jdk/src/share/classes/sun/security/krb5/internal/ktab/KeyTab.java
author weijun
Sun, 01 May 2011 14:22:32 +0800
changeset 9542 6f715a596a2e
parent 9499 f3115698a012
child 11911 f960f3b33af3
permissions -rw-r--r--
7040916: DynamicKeyTab test fails on Windows Reviewed-by: xuelei
Ignore whitespace changes - Everywhere: Within whitespace: At end of lines:
2
90ce3da70b43 Initial load
duke
parents:
diff changeset
     1
/*
9035
1255eb81cc2f 7033660: Update copyright year to 2011 on any files changed in 2011
ohair
parents: 7977
diff changeset
     2
 * Copyright (c) 2000, 2011, Oracle and/or its affiliates. All rights reserved.
2
90ce3da70b43 Initial load
duke
parents:
diff changeset
     3
 * DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
90ce3da70b43 Initial load
duke
parents:
diff changeset
     4
 *
90ce3da70b43 Initial load
duke
parents:
diff changeset
     5
 * This code is free software; you can redistribute it and/or modify it
90ce3da70b43 Initial load
duke
parents:
diff changeset
     6
 * under the terms of the GNU General Public License version 2 only, as
5506
202f599c92aa 6943119: Rebrand source copyright notices
ohair
parents: 4168
diff changeset
     7
 * published by the Free Software Foundation.  Oracle designates this
2
90ce3da70b43 Initial load
duke
parents:
diff changeset
     8
 * particular file as subject to the "Classpath" exception as provided
5506
202f599c92aa 6943119: Rebrand source copyright notices
ohair
parents: 4168
diff changeset
     9
 * by Oracle in the LICENSE file that accompanied this code.
2
90ce3da70b43 Initial load
duke
parents:
diff changeset
    10
 *
90ce3da70b43 Initial load
duke
parents:
diff changeset
    11
 * This code is distributed in the hope that it will be useful, but WITHOUT
90ce3da70b43 Initial load
duke
parents:
diff changeset
    12
 * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
90ce3da70b43 Initial load
duke
parents:
diff changeset
    13
 * FITNESS FOR A PARTICULAR PURPOSE.  See the GNU General Public License
90ce3da70b43 Initial load
duke
parents:
diff changeset
    14
 * version 2 for more details (a copy is included in the LICENSE file that
90ce3da70b43 Initial load
duke
parents:
diff changeset
    15
 * accompanied this code).
90ce3da70b43 Initial load
duke
parents:
diff changeset
    16
 *
90ce3da70b43 Initial load
duke
parents:
diff changeset
    17
 * You should have received a copy of the GNU General Public License version
90ce3da70b43 Initial load
duke
parents:
diff changeset
    18
 * 2 along with this work; if not, write to the Free Software Foundation,
90ce3da70b43 Initial load
duke
parents:
diff changeset
    19
 * Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
90ce3da70b43 Initial load
duke
parents:
diff changeset
    20
 *
5506
202f599c92aa 6943119: Rebrand source copyright notices
ohair
parents: 4168
diff changeset
    21
 * Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
202f599c92aa 6943119: Rebrand source copyright notices
ohair
parents: 4168
diff changeset
    22
 * or visit www.oracle.com if you need additional information or have any
202f599c92aa 6943119: Rebrand source copyright notices
ohair
parents: 4168
diff changeset
    23
 * questions.
2
90ce3da70b43 Initial load
duke
parents:
diff changeset
    24
 */
90ce3da70b43 Initial load
duke
parents:
diff changeset
    25
90ce3da70b43 Initial load
duke
parents:
diff changeset
    26
/*
90ce3da70b43 Initial load
duke
parents:
diff changeset
    27
 *
90ce3da70b43 Initial load
duke
parents:
diff changeset
    28
 *  (C) Copyright IBM Corp. 1999 All Rights Reserved.
90ce3da70b43 Initial load
duke
parents:
diff changeset
    29
 *  Copyright 1997 The Open Group Research Institute.  All rights reserved.
90ce3da70b43 Initial load
duke
parents:
diff changeset
    30
 */
90ce3da70b43 Initial load
duke
parents:
diff changeset
    31
90ce3da70b43 Initial load
duke
parents:
diff changeset
    32
package sun.security.krb5.internal.ktab;
90ce3da70b43 Initial load
duke
parents:
diff changeset
    33
90ce3da70b43 Initial load
duke
parents:
diff changeset
    34
import sun.security.krb5.*;
90ce3da70b43 Initial load
duke
parents:
diff changeset
    35
import sun.security.krb5.internal.*;
90ce3da70b43 Initial load
duke
parents:
diff changeset
    36
import sun.security.krb5.internal.crypto.*;
90ce3da70b43 Initial load
duke
parents:
diff changeset
    37
import java.util.ArrayList;
90ce3da70b43 Initial load
duke
parents:
diff changeset
    38
import java.util.Arrays;
90ce3da70b43 Initial load
duke
parents:
diff changeset
    39
import java.io.IOException;
90ce3da70b43 Initial load
duke
parents:
diff changeset
    40
import java.io.FileInputStream;
90ce3da70b43 Initial load
duke
parents:
diff changeset
    41
import java.io.FileOutputStream;
90ce3da70b43 Initial load
duke
parents:
diff changeset
    42
import java.io.File;
9499
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
    43
import java.io.FileNotFoundException;
3626
78722c321f85 6867665: Problem with keytabs with multiple kvno's (key versions)
weijun
parents: 3317
diff changeset
    44
import java.util.Comparator;
7037
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
    45
import java.util.HashMap;
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
    46
import java.util.Map;
2
90ce3da70b43 Initial load
duke
parents:
diff changeset
    47
import java.util.StringTokenizer;
7037
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
    48
import java.util.Vector;
2
90ce3da70b43 Initial load
duke
parents:
diff changeset
    49
90ce3da70b43 Initial load
duke
parents:
diff changeset
    50
/**
90ce3da70b43 Initial load
duke
parents:
diff changeset
    51
 * This class represents key table. The key table functions deal with storing
90ce3da70b43 Initial load
duke
parents:
diff changeset
    52
 * and retrieving service keys for use in authentication exchanges.
90ce3da70b43 Initial load
duke
parents:
diff changeset
    53
 *
9499
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
    54
 * A KeyTab object is always constructed, if the file specified does not
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
    55
 * exist, it's still valid but empty. If there is an I/O error or file format
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
    56
 * error, it's invalid.
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
    57
 *
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
    58
 * The class is immutable on the read side (the write side is only used by
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
    59
 * the ktab tool).
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
    60
 *
2
90ce3da70b43 Initial load
duke
parents:
diff changeset
    61
 * @author Yanni Zhang
90ce3da70b43 Initial load
duke
parents:
diff changeset
    62
 */
90ce3da70b43 Initial load
duke
parents:
diff changeset
    63
public class KeyTab implements KeyTabConstants {
9499
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
    64
2
90ce3da70b43 Initial load
duke
parents:
diff changeset
    65
    private static final boolean DEBUG = Krb5.DEBUG;
9499
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
    66
    private static String defaultTabName = null;
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
    67
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
    68
    // Attention: Currently there is no way to remove a keytab from this map,
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
    69
    // this might lead to a memory leak.
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
    70
    private static Map<String,KeyTab> map = new HashMap<>();
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
    71
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
    72
    // KeyTab file does not exist. Note: a missing keytab is still valid
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
    73
    private boolean isMissing = false;
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
    74
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
    75
    // KeyTab file is invalid, possibly an I/O error or a file format error.
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
    76
    private boolean isValid = true;
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
    77
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
    78
    private final String tabName;
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
    79
    private long lastModified;
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
    80
    private int kt_vno;
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
    81
7977
f47f211cd627 7008713: diamond conversion of kerberos5 and security tools
smarks
parents: 7037
diff changeset
    82
    private Vector<KeyTabEntry> entries = new Vector<>();
2
90ce3da70b43 Initial load
duke
parents:
diff changeset
    83
9499
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
    84
    /**
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
    85
     * Constructs a KeyTab object.
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
    86
     *
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
    87
     * If there is any I/O error or format errot during the loading, the
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
    88
     * isValid flag is set to false, and all half-read entries are dismissed.
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
    89
     * @param filename path name for the keytab file, must not be null
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
    90
     */
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
    91
    private KeyTab(String filename) {
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
    92
        tabName = filename;
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
    93
        try {
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
    94
            lastModified = new File(tabName).lastModified();
9542
6f715a596a2e 7040916: DynamicKeyTab test fails on Windows
weijun
parents: 9499
diff changeset
    95
            try (KeyTabInputStream kis =
6f715a596a2e 7040916: DynamicKeyTab test fails on Windows
weijun
parents: 9499
diff changeset
    96
                    new KeyTabInputStream(new FileInputStream(filename))) {
6f715a596a2e 7040916: DynamicKeyTab test fails on Windows
weijun
parents: 9499
diff changeset
    97
                load(kis);
6f715a596a2e 7040916: DynamicKeyTab test fails on Windows
weijun
parents: 9499
diff changeset
    98
            }
9499
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
    99
        } catch (FileNotFoundException e) {
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   100
            entries.clear();
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   101
            isMissing = true;
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   102
        } catch (Exception ioe) {
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   103
            entries.clear();
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   104
            isValid = false;
2
90ce3da70b43 Initial load
duke
parents:
diff changeset
   105
        }
90ce3da70b43 Initial load
duke
parents:
diff changeset
   106
    }
90ce3da70b43 Initial load
duke
parents:
diff changeset
   107
90ce3da70b43 Initial load
duke
parents:
diff changeset
   108
    /**
9499
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   109
     * Read a keytab file. Returns a new object and save it into cache when
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   110
     * new content (modified since last read) is available. If keytab file is
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   111
     * invalid, the old object will be returned. This is a safeguard for
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   112
     * partial-written keytab files or non-stable network. Please note that
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   113
     * a missing keytab is valid, which is equivalent to an empty keytab.
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   114
     *
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   115
     * @param s file name of keytab, must not be null
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   116
     * @return the keytab object, can be invalid, but never null.
2
90ce3da70b43 Initial load
duke
parents:
diff changeset
   117
     */
9499
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   118
    private synchronized static KeyTab getInstance0(String s) {
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   119
        long lm = new File(s).lastModified();
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   120
        KeyTab old = map.get(s);
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   121
        if (old != null && old.isValid() && old.lastModified == lm) {
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   122
            return old;
2
90ce3da70b43 Initial load
duke
parents:
diff changeset
   123
        }
9499
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   124
        KeyTab ktab = new KeyTab(s);
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   125
        if (ktab.isValid()) {               // A valid new keytab
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   126
            map.put(s, ktab);
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   127
            return ktab;
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   128
        } else if (old != null) {           // An existing old one
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   129
            return old;
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   130
        } else {
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   131
            return ktab;                    // first read is invalid
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   132
        }
2
90ce3da70b43 Initial load
duke
parents:
diff changeset
   133
    }
90ce3da70b43 Initial load
duke
parents:
diff changeset
   134
90ce3da70b43 Initial load
duke
parents:
diff changeset
   135
    /**
9499
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   136
     * Gets a KeyTab object.
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   137
     * @param s the key tab file name.
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   138
     * @return the KeyTab object, never null.
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   139
     */
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   140
    public static KeyTab getInstance(String s) {
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   141
        if (s == null) {
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   142
            return getInstance();
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   143
        } else {
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   144
            return getInstance0(s);
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   145
        }
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   146
    }
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   147
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   148
    /**
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   149
     * Gets a KeyTab object.
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   150
     * @param file the key tab file.
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   151
     * @return the KeyTab object, never null.
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   152
     */
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   153
    public static KeyTab getInstance(File file) {
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   154
        if (file == null) {
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   155
            return getInstance();
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   156
        } else {
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   157
            return getInstance0(file.getPath());
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   158
        }
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   159
    }
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   160
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   161
    /**
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   162
     * Gets the default KeyTab object.
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   163
     * @return the KeyTab object, never null.
2
90ce3da70b43 Initial load
duke
parents:
diff changeset
   164
     */
90ce3da70b43 Initial load
duke
parents:
diff changeset
   165
    public static KeyTab getInstance() {
9499
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   166
        return getInstance(getDefaultTabName());
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   167
    }
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   168
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   169
    public boolean isMissing() {
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   170
        return isMissing;
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   171
    }
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   172
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   173
    public boolean isValid() {
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   174
        return isValid;
2
90ce3da70b43 Initial load
duke
parents:
diff changeset
   175
    }
90ce3da70b43 Initial load
duke
parents:
diff changeset
   176
90ce3da70b43 Initial load
duke
parents:
diff changeset
   177
    /**
90ce3da70b43 Initial load
duke
parents:
diff changeset
   178
     * The location of keytab file will be read from the configuration file
90ce3da70b43 Initial load
duke
parents:
diff changeset
   179
     * If it is not specified, consider user.home as the keytab file's
90ce3da70b43 Initial load
duke
parents:
diff changeset
   180
     * default location.
9499
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   181
     * @return never null
2
90ce3da70b43 Initial load
duke
parents:
diff changeset
   182
     */
9499
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   183
    private static String getDefaultTabName() {
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   184
        if (defaultTabName != null) {
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   185
            return defaultTabName;
2
90ce3da70b43 Initial load
duke
parents:
diff changeset
   186
        } else {
90ce3da70b43 Initial load
duke
parents:
diff changeset
   187
            String kname = null;
90ce3da70b43 Initial load
duke
parents:
diff changeset
   188
            try {
90ce3da70b43 Initial load
duke
parents:
diff changeset
   189
                String keytab_names = Config.getInstance().getDefault
90ce3da70b43 Initial load
duke
parents:
diff changeset
   190
                    ("default_keytab_name", "libdefaults");
90ce3da70b43 Initial load
duke
parents:
diff changeset
   191
                if (keytab_names != null) {
90ce3da70b43 Initial load
duke
parents:
diff changeset
   192
                    StringTokenizer st = new StringTokenizer(keytab_names, " ");
90ce3da70b43 Initial load
duke
parents:
diff changeset
   193
                    while (st.hasMoreTokens()) {
90ce3da70b43 Initial load
duke
parents:
diff changeset
   194
                        kname = parse(st.nextToken());
9499
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   195
                        if (new File(kname).exists()) {
2
90ce3da70b43 Initial load
duke
parents:
diff changeset
   196
                            break;
90ce3da70b43 Initial load
duke
parents:
diff changeset
   197
                        }
90ce3da70b43 Initial load
duke
parents:
diff changeset
   198
                    }
90ce3da70b43 Initial load
duke
parents:
diff changeset
   199
                }
90ce3da70b43 Initial load
duke
parents:
diff changeset
   200
            } catch (KrbException e) {
90ce3da70b43 Initial load
duke
parents:
diff changeset
   201
                kname = null;
90ce3da70b43 Initial load
duke
parents:
diff changeset
   202
            }
90ce3da70b43 Initial load
duke
parents:
diff changeset
   203
90ce3da70b43 Initial load
duke
parents:
diff changeset
   204
            if (kname == null) {
90ce3da70b43 Initial load
duke
parents:
diff changeset
   205
                String user_home =
90ce3da70b43 Initial load
duke
parents:
diff changeset
   206
                        java.security.AccessController.doPrivileged(
90ce3da70b43 Initial load
duke
parents:
diff changeset
   207
                        new sun.security.action.GetPropertyAction("user.home"));
90ce3da70b43 Initial load
duke
parents:
diff changeset
   208
90ce3da70b43 Initial load
duke
parents:
diff changeset
   209
                if (user_home == null) {
90ce3da70b43 Initial load
duke
parents:
diff changeset
   210
                    user_home =
90ce3da70b43 Initial load
duke
parents:
diff changeset
   211
                        java.security.AccessController.doPrivileged(
90ce3da70b43 Initial load
duke
parents:
diff changeset
   212
                        new sun.security.action.GetPropertyAction("user.dir"));
90ce3da70b43 Initial load
duke
parents:
diff changeset
   213
                }
90ce3da70b43 Initial load
duke
parents:
diff changeset
   214
9499
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   215
                kname = user_home + File.separator  + "krb5.keytab";
2
90ce3da70b43 Initial load
duke
parents:
diff changeset
   216
            }
9499
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   217
            defaultTabName = kname;
2
90ce3da70b43 Initial load
duke
parents:
diff changeset
   218
            return kname;
90ce3da70b43 Initial load
duke
parents:
diff changeset
   219
        }
90ce3da70b43 Initial load
duke
parents:
diff changeset
   220
    }
90ce3da70b43 Initial load
duke
parents:
diff changeset
   221
9499
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   222
    /**
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   223
     * Parses some common keytab name formats
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   224
     * @param name never null
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   225
     * @return never null
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   226
     */
2
90ce3da70b43 Initial load
duke
parents:
diff changeset
   227
    private static String parse(String name) {
9499
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   228
        String kname;
2
90ce3da70b43 Initial load
duke
parents:
diff changeset
   229
        if ((name.length() >= 5) &&
90ce3da70b43 Initial load
duke
parents:
diff changeset
   230
            (name.substring(0, 5).equalsIgnoreCase("FILE:"))) {
90ce3da70b43 Initial load
duke
parents:
diff changeset
   231
            kname = name.substring(5);
90ce3da70b43 Initial load
duke
parents:
diff changeset
   232
        } else if ((name.length() >= 9) &&
90ce3da70b43 Initial load
duke
parents:
diff changeset
   233
                (name.substring(0, 9).equalsIgnoreCase("ANY:FILE:"))) {
90ce3da70b43 Initial load
duke
parents:
diff changeset
   234
            // this format found in MIT's krb5.ini.
90ce3da70b43 Initial load
duke
parents:
diff changeset
   235
            kname = name.substring(9);
90ce3da70b43 Initial load
duke
parents:
diff changeset
   236
        } else if ((name.length() >= 7) &&
90ce3da70b43 Initial load
duke
parents:
diff changeset
   237
                (name.substring(0, 7).equalsIgnoreCase("SRVTAB:"))) {
90ce3da70b43 Initial load
duke
parents:
diff changeset
   238
            // this format found in MIT's krb5.ini.
90ce3da70b43 Initial load
duke
parents:
diff changeset
   239
            kname = name.substring(7);
90ce3da70b43 Initial load
duke
parents:
diff changeset
   240
        } else
90ce3da70b43 Initial load
duke
parents:
diff changeset
   241
            kname = name;
90ce3da70b43 Initial load
duke
parents:
diff changeset
   242
        return kname;
90ce3da70b43 Initial load
duke
parents:
diff changeset
   243
    }
90ce3da70b43 Initial load
duke
parents:
diff changeset
   244
90ce3da70b43 Initial load
duke
parents:
diff changeset
   245
    private void load(KeyTabInputStream kis)
90ce3da70b43 Initial load
duke
parents:
diff changeset
   246
        throws IOException, RealmException {
90ce3da70b43 Initial load
duke
parents:
diff changeset
   247
90ce3da70b43 Initial load
duke
parents:
diff changeset
   248
        entries.clear();
90ce3da70b43 Initial load
duke
parents:
diff changeset
   249
        kt_vno = kis.readVersion();
90ce3da70b43 Initial load
duke
parents:
diff changeset
   250
        if (kt_vno == KRB5_KT_VNO_1) {
90ce3da70b43 Initial load
duke
parents:
diff changeset
   251
            kis.setNativeByteOrder();
90ce3da70b43 Initial load
duke
parents:
diff changeset
   252
        }
90ce3da70b43 Initial load
duke
parents:
diff changeset
   253
        int entryLength = 0;
90ce3da70b43 Initial load
duke
parents:
diff changeset
   254
        KeyTabEntry entry;
90ce3da70b43 Initial load
duke
parents:
diff changeset
   255
        while (kis.available() > 0) {
90ce3da70b43 Initial load
duke
parents:
diff changeset
   256
            entryLength = kis.readEntryLength();
90ce3da70b43 Initial load
duke
parents:
diff changeset
   257
            entry = kis.readEntry(entryLength, kt_vno);
90ce3da70b43 Initial load
duke
parents:
diff changeset
   258
            if (DEBUG) {
90ce3da70b43 Initial load
duke
parents:
diff changeset
   259
                System.out.println(">>> KeyTab: load() entry length: " +
90ce3da70b43 Initial load
duke
parents:
diff changeset
   260
                        entryLength + "; type: " +
90ce3da70b43 Initial load
duke
parents:
diff changeset
   261
                        (entry != null? entry.keyType : 0));
90ce3da70b43 Initial load
duke
parents:
diff changeset
   262
            }
90ce3da70b43 Initial load
duke
parents:
diff changeset
   263
            if (entry != null)
90ce3da70b43 Initial load
duke
parents:
diff changeset
   264
                entries.addElement(entry);
90ce3da70b43 Initial load
duke
parents:
diff changeset
   265
        }
90ce3da70b43 Initial load
duke
parents:
diff changeset
   266
    }
90ce3da70b43 Initial load
duke
parents:
diff changeset
   267
90ce3da70b43 Initial load
duke
parents:
diff changeset
   268
    /**
90ce3da70b43 Initial load
duke
parents:
diff changeset
   269
     * Reads all keys for a service from the keytab file that have
3626
78722c321f85 6867665: Problem with keytabs with multiple kvno's (key versions)
weijun
parents: 3317
diff changeset
   270
     * etypes that have been configured for use. If there are multiple
78722c321f85 6867665: Problem with keytabs with multiple kvno's (key versions)
weijun
parents: 3317
diff changeset
   271
     * keys with same etype, the one with the highest kvno is returned.
2
90ce3da70b43 Initial load
duke
parents:
diff changeset
   272
     * @param service the PrincipalName of the requested service
9499
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   273
     * @return an array containing all the service keys, never null
2
90ce3da70b43 Initial load
duke
parents:
diff changeset
   274
     */
90ce3da70b43 Initial load
duke
parents:
diff changeset
   275
    public EncryptionKey[] readServiceKeys(PrincipalName service) {
90ce3da70b43 Initial load
duke
parents:
diff changeset
   276
        KeyTabEntry entry;
90ce3da70b43 Initial load
duke
parents:
diff changeset
   277
        EncryptionKey key;
90ce3da70b43 Initial load
duke
parents:
diff changeset
   278
        int size = entries.size();
7977
f47f211cd627 7008713: diamond conversion of kerberos5 and security tools
smarks
parents: 7037
diff changeset
   279
        ArrayList<EncryptionKey> keys = new ArrayList<>(size);
7037
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   280
        for (int i = size-1; i >= 0; i--) {
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   281
            entry = entries.elementAt(i);
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   282
            if (entry.service.match(service)) {
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   283
                if (EType.isSupported(entry.keyType)) {
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   284
                    key = new EncryptionKey(entry.keyblock,
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   285
                                        entry.keyType,
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   286
                                        new Integer(entry.keyVersion));
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   287
                    keys.add(key);
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   288
                    if (DEBUG) {
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   289
                        System.out.println("Added key: " + entry.keyType +
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   290
                            "version: " + entry.keyVersion);
2
90ce3da70b43 Initial load
duke
parents:
diff changeset
   291
                    }
7037
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   292
                } else if (DEBUG) {
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   293
                    System.out.println("Found unsupported keytype (" +
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   294
                        entry.keyType + ") for " + service);
2
90ce3da70b43 Initial load
duke
parents:
diff changeset
   295
                }
90ce3da70b43 Initial load
duke
parents:
diff changeset
   296
            }
90ce3da70b43 Initial load
duke
parents:
diff changeset
   297
        }
90ce3da70b43 Initial load
duke
parents:
diff changeset
   298
        size = keys.size();
3626
78722c321f85 6867665: Problem with keytabs with multiple kvno's (key versions)
weijun
parents: 3317
diff changeset
   299
        EncryptionKey[] retVal = keys.toArray(new EncryptionKey[size]);
2
90ce3da70b43 Initial load
duke
parents:
diff changeset
   300
90ce3da70b43 Initial load
duke
parents:
diff changeset
   301
        // Sort keys according to default_tkt_enctypes
90ce3da70b43 Initial load
duke
parents:
diff changeset
   302
        if (DEBUG) {
90ce3da70b43 Initial load
duke
parents:
diff changeset
   303
            System.out.println("Ordering keys wrt default_tkt_enctypes list");
90ce3da70b43 Initial load
duke
parents:
diff changeset
   304
        }
3626
78722c321f85 6867665: Problem with keytabs with multiple kvno's (key versions)
weijun
parents: 3317
diff changeset
   305
78722c321f85 6867665: Problem with keytabs with multiple kvno's (key versions)
weijun
parents: 3317
diff changeset
   306
        final int[] etypes = EType.getDefaults("default_tkt_enctypes");
78722c321f85 6867665: Problem with keytabs with multiple kvno's (key versions)
weijun
parents: 3317
diff changeset
   307
78722c321f85 6867665: Problem with keytabs with multiple kvno's (key versions)
weijun
parents: 3317
diff changeset
   308
        // Sort the keys, k1 is preferred than k2 if:
78722c321f85 6867665: Problem with keytabs with multiple kvno's (key versions)
weijun
parents: 3317
diff changeset
   309
        // 1. k1's etype appears earlier in etypes than k2's
78722c321f85 6867665: Problem with keytabs with multiple kvno's (key versions)
weijun
parents: 3317
diff changeset
   310
        // 2. If same, k1's KVNO is higher
78722c321f85 6867665: Problem with keytabs with multiple kvno's (key versions)
weijun
parents: 3317
diff changeset
   311
        Arrays.sort(retVal, new Comparator<EncryptionKey>() {
78722c321f85 6867665: Problem with keytabs with multiple kvno's (key versions)
weijun
parents: 3317
diff changeset
   312
            @Override
78722c321f85 6867665: Problem with keytabs with multiple kvno's (key versions)
weijun
parents: 3317
diff changeset
   313
            public int compare(EncryptionKey o1, EncryptionKey o2) {
5974
f0531b7dfebe 6844907: krb5 etype order should be from strong to weak
weijun
parents: 5506
diff changeset
   314
                if (etypes != null) {
3626
78722c321f85 6867665: Problem with keytabs with multiple kvno's (key versions)
weijun
parents: 3317
diff changeset
   315
                    int o1EType = o1.getEType();
78722c321f85 6867665: Problem with keytabs with multiple kvno's (key versions)
weijun
parents: 3317
diff changeset
   316
                    int o2EType = o2.getEType();
78722c321f85 6867665: Problem with keytabs with multiple kvno's (key versions)
weijun
parents: 3317
diff changeset
   317
                    if (o1EType != o2EType) {
78722c321f85 6867665: Problem with keytabs with multiple kvno's (key versions)
weijun
parents: 3317
diff changeset
   318
                        for (int i=0; i<etypes.length; i++) {
78722c321f85 6867665: Problem with keytabs with multiple kvno's (key versions)
weijun
parents: 3317
diff changeset
   319
                            if (etypes[i] == o1EType) {
78722c321f85 6867665: Problem with keytabs with multiple kvno's (key versions)
weijun
parents: 3317
diff changeset
   320
                                return -1;
78722c321f85 6867665: Problem with keytabs with multiple kvno's (key versions)
weijun
parents: 3317
diff changeset
   321
                            } else if (etypes[i] == o2EType) {
78722c321f85 6867665: Problem with keytabs with multiple kvno's (key versions)
weijun
parents: 3317
diff changeset
   322
                                return 1;
78722c321f85 6867665: Problem with keytabs with multiple kvno's (key versions)
weijun
parents: 3317
diff changeset
   323
                            }
2
90ce3da70b43 Initial load
duke
parents:
diff changeset
   324
                        }
5974
f0531b7dfebe 6844907: krb5 etype order should be from strong to weak
weijun
parents: 5506
diff changeset
   325
                        // Neither o1EType nor o2EType in default_tkt_enctypes,
f0531b7dfebe 6844907: krb5 etype order should be from strong to weak
weijun
parents: 5506
diff changeset
   326
                        // therefore won't be used in AS-REQ. We do not care
f0531b7dfebe 6844907: krb5 etype order should be from strong to weak
weijun
parents: 5506
diff changeset
   327
                        // about their order, use kvno is OK.
2
90ce3da70b43 Initial load
duke
parents:
diff changeset
   328
                    }
90ce3da70b43 Initial load
duke
parents:
diff changeset
   329
                }
3626
78722c321f85 6867665: Problem with keytabs with multiple kvno's (key versions)
weijun
parents: 3317
diff changeset
   330
                return o2.getKeyVersionNumber().intValue()
78722c321f85 6867665: Problem with keytabs with multiple kvno's (key versions)
weijun
parents: 3317
diff changeset
   331
                        - o1.getKeyVersionNumber().intValue();
2
90ce3da70b43 Initial load
duke
parents:
diff changeset
   332
            }
3626
78722c321f85 6867665: Problem with keytabs with multiple kvno's (key versions)
weijun
parents: 3317
diff changeset
   333
        });
78722c321f85 6867665: Problem with keytabs with multiple kvno's (key versions)
weijun
parents: 3317
diff changeset
   334
2
90ce3da70b43 Initial load
duke
parents:
diff changeset
   335
        return retVal;
90ce3da70b43 Initial load
duke
parents:
diff changeset
   336
    }
90ce3da70b43 Initial load
duke
parents:
diff changeset
   337
90ce3da70b43 Initial load
duke
parents:
diff changeset
   338
90ce3da70b43 Initial load
duke
parents:
diff changeset
   339
90ce3da70b43 Initial load
duke
parents:
diff changeset
   340
    /**
90ce3da70b43 Initial load
duke
parents:
diff changeset
   341
     * Searches for the service entry in the keytab file.
90ce3da70b43 Initial load
duke
parents:
diff changeset
   342
     * The etype of the key must be one that has been configured
90ce3da70b43 Initial load
duke
parents:
diff changeset
   343
     * to be used.
90ce3da70b43 Initial load
duke
parents:
diff changeset
   344
     * @param service the PrincipalName of the requested service.
90ce3da70b43 Initial load
duke
parents:
diff changeset
   345
     * @return true if the entry is found, otherwise, return false.
90ce3da70b43 Initial load
duke
parents:
diff changeset
   346
     */
90ce3da70b43 Initial load
duke
parents:
diff changeset
   347
    public boolean findServiceEntry(PrincipalName service) {
90ce3da70b43 Initial load
duke
parents:
diff changeset
   348
        KeyTabEntry entry;
7037
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   349
        for (int i = 0; i < entries.size(); i++) {
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   350
            entry = entries.elementAt(i);
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   351
            if (entry.service.match(service)) {
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   352
                if (EType.isSupported(entry.keyType)) {
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   353
                    return true;
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   354
                } else if (DEBUG) {
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   355
                    System.out.println("Found unsupported keytype (" +
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   356
                        entry.keyType + ") for " + service);
2
90ce3da70b43 Initial load
duke
parents:
diff changeset
   357
                }
90ce3da70b43 Initial load
duke
parents:
diff changeset
   358
            }
90ce3da70b43 Initial load
duke
parents:
diff changeset
   359
        }
90ce3da70b43 Initial load
duke
parents:
diff changeset
   360
        return false;
90ce3da70b43 Initial load
duke
parents:
diff changeset
   361
    }
90ce3da70b43 Initial load
duke
parents:
diff changeset
   362
9499
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   363
    public String tabName() {
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   364
        return tabName;
2
90ce3da70b43 Initial load
duke
parents:
diff changeset
   365
    }
90ce3da70b43 Initial load
duke
parents:
diff changeset
   366
9499
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   367
    /////////////////// THE WRITE SIDE ///////////////////////
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   368
    /////////////// only used by ktab tool //////////////////
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   369
2
90ce3da70b43 Initial load
duke
parents:
diff changeset
   370
    /**
90ce3da70b43 Initial load
duke
parents:
diff changeset
   371
     * Adds a new entry in the key table.
90ce3da70b43 Initial load
duke
parents:
diff changeset
   372
     * @param service the service which will have a new entry in the key table.
90ce3da70b43 Initial load
duke
parents:
diff changeset
   373
     * @param psswd the password which generates the key.
7037
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   374
     * @param kvno the kvno to use, -1 means automatic increasing
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   375
     * @param append false if entries with old kvno would be removed.
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   376
     * Note: if kvno is not -1, entries with the same kvno are always removed
2
90ce3da70b43 Initial load
duke
parents:
diff changeset
   377
     */
7037
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   378
    public void addEntry(PrincipalName service, char[] psswd,
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   379
            int kvno, boolean append) throws KrbException {
2
90ce3da70b43 Initial load
duke
parents:
diff changeset
   380
90ce3da70b43 Initial load
duke
parents:
diff changeset
   381
        EncryptionKey[] encKeys = EncryptionKey.acquireSecretKeys(
90ce3da70b43 Initial load
duke
parents:
diff changeset
   382
            psswd, service.getSalt());
90ce3da70b43 Initial load
duke
parents:
diff changeset
   383
7037
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   384
        // There should be only one maximum KVNO value for all etypes, so that
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   385
        // all added keys can have the same KVNO.
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   386
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   387
        int maxKvno = 0;    // only useful when kvno == -1
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   388
        for (int i = entries.size()-1; i >= 0; i--) {
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   389
            KeyTabEntry e = entries.get(i);
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   390
            if (e.service.match(service)) {
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   391
                if (e.keyVersion > maxKvno) {
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   392
                    maxKvno = e.keyVersion;
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   393
                }
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   394
                if (!append || e.keyVersion == kvno) {
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   395
                    entries.removeElementAt(i);
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   396
                }
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   397
            }
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   398
        }
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   399
        if (kvno == -1) {
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   400
            kvno = maxKvno + 1;
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   401
        }
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   402
2
90ce3da70b43 Initial load
duke
parents:
diff changeset
   403
        for (int i = 0; encKeys != null && i < encKeys.length; i++) {
90ce3da70b43 Initial load
duke
parents:
diff changeset
   404
            int keyType = encKeys[i].getEType();
90ce3da70b43 Initial load
duke
parents:
diff changeset
   405
            byte[] keyValue = encKeys[i].getBytes();
90ce3da70b43 Initial load
duke
parents:
diff changeset
   406
90ce3da70b43 Initial load
duke
parents:
diff changeset
   407
            KeyTabEntry newEntry = new KeyTabEntry(service,
90ce3da70b43 Initial load
duke
parents:
diff changeset
   408
                            service.getRealm(),
90ce3da70b43 Initial load
duke
parents:
diff changeset
   409
                            new KerberosTime(System.currentTimeMillis()),
90ce3da70b43 Initial load
duke
parents:
diff changeset
   410
                                               kvno, keyType, keyValue);
90ce3da70b43 Initial load
duke
parents:
diff changeset
   411
            entries.addElement(newEntry);
90ce3da70b43 Initial load
duke
parents:
diff changeset
   412
        }
90ce3da70b43 Initial load
duke
parents:
diff changeset
   413
    }
90ce3da70b43 Initial load
duke
parents:
diff changeset
   414
4168
1a8d21bb898c 6893158: AP_REQ check should use key version number
weijun
parents: 3626
diff changeset
   415
    /**
2
90ce3da70b43 Initial load
duke
parents:
diff changeset
   416
     * Gets the list of service entries in key table.
90ce3da70b43 Initial load
duke
parents:
diff changeset
   417
     * @return array of <code>KeyTabEntry</code>.
90ce3da70b43 Initial load
duke
parents:
diff changeset
   418
     */
90ce3da70b43 Initial load
duke
parents:
diff changeset
   419
    public KeyTabEntry[] getEntries() {
7037
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   420
        KeyTabEntry[] kentries = new KeyTabEntry[entries.size()];
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   421
        for (int i = 0; i < kentries.length; i++) {
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   422
            kentries[i] = entries.elementAt(i);
2
90ce3da70b43 Initial load
duke
parents:
diff changeset
   423
        }
7037
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   424
        return kentries;
2
90ce3da70b43 Initial load
duke
parents:
diff changeset
   425
    }
90ce3da70b43 Initial load
duke
parents:
diff changeset
   426
90ce3da70b43 Initial load
duke
parents:
diff changeset
   427
    /**
90ce3da70b43 Initial load
duke
parents:
diff changeset
   428
     * Creates a new default key table.
90ce3da70b43 Initial load
duke
parents:
diff changeset
   429
     */
90ce3da70b43 Initial load
duke
parents:
diff changeset
   430
    public synchronized static KeyTab create()
90ce3da70b43 Initial load
duke
parents:
diff changeset
   431
        throws IOException, RealmException {
9499
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   432
        String dname = getDefaultTabName();
2
90ce3da70b43 Initial load
duke
parents:
diff changeset
   433
        return create(dname);
90ce3da70b43 Initial load
duke
parents:
diff changeset
   434
    }
90ce3da70b43 Initial load
duke
parents:
diff changeset
   435
90ce3da70b43 Initial load
duke
parents:
diff changeset
   436
    /**
90ce3da70b43 Initial load
duke
parents:
diff changeset
   437
     * Creates a new default key table.
90ce3da70b43 Initial load
duke
parents:
diff changeset
   438
     */
90ce3da70b43 Initial load
duke
parents:
diff changeset
   439
    public synchronized static KeyTab create(String name)
90ce3da70b43 Initial load
duke
parents:
diff changeset
   440
        throws IOException, RealmException {
90ce3da70b43 Initial load
duke
parents:
diff changeset
   441
9542
6f715a596a2e 7040916: DynamicKeyTab test fails on Windows
weijun
parents: 9499
diff changeset
   442
        try (KeyTabOutputStream kos =
6f715a596a2e 7040916: DynamicKeyTab test fails on Windows
weijun
parents: 9499
diff changeset
   443
                new KeyTabOutputStream(new FileOutputStream(name))) {
6f715a596a2e 7040916: DynamicKeyTab test fails on Windows
weijun
parents: 9499
diff changeset
   444
            kos.writeVersion(KRB5_KT_VNO);
6f715a596a2e 7040916: DynamicKeyTab test fails on Windows
weijun
parents: 9499
diff changeset
   445
        }
9499
f3115698a012 6894072: always refresh keytab
weijun
parents: 9035
diff changeset
   446
        return new KeyTab(name);
2
90ce3da70b43 Initial load
duke
parents:
diff changeset
   447
    }
90ce3da70b43 Initial load
duke
parents:
diff changeset
   448
90ce3da70b43 Initial load
duke
parents:
diff changeset
   449
    /**
90ce3da70b43 Initial load
duke
parents:
diff changeset
   450
     * Saves the file at the directory.
90ce3da70b43 Initial load
duke
parents:
diff changeset
   451
     */
90ce3da70b43 Initial load
duke
parents:
diff changeset
   452
    public synchronized void save() throws IOException {
9542
6f715a596a2e 7040916: DynamicKeyTab test fails on Windows
weijun
parents: 9499
diff changeset
   453
        try (KeyTabOutputStream kos =
6f715a596a2e 7040916: DynamicKeyTab test fails on Windows
weijun
parents: 9499
diff changeset
   454
                new KeyTabOutputStream(new FileOutputStream(tabName))) {
6f715a596a2e 7040916: DynamicKeyTab test fails on Windows
weijun
parents: 9499
diff changeset
   455
            kos.writeVersion(kt_vno);
6f715a596a2e 7040916: DynamicKeyTab test fails on Windows
weijun
parents: 9499
diff changeset
   456
            for (int i = 0; i < entries.size(); i++) {
6f715a596a2e 7040916: DynamicKeyTab test fails on Windows
weijun
parents: 9499
diff changeset
   457
                kos.writeEntry(entries.elementAt(i));
6f715a596a2e 7040916: DynamicKeyTab test fails on Windows
weijun
parents: 9499
diff changeset
   458
            }
2
90ce3da70b43 Initial load
duke
parents:
diff changeset
   459
        }
90ce3da70b43 Initial load
duke
parents:
diff changeset
   460
    }
90ce3da70b43 Initial load
duke
parents:
diff changeset
   461
90ce3da70b43 Initial load
duke
parents:
diff changeset
   462
    /**
7037
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   463
     * Removes entries from the key table.
2
90ce3da70b43 Initial load
duke
parents:
diff changeset
   464
     * @param service the service <code>PrincipalName</code>.
7037
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   465
     * @param etype the etype to match, remove all if -1
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   466
     * @param kvno what kvno to remove, -1 for all, -2 for old
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   467
     * @return the number of entries deleted
2
90ce3da70b43 Initial load
duke
parents:
diff changeset
   468
     */
7037
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   469
    public int deleteEntries(PrincipalName service, int etype, int kvno) {
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   470
        int count = 0;
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   471
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   472
        // Remember the highest KVNO for each etype. Used for kvno == -2
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   473
        Map<Integer,Integer> highest = new HashMap<>();
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   474
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   475
        for (int i = entries.size()-1; i >= 0; i--) {
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   476
            KeyTabEntry e = entries.get(i);
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   477
            if (service.match(e.getService())) {
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   478
                if (etype == -1 || e.keyType == etype) {
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   479
                    if (kvno == -2) {
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   480
                        // Two rounds for kvno == -2. In the first round (here),
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   481
                        // only find out highest KVNO for each etype
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   482
                        if (highest.containsKey(e.keyType)) {
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   483
                            int n = highest.get(e.keyType);
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   484
                            if (e.keyVersion > n) {
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   485
                                highest.put(e.keyType, e.keyVersion);
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   486
                            }
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   487
                        } else {
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   488
                            highest.put(e.keyType, e.keyVersion);
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   489
                        }
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   490
                    } else if (kvno == -1 || e.keyVersion == kvno) {
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   491
                        entries.removeElementAt(i);
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   492
                        count++;
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   493
                    }
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   494
                }
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   495
            }
2
90ce3da70b43 Initial load
duke
parents:
diff changeset
   496
        }
3317
a1ea2f1893f9 6854308: more ktab options
weijun
parents: 2
diff changeset
   497
7037
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   498
        // Second round for kvno == -2, remove old entries
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   499
        if (kvno == -2) {
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   500
            for (int i = entries.size()-1; i >= 0; i--) {
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   501
                KeyTabEntry e = entries.get(i);
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   502
                if (service.match(e.getService())) {
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   503
                    if (etype == -1 || e.keyType == etype) {
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   504
                        int n = highest.get(e.keyType);
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   505
                        if (e.keyVersion != n) {
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   506
                            entries.removeElementAt(i);
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   507
                            count++;
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   508
                        }
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   509
                    }
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   510
                }
9fd3887c8010 6950546: "ktab -d name etype" to "ktab -d name [-e etype] [kvno | all | old]"
weijun
parents: 5974
diff changeset
   511
            }
3317
a1ea2f1893f9 6854308: more ktab options
weijun
parents: 2
diff changeset
   512
        }
a1ea2f1893f9 6854308: more ktab options
weijun
parents: 2
diff changeset
   513
        return count;
2
90ce3da70b43 Initial load
duke
parents:
diff changeset
   514
    }
90ce3da70b43 Initial load
duke
parents:
diff changeset
   515
90ce3da70b43 Initial load
duke
parents:
diff changeset
   516
    /**
90ce3da70b43 Initial load
duke
parents:
diff changeset
   517
     * Creates key table file version.
90ce3da70b43 Initial load
duke
parents:
diff changeset
   518
     * @param file the key table file.
90ce3da70b43 Initial load
duke
parents:
diff changeset
   519
     * @exception IOException.
90ce3da70b43 Initial load
duke
parents:
diff changeset
   520
     */
90ce3da70b43 Initial load
duke
parents:
diff changeset
   521
    public synchronized void createVersion(File file) throws IOException {
9542
6f715a596a2e 7040916: DynamicKeyTab test fails on Windows
weijun
parents: 9499
diff changeset
   522
        try (KeyTabOutputStream kos =
6f715a596a2e 7040916: DynamicKeyTab test fails on Windows
weijun
parents: 9499
diff changeset
   523
                new KeyTabOutputStream(new FileOutputStream(file))) {
6f715a596a2e 7040916: DynamicKeyTab test fails on Windows
weijun
parents: 9499
diff changeset
   524
            kos.write16(KRB5_KT_VNO);
6f715a596a2e 7040916: DynamicKeyTab test fails on Windows
weijun
parents: 9499
diff changeset
   525
        }
2
90ce3da70b43 Initial load
duke
parents:
diff changeset
   526
    }
90ce3da70b43 Initial load
duke
parents:
diff changeset
   527
}