDoug Rabson 1860*c19800e8SDoug Rabson * accept_sec_context.c (spnego_accept_sec_context): make sure the 18611c43270aSJacques Vidrine length of the choice element doesn't overrun us 18621c43270aSJacques Vidrine 18631c43270aSJacques Vidrine * init_sec_context.c (spnego_reply): make sure the length of the 1864*c19800e8SDoug Rabson choice element doesn't overrun us 1865*c19800e8SDoug Rabson 18661c43270aSJacques Vidrine * spnego.asn1: move NegotiationToken to avoid warning 1867*c19800e8SDoug Rabson 1868*c19800e8SDoug Rabson * spnego.asn1: uncomment NegotiationToken 18691c43270aSJacques Vidrine 18701c43270aSJacques Vidrine * Makefile.am: spnego_files += asn1_NegotiationToken.x 18711c43270aSJacques Vidrine 1872*c19800e8SDoug Rabson2004-01-25 Love Hörnquist Åstrand <[email protected]> 18731c43270aSJacques Vidrine 1874*c19800e8SDoug Rabson * gssapi.h: add gss_krb5_ccache_name 18751c43270aSJacques Vidrine 1876*c19800e8SDoug Rabson * Makefile.am (libgssapi_la_SOURCES): += ccache_name.c 1877*c19800e8SDoug Rabson 1878*c19800e8SDoug Rabson * ccache_name.c (gss_krb5_ccache_name): help function enable to 18791c43270aSJacques Vidrine set krb5 name, using out_name argument makes function no longer 1880*c19800e8SDoug Rabson thread-safe 1881*c19800e8SDoug Rabson 18821c43270aSJacques Vidrine * gssapi.3: add missing gss_krb5_ references 1883*c19800e8SDoug Rabson 18841c43270aSJacques Vidrine * gss_acquire_cred.3: document gss_krb5_ccache_name 1885*c19800e8SDoug Rabson 1886*c19800e8SDoug Rabson2003-12-12 Love Hörnquist Åstrand <[email protected]> 1887*c19800e8SDoug Rabson 18881c43270aSJacques Vidrine * cfx.c: make rrc a modulus operation if its longer then the 1889*c19800e8SDoug Rabson length of the message, noticed by Sam Hartman 1890*c19800e8SDoug Rabson 18911c43270aSJacques Vidrine2003-12-07 Love Hörnquist Åstrand <[email protected]> 1892*c19800e8SDoug Rabson 18931c43270aSJacques Vidrine * accept_sec_context.c: use krb5_auth_con_addflags 1894*c19800e8SDoug Rabson 1895*c19800e8SDoug Rabson2003-12-05 Love Hörnquist Åstrand <[email protected]> 18961c43270aSJacques Vidrine 1897*c19800e8SDoug Rabson * cfx.c: Wrap token id was in wrong order, found by Sam Hartman 18981c43270aSJacques Vidrine 1899*c19800e8SDoug Rabson2003-12-04 Love Hörnquist Åstrand <[email protected]> 1900*c19800e8SDoug Rabson 1901*c19800e8SDoug Rabson * cfx.c: add AcceptorSubkey (but no code understand it yet) ignore 1902*c19800e8SDoug Rabson unknown token flags 1903*c19800e8SDoug Rabson 1904*c19800e8SDoug Rabson2003-11-22 Love Hörnquist Åstrand <[email protected]> 1905*c19800e8SDoug Rabson 1906*c19800e8SDoug Rabson * accept_sec_context.c: Don't require timestamp to be set on 1907*c19800e8SDoug Rabson delegated token, its already protected by the outer token (and 1908*c19800e8SDoug Rabson windows doesn't alway send it) Pointed out by Zi-Bin Yang 1909*c19800e8SDoug Rabson <[email protected]> on heimdal-discuss 1910*c19800e8SDoug Rabson 1911*c19800e8SDoug Rabson2003-11-14 Love Hörnquist Åstrand <[email protected]> 1912*c19800e8SDoug Rabson 1913*c19800e8SDoug Rabson * cfx.c: fix {} error, pointed out by Liqiang Zhu 1914*c19800e8SDoug Rabson 1915*c19800e8SDoug Rabson2003-11-10 Love Hörnquist Åstrand <[email protected]> 1916*c19800e8SDoug Rabson 1917*c19800e8SDoug Rabson * cfx.c: Sequence number should be stored in bigendian order From: 1918*c19800e8SDoug Rabson Luke Howard <[email protected]> 1919*c19800e8SDoug Rabson 1920*c19800e8SDoug Rabson2003-11-09 Love Hörnquist Åstrand <[email protected]> 1921*c19800e8SDoug Rabson 1922*c19800e8SDoug Rabson * delete_sec_context.c (gss_delete_sec_context): don't free 1923*c19800e8SDoug Rabson ticket, krb5_free_ticket does that now 1924*c19800e8SDoug Rabson 1925*c19800e8SDoug Rabson2003-11-06 Love Hörnquist Åstrand <[email protected]> 1926*c19800e8SDoug Rabson 1927*c19800e8SDoug Rabson * cfx.c: checksum the header last in MIC token, update to -03 1928*c19800e8SDoug Rabson From: Luke Howard <[email protected]> 1929*c19800e8SDoug Rabson 1930*c19800e8SDoug Rabson2003-10-07 Love Hörnquist Åstrand <[email protected]> 1931*c19800e8SDoug Rabson 1932*c19800e8SDoug Rabson * add_cred.c: If its a MEMORY cc, make a copy. We need to do this 1933*c19800e8SDoug Rabson since now gss_release_cred will destroy the cred. This should be 1934*c19800e8SDoug Rabson really be solved a better way. 1935*c19800e8SDoug Rabson 1936*c19800e8SDoug Rabson * acquire_cred.c (gss_release_cred): if its a mcc, destroy it 1937*c19800e8SDoug Rabson rather the just release it Found by: "Zi-Bin Yang" 1938*c19800e8SDoug Rabson <[email protected]> 1939*c19800e8SDoug Rabson 1940*c19800e8SDoug Rabson * acquire_cred.c (acquire_initiator_cred): use kret instead of ret 1941*c19800e8SDoug Rabson where appropriate 1942*c19800e8SDoug Rabson 1943*c19800e8SDoug Rabson2003-09-30 Love Hörnquist Åstrand <[email protected]> 1944*c19800e8SDoug Rabson 1945*c19800e8SDoug Rabson * gss_acquire_cred.3: spelling 1946*c19800e8SDoug Rabson From: jmc <[email protected]> 1947*c19800e8SDoug Rabson 1948*c19800e8SDoug Rabson2003-09-23 Love Hörnquist Åstrand <[email protected]> 1949*c19800e8SDoug Rabson 1950*c19800e8SDoug Rabson * cfx.c: - EC and RRC are big-endian, not little-endian - The 1951*c19800e8SDoug Rabson default is now to rotate regardless of GSS_C_DCE_STYLE. There are 1952*c19800e8SDoug Rabson no longer any references to GSS_C_DCE_STYLE. - rrc_rotate() 1953*c19800e8SDoug Rabson avoids allocating memory on the heap if rrc <= 256 1954*c19800e8SDoug Rabson From: Luke Howard <[email protected]> 1955*c19800e8SDoug Rabson 1956*c19800e8SDoug Rabson2003-09-22 Love Hörnquist Åstrand <[email protected]> 1957*c19800e8SDoug Rabson 1958*c19800e8SDoug Rabson * cfx.[ch]: rrc_rotate() was untested and broken, fix it. 1959*c19800e8SDoug Rabson Set and verify wrap Token->Filler. 1960*c19800e8SDoug Rabson Correct token ID for wrap tokens, 1961*c19800e8SDoug Rabson were accidentally swapped with delete tokens. 1962*c19800e8SDoug Rabson From: Luke Howard <[email protected]> 1963*c19800e8SDoug Rabson 1964*c19800e8SDoug Rabson2003-09-21 Love Hörnquist Åstrand <[email protected]> 1965*c19800e8SDoug Rabson 1966*c19800e8SDoug Rabson * cfx.[ch]: no ASN.1-ish header on per-message tokens 1967*c19800e8SDoug Rabson From: Luke Howard <[email protected]> 1968*c19800e8SDoug Rabson 1969*c19800e8SDoug Rabson2003-09-19 Love Hörnquist Åstrand <[email protected]> 1970*c19800e8SDoug Rabson 1971*c19800e8SDoug Rabson * arcfour.h: remove depenency on gss_arcfour_mic_token and 1972*c19800e8SDoug Rabson gss_arcfour_warp_token 1973*c19800e8SDoug Rabson 1974*c19800e8SDoug Rabson * arcfour.c: remove depenency on gss_arcfour_mic_token and 1975*c19800e8SDoug Rabson gss_arcfour_warp_token 1976*c19800e8SDoug Rabson 1977*c19800e8SDoug Rabson2003-09-18 Love Hörnquist Åstrand <[email protected]> 1978*c19800e8SDoug Rabson 1979*c19800e8SDoug Rabson * 8003.c: remove #if 0'ed code 1980*c19800e8SDoug Rabson 1981*c19800e8SDoug Rabson2003-09-17 Love Hörnquist Åstrand <[email protected]> 1982*c19800e8SDoug Rabson 1983*c19800e8SDoug Rabson * accept_sec_context.c (gsskrb5_accept_sec_context): set sequence 1984*c19800e8SDoug Rabson number when not requesting mutual auth From: Luke Howard 1985*c19800e8SDoug Rabson <[email protected]> 1986*c19800e8SDoug Rabson 1987*c19800e8SDoug Rabson * init_sec_context.c (init_auth): set sequence number when not 1988*c19800e8SDoug Rabson requesting mutual auth From: Luke Howard <[email protected]> 1989*c19800e8SDoug Rabson 1990*c19800e8SDoug Rabson2003-09-16 Love Hörnquist Åstrand <[email protected]> 1991*c19800e8SDoug Rabson 1992*c19800e8SDoug Rabson * arcfour.c (*): set minor_status 1993*c19800e8SDoug Rabson (gss_wrap): set conf_state to conf_req_flags on success 1994*c19800e8SDoug Rabson From: Luke Howard <[email protected]> 1995*c19800e8SDoug Rabson 1996*c19800e8SDoug Rabson * wrap.c (gss_wrap_size_limit): use existing function From: Luke 1997*c19800e8SDoug Rabson Howard <[email protected]> 1998*c19800e8SDoug Rabson 1999*c19800e8SDoug Rabson2003-09-12 Love Hörnquist Åstrand <[email protected]> 2000*c19800e8SDoug Rabson 2001*c19800e8SDoug Rabson * indicate_mechs.c (gss_indicate_mechs): in case of error, free 2002*c19800e8SDoug Rabson mech_set 2003*c19800e8SDoug Rabson 2004*c19800e8SDoug Rabson * indicate_mechs.c (gss_indicate_mechs): add SPNEGO 2005*c19800e8SDoug Rabson 2006*c19800e8SDoug Rabson2003-09-10 Love Hörnquist Åstrand <[email protected]> 2007*c19800e8SDoug Rabson 2008*c19800e8SDoug Rabson * init_sec_context.c (spnego_initial): catch errors and return 2009*c19800e8SDoug Rabson them 2010*c19800e8SDoug Rabson 2011*c19800e8SDoug Rabson * init_sec_context.c (spnego_initial): add #if 0 out version of 2012*c19800e8SDoug Rabson the CHOICE branch encoding, also where here, free no longer used 2013*c19800e8SDoug Rabson memory 2014*c19800e8SDoug Rabson 2015*c19800e8SDoug Rabson2003-09-09 Love Hörnquist Åstrand <[email protected]> 2016*c19800e8SDoug Rabson 2017*c19800e8SDoug Rabson * gss_acquire_cred.3: support GSS_SPNEGO_MECHANISM 2018*c19800e8SDoug Rabson 2019*c19800e8SDoug Rabson * accept_sec_context.c: SPNEGO doesn't include gss wrapping on 2020*c19800e8SDoug Rabson SubsequentContextToken like the Kerberos 5 mech does. 2021*c19800e8SDoug Rabson 2022*c19800e8SDoug Rabson * init_sec_context.c (spnego_reply): SPNEGO doesn't include gss 2023*c19800e8SDoug Rabson wrapping on SubsequentContextToken like the Kerberos 5 mech 2024*c19800e8SDoug Rabson does. Lets check for it anyway. 2025*c19800e8SDoug Rabson 2026*c19800e8SDoug Rabson * accept_sec_context.c: Add support for SPNEGO on the initator 2027*c19800e8SDoug Rabson side. Implementation initially from Assar Westerlund, passes 2028*c19800e8SDoug Rabson though quite a lot of hands before I commited it. 2029*c19800e8SDoug Rabson 2030*c19800e8SDoug Rabson * init_sec_context.c: Add support for SPNEGO on the initator side. 2031*c19800e8SDoug Rabson Tested with ldap server on a Windows 2000 DC. Implementation 2032*c19800e8SDoug Rabson initially from Assar Westerlund, passes though quite a lot of 2033*c19800e8SDoug Rabson hands before I commited it. 2034*c19800e8SDoug Rabson 2035*c19800e8SDoug Rabson * gssapi.h: export GSS_SPNEGO_MECHANISM 2036*c19800e8SDoug Rabson 2037*c19800e8SDoug Rabson * gssapi_locl.h: include spnego_as.h add prototype for 2038*c19800e8SDoug Rabson gssapi_krb5_get_mech 2039*c19800e8SDoug Rabson 2040*c19800e8SDoug Rabson * decapsulate.c (gssapi_krb5_get_mech): make non static 2041*c19800e8SDoug Rabson 2042*c19800e8SDoug Rabson * Makefile.am: build SPNEGO file 2043*c19800e8SDoug Rabson 2044*c19800e8SDoug Rabson2003-09-08 Love Hörnquist Åstrand <[email protected]> 2045*c19800e8SDoug Rabson 2046*c19800e8SDoug Rabson * external.c: SPENGO and IAKERB oids 2047*c19800e8SDoug Rabson 2048*c19800e8SDoug Rabson * spnego.asn1: SPENGO ASN1 2049*c19800e8SDoug Rabson 2050*c19800e8SDoug Rabson2003-09-05 Love Hörnquist Åstrand <[email protected]> 2051*c19800e8SDoug Rabson 2052*c19800e8SDoug Rabson * cfx.c: RRC also need to be zero before wraping them 2053*c19800e8SDoug Rabson From: Luke Howard <[email protected]> 2054*c19800e8SDoug Rabson 2055*c19800e8SDoug Rabson2003-09-04 Love Hörnquist Åstrand <[email protected]> 2056*c19800e8SDoug Rabson 2057*c19800e8SDoug Rabson * encapsulate.c (gssapi_krb5_encap_length): don't return void 2058*c19800e8SDoug Rabson 2059*c19800e8SDoug Rabson2003-09-03 Love Hörnquist Åstrand <[email protected]> 2060*c19800e8SDoug Rabson 2061*c19800e8SDoug Rabson * verify_mic.c: switch from the des_ to the DES_ api 2062*c19800e8SDoug Rabson 2063*c19800e8SDoug Rabson * get_mic.c: switch from the des_ to the DES_ api 2064*c19800e8SDoug Rabson 2065*c19800e8SDoug Rabson * unwrap.c: switch from the des_ to the DES_ api 2066*c19800e8SDoug Rabson 2067*c19800e8SDoug Rabson * wrap.c: switch from the des_ to the DES_ api 2068*c19800e8SDoug Rabson 2069*c19800e8SDoug Rabson * cfx.c: EC is not included in the checksum since the length might 2070*c19800e8SDoug Rabson change depending on the data. From: Luke Howard <[email protected]> 2071*c19800e8SDoug Rabson 2072*c19800e8SDoug Rabson * acquire_cred.c: use 2073*c19800e8SDoug Rabson krb5_get_init_creds_opt_alloc/krb5_get_init_creds_opt_free 2074*c19800e8SDoug Rabson 2075*c19800e8SDoug Rabson2003-09-01 Love Hörnquist Åstrand <[email protected]> 2076*c19800e8SDoug Rabson 2077*c19800e8SDoug Rabson * copy_ccache.c: rename 2078*c19800e8SDoug Rabson gss_krb5_extract_authz_data_from_sec_context to 2079*c19800e8SDoug Rabson gsskrb5_extract_authz_data_from_sec_context 2080*c19800e8SDoug Rabson 2081*c19800e8SDoug Rabson * gssapi.h: rename gss_krb5_extract_authz_data_from_sec_context to 2082*c19800e8SDoug Rabson gsskrb5_extract_authz_data_from_sec_context 2083*c19800e8SDoug Rabson 2084*c19800e8SDoug Rabson2003-08-31 Love Hörnquist Åstrand <[email protected]> 2085*c19800e8SDoug Rabson 2086*c19800e8SDoug Rabson * copy_ccache.c (gss_krb5_extract_authz_data_from_sec_context): 2087*c19800e8SDoug Rabson check that we have a ticket before we start to use it 2088*c19800e8SDoug Rabson 2089*c19800e8SDoug Rabson * gss_acquire_cred.3: document 2090*c19800e8SDoug Rabson gss_krb5_extract_authz_data_from_sec_context 2091*c19800e8SDoug Rabson 2092*c19800e8SDoug Rabson * gssapi.h (gss_krb5_extract_authz_data_from_sec_context): 2093*c19800e8SDoug Rabson return the kerberos authorizationdata, from idea of Luke Howard 2094*c19800e8SDoug Rabson 2095*c19800e8SDoug Rabson * copy_ccache.c (gss_krb5_extract_authz_data_from_sec_context): 2096*c19800e8SDoug Rabson return the kerberos authorizationdata, from idea of Luke Howard 2097*c19800e8SDoug Rabson 2098*c19800e8SDoug Rabson * verify_mic.c (gss_verify_mic_internal): switch type and key 2099*c19800e8SDoug Rabson argument 2100*c19800e8SDoug Rabson 2101*c19800e8SDoug Rabson2003-08-30 Love Hörnquist Åstrand <[email protected]> 2102*c19800e8SDoug Rabson 2103*c19800e8SDoug Rabson * cfx.[ch]: draft-ietf-krb-wg-gssapi-cfx-01.txt implemetation 2104*c19800e8SDoug Rabson From: Luke Howard <[email protected]> 2105*c19800e8SDoug Rabson 2106*c19800e8SDoug Rabson2003-08-28 Love Hörnquist Åstrand <[email protected]> 2107*c19800e8SDoug Rabson 2108*c19800e8SDoug Rabson * arcfour.c (arcfour_mic_cksum): use free_Checksum to free the 2109*c19800e8SDoug Rabson checksum 2110*c19800e8SDoug Rabson 2111*c19800e8SDoug Rabson * arcfour.h: swap two last arguments to verify_mic for consistency 2112*c19800e8SDoug Rabson with des3 2113*c19800e8SDoug Rabson 2114*c19800e8SDoug Rabson * wrap.c,unwrap.c,get_mic.c,verify_mic.c,cfx.c,cfx.h: 2115*c19800e8SDoug Rabson prefix cfx symbols with _gssapi_ 2116*c19800e8SDoug Rabson 2117*c19800e8SDoug Rabson * arcfour.c: release the right buffer 2118*c19800e8SDoug Rabson 2119*c19800e8SDoug Rabson * arcfour.c: rename token structure in consistency with rest of 2120*c19800e8SDoug Rabson GSS-API From: Luke Howard <[email protected]> 2121*c19800e8SDoug Rabson 2122*c19800e8SDoug Rabson * unwrap.c (unwrap_des3): use _gssapi_verify_pad 2123*c19800e8SDoug Rabson (unwrap_des): use _gssapi_verify_pad 2124*c19800e8SDoug Rabson 2125*c19800e8SDoug Rabson * arcfour.c (_gssapi_wrap_arcfour): set the correct padding 2126*c19800e8SDoug Rabson (_gssapi_unwrap_arcfour): verify and strip padding 2127*c19800e8SDoug Rabson 2128*c19800e8SDoug Rabson * gssapi_locl.h: added _gssapi_verify_pad 2129*c19800e8SDoug Rabson 2130*c19800e8SDoug Rabson * decapsulate.c (_gssapi_verify_pad): verify padding of a gss 2131*c19800e8SDoug Rabson wrapped message and return its length 2132*c19800e8SDoug Rabson 2133*c19800e8SDoug Rabson * arcfour.c: support KEYTYPE_ARCFOUR_56 keys, from Luke Howard 2134*c19800e8SDoug Rabson <[email protected]> 2135*c19800e8SDoug Rabson 2136*c19800e8SDoug Rabson * arcfour.c: use right seal alg, inherit keytype from parent key 2137*c19800e8SDoug Rabson 2138*c19800e8SDoug Rabson * arcfour.c: include the confounder in the checksum use the right 2139*c19800e8SDoug Rabson key usage number for warped/unwraped tokens 2140*c19800e8SDoug Rabson 2141*c19800e8SDoug Rabson * gssapi.h: add gss_krb5_nt_general_name as an mit compat glue 2142*c19800e8SDoug Rabson (same as GSS_KRB5_NT_PRINCIPAL_NAME) 2143*c19800e8SDoug Rabson 2144*c19800e8SDoug Rabson * unwrap.c: hook in arcfour unwrap 2145*c19800e8SDoug Rabson 2146*c19800e8SDoug Rabson * wrap.c: hook in arcfour wrap 2147*c19800e8SDoug Rabson 2148*c19800e8SDoug Rabson * verify_mic.c: hook in arcfour verify_mic 2149*c19800e8SDoug Rabson 2150*c19800e8SDoug Rabson * get_mic.c: hook in arcfour get_mic 2151*c19800e8SDoug Rabson 2152*c19800e8SDoug Rabson * arcfour.c: implement wrap/unwarp 2153*c19800e8SDoug Rabson 2154*c19800e8SDoug Rabson * gssapi_locl.h: add gssapi_{en,de}code_be_om_uint32 2155*c19800e8SDoug Rabson 2156*c19800e8SDoug Rabson * 8003.c: add gssapi_{en,de}code_be_om_uint32 2157*c19800e8SDoug Rabson 2158*c19800e8SDoug Rabson2003-08-27 Love Hörnquist Åstrand <[email protected]> 2159*c19800e8SDoug Rabson 2160*c19800e8SDoug Rabson * arcfour.c (_gssapi_verify_mic_arcfour): Do the checksum on right 2161*c19800e8SDoug Rabson area. Swap filler check, it was reversed. 2162*c19800e8SDoug Rabson 2163*c19800e8SDoug Rabson * Makefile.am (libgssapi_la_SOURCES): += arcfour.c 2164*c19800e8SDoug Rabson 2165*c19800e8SDoug Rabson * gssapi_locl.h: include "arcfour.h" 2166*c19800e8SDoug Rabson 2167*c19800e8SDoug Rabson * arcfour.c: arcfour gss-api mech, get_mic/verify_mic working 2168*c19800e8SDoug Rabson 2169*c19800e8SDoug Rabson * arcfour.h: arcfour gss-api mech, get_mic/verify_mic working 2170*c19800e8SDoug Rabson 2171*c19800e8SDoug Rabson2003-08-26 Love Hörnquist Åstrand <[email protected]> 2172*c19800e8SDoug Rabson 2173*c19800e8SDoug Rabson * gssapi_locl.h: always include cfx.h add prototype for 2174*c19800e8SDoug Rabson _gssapi_decapsulate 2175*c19800e8SDoug Rabson 2176*c19800e8SDoug Rabson * cfx.[ch]: Implementation of draft-ietf-krb-wg-gssapi-cfx-00.txt 2177*c19800e8SDoug Rabson from Luke Howard <[email protected]> 2178*c19800e8SDoug Rabson 2179*c19800e8SDoug Rabson * decapsulate.c: add _gssapi_decapsulate, from Luke Howard 2180*c19800e8SDoug Rabson <[email protected]> 2181*c19800e8SDoug Rabson 2182*c19800e8SDoug Rabson2003-08-25 Love Hörnquist Åstrand <[email protected]> 2183*c19800e8SDoug Rabson 2184*c19800e8SDoug Rabson * unwrap.c: encap/decap now takes a oid if the enctype/keytype is 2185*c19800e8SDoug Rabson arcfour, return error add hook for cfx 2186*c19800e8SDoug Rabson 2187*c19800e8SDoug Rabson * verify_mic.c: encap/decap now takes a oid if the enctype/keytype 2188*c19800e8SDoug Rabson is arcfour, return error add hook for cfx 2189*c19800e8SDoug Rabson 2190*c19800e8SDoug Rabson * get_mic.c: encap/decap now takes a oid if the enctype/keytype is 2191*c19800e8SDoug Rabson arcfour, return error add hook for cfx 2192*c19800e8SDoug Rabson 2193*c19800e8SDoug Rabson * accept_sec_context.c: encap/decap now takes a oid 2194*c19800e8SDoug Rabson 2195*c19800e8SDoug Rabson * init_sec_context.c: encap/decap now takes a oid 2196*c19800e8SDoug Rabson 2197*c19800e8SDoug Rabson * gssapi_locl.h: include cfx.h if we need it lifetime is a 2198*c19800e8SDoug Rabson OM_uint32, depend on gssapi interface add all new encap/decap 2199*c19800e8SDoug Rabson functions 22001c43270aSJacques Vidrine 22011c43270aSJacques Vidrine * decapsulate.c: add decap functions that doesn't take the token 2202*c19800e8SDoug Rabson type also make all decap function take the oid mech that they 2203*c19800e8SDoug Rabson should use 22041c43270aSJacques Vidrine 2205*c19800e8SDoug Rabson * encapsulate.c: add encap functions that doesn't take the token 2206*c19800e8SDoug Rabson type also make all encap function take the oid mech that they 2207*c19800e8SDoug Rabson should use 2208*c19800e8SDoug Rabson 2209*c19800e8SDoug Rabson * sequence.c (elem_insert): fix a off by one index counter 2210bbd80c28SJacques Vidrine 2211*c19800e8SDoug Rabson * inquire_cred.c (gss_inquire_cred): handle cred_handle being 2212*c19800e8SDoug Rabson GSS_C_NO_CREDENTIAL and use the default cred then. 2213*c19800e8SDoug Rabson 2214*c19800e8SDoug Rabson2003-08-19 Love Hörnquist Åstrand <[email protected]> 2215*c19800e8SDoug Rabson 2216*c19800e8SDoug Rabson * gss_acquire_cred.3: break out extensions and document 2217*c19800e8SDoug Rabson gsskrb5_register_acceptor_identity 2218*c19800e8SDoug Rabson 2219*c19800e8SDoug Rabson2003-08-18 Love Hörnquist Åstrand <[email protected]> 2220*c19800e8SDoug Rabson 2221*c19800e8SDoug Rabson * test_acquire_cred.c (print_time): time is returned in seconds 2222*c19800e8SDoug Rabson from now, not unix time 2223*c19800e8SDoug Rabson 2224*c19800e8SDoug Rabson2003-08-17 Love Hörnquist Åstrand <[email protected]> 2225*c19800e8SDoug Rabson 2226*c19800e8SDoug Rabson * compat.c (check_compat): avoid leaking principal when finding a 2227*c19800e8SDoug Rabson match 2228*c19800e8SDoug Rabson 2229*c19800e8SDoug Rabson * address_to_krb5addr.c: sa_size argument to krb5_addr2sockaddr is 2230*c19800e8SDoug Rabson a krb5_socklen_t 2231*c19800e8SDoug Rabson 2232*c19800e8SDoug Rabson * acquire_cred.c (gss_acquire_cred): 4th argument to 2233*c19800e8SDoug Rabson gss_test_oid_set_member is a int 2234*c19800e8SDoug Rabson 2235bbd80c28SJacques Vidrine2003-07-22 Love Hörnquist Åstrand <[email protected]> 2236bbd80c28SJacques Vidrine 2237bbd80c28SJacques Vidrine * init_sec_context.c (repl_mutual): don't set kerberos error where 2238bbd80c28SJacques Vidrine there was no kerberos error 2239bbd80c28SJacques Vidrine 2240*c19800e8SDoug Rabson * gssapi_locl.h: Add destruction/creation prototypes and structure 2241*c19800e8SDoug Rabson for the thread specific storage. 2242bbd80c28SJacques Vidrine 2243*c19800e8SDoug Rabson * display_status.c: use thread specific storage to set/get the 2244bbd80c28SJacques Vidrine kerberos error message 2245*c19800e8SDoug Rabson 2246*c19800e8SDoug Rabson * init.c: Provide locking around the creation of the global 2247bbd80c28SJacques Vidrine krb5_context. Add destruction/creation functions for the thread 2248*c19800e8SDoug Rabson specific storage that the error string handling is using. 2249bbd80c28SJacques Vidrine 2250*c19800e8SDoug Rabson2003-07-20 Love Hörnquist Åstrand <[email protected]> 2251*c19800e8SDoug Rabson 2252bbd80c28SJacques Vidrine * gss_acquire_cred.3: add missing prototype and missing .Ft 2253*c19800e8SDoug Rabson arguments 2254*c19800e8SDoug Rabson 2255*c19800e8SDoug Rabson2003-06-17 Love Hörnquist Åstrand <[email protected]> 2256*c19800e8SDoug Rabson 2257*c19800e8SDoug Rabson * verify_mic.c: reorder code so sequence numbers can can be used 2258*c19800e8SDoug Rabson 2259*c19800e8SDoug Rabson * unwrap.c: reorder code so sequence numbers can can be used 2260*c19800e8SDoug Rabson 2261*c19800e8SDoug Rabson * sequence.c: remove unused function, indent, add 2262*c19800e8SDoug Rabson gssapi_msg_order_f that filter gss flags to gss_msg_order flags 2263bbd80c28SJacques Vidrine 2264bbd80c28SJacques Vidrine * gssapi_locl.h: prototypes for 2265*c19800e8SDoug Rabson gssapi_{encode_om_uint32,decode_om_uint32} add sequence number 2266*c19800e8SDoug Rabson verifier prototypes 2267*c19800e8SDoug Rabson 2268*c19800e8SDoug Rabson * delete_sec_context.c: destroy sequence number verifier 2269bbd80c28SJacques Vidrine 2270bbd80c28SJacques Vidrine * init_sec_context.c: remember to free data use sequence number 2271*c19800e8SDoug Rabson verifier 2272*c19800e8SDoug Rabson 2273bbd80c28SJacques Vidrine * accept_sec_context.c: don't clear output_token twice remember to 2274bbd80c28SJacques Vidrine free data use sequence number verifier 2275bbd80c28SJacques Vidrine 2276*c19800e8SDoug Rabson * 8003.c: export and rename encode_om_uint32/decode_om_uint32 and 2277*c19800e8SDoug Rabson start to use them 2278*c19800e8SDoug Rabson 2279*c19800e8SDoug Rabson2003-06-09 Johan Danielsson <[email protected]> 2280*c19800e8SDoug Rabson 2281bbd80c28SJacques Vidrine * Makefile.am: can't have sequence.c in two different places 2282bbd80c28SJacques Vidrine 2283*c19800e8SDoug Rabson2003-06-06 Love Hörnquist Åstrand <[email protected]> 2284*c19800e8SDoug Rabson 2285bbd80c28SJacques Vidrine * test_sequence.c: check rollover, print summery 2286bbd80c28SJacques Vidrine 2287bbd80c28SJacques Vidrine * wrap.c (sub_wrap_size): gss_wrap_size_limit() has 2288bbd80c28SJacques Vidrine req_output_size and max_input_size around the wrong way -- it 2289bbd80c28SJacques Vidrine returns the output token size for a given input size, rather than 2290bbd80c28SJacques Vidrine the maximum input size for a given output token size. 2291bbd80c28SJacques Vidrine 2292bbd80c28SJacques Vidrine From: Luke Howard <[email protected]> 2293bbd80c28SJacques Vidrine 2294bbd80c28SJacques Vidrine2003-06-05 Love Hörnquist Åstrand <[email protected]> 2295bbd80c28SJacques Vidrine 2296bbd80c28SJacques Vidrine * gssapi_locl.h: add prototypes for sequence.c 2297bbd80c28SJacques Vidrine 2298bbd80c28SJacques Vidrine * Makefile.am (libgssapi_la_SOURCES): add sequence.c 2299bbd80c28SJacques Vidrine (test_sequence): build 2300bbd80c28SJacques Vidrine 2301bbd80c28SJacques Vidrine * sequence.c: sequence number checks, order and replay 2302bbd80c28SJacques Vidrine * test_sequence.c: sequence number checks, order and replay 2303bbd80c28SJacques Vidrine 2304bbd80c28SJacques Vidrine2003-06-03 Love Hörnquist Åstrand <[email protected]> 2305bbd80c28SJacques Vidrine 2306bbd80c28SJacques Vidrine * accept_sec_context.c (gss_accept_sec_context): make sure time is 2307bbd80c28SJacques Vidrine returned in seconds from now, not in kerberos time 2308bbd80c28SJacques Vidrine 2309bbd80c28SJacques Vidrine * acquire_cred.c (gss_aquire_cred): make sure time is returned in 2310bbd80c28SJacques Vidrine seconds from now, not in kerberos time 2311bbd80c28SJacques Vidrine 2312bbd80c28SJacques Vidrine * init_sec_context.c (init_auth): if the cred is expired before we 2313bbd80c28SJacques Vidrine tries to create a token, fail so the peer doesn't need reject us 2314bbd80c28SJacques Vidrine (*): make sure time is returned in seconds from now, 2315bbd80c28SJacques Vidrine not in kerberos time 2316bbd80c28SJacques Vidrine (repl_mutual): remember to unlock the context mutex 2317bbd80c28SJacques Vidrine 2318bbd80c28SJacques Vidrine * context_time.c (gss_context_time): remove unused variable 2319bbd80c28SJacques Vidrine 2320bbd80c28SJacques Vidrine * verify_mic.c: make sure minor_status is always set, pointed out 2321bbd80c28SJacques Vidrine by Luke Howard <[email protected]> 2322bbd80c28SJacques Vidrine 2323bbd80c28SJacques Vidrine2003-05-21 Love Hörnquist Åstrand <[email protected]> 2324bbd80c28SJacques Vidrine 2325bbd80c28SJacques Vidrine * *.[ch]: do some basic locking (no reference counting so contexts 2326bbd80c28SJacques Vidrine can be removed while still used) 2327bbd80c28SJacques Vidrine - don't export gss_ctx_id_t_desc_struct and gss_cred_id_t_desc_struct 2328bbd80c28SJacques Vidrine - make sure all lifetime are returned in seconds left until expired, 2329bbd80c28SJacques Vidrine not in unix epoch 2330bbd80c28SJacques Vidrine 2331bbd80c28SJacques Vidrine * gss_acquire_cred.3: document argument lifetime_rec to function 2332bbd80c28SJacques Vidrine gss_inquire_context 2333bbd80c28SJacques Vidrine 2334bbd80c28SJacques Vidrine2003-05-17 Love Hörnquist Åstrand <[email protected]> 2335bbd80c28SJacques Vidrine 2336bbd80c28SJacques Vidrine * test_acquire_cred.c: test gss_add_cred more then once 2337bbd80c28SJacques Vidrine 2338bbd80c28SJacques Vidrine2003-05-06 Love Hörnquist Åstrand <[email protected]> 2339bbd80c28SJacques Vidrine 2340bbd80c28SJacques Vidrine * gssapi.h: if __cplusplus, wrap the extern variable (just to be 2341bbd80c28SJacques Vidrine safe) and functions in extern "C" { } 2342bbd80c28SJacques Vidrine 2343bbd80c28SJacques Vidrine2003-04-30 Love Hörnquist Åstrand <[email protected]> 2344bbd80c28SJacques Vidrine 2345bbd80c28SJacques Vidrine * gssapi.3: more about the des3 mic mess 2346bbd80c28SJacques Vidrine 2347bbd80c28SJacques Vidrine * verify_mic.c (verify_mic_des3): always check if the mic is the 2348bbd80c28SJacques Vidrine correct mic or the mic that old heimdal would have generated 2349bbd80c28SJacques Vidrine 2350bbd80c28SJacques Vidrine2003-04-28 Jacques Vidrine <[email protected]> 2351bbd80c28SJacques Vidrine 2352bbd80c28SJacques Vidrine * verify_mic.c (verify_mic_des3): If MIC verification fails, 2353bbd80c28SJacques Vidrine retry using the `old' MIC computation (with zero IV). 2354bbd80c28SJacques Vidrine 2355bbd80c28SJacques Vidrine2003-04-26 Love Hörnquist Åstrand <[email protected]> 2356bbd80c28SJacques Vidrine 2357bbd80c28SJacques Vidrine * gss_acquire_cred.3: more about difference between comparing IN 2358bbd80c28SJacques Vidrine and MN 2359bbd80c28SJacques Vidrine 2360bbd80c28SJacques Vidrine * gss_acquire_cred.3: more about name type and access control 2361bbd80c28SJacques Vidrine 2362bbd80c28SJacques Vidrine2003-04-25 Love Hörnquist Åstrand <[email protected]> 2363bbd80c28SJacques Vidrine 2364bbd80c28SJacques Vidrine * gss_acquire_cred.3: document gss_context_time 2365bbd80c28SJacques Vidrine 2366bbd80c28SJacques Vidrine * context_time.c: if lifetime of context have expired, set 2367bbd80c28SJacques Vidrine time_rec to 0 and return GSS_S_CONTEXT_EXPIRED 2368bbd80c28SJacques Vidrine 2369bbd80c28SJacques Vidrine * gssapi.3: document [gssapi]correct_des3_mic 2370bbd80c28SJacques Vidrine [gssapi]broken_des3_mic 2371bbd80c28SJacques Vidrine 2372bbd80c28SJacques Vidrine * gss_acquire_cred.3: document gss_krb5_compat_des3_mic 2373bbd80c28SJacques Vidrine 2374bbd80c28SJacques Vidrine * compat.c (gss_krb5_compat_des3_mic): enable turning on/off des3 2375bbd80c28SJacques Vidrine mic compat 2376bbd80c28SJacques Vidrine (_gss_DES3_get_mic_compat): handle [gssapi]correct_des3_mic too 2377bbd80c28SJacques Vidrine 2378bbd80c28SJacques Vidrine * gssapi.h (gss_krb5_compat_des3_mic): new function, turn on/off 2379bbd80c28SJacques Vidrine des3 mic compat 2380bbd80c28SJacques Vidrine (GSS_C_KRB5_COMPAT_DES3_MIC): cpp symbol that exists if 2381bbd80c28SJacques Vidrine gss_krb5_compat_des3_mic exists 2382bbd80c28SJacques Vidrine 2383bbd80c28SJacques Vidrine2003-04-24 Love Hörnquist Åstrand <[email protected]> 2384bbd80c28SJacques Vidrine 2385bbd80c28SJacques Vidrine * Makefile.am: (libgssapi_la_LDFLAGS): update major 2386bbd80c28SJacques Vidrine version of gssapi for incompatiblity in 3des getmic support 2387bbd80c28SJacques Vidrine 2388bbd80c28SJacques Vidrine2003-04-23 Love Hörnquist Åstrand <[email protected]> 2389bbd80c28SJacques Vidrine 2390bbd80c28SJacques Vidrine * Makefile.am: test_acquire_cred_LDADD: use libgssapi.la not 2391bbd80c28SJacques Vidrine ./libgssapi.la (make make -jN work) 2392bbd80c28SJacques Vidrine 2393bbd80c28SJacques Vidrine2003-04-16 Love Hörnquist Åstrand <[email protected]> 2394bbd80c28SJacques Vidrine 2395bbd80c28SJacques Vidrine * gssapi.3: spelling 2396bbd80c28SJacques Vidrine 2397bbd80c28SJacques Vidrine * gss_acquire_cred.3: Change .Fd #include <header.h> to .In 2398bbd80c28SJacques Vidrine header.h, from Thomas Klausner <[email protected]> 2399bbd80c28SJacques Vidrine 2400bbd80c28SJacques Vidrine 2401bbd80c28SJacques Vidrine2003-04-06 Love Hörnquist Åstrand <[email protected]> 2402bbd80c28SJacques Vidrine 2403bbd80c28SJacques Vidrine * gss_acquire_cred.3: spelling 2404bbd80c28SJacques Vidrine 2405bbd80c28SJacques Vidrine * Makefile.am: remove stuff that sneaked in with last commit 2406bbd80c28SJacques Vidrine 2407bbd80c28SJacques Vidrine * acquire_cred.c (acquire_initiator_cred): if the requested name 2408bbd80c28SJacques Vidrine isn't in the ccache, also check keytab. Extact the krbtgt for the 2409bbd80c28SJacques Vidrine default realm to check how long the credentials will last. 2410bbd80c28SJacques Vidrine 2411bbd80c28SJacques Vidrine * add_cred.c (gss_add_cred): don't create a new ccache, just open 2412bbd80c28SJacques Vidrine the old one; better check if output handle is compatible with new 2413bbd80c28SJacques Vidrine (copied) handle 2414bbd80c28SJacques Vidrine 2415bbd80c28SJacques Vidrine * test_acquire_cred.c: test gss_add_cred too 2416bbd80c28SJacques Vidrine 2417bbd80c28SJacques Vidrine2003-04-03 Love Hörnquist Åstrand <[email protected]> 2418bbd80c28SJacques Vidrine 2419bbd80c28SJacques Vidrine * Makefile.am: build test_acquire_cred 2420bbd80c28SJacques Vidrine 2421bbd80c28SJacques Vidrine * test_acquire_cred.c: simple gss_acquire_cred test 2422bbd80c28SJacques Vidrine 2423bbd80c28SJacques Vidrine2003-04-02 Love Hörnquist Åstrand <[email protected]> 2424bbd80c28SJacques Vidrine 2425bbd80c28SJacques Vidrine * gss_acquire_cred.3: s/gssapi/GSS-API/ 2426bbd80c28SJacques Vidrine 2427bbd80c28SJacques Vidrine2003-03-19 Love Hörnquist Åstrand <[email protected]> 2428bbd80c28SJacques Vidrine 2429bbd80c28SJacques Vidrine * gss_acquire_cred.3: document v1 interface (and that they are 2430bbd80c28SJacques Vidrine obsolete) 2431bbd80c28SJacques Vidrine 2432bbd80c28SJacques Vidrine2003-03-18 Love Hörnquist Åstrand <[email protected]> 2433bbd80c28SJacques Vidrine 2434bbd80c28SJacques Vidrine * gss_acquire_cred.3: list supported mechanism and nametypes 2435bbd80c28SJacques Vidrine 2436bbd80c28SJacques Vidrine2003-03-16 Love Hörnquist Åstrand <[email protected]> 2437bbd80c28SJacques Vidrine 2438bbd80c28SJacques Vidrine * gss_acquire_cred.3: text about gss_display_name 2439bbd80c28SJacques Vidrine 2440bbd80c28SJacques Vidrine * Makefile.am (libgssapi_la_LDFLAGS): bump to 3:6:2 2441bbd80c28SJacques Vidrine (libgssapi_la_SOURCES): add all new functions 2442bbd80c28SJacques Vidrine 2443bbd80c28SJacques Vidrine * gssapi.3: now that we have a functions, uncomment the missing 2444bbd80c28SJacques Vidrine ones 2445bbd80c28SJacques Vidrine 2446bbd80c28SJacques Vidrine * gss_acquire_cred.3: now that we have a functions, uncomment the 2447bbd80c28SJacques Vidrine missing ones 2448bbd80c28SJacques Vidrine 2449bbd80c28SJacques Vidrine * process_context_token.c: implement gss_process_context_token 2450bbd80c28SJacques Vidrine 2451bbd80c28SJacques Vidrine * inquire_names_for_mech.c: implement gss_inquire_names_for_mech 2452bbd80c28SJacques Vidrine 2453bbd80c28SJacques Vidrine * inquire_mechs_for_name.c: implement gss_inquire_mechs_for_name 2454bbd80c28SJacques Vidrine 2455bbd80c28SJacques Vidrine * inquire_cred_by_mech.c: implement gss_inquire_cred_by_mech 2456bbd80c28SJacques Vidrine 2457bbd80c28SJacques Vidrine * add_cred.c: implement gss_add_cred 2458bbd80c28SJacques Vidrine 2459bbd80c28SJacques Vidrine * acquire_cred.c (gss_acquire_cred): more testing of input 2460bbd80c28SJacques Vidrine argument, make sure output arguments are ok, since we don't know 2461bbd80c28SJacques Vidrine the time_rec (for now), set it to time_req 2462bbd80c28SJacques Vidrine 2463bbd80c28SJacques Vidrine * export_sec_context.c: send lifetime, also set minor_status 2464bbd80c28SJacques Vidrine 2465bbd80c28SJacques Vidrine * get_mic.c: set minor_status 2466bbd80c28SJacques Vidrine 2467bbd80c28SJacques Vidrine * import_sec_context.c (gss_import_sec_context): add error 2468bbd80c28SJacques Vidrine checking, pick up lifetime (if there is no lifetime, use 2469bbd80c28SJacques Vidrine GSS_C_INDEFINITE) 2470bbd80c28SJacques Vidrine 2471bbd80c28SJacques Vidrine * init_sec_context.c: take care to set export value to something 2472bbd80c28SJacques Vidrine sane before we start so caller will have harmless values in them 2473bbd80c28SJacques Vidrine if then function fails 2474bbd80c28SJacques Vidrine 2475bbd80c28SJacques Vidrine * release_buffer.c (gss_release_buffer): set minor_status 2476bbd80c28SJacques Vidrine 2477bbd80c28SJacques Vidrine * wrap.c: make sure minor_status get set 2478bbd80c28SJacques Vidrine 2479bbd80c28SJacques Vidrine * verify_mic.c (gss_verify_mic_internal): rename verify_mic to 2480bbd80c28SJacques Vidrine gss_verify_mic_internal and let it take the type as an argument, 2481bbd80c28SJacques Vidrine (gss_verify_mic): call gss_verify_mic_internal 2482bbd80c28SJacques Vidrine set minor_status 2483bbd80c28SJacques Vidrine 2484bbd80c28SJacques Vidrine * unwrap.c: set minor_status 2485bbd80c28SJacques Vidrine 2486bbd80c28SJacques Vidrine * test_oid_set_member.c (gss_test_oid_set_member): use 2487bbd80c28SJacques Vidrine gss_oid_equal 2488bbd80c28SJacques Vidrine 2489bbd80c28SJacques Vidrine * release_oid_set.c (gss_release_oid_set): set minor_status 2490bbd80c28SJacques Vidrine 2491bbd80c28SJacques Vidrine * release_name.c (gss_release_name): set minor_status 2492bbd80c28SJacques Vidrine 2493bbd80c28SJacques Vidrine * release_cred.c (gss_release_cred): set minor_status 2494bbd80c28SJacques Vidrine 2495bbd80c28SJacques Vidrine * add_oid_set_member.c (gss_add_oid_set_member): set minor_status 2496bbd80c28SJacques Vidrine 2497bbd80c28SJacques Vidrine * compare_name.c (gss_compare_name): set minor_status 2498bbd80c28SJacques Vidrine 2499bbd80c28SJacques Vidrine * compat.c (check_compat): make sure ret have a defined value 2500bbd80c28SJacques Vidrine 2501bbd80c28SJacques Vidrine * context_time.c (gss_context_time): set minor_status 25020cadf2f4SJacques Vidrine 25030cadf2f4SJacques Vidrine * copy_ccache.c (gss_krb5_copy_ccache): set minor_status 25040cadf2f4SJacques Vidrine 25050cadf2f4SJacques Vidrine * create_emtpy_oid_set.c (gss_create_empty_oid_set): set 25060cadf2f4SJacques Vidrine minor_status 25070cadf2f4SJacques Vidrine 25080cadf2f4SJacques Vidrine * delete_sec_context.c (gss_delete_sec_context): set minor_status 25090cadf2f4SJacques Vidrine 25100cadf2f4SJacques Vidrine * display_name.c (gss_display_name): set minor_status 25110cadf2f4SJacques Vidrine 25128373020dSJacques Vidrine * display_status.c (gss_display_status): use gss_oid_equal, handle 25138373020dSJacques Vidrine supplementary errors 25148373020dSJacques Vidrine 25158373020dSJacques Vidrine * duplicate_name.c (gss_duplicate_name): set minor_status 25168373020dSJacques Vidrine 25178373020dSJacques Vidrine * inquire_context.c (gss_inquire_context): set lifetime_rec now 25188373020dSJacques Vidrine when we know it, set minor_status 25198373020dSJacques Vidrine 25208373020dSJacques Vidrine * inquire_cred.c (gss_inquire_cred): take care to set export value 25218373020dSJacques Vidrine to something sane before we start so caller will have harmless 25228373020dSJacques Vidrine values in them if the function fails 25238373020dSJacques Vidrine 25248373020dSJacques Vidrine * accept_sec_context.c (gss_accept_sec_context): take care to set 25258373020dSJacques Vidrine export value to something sane before we start so caller will have 25268373020dSJacques Vidrine harmless values in them if then function fails, set lifetime from 25278373020dSJacques Vidrine ticket expiration date 25288373020dSJacques Vidrine 25298373020dSJacques Vidrine * indicate_mechs.c (gss_indicate_mechs): use 25308373020dSJacques Vidrine gss_create_empty_oid_set and gss_add_oid_set_member 25318373020dSJacques Vidrine 25328373020dSJacques Vidrine * gssapi.h (gss_ctx_id_t_desc): store the lifetime in the cred, 25338373020dSJacques Vidrine since there is no ticket transfered in the exported context 25348373020dSJacques Vidrine 25358373020dSJacques Vidrine * export_name.c (gss_export_name): export name with 25368373020dSJacques Vidrine GSS_C_NT_EXPORT_NAME wrapping, not just the principal 25378373020dSJacques Vidrine 25388373020dSJacques Vidrine * import_name.c (import_export_name): new function, parses a 25398373020dSJacques Vidrine GSS_C_NT_EXPORT_NAME 25408373020dSJacques Vidrine (import_krb5_name): factor out common code of parsing krb5 name 25418373020dSJacques Vidrine (gss_oid_equal): rename from oid_equal 25428373020dSJacques Vidrine 25438373020dSJacques Vidrine * gssapi_locl.h: add prototypes for gss_oid_equal and 25448373020dSJacques Vidrine gss_verify_mic_internal 25458373020dSJacques Vidrine 25464137ff4cSJacques Vidrine * gssapi.h: comment out the argument names 25474137ff4cSJacques Vidrine 25484137ff4cSJacques Vidrine2003-03-15 Love Hörnquist Åstrand <[email protected]> 25494137ff4cSJacques Vidrine 25504137ff4cSJacques Vidrine * gssapi.3: add LIST OF FUNCTIONS and copyright/license 25514137ff4cSJacques Vidrine 25524137ff4cSJacques Vidrine * Makefile.am: s/gss_aquire_cred.3/gss_acquire_cred.3/ 25534137ff4cSJacques Vidrine 25544137ff4cSJacques Vidrine * Makefile.am: man_MANS += gss_aquire_cred.3 25554137ff4cSJacques Vidrine 25564137ff4cSJacques Vidrine2003-03-14 Love Hörnquist Åstrand <[email protected]> 25574137ff4cSJacques Vidrine 25584137ff4cSJacques Vidrine * gss_aquire_cred.3: the gssapi api manpage 25594137ff4cSJacques Vidrine 25604137ff4cSJacques Vidrine2003-03-03 Love Hörnquist Åstrand <[email protected]> 25614137ff4cSJacques Vidrine 25624137ff4cSJacques Vidrine * inquire_context.c: (gss_inquire_context): rename argument open 25634137ff4cSJacques Vidrine to open_context 25644137ff4cSJacques Vidrine 25654137ff4cSJacques Vidrine * gssapi.h (gss_inquire_context): rename argument open to open_context 25664137ff4cSJacques Vidrine 25674137ff4cSJacques Vidrine2003-02-27 Love Hörnquist Åstrand <[email protected]> 25684137ff4cSJacques Vidrine 25694137ff4cSJacques Vidrine * init_sec_context.c (do_delegation): remove unused variable 25704137ff4cSJacques Vidrine subkey 25714137ff4cSJacques Vidrine 25724137ff4cSJacques Vidrine * gssapi.3: all 0.5.x version had broken token delegation 25734137ff4cSJacques Vidrine 25744137ff4cSJacques Vidrine2003-02-21 Love Hörnquist Åstrand <[email protected]> 25754137ff4cSJacques Vidrine 25764137ff4cSJacques Vidrine * (init_auth): only generate one subkey 25774137ff4cSJacques Vidrine 25784137ff4cSJacques Vidrine2003-01-27 Love Hörnquist Åstrand <[email protected]> 25794137ff4cSJacques Vidrine 25804137ff4cSJacques Vidrine * verify_mic.c (verify_mic_des3): fix 3des verify_mic to conform 25814137ff4cSJacques Vidrine to rfc (and mit kerberos), provide backward compat hook 25824137ff4cSJacques Vidrine 25834137ff4cSJacques Vidrine * get_mic.c (mic_des3): fix 3des get_mic to conform to rfc (and 25844137ff4cSJacques Vidrine mit kerberos), provide backward compat hook 25854137ff4cSJacques Vidrine 25864137ff4cSJacques Vidrine * init_sec_context.c (init_auth): check if we need compat for 25874137ff4cSJacques Vidrine older get_mic/verify_mic 25884137ff4cSJacques Vidrine 25894137ff4cSJacques Vidrine * gssapi_locl.h: add prototype for _gss_DES3_get_mic_compat 25904137ff4cSJacques Vidrine 25914137ff4cSJacques Vidrine * gssapi.h (more_flags): add COMPAT_OLD_DES3 25924137ff4cSJacques Vidrine 25934137ff4cSJacques Vidrine * Makefile.am: add gssapi.3 and compat.c 25944137ff4cSJacques Vidrine 25954137ff4cSJacques Vidrine * gssapi.3: add gssapi COMPATIBILITY documentation 25964137ff4cSJacques Vidrine 25974137ff4cSJacques Vidrine * accept_sec_context.c (gss_accept_sec_context): check if we need 25984137ff4cSJacques Vidrine compat for older get_mic/verify_mic 25994137ff4cSJacques Vidrine 26004137ff4cSJacques Vidrine * compat.c: check for compatiblity with other heimdal's 3des 26014137ff4cSJacques Vidrine get_mic/verify_mic 26024137ff4cSJacques Vidrine 26034137ff4cSJacques Vidrine2002-10-31 Johan Danielsson <[email protected]> 26044137ff4cSJacques Vidrine 26054137ff4cSJacques Vidrine * check return value from gssapi_krb5_init 26064137ff4cSJacques Vidrine 26074137ff4cSJacques Vidrine * 8003.c (gssapi_krb5_verify_8003_checksum): check size of input 26084137ff4cSJacques Vidrine 26094137ff4cSJacques Vidrine2002-09-03 Johan Danielsson <[email protected]> 26104137ff4cSJacques Vidrine 26114137ff4cSJacques Vidrine * wrap.c (wrap_des3): use ETYPE_DES3_CBC_NONE 26124137ff4cSJacques Vidrine 26134137ff4cSJacques Vidrine * unwrap.c (unwrap_des3): use ETYPE_DES3_CBC_NONE 26144137ff4cSJacques Vidrine 26154137ff4cSJacques Vidrine2002-09-02 Johan Danielsson <[email protected]> 26164137ff4cSJacques Vidrine 26174137ff4cSJacques Vidrine * init_sec_context.c: we need to generate a local subkey here 2618adb0ddaeSAssar Westerlund 2619adb0ddaeSAssar Westerlund2002-08-20 Jacques Vidrine <[email protected]> 2620adb0ddaeSAssar Westerlund 2621adb0ddaeSAssar Westerlund * acquire_cred.c, inquire_cred.c, release_cred.c: Use default 2622adb0ddaeSAssar Westerlund credential resolution if gss_acquire_cred is called with 2623adb0ddaeSAssar Westerlund GSS_C_NO_NAME. 2624adb0ddaeSAssar Westerlund 2625adb0ddaeSAssar Westerlund2002-06-20 Jacques Vidrine <[email protected]> 2626adb0ddaeSAssar Westerlund 2627adb0ddaeSAssar Westerlund * import_name.c: Compare name types by value if pointers do 2628adb0ddaeSAssar Westerlund not match. Reported by: "Douglas E. Engert" <[email protected]> 2629adb0ddaeSAssar Westerlund 2630adb0ddaeSAssar Westerlund2002-05-20 Jacques Vidrine <[email protected]> 2631adb0ddaeSAssar Westerlund 2632adb0ddaeSAssar Westerlund * verify_mic.c (gss_verify_mic), unwrap.c (gss_unwrap): initialize 2633adb0ddaeSAssar Westerlund the qop_state parameter. from Doug Rabson <[email protected]> 2634adb0ddaeSAssar Westerlund 2635adb0ddaeSAssar Westerlund2002-05-09 Jacques Vidrine <[email protected]> 2636adb0ddaeSAssar Westerlund 2637adb0ddaeSAssar Westerlund * acquire_cred.c: handle GSS_C_INITIATE/GSS_C_ACCEPT/GSS_C_BOTH 2638adb0ddaeSAssar Westerlund 2639adb0ddaeSAssar Westerlund2002-05-08 Jacques Vidrine <[email protected]> 2640adb0ddaeSAssar Westerlund 2641adb0ddaeSAssar Westerlund * acquire_cred.c: initialize gssapi; handle null desired_name 2642adb0ddaeSAssar Westerlund 2643adb0ddaeSAssar Westerlund2002-03-22 Johan Danielsson <[email protected]> 2644adb0ddaeSAssar Westerlund 2645adb0ddaeSAssar Westerlund * Makefile.am: remove non-functional stuff accidentally committed 2646adb0ddaeSAssar Westerlund 2647adb0ddaeSAssar Westerlund2002-03-11 Assar Westerlund <[email protected]> 2648adb0ddaeSAssar Westerlund 2649adb0ddaeSAssar Westerlund * Makefile.am (libgssapi_la_LDFLAGS): bump version to 3:5:2 2650adb0ddaeSAssar Westerlund * 8003.c (gssapi_krb5_verify_8003_checksum): handle zero channel 2651adb0ddaeSAssar Westerlund bindings 2652adb0ddaeSAssar Westerlund 2653adb0ddaeSAssar Westerlund2001-10-31 Jacques Vidrine <[email protected]> 2654adb0ddaeSAssar Westerlund 2655adb0ddaeSAssar Westerlund * get_mic.c (mic_des3): MIC computation using DES3/SHA1 2656adb0ddaeSAssar Westerlund was bogusly appending the message buffer to the result, 2657adb0ddaeSAssar Westerlund overwriting a heap buffer in the process. 26585e9cd1aeSAssar Westerlund 26595e9cd1aeSAssar Westerlund2001-08-29 Assar Westerlund <[email protected]> 26605e9cd1aeSAssar Westerlund 26615e9cd1aeSAssar Westerlund * 8003.c (gssapi_krb5_verify_8003_checksum, 26625e9cd1aeSAssar Westerlund gssapi_krb5_create_8003_checksum): make more consistent by always 26635e9cd1aeSAssar Westerlund returning an gssapi error and setting minor status. update 26645e9cd1aeSAssar Westerlund callers 26655e9cd1aeSAssar Westerlund 26665e9cd1aeSAssar Westerlund2001-08-28 Jacques Vidrine <[email protected]> 26675e9cd1aeSAssar Westerlund 26685e9cd1aeSAssar Westerlund * accept_sec_context.c: Create a cache for delegated credentials 26695e9cd1aeSAssar Westerlund when needed. 26705e9cd1aeSAssar Westerlund 26715e9cd1aeSAssar Westerlund2001-08-28 Assar Westerlund <[email protected]> 26725e9cd1aeSAssar Westerlund 26735e9cd1aeSAssar Westerlund * Makefile.am (libgssapi_la_LDFLAGS): set version to 3:4:2 26745e9cd1aeSAssar Westerlund 26755e9cd1aeSAssar Westerlund2001-08-23 Assar Westerlund <[email protected]> 26765e9cd1aeSAssar Westerlund 26775e9cd1aeSAssar Westerlund * *.c: handle minor_status more consistently 26785e9cd1aeSAssar Westerlund 26795e9cd1aeSAssar Westerlund * display_status.c (gss_display_status): handle krb5_get_err_text 26805e9cd1aeSAssar Westerlund failing 26815e9cd1aeSAssar Westerlund 26825e9cd1aeSAssar Westerlund2001-08-15 Johan Danielsson <[email protected]> 26835e9cd1aeSAssar Westerlund 26845e9cd1aeSAssar Westerlund * gssapi_locl.h: fix prototype for gssapi_krb5_init 26855e9cd1aeSAssar Westerlund 26865e9cd1aeSAssar Westerlund2001-08-13 Johan Danielsson <[email protected]> 26875e9cd1aeSAssar Westerlund 26885e9cd1aeSAssar Westerlund * accept_sec_context.c (gsskrb5_register_acceptor_identity): init 26895e9cd1aeSAssar Westerlund context and check return value from kt_resolve 26905e9cd1aeSAssar Westerlund 26915e9cd1aeSAssar Westerlund * init.c: return error code 26925e9cd1aeSAssar Westerlund 26935e9cd1aeSAssar Westerlund2001-07-19 Assar Westerlund <[email protected]> 26945e9cd1aeSAssar Westerlund 26955e9cd1aeSAssar Westerlund * Makefile.am (libgssapi_la_LDFLAGS): update to 3:3:2 26965e9cd1aeSAssar Westerlund 26975e9cd1aeSAssar Westerlund2001-07-12 Assar Westerlund <[email protected]> 26985e9cd1aeSAssar Westerlund 26995e9cd1aeSAssar Westerlund * Makefile.am (libgssapi_la_LIBADD): add required library 27005e9cd1aeSAssar Westerlund dependencies 27015e9cd1aeSAssar Westerlund 27025e9cd1aeSAssar Westerlund2001-07-06 Assar Westerlund <[email protected]> 27035e9cd1aeSAssar Westerlund 27045e9cd1aeSAssar Westerlund * accept_sec_context.c (gsskrb5_register_acceptor_identity): set 27055e9cd1aeSAssar Westerlund the keytab to be used for gss_acquire_cred too' 27065e9cd1aeSAssar Westerlund 27075e9cd1aeSAssar Westerlund2001-07-03 Assar Westerlund <[email protected]> 27085e9cd1aeSAssar Westerlund 27095e9cd1aeSAssar Westerlund * Makefile.am (libgssapi_la_LDFLAGS): set version to 3:2:2 27105e9cd1aeSAssar Westerlund 27115e9cd1aeSAssar Westerlund2001-06-18 Assar Westerlund <[email protected]> 27125e9cd1aeSAssar Westerlund 27135e9cd1aeSAssar Westerlund * wrap.c: replace gss_krb5_getsomekey with gss_krb5_get_localkey 27145e9cd1aeSAssar Westerlund and gss_krb5_get_remotekey 27155e9cd1aeSAssar Westerlund * verify_mic.c: update krb5_auth_con function names use 27165e9cd1aeSAssar Westerlund gss_krb5_get_remotekey 27175e9cd1aeSAssar Westerlund * unwrap.c: replace gss_krb5_getsomekey with gss_krb5_get_localkey 27185e9cd1aeSAssar Westerlund and gss_krb5_get_remotekey 27195e9cd1aeSAssar Westerlund * gssapi_locl.h (gss_krb5_get_remotekey, gss_krb5_get_localkey): 27205e9cd1aeSAssar Westerlund add prototypes 27215e9cd1aeSAssar Westerlund * get_mic.c: update krb5_auth_con function names. use 27225e9cd1aeSAssar Westerlund gss_krb5_get_localkey 27235e9cd1aeSAssar Westerlund * accept_sec_context.c: update krb5_auth_con function names 27245e9cd1aeSAssar Westerlund 27255e9cd1aeSAssar Westerlund2001-05-17 Assar Westerlund <[email protected]> 27265e9cd1aeSAssar Westerlund 27275e9cd1aeSAssar Westerlund * Makefile.am: bump version to 3:1:2 27285e9cd1aeSAssar Westerlund 27295e9cd1aeSAssar Westerlund2001-05-14 Assar Westerlund <[email protected]> 27305e9cd1aeSAssar Westerlund 27315e9cd1aeSAssar Westerlund * address_to_krb5addr.c: adapt to new address functions 27325e9cd1aeSAssar Westerlund 27335e9cd1aeSAssar Westerlund2001-05-11 Assar Westerlund <[email protected]> 27345e9cd1aeSAssar Westerlund 27355e9cd1aeSAssar Westerlund * try to return the error string from libkrb5 where applicable 27365e9cd1aeSAssar Westerlund 27375e9cd1aeSAssar Westerlund2001-05-08 Assar Westerlund <[email protected]> 27385e9cd1aeSAssar Westerlund 27395e9cd1aeSAssar Westerlund * delete_sec_context.c (gss_delete_sec_context): remember to free 27405e9cd1aeSAssar Westerlund the memory used by the ticket itself. from <[email protected]> 27415e9cd1aeSAssar Westerlund 27425e9cd1aeSAssar Westerlund2001-05-04 Assar Westerlund <[email protected]> 27435e9cd1aeSAssar Westerlund 27445e9cd1aeSAssar Westerlund * gssapi_locl.h: add config.h for completeness 27455e9cd1aeSAssar Westerlund * gssapi.h: remove config.h, this is an installed header file 27465e9cd1aeSAssar Westerlund sys/types.h is not needed either 27475e9cd1aeSAssar Westerlund 27485e9cd1aeSAssar Westerlund2001-03-12 Assar Westerlund <[email protected]> 27495e9cd1aeSAssar Westerlund 27505e9cd1aeSAssar Westerlund * acquire_cred.c (gss_acquire_cred): remove memory leaks. from 27515e9cd1aeSAssar Westerlund Jason R Thorpe <[email protected]> 27525e9cd1aeSAssar Westerlund 27535e9cd1aeSAssar Westerlund2001-02-18 Assar Westerlund <[email protected]> 27545e9cd1aeSAssar Westerlund 27555e9cd1aeSAssar Westerlund * accept_sec_context.c (gss_accept_sec_context): either return 27565e9cd1aeSAssar Westerlund gss_name NULL-ed or set 27575e9cd1aeSAssar Westerlund 27585e9cd1aeSAssar Westerlund * import_name.c: set minor_status in some cases where it was not 27595e9cd1aeSAssar Westerlund done 27605e9cd1aeSAssar Westerlund 2761283d988cSMark Murray2001-02-15 Assar Westerlund <[email protected]> 2762283d988cSMark Murray 2763283d988cSMark Murray * wrap.c: use krb5_generate_random_block for the confounders 2764283d988cSMark Murray 2765283d988cSMark Murray2001-01-30 Assar Westerlund <[email protected]> 2766283d988cSMark Murray 2767283d988cSMark Murray * Makefile.am (libgssapi_la_LDFLAGS): bump version to 3:0:2 2768283d988cSMark Murray * acquire_cred.c, init_sec_context.c, release_cred.c: add support 2769283d988cSMark Murray for getting creds from a keytab, from [email protected] 2770283d988cSMark Murray 2771283d988cSMark Murray * copy_ccache.c: add gss_krb5_copy_ccache 2772283d988cSMark Murray 2773283d988cSMark Murray2001-01-27 Assar Westerlund <[email protected]> 2774283d988cSMark Murray 2775283d988cSMark Murray * get_mic.c: cast parameters to des function to non-const pointers 2776283d988cSMark Murray to handle the case where these functions actually take non-const 2777283d988cSMark Murray des_cblock * 2778283d988cSMark Murray 2779283d988cSMark Murray2001-01-09 Assar Westerlund <[email protected]> 2780283d988cSMark Murray 2781283d988cSMark Murray * accept_sec_context.c (gss_accept_sec_context): use krb5_rd_cred2 2782283d988cSMark Murray instead of krb5_rd_cred 2783283d988cSMark Murray 2784283d988cSMark Murray2000-12-11 Assar Westerlund <[email protected]> 278513e3f4d6SMark Murray 278613e3f4d6SMark Murray * Makefile.am (libgssapi_la_LDFLAGS): bump to 2:3:1 278713e3f4d6SMark Murray 278813e3f4d6SMark Murray2000-12-08 Assar Westerlund <[email protected]> 278913e3f4d6SMark Murray 279013e3f4d6SMark Murray * wrap.c (wrap_des3): use the checksum as ivec when encrypting the 279113e3f4d6SMark Murray sequence number 279213e3f4d6SMark Murray * unwrap.c (unwrap_des3): use the checksum as ivec when encrypting 279313e3f4d6SMark Murray the sequence number 279413e3f4d6SMark Murray * init_sec_context.c (init_auth): always zero fwd_data 279513e3f4d6SMark Murray 279613e3f4d6SMark Murray2000-12-06 Johan Danielsson <[email protected]> 279713e3f4d6SMark Murray 279813e3f4d6SMark Murray * accept_sec_context.c: de-pointerise auth_context parameter to 279913e3f4d6SMark Murray krb5_mk_rep 280013e3f4d6SMark Murray 280113e3f4d6SMark Murray2000-11-15 Assar Westerlund <[email protected]> 280213e3f4d6SMark Murray 280313e3f4d6SMark Murray * init_sec_context.c (init_auth): update to new 2804b528cefcSMark Murray krb5_build_authenticator 2805b528cefcSMark Murray 2806b528cefcSMark Murray2000-09-19 Assar Westerlund <[email protected]> 2807b528cefcSMark Murray 2808b528cefcSMark Murray * Makefile.am (libgssapi_la_LDFLAGS): bump to 2:2:1 2809b528cefcSMark Murray 2810b528cefcSMark Murray2000-08-27 Assar Westerlund <[email protected]> 2811b528cefcSMark Murray 2812b528cefcSMark Murray * init_sec_context.c: actually pay attention to `time_req' 2813b528cefcSMark Murray * init_sec_context.c: re-organize. leak less memory. 2814b528cefcSMark Murray * gssapi_locl.h (gssapi_krb5_encapsulate, gss_krb5_getsomekey): 2815b528cefcSMark Murray update prototypes add assert.h 2816b528cefcSMark Murray * gssapi.h (GSS_KRB5_CONF_C_QOP_DES, GSS_KRB5_CONF_C_QOP_DES3_KD): 2817b528cefcSMark Murray add 2818b528cefcSMark Murray * verify_mic.c: re-organize and add 3DES code 2819b528cefcSMark Murray * wrap.c: re-organize and add 3DES code 2820b528cefcSMark Murray * unwrap.c: re-organize and add 3DES code 2821b528cefcSMark Murray * get_mic.c: re-organize and add 3DES code 2822b528cefcSMark Murray * encapsulate.c (gssapi_krb5_encapsulate): do not free `in_data', 2823b528cefcSMark Murray let the caller do that. fix the callers. 2824b528cefcSMark Murray 2825b528cefcSMark Murray2000-08-16 Assar Westerlund <[email protected]> 2826b528cefcSMark Murray 2827b528cefcSMark Murray * Makefile.am: bump version to 2:1:1 2828b528cefcSMark Murray 2829b528cefcSMark Murray2000-07-29 Assar Westerlund <[email protected]> 2830b528cefcSMark Murray 2831b528cefcSMark Murray * decapsulate.c (gssapi_krb5_verify_header): sanity-check length 2832b528cefcSMark Murray 2833b528cefcSMark Murray2000-07-25 Johan Danielsson <[email protected]> 2834b528cefcSMark Murray 2835b528cefcSMark Murray * Makefile.am: bump version to 2:0:1 2836b528cefcSMark Murray 2837b528cefcSMark Murray2000-07-22 Assar Westerlund <[email protected]> 2838b528cefcSMark Murray 2839b528cefcSMark Murray * gssapi.h: update OID for GSS_C_NT_HOSTBASED_SERVICE and other 2840b528cefcSMark Murray details from rfc2744 2841b528cefcSMark Murray 2842b528cefcSMark Murray2000-06-29 Assar Westerlund <[email protected]> 2843b528cefcSMark Murray 2844b528cefcSMark Murray * address_to_krb5addr.c (gss_address_to_krb5addr): actually use 2845b528cefcSMark Murray `int' instead of `sa_family_t' for the address family. 2846b528cefcSMark Murray 2847b528cefcSMark Murray2000-06-21 Assar Westerlund <[email protected]> 2848b528cefcSMark Murray 2849b528cefcSMark Murray * add support for token delegation. From Daniel Kouril 2850b528cefcSMark Murray <[email protected]> and Miroslav Ruda <[email protected]> 2851b528cefcSMark Murray 2852b528cefcSMark Murray2000-05-15 Assar Westerlund <[email protected]> 2853b528cefcSMark Murray 2854b528cefcSMark Murray * Makefile.am (libgssapi_la_LDFLAGS): set version to 1:1:1 2855b528cefcSMark Murray 2856b528cefcSMark Murray2000-04-12 Assar Westerlund <[email protected]> 2857b528cefcSMark Murray 2858b528cefcSMark Murray * release_oid_set.c (gss_release_oid_set): clear set for 2859b528cefcSMark Murray robustness. From GOMBAS Gabor <[email protected]> 2860b528cefcSMark Murray * release_name.c (gss_release_name): reset input_name for 2861b528cefcSMark Murray robustness. From GOMBAS Gabor <[email protected]> 2862b528cefcSMark Murray * release_buffer.c (gss_release_buffer): set value to NULL to be 2863b528cefcSMark Murray more robust. From GOMBAS Gabor <[email protected]> 2864 * add_oid_set_member.c (gss_add_oid_set_member): actually check if 2865 the oid is a member first. leave the oid_set unchanged if realloc 2866 fails. 2867 28682000-02-13 Assar Westerlund <[email protected]> 2869 2870 * Makefile.am: set version to 1:0:1 2871 28722000-02-12 Assar Westerlund <[email protected]> 2873 2874 * gssapi_locl.h: add flags for import/export 2875 * import_sec_context.c (import_sec_context: add flags for what 2876 fields are included. do not include the authenticator for now. 2877 * export_sec_context.c (export_sec_context: add flags for what 2878 fields are included. do not include the authenticator for now. 2879 * accept_sec_context.c (gss_accept_sec_context): set target in 2880 context_handle 2881 28822000-02-11 Assar Westerlund <[email protected]> 2883 2884 * delete_sec_context.c (gss_delete_sec_context): set context to 2885 GSS_C_NO_CONTEXT 2886 2887 * Makefile.am: add {export,import}_sec_context.c 2888 * export_sec_context.c: new file 2889 * import_sec_context.c: new file 2890 * accept_sec_context.c (gss_accept_sec_context): set trans flag 2891 28922000-02-07 Assar Westerlund <[email protected]> 2893 2894 * Makefile.am: set version to 0:5:0 2895 28962000-01-26 Assar Westerlund <[email protected]> 2897 2898 * delete_sec_context.c (gss_delete_sec_context): handle a NULL 2899 output_token 2900 2901 * wrap.c: update to pseudo-standard APIs for md4,md5,sha. some 2902 changes to libdes calls to make them more portable. 2903 * verify_mic.c: update to pseudo-standard APIs for md4,md5,sha. 2904 some changes to libdes calls to make them more portable. 2905 * unwrap.c: update to pseudo-standard APIs for md4,md5,sha. some 2906 changes to libdes calls to make them more portable. 2907 * get_mic.c: update to pseudo-standard APIs for md4,md5,sha. some 2908 changes to libdes calls to make them more portable. 2909 * 8003.c: update to pseudo-standard APIs for md4,md5,sha. 2910 29112000-01-06 Assar Westerlund <[email protected]> 2912 2913 * Makefile.am: set version to 0:4:0 2914 29151999-12-26 Assar Westerlund <[email protected]> 2916 2917 * accept_sec_context.c (gss_accept_sec_context): always set 2918 `output_token' 2919 * init_sec_context.c (init_auth): always initialize `output_token' 2920 * delete_sec_context.c (gss_delete_sec_context): always set 2921 `output_token' 2922 29231999-12-06 Assar Westerlund <[email protected]> 2924 2925 * Makefile.am: bump version to 0:3:0 2926 29271999-10-20 Assar Westerlund <[email protected]> 2928 2929 * Makefile.am: set version to 0:2:0 2930 29311999-09-21 Assar Westerlund <[email protected]> 2932 2933 * init_sec_context.c (gss_init_sec_context): initialize `ticket' 2934 2935 * gssapi.h (gss_ctx_id_t_desc): add ticket in here. ick. 2936 2937 * delete_sec_context.c (gss_delete_sec_context): free ticket 2938 2939 * accept_sec_context.c (gss_accept_sec_context): stove away 2940 `krb5_ticket' in context so that ugly programs such as 2941 gss_nt_server can get at it. uck. 2942 29431999-09-20 Johan Danielsson <[email protected]> 2944 2945 * accept_sec_context.c: set minor_status 2946 29471999-08-04 Assar Westerlund <[email protected]> 2948 2949 * display_status.c (calling_error, routine_error): right shift the 2950 code to make it possible to index into the arrays 2951 29521999-07-28 Assar Westerlund <[email protected]> 2953 2954 * gssapi.h (GSS_C_AF_INET6): add 2955 2956 * import_name.c (import_hostbased_name): set minor_status 2957 29581999-07-26 Assar Westerlund <[email protected]> 2959 2960 * Makefile.am: set version to 0:1:0 2961 2962Wed Apr 7 14:05:15 1999 Johan Danielsson <[email protected]> 2963 2964 * display_status.c: set minor_status 2965 2966 * init_sec_context.c: set minor_status 2967 2968 * lib/gssapi/init.c: remove donep (check gssapi_krb5_context 2969 directly) 2970 2971