6815182: GSSAPI/SPNEGO does not work with server using MIT Kerberos library
Reviewed-by: valeriep
This commit is contained in:
parent
2f06b83dfc
commit
78ae650f8f
@ -1,5 +1,5 @@
|
|||||||
/*
|
/*
|
||||||
* Copyright 2005-2006 Sun Microsystems, Inc. All Rights Reserved.
|
* Copyright 2005-2009 Sun Microsystems, Inc. All Rights Reserved.
|
||||||
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
|
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
|
||||||
*
|
*
|
||||||
* This code is free software; you can redistribute it and/or modify it
|
* This code is free software; you can redistribute it and/or modify it
|
||||||
@ -66,11 +66,11 @@ public class NegTokenInit extends SpNegoToken {
|
|||||||
private byte[] mechTypes = null;
|
private byte[] mechTypes = null;
|
||||||
private Oid[] mechTypeList = null;
|
private Oid[] mechTypeList = null;
|
||||||
|
|
||||||
private byte[] reqFlags = null;
|
private BitArray reqFlags = null;
|
||||||
private byte[] mechToken = null;
|
private byte[] mechToken = null;
|
||||||
private byte[] mechListMIC = null;
|
private byte[] mechListMIC = null;
|
||||||
|
|
||||||
NegTokenInit(byte[] mechTypes, byte[] flags,
|
NegTokenInit(byte[] mechTypes, BitArray flags,
|
||||||
byte[] token, byte[] mechListMIC)
|
byte[] token, byte[] mechListMIC)
|
||||||
{
|
{
|
||||||
super(NEG_TOKEN_INIT_ID);
|
super(NEG_TOKEN_INIT_ID);
|
||||||
@ -101,7 +101,7 @@ public class NegTokenInit extends SpNegoToken {
|
|||||||
// write context flags with CONTEXT 01
|
// write context flags with CONTEXT 01
|
||||||
if (reqFlags != null) {
|
if (reqFlags != null) {
|
||||||
DerOutputStream flags = new DerOutputStream();
|
DerOutputStream flags = new DerOutputStream();
|
||||||
flags.putBitString(reqFlags);
|
flags.putUnalignedBitString(reqFlags);
|
||||||
initToken.write(DerValue.createTag(DerValue.TAG_CONTEXT,
|
initToken.write(DerValue.createTag(DerValue.TAG_CONTEXT,
|
||||||
true, (byte) 0x01), flags);
|
true, (byte) 0x01), flags);
|
||||||
}
|
}
|
||||||
@ -237,7 +237,7 @@ public class NegTokenInit extends SpNegoToken {
|
|||||||
return mechTypeList;
|
return mechTypeList;
|
||||||
}
|
}
|
||||||
|
|
||||||
byte[] getReqFlags() {
|
BitArray getReqFlags() {
|
||||||
return reqFlags;
|
return reqFlags;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
@ -1,5 +1,5 @@
|
|||||||
/*
|
/*
|
||||||
* Copyright 2005-2008 Sun Microsystems, Inc. All Rights Reserved.
|
* Copyright 2005-2009 Sun Microsystems, Inc. All Rights Reserved.
|
||||||
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
|
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
|
||||||
*
|
*
|
||||||
* This code is free software; you can redistribute it and/or modify it
|
* This code is free software; you can redistribute it and/or modify it
|
||||||
@ -53,13 +53,6 @@ public class SpNegoContext implements GSSContextSpi {
|
|||||||
|
|
||||||
private int state = STATE_NEW;
|
private int state = STATE_NEW;
|
||||||
|
|
||||||
private static final int CHECKSUM_DELEG_FLAG = 1;
|
|
||||||
private static final int CHECKSUM_MUTUAL_FLAG = 2;
|
|
||||||
private static final int CHECKSUM_REPLAY_FLAG = 4;
|
|
||||||
private static final int CHECKSUM_SEQUENCE_FLAG = 8;
|
|
||||||
private static final int CHECKSUM_CONF_FLAG = 16;
|
|
||||||
private static final int CHECKSUM_INTEG_FLAG = 32;
|
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* Optional features that the application can set and their default
|
* Optional features that the application can set and their default
|
||||||
* values.
|
* values.
|
||||||
@ -697,25 +690,17 @@ public class SpNegoContext implements GSSContextSpi {
|
|||||||
/**
|
/**
|
||||||
* get the context flags
|
* get the context flags
|
||||||
*/
|
*/
|
||||||
private byte[] getContextFlags() {
|
private BitArray getContextFlags() {
|
||||||
int flags = 0;
|
BitArray out = new BitArray(7);
|
||||||
|
|
||||||
if (getCredDelegState())
|
if (getCredDelegState()) out.set(0, true);
|
||||||
flags |= CHECKSUM_DELEG_FLAG;
|
if (getMutualAuthState()) out.set(1, true);
|
||||||
if (getMutualAuthState())
|
if (getReplayDetState()) out.set(2, true);
|
||||||
flags |= CHECKSUM_MUTUAL_FLAG;
|
if (getSequenceDetState()) out.set(3, true);
|
||||||
if (getReplayDetState())
|
if (getConfState()) out.set(5, true);
|
||||||
flags |= CHECKSUM_REPLAY_FLAG;
|
if (getIntegState()) out.set(6, true);
|
||||||
if (getSequenceDetState())
|
|
||||||
flags |= CHECKSUM_SEQUENCE_FLAG;
|
|
||||||
if (getIntegState())
|
|
||||||
flags |= CHECKSUM_INTEG_FLAG;
|
|
||||||
if (getConfState())
|
|
||||||
flags |= CHECKSUM_CONF_FLAG;
|
|
||||||
|
|
||||||
byte[] temp = new byte[1];
|
return out;
|
||||||
temp[0] = (byte)(flags & 0xff);
|
|
||||||
return temp;
|
|
||||||
}
|
}
|
||||||
|
|
||||||
private void setContextFlags() {
|
private void setContextFlags() {
|
||||||
|
92
jdk/test/sun/security/krb5/auto/SpnegoReqFlags.java
Normal file
92
jdk/test/sun/security/krb5/auto/SpnegoReqFlags.java
Normal file
@ -0,0 +1,92 @@
|
|||||||
|
/*
|
||||||
|
* Copyright 2009 Sun Microsystems, Inc. All Rights Reserved.
|
||||||
|
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
|
||||||
|
*
|
||||||
|
* This code is free software; you can redistribute it and/or modify it
|
||||||
|
* under the terms of the GNU General Public License version 2 only, as
|
||||||
|
* published by the Free Software Foundation.
|
||||||
|
*
|
||||||
|
* This code is distributed in the hope that it will be useful, but WITHOUT
|
||||||
|
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
|
||||||
|
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||||
|
* version 2 for more details (a copy is included in the LICENSE file that
|
||||||
|
* accompanied this code).
|
||||||
|
*
|
||||||
|
* You should have received a copy of the GNU General Public License version
|
||||||
|
* 2 along with this work; if not, write to the Free Software Foundation,
|
||||||
|
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
|
||||||
|
*
|
||||||
|
* Please contact Sun Microsystems, Inc., 4150 Network Circle, Santa Clara,
|
||||||
|
* CA 95054 USA or visit www.sun.com if you need additional information or
|
||||||
|
* have any questions.
|
||||||
|
*/
|
||||||
|
|
||||||
|
/*
|
||||||
|
* @test
|
||||||
|
* @bug 6815182
|
||||||
|
* @summary GSSAPI/SPNEGO does not work with server using MIT Kerberos library
|
||||||
|
*/
|
||||||
|
|
||||||
|
import sun.security.jgss.GSSUtil;
|
||||||
|
import sun.security.util.BitArray;
|
||||||
|
import sun.security.util.DerInputStream;
|
||||||
|
import sun.security.util.DerValue;
|
||||||
|
|
||||||
|
public class SpnegoReqFlags {
|
||||||
|
|
||||||
|
public static void main(String[] args)
|
||||||
|
throws Exception {
|
||||||
|
|
||||||
|
// Create and start the KDC
|
||||||
|
new OneKDC(null).writeJAASConf();
|
||||||
|
new SpnegoReqFlags().go();
|
||||||
|
}
|
||||||
|
|
||||||
|
void go() throws Exception {
|
||||||
|
Context c = Context.fromJAAS("client");
|
||||||
|
c.startAsClient(OneKDC.SERVER, GSSUtil.GSS_SPNEGO_MECH_OID);
|
||||||
|
|
||||||
|
byte[] token = c.doAs(new Action() {
|
||||||
|
@Override
|
||||||
|
public byte[] run(Context me, byte[] input) throws Exception {
|
||||||
|
me.x().requestCredDeleg(true);
|
||||||
|
me.x().requestReplayDet(false);
|
||||||
|
me.x().requestSequenceDet(false);
|
||||||
|
return me.x().initSecContext(new byte[0], 0, 0);
|
||||||
|
}
|
||||||
|
}, null);
|
||||||
|
|
||||||
|
DerValue d = new DerValue(token); // GSSToken
|
||||||
|
DerInputStream ins = d.data; // OID + mech token
|
||||||
|
d.data.getDerValue(); // skip OID
|
||||||
|
d = d.data.getDerValue(); // NegTokenInit
|
||||||
|
d = d.data.getDerValue(); // The SEQUENCE inside
|
||||||
|
|
||||||
|
boolean found = false;
|
||||||
|
|
||||||
|
// Go through all fields inside NegTokenInit. The reqFlags field
|
||||||
|
// is optional. It's even not recommended in RFC 4178.
|
||||||
|
while (d.data.available() > 0) {
|
||||||
|
DerValue d2 = d.data.getDerValue();
|
||||||
|
if (d2.isContextSpecific((byte)1)) {
|
||||||
|
found = true;
|
||||||
|
System.out.println("regFlags field located.");
|
||||||
|
BitArray ba = d2.data.getUnalignedBitString();
|
||||||
|
if (ba.length() != 7) {
|
||||||
|
throw new Exception("reqFlags should contain 7 bits");
|
||||||
|
}
|
||||||
|
if (!ba.get(0)) {
|
||||||
|
throw new Exception("delegFlag should be true");
|
||||||
|
}
|
||||||
|
if (ba.get(2) || ba.get(3)) {
|
||||||
|
throw new Exception("replay/sequenceFlag should be false");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!found) {
|
||||||
|
System.out.println("Warning: regFlags field not found, too new?");
|
||||||
|
}
|
||||||
|
c.dispose();
|
||||||
|
}
|
||||||
|
}
|
Loading…
x
Reference in New Issue
Block a user