-NTSTATUS gse_get_client_name(struct gse_context *gse_ctx,
- TALLOC_CTX *mem_ctx, char **cli_name)
-{
- OM_uint32 gss_min, gss_maj;
- gss_buffer_desc name_buffer;
-
- if (!gse_ctx->authenticated) {
- return NT_STATUS_ACCESS_DENIED;
- }
-
- if (!gse_ctx->client_name) {
- return NT_STATUS_NOT_FOUND;
- }
-
- /* TODO: check OID matches KRB5 Principal Name OID ? */
-
- gss_maj = gss_display_name(&gss_min,
- gse_ctx->client_name,
- &name_buffer, NULL);
- if (gss_maj) {
- DEBUG(0, ("gss_display_name failed [%s]\n",
- gse_errstr(talloc_tos(), gss_maj, gss_min)));
- return NT_STATUS_INTERNAL_ERROR;
- }
-
- *cli_name = talloc_strndup(talloc_tos(),
- (char *)name_buffer.value,
- name_buffer.length);
-
- gss_maj = gss_release_buffer(&gss_min, &name_buffer);
-
- if (!*cli_name) {
- return NT_STATUS_NO_MEMORY;
- }
-
- return NT_STATUS_OK;
-}
-
-NTSTATUS gse_get_authz_data(struct gse_context *gse_ctx,
- TALLOC_CTX *mem_ctx, DATA_BLOB *pac)
-{
- OM_uint32 gss_min, gss_maj;
- gss_buffer_set_t set = GSS_C_NO_BUFFER_SET;
-
- if (!gse_ctx->authenticated) {
- return NT_STATUS_ACCESS_DENIED;
- }
-
- gss_maj = gss_inquire_sec_context_by_oid(
- &gss_min, gse_ctx->gss_ctx,
- &gse_authz_data_oid, &set);
- if (gss_maj) {
- DEBUG(0, ("gss_inquire_sec_context_by_oid failed [%s]\n",
- gse_errstr(talloc_tos(), gss_maj, gss_min)));
- return NT_STATUS_NOT_FOUND;
- }
-
- if (set == GSS_C_NO_BUFFER_SET) {
- DEBUG(0, ("gss_inquire_sec_context_by_oid returned unknown "
- "data in results.\n"));
- return NT_STATUS_INTERNAL_ERROR;
- }
-
- /* for now we just hope it is the first value */
- *pac = data_blob_talloc(mem_ctx,
- set->elements[0].value,
- set->elements[0].length);
-
- gss_maj = gss_release_buffer_set(&gss_min, &set);
-
- return NT_STATUS_OK;
-}
-
-NTSTATUS gse_get_pac_blob(struct gse_context *gse_ctx,
- TALLOC_CTX *mem_ctx, DATA_BLOB *pac_blob)
-{
- if (!gse_ctx->authenticated) {
- return NT_STATUS_ACCESS_DENIED;
- }
-
- return gssapi_obtain_pac_blob(mem_ctx, gse_ctx->gss_ctx,
- gse_ctx->client_name, pac_blob);
-}
-
-size_t gse_get_signature_length(struct gse_context *gse_ctx,
- int seal, size_t payload_size)