|
| 1 | +#!/usr/bin/python |
| 2 | + |
| 3 | +# Author |
| 4 | +# ------ |
| 5 | +# Sylvain Monne |
| 6 | +# Contact : sylvain dot monne at solucom dot fr |
| 7 | +# http://twitter.com/bidord |
| 8 | + |
| 9 | +from collections import namedtuple |
| 10 | +import struct |
| 11 | +from struct import pack, unpack |
| 12 | + |
| 13 | +from util import gt2epoch, bitstring2int |
| 14 | +from krb5 import encode, Ticket, NT_PRINCIPAL |
| 15 | + |
| 16 | +CCacheCredential = namedtuple('CCacheCredential', 'client server key time is_skey tktflags addrs authdata ticket second_ticket') |
| 17 | +CCacheKeyblock = namedtuple('CCacheKeyblock', 'keytype etype keyvalue') |
| 18 | +CCacheTimes = namedtuple('CCacheTimes', 'authtime starttime endtime renew_till') |
| 19 | +CCacheAddress = namedtuple('CCacheAddress', 'addrtype addrdata') |
| 20 | +CCacheAuthdata = namedtuple('CCacheAuthdata', 'authtype authdata') |
| 21 | +CCachePrincipal = namedtuple('CCachePrincipal', 'name_type realm components') |
| 22 | + |
| 23 | +VERSION = 0x0504 |
| 24 | +DEFAULT_HEADER = '00010008ffffffff00000000'.decode('hex') |
| 25 | + |
| 26 | +class CCache(object): |
| 27 | + def __init__(self, primary_principal, credentials=[], header=DEFAULT_HEADER): |
| 28 | + if not isinstance(primary_principal, CCachePrincipal): |
| 29 | + if isinstance(primary_principal, basestring) and '@' in primary_principal: |
| 30 | + realm, user_name = primary_principal.split('@', 1) |
| 31 | + elif isinstance(primary_principal, tuple) and len(primary_principal) == 2: |
| 32 | + realm, user_name = primary_principal |
| 33 | + else: |
| 34 | + raise ValueError('Bad primary principal format: %r' % primary_principal) |
| 35 | + primary_principal = CCachePrincipal(NT_PRINCIPAL, realm, [user_name]) |
| 36 | + |
| 37 | + self.primary_principal = primary_principal |
| 38 | + self.credentials = credentials |
| 39 | + self.header = header |
| 40 | + |
| 41 | + @classmethod |
| 42 | + def load(cls, filename): |
| 43 | + fp = open(filename, 'rb') |
| 44 | + version, headerlen = unpack('>HH', fp.read(4)) |
| 45 | + if version != VERSION: |
| 46 | + raise ValueError('Unsupported version: 0x%04x' % version) |
| 47 | + header = fp.read(headerlen) |
| 48 | + primary_principal = cls.read_principal(fp) |
| 49 | + credentials = [] |
| 50 | + while True: |
| 51 | + try: |
| 52 | + credentials.append(cls.read_credential(fp)) |
| 53 | + except struct.error: |
| 54 | + break |
| 55 | + fp.close() |
| 56 | + return cls(primary_principal, credentials, header) |
| 57 | + |
| 58 | + def save(self, filename): |
| 59 | + fp = open(filename, 'wb') |
| 60 | + fp.write(pack('>HH', VERSION, len(self.header))) |
| 61 | + fp.write(self.header) |
| 62 | + self.write_principal(fp, self.primary_principal) |
| 63 | + for cred in self.credentials: |
| 64 | + self.write_credential(fp, cred) |
| 65 | + fp.close() |
| 66 | + |
| 67 | + def add_credential(self, newcred): |
| 68 | + for i in range(len(self.credentials)): |
| 69 | + if self.credentials[i].client == newcred.client and \ |
| 70 | + self.credentials[i].server == newcred.server: |
| 71 | + self.credentials[i] = newcred |
| 72 | + return |
| 73 | + self.credentials.append(newcred) |
| 74 | + |
| 75 | + @classmethod |
| 76 | + def read_string(cls, fp): |
| 77 | + length = unpack('>I', fp.read(4))[0] |
| 78 | + return fp.read(length) |
| 79 | + |
| 80 | + @classmethod |
| 81 | + def write_string(cls, fp, s): |
| 82 | + fp.write(pack('>I', len(s))) |
| 83 | + fp.write(s) |
| 84 | + |
| 85 | + @classmethod |
| 86 | + def read_principal(cls, fp): |
| 87 | + name_type, num_components = unpack('>II', fp.read(8)) |
| 88 | + realm = cls.read_string(fp) |
| 89 | + components = [cls.read_string(fp) for i in range(num_components)] |
| 90 | + return CCachePrincipal(name_type, realm, components) |
| 91 | + |
| 92 | + @classmethod |
| 93 | + def write_principal(cls, fp, p): |
| 94 | + fp.write(pack('>II', p.name_type, len(p.components))) |
| 95 | + cls.write_string(fp, p.realm) |
| 96 | + for comp in p.components: |
| 97 | + cls.write_string(fp, comp) |
| 98 | + |
| 99 | + @classmethod |
| 100 | + def read_keyblock(cls, fp): |
| 101 | + keytype, etype, keylen = unpack('>HHH', fp.read(6)) |
| 102 | + keyvalue = fp.read(keylen) |
| 103 | + return CCacheKeyblock(keytype, etype, keyvalue) |
| 104 | + |
| 105 | + @classmethod |
| 106 | + def write_keyblock(cls, fp, k): |
| 107 | + fp.write(pack('>HHH', k.keytype, k.etype, len(k.keyvalue))) |
| 108 | + fp.write(k.keyvalue) |
| 109 | + |
| 110 | + @classmethod |
| 111 | + def read_times(cls, fp): |
| 112 | + authtime, starttime, endtime, renew_till = unpack('>IIII', fp.read(16)) |
| 113 | + return CCacheTimes(authtime, starttime, endtime, renew_till) |
| 114 | + |
| 115 | + @classmethod |
| 116 | + def write_times(cls, fp, t): |
| 117 | + fp.write(pack('>IIII', t.authtime, t.starttime, t.endtime, t.renew_till)) |
| 118 | + |
| 119 | + @classmethod |
| 120 | + def read_address(cls, fp): |
| 121 | + addrtype = unpack('>H', fp.read(2))[0] |
| 122 | + addrdata = cls.read_string(fp) |
| 123 | + return CCacheAddress(addrtype, addrdata) |
| 124 | + |
| 125 | + @classmethod |
| 126 | + def write_address(cls, fp, a): |
| 127 | + fp.write(pack('>H', a.addrtype)) |
| 128 | + cls.write_string(fp, a.addrdata) |
| 129 | + |
| 130 | + @classmethod |
| 131 | + def read_credential(cls, fp): |
| 132 | + client = cls.read_principal(fp) |
| 133 | + server = cls.read_principal(fp) |
| 134 | + key = cls.read_keyblock(fp) |
| 135 | + time = cls.read_times(fp) |
| 136 | + is_skey, tktflags, num_address = unpack('>BII', fp.read(9)) |
| 137 | + addrs = [cls.read_address(fp) for i in range(num_address)] |
| 138 | + num_authdata = unpack('>I', fp.read(4))[0] |
| 139 | + authdata = [cls.read_authdata(fp) for i in range(num_authdata)] |
| 140 | + ticket = cls.read_string(fp) |
| 141 | + second_ticket = cls.read_string(fp) |
| 142 | + return CCacheCredential(client, server, key, time, is_skey, tktflags, |
| 143 | + addrs, authdata, ticket, second_ticket) |
| 144 | + |
| 145 | + @classmethod |
| 146 | + def write_credential(cls, fp, c): |
| 147 | + cls.write_principal(fp, c.client) |
| 148 | + cls.write_principal(fp, c.server) |
| 149 | + cls.write_keyblock(fp, c.key) |
| 150 | + cls.write_times(fp, c.time) |
| 151 | + fp.write(pack('>BII', c.is_skey, c.tktflags, len(c.addrs))) |
| 152 | + for addr in c.addrs: |
| 153 | + cls.write_address(fp, addr) |
| 154 | + fp.write(pack('>I', len(c.authdata))) |
| 155 | + for authdata in c.authdata: |
| 156 | + cls.write_authdata(fp, authdata) |
| 157 | + cls.write_string(fp, c.ticket) |
| 158 | + cls.write_string(fp, c.second_ticket) |
| 159 | + |
| 160 | +def get_tgt_cred(ccache): |
| 161 | + for credential in ccache.credentials: |
| 162 | + if credential.server.components[0] == 'krbtgt': |
| 163 | + return credential |
| 164 | + raise ValueError('No TGT in CCache!') |
| 165 | + |
| 166 | +def kdc_rep2ccache(kdc_rep, kdc_rep_enc): |
| 167 | + return CCacheCredential( |
| 168 | + client=CCachePrincipal( |
| 169 | + name_type=int(kdc_rep['cname']['name-type']), |
| 170 | + realm=str(kdc_rep['crealm']), |
| 171 | + components=[str(c) for c in kdc_rep['cname']['name-string']]), |
| 172 | + server=CCachePrincipal( |
| 173 | + name_type=int(kdc_rep_enc['sname']['name-type']), |
| 174 | + realm=str(kdc_rep_enc['srealm']), |
| 175 | + components=[str(c) for c in kdc_rep_enc['sname']['name-string']]), |
| 176 | + key=CCacheKeyblock( |
| 177 | + keytype=int(kdc_rep_enc['key']['keytype']), |
| 178 | + etype=0, |
| 179 | + keyvalue=str(kdc_rep_enc['key']['keyvalue'])), |
| 180 | + time=CCacheTimes( |
| 181 | + authtime=gt2epoch(str(kdc_rep_enc['authtime'])), |
| 182 | + starttime=gt2epoch(str(kdc_rep_enc['starttime'])), |
| 183 | + endtime=gt2epoch(str(kdc_rep_enc['endtime'])), |
| 184 | + renew_till=gt2epoch(str(kdc_rep_enc['renew-till']))), |
| 185 | + is_skey=0, |
| 186 | + tktflags=bitstring2int(kdc_rep_enc['flags']), |
| 187 | + addrs=[], |
| 188 | + authdata=[], |
| 189 | + ticket=encode(kdc_rep['ticket'].clone(tagSet=Ticket.tagSet, cloneValueFlag=True)), |
| 190 | + second_ticket='') |
0 commit comments