static cc_int32 ccache_get_principal(cc_ccache_t in_ccache, cc_uint32 in_credentials_version, cc_string_t *out_principal) { struct cc_ccache *c = (struct cc_ccache *)in_ccache; krb5_principal princ; krb5_error_code ret; char *name; LOG_ENTRY(); if (out_principal == NULL) return ccErrBadParam; if (in_credentials_version != cc_credentials_v5) return LOG_FAILURE(ccErrBadCredentialsVersion, "wrong version"); if (c->id == NULL) return ccErrInvalidCCache; ret = heim_krb5_cc_get_principal(milcontext, c->id, &princ); if (ret) return LOG_FAILURE(ret, "get principal"); ret = heim_krb5_unparse_name(milcontext, princ, &name); heim_krb5_free_principal(milcontext, princ); if (ret) return LOG_FAILURE(ret, "unparse name"); *out_principal = create_string(name); free(name); return ccNoError; }
static cc_int32 check_exists(krb5_ccache id) { krb5_principal princ; int ret; ret = heim_krb5_cc_get_principal(milcontext, id, &princ); if (ret) return 0; heim_krb5_free_principal(milcontext, princ); return 1; }
static krb5_error_code fetch_creds(KLPrincipal inPrincipal, krb5_creds **ocreds, char **outCredCacheName) { krb5_context context = mshim_ctx(); krb5_principal princ = NULL; krb5_creds in_creds; krb5_const_realm realm; krb5_error_code ret; krb5_ccache id = NULL; LOG_ENTRY(); memset(&in_creds, 0, sizeof(in_creds)); if (inPrincipal) { ret = heim_krb5_cc_cache_match(context, inPrincipal, &id); } else { ret = heim_krb5_cc_default(context, &id); if (ret == 0) ret = heim_krb5_cc_get_principal(context, id, &princ); inPrincipal = princ; } if (ret) goto out; realm = heim_krb5_principal_get_realm(context, inPrincipal); ret = heim_krb5_make_principal(context, &in_creds.server, realm, KRB5_TGS_NAME, realm, NULL); if (ret) goto out; in_creds.client = inPrincipal; ret = heim_krb5_get_credentials(context, KRB5_GC_CACHED, id, &in_creds, ocreds); heim_krb5_free_principal(context, in_creds.server); if (outCredCacheName) *outCredCacheName = strdup(heim_krb5_cc_get_name(context, id)); out: if (id) heim_krb5_cc_close(context, id); if (princ) heim_krb5_free_principal(context, princ); return LOG_FAILURE(ret, "fetch_creds"); }