curl_sspi.h 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351
  1. #ifndef HEADER_CURL_SSPI_H
  2. #define HEADER_CURL_SSPI_H
  3. /***************************************************************************
  4. * _ _ ____ _
  5. * Project ___| | | | _ \| |
  6. * / __| | | | |_) | |
  7. * | (__| |_| | _ <| |___
  8. * \___|\___/|_| \_\_____|
  9. *
  10. * Copyright (C) Daniel Stenberg, <[email protected]>, et al.
  11. *
  12. * This software is licensed as described in the file COPYING, which
  13. * you should have received as part of this distribution. The terms
  14. * are also available at https://curl.se/docs/copyright.html.
  15. *
  16. * You may opt to use, copy, modify, merge, publish, distribute and/or sell
  17. * copies of the Software, and permit persons to whom the Software is
  18. * furnished to do so, under the terms of the COPYING file.
  19. *
  20. * This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY
  21. * KIND, either express or implied.
  22. *
  23. * SPDX-License-Identifier: curl
  24. *
  25. ***************************************************************************/
  26. #include "curl_setup.h"
  27. #ifdef USE_WINDOWS_SSPI
  28. #include <curl/curl.h>
  29. /*
  30. * When including the following three headers, it is mandatory to define either
  31. * SECURITY_WIN32 or SECURITY_KERNEL, indicating who is compiling the code.
  32. */
  33. #undef SECURITY_WIN32
  34. #undef SECURITY_KERNEL
  35. #define SECURITY_WIN32 1
  36. #include <security.h>
  37. #include <sspi.h>
  38. #include <rpc.h>
  39. CURLcode Curl_sspi_global_init(void);
  40. void Curl_sspi_global_cleanup(void);
  41. /* This is used to populate the domain in an SSPI identity structure */
  42. CURLcode Curl_override_sspi_http_realm(const char *chlg,
  43. SEC_WINNT_AUTH_IDENTITY *identity);
  44. /* This is used to generate an SSPI identity structure */
  45. CURLcode Curl_create_sspi_identity(const char *userp, const char *passwdp,
  46. SEC_WINNT_AUTH_IDENTITY *identity);
  47. /* This is used to free an SSPI identity structure */
  48. void Curl_sspi_free_identity(SEC_WINNT_AUTH_IDENTITY *identity);
  49. /* Forward-declaration of global variables defined in curl_sspi.c */
  50. extern PSecurityFunctionTable Curl_pSecFn;
  51. /* Provide some definitions missing in old headers */
  52. #define SP_NAME_DIGEST "WDigest"
  53. #define SP_NAME_NTLM "NTLM"
  54. #define SP_NAME_NEGOTIATE "Negotiate"
  55. #define SP_NAME_KERBEROS "Kerberos"
  56. /* Offered by mingw-w64 v9+. MS SDK 7.0A+. */
  57. #ifndef ISC_REQ_USE_HTTP_STYLE
  58. #define ISC_REQ_USE_HTTP_STYLE 0x01000000
  59. #endif
  60. #ifdef __MINGW32CE__
  61. #ifndef ISC_RET_REPLAY_DETECT
  62. #define ISC_RET_REPLAY_DETECT 0x00000004
  63. #endif
  64. #ifndef ISC_RET_SEQUENCE_DETECT
  65. #define ISC_RET_SEQUENCE_DETECT 0x00000008
  66. #endif
  67. #ifndef ISC_RET_CONFIDENTIALITY
  68. #define ISC_RET_CONFIDENTIALITY 0x00000010
  69. #endif
  70. #ifndef ISC_RET_ALLOCATED_MEMORY
  71. #define ISC_RET_ALLOCATED_MEMORY 0x00000100
  72. #endif
  73. #ifndef ISC_RET_STREAM
  74. #define ISC_RET_STREAM 0x00008000
  75. #endif
  76. #ifndef SEC_E_INSUFFICIENT_MEMORY
  77. #define SEC_E_INSUFFICIENT_MEMORY ((HRESULT)0x80090300L)
  78. #endif
  79. #ifndef SEC_E_INVALID_HANDLE
  80. #define SEC_E_INVALID_HANDLE ((HRESULT)0x80090301L)
  81. #endif
  82. #ifndef SEC_E_UNSUPPORTED_FUNCTION
  83. #define SEC_E_UNSUPPORTED_FUNCTION ((HRESULT)0x80090302L)
  84. #endif
  85. #ifndef SEC_E_TARGET_UNKNOWN
  86. #define SEC_E_TARGET_UNKNOWN ((HRESULT)0x80090303L)
  87. #endif
  88. #ifndef SEC_E_INTERNAL_ERROR
  89. #define SEC_E_INTERNAL_ERROR ((HRESULT)0x80090304L)
  90. #endif
  91. #ifndef SEC_E_SECPKG_NOT_FOUND
  92. #define SEC_E_SECPKG_NOT_FOUND ((HRESULT)0x80090305L)
  93. #endif
  94. #ifndef SEC_E_NOT_OWNER
  95. #define SEC_E_NOT_OWNER ((HRESULT)0x80090306L)
  96. #endif
  97. #ifndef SEC_E_CANNOT_INSTALL
  98. #define SEC_E_CANNOT_INSTALL ((HRESULT)0x80090307L)
  99. #endif
  100. #ifndef SEC_E_INVALID_TOKEN
  101. #define SEC_E_INVALID_TOKEN ((HRESULT)0x80090308L)
  102. #endif
  103. #ifndef SEC_E_CANNOT_PACK
  104. #define SEC_E_CANNOT_PACK ((HRESULT)0x80090309L)
  105. #endif
  106. #ifndef SEC_E_QOP_NOT_SUPPORTED
  107. #define SEC_E_QOP_NOT_SUPPORTED ((HRESULT)0x8009030AL)
  108. #endif
  109. #ifndef SEC_E_NO_IMPERSONATION
  110. #define SEC_E_NO_IMPERSONATION ((HRESULT)0x8009030BL)
  111. #endif
  112. #ifndef SEC_E_LOGON_DENIED
  113. #define SEC_E_LOGON_DENIED ((HRESULT)0x8009030CL)
  114. #endif
  115. #ifndef SEC_E_UNKNOWN_CREDENTIALS
  116. #define SEC_E_UNKNOWN_CREDENTIALS ((HRESULT)0x8009030DL)
  117. #endif
  118. #ifndef SEC_E_NO_CREDENTIALS
  119. #define SEC_E_NO_CREDENTIALS ((HRESULT)0x8009030EL)
  120. #endif
  121. #ifndef SEC_E_MESSAGE_ALTERED
  122. #define SEC_E_MESSAGE_ALTERED ((HRESULT)0x8009030FL)
  123. #endif
  124. #ifndef SEC_E_OUT_OF_SEQUENCE
  125. #define SEC_E_OUT_OF_SEQUENCE ((HRESULT)0x80090310L)
  126. #endif
  127. #ifndef SEC_E_NO_AUTHENTICATING_AUTHORITY
  128. #define SEC_E_NO_AUTHENTICATING_AUTHORITY ((HRESULT)0x80090311L)
  129. #endif
  130. #ifndef SEC_E_BAD_PKGID
  131. #define SEC_E_BAD_PKGID ((HRESULT)0x80090316L)
  132. #endif
  133. #ifndef SEC_E_CONTEXT_EXPIRED
  134. #define SEC_E_CONTEXT_EXPIRED ((HRESULT)0x80090317L)
  135. #endif
  136. #ifndef SEC_E_INCOMPLETE_MESSAGE
  137. #define SEC_E_INCOMPLETE_MESSAGE ((HRESULT)0x80090318L)
  138. #endif
  139. #ifndef SEC_E_INCOMPLETE_CREDENTIALS
  140. #define SEC_E_INCOMPLETE_CREDENTIALS ((HRESULT)0x80090320L)
  141. #endif
  142. #ifndef SEC_E_BUFFER_TOO_SMALL
  143. #define SEC_E_BUFFER_TOO_SMALL ((HRESULT)0x80090321L)
  144. #endif
  145. #ifndef SEC_E_WRONG_PRINCIPAL
  146. #define SEC_E_WRONG_PRINCIPAL ((HRESULT)0x80090322L)
  147. #endif
  148. #ifndef SEC_E_TIME_SKEW
  149. #define SEC_E_TIME_SKEW ((HRESULT)0x80090324L)
  150. #endif
  151. #ifndef SEC_E_UNTRUSTED_ROOT
  152. #define SEC_E_UNTRUSTED_ROOT ((HRESULT)0x80090325L)
  153. #endif
  154. #ifndef SEC_E_ILLEGAL_MESSAGE
  155. #define SEC_E_ILLEGAL_MESSAGE ((HRESULT)0x80090326L)
  156. #endif
  157. #ifndef SEC_E_CERT_UNKNOWN
  158. #define SEC_E_CERT_UNKNOWN ((HRESULT)0x80090327L)
  159. #endif
  160. #ifndef SEC_E_CERT_EXPIRED
  161. #define SEC_E_CERT_EXPIRED ((HRESULT)0x80090328L)
  162. #endif
  163. #ifndef SEC_E_ENCRYPT_FAILURE
  164. #define SEC_E_ENCRYPT_FAILURE ((HRESULT)0x80090329L)
  165. #endif
  166. #ifndef SEC_E_DECRYPT_FAILURE
  167. #define SEC_E_DECRYPT_FAILURE ((HRESULT)0x80090330L)
  168. #endif
  169. #ifndef SEC_E_ALGORITHM_MISMATCH
  170. #define SEC_E_ALGORITHM_MISMATCH ((HRESULT)0x80090331L)
  171. #endif
  172. #ifndef SEC_E_SECURITY_QOS_FAILED
  173. #define SEC_E_SECURITY_QOS_FAILED ((HRESULT)0x80090332L)
  174. #endif
  175. #ifndef SEC_E_UNFINISHED_CONTEXT_DELETED
  176. #define SEC_E_UNFINISHED_CONTEXT_DELETED ((HRESULT)0x80090333L)
  177. #endif
  178. #ifndef SEC_E_NO_TGT_REPLY
  179. #define SEC_E_NO_TGT_REPLY ((HRESULT)0x80090334L)
  180. #endif
  181. #ifndef SEC_E_NO_IP_ADDRESSES
  182. #define SEC_E_NO_IP_ADDRESSES ((HRESULT)0x80090335L)
  183. #endif
  184. #ifndef SEC_E_WRONG_CREDENTIAL_HANDLE
  185. #define SEC_E_WRONG_CREDENTIAL_HANDLE ((HRESULT)0x80090336L)
  186. #endif
  187. #ifndef SEC_E_CRYPTO_SYSTEM_INVALID
  188. #define SEC_E_CRYPTO_SYSTEM_INVALID ((HRESULT)0x80090337L)
  189. #endif
  190. #ifndef SEC_E_MAX_REFERRALS_EXCEEDED
  191. #define SEC_E_MAX_REFERRALS_EXCEEDED ((HRESULT)0x80090338L)
  192. #endif
  193. #ifndef SEC_E_MUST_BE_KDC
  194. #define SEC_E_MUST_BE_KDC ((HRESULT)0x80090339L)
  195. #endif
  196. #ifndef SEC_E_STRONG_CRYPTO_NOT_SUPPORTED
  197. #define SEC_E_STRONG_CRYPTO_NOT_SUPPORTED ((HRESULT)0x8009033AL)
  198. #endif
  199. #ifndef SEC_E_TOO_MANY_PRINCIPALS
  200. #define SEC_E_TOO_MANY_PRINCIPALS ((HRESULT)0x8009033BL)
  201. #endif
  202. #ifndef SEC_E_NO_PA_DATA
  203. #define SEC_E_NO_PA_DATA ((HRESULT)0x8009033CL)
  204. #endif
  205. #ifndef SEC_E_PKINIT_NAME_MISMATCH
  206. #define SEC_E_PKINIT_NAME_MISMATCH ((HRESULT)0x8009033DL)
  207. #endif
  208. #ifndef SEC_E_SMARTCARD_LOGON_REQUIRED
  209. #define SEC_E_SMARTCARD_LOGON_REQUIRED ((HRESULT)0x8009033EL)
  210. #endif
  211. #ifndef SEC_E_SHUTDOWN_IN_PROGRESS
  212. #define SEC_E_SHUTDOWN_IN_PROGRESS ((HRESULT)0x8009033FL)
  213. #endif
  214. #ifndef SEC_E_KDC_INVALID_REQUEST
  215. #define SEC_E_KDC_INVALID_REQUEST ((HRESULT)0x80090340L)
  216. #endif
  217. #ifndef SEC_E_KDC_UNABLE_TO_REFER
  218. #define SEC_E_KDC_UNABLE_TO_REFER ((HRESULT)0x80090341L)
  219. #endif
  220. #ifndef SEC_E_KDC_UNKNOWN_ETYPE
  221. #define SEC_E_KDC_UNKNOWN_ETYPE ((HRESULT)0x80090342L)
  222. #endif
  223. #ifndef SEC_E_UNSUPPORTED_PREAUTH
  224. #define SEC_E_UNSUPPORTED_PREAUTH ((HRESULT)0x80090343L)
  225. #endif
  226. #ifndef SEC_E_DELEGATION_REQUIRED
  227. #define SEC_E_DELEGATION_REQUIRED ((HRESULT)0x80090345L)
  228. #endif
  229. #ifndef SEC_E_BAD_BINDINGS
  230. #define SEC_E_BAD_BINDINGS ((HRESULT)0x80090346L)
  231. #endif
  232. #ifndef SEC_E_MULTIPLE_ACCOUNTS
  233. #define SEC_E_MULTIPLE_ACCOUNTS ((HRESULT)0x80090347L)
  234. #endif
  235. #ifndef SEC_E_NO_KERB_KEY
  236. #define SEC_E_NO_KERB_KEY ((HRESULT)0x80090348L)
  237. #endif
  238. #ifndef SEC_E_CERT_WRONG_USAGE
  239. #define SEC_E_CERT_WRONG_USAGE ((HRESULT)0x80090349L)
  240. #endif
  241. #ifndef SEC_E_DOWNGRADE_DETECTED
  242. #define SEC_E_DOWNGRADE_DETECTED ((HRESULT)0x80090350L)
  243. #endif
  244. #ifndef SEC_E_SMARTCARD_CERT_REVOKED
  245. #define SEC_E_SMARTCARD_CERT_REVOKED ((HRESULT)0x80090351L)
  246. #endif
  247. #ifndef SEC_E_ISSUING_CA_UNTRUSTED
  248. #define SEC_E_ISSUING_CA_UNTRUSTED ((HRESULT)0x80090352L)
  249. #endif
  250. #ifndef SEC_E_REVOCATION_OFFLINE_C
  251. #define SEC_E_REVOCATION_OFFLINE_C ((HRESULT)0x80090353L)
  252. #endif
  253. #ifndef SEC_E_PKINIT_CLIENT_FAILURE
  254. #define SEC_E_PKINIT_CLIENT_FAILURE ((HRESULT)0x80090354L)
  255. #endif
  256. #ifndef SEC_E_SMARTCARD_CERT_EXPIRED
  257. #define SEC_E_SMARTCARD_CERT_EXPIRED ((HRESULT)0x80090355L)
  258. #endif
  259. #ifndef SEC_E_NO_S4U_PROT_SUPPORT
  260. #define SEC_E_NO_S4U_PROT_SUPPORT ((HRESULT)0x80090356L)
  261. #endif
  262. #ifndef SEC_E_CROSSREALM_DELEGATION_FAILURE
  263. #define SEC_E_CROSSREALM_DELEGATION_FAILURE ((HRESULT)0x80090357L)
  264. #endif
  265. #ifndef SEC_E_REVOCATION_OFFLINE_KDC
  266. #define SEC_E_REVOCATION_OFFLINE_KDC ((HRESULT)0x80090358L)
  267. #endif
  268. #ifndef SEC_E_ISSUING_CA_UNTRUSTED_KDC
  269. #define SEC_E_ISSUING_CA_UNTRUSTED_KDC ((HRESULT)0x80090359L)
  270. #endif
  271. #ifndef SEC_E_KDC_CERT_EXPIRED
  272. #define SEC_E_KDC_CERT_EXPIRED ((HRESULT)0x8009035AL)
  273. #endif
  274. #ifndef SEC_E_KDC_CERT_REVOKED
  275. #define SEC_E_KDC_CERT_REVOKED ((HRESULT)0x8009035BL)
  276. #endif
  277. #endif /* __MINGW32CE__ */
  278. /* Offered by mingw-w64 v8+. MS SDK 6.0A+. */
  279. #ifndef SEC_E_INVALID_PARAMETER
  280. #define SEC_E_INVALID_PARAMETER ((HRESULT)0x8009035DL)
  281. #endif
  282. /* Offered by mingw-w64 v8+. MS SDK 6.0A+. */
  283. #ifndef SEC_E_DELEGATION_POLICY
  284. #define SEC_E_DELEGATION_POLICY ((HRESULT)0x8009035EL)
  285. #endif
  286. /* Offered by mingw-w64 v8+. MS SDK 6.0A+. */
  287. #ifndef SEC_E_POLICY_NLTM_ONLY
  288. #define SEC_E_POLICY_NLTM_ONLY ((HRESULT)0x8009035FL)
  289. #endif
  290. #ifdef __MINGW32CE__
  291. #ifndef SEC_I_CONTINUE_NEEDED
  292. #define SEC_I_CONTINUE_NEEDED ((HRESULT)0x00090312L)
  293. #endif
  294. #ifndef SEC_I_COMPLETE_NEEDED
  295. #define SEC_I_COMPLETE_NEEDED ((HRESULT)0x00090313L)
  296. #endif
  297. #ifndef SEC_I_COMPLETE_AND_CONTINUE
  298. #define SEC_I_COMPLETE_AND_CONTINUE ((HRESULT)0x00090314L)
  299. #endif
  300. #ifndef SEC_I_LOCAL_LOGON
  301. #define SEC_I_LOCAL_LOGON ((HRESULT)0x00090315L)
  302. #endif
  303. #ifndef SEC_I_CONTEXT_EXPIRED
  304. #define SEC_I_CONTEXT_EXPIRED ((HRESULT)0x00090317L)
  305. #endif
  306. #ifndef SEC_I_INCOMPLETE_CREDENTIALS
  307. #define SEC_I_INCOMPLETE_CREDENTIALS ((HRESULT)0x00090320L)
  308. #endif
  309. #ifndef SEC_I_RENEGOTIATE
  310. #define SEC_I_RENEGOTIATE ((HRESULT)0x00090321L)
  311. #endif
  312. #ifndef SEC_I_NO_LSA_CONTEXT
  313. #define SEC_I_NO_LSA_CONTEXT ((HRESULT)0x00090323L)
  314. #endif
  315. #endif /* __MINGW32CE__ */
  316. /* Offered by mingw-w64 v8+. MS SDK 6.0A+. */
  317. #ifndef SEC_I_SIGNATURE_NEEDED
  318. #define SEC_I_SIGNATURE_NEEDED ((HRESULT)0x0009035CL)
  319. #endif
  320. #ifdef __MINGW32CE__
  321. #ifndef CRYPT_E_NOT_IN_REVOCATION_DATABASE
  322. #define CRYPT_E_NOT_IN_REVOCATION_DATABASE ((HRESULT)0x80092014L)
  323. #endif
  324. #endif /* __MINGW32CE__ */
  325. /*
  326. * Definitions required from ntsecapi.h are directly provided below this point
  327. * to avoid including ntsecapi.h due to a conflict with OpenSSL's safestack.h
  328. */
  329. #define KERB_WRAP_NO_ENCRYPT 0x80000001
  330. #endif /* USE_WINDOWS_SSPI */
  331. #endif /* HEADER_CURL_SSPI_H */