Blame SOURCES/cyrus-sasl-2.1.27-Add-support-for-setting-max-ssf-0-to-GSS-SPNEGO.patch

138d55
From 49e965f41257a0ed299c58a7cf1c120ddf944aaa Mon Sep 17 00:00:00 2001
138d55
From: Simo Sorce <simo@redhat.com>
138d55
Date: Tue, 5 May 2020 14:51:36 -0400
138d55
Subject: [PATCH] Add support for setting max ssf 0 to GSS-SPNEGO
138d55
138d55
Bacport form this proposed PR (still open at bacport time):
138d55
https://github.com/cyrusimap/cyrus-sasl/pull/603
138d55
138d55
Signed-off-by: Simo Sorce <simo@redhat.com>
138d55
---
138d55
 m4/sasl2.m4          | 13 +++++++
138d55
 plugins/gssapi.c     | 44 ++++++++++++++++++++-
138d55
 tests/runtests.py    | 91 ++++++++++++++++++++++++++++++++++++++++----
138d55
 tests/t_common.c     | 13 ++++---
138d55
 tests/t_common.h     |  3 +-
138d55
 tests/t_gssapi_cli.c | 25 ++++++++++--
138d55
 tests/t_gssapi_srv.c | 28 +++++++++++---
138d55
 7 files changed, 194 insertions(+), 23 deletions(-)
138d55
138d55
diff --git a/m4/sasl2.m4 b/m4/sasl2.m4
138d55
index 56e0504..6effe99 100644
138d55
--- a/m4/sasl2.m4
138d55
+++ b/m4/sasl2.m4
138d55
@@ -287,6 +287,19 @@ if test "$gssapi" != no; then
138d55
   AC_CHECK_FUNCS(gss_oid_equal)
138d55
   LIBS="$cmu_save_LIBS"
138d55
 
138d55
+  cmu_save_LIBS="$LIBS"
138d55
+  LIBS="$LIBS $GSSAPIBASE_LIBS"
138d55
+  if test "$ac_cv_header_gssapi_gssapi_krb5_h" = "yes"; then
138d55
+    AC_CHECK_DECL(GSS_KRB5_CRED_NO_CI_FLAGS_X,
138d55
+                  [AC_DEFINE(HAVE_GSS_KRB5_CRED_NO_CI_FLAGS_X,1,
138d55
+                             [Define if your GSSAPI implementation supports GSS_KRB5_CRED_NO_CI_FLAGS_X])],,
138d55
+                  [
138d55
+                    AC_INCLUDES_DEFAULT
138d55
+                    #include <gssapi/gssapi_krb5.h>
138d55
+                    ])
138d55
+  fi
138d55
+  LIBS="$cmu_save_LIBS"
138d55
+
138d55
   cmu_save_LIBS="$LIBS"
138d55
   LIBS="$LIBS $GSSAPIBASE_LIBS"
138d55
   AC_CHECK_FUNCS(gss_get_name_attribute)
138d55
diff --git a/plugins/gssapi.c b/plugins/gssapi.c
138d55
index 5d900c5..7480316 100644
138d55
--- a/plugins/gssapi.c
138d55
+++ b/plugins/gssapi.c
138d55
@@ -1783,7 +1783,49 @@ static int gssapi_client_mech_step(void *conn_context,
138d55
 		/* We want to try for privacy */
138d55
 		req_flags |= GSS_C_CONF_FLAG;
138d55
 	    }
138d55
-	}
138d55
+#ifdef HAVE_GSS_KRB5_CRED_NO_CI_FLAGS_X
138d55
+        /* The krb5 mechanism automatically adds INTEG and CONF flags even when
138d55
+         * not specified, this has the effect of rendering explicit requests
138d55
+         * of no confidentiality and integrity via setting maxssf 0 moot.
138d55
+         * However to interoperate with Windows machines it needs to be
138d55
+         * possible to unset these flags as Windows machines refuse to allow
138d55
+         * two layers (say TLS and GSSAPI) to both provide these services.
138d55
+         * So if we do not suppress these flags a SASL/GSS-SPNEGO negotiation
138d55
+         * over, say, LDAPS will fail against Windows Servers */
138d55
+	} else if (params->props.max_ssf == 0) {
138d55
+            gss_buffer_desc empty_buffer = GSS_C_EMPTY_BUFFER;
138d55
+            if (client_creds == GSS_C_NO_CREDENTIAL) {
138d55
+                gss_OID_set_desc mechs = { 0 };
138d55
+                gss_OID_set desired_mechs = GSS_C_NO_OID_SET;
138d55
+                if (text->mech_type != GSS_C_NO_OID) {
138d55
+                    mechs.count = 1;
138d55
+                    mechs.elements = text->mech_type;
138d55
+                    desired_mechs = &mechs;
138d55
+                }
138d55
+
138d55
+                maj_stat = gss_acquire_cred(&min_stat, GSS_C_NO_NAME,
138d55
+                                            GSS_C_INDEFINITE, desired_mechs,
138d55
+                                            GSS_C_INITIATE,
138d55
+                                            &text->client_creds, NULL, NULL);
138d55
+                if (GSS_ERROR(maj_stat)) {
138d55
+                    sasl_gss_seterror(text->utils, maj_stat, min_stat);
138d55
+                    sasl_gss_free_context_contents(text);
138d55
+                    return SASL_FAIL;
138d55
+                }
138d55
+                client_creds = text->client_creds;
138d55
+            }
138d55
+
138d55
+            maj_stat = gss_set_cred_option(&min_stat, &client_creds,
138d55
+                                           (gss_OID)GSS_KRB5_CRED_NO_CI_FLAGS_X,
138d55
+                                            &empty_buffer);
138d55
+            if (GSS_ERROR(maj_stat)) {
138d55
+                sasl_gss_seterror(text->utils, maj_stat, min_stat);
138d55
+                sasl_gss_free_context_contents(text);
138d55
+                return SASL_FAIL;
138d55
+            }
138d55
+#endif
138d55
+        }
138d55
+
138d55
 
138d55
 	if (params->props.security_flags & SASL_SEC_PASS_CREDENTIALS) {
138d55
 	    req_flags = req_flags |  GSS_C_DELEG_FLAG;
138d55
diff --git a/tests/runtests.py b/tests/runtests.py
138d55
index fc9cf24..4106401 100755
138d55
--- a/tests/runtests.py
138d55
+++ b/tests/runtests.py
138d55
@@ -6,6 +6,7 @@ import os
138d55
 import shutil
138d55
 import signal
138d55
 import subprocess
138d55
+import sys
138d55
 import time
138d55
 from string import Template
138d55
 
138d55
@@ -149,11 +150,12 @@ def gssapi_basic_test(kenv):
138d55
                 srv.returncode, srv.stderr.read().decode('utf-8')))
138d55
     except Exception as e:
138d55
         print("FAIL: {}".format(e))
138d55
-        return
138d55
+        return 1
138d55
 
138d55
     print("PASS: CLI({}) SRV({})".format(
138d55
         cli.stdout.read().decode('utf-8').strip(),
138d55
         srv.stdout.read().decode('utf-8').strip()))
138d55
+    return 0
138d55
 
138d55
 def gssapi_channel_binding_test(kenv):
138d55
     try:
138d55
@@ -178,11 +180,12 @@ def gssapi_channel_binding_test(kenv):
138d55
                 srv.returncode, srv.stderr.read().decode('utf-8')))
138d55
     except Exception as e:
138d55
         print("FAIL: {}".format(e))
138d55
-        return
138d55
+        return 1
138d55
 
138d55
     print("PASS: CLI({}) SRV({})".format(
138d55
         cli.stdout.read().decode('utf-8').strip(),
138d55
         srv.stdout.read().decode('utf-8').strip()))
138d55
+    return 0
138d55
 
138d55
 def gssapi_channel_binding_mismatch_test(kenv):
138d55
     result = "FAIL"
138d55
@@ -212,11 +215,70 @@ def gssapi_channel_binding_mismatch_test(kenv):
138d55
                 cli.returncode, cli_err, srv.returncode, srv_err))
138d55
     except Exception as e:
138d55
         print("{}: {}".format(result, e))
138d55
-        return
138d55
+        return 0
138d55
 
138d55
     print("FAIL: This test should fail [CLI({}) SRV({})]".format(
138d55
         cli.stdout.read().decode('utf-8').strip(),
138d55
         srv.stdout.read().decode('utf-8').strip()))
138d55
+    return 1
138d55
+
138d55
+def gss_spnego_basic_test(kenv):
138d55
+    try:
138d55
+        srv = subprocess.Popen(["../tests/t_gssapi_srv", "-N"],
138d55
+                               stdout=subprocess.PIPE,
138d55
+                               stderr=subprocess.PIPE, env=kenv)
138d55
+        srv.stdout.readline() # Wait for srv to say it is ready
138d55
+        cli = subprocess.Popen(["../tests/t_gssapi_cli", "-N"],
138d55
+                               stdout=subprocess.PIPE,
138d55
+                               stderr=subprocess.PIPE, env=kenv)
138d55
+        try:
138d55
+            cli.wait(timeout=5)
138d55
+            srv.wait(timeout=5)
138d55
+        except Exception as e:
138d55
+            print("Failed on {}".format(e));
138d55
+            cli.kill()
138d55
+            srv.kill()
138d55
+        if cli.returncode != 0 or srv.returncode != 0:
138d55
+            raise Exception("CLI ({}): {} --> SRV ({}): {}".format(
138d55
+                cli.returncode, cli.stderr.read().decode('utf-8'),
138d55
+                srv.returncode, srv.stderr.read().decode('utf-8')))
138d55
+    except Exception as e:
138d55
+        print("FAIL: {}".format(e))
138d55
+        return 1
138d55
+
138d55
+    print("PASS: CLI({}) SRV({})".format(
138d55
+        cli.stdout.read().decode('utf-8').strip(),
138d55
+        srv.stdout.read().decode('utf-8').strip()))
138d55
+    return 0
138d55
+
138d55
+def gss_spnego_zeromaxssf_test(kenv):
138d55
+    try:
138d55
+        srv = subprocess.Popen(["../tests/t_gssapi_srv", "-N", "-z"],
138d55
+                               stdout=subprocess.PIPE,
138d55
+                               stderr=subprocess.PIPE, env=kenv)
138d55
+        srv.stdout.readline() # Wait for srv to say it is ready
138d55
+        cli = subprocess.Popen(["../tests/t_gssapi_cli", "-N", "-z"],
138d55
+                               stdout=subprocess.PIPE,
138d55
+                               stderr=subprocess.PIPE, env=kenv)
138d55
+        try:
138d55
+            cli.wait(timeout=5)
138d55
+            srv.wait(timeout=5)
138d55
+        except Exception as e:
138d55
+            print("Failed on {}".format(e));
138d55
+            cli.kill()
138d55
+            srv.kill()
138d55
+        if cli.returncode != 0 or srv.returncode != 0:
138d55
+            raise Exception("CLI ({}): {} --> SRV ({}): {}".format(
138d55
+                cli.returncode, cli.stderr.read().decode('utf-8'),
138d55
+                srv.returncode, srv.stderr.read().decode('utf-8')))
138d55
+    except Exception as e:
138d55
+        print("FAIL: {}".format(e))
138d55
+        return 1
138d55
+
138d55
+    print("PASS: CLI({}) SRV({})".format(
138d55
+        cli.stdout.read().decode('utf-8').strip(),
138d55
+        srv.stdout.read().decode('utf-8').strip()))
138d55
+    return 0
138d55
 
138d55
 def gssapi_tests(testdir):
138d55
     """ SASL/GSSAPI Tests """
138d55
@@ -225,20 +287,32 @@ def gssapi_tests(testdir):
138d55
     #print("KDC: {}, ENV: {}".format(kdc, kenv))
138d55
     kenv['KRB5_TRACE'] = os.path.join(testdir, 'trace.log')
138d55
 
138d55
+    err = 0
138d55
+
138d55
     print('GSSAPI BASIC:')
138d55
     print('    ', end='')
138d55
-    gssapi_basic_test(kenv)
138d55
+    err += gssapi_basic_test(kenv)
138d55
 
138d55
     print('GSSAPI CHANNEL BINDING:')
138d55
     print('    ', end='')
138d55
-    gssapi_channel_binding_test(kenv)
138d55
+    err += gssapi_channel_binding_test(kenv)
138d55
 
138d55
     print('GSSAPI CHANNEL BINDING MISMTACH:')
138d55
     print('    ', end='')
138d55
-    gssapi_channel_binding_mismatch_test(kenv)
138d55
+    err += gssapi_channel_binding_mismatch_test(kenv)
138d55
+
138d55
+    print('GSS-SPNEGO BASIC:')
138d55
+    print('    ', end='')
138d55
+    err += gss_spnego_basic_test(kenv)
138d55
+
138d55
+    print('GSS-SPNEGO 0 MAXSSF:')
138d55
+    print('    ', end='')
138d55
+    err += gss_spnego_zeromaxssf_test(kenv)
138d55
 
138d55
     os.killpg(kdc.pid, signal.SIGTERM)
138d55
 
138d55
+    return err
138d55
+
138d55
 
138d55
 if __name__ == "__main__":
138d55
 
138d55
@@ -253,4 +327,7 @@ if __name__ == "__main__":
138d55
         shutil.rmtree(T)
138d55
     os.makedirs(T)
138d55
 
138d55
-    gssapi_tests(T)
138d55
+    err = gssapi_tests(T)
138d55
+    if err != 0:
138d55
+        print('{} test(s) FAILED'.format(err))
138d55
+        sys.exit(-1)
138d55
diff --git a/tests/t_common.c b/tests/t_common.c
138d55
index 478e6a1..f56098e 100644
138d55
--- a/tests/t_common.c
138d55
+++ b/tests/t_common.c
138d55
@@ -23,20 +23,21 @@ void send_string(int sd, const char *s, unsigned int l)
138d55
     if (ret != l) s_error("send data", ret, l, errno);
138d55
 }
138d55
 
138d55
-void recv_string(int sd, char *buf, unsigned int *buflen)
138d55
+void recv_string(int sd, char *buf, unsigned int *buflen, bool allow_eof)
138d55
 {
138d55
+    unsigned int bufsize = *buflen;
138d55
     unsigned int l;
138d55
     ssize_t ret;
138d55
 
138d55
+    *buflen = 0;
138d55
+
138d55
     ret = recv(sd, &l, sizeof(l), MSG_WAITALL);
138d55
+    if (allow_eof && ret == 0) return;
138d55
     if (ret != sizeof(l)) s_error("recv size", ret, sizeof(l), errno);
138d55
 
138d55
-    if (l == 0) {
138d55
-        *buflen = 0;
138d55
-        return;
138d55
-    }
138d55
+    if (l == 0) return;
138d55
 
138d55
-    if (*buflen < l) s_error("recv len", l, *buflen, E2BIG);
138d55
+    if (bufsize < l) s_error("recv len", l, bufsize, E2BIG);
138d55
 
138d55
     ret = recv(sd, buf, l, 0);
138d55
     if (ret != l) s_error("recv data", ret, l, errno);
138d55
diff --git a/tests/t_common.h b/tests/t_common.h
138d55
index a10def1..be24a53 100644
138d55
--- a/tests/t_common.h
138d55
+++ b/tests/t_common.h
138d55
@@ -4,6 +4,7 @@
138d55
 #include "config.h"
138d55
 
138d55
 #include <errno.h>
138d55
+#include <stdbool.h>
138d55
 #include <stdio.h>
138d55
 #include <sys/socket.h>
138d55
 
138d55
@@ -12,7 +13,7 @@
138d55
 
138d55
 void s_error(const char *hdr, ssize_t ret, ssize_t len, int err);
138d55
 void send_string(int sd, const char *s, unsigned int l);
138d55
-void recv_string(int sd, char *buf, unsigned int *buflen);
138d55
+void recv_string(int sd, char *buf, unsigned int *buflen, bool allow_eof);
138d55
 void saslerr(int why, const char *what);
138d55
 int getpath(void *context __attribute__((unused)), const char **path);
138d55
 void parse_cb(sasl_channel_binding_t *cb, char *buf, unsigned max, char *in);
138d55
diff --git a/tests/t_gssapi_cli.c b/tests/t_gssapi_cli.c
138d55
index a44a3f5..d9eafe1 100644
138d55
--- a/tests/t_gssapi_cli.c
138d55
+++ b/tests/t_gssapi_cli.c
138d55
@@ -46,12 +46,21 @@ int main(int argc, char *argv[])
138d55
     char cb_buf[256];
138d55
     int sd;
138d55
     int c, r;
138d55
+    const char *sasl_mech = "GSSAPI";
138d55
+    bool spnego = false;
138d55
+    bool zeromaxssf = false;
138d55
 
138d55
-    while ((c = getopt(argc, argv, "c:")) != EOF) {
138d55
+    while ((c = getopt(argc, argv, "c:zN")) != EOF) {
138d55
         switch (c) {
138d55
         case 'c':
138d55
             parse_cb(&cb, cb_buf, 256, optarg);
138d55
             break;
138d55
+        case 'z':
138d55
+            zeromaxssf = true;
138d55
+            break;
138d55
+        case 'N':
138d55
+            spnego = true;
138d55
+            break;
138d55
         default:
138d55
             break;
138d55
         }
138d55
@@ -78,7 +87,17 @@ int main(int argc, char *argv[])
138d55
         sasl_setprop(conn, SASL_CHANNEL_BINDING, &cb;;
138d55
     }
138d55
 
138d55
-    r = sasl_client_start(conn, "GSSAPI", NULL, &data, &len, &chosenmech);
138d55
+    if (spnego) {
138d55
+        sasl_mech = "GSS-SPNEGO";
138d55
+    }
138d55
+
138d55
+    if (zeromaxssf) {
138d55
+        /* set all security properties to 0 including maxssf */
138d55
+        sasl_security_properties_t secprops = { 0 };
138d55
+        sasl_setprop(conn, SASL_SEC_PROPS, &secprops);
138d55
+    }
138d55
+
138d55
+    r = sasl_client_start(conn, sasl_mech, NULL, &data, &len, &chosenmech);
138d55
     if (r != SASL_OK && r != SASL_CONTINUE) {
138d55
 	saslerr(r, "starting SASL negotiation");
138d55
 	printf("\n%s\n", sasl_errdetail(conn));
138d55
@@ -90,7 +109,7 @@ int main(int argc, char *argv[])
138d55
     while (r == SASL_CONTINUE) {
138d55
         send_string(sd, data, len);
138d55
         len = 8192;
138d55
-        recv_string(sd, buf, &len;;
138d55
+        recv_string(sd, buf, &len, false);
138d55
 
138d55
 	r = sasl_client_step(conn, buf, len, NULL, &data, &len;;
138d55
 	if (r != SASL_OK && r != SASL_CONTINUE) {
138d55
diff --git a/tests/t_gssapi_srv.c b/tests/t_gssapi_srv.c
138d55
index ef1217f..448a218 100644
138d55
--- a/tests/t_gssapi_srv.c
138d55
+++ b/tests/t_gssapi_srv.c
138d55
@@ -56,12 +56,21 @@ int main(int argc, char *argv[])
138d55
     unsigned char cb_buf[256];
138d55
     int sd;
138d55
     int c, r;
138d55
+    const char *sasl_mech = "GSSAPI";
138d55
+    bool spnego = false;
138d55
+    bool zeromaxssf = false;
138d55
 
138d55
-    while ((c = getopt(argc, argv, "c:")) != EOF) {
138d55
+    while ((c = getopt(argc, argv, "c:zN")) != EOF) {
138d55
         switch (c) {
138d55
         case 'c':
138d55
             parse_cb(&cb, cb_buf, 256, optarg);
138d55
             break;
138d55
+        case 'z':
138d55
+            zeromaxssf = true;
138d55
+            break;
138d55
+        case 'N':
138d55
+            spnego = true;
138d55
+            break;
138d55
         default:
138d55
             break;
138d55
         }
138d55
@@ -90,12 +99,22 @@ int main(int argc, char *argv[])
138d55
         sasl_setprop(conn, SASL_CHANNEL_BINDING, &cb;;
138d55
     }
138d55
 
138d55
+    if (spnego) {
138d55
+        sasl_mech = "GSS-SPNEGO";
138d55
+    }
138d55
+
138d55
+    if (zeromaxssf) {
138d55
+        /* set all security properties to 0 including maxssf */
138d55
+        sasl_security_properties_t secprops = { 0 };
138d55
+        sasl_setprop(conn, SASL_SEC_PROPS, &secprops);
138d55
+    }
138d55
+
138d55
     sd = setup_socket();
138d55
 
138d55
     len = 8192;
138d55
-    recv_string(sd, buf, &len;;
138d55
+    recv_string(sd, buf, &len, false);
138d55
 
138d55
-    r = sasl_server_start(conn, "GSSAPI", buf, len, &data, &len;;
138d55
+    r = sasl_server_start(conn, sasl_mech, buf, len, &data, &len;;
138d55
     if (r != SASL_OK && r != SASL_CONTINUE) {
138d55
 	saslerr(r, "starting SASL negotiation");
138d55
 	printf("\n%s\n", sasl_errdetail(conn));
138d55
@@ -105,7 +124,7 @@ int main(int argc, char *argv[])
138d55
     while (r == SASL_CONTINUE) {
138d55
         send_string(sd, data, len);
138d55
         len = 8192;
138d55
-        recv_string(sd, buf, &len;;
138d55
+        recv_string(sd, buf, &len, true);
138d55
 
138d55
 	r = sasl_server_step(conn, buf, len, &data, &len;;
138d55
 	if (r != SASL_OK && r != SASL_CONTINUE) {
138d55
@@ -113,7 +132,6 @@ int main(int argc, char *argv[])
138d55
 	    printf("\n%s\n", sasl_errdetail(conn));
138d55
 	    exit(-1);
138d55
 	}
138d55
-
138d55
     }
138d55
 
138d55
     if (r != SASL_OK) exit(-1);
138d55
-- 
138d55
2.18.2
138d55