auth/common_auth.h Add a few more 'common' functions
[abartlet/samba.git/.git] / auth / common_auth.h
1 /*
2    Unix SMB/CIFS implementation.
3    Standardised Authentication types
4    Copyright (C) Andrew Bartlett 2001-2010
5
6    This program is free software; you can redistribute it and/or modify
7    it under the terms of the GNU General Public License as published by
8    the Free Software Foundation; either version 3 of the License, or
9    (at your option) any later version.
10
11    This program is distributed in the hope that it will be useful,
12    but WITHOUT ANY WARRANTY; without even the implied warranty of
13    MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
14    GNU General Public License for more details.
15
16    You should have received a copy of the GNU General Public License
17    along with this program.  If not, see <http://www.gnu.org/licenses/>.
18 */
19
20 #include "librpc/gen_ndr/krb5pac.h"
21
22 #define USER_INFO_CASE_INSENSITIVE_USERNAME 0x01 /* username may be in any case */
23 #define USER_INFO_CASE_INSENSITIVE_PASSWORD 0x02 /* password may be in any case */
24 #define USER_INFO_DONT_CHECK_UNIX_ACCOUNT   0x04 /* don't check unix account status */
25 #define USER_INFO_INTERACTIVE_LOGON         0x08 /* don't check unix account status */
26
27 enum auth_password_state {
28         AUTH_PASSWORD_PLAIN = 1,
29         AUTH_PASSWORD_HASH = 2,
30         AUTH_PASSWORD_RESPONSE = 3
31 };
32
33 struct auth_usersupplied_info
34 {
35         const char *workstation_name;
36         const struct tsocket_address *remote_host;
37
38         uint32_t logon_parameters;
39
40         bool mapped_state;
41         bool was_mapped;
42         /* the values the client gives us */
43         struct {
44                 const char *account_name;
45                 const char *domain_name;
46         } client, mapped;
47
48         enum auth_password_state password_state;
49
50         struct {
51                 struct {
52                         DATA_BLOB lanman;
53                         DATA_BLOB nt;
54                 } response;
55                 struct {
56                         struct samr_Password *lanman;
57                         struct samr_Password *nt;
58                 } hash;
59
60                 char *plaintext;
61         } password;
62         uint32_t flags;
63 };
64 struct auth_serversupplied_info;
65
66 struct auth_serversupplied_info;
67
68 /* Shared prototypes for functions that may be replaced using s3compat, to ensure things stay in sync */
69 NTSTATUS ads_verify_ticket(TALLOC_CTX *mem_ctx,
70                            const char *realm,
71                            time_t time_offset,
72                            const DATA_BLOB *ticket,
73                            char **principal,
74                            struct PAC_LOGON_INFO **logon_info,
75                            DATA_BLOB *ap_rep,
76                            DATA_BLOB *session_key,
77                            bool use_replay_cache);
78
79 /****************************************************************
80 Given a username, password and other details, return the
81 PAC_LOGON_INFO (the structure containing the important user
82 information such as groups).
83 ****************************************************************/
84
85 NTSTATUS kerberos_return_pac(TALLOC_CTX *mem_ctx,
86                              const char *name,
87                              const char *pass,
88                              time_t time_offset,
89                              time_t *expire_time,
90                              time_t *renew_till_time,
91                              const char *cache_name,
92                              bool request_pac,
93                              bool add_netbios_addr,
94                              time_t renewable_time,
95                              const char *impersonate_princ_s,
96                              struct PAC_LOGON_INFO **logon_info);
97 NTSTATUS auth_samba4_init(void);
98 NTSTATUS check_sam_security(const DATA_BLOB *challenge,
99                             TALLOC_CTX *mem_ctx,
100                             const struct auth_usersupplied_info *user_info,
101                             struct auth_serversupplied_info **server_info);