codekingpro/portable-devtools
114k
1import typing as t2 3if t.TYPE_CHECKING:4 from gssapi.raw.creds import Creds5 from gssapi.raw.named_tuples import CfxKeyData, Rfc1964KeyData6 from gssapi.raw.sec_contexts import SecurityContext7 8 9class Krb5LucidContext:10 """11 The base container returned by :meth:`krb5_export_lucid_sec_context` when12 an unknown version was requested.13 """14 15 16class Krb5LucidContextV1(Krb5LucidContext):17 """18 Kerberos context data returned by :meth:`krb5_export_lucid_sec_context`19 when version 1 was requested.20 """21 22 @property23 def version(self) -> t.Optional[int]:24 """The structure version number25 26 Returns:27 Optional[int]: the structure version number28 """29 30 @property31 def is_initiator(self) -> t.Optional[bool]:32 """Whether the context was the initiator33 34 Returns:35 Optional[bool]: ``True`` when the exported context was the36 initiator37 """38 39 @property40 def endtime(self) -> t.Optional[int]:41 """Expiration time of the context42 43 Returns:44 Optional[int]: the expiration time of the context45 """46 47 @property48 def send_seq(self) -> t.Optional[int]:49 """Sender sequence number50 51 Returns:52 Optional[int]: the sender sequence number53 """54 55 @property56 def recv_seq(self) -> t.Optional[int]:57 """Receiver sequence number58 59 Returns:60 Optional[int]: the receiver sequence number61 """62 63 @property64 def protocol(self) -> t.Optional[int]:65 """The protocol number66 67 If the protocol number is 0 then :attr:`rfc1964_kd` is set and68 :attr:`cfx_kd` is `None`. If the protocol number is 1 then the opposite69 is true.70 71 Protocol 0 refers to RFC1964 and 1 refers to RFC4121.72 73 Returns:74 Optional[int]: the protocol number75 """76 77 @property78 def rfc1964_kd(self) -> t.Optional["Rfc1964KeyData"]:79 """Keydata for protocol 0 (RFC1964)80 81 This will be set when :attr:`protocol` is ``0``.82 83 Returns:84 Optional[Rfc1964KeyData]: the RFC1964 key data85 """86 87 @property88 def cfx_kd(self) -> t.Optional["CfxKeyData"]:89 """Key data for protocol 1 (RFC4121)90 91 This will be set when :attr:`protocol` is ``1``.92 93 Returns:94 Optional[CfxKeyData]: the RFC4121 key data95 """96 97 98def krb5_ccache_name(99 name: t.Optional[bytes],100) -> bytes:101 """Set the default Kerberos Protocol credentials cache name.102 103 This method sets the default credentials cache name for use by he Kerberos104 mechanism. The default credentials cache is used by105 :meth:`~gssapi.raw.creds.acquire_cred` to create a GSS-API credential. It106 is also used by :meth:`~gssapi.raw.sec_contexts.init_sec_context` when107 `GSS_C_NO_CREDENTIAL` is specified.108 109 Note:110 Heimdal does not return the old name when called. It also does not111 reset the ccache lookup behaviour when setting to ``None``.112 113 Note:114 The return value may not be thread safe.115 116 Args:117 name (Optional[bytes]): the name to set as the new thread specific118 ccache name. Set to ``None`` to revert back to getting the ccache119 from the config/environment settings.120 121 Returns:122 bytes: the old name that was previously set123 124 Raises:125 ~gssapi.exceptions.GSSError126 """127 128 129def krb5_export_lucid_sec_context(130 context: "SecurityContext",131 version: int,132) -> Krb5LucidContext:133 """Returns a non-opaque version of the internal context info.134 135 Gets information about the Kerberos security context passed in. Currently136 only version 1 is known and supported by this library.137 138 Note:139 The context handle must not be used again by the caller after this140 call.141 142 Args:143 context (~gssapi.raw.sec_contexts.SecurityContext): the current144 security context145 version (int): the output structure version to export. Currently146 only 1 is supported.147 148 Returns:149 Krb5LucidContext: the non-opaque version context info150 151 Raises:152 ~gssapi.exceptions.GSSError153 """154 155 156def krb5_extract_authtime_from_sec_context(157 context: "SecurityContext",158) -> int:159 """Get the auth time for the security context.160 161 Gets the auth time for the established security context.162 163 Note:164 Heimdal can only get the authtime on the acceptor security context.165 MIT is able to get the authtime on both initiators and acceptors.166 167 Args:168 context (~gssapi.raw.sec_contexts.SecurityContext): the current169 security context170 171 Returns:172 int: the authtime173 174 Raises:175 ~gssapi.exceptions.GSSError176 """177 178 179def krb5_extract_authz_data_from_sec_context(180 context: "SecurityContext",181 ad_type: int,182) -> bytes:183 """Extracts Kerberos authorization data.184 185 Extracts authorization data that may be stored within the context.186 187 Note:188 Only operates on acceptor contexts.189 190 Args:191 context (~gssapi.raw.sec_contexts.SecurityContext): the current192 security context193 ad_type (int): the type of data to extract194 195 Returns:196 bytes: the raw authz data from the sec context197 198 Raises:199 ~gssapi.exceptions.GSSError200 """201 202 203def krb5_import_cred(204 cred_handle: "Creds",205 cache: t.Optional[int] = None,206 keytab_principal: t.Optional[int] = None,207 keytab: t.Optional[int] = None,208) -> None:209 """Import Krb5 credentials into GSSAPI credential.210 211 Imports the krb5 credentials (either or both of the keytab and cache) into212 the GSSAPI credential so it can be used within GSSAPI. The ccache is213 copied by reference and thus shared, so if the credential is destroyed,214 all users of cred_handle will fail.215 216 Args:217 cred_handle (Creds): the credential handle to import into218 cache (int): the krb5_ccache address pointer, as an int, to import219 from220 keytab_principal (int): the krb5_principal address pointer, as an int,221 of the credential to import222 keytab (int): the krb5_keytab address pointer, as an int, of the223 keytab to import224 225 Returns:226 None227 228 Raises:229 ~gssapi.exceptions.GSSError230 """231 232 233def krb5_get_tkt_flags(234 context: "SecurityContext",235) -> int:236 """Return ticket flags for the kerberos ticket.237 238 Return the ticket flags for the kerberos ticket received when239 authenticating the initiator.240 241 Note:242 Heimdal can only get the tkt flags on the acceptor security context.243 MIT is able to get the tkt flags on initiators and acceptors.244 245 Args:246 context (~gssapi.raw.sec_contexts.SecurityContext): the security247 context248 249 Returns:250 int: the ticket flags for the received kerberos ticket251 252 Raises:253 ~gssapi.exceptions.GSSError254 """255 256 257def krb5_set_allowable_enctypes(258 cred_handle: "Creds",259 ktypes: t.Iterable[int],260) -> None:261 """Limits the keys that can be exported.262 263 Called by a context initiator after acquiring the creds but before calling264 :meth:`~gssapi.raw.sec_contexts.init_sec_context` to restrict the set of265 enctypes which will be negotiated during context establisment to those in266 the provided list.267 268 Warning:269 The cred_handle should not be ``GSS_C_NO_CREDENTIAL``.270 271 Args:272 cred_hande (Creds): the credential handle273 ktypes (List[int]): list of enctypes allowed274 275 Returns:276 None277 278 Raises:279 ~gssapi.exceptions.GSSError280 """281 