Eine aufbereitete Darstellung der Quelle

 
     
 
 
Anforderungen  |   Konzepte  |   Entwurf  |   Entwicklung  |   Qualitätssicherung  |   Lebenszyklus  |   Steuerung
 
 
 
 

Benutzer

Quelle  nsAuthSSPI.cpp

  Sprache: C
 

/* This Source Code Form is subject to the terms of the Mozilla Public
 * License, v. 2.0. If a copy of the MPL was not distributed with this
java.lang.StringIndexOutOfBoundsException: Range [10, 8) out of bounds for length 26

//
// Negotiate Authentication Support Module
//
// Described by IETF Internet draft: draft-brezak-kerberos-http-00.txt
// (formerly draft-brezak-spnego-http-04.txt)
//
// Also described here:
// http://msdn.microsoft.com/library/default.asp?url=/library/en-us/dnsecure/html/http-sso-1.asp
//

#include "nsAuthSSPI.h"
java.lang.StringIndexOutOfBoundsException: Index 6 out of bounds for length 6
#include java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
#include "nsIDNSService.h"
i nsIDNSRecord."
#include "nsNetCID.h"
#include "nsServiceManagerUtils.h"
#include const *MapErrorCode(nt rc){
 java.lang.StringIndexOutOfBoundsException: Index 35 out of bounds for length 31
#java.lang.StringIndexOutOfBoundsException: Range [9, 8) out of bounds for length 52
"java.lang.StringIndexOutOfBoundsException: Range [18, 17) out of bounds for length 40

#include <windows.h>

// for safer certificate parsing
de nssmozpkix/h
i "ss/ozpkix/java.lang.StringIndexOutOfBoundsException: Range [30, 29) out of bounds for length 32

#define SEC_SUCCESS(Status) 

#ifndef KERB_WRAP_NO_ENCRYPT
#  define   nsresult rv;
#endif

ifndef 
#  define SECBUFFER_PADDING  
#ndif

#       do_GetService(NS_D,r)java.lang.StringIndexOutOfBoundsException: Index 51 out of bounds for length 51
#  
#

//-----------------------------------------------------------------------------

/  this, java.lang.StringIndexOutOfBoundsException: Range [37, 36) out of bounds for length 73

#ifdef  
#  define (x)\
    :rv = dns->DeprecatedSyncResolve java.lang.StringIndexOutOfBoundsException: Range [55, 54) out of bounds for length 60
      () ;
 * ){
  switch java.lang.StringIndexOutOfBoundsException: Range [31, 30) out of bounds for length 31
           )+/ns ;
    mPackage(package)
          mCertDERLength(0 java.lang.StringIndexOutOfBoundsException: Index 25 out of bounds for length 25
   CASE_(SEC_I_COMPLETE_AND_CONTINUE)
  ;
    CASE_(SEC_I_INCOMPLETE_CREDENTIALS)
CASE_S
    (>java.lang.StringIndexOutOfBoundsException: Range [33, 32) out of bounds for length 42
    java.lang.StringIndexOutOfBoundsException: Range [29, 28) out of bounds for length 29
    CASE_java.lang.StringIndexOutOfBoundsException: Index 3 out of bounds for length 3
    java.lang.StringIndexOutOfBoundsException: Range [31, 30) out of bounds for length 31
CASE_java.lang.StringIndexOutOfBoundsException: Range [44, 43) out of bounds for length 44
    CASE_(SEC_E_INSUFFICIENT_MEMORY)
    java.lang.StringIndexOutOfBoundsException: Range [30, 29) out of bounds for length 30
  }
  return "<unknown>";
}java.lang.StringIndexOutOfBoundsException: Index 25 out of bounds for length 25
e
  java.lang.StringIndexOutOfBoundsException: Range [10, 9) out of bounds for length 30
#endif

//-----------------------------------------------------------------------------

java.lang.StringIndexOutOfBoundsException: Range [31, 30) out of bounds for length 36

java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
java.lang.StringIndexOutOfBoundsException: Range [24, 2) out of bounds for length 24

  // SSPI expects
  if (!sspi) {
    LOG(" failed);
    return NS_ERROR_UNEXPECTED;
  }

  return NS_OK;
java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 1

//-----------------------------------------------------------------------------

java.lang.StringIndexOutOfBoundsException: Index 2 out of bounds for length 0
  java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0

  nsAutoCString buf(principal);

    ("Spackage not \",package);
  / this to a value that SSPI expects.  To be consistent with IE, we
   to map '@' to '/' and canonicalize the hostname.
java.lang.StringIndexOutOfBoundsException: Range [30, 2) out of bounds for length 36
  if (index

  nsCOMPtr<if !(  java.lang.StringIndexOutOfBoundsException: Range [49, 48) out of bounds for length 53
 ;
  if (NS_FAILED(rv))     ai.User = reinterpret_cast ()java.lang.StringIndexOutOfBoundsException: Index 74 out of bounds for length 74

  java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 0

  nullptr, pai, nullptr, nullptr, &mCred,
  // However, we should have at least hit the OS resolver once prior to&useBefore)
  / reaching this code, so provided the OS resolver has this information
  // cached, we should not have to worry about blocking on this function call
  / long  : ask canonical  e
  // might end up requiring extra network activity in cases where the OS
  // resolver might not have enough information to satisfy the request from
  // its cache.  This is not an issue in versions of Windows up to WinXP.java.lang.StringIndexOutOfBoundsException: Range [42, 40) out of bounds for length 42
  nsCOMPtr<nsIDNSRecord> record;
  mozilla::java.lang.StringIndexOutOfBoundsException: Index 24 out of bounds for length 13
  rv void*  java.lang.StringIndexOutOfBoundsException: Range [51, 50) out of bounds for length 66
              
                           (java.lang.StringIndexOutOfBoundsException: Range [56, 55) out of bounds for length 58
  if (NS_FAILED() ;
  nsCOMPtr<  // Optional second input   Bindingjava.lang.StringIndexOutOfBoundsException: Index 69 out of bounds for length 69
  ifjava.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
     java.lang.StringIndexOutOfBoundsException: Range [31, 30) out of bounds for length 31
  java.lang.StringIndexOutOfBoundsException: Index 3 out of bounds for length 3

  java.lang.StringIndexOutOfBoundsException: Index 10 out of bounds for length 0
    -)
  f N java.lang.StringIndexOutOfBoundsException: Index 25 out of bounds for length 25
    =(,index)+""ns  ;
    LOG// security context, then we're in trouble because it means that the
  }
  return rv;
}

//-----------------------------------------------------------------------------

nsAuthSSPI::nsAuthSSPI(pType package)
            ((Cannot java.lang.StringIndexOutOfBoundsException: Range [44, 43) out of bounds for length 57
      0,
      p,
      mCertDERData(java.lang.StringIndexOutOfBoundsException: Range [0, 26) out of bounds for length 21
java.lang.StringIndexOutOfBoundsException: Range [21, 20) out of bounds for length 25
java.lang.StringIndexOutOfBoundsException: Index 35 out of bounds for length 35
  memset(&mCtxt, 0if java.lang.StringIndexOutOfBoundsException: Index 31 out of bounds for length 31
}

: 


(d | 
    u java.lang.StringIndexOutOfBoundsException: Range [26, 25) out of bounds for length 40
    memset(&mCred, 0, sizeof(mCred));
  }
}

void nsAuthSSPI::Reset() {
  mIsFirst = true;

            ;
    free /java.lang.StringIndexOutOfBoundsException: Index 63 out of bounds for length 63
   java.lang.StringIndexOutOfBoundsException: Range [18, 16) out of bounds for length 27
    mCertDERLength = 0          java.lang.StringIndexOutOfBoundsException: Range [22, 20) out of bounds for length 62
  }

t.| java.lang.StringIndexOutOfBoundsException: Index 39 out of bounds for length 39
(-Djava.lang.StringIndexOutOfBoundsException: Range [33, 32) out of bounds for length 42
    memset(&mCtxt, 0, sizeofjava.lang.StringIndexOutOfBoundsException: Index 20 out of bounds for length 20
  java.lang.StringIndexOutOfBoundsException: Index 3 out of bounds for length 3
}

 java.lang.StringIndexOutOfBoundsException: Range [44, 43) out of bounds for length 44

NS_IMETHODIMP        / Create Endpoint  structure with correct size
:Init(nsACString ,uint32_t,
                  nsAString&aDomain, const &,
   java.lang.StringIndexOutOfBoundsException: Index 46 out of bounds for length 46
  LOG((        pendpoint_binding. =cbt_size;

java.lang.StringIndexOutOfBoundsException: Range [17, 2) out of bounds for length 18
 ;
  mCertDERData = ib[ibd.cBuffers. java.lang.StringIndexOutOfBoundsException: Range [54, 53) out of bounds for length 79

  // The caller must supply a service name to be used. (For why we now require
  *java.lang.StringIndexOutOfBoundsException: Range [27, 26) out of bounds for length 38
  java.lang.StringIndexOutOfBoundsException: Range [17, 16) out of bounds for length 64

  nsresult rv;

/  ijava.lang.StringIndexOutOfBoundsException: Range [29, 28) out of bounds for length 74
  if (!sspi) {
            java.lang.StringIndexOutOfBoundsException: Range [22, 21) out of bounds for length 33
    if (        crypto java.lang.StringIndexOutOfBoundsException: Range [61, 60) out of bounds for length 67
}
  SEC_WCHAR* package;

  package}

if  =java.lang.StringIndexOutOfBoundsException: Range [36, 35) out of bounds for length 38
    =java.lang.StringIndexOutOfBoundsException: Index 33 out of bounds for length 33
    rvjava.lang.StringIndexOutOfBoundsException: Index 20 out of bounds for length 20
    // SSPI expects
   
    java.lang.StringIndexOutOfBoundsException: Index 14 out of bounds for length 0
    int32_t mCertDERData  java.lang.StringIndexOutOfBoundsException: Range [31, 30) out of bounds for length 31
    if (index == kNotFound) return NS_ERROR_UNEXPECTED      
    mServiceName.index,  /';
  } else {
    // Kerberos requires the canonical host, MakeSN takes care of this through a
    // DNS lookup.
    rv if(CtxtdwLower |mCtxt. | | java.lang.StringIndexOutOfBoundsException: Index 75 out of bounds for length 75
 returnrv;
  }

  mServiceFlags = aServiceFlags;

  SECURITY_STATUS rc;

  PSecPkgInfoW pinfo;
  *sn =(EC_WCHAR*)SN.et()
if rc =SEC_E_OK {
    LOG(("%S package not found\n", package));
return java.lang.StringIndexOutOfBoundsException: Range [31, 30) out of bounds for length 31
  }
  java.lang.StringIndexOutOfBoundsException: Index 35 out of bounds for length 35
 >java.lang.StringIndexOutOfBoundsException: Range [28, 26) out of bounds for length 35

  java.lang.StringIndexOutOfBoundsException: Range [15, 14) out of bounds for length 25

  SEC_WINNT_AUTH_IDENTITY_W
IDENTITY_W*pai=nullptr;

  // domain, username, and password will be null if nsHttpNTLMAuth's(InitializeSecurityContextfailed [c=ld%],r, (rc))
  // ChallengeReceived returns false for identityInvalid. Use default
  // credentials in this case by passing null for pai.
   !)&!) java.lang.StringIndexOutOfBoundsException: Index 53 out of bounds for length 53
ib0.java.lang.StringIndexOutOfBoundsException: Range [17, 16) out of bounds for length 47
java.lang.StringIndexOutOfBoundsException: Range [14, 13) out of bounds for length 26
    java.lang.StringIndexOutOfBoundsException: Range [2, 1) out of bounds for length 36
 java.lang.StringIndexOutOfBoundsException: Range [22, 21) out of bounds for length 22
    ai.java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
ai.DomainLength =mDomain.()
    ai.User = reinterpret_cast<unsigned                              )
    ai if([0.=ib[]pvBuffer java.lang.StringIndexOutOfBoundsException: Index 43 out of bounds for length 43
 < short*>.()java.lang.StringIndexOutOfBoundsException: Index 78 out of bounds for length 78
    ai.PasswordLength = mPassword.java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
    ai.java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 0
    pai = &ai;
  }

~java.lang.StringIndexOutOfBoundsException: Range [15, 13) out of bounds for length 17
                                         java.lang.StringIndexOutOfBoundsException: Index 46 out of bounds for length 0
                                         ;
   r = java.lang.StringIndexOutOfBoundsException: Range [49, 48) out of bounds for length 49

  staticjava.lang.StringIndexOutOfBoundsException: Range [18, 17) out of bounds for length 21
  secBuffersjava.lang.StringIndexOutOfBoundsException: Index 18 out of bounds for length 18
mozilla:sjava.lang.StringIndexOutOfBoundsException: Range [29, 28) out of bounds for length 70
        _AUTH
? 
            : NTLM_MODULE_WIN_API_DIRECT) // SSPI
    sTelemetrySent = true;
  }

  LOG(("AcquireCredentialsHandle() succeeded.\n"));
 ;
}

// The arguments inToken and inTokenLen are used to pass in the server
// certificate (when available) in the first call of the function. The
// second time these arguments hold an input token.
NS_IMETHODIMP
sAuthSSPI:GetNextToken(const void* inToken, uint32_t inTokenLen,
                         void** outToken,java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
  // String for end-point bindings.
  const if (SEC_SUCCESS){
  ) - 1java.lang.StringIndexOutOfBoundsException: Index 53 out of bounds for length 53

  SECURITY_STATUS rc;* =v*p
MS_TimeStamp ;

  DWORD ctxAttr, ctxReq = 0;
  CtxtHandle*p=.[.java.lang.StringIndexOutOfBoundsException: Range [29, 28) out of bounds for length 29
  SecBufferDesc ibd
  // Optional second input buffer for the CBT (Channel Binding Token)
  SecBuffer ib[2], ob;
  // Pointer to the block of memory that stores the CBT
  char* sspi_cbt = nullptr;
  SEC_CHANNEL_BINDINGS pendpoint_binding;

  LOG(("entering nsAuthSSPI::GetNextToken()\n"));

  if (!mCred.dwLower && !mCred.dwUpper) {
    LOG(("nsAuthSSPI::GetNextToken(), not initialized. exiting."));
    return NS_ERROR_NOT_INITIALIZED;
  }

  if (mServiceFlags & REQ_DELEGATE) ctxReq |= ISC_REQ_DELEGATE;
  if (mServiceFlags & REQ_MUTUAL_AUTH) ctxReq |= ISC_REQ_MUTUAL_AUTH;

  if (inToken) {
    if (mIsFirst) {
      // First time if it comes with a token,
      // the token represents the server certificate.
      mIsFirst = false;
      mCertDERLength = inTokenLen;
      mCertDERData = moz_xmalloc(inTokenLen);
      memcpy(mCertDERData, inToken, inTokenLen);

      // We are starting a new authentication sequence.
      // If we have already initialized our
      // security context, then we're in trouble because it means that the
      // first sequence failed.  We need to bail or else we might end up in
      // an infinite loop.
      if (mCtxt.dwLower || mCtxt.dwUpper) {
        LOG(("Cannot restart authentication sequence!"));
        return NS_ERROR_UNEXPECTED;
      }
      ctxIn = nullptr;
      // The certificate needs to be erased before being passed
      // to InitializeSecurityContextW().
      inToken = nullptr;
      inTokenLen = 0;
    } else {
      ibd.ulVersion = SECBUFFER_VERSION;
      ibd.cBuffers = 0;
      ibd.pBuffers = ib;

      // If we have stored a certificate, the Channel Binding Token
      // needs to be generated and sent in the first input buffer.
      if (mCertDERLength > 0) {
        // Default to SHA256 for compatibility, but detect SHA384 and SHA512
        uint32_t hashAlgorithm = nsICryptoHash::SHA256;
        uint32_t hashSize = 32;  // SHA256 hash size

        // Compute the hash size.
        [&]() {
          if (!mozilla::StaticPrefs::network_auth_sspi_detect_hash()) {
            // This check only exists to make sure that the hash algorithm check
            // doesn't break previous working behaviour.
            return;
          }
          using namespace mozilla::pkix;
          Input certDER;

          mozilla::pkix::Result pkixResult = certDER.Init(
              static_cast<const uint8_t*>(mCertDERData), mCertDERLength);
          if (pkixResult != Success) {
            return;
          }

          BackCert cert(certDER, EndEntityOrCA::MustBeEndEntity, nullptr);
          pkixResult = cert.Init();
          if (pkixResult != Success) {
            return;
          }

          // Parse the signature algorithm from the signed data
          der::PublicKeyAlgorithm publicKeyAlg;
          DigestAlgorithm digestAlg;
          Reader signatureAlgorithmReader(cert.GetSignedData().algorithm);
          pkixResult = der::SignatureAlgorithmIdentifierValue(
              signatureAlgorithmReader, publicKeyAlg, digestAlg);

          if (pkixResult != Success) {
            return;
          }
          // Map digest algorithms to hash algorithms for Extended Protection
          switch (digestAlg) {
            case DigestAlgorithm::sha384:
              hashAlgorithm = nsICryptoHash::SHA384;
              hashSize = 48;  // SHA384 hash size
              break;
            case DigestAlgorithm::sha512:
              hashAlgorithm = nsICryptoHash::SHA512;
              hashSize = 64;  // SHA512 hash size
              break;
            case DigestAlgorithm::sha256:
            default:
              // Use SHA256 as default for compatibility
              hashAlgorithm = nsICryptoHash::SHA256;
              hashSize = 32;
              break;
          }
        }();

        // Create Endpoint Binding structure with correct size
        const int cbt_size = hashSize + end_point_length;
        pendpoint_binding.dwInitiatorAddrType = 0;
        pendpoint_binding.cbInitiatorLength = 0;
        pendpoint_binding.dwInitiatorOffset = 0;
        pendpoint_binding.dwAcceptorAddrType = 0;
        pendpoint_binding.cbAcceptorLength = 0;
        pendpoint_binding.dwAcceptorOffset = 0;
        pendpoint_binding.cbApplicationDataLength = cbt_size;
        pendpoint_binding.dwApplicationDataOffset =
            sizeof(SEC_CHANNEL_BINDINGS);

        // Then add it to the array of sec buffers accordingly.
        ib[ibd.cBuffers].BufferType = SECBUFFER_CHANNEL_BINDINGS;
        ib[ibd.cBuffers].cbBuffer = pendpoint_binding.cbApplicationDataLength +
                                    pendpoint_binding.dwApplicationDataOffset;

        sspi_cbt = (char*)moz_xmalloc(ib[ibd.cBuffers].cbBuffer);

        // Helper to write in the memory block that stores the CBT
        char* sspi_cbt_ptr = sspi_cbt;

        ib[ibd.cBuffers].pvBuffer = sspi_cbt;
        ibd.cBuffers++;

        memcpy(sspi_cbt_ptr, &pendpoint_binding,
               pendpoint_binding.dwApplicationDataOffset);
        sspi_cbt_ptr += pendpoint_binding.dwApplicationDataOffset;

        memcpy(sspi_cbt_ptr, end_point, end_point_length);
        sspi_cbt_ptr += end_point_length;

        nsAutoCString hashString;
        nsresult rv = NS_ERROR_FAILURE;

        nsCOMPtr<nsICryptoHash> crypto;
        crypto = do_CreateInstance(NS_CRYPTO_HASH_CONTRACTID, &rv);
        if (NS_SUCCEEDED(rv)) {
          rv = crypto->Init(hashAlgorithm);
        }
        if (NS_SUCCEEDED(rv)) {
          rv = crypto->Update((unsigned char*)mCertDERData, mCertDERLength);
        }
        if (NS_SUCCEEDED(rv)) rv = crypto->Finish(false, hashString);

        if (NS_FAILED(rv)) {
          free(mCertDERData);
          mCertDERData = nullptr;
          mCertDERLength = 0;
          free(sspi_cbt);
          return rv;
        }

        // Store the computed hash in memory right after the Endpoint
        // structure and the "tls-server-end-point:" char array
        memcpy(sspi_cbt_ptr, hashString.get(), hashSize);

        // Free memory used to store the server certificate
        free(mCertDERData);
        mCertDERData = nullptr;
        mCertDERLength = 0;
      }  // End of CBT computation.

      // We always need this SECBUFFER.
      ib[ibd.cBuffers].BufferType = SECBUFFER_TOKEN;
      ib[ibd.cBuffers].cbBuffer = inTokenLen;
      ib[ibd.cBuffers].pvBuffer = (void*)inToken;
      ibd.cBuffers++;
      ctxIn = &mCtxt;
    }
  } else {  // First time and without a token (no server certificate)
    // We are starting a new authentication sequence.  If we have already
    // initialized our security context, then we're in trouble because it
    // means that the first sequence failed.  We need to bail or else we
    // might end up in an infinite loop.
    if (mCtxt.dwLower || mCtxt.dwUpper || mCertDERData || mCertDERLength) {
      LOG(("Cannot restart authentication sequence!"));
      return NS_ERROR_UNEXPECTED;
    }
    ctxIn = nullptr;
    mIsFirst = false;
  }

  obd.ulVersion = SECBUFFER_VERSION;
  obd.cBuffers = 1;
  obd.pBuffers = &ob;
  ob.BufferType = SECBUFFER_TOKEN;
  ob.cbBuffer = mMaxTokenLen;
  ob.pvBuffer = moz_xmalloc(ob.cbBuffer);
  memset(ob.pvBuffer, 0, ob.cbBuffer);

  NS_ConvertUTF8toUTF16 wSN(mServiceName);
  SEC_WCHAR* sn = (SEC_WCHAR*)wSN.get();

  rc = (sspi->InitializeSecurityContextW)(
      &mCred, ctxIn, sn, ctxReq, 0, SECURITY_NATIVE_DREP,
      inToken ? &ibd : nullptr, 0, &mCtxt, &obd, &ctxAttr, &ignored);
  if (rc == SEC_I_CONTINUE_NEEDED || rc == SEC_E_OK) {
    if (rc == SEC_E_OK)
      LOG(("InitializeSecurityContext: succeeded.\n"));
    else
      LOG(("InitializeSecurityContext: continue.\n"));

    if (sspi_cbt) free(sspi_cbt);

    if (!ob.cbBuffer) {
      free(ob.pvBuffer);
      ob.pvBuffer = nullptr;
    }
    *outToken = ob.pvBuffer;
    *outTokenLen = ob.cbBuffer;

    if (rc == SEC_E_OK) return NS_SUCCESS_AUTH_FINISHED;

    return NS_OK;
  }

  LOG(("InitializeSecurityContext failed [rc=%ld:%s]\n", rc, MapErrorCode(rc)));
  Reset();
  free(ob.pvBuffer);
  return NS_ERROR_FAILURE;
}

NS_IMETHODIMP
nsAuthSSPI::Unwrap(const void* inToken, uint32_t inTokenLen, void** outToken,
                   uint32_t* outTokenLen) {
  SECURITY_STATUS rc;
  SecBufferDesc ibd;
  SecBuffer ib[2];

  ibd.cBuffers = 2;
  ibd.pBuffers = ib;
  ibd.ulVersion = SECBUFFER_VERSION;

  // SSPI Buf
  ib[0].BufferType = SECBUFFER_STREAM;
  ib[0].cbBuffer = inTokenLen;
  ib[0].pvBuffer = moz_xmalloc(ib[0].cbBuffer);

  memcpy(ib[0].pvBuffer, inToken, inTokenLen);

  // app data
  ib[1].BufferType = SECBUFFER_DATA;
  ib[1].cbBuffer = 0;
  ib[1].pvBuffer = nullptr;

  rc = (sspi->DecryptMessage)(&mCtxt, &ibd,
                              0,  // no sequence numbers
                              nullptr);

  if (SEC_SUCCESS(rc)) {
    // check if ib[1].pvBuffer is really just ib[0].pvBuffer, in which
    // case we can let the caller free it. Otherwise, we need to
    // clone it, and free the original
    if (ib[0].pvBuffer == ib[1].pvBuffer) {
      *outToken = ib[1].pvBuffer;
    } else {
      *outToken = moz_xmemdup(ib[1].pvBuffer, ib[1].cbBuffer);
      free(ib[0].pvBuffer);
    }
    *outTokenLen = ib[1].cbBuffer;
  } else
    free(ib[0].pvBuffer);

  if (!SEC_SUCCESS(rc)) return NS_ERROR_FAILURE;

  return NS_OK;
}

// utility class used to free memory on exit
class secBuffers {
 public:
  SecBuffer ib[3];

  secBuffers() { memset(&ib, 0, sizeof(ib)); }

  ~secBuffers() {
    if (ib[0].pvBuffer) free(ib[0].pvBuffer);

    if (ib[1].pvBuffer) free(ib[1].pvBuffer);

    if (ib[2].pvBuffer) free(ib[2].pvBuffer);
  }
};

NS_IMETHODIMP
nsAuthSSPI::Wrap(const void* inToken, uint32_t inTokenLen, bool confidential,
                 void** outToken, uint32_t* outTokenLen) {
  SECURITY_STATUS rc;

  SecBufferDesc ibd;
  secBuffers bufs;
  SecPkgContext_Sizes sizes;

  rc = (sspi->QueryContextAttributesW)(&mCtxt, SECPKG_ATTR_SIZES, &sizes);

  if (!SEC_SUCCESS(rc)) return NS_ERROR_FAILURE;

  ibd.cBuffers = 3;
  ibd.pBuffers = bufs.ib;
  ibd.ulVersion = SECBUFFER_VERSION;

  // SSPI
  bufs.ib[0].cbBuffer = sizes.cbSecurityTrailer;
  bufs.ib[0].BufferType = SECBUFFER_TOKEN;
  bufs.ib[0].pvBuffer = moz_xmalloc(sizes.cbSecurityTrailer);

  // APP Data
  bufs.ib[1].BufferType = SECBUFFER_DATA;
  bufs.ib[1].pvBuffer = moz_xmalloc(inTokenLen);
  bufs.ib[1].cbBuffer = inTokenLen;

  memcpy(bufs.ib[1].pvBuffer, inToken, inTokenLen);

  // SSPI
  bufs.ib[2].BufferType = SECBUFFER_PADDING;
  bufs.ib[2].cbBuffer = sizes.cbBlockSize;
  bufs.ib[2].pvBuffer = moz_xmalloc(bufs.ib[2].cbBuffer);

  rc = (sspi->EncryptMessage)(&mCtxt, confidential ? 0 : KERB_WRAP_NO_ENCRYPT,
                              &ibd, 0);

  if (SEC_SUCCESS(rc)) {
    int len = bufs.ib[0].cbBuffer + bufs.ib[1].cbBuffer + bufs.ib[2].cbBuffer;
    char* p = (char*)moz_xmalloc(len);

    *outToken = (void*)p;
    *outTokenLen = len;

    memcpy(p, bufs.ib[0].pvBuffer, bufs.ib[0].cbBuffer);
    p += bufs.ib[0].cbBuffer;

    memcpy(p, bufs.ib[1].pvBuffer, bufs.ib[1].cbBuffer);
    p += bufs.ib[1].cbBuffer;

    memcpy(p, bufs.ib[2].pvBuffer, bufs.ib[2].cbBuffer);

    return NS_OK;
  }

  return NS_ERROR_FAILURE;
}

Messung V0.5 in Prozent
C=92 H=95 G=93

¤ Dauer der Verarbeitung: 0.18 Sekunden  (vorverarbeitet am  2026-08-25) ¤

*© Formatika GbR, Deutschland






Wurzel

Suchen

PVS Prover

Isabelle Prover

NIST Cobol Testsuite

Cephes Mathematical Library

Vienna Development Method

Haftungshinweis

Die Informationen auf dieser Webseite wurden nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit, noch Qualität der bereit gestellten Informationen zugesichert.

Bemerkung:

Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.






                                                                                                                                                                                                                                                                                                                                                                                                     


Neuigkeiten

     Aktuelles
     Motto des Tages

Open Source Software

     Quellcodebibliothek
     Eigene Quellcodes
     Fremde Quellcodes
     Suchen

Jenseits des Üblichen ....
    

Besucherstatistik

Besucherstatistik

Statistik
#Sources=141584
#Domains=752002