2000-01-24 14:14:26 -05:00
|
|
|
/*
|
2018-02-23 03:53:12 -05:00
|
|
|
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
2000-07-31 21:33:37 -04:00
|
|
|
*
|
2016-06-27 00:56:38 -04:00
|
|
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
|
|
|
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
|
|
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
2018-02-23 03:53:12 -05:00
|
|
|
*
|
|
|
|
|
* See the COPYRIGHT file distributed with this work for additional
|
|
|
|
|
* information regarding copyright ownership.
|
2000-01-24 14:14:26 -05:00
|
|
|
*/
|
|
|
|
|
|
2005-04-27 00:57:32 -04:00
|
|
|
|
|
|
|
|
/*! \file */
|
2000-06-22 18:00:42 -04:00
|
|
|
|
2018-03-28 08:19:37 -04:00
|
|
|
#include <inttypes.h>
|
|
|
|
|
|
2000-05-08 10:38:29 -04:00
|
|
|
#include <isc/buffer.h>
|
2000-05-08 15:23:32 -04:00
|
|
|
#include <isc/string.h> /* Required for HP/UX (and others?) */
|
2000-05-08 10:38:29 -04:00
|
|
|
#include <isc/mem.h>
|
2000-01-24 14:14:26 -05:00
|
|
|
|
2001-03-04 16:21:39 -05:00
|
|
|
#include <isccfg/cfg.h>
|
|
|
|
|
|
2000-10-11 20:39:17 -04:00
|
|
|
#include <dns/fixedname.h>
|
2000-01-24 14:14:26 -05:00
|
|
|
#include <dns/keyvalues.h>
|
|
|
|
|
#include <dns/name.h>
|
2000-05-08 10:38:29 -04:00
|
|
|
#include <dns/tkey.h>
|
2000-01-24 14:14:26 -05:00
|
|
|
|
2000-10-11 21:08:32 -04:00
|
|
|
#include <dst/gssapi.h>
|
|
|
|
|
|
2000-11-27 14:42:38 -05:00
|
|
|
#include <named/tkeyconf.h>
|
|
|
|
|
|
2000-01-24 14:14:26 -05:00
|
|
|
#define RETERR(x) do { \
|
|
|
|
|
result = (x); \
|
|
|
|
|
if (result != ISC_R_SUCCESS) \
|
|
|
|
|
goto failure; \
|
|
|
|
|
} while (0)
|
|
|
|
|
|
2006-12-03 20:54:53 -05:00
|
|
|
#include<named/log.h>
|
|
|
|
|
#define LOG(msg) \
|
2017-09-08 16:39:09 -04:00
|
|
|
isc_log_write(named_g_lctx, \
|
|
|
|
|
NAMED_LOGCATEGORY_GENERAL, \
|
|
|
|
|
NAMED_LOGMODULE_SERVER, \
|
2006-12-03 20:54:53 -05:00
|
|
|
ISC_LOG_ERROR, \
|
|
|
|
|
"%s", msg)
|
2000-01-24 14:14:26 -05:00
|
|
|
|
|
|
|
|
isc_result_t
|
2017-09-08 16:39:09 -04:00
|
|
|
named_tkeyctx_fromconfig(const cfg_obj_t *options, isc_mem_t *mctx,
|
2018-04-22 08:56:28 -04:00
|
|
|
dns_tkeyctx_t **tctxp)
|
2000-01-24 14:14:26 -05:00
|
|
|
{
|
|
|
|
|
isc_result_t result;
|
2000-06-09 18:33:08 -04:00
|
|
|
dns_tkeyctx_t *tctx = NULL;
|
2005-08-22 22:36:11 -04:00
|
|
|
const char *s;
|
2018-03-28 08:19:37 -04:00
|
|
|
uint32_t n;
|
2000-10-11 20:39:17 -04:00
|
|
|
dns_fixedname_t fname;
|
|
|
|
|
dns_name_t *name;
|
|
|
|
|
isc_buffer_t b;
|
2006-02-27 21:39:52 -05:00
|
|
|
const cfg_obj_t *obj;
|
2004-06-10 20:27:06 -04:00
|
|
|
int type;
|
2000-01-24 14:14:26 -05:00
|
|
|
|
2018-04-22 08:56:28 -04:00
|
|
|
result = dns_tkeyctx_create(mctx, &tctx);
|
2000-01-24 14:14:26 -05:00
|
|
|
if (result != ISC_R_SUCCESS)
|
|
|
|
|
return (result);
|
|
|
|
|
|
2001-03-04 16:21:39 -05:00
|
|
|
obj = NULL;
|
|
|
|
|
result = cfg_map_get(options, "tkey-dhkey", &obj);
|
2000-10-11 20:39:17 -04:00
|
|
|
if (result == ISC_R_SUCCESS) {
|
2001-03-04 16:21:39 -05:00
|
|
|
s = cfg_obj_asstring(cfg_tuple_get(obj, "name"));
|
|
|
|
|
n = cfg_obj_asuint32(cfg_tuple_get(obj, "keyid"));
|
2012-12-07 20:48:57 -05:00
|
|
|
isc_buffer_constinit(&b, s, strlen(s));
|
2000-10-11 20:39:17 -04:00
|
|
|
isc_buffer_add(&b, strlen(s));
|
2018-03-28 08:38:09 -04:00
|
|
|
name = dns_fixedname_initname(&fname);
|
2009-08-31 20:22:28 -04:00
|
|
|
RETERR(dns_name_fromtext(name, &b, dns_rootname, 0, NULL));
|
2004-06-10 20:27:06 -04:00
|
|
|
type = DST_TYPE_PUBLIC|DST_TYPE_PRIVATE|DST_TYPE_KEY;
|
2001-05-05 22:20:29 -04:00
|
|
|
RETERR(dst_key_fromfile(name, (dns_keytag_t) n, DNS_KEYALG_DH,
|
2004-06-10 20:27:06 -04:00
|
|
|
type, NULL, mctx, &tctx->dhkey));
|
2001-03-04 16:21:39 -05:00
|
|
|
}
|
2000-10-11 20:39:17 -04:00
|
|
|
|
2001-03-04 16:21:39 -05:00
|
|
|
obj = NULL;
|
|
|
|
|
result = cfg_map_get(options, "tkey-domain", &obj);
|
2000-10-11 20:39:17 -04:00
|
|
|
if (result == ISC_R_SUCCESS) {
|
2001-03-04 16:21:39 -05:00
|
|
|
s = cfg_obj_asstring(obj);
|
2012-12-07 20:48:57 -05:00
|
|
|
isc_buffer_constinit(&b, s, strlen(s));
|
2000-10-11 20:39:17 -04:00
|
|
|
isc_buffer_add(&b, strlen(s));
|
2018-03-28 08:38:09 -04:00
|
|
|
name = dns_fixedname_initname(&fname);
|
2009-08-31 20:22:28 -04:00
|
|
|
RETERR(dns_name_fromtext(name, &b, dns_rootname, 0, NULL));
|
2000-10-11 20:39:17 -04:00
|
|
|
tctx->domain = isc_mem_get(mctx, sizeof(dns_name_t));
|
|
|
|
|
dns_name_init(tctx->domain, NULL);
|
|
|
|
|
RETERR(dns_name_dup(name, mctx, tctx->domain));
|
2001-03-04 16:21:39 -05:00
|
|
|
}
|
2000-10-11 20:39:17 -04:00
|
|
|
|
2001-03-04 16:21:39 -05:00
|
|
|
obj = NULL;
|
|
|
|
|
result = cfg_map_get(options, "tkey-gssapi-credential", &obj);
|
2000-10-11 20:39:17 -04:00
|
|
|
if (result == ISC_R_SUCCESS) {
|
2001-03-04 16:21:39 -05:00
|
|
|
s = cfg_obj_asstring(obj);
|
2006-12-03 20:54:53 -05:00
|
|
|
|
2012-12-07 20:48:57 -05:00
|
|
|
isc_buffer_constinit(&b, s, strlen(s));
|
2000-10-11 20:39:17 -04:00
|
|
|
isc_buffer_add(&b, strlen(s));
|
2018-03-28 08:38:09 -04:00
|
|
|
name = dns_fixedname_initname(&fname);
|
2009-08-31 20:22:28 -04:00
|
|
|
RETERR(dns_name_fromtext(name, &b, dns_rootname, 0, NULL));
|
2018-04-17 11:29:14 -04:00
|
|
|
RETERR(dst_gssapi_acquirecred(name, false, &tctx->gsscred));
|
2001-03-04 16:21:39 -05:00
|
|
|
}
|
2000-01-24 14:14:26 -05:00
|
|
|
|
2010-12-17 20:56:23 -05:00
|
|
|
obj = NULL;
|
|
|
|
|
result = cfg_map_get(options, "tkey-gssapi-keytab", &obj);
|
|
|
|
|
if (result == ISC_R_SUCCESS) {
|
|
|
|
|
s = cfg_obj_asstring(obj);
|
|
|
|
|
tctx->gssapi_keytab = isc_mem_strdup(mctx, s);
|
|
|
|
|
}
|
|
|
|
|
|
2000-01-24 14:14:26 -05:00
|
|
|
*tctxp = tctx;
|
|
|
|
|
return (ISC_R_SUCCESS);
|
|
|
|
|
|
|
|
|
|
failure:
|
|
|
|
|
dns_tkeyctx_destroy(&tctx);
|
|
|
|
|
return (result);
|
|
|
|
|
}
|
|
|
|
|
|