1 /***************************************************************************
3 * Project ___| | | | _ \| |
5 * | (__| |_| | _ <| |___
6 * \___|\___/|_| \_\_____|
8 * Copyright (C) 1998 - 2009, Daniel Stenberg, <daniel@haxx.se>, et al.
10 * This software is licensed as described in the file COPYING, which
11 * you should have received as part of this distribution. The terms
12 * are also available at http://curl.haxx.se/docs/copyright.html.
14 * You may opt to use, copy, modify, merge, publish, distribute and/or sell
15 * copies of the Software, and permit persons to whom the Software is
16 * furnished to do so, under the terms of the COPYING file.
18 * This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY
19 * KIND, either express or implied.
21 ***************************************************************************/
25 #ifdef USE_WINDOWS_SSPI
27 #include <curl/curl.h>
29 #include "curl_sspi.h"
31 #define _MPRINTF_REPLACE /* use our functions only */
32 #include <curl/mprintf.h>
34 #include "curl_memory.h"
35 /* The last #include file should be: */
39 /* We use our own typedef here since some headers might lack these */
40 typedef PSecurityFunctionTableA (APIENTRY *INITSECURITYINTERFACE_FN_A)(VOID);
42 /* Handle of security.dll or secur32.dll, depending on Windows version */
43 HMODULE s_hSecDll = NULL;
45 /* Pointer to SSPI dispatch table */
46 PSecurityFunctionTableA s_pSecFn = NULL;
50 * Curl_sspi_global_init()
52 * This is used to load the Security Service Provider Interface (SSPI)
53 * dynamic link library portably across all Windows versions, without
54 * the need to directly link libcurl, nor the application using it, at
57 * Once this function has been executed, Windows SSPI functions can be
58 * called through the Security Service Provider Interface dispatch table.
62 Curl_sspi_global_init(void)
65 INITSECURITYINTERFACE_FN_A pInitSecurityInterface;
67 /* If security interface is not yet initialized try to do this */
68 if(s_hSecDll == NULL) {
70 /* Find out Windows version */
71 memset(&osver, 0, sizeof(osver));
72 osver.dwOSVersionInfoSize = sizeof(osver);
73 if(! GetVersionEx(&osver))
74 return CURLE_FAILED_INIT;
76 /* Security Service Provider Interface (SSPI) functions are located in
77 * security.dll on WinNT 4.0 and in secur32.dll on Win9x. Win2K and XP
78 * have both these DLLs (security.dll forwards calls to secur32.dll) */
80 /* Load SSPI dll into the address space of the calling process */
81 if(osver.dwPlatformId == VER_PLATFORM_WIN32_NT
82 && osver.dwMajorVersion == 4)
83 s_hSecDll = LoadLibrary("security.dll");
85 s_hSecDll = LoadLibrary("secur32.dll");
87 return CURLE_FAILED_INIT;
89 /* Get address of the InitSecurityInterfaceA function from the SSPI dll */
90 pInitSecurityInterface = (INITSECURITYINTERFACE_FN_A)
91 GetProcAddress(s_hSecDll, "InitSecurityInterfaceA");
92 if(! pInitSecurityInterface)
93 return CURLE_FAILED_INIT;
95 /* Get pointer to Security Service Provider Interface dispatch table */
96 s_pSecFn = pInitSecurityInterface();
98 return CURLE_FAILED_INIT;
106 * Curl_sspi_global_cleanup()
108 * This deinitializes the Security Service Provider Interface from libcurl.
112 Curl_sspi_global_cleanup(void)
115 FreeLibrary(s_hSecDll);
123 * Curl_sspi_status(SECURIY_STATUS status)
125 * This function returns a string representing an SSPI status.
126 * It will in any case return a usable string pointer which needs to be freed.
129 Curl_sspi_status(SECURITY_STATUS status)
131 const char* status_const;
134 case SEC_I_COMPLETE_AND_CONTINUE:
135 status_const = "SEC_I_COMPLETE_AND_CONTINUE";
137 case SEC_I_COMPLETE_NEEDED:
138 status_const = "SEC_I_COMPLETE_NEEDED";
140 case SEC_I_CONTINUE_NEEDED:
141 status_const = "SEC_I_CONTINUE_NEEDED";
143 case SEC_I_CONTEXT_EXPIRED:
144 status_const = "SEC_I_CONTEXT_EXPIRED";
146 case SEC_I_INCOMPLETE_CREDENTIALS:
147 status_const = "SEC_I_INCOMPLETE_CREDENTIALS";
149 case SEC_I_RENEGOTIATE:
150 status_const = "SEC_I_RENEGOTIATE";
152 case SEC_E_BUFFER_TOO_SMALL:
153 status_const = "SEC_E_BUFFER_TOO_SMALL";
155 case SEC_E_CONTEXT_EXPIRED:
156 status_const = "SEC_E_CONTEXT_EXPIRED";
158 case SEC_E_CRYPTO_SYSTEM_INVALID:
159 status_const = "SEC_E_CRYPTO_SYSTEM_INVALID";
161 case SEC_E_INCOMPLETE_MESSAGE:
162 status_const = "SEC_E_INCOMPLETE_MESSAGE";
164 case SEC_E_INSUFFICIENT_MEMORY:
165 status_const = "SEC_E_INSUFFICIENT_MEMORY";
167 case SEC_E_INTERNAL_ERROR:
168 status_const = "SEC_E_INTERNAL_ERROR";
170 case SEC_E_INVALID_HANDLE:
171 status_const = "SEC_E_INVALID_HANDLE";
173 case SEC_E_INVALID_TOKEN:
174 status_const = "SEC_E_INVALID_TOKEN";
176 case SEC_E_LOGON_DENIED:
177 status_const = "SEC_E_LOGON_DENIED";
179 case SEC_E_MESSAGE_ALTERED:
180 status_const = "SEC_E_MESSAGE_ALTERED";
182 case SEC_E_NO_AUTHENTICATING_AUTHORITY:
183 status_const = "SEC_E_NO_AUTHENTICATING_AUTHORITY";
185 case SEC_E_NO_CREDENTIALS:
186 status_const = "SEC_E_NO_CREDENTIALS";
188 case SEC_E_NOT_OWNER:
189 status_const = "SEC_E_NOT_OWNER";
192 status_const = "SEC_E_OK";
194 case SEC_E_OUT_OF_SEQUENCE:
195 status_const = "SEC_E_OUT_OF_SEQUENCE";
197 case SEC_E_QOP_NOT_SUPPORTED:
198 status_const = "SEC_E_QOP_NOT_SUPPORTED";
200 case SEC_E_SECPKG_NOT_FOUND:
201 status_const = "SEC_E_SECPKG_NOT_FOUND";
203 case SEC_E_TARGET_UNKNOWN:
204 status_const = "SEC_E_TARGET_UNKNOWN";
206 case SEC_E_UNKNOWN_CREDENTIALS:
207 status_const = "SEC_E_UNKNOWN_CREDENTIALS";
209 case SEC_E_UNSUPPORTED_FUNCTION:
210 status_const = "SEC_E_UNSUPPORTED_FUNCTION";
212 case SEC_E_WRONG_PRINCIPAL:
213 status_const = "SEC_E_WRONG_PRINCIPAL";
216 status_const = "Unknown error";
219 return curl_maprintf("%s (0x%08X)", status_const, status);
223 * Curl_sspi_status_msg(SECURITY_STATUS status)
225 * This function returns a message representing an SSPI status.
226 * It will in any case return a usable string pointer which needs to be freed.
230 Curl_sspi_status_msg(SECURITY_STATUS status)
232 LPSTR format_msg = NULL;
233 char *status_msg = NULL, *status_const = NULL;
236 status_len = FormatMessage(FORMAT_MESSAGE_ALLOCATE_BUFFER |
237 FORMAT_MESSAGE_FROM_SYSTEM |
238 FORMAT_MESSAGE_IGNORE_INSERTS,
239 NULL, status, 0, (LPTSTR)&format_msg, 0, NULL);
241 if(status_len > 0 && format_msg) {
242 status_msg = strdup(format_msg);
243 LocalFree(format_msg);
245 /* remove trailing CR+LF */
247 if(status_msg[status_len-1] == '\n') {
248 status_msg[status_len-1] = '\0';
250 if(status_msg[status_len-2] == '\r') {
251 status_msg[status_len-2] = '\0';
258 status_const = Curl_sspi_status(status);
260 status_msg = curl_maprintf("%s [%s]", status_msg, status_const);
264 status_msg = status_const;
270 #endif /* USE_WINDOWS_SSPI */