/*********************************************************************** * * Copyright (C) 2006 Novell, Inc. All Rights Reserved. * * This library is free software; you can redistribute it and/or * modify it under the terms of the GNU Lesser General Public * License as published by the Free Software Foundation; version 2.1 * of the License. * * This library is distributed in the hope that it will be useful, * but WITHOUT ANY WARRANTY; without even the implied warranty of * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU * Library Lesser General Public License for more details. * * You should have received a copy of the GNU Lesser General Public * License along with this library; if not, Novell, Inc. * * To contact Novell about this file by physical or electronic mail, * you may find current contact information at www.novell.com. * * Author: Juan Carlos Luciani * ***********************************************************************/ //===[ Include files ]===================================================== #include "internal.h" //===[ Type definitions ]================================================== #define DEFAULT_RETRY_LIFETIME 5 // seconds //===[ Function prototypes ]=============================================== //===[ Global variables ]================================================== // // Debug tracing level // int DebugLevel = 0; // // Operating parameter // bool secureRpcSetting = false; int retryLifetime = DEFAULT_RETRY_LIFETIME; //++======================================================================= static CasaStatus ObtainSessionToken( IN RpcSession *pRpcSession, IN AuthPolicy *pAuthPolicy, INOUT char **ppSessionToken) // // Arguments: // // Returns: // // Abstract: // // Notes: // // L2 //=======================================================================-- { CasaStatus retStatus = CasaStatusBuild(CASA_SEVERITY_ERROR, CASA_FACILITY_AUTHTOKEN, CASA_STATUS_UNSUCCESSFUL); LIST_ENTRY *pListEntry; AuthCacheEntry *pCacheEntry = NULL; DbgTrace(1, "-ObtainSessionToken- Start\n", 0); // Initialize output parameter *ppSessionToken = NULL; // Look in our cache for an entry that matches one of the auth // contexts specified in the AuthPolicy object. pListEntry = pAuthPolicy->authContextListHead.Flink; while (pListEntry != &pAuthPolicy->authContextListHead) { AuthContext *pAuthContext; // Get pointer to AuthContext structure pAuthContext = CONTAINING_RECORD(pListEntry, AuthContext, listEntry); // Try to find a cache entry for the auth context pCacheEntry = FindSessionTokenEntryInCache(pAuthContext->pContext); if (pCacheEntry != NULL) { // Cache entry found, check if it is of use to us. if (CASA_SUCCESS(pCacheEntry->status)) { // This entry can be used, stop looking. retStatus = pCacheEntry->status; break; } else { // Release auth cache entry reference ReleaseAuthCacheEntry(pCacheEntry); } } // Advance to the next entry pListEntry = pListEntry->Flink; } // If we did not find a cache entry that we can use, then try to create one. pListEntry = pAuthPolicy->authContextListHead.Flink; while (!CASA_SUCCESS(retStatus) && pListEntry != &pAuthPolicy->authContextListHead) { AuthContext *pAuthContext; char *pAuthMechToken; // Get pointer to AuthContext structure pAuthContext = CONTAINING_RECORD(pListEntry, AuthContext, listEntry); // Only try to create cache entry for the auth context if there is not // one already. pCacheEntry = FindSessionTokenEntryInCache(pAuthContext->pContext); if (pCacheEntry == NULL) { // Get authentication mechanism token retStatus = GetAuthMechToken(pAuthContext, &pAuthMechToken); if (!CASA_SUCCESS(retStatus)) { // We were not able to obtain an authentication mechanism token // for the context. // // Advance to the next entry pListEntry = pListEntry->Flink; continue; } // Create a cache entry for the auth context pCacheEntry = CreateSessionTokenCacheEntry(pAuthContext->pContext); if (pCacheEntry) { char *pReqMsg = NULL; char *pRespMsg = NULL; int respLen; int cacheEntryLifetime = retryLifetime; // Initialize to retry in case of failure // Authenticate to the ATS pReqMsg = BuildAuthenticateMsg(pAuthContext, pAuthMechToken); if (pReqMsg) { // Issue rpc retStatus = Rpc(pRpcSession, "Authenticate", secureRpcSetting, pReqMsg, &pRespMsg, &respLen); if (CASA_SUCCESS(retStatus)) { AuthenticateResp *pAuthenticateResp; // Create Authenticate response object retStatus = CreateAuthenticateResp(pRespMsg, respLen, &pAuthenticateResp); if (CASA_SUCCESS(retStatus)) { // Return the auth token to the caller pCacheEntry->pToken = pAuthenticateResp->pToken; pAuthenticateResp->pToken = NULL; // To keep us from freeing the buffer cacheEntryLifetime = pAuthenticateResp->tokenLifetime; // Free the Authenticate response object RelAuthenticateResp(pAuthenticateResp); } } else { DbgTrace(0, "-ObtainSessionToken- Authenticate Rpc failure, error = %08X\n", retStatus); } // Free resources that may be hanging around if (pRespMsg) free(pRespMsg); free(pReqMsg); } else { DbgTrace(0, "-ObtainSessionToken- Error building Authenticate msg\n", 0); retStatus = CasaStatusBuild(CASA_SEVERITY_ERROR, CASA_FACILITY_AUTHTOKEN, CASA_STATUS_INSUFFICIENT_RESOURCES); } // Add the entry to the cache if successful or if the reason that we failed // was because the server was unavailable. if (CASA_SUCCESS(retStatus) || CasaStatusCode(retStatus) == CASA_STATUS_AUTH_SERVER_UNAVAILABLE) { pCacheEntry->status = retStatus; AddEntryToAuthCache(pCacheEntry, cacheEntryLifetime); } // Release the cache entry if the resulting status is not successful if (!CASA_SUCCESS(retStatus)) { // Release auth cache entry reference ReleaseAuthCacheEntry(pCacheEntry); } } else { DbgTrace(0, "-ObtainSessionToken- Cache entry creation failure\n", 0); retStatus = CasaStatusBuild(CASA_SEVERITY_ERROR, CASA_FACILITY_AUTHTOKEN, CASA_STATUS_INSUFFICIENT_RESOURCES); } // Free up the buffer associated with the authentication mechanism token free(pAuthMechToken); } else { // Release auth cache entry reference ReleaseAuthCacheEntry(pCacheEntry); } // Advance to the next entry pListEntry = pListEntry->Flink; } // Return session token if successful if (CASA_SUCCESS(retStatus)) { // Allocate a buffer for the return token *ppSessionToken = (char*) malloc(strlen(pCacheEntry->pToken) + 1); if (*ppSessionToken) { // Copy the token onto the allocated buffer strcpy(*ppSessionToken, pCacheEntry->pToken); } else { DbgTrace(0, "-ObtainSessionToken- Buffer allocation failure\n", 0); retStatus = CasaStatusBuild(CASA_SEVERITY_ERROR, CASA_FACILITY_AUTHTOKEN, CASA_STATUS_INSUFFICIENT_RESOURCES); } // Release auth cache entry reference ReleaseAuthCacheEntry(pCacheEntry); } DbgTrace(1, "-ObtainSessionToken- End, retStatus = %08X\n", retStatus); return retStatus; } //++======================================================================= static CasaStatus ObtainAuthTokenFromServer( IN const char *pServiceName, IN const char *pHostName, INOUT char **ppAuthToken, INOUT int *pTokenLifetime) // // Arguments: // // Returns: // // Abstract: // // Notes: // // L2 //=======================================================================-- { CasaStatus retStatus = CASA_STATUS_SUCCESS; RpcSession *pRpcSession; DbgTrace(1, "-ObtainAuthTokenFromServer- Start\n", 0); // Initialize output parameter *ppAuthToken = NULL; // Open Rpc Session to the auth service at the specified host pRpcSession = OpenRpcSession(pHostName); if (pRpcSession) { char *pReqMsg = NULL; char *pRespMsg = NULL; int respLen; AuthPolicy *pAuthPolicy = NULL; GetAuthPolicyResp *pGetAuthPolicyResp = NULL; GetAuthTokenResp *pGetAuthTokenResp = NULL; char *pSessionToken = NULL; // Request the auth parameters associated with this service pReqMsg = BuildGetAuthPolicyMsg(pServiceName, pHostName); if (pReqMsg) { // Issue rpc retStatus = Rpc(pRpcSession, "GetAuthPolicy", secureRpcSetting, pReqMsg, &pRespMsg, &respLen); if (CASA_SUCCESS(retStatus)) { // Create GetAuthPolicy response object retStatus = CreateGetAuthPolicyResp(pRespMsg, respLen, &pGetAuthPolicyResp); if (CASA_SUCCESS(retStatus)) { // Create the AuthPolicy object retStatus = CreateAuthPolicy(pGetAuthPolicyResp->pPolicy, pGetAuthPolicyResp->policyLen, &pAuthPolicy); if (CASA_SUCCESS(retStatus)) { // Now try to obtain a session token retStatus = ObtainSessionToken(pRpcSession, pAuthPolicy, &pSessionToken); if (CASA_SUCCESS(retStatus)) { // Request auth token for the service free(pReqMsg); pReqMsg = BuildGetAuthTokenMsg(pServiceName, pHostName, pSessionToken); if (pReqMsg) { // Free the previous response msg buffer free(pRespMsg); pRespMsg = NULL; // Issue rpc retStatus = Rpc(pRpcSession, "GetAuthToken", secureRpcSetting, pReqMsg, &pRespMsg, &respLen); if (CASA_SUCCESS(retStatus)) { // Create GetAuthPolicy response object retStatus = CreateGetAuthTokenResp(pRespMsg, respLen, &pGetAuthTokenResp); if (CASA_SUCCESS(retStatus)) { // Return the auth token to the caller *ppAuthToken = pGetAuthTokenResp->pToken; pGetAuthTokenResp->pToken = NULL; // To keep us from freeing the buffer *pTokenLifetime = pGetAuthTokenResp->tokenLifetime; } else { DbgTrace(0, "-ObtainAuthTokenFromServer- Failed to create GetAuthTokenResp object, error = %08X\n", retStatus); } } else { DbgTrace(0, "-ObtainAuthTokenFromServer- GetAuthToken Rpc failure, error = %08X\n", retStatus); } } else { DbgTrace(0, "-ObtainAuthTokenFromServer- Error building GetAuthToken msg\n", 0); retStatus = CasaStatusBuild(CASA_SEVERITY_ERROR, CASA_FACILITY_AUTHTOKEN, CASA_STATUS_INSUFFICIENT_RESOURCES); } } else { DbgTrace(0, "-ObtainAuthTokenFromServer- Failed to obtain session token, error = %08X\n", retStatus); } } else { DbgTrace(0, "-ObtainAuthTokenFromServer- Failed to create AuthPolicy object, error = %08X\n", retStatus); } } else { DbgTrace(0, "-ObtainAuthTokenFromServer- Failed to create GetAuthPolicyResp object, error = %08X\n", retStatus); } } else { DbgTrace(0, "-ObtainAuthTokenFromServer- GetAuthPolicy Rpc failure, error = %08X\n", retStatus); } // Free resources that may be hanging around if (pReqMsg) free(pReqMsg); if (pRespMsg) free(pRespMsg); if (pSessionToken) free(pSessionToken); if (pGetAuthTokenResp) RelGetAuthTokenResp(pGetAuthTokenResp); if (pGetAuthPolicyResp) RelGetAuthPolicyResp(pGetAuthPolicyResp); if (pAuthPolicy) RelAuthPolicy(pAuthPolicy); } else { DbgTrace(0, "-ObtainAuthTokenFromServer- Error building GetAuthPolicy msg\n", 0); retStatus = CasaStatusBuild(CASA_SEVERITY_ERROR, CASA_FACILITY_AUTHTOKEN, CASA_STATUS_INSUFFICIENT_RESOURCES); } // Close the Rpc Session CloseRpcSession(pRpcSession); } else { DbgTrace(0, "-ObtainAuthTokenFromServer- Error opening Rpc session\n", 0); retStatus = CasaStatusBuild(CASA_SEVERITY_ERROR, CASA_FACILITY_AUTHTOKEN, CASA_STATUS_INSUFFICIENT_RESOURCES); } DbgTrace(1, "-ObtainAuthTokenFromServer- End, retStatus = %08X\n", retStatus); return retStatus; } //++======================================================================= CasaStatus SSCS_CALL ObtainAuthToken( IN const char *pServiceName, IN const char *pHostName, INOUT char *pAuthTokenBuf, INOUT int *pAuthTokenBufLen) // // Arguments: // pServiceName - // Pointer to NULL terminated string that contains the // name of the service to which the client is trying to // authenticate. // // pHostName - // Pointer to NULL terminated string that contains the // name of the host where resides the service to which the // client is trying to authenticate. Note that the name // can either be a DNS name or a dotted IP address. // // pAuthTokenBuf - // Pointer to buffer that will receive the authentication // token. The length of this buffer is specified by the // pAuthTokenBufLen parameter. Note that the the authentication // token will be in the form of a NULL terminated string. // // pAuthTokenBufLen - // Pointer to integer that contains the length of the // buffer pointed at by pAuthTokenBuf. Upon return of the // function, the integer will contain the actual length // of the authentication token if the function successfully // completes or the buffer length required if the function // fails because the buffer pointed at by pAuthTokenBuf is // not large enough. // // Returns: // Casa Status // // Description: // Get authentication token to authenticate user to specified // service at host. // // L2 //=======================================================================-- { CasaStatus retStatus = CASA_STATUS_SUCCESS; AuthCacheEntry *pCacheEntry; char *pNormalizedHostName; DbgTrace(1, "-ObtainAuthToken- Start\n", 0); // Verify the input parameters if (pServiceName == NULL || pHostName == NULL || pAuthTokenBufLen == NULL || (*pAuthTokenBufLen != 0 && pAuthTokenBuf == NULL)) { DbgTrace(0, "-ObtainAuthToken- Invalid parameter\n", 0); retStatus = CasaStatusBuild(CASA_SEVERITY_ERROR, CASA_FACILITY_AUTHTOKEN, CASA_STATUS_INVALID_PARAMETER); goto exit; } // Normalize the host name pNormalizedHostName = NormalizeHostName(pHostName); if (pNormalizedHostName) { // Start user process synchronization AcquireUserMutex(); // Try to find a cache entry for the service pCacheEntry = FindAuthTokenEntryInCache(pServiceName, pNormalizedHostName); if (pCacheEntry == NULL) { // No entry found in the cache, create one. pCacheEntry = CreateAuthTokenCacheEntry(pServiceName, pNormalizedHostName); if (pCacheEntry) { int cacheEntryLifetime = retryLifetime; // Initialize to retry in case of failure // Cache entry created, now try to obtain auth token from the CASA Server retStatus = ObtainAuthTokenFromServer(pServiceName, pNormalizedHostName, &pCacheEntry->pToken, &cacheEntryLifetime); // Add the entry to the cache if successful or if the reason that we failed // was because the server was un-available. if (CASA_SUCCESS(retStatus) || CasaStatusCode(retStatus) == CASA_STATUS_AUTH_SERVER_UNAVAILABLE) { pCacheEntry->status = retStatus; AddEntryToAuthCache(pCacheEntry, cacheEntryLifetime); } // Release the cache entry if the resulting status is not successful if (!CASA_SUCCESS(retStatus)) { // Release auth cache entry reference ReleaseAuthCacheEntry(pCacheEntry); } } else { DbgTrace(0, "-ObtainAuthToken- Cache entry creation failure\n", 0); retStatus = CasaStatusBuild(CASA_SEVERITY_ERROR, CASA_FACILITY_AUTHTOKEN, CASA_STATUS_INSUFFICIENT_RESOURCES); } } else { // Cache entry found, update the return status with the information saved in it // and release it if its status is not successful. if (!CASA_SUCCESS(retStatus = pCacheEntry->status)) { // Release auth cache entry reference ReleaseAuthCacheEntry(pCacheEntry); } } // Try to return auth token if we have one to return if (CASA_SUCCESS(retStatus)) { int tokenLen = (int) strlen(pCacheEntry->pToken) + 1; // We have an authentication token, try to return it to the caller // after verifying that the supplied buffer is big enough. if (*pAuthTokenBufLen >= tokenLen) { // Return the auth token to the caller strcpy(pAuthTokenBuf, pCacheEntry->pToken); } else { DbgTrace(0, "-ObtainAuthToken- The supplied buffer is not large enough", 0); retStatus = CasaStatusBuild(CASA_SEVERITY_ERROR, CASA_FACILITY_AUTHTOKEN, CASA_STATUS_BUFFER_OVERFLOW); } // Return the token length to the caller *pAuthTokenBufLen = tokenLen; // Release auth cache entry reference ReleaseAuthCacheEntry(pCacheEntry); } // Stop user process synchronization ReleaseUserMutex(); // Free the space allocated for the normalized host name free(pNormalizedHostName); } else { DbgTrace(0, "-ObtainAuthToken- Host name normalization failed\n", 0); retStatus = CasaStatusBuild(CASA_SEVERITY_ERROR, CASA_FACILITY_AUTHTOKEN, CASA_STATUS_UNSUCCESSFUL); } exit: DbgTrace(1, "-ObtainAuthToken- End, retStatus = %08X\n", retStatus); return retStatus; } //++======================================================================= int InitializeLibrary(void) // // Arguments: // // Returns: // // Abstract: // // Notes: // // L2 //=======================================================================-- { int retStatus = -1; DbgTrace(1, "-InitializeLibrary- Start\n", 0); // Create user synchronization mutex if (CreateUserMutex() == 0) { // Initialize the auth cache if (CASA_SUCCESS(InitializeAuthCache())) { // Initialize the host name normalization if (CASA_SUCCESS(InitializeHostNameNormalization())) { // Success retStatus = 0; } else { DbgTrace(0, "-InitializeLibrary- Error initializing host name normalization\n", 0); } } else { DbgTrace(0, "-InitializeLibrary- Error initializing the auth cache\n", 0); } } else { DbgTrace(0, "-InitializeLibrary- Error creating mutex for the user\n", 0); } DbgTrace(1, "-InitializeLibrary- End, retStatus = %08X\n", retStatus); return retStatus; } //++======================================================================= //++======================================================================= //++=======================================================================