2 * Copyright (C) 2004-2007, 2009, 2010 Internet Systems Consortium, Inc. ("ISC")
3 * Copyright (C) 1999-2001 Internet Software Consortium.
5 * Permission to use, copy, modify, and/or distribute this software for any
6 * purpose with or without fee is hereby granted, provided that the above
7 * copyright notice and this permission notice appear in all copies.
9 * THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
10 * REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
11 * AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
12 * INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
13 * LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
14 * OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
15 * PERFORMANCE OF THIS SOFTWARE.
18 /* $Id: tkeyconf.c,v 1.33 2010-12-20 23:47:20 tbox Exp $ */
24 #include <isc/buffer.h>
25 #include <isc/string.h> /* Required for HP/UX (and others?) */
28 #include <isccfg/cfg.h>
30 #include <dns/fixedname.h>
31 #include <dns/keyvalues.h>
35 #include <dst/gssapi.h>
37 #include <named/tkeyconf.h>
39 #define RETERR(x) do { \
41 if (result != ISC_R_SUCCESS) \
47 isc_log_write(ns_g_lctx, \
48 NS_LOGCATEGORY_GENERAL, \
49 NS_LOGMODULE_SERVER, \
54 ns_tkeyctx_fromconfig(const cfg_obj_t *options, isc_mem_t *mctx,
55 isc_entropy_t *ectx, dns_tkeyctx_t **tctxp)
58 dns_tkeyctx_t *tctx = NULL;
61 dns_fixedname_t fname;
67 result = dns_tkeyctx_create(mctx, ectx, &tctx);
68 if (result != ISC_R_SUCCESS)
72 result = cfg_map_get(options, "tkey-dhkey", &obj);
73 if (result == ISC_R_SUCCESS) {
74 s = cfg_obj_asstring(cfg_tuple_get(obj, "name"));
75 n = cfg_obj_asuint32(cfg_tuple_get(obj, "keyid"));
76 isc_buffer_init(&b, s, strlen(s));
77 isc_buffer_add(&b, strlen(s));
78 dns_fixedname_init(&fname);
79 name = dns_fixedname_name(&fname);
80 RETERR(dns_name_fromtext(name, &b, dns_rootname, 0, NULL));
81 type = DST_TYPE_PUBLIC|DST_TYPE_PRIVATE|DST_TYPE_KEY;
82 RETERR(dst_key_fromfile(name, (dns_keytag_t) n, DNS_KEYALG_DH,
83 type, NULL, mctx, &tctx->dhkey));
87 result = cfg_map_get(options, "tkey-domain", &obj);
88 if (result == ISC_R_SUCCESS) {
89 s = cfg_obj_asstring(obj);
90 isc_buffer_init(&b, s, strlen(s));
91 isc_buffer_add(&b, strlen(s));
92 dns_fixedname_init(&fname);
93 name = dns_fixedname_name(&fname);
94 RETERR(dns_name_fromtext(name, &b, dns_rootname, 0, NULL));
95 tctx->domain = isc_mem_get(mctx, sizeof(dns_name_t));
96 if (tctx->domain == NULL) {
97 result = ISC_R_NOMEMORY;
100 dns_name_init(tctx->domain, NULL);
101 RETERR(dns_name_dup(name, mctx, tctx->domain));
105 result = cfg_map_get(options, "tkey-gssapi-credential", &obj);
106 if (result == ISC_R_SUCCESS) {
107 s = cfg_obj_asstring(obj);
109 isc_buffer_init(&b, s, strlen(s));
110 isc_buffer_add(&b, strlen(s));
111 dns_fixedname_init(&fname);
112 name = dns_fixedname_name(&fname);
113 RETERR(dns_name_fromtext(name, &b, dns_rootname, 0, NULL));
114 RETERR(dst_gssapi_acquirecred(name, ISC_FALSE, &tctx->gsscred));
118 result = cfg_map_get(options, "tkey-gssapi-keytab", &obj);
119 if (result == ISC_R_SUCCESS) {
120 s = cfg_obj_asstring(obj);
121 tctx->gssapi_keytab = isc_mem_strdup(mctx, s);
122 if (tctx->gssapi_keytab == NULL) {
123 result = ISC_R_NOMEMORY;
130 return (ISC_R_SUCCESS);
133 dns_tkeyctx_destroy(&tctx);