Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
20 changes: 10 additions & 10 deletions Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

4 changes: 2 additions & 2 deletions Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -115,7 +115,7 @@ rand = "0.10"
rand_core = "0.10"
getrandom = "0.3"
cfg-if = "1"
picky = { version = "=7.0.0-rc.26", default-features = false }
picky = { version = "=7.0.0-rc.27", default-features = false }
sha1 = { version = "0.11", default-features = false }
sha2 = "0.11"
num-derive = "0.5"
Expand Down Expand Up @@ -180,7 +180,7 @@ pkcs1 = "=0.8.0-rc.4"
base64 = "0.23"
static_assertions = "1"
whoami = "2.1"
picky = { version = "=7.0.0-rc.26", default-features = false, features = ["x509"] }
picky = { version = "=7.0.0-rc.27", default-features = false, features = ["x509"] }
tracing-subscriber = { version = "0.3", features = ["env-filter"] }
proptest = "1.6"
cfg-if = "1"
Expand Down
4 changes: 2 additions & 2 deletions crates/dpapi-web/src/lib.rs
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@ use std::rc::Rc;

use anyhow::Context;
use dpapi::{CryptProtectSecretArgs, CryptUnprotectSecretArgs};
use sspi::KerberosConfig;
use sspi::{KdcResolution, KerberosConfig};
use url::Url;
use wasm_bindgen::prelude::*;

Expand Down Expand Up @@ -169,7 +169,7 @@ impl DpapiConfig {
let kerberos_config = Url::parse(kdc_proxy_url.unwrap_or_default().as_str())
.ok()
.map(|url| KerberosConfig {
kdc_url: Some(url),
kdc_resolution: KdcResolution::KdcUrl(Some(url)),
client_computer_name: computer_name.clone(),
});

Expand Down
2 changes: 1 addition & 1 deletion crates/winscard/Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,7 @@ name = "winscard"
bitflags = "2.11"
iso7816 = "0.1"
iso7816-tlv = "0.4"
picky = { version = "=7.0.0-rc.26", default-features = false, features = ["x509"] }
picky = { version = "=7.0.0-rc.27", default-features = false, features = ["x509"] }
picky-asn1-x509 = "0.15"
tracing = { version = "0.1", default-features = false, features = ["attributes"] }
time = { version = "0.3", default-features = false, features = [
Expand Down
2 changes: 1 addition & 1 deletion examples/kerberos.rs
Original file line number Diff line number Diff line change
Expand Up @@ -26,7 +26,7 @@ fn main() -> Result<(), Box<dyn Error + Send + Sync>> {
.with(EnvFilter::from_env("SSPI_LOG_LEVEL"))
.init();

let kerberos_config = KerberosConfig::new(&kdc_url, hostname.clone());
let kerberos_config = KerberosConfig::new_with_kdc_url(&kdc_url, hostname.clone());
let mut kerberos = Kerberos::new_client_from_config(kerberos_config).unwrap();

let mut acq_creds_handle_result = get_cred_handle(&mut kerberos, username, password);
Expand Down
2 changes: 1 addition & 1 deletion ffi/Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -29,7 +29,7 @@ sha1 = { version = "0.11", default-features = false }
sha2 = "0.11"
ffi-types = { workspace = true, features = ["sspi"] }

picky = { version = "=7.0.0-rc.26", default-features = false, features = ["x509"], optional = true }
picky = { version = "=7.0.0-rc.27", default-features = false, features = ["x509"], optional = true }
picky-asn1-der = "0.5"
picky-asn1 = { version = "0.10", optional = true }
picky-asn1-x509 = { version = "0.15", optional = true }
Expand Down
14 changes: 7 additions & 7 deletions ffi/src/sspi/sec_handle.rs
Original file line number Diff line number Diff line change
Expand Up @@ -20,8 +20,8 @@ use sspi::kerberos::config::KerberosConfig;
use sspi::ntlm::NtlmConfig;
use sspi::{
CertContext, ClientRequestFlags, ConnectionInfo, Credentials, CredentialsBuffers, DataRepresentation, Error,
ErrorKind, Kerberos, Negotiate, NegotiateConfig, Ntlm, PackageInfo, Result, Secret, Sspi, SspiImpl, StreamSizes,
U16CString, Utf16String, Utf16StringExt, kerberos, negotiate, ntlm, pku2u,
ErrorKind, KdcResolution, Kerberos, Negotiate, NegotiateConfig, Ntlm, PackageInfo, Result, Secret, Sspi, SspiImpl,
StreamSizes, U16CString, Utf16String, Utf16StringExt, kerberos, negotiate, ntlm, pku2u,
};
#[cfg(target_os = "windows")]
use windows::Win32::Security::Cryptography::{
Expand Down Expand Up @@ -438,7 +438,7 @@ fn create_negotiate_context(attributes: &CredentialsAttributes) -> Result<Negoti
let client_computer_name = attributes.hostname()?;

let negotiate_config = if let Some(kdc_url) = attributes.kdc_url() {
let kerberos_config = KerberosConfig::new(&kdc_url, client_computer_name.clone());
let kerberos_config = KerberosConfig::new_with_kdc_url(&kdc_url, client_computer_name.clone());

NegotiateConfig::new(
Box::new(kerberos_config),
Expand Down Expand Up @@ -505,14 +505,14 @@ pub(crate) unsafe fn p_ctxt_handle_to_sspi_context(
let client_computer_name = attributes.hostname()?;

if let Some(kdc_url) = attributes.kdc_url() {
SspiContext::Kerberos(Kerberos::new_client_from_config(KerberosConfig::new(
SspiContext::Kerberos(Kerberos::new_client_from_config(KerberosConfig::new_with_kdc_url(
&kdc_url,
client_computer_name,
))?)
} else {
let krb_config = KerberosConfig {
client_computer_name,
kdc_url: None,
kdc_resolution: KdcResolution::KdcUrl(None),
};
SspiContext::Kerberos(Kerberos::new_client_from_config(krb_config)?)
}
Expand Down Expand Up @@ -1775,9 +1775,9 @@ pub unsafe extern "system" fn ChangeAccountPasswordA(
SspiContext::Negotiate(try_execute!(Negotiate::new_client(negotiate_config)))
},
kerberos::PKG_NAME => {
let krb_config = KerberosConfig{
let krb_config = KerberosConfig {
client_computer_name: try_execute!(hostname()),
kdc_url:None
kdc_resolution: KdcResolution::KdcUrl(None),
};
SspiContext::Kerberos(try_execute!(Kerberos::new_client_from_config(
krb_config
Expand Down
9 changes: 9 additions & 0 deletions src/auth_identity.rs
Original file line number Diff line number Diff line change
Expand Up @@ -733,6 +733,15 @@ impl CredentialsBuffers {
_ => None,
}
}

pub fn extract_password(&self) -> Secret<String> {
Secret::new(match self {
CredentialsBuffers::AuthIdentity(auth_identity) => auth_identity.password.as_ref().as_ref().to_string(),
#[cfg(feature = "scard")]
CredentialsBuffers::SmartCard(smart_card) => smart_card.pin.as_ref().as_ref().to_string(),
CredentialsBuffers::Keytab(_keytab) => String::new(),
})
}
}

/// Generic enum that encapsulates credentials for any type of authentication
Expand Down
112 changes: 0 additions & 112 deletions src/kerberos/client/as_exchange.rs

This file was deleted.

11 changes: 9 additions & 2 deletions src/kerberos/client/change_password.rs
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,7 @@ use crate::kerberos::client::generators::{
use crate::kerberos::client::principal::{get_client_principal_name_type, get_client_principal_realm};
use crate::kerberos::pa_datas::AsReqPaDataOptions;
use crate::kerberos::utils::serialize_message;
use crate::kerberos::{CHANGE_PASSWORD_SERVICE_NAME, DEFAULT_ENCRYPTION_TYPE, KADMIN, client};
use crate::kerberos::{CHANGE_PASSWORD_SERVICE_NAME, DEFAULT_ENCRYPTION_TYPE, KADMIN, server};
use crate::utils::generate_random_symmetric_key;
use crate::{ClientRequestFlags, Error, ErrorKind, Kerberos, Result};

Expand All @@ -29,6 +29,13 @@ pub async fn change_password<'a>(
yield_point: &mut YieldPointLocal,
change_password: ChangePassword<'a>,
) -> Result<()> {
if client.is_iakerb() {
return Err(Error::new(
ErrorKind::UnsupportedFunction,
"Changing password is not supported with IAKerb.",
));
}

let username = &change_password.account_name;
let domain = &change_password.domain_name;
let password = &change_password.old_password;
Expand Down Expand Up @@ -59,7 +66,7 @@ pub async fn change_password<'a>(
with_pre_auth: false,
});

let as_rep = client::as_exchange(client, yield_point, &kdc_req_body, pa_data_options).await?;
let as_rep = server::as_exchange::as_exchange(client, yield_point, &kdc_req_body, pa_data_options).await?;

debug!("AS exchange finished successfully.");

Expand Down
6 changes: 6 additions & 0 deletions src/kerberos/client/extractors.rs
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,7 @@ use std::io::Read;
use picky_asn1::wrapper::{Asn1SequenceOf, ObjectIdentifierAsn1};
use picky_asn1_der::Asn1RawDer;
use picky_asn1_der::application_tag::ApplicationTag;
use picky_krb::constants::error_codes::KDC_ERR_PREAUTH_REQUIRED;
use picky_krb::constants::key_usages::{AP_REP_ENC, AS_REP_ENC, KRB_PRIV_ENC_PART, TGS_REP_ENC_SESSION_KEY};
use picky_krb::constants::types::PA_ETYPE_INFO2_TYPE;
use picky_krb::crypto::CipherSuite;
Expand All @@ -23,6 +24,11 @@ use crate::{Error, ErrorKind, Result, Secret};
pub fn extract_salt_from_krb_error(error: &KrbError) -> Result<Option<String>> {
trace!(?error, "KRB_ERROR");

// Check if the error code is KDC_ERR_PREAUTH_REQUIRED. If not, propagate the KDC error.
if error.0.error_code.0 != KDC_ERR_PREAUTH_REQUIRED {
return Err(error.clone().into());
}

if let Some(e_data) = error.0.e_data.0.as_ref() {
let pa_datas: Asn1SequenceOf<PaData> = picky_asn1_der::from_bytes(&e_data.0.0)?;

Expand Down
11 changes: 10 additions & 1 deletion src/kerberos/client/generators.rs
Original file line number Diff line number Diff line change
Expand Up @@ -652,7 +652,7 @@ pub(crate) fn generate_authenticator_at(
sub_key,
checksum,
channel_bindings,
..
extensions,
} = options;

let mut microseconds = current_date.microsecond();
Expand Down Expand Up @@ -689,6 +689,15 @@ pub(crate) fn generate_authenticator_at(
// 4..19 - Channel binding information (19 inclusive).
channel_binding_buf.copy_from_slice(&compute_md5_channel_bindings_hash(channel_bindings)?);
}

for extension in extensions {
// Although RFC 6542 specifies big-endian encoding for the extension type and length,
// Windows implementation uses little-endian encoding.
checksum_value.extend_from_slice(&extension.extension_type.to_le_bytes());
checksum_value.extend_from_slice(&u32::try_from(extension.extension_value.len())?.to_le_bytes());
checksum_value.extend_from_slice(&extension.extension_value);
}

Optional::from(Some(ExplicitContextTag3::from(Checksum {
cksumtype: ExplicitContextTag0::from(IntegerAsn1::from(checksum_type)),
checksum: ExplicitContextTag1::from(OctetStringAsn1::from(checksum_value)),
Expand Down
Loading