1 /* $NetBSD: authorize_localname.c,v 1.1.1.1 2014/04/24 12:45:29 pettai Exp $ */
4 * Copyright (c) 2011, PADL Software Pty Ltd.
7 * Redistribution and use in source and binary forms, with or without
8 * modification, are permitted provided that the following conditions
11 * 1. Redistributions of source code must retain the above copyright
12 * notice, this list of conditions and the following disclaimer.
14 * 2. Redistributions in binary form must reproduce the above copyright
15 * notice, this list of conditions and the following disclaimer in the
16 * documentation and/or other materials provided with the distribution.
18 * 3. Neither the name of PADL Software nor the names of its contributors
19 * may be used to endorse or promote products derived from this software
20 * without specific prior written permission.
22 * THIS SOFTWARE IS PROVIDED BY PADL SOFTWARE AND CONTRIBUTORS ``AS IS'' AND
23 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
24 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
25 * ARE DISCLAIMED. IN NO EVENT SHALL PADL SOFTWARE OR CONTRIBUTORS BE LIABLE
26 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
27 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
28 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
29 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
30 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
31 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
35 #include "gsskrb5_locl.h"
37 OM_uint32 GSSAPI_CALLCONV
38 _gsskrb5_authorize_localname(OM_uint32
*minor_status
,
39 const gss_name_t input_name
,
40 gss_const_buffer_t user_name
,
41 gss_const_OID user_name_type
)
44 krb5_principal princ
= (krb5_principal
)input_name
;
48 if (!gss_oid_equal(user_name_type
, GSS_C_NT_USER_NAME
))
49 return GSS_S_BAD_NAMETYPE
;
51 GSSAPI_KRB5_INIT(&context
);
53 user
= malloc(user_name
->length
+ 1);
55 *minor_status
= ENOMEM
;
59 memcpy(user
, user_name
->value
, user_name
->length
);
60 user
[user_name
->length
] = '\0';
63 user_ok
= krb5_kuserok(context
, princ
, user
);
67 return user_ok
? GSS_S_COMPLETE
: GSS_S_UNAUTHORIZED
;