1 /* $FreeBSD: src/crypto/kerberosIV/appl/sample/sample_server.c,v 1.1.1.2.2.1 2000/07/20 14:04:34 assar Exp $ */
5 * Copyright 1987, 1988 by the Massachusetts Institute of Technology.
7 * For copying and distribution information,
8 * please see the file <mit-copyright.h>.
11 * A sample Kerberos server, which reads a ticket from a TCP socket,
12 * decodes it, and writes back the results (in ASCII) to the client.
17 * file descriptor 0 (zero) should be a socket connected to the requesting
18 * client (this will be correct if this server is started by inetd).
23 RCSID("$Id: sample_server.c,v 1.14.2.1 2000/06/28 19:08:00 assar Exp $");
28 fprintf (stderr, "Usage: %s [-i] [-s service] [-t srvtab]\n",
34 main(int argc, char **argv)
36 struct sockaddr_in peername, myname;
37 int namelen = sizeof(peername);
38 int status, count, len;
42 des_key_schedule sched;
43 char instance[INST_SZ];
44 char service[ANAME_SZ];
45 char version[KRB_SENDAUTH_VLEN+1];
48 char srvtab[MaxPathLen];
52 /* open a log connection */
54 set_progname (argv[0]);
56 roken_openlog(__progname, LOG_ODELAY, LOG_DAEMON);
58 strlcpy (service, SAMPLE_SERVICE, sizeof(service));
61 while ((c = getopt (argc, argv, "s:t:i")) != -1)
64 strlcpy (service, optarg, sizeof(service));
67 strlcpy (srvtab, optarg, sizeof(srvtab));
78 mini_inetd (htons(SAMPLE_PORT));
81 * To verify authenticity, we need to know the address of the
84 if (getpeername(STDIN_FILENO,
85 (struct sockaddr *)&peername,
87 syslog(LOG_ERR, "getpeername: %m");
91 /* for mutual authentication, we need to know our address */
92 namelen = sizeof(myname);
93 if (getsockname(STDIN_FILENO, (struct sockaddr *)&myname, &namelen) < 0) {
94 syslog(LOG_ERR, "getsocknamename: %m");
98 /* read the authenticator and decode it. Using `k_getsockinst' we
99 * always get the right instance on a multi-homed host.
101 k_getsockinst (STDIN_FILENO, instance, sizeof(instance));
103 /* we want mutual authentication */
104 authopts = KOPT_DO_MUTUAL;
105 status = krb_recvauth(authopts, STDIN_FILENO, &clt_ticket,
106 service, instance, &peername, &myname,
109 if (status != KSUCCESS) {
110 snprintf(retbuf, sizeof(retbuf),
111 "Kerberos error: %s\n",
112 krb_get_err_text(status));
113 syslog(LOG_ERR, "%s", retbuf);
115 /* Check the version string (KRB_SENDAUTH_VLEN chars) */
116 if (strncmp(version, SAMPLE_VERSION, KRB_SENDAUTH_VLEN)) {
117 /* didn't match the expected version */
118 /* could do something different, but we just log an error
120 version[8] = '\0'; /* make sure null term */
121 syslog(LOG_ERR, "Version mismatch: '%s' isn't '%s'",
122 version, SAMPLE_VERSION);
124 /* now that we have decoded the authenticator, translate
125 the kerberos principal.instance@realm into a local name */
126 if (krb_kntoln(&auth_data, lname) != KSUCCESS)
128 "*No local name returned by krb_kntoln*",
130 /* compose the reply */
131 snprintf(retbuf, sizeof(retbuf),
132 "You are %s.%s@%s (local name %s),\n at address %s, version %s, cksum %ld\n",
137 inet_ntoa(peername.sin_addr),
139 (long)auth_data.checksum);
142 /* write back the response */
143 if ((count = write(0, retbuf, (len = strlen(retbuf) + 1))) < 0) {
144 syslog(LOG_ERR,"write: %m");
146 } else if (count != len) {
147 syslog(LOG_ERR, "write count incorrect: %d != %d\n",
152 /* close up and exit */