-/*
- * $Source$
- * $Header$
+/* $Id$
+ *
+ * Copyright (C) 1988-1998 by the Massachusetts Institute of Technology.
+ * For copying and distribution information, please see the file
+ * <mit-copyright.h>.
*/
-/* (c) Copyright 1988 by the Massachusetts Institute of Technology. */
-/* For copying and distribution information, please see the file */
-/* <mit-copyright.h>. */
-
-#ifndef lint
-static char *rcsid_ticket_c = "$Header$";
-#endif lint
#include <mit-copyright.h>
+#include <moira.h>
+
+#include <sys/stat.h>
+
#include <stdio.h>
+#include <string.h>
+
+#ifdef HAVE_KRB4
#include <krb.h>
-#include <sys/types.h>
-#include <sys/stat.h>
-#include <strings.h>
+#else
+#define KTEXT void*
+#endif
+#include <krb5.h>
#include <update.h>
-#include <com_err.h>
-#include <krb_et.h>
-/* too bad we can't set the pathname easily */
-static char *srvtab = KEYFILE; /* default == /etc/srvtab */
-static char realm[REALM_SZ];
-static char master[] = "sms";
-static char service[] = "rcmd";
+RCSID("$Header$");
-extern char *tkt_string(), *PrincipalHostname();
+#ifdef HAVE_KRB4
+static char realm[REALM_SZ];
+static char master[INST_SZ] = "sms";
+static char service[ANAME_SZ] = "rcmd";
+des_cblock session;
+#endif
+krb5_context context = NULL;
+#ifdef HAVE_KRB4
+static int get_mr_tgt(void);
+#endif
-static init()
+int get_mr_krb5_update_ticket(char *host, krb5_data auth)
{
- static int initialized = 0;
+ krb5_auth_context auth_con = NULL;
+ krb5_ccache ccache = NULL;
+ krb5_error_code code;
- if (!initialized) {
- get_krbrlm(realm, 1);
- initialize_krb_error_table();
- initialized=1;
- }
-}
+ code = krb5_init_context(&context);
+ if (code)
+ goto out;
+ code = krb5_auth_con_init(context, &auth_con);
+ if (code)
+ goto out;
-int
-get_sms_update_ticket(host, ticket)
- char *host;
- KTEXT ticket;
+ code = krb5_cc_default(context, &ccache);
+ if (code)
+ goto out;
+
+ code = krb5_mk_req(context, &auth_con, 0, "host", host, NULL, ccache,
+ &auth);
+
+ out:
+ if (ccache)
+ krb5_cc_close(context, ccache);
+ if (auth_con)
+ krb5_auth_con_free(context, auth_con);
+ return code;
+}
+
+int get_mr_update_ticket(char *host, KTEXT ticket)
{
- register int code;
- register int pass;
- char phost[BUFSIZ];
-
- pass = 1;
- init();
- strcpy(phost, PrincipalHostname(host));
- try_it:
- code = krb_mk_req(ticket, service, phost, realm, (long)0);
- if (code)
- code += ERROR_TABLE_BASE_krb;
- if (pass == 1) {
- /* maybe we're taking too long? */
- if ((code = get_sms_tgt()) != 0) {
- /* don't need phost buffer any more */
- com_err(whoami, code, " can't get Kerberos TGT");
- return(code);
- }
- pass++;
- goto try_it;
- }
- return(code);
+#ifdef HAVE_KRB4
+ int code, pass;
+ char phost[BUFSIZ];
+ CREDENTIALS cr;
+
+ pass = 1;
+ if (krb_get_lrealm(realm, 1))
+ strcpy(realm, KRB_REALM);
+ strcpy(phost, (char *)krb_get_phost(host));
+
+try_it:
+ code = krb_mk_req(ticket, service, phost, realm, (long)0);
+ if (code)
+ {
+ if (pass == 1)
+ {
+ /* maybe we're taking too long? */
+ if ((code = get_mr_tgt()))
+ {
+ com_err(whoami, code, "can't get Kerberos TGT");
+ return code;
+ }
+ pass++;
+ goto try_it;
+ }
+ code += ERROR_TABLE_BASE_krb;
+ com_err(whoami, code, "in krb_mk_req");
+ }
+ else
+ {
+ code = krb_get_cred(service, phost, realm, &cr);
+ if (code)
+ code += ERROR_TABLE_BASE_krb;
+ memcpy(session, cr.session, sizeof(session));
+ }
+ return code;
+#else
+ return MR_NO_KRB4;
+#endif
}
-int
-get_sms_tgt()
+#ifdef HAVE_KRB4
+static int get_mr_tgt(void)
{
- register int code;
- init();
- code = get_svc_in_tkt(master, "", realm, "krbtgt", realm, 1, srvtab);
- if (!code)
- return(0);
- else
- return(code + ERROR_TABLE_BASE_krb);
+ int code;
+ char linst[INST_SZ], kinst[INST_SZ];
+
+ linst[0] = '\0';
+ strcpy(kinst, "krbtgt");
+ code = krb_get_svc_in_tkt(master, linst, realm, kinst, realm,
+ DEFAULT_TKT_LIFE, KEYFILE);
+ if (!code)
+ return 0;
+ else
+ return code + ERROR_TABLE_BASE_krb;
}
+#endif