Path: blob/aarch64-shenandoah-jdk8u272-b10/jdk/src/share/native/sun/security/krb5/nativeccache.c
38918 views
/*1* Copyright (c) 2011, 2019, Oracle and/or its affiliates. All rights reserved.2* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.3*4* This code is free software; you can redistribute it and/or modify it5* under the terms of the GNU General Public License version 2 only, as6* published by the Free Software Foundation. Oracle designates this7* particular file as subject to the "Classpath" exception as provided8* by Oracle in the LICENSE file that accompanied this code.9*10* This code is distributed in the hope that it will be useful, but WITHOUT11* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or12* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License13* version 2 for more details (a copy is included in the LICENSE file that14* accompanied this code).15*16* You should have received a copy of the GNU General Public License version17* 2 along with this work; if not, write to the Free Software Foundation,18* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.19*20* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA21* or visit www.oracle.com if you need additional information or have any22* questions.23*/2425#import "sun_security_krb5_Credentials.h"26#import <Kerberos/Kerberos.h>2728/*29* Based largely on klist.c,30*31* Created by Scott Kovatch on 8/12/04.32*33* See http://www.opensource.apple.com/darwinsource/10.3.3/Kerberos-47/KerberosClients/klist/Sources/klist.c3435*/3637/*38* Statics for this module39*/4041static jclass derValueClass = NULL;42static jclass ticketClass = NULL;43static jclass principalNameClass = NULL;44static jclass encryptionKeyClass = NULL;45static jclass ticketFlagsClass = NULL;46static jclass kerberosTimeClass = NULL;47static jclass javaLangStringClass = NULL;48static jclass javaLangIntegerClass = NULL;49static jclass hostAddressClass = NULL;50static jclass hostAddressesClass = NULL;5152static jmethodID derValueConstructor = 0;53static jmethodID ticketConstructor = 0;54static jmethodID principalNameConstructor = 0;55static jmethodID encryptionKeyConstructor = 0;56static jmethodID ticketFlagsConstructor = 0;57static jmethodID kerberosTimeConstructor = 0;58static jmethodID krbcredsConstructor = 0;59static jmethodID integerConstructor = 0;60static jmethodID hostAddressConstructor = 0;61static jmethodID hostAddressesConstructor = 0;6263/*64* Function prototypes for internal routines65*/6667static jobject BuildTicket(JNIEnv *env, krb5_data *encodedTicket);68static jobject BuildClientPrincipal(JNIEnv *env, krb5_context kcontext, krb5_principal principalName);69static jobject BuildEncryptionKey(JNIEnv *env, krb5_keyblock *cryptoKey);70static jobject BuildTicketFlags(JNIEnv *env, krb5_flags flags);71static jobject BuildKerberosTime(JNIEnv *env, krb5_timestamp kerbtime);72static jobject BuildAddressList(JNIEnv *env, krb5_address **kerbtime);7374static void printiferr (errcode_t err, const char *format, ...);7576static jclass FindClass(JNIEnv *env, char *className)77{78jclass cls = (*env)->FindClass(env, className);7980if (cls == NULL) {81printf("Couldn't find %s\n", className);82return NULL;83}84#ifdef DEBUG85printf("Found %s\n", className);86#endif /* DEBUG */8788jobject returnValue = (*env)->NewWeakGlobalRef(env,cls);89return returnValue;90}91/*92* Class: sun_security_krb5_KrbCreds93* Method: JNI_OnLoad94*/95JNIEXPORT jint JNICALL JNI_OnLoad(JavaVM *jvm, void *reserved)96{97JNIEnv *env;9899if ((*jvm)->GetEnv(jvm, (void **)&env, JNI_VERSION_1_4)) {100return JNI_EVERSION; /* JNI version not supported */101}102103ticketClass = FindClass(env, "sun/security/krb5/internal/Ticket");104if (ticketClass == NULL) return JNI_ERR;105106principalNameClass = FindClass(env, "sun/security/krb5/PrincipalName");107if (principalNameClass == NULL) return JNI_ERR;108109derValueClass = FindClass(env, "sun/security/util/DerValue");110if (derValueClass == NULL) return JNI_ERR;111112encryptionKeyClass = FindClass(env, "sun/security/krb5/EncryptionKey");113if (encryptionKeyClass == NULL) return JNI_ERR;114115ticketFlagsClass = FindClass(env,"sun/security/krb5/internal/TicketFlags");116if (ticketFlagsClass == NULL) return JNI_ERR;117118kerberosTimeClass = FindClass(env,"sun/security/krb5/internal/KerberosTime");119if (kerberosTimeClass == NULL) return JNI_ERR;120121javaLangStringClass = FindClass(env,"java/lang/String");122if (javaLangStringClass == NULL) return JNI_ERR;123124javaLangIntegerClass = FindClass(env,"java/lang/Integer");125if (javaLangIntegerClass == NULL) return JNI_ERR;126127hostAddressClass = FindClass(env,"sun/security/krb5/internal/HostAddress");128if (hostAddressClass == NULL) return JNI_ERR;129130hostAddressesClass = FindClass(env,"sun/security/krb5/internal/HostAddresses");131if (hostAddressesClass == NULL) return JNI_ERR;132133derValueConstructor = (*env)->GetMethodID(env, derValueClass, "<init>", "([B)V");134if (derValueConstructor == 0) {135printf("Couldn't find DerValue constructor\n");136return JNI_ERR;137}138#ifdef DEBUG139printf("Found DerValue constructor\n");140#endif /* DEBUG */141142ticketConstructor = (*env)->GetMethodID(env, ticketClass, "<init>", "(Lsun/security/util/DerValue;)V");143if (ticketConstructor == 0) {144printf("Couldn't find Ticket constructor\n");145return JNI_ERR;146}147#ifdef DEBUG148printf("Found Ticket constructor\n");149#endif /* DEBUG */150151principalNameConstructor = (*env)->GetMethodID(env, principalNameClass, "<init>", "(Ljava/lang/String;I)V");152if (principalNameConstructor == 0) {153printf("Couldn't find PrincipalName constructor\n");154return JNI_ERR;155}156#ifdef DEBUG157printf("Found PrincipalName constructor\n");158#endif /* DEBUG */159160encryptionKeyConstructor = (*env)->GetMethodID(env, encryptionKeyClass, "<init>", "(I[B)V");161if (encryptionKeyConstructor == 0) {162printf("Couldn't find EncryptionKey constructor\n");163return JNI_ERR;164}165#ifdef DEBUG166printf("Found EncryptionKey constructor\n");167#endif /* DEBUG */168169ticketFlagsConstructor = (*env)->GetMethodID(env, ticketFlagsClass, "<init>", "(I[B)V");170if (ticketFlagsConstructor == 0) {171printf("Couldn't find TicketFlags constructor\n");172return JNI_ERR;173}174#ifdef DEBUG175printf("Found TicketFlags constructor\n");176#endif /* DEBUG */177178kerberosTimeConstructor = (*env)->GetMethodID(env, kerberosTimeClass, "<init>", "(J)V");179if (kerberosTimeConstructor == 0) {180printf("Couldn't find KerberosTime constructor\n");181return JNI_ERR;182}183#ifdef DEBUG184printf("Found KerberosTime constructor\n");185#endif /* DEBUG */186187integerConstructor = (*env)->GetMethodID(env, javaLangIntegerClass, "<init>", "(I)V");188if (integerConstructor == 0) {189printf("Couldn't find Integer constructor\n");190return JNI_ERR;191}192#ifdef DEBUG193printf("Found Integer constructor\n");194#endif /* DEBUG */195196hostAddressConstructor = (*env)->GetMethodID(env, hostAddressClass, "<init>", "(I[B)V");197if (hostAddressConstructor == 0) {198printf("Couldn't find HostAddress constructor\n");199return JNI_ERR;200}201#ifdef DEBUG202printf("Found HostAddress constructor\n");203#endif /* DEBUG */204205hostAddressesConstructor = (*env)->GetMethodID(env, hostAddressesClass, "<init>", "([Lsun/security/krb5/internal/HostAddress;)V");206if (hostAddressesConstructor == 0) {207printf("Couldn't find HostAddresses constructor\n");208return JNI_ERR;209}210#ifdef DEBUG211printf("Found HostAddresses constructor\n");212#endif /* DEBUG */213214#ifdef DEBUG215printf("Finished OnLoad processing\n");216#endif /* DEBUG */217218return JNI_VERSION_1_2;219}220221/*222* Class: sun_security_jgss_KrbCreds223* Method: JNI_OnUnload224*/225JNIEXPORT void JNICALL JNI_OnUnload(JavaVM *jvm, void *reserved)226{227JNIEnv *env;228229if ((*jvm)->GetEnv(jvm, (void **)&env, JNI_VERSION_1_2)) {230return; /* Nothing else we can do */231}232233if (ticketClass != NULL) {234(*env)->DeleteWeakGlobalRef(env,ticketClass);235}236if (derValueClass != NULL) {237(*env)->DeleteWeakGlobalRef(env,derValueClass);238}239if (principalNameClass != NULL) {240(*env)->DeleteWeakGlobalRef(env,principalNameClass);241}242if (encryptionKeyClass != NULL) {243(*env)->DeleteWeakGlobalRef(env,encryptionKeyClass);244}245if (ticketFlagsClass != NULL) {246(*env)->DeleteWeakGlobalRef(env,ticketFlagsClass);247}248if (kerberosTimeClass != NULL) {249(*env)->DeleteWeakGlobalRef(env,kerberosTimeClass);250}251if (javaLangStringClass != NULL) {252(*env)->DeleteWeakGlobalRef(env,javaLangStringClass);253}254if (javaLangIntegerClass != NULL) {255(*env)->DeleteWeakGlobalRef(env,javaLangIntegerClass);256}257if (hostAddressClass != NULL) {258(*env)->DeleteWeakGlobalRef(env,hostAddressClass);259}260if (hostAddressesClass != NULL) {261(*env)->DeleteWeakGlobalRef(env,hostAddressesClass);262}263264}265266int isIn(krb5_enctype e, int n, jint* etypes)267{268int i;269for (i=0; i<n; i++) {270if (e == etypes[i]) return 1;271}272return 0;273}274275/*276* Class: sun_security_krb5_Credentials277* Method: acquireDefaultNativeCreds278* Signature: ([I])Lsun/security/krb5/Credentials;279*/280JNIEXPORT jobject JNICALL Java_sun_security_krb5_Credentials_acquireDefaultNativeCreds281(JNIEnv *env, jclass krbcredsClass, jintArray jetypes)282{283jobject krbCreds = NULL;284krb5_error_code err = 0;285krb5_ccache ccache = NULL;286krb5_cc_cursor cursor = NULL;287krb5_creds creds;288krb5_flags flags = 0;289krb5_context kcontext = NULL;290291int netypes;292jint *etypes = NULL;293int proxy_flag = 0;294295/* Initialize the Kerberos 5 context */296err = krb5_init_context (&kcontext);297298if (!err) {299err = krb5_cc_default (kcontext, &ccache);300}301302if (!err) {303err = krb5_cc_set_flags (kcontext, ccache, flags); /* turn off OPENCLOSE */304}305306// First round read. The proxy_impersonator config flag is not supported.307// This ccache will not be used if this flag exists.308if (!err) {309err = krb5_cc_start_seq_get (kcontext, ccache, &cursor);310}311312if (!err) {313while ((err = krb5_cc_next_cred (kcontext, ccache, &cursor, &creds)) == 0) {314char *serverName = NULL;315316if (!err) {317err = krb5_unparse_name (kcontext, creds.server, &serverName);318printiferr (err, "while unparsing server name");319}320321if (!err) {322if (!strcmp(serverName, "krb5_ccache_conf_data/proxy_impersonator@X-CACHECONF:")) {323proxy_flag = 1;324}325}326327if (serverName != NULL) { krb5_free_unparsed_name (kcontext, serverName); }328329krb5_free_cred_contents (kcontext, &creds);330331if (proxy_flag) break;332}333334if (err == KRB5_CC_END) { err = 0; }335printiferr (err, "while retrieving a ticket");336}337338if (!err) {339err = krb5_cc_end_seq_get (kcontext, ccache, &cursor);340printiferr (err, "while finishing ticket retrieval");341}342343if (proxy_flag) {344goto outer_cleanup;345}346// End of first round read347348if (!err) {349err = krb5_cc_start_seq_get (kcontext, ccache, &cursor);350}351352netypes = (*env)->GetArrayLength(env, jetypes);353etypes = (jint *) (*env)->GetIntArrayElements(env, jetypes, NULL);354355if (etypes != NULL && !err) {356while ((err = krb5_cc_next_cred (kcontext, ccache, &cursor, &creds)) == 0) {357char *serverName = NULL;358359if (!err) {360err = krb5_unparse_name (kcontext, creds.server, &serverName);361printiferr (err, "while unparsing server name");362}363364if (!err) {365char* slash = strchr(serverName, '/');366char* at = strchr(serverName, '@');367// Make sure the server's name is krbtgt/REALM@REALM, the etype368// is supported, and the ticket has not expired369if (slash && at &&370strncmp (serverName, "krbtgt", slash-serverName) == 0 &&371// the ablove line shows at must be after slash372strncmp (slash+1, at+1, at-slash-1) == 0 &&373isIn (creds.keyblock.enctype, netypes, etypes) &&374creds.times.endtime > time(0)) {375jobject ticket, clientPrincipal, targetPrincipal, encryptionKey;376jobject ticketFlags, startTime, endTime;377jobject authTime, renewTillTime, hostAddresses;378379ticket = clientPrincipal = targetPrincipal = encryptionKey = NULL;380ticketFlags = startTime = endTime = NULL;381authTime = renewTillTime = hostAddresses = NULL;382383// For the default credentials we're only interested in the krbtgt server.384clientPrincipal = BuildClientPrincipal(env, kcontext, creds.client);385if (clientPrincipal == NULL) goto cleanup;386387targetPrincipal = BuildClientPrincipal(env, kcontext, creds.server);388if (targetPrincipal == NULL) goto cleanup;389390// Build a sun/security/krb5/internal/Ticket391ticket = BuildTicket(env, &creds.ticket);392if (ticket == NULL) goto cleanup;393394// Get the encryption key395encryptionKey = BuildEncryptionKey(env, &creds.keyblock);396if (encryptionKey == NULL) goto cleanup;397398// and the ticket flags399ticketFlags = BuildTicketFlags(env, creds.ticket_flags);400if (ticketFlags == NULL) goto cleanup;401402// Get the timestamps out.403startTime = BuildKerberosTime(env, creds.times.starttime);404if (startTime == NULL) goto cleanup;405406authTime = BuildKerberosTime(env, creds.times.authtime);407if (authTime == NULL) goto cleanup;408409endTime = BuildKerberosTime(env, creds.times.endtime);410if (endTime == NULL) goto cleanup;411412renewTillTime = BuildKerberosTime(env, creds.times.renew_till);413if (renewTillTime == NULL) goto cleanup;414415// Create the addresses object.416hostAddresses = BuildAddressList(env, creds.addresses);417418if (krbcredsConstructor == 0) {419krbcredsConstructor = (*env)->GetMethodID(env, krbcredsClass, "<init>",420"(Lsun/security/krb5/internal/Ticket;Lsun/security/krb5/PrincipalName;Lsun/security/krb5/PrincipalName;Lsun/security/krb5/PrincipalName;Lsun/security/krb5/PrincipalName;Lsun/security/krb5/EncryptionKey;Lsun/security/krb5/internal/TicketFlags;Lsun/security/krb5/internal/KerberosTime;Lsun/security/krb5/internal/KerberosTime;Lsun/security/krb5/internal/KerberosTime;Lsun/security/krb5/internal/KerberosTime;Lsun/security/krb5/internal/HostAddresses;)V");421if (krbcredsConstructor == 0) {422printf("Couldn't find sun.security.krb5.internal.Ticket constructor\n");423break;424}425}426427// and now go build a KrbCreds object428krbCreds = (*env)->NewObject(429env,430krbcredsClass,431krbcredsConstructor,432ticket,433clientPrincipal,434NULL,435targetPrincipal,436NULL,437encryptionKey,438ticketFlags,439authTime,440startTime,441endTime,442renewTillTime,443hostAddresses);444cleanup:445if (ticket) (*env)->DeleteLocalRef(env, ticket);446if (clientPrincipal) (*env)->DeleteLocalRef(env, clientPrincipal);447if (targetPrincipal) (*env)->DeleteLocalRef(env, targetPrincipal);448if (encryptionKey) (*env)->DeleteLocalRef(env, encryptionKey);449if (ticketFlags) (*env)->DeleteLocalRef(env, ticketFlags);450if (authTime) (*env)->DeleteLocalRef(env, authTime);451if (startTime) (*env)->DeleteLocalRef(env, startTime);452if (endTime) (*env)->DeleteLocalRef(env, endTime);453if (renewTillTime) (*env)->DeleteLocalRef(env, renewTillTime);454if (hostAddresses) (*env)->DeleteLocalRef(env, hostAddresses);455456// Stop if there is an exception or we already found the initial TGT457if ((*env)->ExceptionCheck(env) || krbCreds) {458break;459}460}461}462463if (serverName != NULL) { krb5_free_unparsed_name (kcontext, serverName); }464465krb5_free_cred_contents (kcontext, &creds);466}467468if (err == KRB5_CC_END) { err = 0; }469printiferr (err, "while retrieving a ticket");470}471472if (!err) {473err = krb5_cc_end_seq_get (kcontext, ccache, &cursor);474printiferr (err, "while finishing ticket retrieval");475}476477outer_cleanup:478if (!err) {479flags = KRB5_TC_OPENCLOSE; /* restore OPENCLOSE mode */480err = krb5_cc_set_flags (kcontext, ccache, flags);481printiferr (err, "while finishing ticket retrieval");482}483484if (etypes != NULL) {485(*env)->ReleaseIntArrayElements(env, jetypes, etypes, 0);486}487488krb5_free_context (kcontext);489return krbCreds;490}491492493#pragma mark -494495jobject BuildTicket(JNIEnv *env, krb5_data *encodedTicket)496{497/* To build a Ticket, we first need to build a DerValue out of the EncodedTicket.498* But before we can do that, we need to make a byte array out of the ET.499*/500501jobject derValue, ticket;502jbyteArray ary;503504ary = (*env)->NewByteArray(env, encodedTicket->length);505if ((*env)->ExceptionCheck(env)) {506return (jobject) NULL;507}508509(*env)->SetByteArrayRegion(env, ary, (jsize) 0, encodedTicket->length, (jbyte *)encodedTicket->data);510if ((*env)->ExceptionCheck(env)) {511(*env)->DeleteLocalRef(env, ary);512return (jobject) NULL;513}514515derValue = (*env)->NewObject(env, derValueClass, derValueConstructor, ary);516if ((*env)->ExceptionCheck(env)) {517(*env)->DeleteLocalRef(env, ary);518return (jobject) NULL;519}520521(*env)->DeleteLocalRef(env, ary);522ticket = (*env)->NewObject(env, ticketClass, ticketConstructor, derValue);523if ((*env)->ExceptionCheck(env)) {524(*env)->DeleteLocalRef(env, derValue);525return (jobject) NULL;526}527(*env)->DeleteLocalRef(env, derValue);528return ticket;529}530531jobject BuildClientPrincipal(JNIEnv *env, krb5_context kcontext, krb5_principal principalName) {532// Get the full principal string.533char *principalString = NULL;534jobject principal = NULL;535int err = krb5_unparse_name (kcontext, principalName, &principalString);536537if (!err) {538// Make a PrincipalName from the full string and the type. Let the PrincipalName class parse it out.539jstring principalStringObj = (*env)->NewStringUTF(env, principalString);540if (principalStringObj == NULL) {541if (principalString != NULL) { krb5_free_unparsed_name (kcontext, principalString); }542return (jobject) NULL;543}544principal = (*env)->NewObject(env, principalNameClass, principalNameConstructor, principalStringObj, principalName->type);545if (principalString != NULL) { krb5_free_unparsed_name (kcontext, principalString); }546(*env)->DeleteLocalRef(env, principalStringObj);547}548549return principal;550}551552jobject BuildEncryptionKey(JNIEnv *env, krb5_keyblock *cryptoKey) {553// First, need to build a byte array554jbyteArray ary;555jobject encryptionKey = NULL;556557ary = (*env)->NewByteArray(env,cryptoKey->length);558559if (ary == NULL) {560return (jobject) NULL;561}562563(*env)->SetByteArrayRegion(env, ary, (jsize) 0, cryptoKey->length, (jbyte *)cryptoKey->contents);564if (!(*env)->ExceptionCheck(env)) {565encryptionKey = (*env)->NewObject(env, encryptionKeyClass, encryptionKeyConstructor, cryptoKey->enctype, ary);566}567568(*env)->DeleteLocalRef(env, ary);569return encryptionKey;570}571572jobject BuildTicketFlags(JNIEnv *env, krb5_flags flags) {573jobject ticketFlags = NULL;574jbyteArray ary;575576/*577* Convert the bytes to network byte order before copying578* them to a Java byte array.579*/580unsigned long nlflags = htonl(flags);581582ary = (*env)->NewByteArray(env, sizeof(flags));583584if (ary == NULL) {585return (jobject) NULL;586}587588(*env)->SetByteArrayRegion(env, ary, (jsize) 0, sizeof(flags), (jbyte *)&nlflags);589590if (!(*env)->ExceptionCheck(env)) {591ticketFlags = (*env)->NewObject(env, ticketFlagsClass, ticketFlagsConstructor, sizeof(flags)*8, ary);592}593594(*env)->DeleteLocalRef(env, ary);595return ticketFlags;596}597598jobject BuildKerberosTime(JNIEnv *env, krb5_timestamp kerbtime) {599jlong time = kerbtime;600601// Kerberos time is in seconds, but the KerberosTime class assumes milliseconds, so multiply by 1000.602time *= 1000;603return (*env)->NewObject(env, kerberosTimeClass, kerberosTimeConstructor, time);604}605606jobject BuildAddressList(JNIEnv *env, krb5_address **addresses) {607608if (addresses == NULL) {609return NULL;610}611612int addressCount = 0;613614// See how many we have.615krb5_address **p = addresses;616617while (*p != 0) {618addressCount++;619p++;620}621622jobject address_list = (*env)->NewObjectArray(env, addressCount, hostAddressClass, NULL);623624if (address_list == NULL) {625return (jobject) NULL;626}627628// Create a new HostAddress object for each address block.629// First, reset the iterator.630p = addresses;631jsize index = 0;632while (*p != 0) {633krb5_address *currAddress = *p;634635// HostAddres needs a byte array of the host data.636jbyteArray ary = (*env)->NewByteArray(env, currAddress->length);637638if (ary == NULL) return NULL;639640(*env)->SetByteArrayRegion(env, ary, (jsize) 0, currAddress->length, (jbyte *)currAddress->contents);641jobject address = (*env)->NewObject(env, hostAddressClass, hostAddressConstructor, currAddress->length, ary);642643(*env)->DeleteLocalRef(env, ary);644645if (address == NULL) {646return (jobject) NULL;647}648// Add the HostAddress to the arrray.649(*env)->SetObjectArrayElement(env, address_list, index, address);650651if ((*env)->ExceptionCheck(env)) {652return (jobject) NULL;653}654655index++;656p++;657}658659return address_list;660}661662#pragma mark - Utility methods -663664static void printiferr (errcode_t err, const char *format, ...)665{666if (err) {667va_list pvar;668669va_start (pvar, format);670com_err_va ("ticketParser:", err, format, pvar);671va_end (pvar);672}673}674675676677