1 #ifndef HEADER_CURL_SSPI_H
2 #define HEADER_CURL_SSPI_H
3 /***************************************************************************
5 * Project ___| | | | _ \| |
7 * | (__| |_| | _ <| |___
8 * \___|\___/|_| \_\_____|
10 * Copyright (C) 1998 - 2014, Daniel Stenberg, <daniel@haxx.se>, et al.
12 * This software is licensed as described in the file COPYING, which
13 * you should have received as part of this distribution. The terms
14 * are also available at http://curl.haxx.se/docs/copyright.html.
16 * You may opt to use, copy, modify, merge, publish, distribute and/or sell
17 * copies of the Software, and permit persons to whom the Software is
18 * furnished to do so, under the terms of the COPYING file.
20 * This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY
21 * KIND, either express or implied.
23 ***************************************************************************/
25 #include "curl_setup.h"
27 #ifdef USE_WINDOWS_SSPI
29 #include <curl/curl.h>
32 * When including the following three headers, it is mandatory to define either
33 * SECURITY_WIN32 or SECURITY_KERNEL, indicating who is compiling the code.
37 #undef SECURITY_KERNEL
38 #define SECURITY_WIN32 1
43 CURLcode Curl_sspi_global_init(void);
44 void Curl_sspi_global_cleanup(void);
46 /* This is used to generate an SSPI identity structure */
47 CURLcode Curl_create_sspi_identity(const char *userp, const char *passwdp,
48 SEC_WINNT_AUTH_IDENTITY *identity);
50 /* This is used to free an SSPI identity structure */
51 void Curl_sspi_free_identity(SEC_WINNT_AUTH_IDENTITY *identity);
53 /* Forward-declaration of global variables defined in curl_sspi.c */
54 extern HMODULE s_hSecDll;
55 extern PSecurityFunctionTable s_pSecFn;
57 /* Provide some definitions missing in old headers */
58 #define SP_NAME_DIGEST "WDigest"
59 #define SP_NAME_NTLM "NTLM"
60 #define SP_NAME_NEGOTIATE "Negotiate"
61 #define SP_NAME_KERBEROS "Kerberos"
63 #ifndef ISC_REQ_USE_HTTP_STYLE
64 #define ISC_REQ_USE_HTTP_STYLE 0x01000000
67 #ifndef ISC_RET_REPLAY_DETECT
68 #define ISC_RET_REPLAY_DETECT 0x00000004
71 #ifndef ISC_RET_SEQUENCE_DETECT
72 #define ISC_RET_SEQUENCE_DETECT 0x00000008
75 #ifndef ISC_RET_CONFIDENTIALITY
76 #define ISC_RET_CONFIDENTIALITY 0x00000010
79 #ifndef ISC_RET_ALLOCATED_MEMORY
80 #define ISC_RET_ALLOCATED_MEMORY 0x00000100
83 #ifndef ISC_RET_STREAM
84 #define ISC_RET_STREAM 0x00008000
87 #ifndef SEC_E_INSUFFICIENT_MEMORY
88 # define SEC_E_INSUFFICIENT_MEMORY ((HRESULT)0x80090300L)
90 #ifndef SEC_E_INVALID_HANDLE
91 # define SEC_E_INVALID_HANDLE ((HRESULT)0x80090301L)
93 #ifndef SEC_E_UNSUPPORTED_FUNCTION
94 # define SEC_E_UNSUPPORTED_FUNCTION ((HRESULT)0x80090302L)
96 #ifndef SEC_E_TARGET_UNKNOWN
97 # define SEC_E_TARGET_UNKNOWN ((HRESULT)0x80090303L)
99 #ifndef SEC_E_INTERNAL_ERROR
100 # define SEC_E_INTERNAL_ERROR ((HRESULT)0x80090304L)
102 #ifndef SEC_E_SECPKG_NOT_FOUND
103 # define SEC_E_SECPKG_NOT_FOUND ((HRESULT)0x80090305L)
105 #ifndef SEC_E_NOT_OWNER
106 # define SEC_E_NOT_OWNER ((HRESULT)0x80090306L)
108 #ifndef SEC_E_CANNOT_INSTALL
109 # define SEC_E_CANNOT_INSTALL ((HRESULT)0x80090307L)
111 #ifndef SEC_E_INVALID_TOKEN
112 # define SEC_E_INVALID_TOKEN ((HRESULT)0x80090308L)
114 #ifndef SEC_E_CANNOT_PACK
115 # define SEC_E_CANNOT_PACK ((HRESULT)0x80090309L)
117 #ifndef SEC_E_QOP_NOT_SUPPORTED
118 # define SEC_E_QOP_NOT_SUPPORTED ((HRESULT)0x8009030AL)
120 #ifndef SEC_E_NO_IMPERSONATION
121 # define SEC_E_NO_IMPERSONATION ((HRESULT)0x8009030BL)
123 #ifndef SEC_E_LOGON_DENIED
124 # define SEC_E_LOGON_DENIED ((HRESULT)0x8009030CL)
126 #ifndef SEC_E_UNKNOWN_CREDENTIALS
127 # define SEC_E_UNKNOWN_CREDENTIALS ((HRESULT)0x8009030DL)
129 #ifndef SEC_E_NO_CREDENTIALS
130 # define SEC_E_NO_CREDENTIALS ((HRESULT)0x8009030EL)
132 #ifndef SEC_E_MESSAGE_ALTERED
133 # define SEC_E_MESSAGE_ALTERED ((HRESULT)0x8009030FL)
135 #ifndef SEC_E_OUT_OF_SEQUENCE
136 # define SEC_E_OUT_OF_SEQUENCE ((HRESULT)0x80090310L)
138 #ifndef SEC_E_NO_AUTHENTICATING_AUTHORITY
139 # define SEC_E_NO_AUTHENTICATING_AUTHORITY ((HRESULT)0x80090311L)
141 #ifndef SEC_E_BAD_PKGID
142 # define SEC_E_BAD_PKGID ((HRESULT)0x80090316L)
144 #ifndef SEC_E_CONTEXT_EXPIRED
145 # define SEC_E_CONTEXT_EXPIRED ((HRESULT)0x80090317L)
147 #ifndef SEC_E_INCOMPLETE_MESSAGE
148 # define SEC_E_INCOMPLETE_MESSAGE ((HRESULT)0x80090318L)
150 #ifndef SEC_E_INCOMPLETE_CREDENTIALS
151 # define SEC_E_INCOMPLETE_CREDENTIALS ((HRESULT)0x80090320L)
153 #ifndef SEC_E_BUFFER_TOO_SMALL
154 # define SEC_E_BUFFER_TOO_SMALL ((HRESULT)0x80090321L)
156 #ifndef SEC_E_WRONG_PRINCIPAL
157 # define SEC_E_WRONG_PRINCIPAL ((HRESULT)0x80090322L)
159 #ifndef SEC_E_TIME_SKEW
160 # define SEC_E_TIME_SKEW ((HRESULT)0x80090324L)
162 #ifndef SEC_E_UNTRUSTED_ROOT
163 # define SEC_E_UNTRUSTED_ROOT ((HRESULT)0x80090325L)
165 #ifndef SEC_E_ILLEGAL_MESSAGE
166 # define SEC_E_ILLEGAL_MESSAGE ((HRESULT)0x80090326L)
168 #ifndef SEC_E_CERT_UNKNOWN
169 # define SEC_E_CERT_UNKNOWN ((HRESULT)0x80090327L)
171 #ifndef SEC_E_CERT_EXPIRED
172 # define SEC_E_CERT_EXPIRED ((HRESULT)0x80090328L)
174 #ifndef SEC_E_ENCRYPT_FAILURE
175 # define SEC_E_ENCRYPT_FAILURE ((HRESULT)0x80090329L)
177 #ifndef SEC_E_DECRYPT_FAILURE
178 # define SEC_E_DECRYPT_FAILURE ((HRESULT)0x80090330L)
180 #ifndef SEC_E_ALGORITHM_MISMATCH
181 # define SEC_E_ALGORITHM_MISMATCH ((HRESULT)0x80090331L)
183 #ifndef SEC_E_SECURITY_QOS_FAILED
184 # define SEC_E_SECURITY_QOS_FAILED ((HRESULT)0x80090332L)
186 #ifndef SEC_E_UNFINISHED_CONTEXT_DELETED
187 # define SEC_E_UNFINISHED_CONTEXT_DELETED ((HRESULT)0x80090333L)
189 #ifndef SEC_E_NO_TGT_REPLY
190 # define SEC_E_NO_TGT_REPLY ((HRESULT)0x80090334L)
192 #ifndef SEC_E_NO_IP_ADDRESSES
193 # define SEC_E_NO_IP_ADDRESSES ((HRESULT)0x80090335L)
195 #ifndef SEC_E_WRONG_CREDENTIAL_HANDLE
196 # define SEC_E_WRONG_CREDENTIAL_HANDLE ((HRESULT)0x80090336L)
198 #ifndef SEC_E_CRYPTO_SYSTEM_INVALID
199 # define SEC_E_CRYPTO_SYSTEM_INVALID ((HRESULT)0x80090337L)
201 #ifndef SEC_E_MAX_REFERRALS_EXCEEDED
202 # define SEC_E_MAX_REFERRALS_EXCEEDED ((HRESULT)0x80090338L)
204 #ifndef SEC_E_MUST_BE_KDC
205 # define SEC_E_MUST_BE_KDC ((HRESULT)0x80090339L)
207 #ifndef SEC_E_STRONG_CRYPTO_NOT_SUPPORTED
208 # define SEC_E_STRONG_CRYPTO_NOT_SUPPORTED ((HRESULT)0x8009033AL)
210 #ifndef SEC_E_TOO_MANY_PRINCIPALS
211 # define SEC_E_TOO_MANY_PRINCIPALS ((HRESULT)0x8009033BL)
213 #ifndef SEC_E_NO_PA_DATA
214 # define SEC_E_NO_PA_DATA ((HRESULT)0x8009033CL)
216 #ifndef SEC_E_PKINIT_NAME_MISMATCH
217 # define SEC_E_PKINIT_NAME_MISMATCH ((HRESULT)0x8009033DL)
219 #ifndef SEC_E_SMARTCARD_LOGON_REQUIRED
220 # define SEC_E_SMARTCARD_LOGON_REQUIRED ((HRESULT)0x8009033EL)
222 #ifndef SEC_E_SHUTDOWN_IN_PROGRESS
223 # define SEC_E_SHUTDOWN_IN_PROGRESS ((HRESULT)0x8009033FL)
225 #ifndef SEC_E_KDC_INVALID_REQUEST
226 # define SEC_E_KDC_INVALID_REQUEST ((HRESULT)0x80090340L)
228 #ifndef SEC_E_KDC_UNABLE_TO_REFER
229 # define SEC_E_KDC_UNABLE_TO_REFER ((HRESULT)0x80090341L)
231 #ifndef SEC_E_KDC_UNKNOWN_ETYPE
232 # define SEC_E_KDC_UNKNOWN_ETYPE ((HRESULT)0x80090342L)
234 #ifndef SEC_E_UNSUPPORTED_PREAUTH
235 # define SEC_E_UNSUPPORTED_PREAUTH ((HRESULT)0x80090343L)
237 #ifndef SEC_E_DELEGATION_REQUIRED
238 # define SEC_E_DELEGATION_REQUIRED ((HRESULT)0x80090345L)
240 #ifndef SEC_E_BAD_BINDINGS
241 # define SEC_E_BAD_BINDINGS ((HRESULT)0x80090346L)
243 #ifndef SEC_E_MULTIPLE_ACCOUNTS
244 # define SEC_E_MULTIPLE_ACCOUNTS ((HRESULT)0x80090347L)
246 #ifndef SEC_E_NO_KERB_KEY
247 # define SEC_E_NO_KERB_KEY ((HRESULT)0x80090348L)
249 #ifndef SEC_E_CERT_WRONG_USAGE
250 # define SEC_E_CERT_WRONG_USAGE ((HRESULT)0x80090349L)
252 #ifndef SEC_E_DOWNGRADE_DETECTED
253 # define SEC_E_DOWNGRADE_DETECTED ((HRESULT)0x80090350L)
255 #ifndef SEC_E_SMARTCARD_CERT_REVOKED
256 # define SEC_E_SMARTCARD_CERT_REVOKED ((HRESULT)0x80090351L)
258 #ifndef SEC_E_ISSUING_CA_UNTRUSTED
259 # define SEC_E_ISSUING_CA_UNTRUSTED ((HRESULT)0x80090352L)
261 #ifndef SEC_E_REVOCATION_OFFLINE_C
262 # define SEC_E_REVOCATION_OFFLINE_C ((HRESULT)0x80090353L)
264 #ifndef SEC_E_PKINIT_CLIENT_FAILURE
265 # define SEC_E_PKINIT_CLIENT_FAILURE ((HRESULT)0x80090354L)
267 #ifndef SEC_E_SMARTCARD_CERT_EXPIRED
268 # define SEC_E_SMARTCARD_CERT_EXPIRED ((HRESULT)0x80090355L)
270 #ifndef SEC_E_NO_S4U_PROT_SUPPORT
271 # define SEC_E_NO_S4U_PROT_SUPPORT ((HRESULT)0x80090356L)
273 #ifndef SEC_E_CROSSREALM_DELEGATION_FAILURE
274 # define SEC_E_CROSSREALM_DELEGATION_FAILURE ((HRESULT)0x80090357L)
276 #ifndef SEC_E_REVOCATION_OFFLINE_KDC
277 # define SEC_E_REVOCATION_OFFLINE_KDC ((HRESULT)0x80090358L)
279 #ifndef SEC_E_ISSUING_CA_UNTRUSTED_KDC
280 # define SEC_E_ISSUING_CA_UNTRUSTED_KDC ((HRESULT)0x80090359L)
282 #ifndef SEC_E_KDC_CERT_EXPIRED
283 # define SEC_E_KDC_CERT_EXPIRED ((HRESULT)0x8009035AL)
285 #ifndef SEC_E_KDC_CERT_REVOKED
286 # define SEC_E_KDC_CERT_REVOKED ((HRESULT)0x8009035BL)
288 #ifndef SEC_E_INVALID_PARAMETER
289 # define SEC_E_INVALID_PARAMETER ((HRESULT)0x8009035DL)
291 #ifndef SEC_E_DELEGATION_POLICY
292 # define SEC_E_DELEGATION_POLICY ((HRESULT)0x8009035EL)
294 #ifndef SEC_E_POLICY_NLTM_ONLY
295 # define SEC_E_POLICY_NLTM_ONLY ((HRESULT)0x8009035FL)
298 #ifndef SEC_I_CONTINUE_NEEDED
299 # define SEC_I_CONTINUE_NEEDED ((HRESULT)0x00090312L)
301 #ifndef SEC_I_COMPLETE_NEEDED
302 # define SEC_I_COMPLETE_NEEDED ((HRESULT)0x00090313L)
304 #ifndef SEC_I_COMPLETE_AND_CONTINUE
305 # define SEC_I_COMPLETE_AND_CONTINUE ((HRESULT)0x00090314L)
307 #ifndef SEC_I_LOCAL_LOGON
308 # define SEC_I_LOCAL_LOGON ((HRESULT)0x00090315L)
310 #ifndef SEC_I_CONTEXT_EXPIRED
311 # define SEC_I_CONTEXT_EXPIRED ((HRESULT)0x00090317L)
313 #ifndef SEC_I_INCOMPLETE_CREDENTIALS
314 # define SEC_I_INCOMPLETE_CREDENTIALS ((HRESULT)0x00090320L)
316 #ifndef SEC_I_RENEGOTIATE
317 # define SEC_I_RENEGOTIATE ((HRESULT)0x00090321L)
319 #ifndef SEC_I_NO_LSA_CONTEXT
320 # define SEC_I_NO_LSA_CONTEXT ((HRESULT)0x00090323L)
322 #ifndef SEC_I_SIGNATURE_NEEDED
323 # define SEC_I_SIGNATURE_NEEDED ((HRESULT)0x0009035CL)
327 # define SECFLAG_WINNT_AUTH_IDENTITY \
328 (unsigned long)SEC_WINNT_AUTH_IDENTITY_UNICODE
330 # define SECFLAG_WINNT_AUTH_IDENTITY \
331 (unsigned long)SEC_WINNT_AUTH_IDENTITY_ANSI
335 * Definitions required from ntsecapi.h are directly provided below this point
336 * to avoid including ntsecapi.h due to a conflict with OpenSSL's safestack.h
338 #define KERB_WRAP_NO_ENCRYPT 0x80000001
340 #endif /* USE_WINDOWS_SSPI */
342 #endif /* HEADER_CURL_SSPI_H */