-
Notifications
You must be signed in to change notification settings - Fork 0
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
[CIFS] Add upcall files for cifs to use spnego/kerberos
Acked-by: Jeff Layton <jlayton@redhat.com> Signed-off-by: Steve French <sfrench@us.ibm.com>
- Loading branch information
Steve French
committed
Nov 5, 2007
1 parent
e545937
commit f1d662a
Showing
2 changed files
with
170 additions
and
0 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,124 @@ | ||
/* | ||
* fs/cifs/cifs_spnego.c -- SPNEGO upcall management for CIFS | ||
* | ||
* Copyright (c) 2007 Red Hat, Inc. | ||
* Author(s): Jeff Layton (jlayton@redhat.com) | ||
* | ||
* This library is free software; you can redistribute it and/or modify | ||
* it under the terms of the GNU Lesser General Public License as published | ||
* by the Free Software Foundation; either version 2.1 of the License, or | ||
* (at your option) any later version. | ||
* | ||
* This library is distributed in the hope that it will be useful, | ||
* but WITHOUT ANY WARRANTY; without even the implied warranty of | ||
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See | ||
* the GNU Lesser General Public License for more details. | ||
* | ||
* You should have received a copy of the GNU Lesser General Public License | ||
* along with this library; if not, write to the Free Software | ||
* Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA | ||
*/ | ||
|
||
#include <linux/list.h> | ||
#include <linux/string.h> | ||
#include <keys/user-type.h> | ||
#include <linux/key-type.h> | ||
#include "cifsglob.h" | ||
#include "cifs_spnego.h" | ||
#include "cifs_debug.h" | ||
|
||
/* create a new cifs key */ | ||
static int | ||
cifs_spnego_key_instantiate(struct key *key, const void *data, size_t datalen) | ||
{ | ||
char *payload; | ||
int ret; | ||
|
||
ret = -ENOMEM; | ||
payload = kmalloc(datalen, GFP_KERNEL); | ||
if (!payload) | ||
goto error; | ||
|
||
/* attach the data */ | ||
memcpy(payload, data, datalen); | ||
rcu_assign_pointer(key->payload.data, payload); | ||
ret = 0; | ||
|
||
error: | ||
return ret; | ||
} | ||
|
||
static void | ||
cifs_spnego_key_destroy(struct key *key) | ||
{ | ||
kfree(key->payload.data); | ||
} | ||
|
||
|
||
/* | ||
* keytype for CIFS spnego keys | ||
*/ | ||
struct key_type cifs_spnego_key_type = { | ||
.name = "cifs.spnego", | ||
.instantiate = cifs_spnego_key_instantiate, | ||
.match = user_match, | ||
.destroy = cifs_spnego_key_destroy, | ||
.describe = user_describe, | ||
}; | ||
|
||
/* get a key struct with a SPNEGO security blob, suitable for session setup */ | ||
struct key * | ||
cifs_get_spnego_key(struct cifsSesInfo *sesInfo, const char *hostname) | ||
{ | ||
struct TCP_Server_Info *server = sesInfo->server; | ||
char *description, *dp; | ||
size_t desc_len; | ||
struct key *spnego_key; | ||
|
||
|
||
/* version + ;ip{4|6}= + address + ;host=hostname + ;sec= + NULL */ | ||
desc_len = 2 + 5 + 32 + 1 + 5 + strlen(hostname) + | ||
strlen(";sec=krb5") + 1; | ||
spnego_key = ERR_PTR(-ENOMEM); | ||
description = kzalloc(desc_len, GFP_KERNEL); | ||
if (description == NULL) | ||
goto out; | ||
|
||
dp = description; | ||
/* start with version and hostname portion of UNC string */ | ||
spnego_key = ERR_PTR(-EINVAL); | ||
sprintf(dp, "%2.2x;host=%s;", CIFS_SPNEGO_UPCALL_VERSION, | ||
hostname); | ||
dp = description + strlen(description); | ||
|
||
/* add the server address */ | ||
if (server->addr.sockAddr.sin_family == AF_INET) | ||
sprintf(dp, "ip4=" NIPQUAD_FMT, | ||
NIPQUAD(server->addr.sockAddr.sin_addr)); | ||
else if (server->addr.sockAddr.sin_family == AF_INET6) | ||
sprintf(dp, "ip6=" NIP6_SEQFMT, | ||
NIP6(server->addr.sockAddr6.sin6_addr)); | ||
else | ||
goto out; | ||
|
||
dp = description + strlen(description); | ||
|
||
/* for now, only sec=krb5 is valid */ | ||
if (server->secType == Kerberos) | ||
sprintf(dp, ";sec=krb5"); | ||
else | ||
goto out; | ||
|
||
cFYI(1, ("key description = %s", description)); | ||
spnego_key = request_key(&cifs_spnego_key_type, description, ""); | ||
|
||
if (cifsFYI && !IS_ERR(spnego_key)) { | ||
struct cifs_spnego_msg *msg = spnego_key->payload.data; | ||
cifs_dump_mem("SPNEGO reply blob:", msg->data, | ||
msg->secblob_len + msg->sesskey_len); | ||
} | ||
|
||
out: | ||
kfree(description); | ||
return spnego_key; | ||
} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,46 @@ | ||
/* | ||
* fs/cifs/cifs_spnego.h -- SPNEGO upcall management for CIFS | ||
* | ||
* Copyright (c) 2007 Red Hat, Inc. | ||
* Author(s): Jeff Layton (jlayton@redhat.com) | ||
* Steve French (sfrench@us.ibm.com) | ||
* | ||
* This library is free software; you can redistribute it and/or modify | ||
* it under the terms of the GNU Lesser General Public License as published | ||
* by the Free Software Foundation; either version 2.1 of the License, or | ||
* (at your option) any later version. | ||
* | ||
* This library is distributed in the hope that it will be useful, | ||
* but WITHOUT ANY WARRANTY; without even the implied warranty of | ||
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See | ||
* the GNU Lesser General Public License for more details. | ||
* | ||
* You should have received a copy of the GNU Lesser General Public License | ||
* along with this library; if not, write to the Free Software | ||
* Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA | ||
*/ | ||
|
||
#ifndef _CIFS_SPNEGO_H | ||
#define _CIFS_SPNEGO_H | ||
|
||
#define CIFS_SPNEGO_UPCALL_VERSION 1 | ||
|
||
/* | ||
* The version field should always be set to CIFS_SPNEGO_UPCALL_VERSION. | ||
* The flags field is for future use. The request-key callout should set | ||
* sesskey_len and secblob_len, and then concatenate the SessKey+SecBlob | ||
* and stuff it in the data field. | ||
*/ | ||
struct cifs_spnego_msg { | ||
uint32_t version; | ||
uint32_t flags; | ||
uint32_t sesskey_len; | ||
uint32_t secblob_len; | ||
uint8_t data[1]; | ||
}; | ||
|
||
#ifdef __KERNEL__ | ||
extern struct key_type cifs_spnego_key_type; | ||
#endif /* KERNEL */ | ||
|
||
#endif /* _CIFS_SPNEGO_H */ |