|
|
59dcbd |
From c53a51a61d7ac20900836b1bb005bf272c08a849 Mon Sep 17 00:00:00 2001
|
|
|
59dcbd |
From: Sumit Bose <sbose@redhat.com>
|
|
|
59dcbd |
Date: Mon, 4 Jun 2018 10:49:33 +0200
|
|
|
59dcbd |
Subject: [PATCH 3/7] update: allow to add service names
|
|
|
59dcbd |
|
|
|
59dcbd |
Related to https://bugzilla.redhat.com/show_bug.cgi?id=1547013
|
|
|
59dcbd |
https://bugzilla.redhat.com/show_bug.cgi?id=1545568
|
|
|
59dcbd |
---
|
|
|
59dcbd |
library/adenroll.c | 136 +++++++++++++++++++++++++++++++++-------------------
|
|
|
59dcbd |
library/adkrb5.c | 113 +++++++++++++++++++++++++++++++++++++++++++
|
|
|
59dcbd |
library/adprivate.h | 6 +++
|
|
|
59dcbd |
3 files changed, 206 insertions(+), 49 deletions(-)
|
|
|
59dcbd |
|
|
|
59dcbd |
diff --git a/library/adenroll.c b/library/adenroll.c
|
|
|
59dcbd |
index 2be6796..1221e89 100644
|
|
|
59dcbd |
--- a/library/adenroll.c
|
|
|
59dcbd |
+++ b/library/adenroll.c
|
|
|
59dcbd |
@@ -305,13 +305,37 @@ ensure_service_names (adcli_result res,
|
|
|
59dcbd |
}
|
|
|
59dcbd |
|
|
|
59dcbd |
static adcli_result
|
|
|
59dcbd |
-ensure_service_principals (adcli_result res,
|
|
|
59dcbd |
- adcli_enroll *enroll)
|
|
|
59dcbd |
+add_service_names_to_service_principals (adcli_enroll *enroll)
|
|
|
59dcbd |
{
|
|
|
59dcbd |
char *name;
|
|
|
59dcbd |
int length = 0;
|
|
|
59dcbd |
int i;
|
|
|
59dcbd |
|
|
|
59dcbd |
+ if (enroll->service_principals != NULL) {
|
|
|
59dcbd |
+ length = seq_count (enroll->service_principals);
|
|
|
59dcbd |
+ }
|
|
|
59dcbd |
+
|
|
|
59dcbd |
+ for (i = 0; enroll->service_names[i] != NULL; i++) {
|
|
|
59dcbd |
+ if (asprintf (&name, "%s/%s", enroll->service_names[i], enroll->computer_name) < 0)
|
|
|
59dcbd |
+ return_unexpected_if_reached ();
|
|
|
59dcbd |
+ enroll->service_principals = _adcli_strv_add (enroll->service_principals,
|
|
|
59dcbd |
+ name, &length);
|
|
|
59dcbd |
+
|
|
|
59dcbd |
+ if (enroll->host_fqdn) {
|
|
|
59dcbd |
+ if (asprintf (&name, "%s/%s", enroll->service_names[i], enroll->host_fqdn) < 0)
|
|
|
59dcbd |
+ return_unexpected_if_reached ();
|
|
|
59dcbd |
+ enroll->service_principals = _adcli_strv_add (enroll->service_principals,
|
|
|
59dcbd |
+ name, &length);
|
|
|
59dcbd |
+ }
|
|
|
59dcbd |
+ }
|
|
|
59dcbd |
+
|
|
|
59dcbd |
+ return ADCLI_SUCCESS;
|
|
|
59dcbd |
+}
|
|
|
59dcbd |
+
|
|
|
59dcbd |
+static adcli_result
|
|
|
59dcbd |
+ensure_service_principals (adcli_result res,
|
|
|
59dcbd |
+ adcli_enroll *enroll)
|
|
|
59dcbd |
+{
|
|
|
59dcbd |
if (res != ADCLI_SUCCESS)
|
|
|
59dcbd |
return res;
|
|
|
59dcbd |
|
|
|
59dcbd |
@@ -319,20 +343,7 @@ ensure_service_principals (adcli_result res,
|
|
|
59dcbd |
|
|
|
59dcbd |
if (!enroll->service_principals) {
|
|
|
59dcbd |
assert (enroll->service_names != NULL);
|
|
|
59dcbd |
-
|
|
|
59dcbd |
- for (i = 0; enroll->service_names[i] != NULL; i++) {
|
|
|
59dcbd |
- if (asprintf (&name, "%s/%s", enroll->service_names[i], enroll->computer_name) < 0)
|
|
|
59dcbd |
- return_unexpected_if_reached ();
|
|
|
59dcbd |
- enroll->service_principals = _adcli_strv_add (enroll->service_principals,
|
|
|
59dcbd |
- name, &length);
|
|
|
59dcbd |
-
|
|
|
59dcbd |
- if (enroll->host_fqdn) {
|
|
|
59dcbd |
- if (asprintf (&name, "%s/%s", enroll->service_names[i], enroll->host_fqdn) < 0)
|
|
|
59dcbd |
- return_unexpected_if_reached ();
|
|
|
59dcbd |
- enroll->service_principals = _adcli_strv_add (enroll->service_principals,
|
|
|
59dcbd |
- name, &length);
|
|
|
59dcbd |
- }
|
|
|
59dcbd |
- }
|
|
|
59dcbd |
+ return add_service_names_to_service_principals (enroll);
|
|
|
59dcbd |
}
|
|
|
59dcbd |
|
|
|
59dcbd |
return ADCLI_SUCCESS;
|
|
|
59dcbd |
@@ -356,6 +367,7 @@ ensure_keytab_principals (adcli_result res,
|
|
|
59dcbd |
return_unexpected_if_fail (k5 != NULL);
|
|
|
59dcbd |
|
|
|
59dcbd |
enroll->keytab_principals = calloc (count + 3, sizeof (krb5_principal));
|
|
|
59dcbd |
+ return_unexpected_if_fail (enroll->keytab_principals != NULL);
|
|
|
59dcbd |
at = 0;
|
|
|
59dcbd |
|
|
|
59dcbd |
/* First add the principal for the computer account name */
|
|
|
59dcbd |
@@ -1266,7 +1278,7 @@ update_computer_account (adcli_enroll *enroll)
|
|
|
59dcbd |
}
|
|
|
59dcbd |
}
|
|
|
59dcbd |
|
|
|
59dcbd |
- if (res == ADCLI_SUCCESS && !enroll->user_princpal_generate) {
|
|
|
59dcbd |
+ if (res == ADCLI_SUCCESS && enroll->user_principal != NULL && !enroll->user_princpal_generate) {
|
|
|
59dcbd |
char *vals_userPrincipalName[] = { enroll->user_principal, NULL };
|
|
|
59dcbd |
LDAPMod userPrincipalName = { LDAP_MOD_REPLACE, "userPrincipalName", { vals_userPrincipalName, }, };
|
|
|
59dcbd |
LDAPMod *mods[] = { &userPrincipalName, NULL, };
|
|
|
59dcbd |
@@ -1519,7 +1531,8 @@ add_principal_to_keytab (adcli_enroll *enroll,
|
|
|
59dcbd |
krb5_context k5,
|
|
|
59dcbd |
krb5_principal principal,
|
|
|
59dcbd |
const char *principal_name,
|
|
|
59dcbd |
- int *which_salt)
|
|
|
59dcbd |
+ int *which_salt,
|
|
|
59dcbd |
+ adcli_enroll_flags flags)
|
|
|
59dcbd |
{
|
|
|
59dcbd |
match_principal_kvno closure;
|
|
|
59dcbd |
krb5_data password;
|
|
|
59dcbd |
@@ -1547,41 +1560,47 @@ add_principal_to_keytab (adcli_enroll *enroll,
|
|
|
59dcbd |
enroll->keytab_name);
|
|
|
59dcbd |
}
|
|
|
59dcbd |
|
|
|
59dcbd |
- password.data = enroll->computer_password;
|
|
|
59dcbd |
- password.length = strlen (enroll->computer_password);
|
|
|
59dcbd |
-
|
|
|
59dcbd |
enctypes = adcli_enroll_get_keytab_enctypes (enroll);
|
|
|
59dcbd |
|
|
|
59dcbd |
- /*
|
|
|
59dcbd |
- * So we need to discover which salt to use. As a side effect we are
|
|
|
59dcbd |
- * also testing that our account works.
|
|
|
59dcbd |
- */
|
|
|
59dcbd |
+ if (flags & ADCLI_ENROLL_PASSWORD_VALID) {
|
|
|
59dcbd |
+ code = _adcli_krb5_keytab_copy_entries (k5, enroll->keytab, principal,
|
|
|
59dcbd |
+ enroll->kvno, enctypes);
|
|
|
59dcbd |
+ } else {
|
|
|
59dcbd |
|
|
|
59dcbd |
- salts = build_principal_salts (enroll, k5, principal);
|
|
|
59dcbd |
- return_unexpected_if_fail (salts != NULL);
|
|
|
59dcbd |
+ password.data = enroll->computer_password;
|
|
|
59dcbd |
+ password.length = strlen (enroll->computer_password);
|
|
|
59dcbd |
|
|
|
59dcbd |
- if (*which_salt < 0) {
|
|
|
59dcbd |
- code = _adcli_krb5_keytab_discover_salt (k5, principal, enroll->kvno, &password,
|
|
|
59dcbd |
- enctypes, salts, which_salt);
|
|
|
59dcbd |
- if (code != 0) {
|
|
|
59dcbd |
- _adcli_warn ("Couldn't authenticate with keytab while discovering which salt to use: %s: %s",
|
|
|
59dcbd |
- principal_name, krb5_get_error_message (k5, code));
|
|
|
59dcbd |
- *which_salt = DEFAULT_SALT;
|
|
|
59dcbd |
- } else {
|
|
|
59dcbd |
- assert (*which_salt >= 0);
|
|
|
59dcbd |
- _adcli_info ("Discovered which keytab salt to use");
|
|
|
59dcbd |
+ /*
|
|
|
59dcbd |
+ * So we need to discover which salt to use. As a side effect we are
|
|
|
59dcbd |
+ * also testing that our account works.
|
|
|
59dcbd |
+ */
|
|
|
59dcbd |
+
|
|
|
59dcbd |
+ salts = build_principal_salts (enroll, k5, principal);
|
|
|
59dcbd |
+ return_unexpected_if_fail (salts != NULL);
|
|
|
59dcbd |
+
|
|
|
59dcbd |
+ if (*which_salt < 0) {
|
|
|
59dcbd |
+ code = _adcli_krb5_keytab_discover_salt (k5, principal, enroll->kvno, &password,
|
|
|
59dcbd |
+ enctypes, salts, which_salt);
|
|
|
59dcbd |
+ if (code != 0) {
|
|
|
59dcbd |
+ _adcli_warn ("Couldn't authenticate with keytab while discovering which salt to use: %s: %s",
|
|
|
59dcbd |
+ principal_name, krb5_get_error_message (k5, code));
|
|
|
59dcbd |
+ *which_salt = DEFAULT_SALT;
|
|
|
59dcbd |
+ } else {
|
|
|
59dcbd |
+ assert (*which_salt >= 0);
|
|
|
59dcbd |
+ _adcli_info ("Discovered which keytab salt to use");
|
|
|
59dcbd |
+ }
|
|
|
59dcbd |
}
|
|
|
59dcbd |
- }
|
|
|
59dcbd |
|
|
|
59dcbd |
- code = _adcli_krb5_keytab_add_entries (k5, enroll->keytab, principal,
|
|
|
59dcbd |
- enroll->kvno, &password, enctypes, &salts[*which_salt]);
|
|
|
59dcbd |
+ code = _adcli_krb5_keytab_add_entries (k5, enroll->keytab, principal,
|
|
|
59dcbd |
+ enroll->kvno, &password, enctypes, &salts[*which_salt]);
|
|
|
59dcbd |
|
|
|
59dcbd |
- free_principal_salts (k5, salts);
|
|
|
59dcbd |
+ free_principal_salts (k5, salts);
|
|
|
59dcbd |
|
|
|
59dcbd |
- if (code != 0) {
|
|
|
59dcbd |
- _adcli_err ("Couldn't add keytab entries: %s: %s",
|
|
|
59dcbd |
- enroll->keytab_name, krb5_get_error_message (k5, code));
|
|
|
59dcbd |
- return ADCLI_ERR_FAIL;
|
|
|
59dcbd |
+ if (code != 0) {
|
|
|
59dcbd |
+ _adcli_err ("Couldn't add keytab entries: %s: %s",
|
|
|
59dcbd |
+ enroll->keytab_name, krb5_get_error_message (k5, code));
|
|
|
59dcbd |
+ return ADCLI_ERR_FAIL;
|
|
|
59dcbd |
+ }
|
|
|
59dcbd |
}
|
|
|
59dcbd |
|
|
|
59dcbd |
|
|
|
59dcbd |
@@ -1591,7 +1610,8 @@ add_principal_to_keytab (adcli_enroll *enroll,
|
|
|
59dcbd |
}
|
|
|
59dcbd |
|
|
|
59dcbd |
static adcli_result
|
|
|
59dcbd |
-update_keytab_for_principals (adcli_enroll *enroll)
|
|
|
59dcbd |
+update_keytab_for_principals (adcli_enroll *enroll,
|
|
|
59dcbd |
+ adcli_enroll_flags flags)
|
|
|
59dcbd |
{
|
|
|
59dcbd |
krb5_context k5;
|
|
|
59dcbd |
adcli_result res;
|
|
|
59dcbd |
@@ -1608,7 +1628,7 @@ update_keytab_for_principals (adcli_enroll *enroll)
|
|
|
59dcbd |
if (krb5_unparse_name (k5, enroll->keytab_principals[i], &name) != 0)
|
|
|
59dcbd |
name = "";
|
|
|
59dcbd |
res = add_principal_to_keytab (enroll, k5, enroll->keytab_principals[i],
|
|
|
59dcbd |
- name, &which_salt);
|
|
|
59dcbd |
+ name, &which_salt, flags);
|
|
|
59dcbd |
krb5_free_unparsed_name (k5, name);
|
|
|
59dcbd |
|
|
|
59dcbd |
if (res != ADCLI_SUCCESS)
|
|
|
59dcbd |
@@ -1807,6 +1827,20 @@ enroll_join_or_update_tasks (adcli_enroll *enroll,
|
|
|
59dcbd |
/* We ignore failures of setting these fields */
|
|
|
59dcbd |
update_and_calculate_enctypes (enroll);
|
|
|
59dcbd |
update_computer_account (enroll);
|
|
|
59dcbd |
+
|
|
|
59dcbd |
+ /* service_names is only set from input on the command line, so no
|
|
|
59dcbd |
+ * additional check for explicit is needed here */
|
|
|
59dcbd |
+ if (enroll->service_names != NULL) {
|
|
|
59dcbd |
+ res = add_service_names_to_service_principals (enroll);
|
|
|
59dcbd |
+ if (res != ADCLI_SUCCESS) {
|
|
|
59dcbd |
+ return res;
|
|
|
59dcbd |
+ }
|
|
|
59dcbd |
+ res = ensure_keytab_principals (res, enroll);
|
|
|
59dcbd |
+ if (res != ADCLI_SUCCESS) {
|
|
|
59dcbd |
+ return res;
|
|
|
59dcbd |
+ }
|
|
|
59dcbd |
+ }
|
|
|
59dcbd |
+
|
|
|
59dcbd |
update_service_principals (enroll);
|
|
|
59dcbd |
|
|
|
59dcbd |
if ( (flags & ADCLI_ENROLL_ADD_SAMBA_DATA) && ! (flags & ADCLI_ENROLL_PASSWORD_VALID)) {
|
|
|
59dcbd |
@@ -1826,7 +1860,7 @@ enroll_join_or_update_tasks (adcli_enroll *enroll,
|
|
|
59dcbd |
* that we use for salting.
|
|
|
59dcbd |
*/
|
|
|
59dcbd |
|
|
|
59dcbd |
- return update_keytab_for_principals (enroll);
|
|
|
59dcbd |
+ return update_keytab_for_principals (enroll, flags);
|
|
|
59dcbd |
}
|
|
|
59dcbd |
|
|
|
59dcbd |
adcli_result
|
|
|
59dcbd |
@@ -1927,7 +1961,11 @@ adcli_enroll_update (adcli_enroll *enroll,
|
|
|
59dcbd |
|
|
|
59dcbd |
if (_adcli_check_nt_time_string_lifetime (value,
|
|
|
59dcbd |
adcli_enroll_get_computer_password_lifetime (enroll))) {
|
|
|
59dcbd |
- flags |= ADCLI_ENROLL_NO_KEYTAB;
|
|
|
59dcbd |
+ /* Do not update keytab if neither new service principals have
|
|
|
59dcbd |
+ * to be added nor the user principal has to be changed. */
|
|
|
59dcbd |
+ if (enroll->service_names == NULL && (enroll->user_principal == NULL || enroll->user_princpal_generate)) {
|
|
|
59dcbd |
+ flags |= ADCLI_ENROLL_NO_KEYTAB;
|
|
|
59dcbd |
+ }
|
|
|
59dcbd |
flags |= ADCLI_ENROLL_PASSWORD_VALID;
|
|
|
59dcbd |
}
|
|
|
59dcbd |
free (value);
|
|
|
59dcbd |
diff --git a/library/adkrb5.c b/library/adkrb5.c
|
|
|
59dcbd |
index b0e903e..033c181 100644
|
|
|
59dcbd |
--- a/library/adkrb5.c
|
|
|
59dcbd |
+++ b/library/adkrb5.c
|
|
|
59dcbd |
@@ -204,6 +204,119 @@ _adcli_krb5_open_keytab (krb5_context k5,
|
|
|
59dcbd |
return ADCLI_SUCCESS;
|
|
|
59dcbd |
}
|
|
|
59dcbd |
|
|
|
59dcbd |
+typedef struct {
|
|
|
59dcbd |
+ krb5_kvno kvno;
|
|
|
59dcbd |
+ krb5_enctype enctype;
|
|
|
59dcbd |
+ int matched;
|
|
|
59dcbd |
+} match_enctype_kvno;
|
|
|
59dcbd |
+
|
|
|
59dcbd |
+static krb5_boolean
|
|
|
59dcbd |
+match_enctype_and_kvno (krb5_context k5,
|
|
|
59dcbd |
+ krb5_keytab_entry *entry,
|
|
|
59dcbd |
+ void *data)
|
|
|
59dcbd |
+{
|
|
|
59dcbd |
+ krb5_boolean similar = FALSE;
|
|
|
59dcbd |
+ match_enctype_kvno *closure = data;
|
|
|
59dcbd |
+ krb5_error_code code;
|
|
|
59dcbd |
+
|
|
|
59dcbd |
+ assert (closure->enctype);
|
|
|
59dcbd |
+
|
|
|
59dcbd |
+ code = krb5_c_enctype_compare (k5, closure->enctype, entry->key.enctype,
|
|
|
59dcbd |
+ &similar);
|
|
|
59dcbd |
+
|
|
|
59dcbd |
+ if (code == 0 && entry->vno == closure->kvno && similar) {
|
|
|
59dcbd |
+ closure->matched = 1;
|
|
|
59dcbd |
+ return 1;
|
|
|
59dcbd |
+ }
|
|
|
59dcbd |
+
|
|
|
59dcbd |
+ return 0;
|
|
|
59dcbd |
+}
|
|
|
59dcbd |
+
|
|
|
59dcbd |
+static krb5_error_code
|
|
|
59dcbd |
+_adcli_krb5_get_keyblock (krb5_context k5,
|
|
|
59dcbd |
+ krb5_keytab keytab,
|
|
|
59dcbd |
+ krb5_keyblock *keyblock,
|
|
|
59dcbd |
+ krb5_boolean (* match_func) (krb5_context,
|
|
|
59dcbd |
+ krb5_keytab_entry *,
|
|
|
59dcbd |
+ void *),
|
|
|
59dcbd |
+ void *match_data)
|
|
|
59dcbd |
+{
|
|
|
59dcbd |
+ krb5_kt_cursor cursor;
|
|
|
59dcbd |
+ krb5_keytab_entry entry;
|
|
|
59dcbd |
+ krb5_error_code code;
|
|
|
59dcbd |
+
|
|
|
59dcbd |
+ code = krb5_kt_start_seq_get (k5, keytab, &cursor);
|
|
|
59dcbd |
+ if (code == KRB5_KT_END || code == ENOENT)
|
|
|
59dcbd |
+ return 0;
|
|
|
59dcbd |
+ else if (code != 0)
|
|
|
59dcbd |
+ return code;
|
|
|
59dcbd |
+
|
|
|
59dcbd |
+ for (;;) {
|
|
|
59dcbd |
+ code = krb5_kt_next_entry (k5, keytab, &entry, &cursor);
|
|
|
59dcbd |
+ if (code != 0)
|
|
|
59dcbd |
+ break;
|
|
|
59dcbd |
+
|
|
|
59dcbd |
+ /* See if we should remove this entry */
|
|
|
59dcbd |
+ if (!match_func (k5, &entry, match_data)) {
|
|
|
59dcbd |
+ krb5_free_keytab_entry_contents (k5, &entry);
|
|
|
59dcbd |
+ continue;
|
|
|
59dcbd |
+ }
|
|
|
59dcbd |
+
|
|
|
59dcbd |
+ code = krb5_copy_keyblock_contents (k5, &entry.key, keyblock);
|
|
|
59dcbd |
+ krb5_free_keytab_entry_contents (k5, &entry);
|
|
|
59dcbd |
+ break;
|
|
|
59dcbd |
+
|
|
|
59dcbd |
+
|
|
|
59dcbd |
+ }
|
|
|
59dcbd |
+
|
|
|
59dcbd |
+ if (code == KRB5_KT_END)
|
|
|
59dcbd |
+ code = 0;
|
|
|
59dcbd |
+
|
|
|
59dcbd |
+ krb5_kt_end_seq_get (k5, keytab, &cursor);
|
|
|
59dcbd |
+ return code;
|
|
|
59dcbd |
+}
|
|
|
59dcbd |
+
|
|
|
59dcbd |
+krb5_error_code
|
|
|
59dcbd |
+_adcli_krb5_keytab_copy_entries (krb5_context k5,
|
|
|
59dcbd |
+ krb5_keytab keytab,
|
|
|
59dcbd |
+ krb5_principal principal,
|
|
|
59dcbd |
+ krb5_kvno kvno,
|
|
|
59dcbd |
+ krb5_enctype *enctypes)
|
|
|
59dcbd |
+{
|
|
|
59dcbd |
+ krb5_keytab_entry entry;
|
|
|
59dcbd |
+ krb5_error_code code;
|
|
|
59dcbd |
+ int i;
|
|
|
59dcbd |
+ match_enctype_kvno closure;
|
|
|
59dcbd |
+
|
|
|
59dcbd |
+ for (i = 0; enctypes[i] != 0; i++) {
|
|
|
59dcbd |
+
|
|
|
59dcbd |
+ closure.kvno = kvno;
|
|
|
59dcbd |
+ closure.enctype = enctypes[i];
|
|
|
59dcbd |
+ closure.matched = 0;
|
|
|
59dcbd |
+
|
|
|
59dcbd |
+ memset (&entry, 0, sizeof (entry));
|
|
|
59dcbd |
+
|
|
|
59dcbd |
+ code = _adcli_krb5_get_keyblock (k5, keytab, &entry.key,
|
|
|
59dcbd |
+ match_enctype_and_kvno, &closure);
|
|
|
59dcbd |
+ if (code != 0) {
|
|
|
59dcbd |
+ return code;
|
|
|
59dcbd |
+ }
|
|
|
59dcbd |
+
|
|
|
59dcbd |
+
|
|
|
59dcbd |
+ entry.principal = principal;
|
|
|
59dcbd |
+ entry.vno = kvno;
|
|
|
59dcbd |
+
|
|
|
59dcbd |
+ code = krb5_kt_add_entry (k5, keytab, &entry);
|
|
|
59dcbd |
+
|
|
|
59dcbd |
+ entry.principal = NULL;
|
|
|
59dcbd |
+ krb5_free_keytab_entry_contents (k5, &entry);
|
|
|
59dcbd |
+
|
|
|
59dcbd |
+ if (code != 0)
|
|
|
59dcbd |
+ return code;
|
|
|
59dcbd |
+ }
|
|
|
59dcbd |
+
|
|
|
59dcbd |
+ return 0;
|
|
|
59dcbd |
+}
|
|
|
59dcbd |
|
|
|
59dcbd |
krb5_error_code
|
|
|
59dcbd |
_adcli_krb5_keytab_add_entries (krb5_context k5,
|
|
|
59dcbd |
diff --git a/library/adprivate.h b/library/adprivate.h
|
|
|
59dcbd |
index 83a88f6..7485249 100644
|
|
|
59dcbd |
--- a/library/adprivate.h
|
|
|
59dcbd |
+++ b/library/adprivate.h
|
|
|
59dcbd |
@@ -282,6 +282,12 @@ krb5_enctype * _adcli_krb5_parse_enctypes (const char *value);
|
|
|
59dcbd |
|
|
|
59dcbd |
char * _adcli_krb5_format_enctypes (krb5_enctype *enctypes);
|
|
|
59dcbd |
|
|
|
59dcbd |
+krb5_error_code _adcli_krb5_keytab_copy_entries (krb5_context k5,
|
|
|
59dcbd |
+ krb5_keytab keytab,
|
|
|
59dcbd |
+ krb5_principal principal,
|
|
|
59dcbd |
+ krb5_kvno kvno,
|
|
|
59dcbd |
+ krb5_enctype *enctypes);
|
|
|
59dcbd |
+
|
|
|
59dcbd |
struct _adcli_attrs {
|
|
|
59dcbd |
LDAPMod **mods;
|
|
|
59dcbd |
int len;
|
|
|
59dcbd |
--
|
|
|
59dcbd |
2.14.4
|
|
|
59dcbd |
|