| | | 1 | | // Licensed to the .NET Foundation under one or more agreements. |
| | | 2 | | // The .NET Foundation licenses this file to you under the MIT license. |
| | | 3 | | |
| | | 4 | | using System.Buffers; |
| | | 5 | | using System.Buffers.Binary; |
| | | 6 | | using System.ComponentModel; |
| | | 7 | | using System.Diagnostics; |
| | | 8 | | using System.Diagnostics.CodeAnalysis; |
| | | 9 | | using System.Globalization; |
| | | 10 | | using System.Net.Security; |
| | | 11 | | using System.Runtime.InteropServices; |
| | | 12 | | using System.Security; |
| | | 13 | | using System.Security.Authentication.ExtendedProtection; |
| | | 14 | | using System.Security.Principal; |
| | | 15 | | |
| | | 16 | | namespace System.Net |
| | | 17 | | { |
| | | 18 | | internal partial class NegotiateAuthenticationPal |
| | | 19 | | { |
| | | 20 | | public static NegotiateAuthenticationPal Create(NegotiateAuthenticationClientOptions clientOptions) |
| | 0 | 21 | | { |
| | | 22 | | try |
| | 0 | 23 | | { |
| | 0 | 24 | | return new WindowsNegotiateAuthenticationPal(clientOptions); |
| | | 25 | | } |
| | 0 | 26 | | catch (NotSupportedException) |
| | 0 | 27 | | { |
| | 0 | 28 | | return new UnsupportedNegotiateAuthenticationPal(clientOptions); |
| | | 29 | | } |
| | 0 | 30 | | } |
| | | 31 | | |
| | | 32 | | public static NegotiateAuthenticationPal Create(NegotiateAuthenticationServerOptions serverOptions) |
| | 0 | 33 | | { |
| | | 34 | | try |
| | 0 | 35 | | { |
| | 0 | 36 | | return new WindowsNegotiateAuthenticationPal(serverOptions); |
| | | 37 | | } |
| | 0 | 38 | | catch (NotSupportedException) |
| | 0 | 39 | | { |
| | 0 | 40 | | return new UnsupportedNegotiateAuthenticationPal(serverOptions); |
| | | 41 | | } |
| | 0 | 42 | | } |
| | | 43 | | |
| | | 44 | | internal sealed class WindowsNegotiateAuthenticationPal : NegotiateAuthenticationPal |
| | | 45 | | { |
| | | 46 | | private bool _isServer; |
| | | 47 | | private bool _isAuthenticated; |
| | | 48 | | private int _tokenSize; |
| | | 49 | | private byte[]? _tokenBuffer; |
| | | 50 | | private SafeFreeCredentials? _credentialsHandle; |
| | | 51 | | private SafeDeleteContext? _securityContext; |
| | | 52 | | private Interop.SspiCli.ContextFlags _requestedContextFlags; |
| | | 53 | | private Interop.SspiCli.ContextFlags _contextFlags; |
| | | 54 | | private string _package; |
| | | 55 | | private string? _protocolName; |
| | | 56 | | private string? _spn; |
| | | 57 | | private ChannelBinding? _channelBinding; |
| | | 58 | | |
| | 0 | 59 | | public override bool IsAuthenticated => _isAuthenticated; |
| | | 60 | | |
| | 0 | 61 | | public override bool IsSigned => (_contextFlags & (_isServer ? Interop.SspiCli.ContextFlags.AcceptIntegrity |
| | | 62 | | |
| | 0 | 63 | | public override bool IsEncrypted => (_contextFlags & Interop.SspiCli.ContextFlags.Confidentiality) != 0; |
| | | 64 | | |
| | 0 | 65 | | public override bool IsMutuallyAuthenticated => (_contextFlags & Interop.SspiCli.ContextFlags.MutualAuth) != |
| | | 66 | | |
| | | 67 | | public override string Package |
| | | 68 | | { |
| | | 69 | | get |
| | 0 | 70 | | { |
| | | 71 | | // Note: May return string.Empty if the auth is not done yet or failed. |
| | 0 | 72 | | if (_protocolName == null) |
| | 0 | 73 | | { |
| | 0 | 74 | | string? negotiationAuthenticationPackage = null; |
| | | 75 | | |
| | 0 | 76 | | if (_securityContext is not null) |
| | 0 | 77 | | { |
| | 0 | 78 | | SecPkgContext_NegotiationInfoW ctx = default; |
| | 0 | 79 | | bool success = SSPIWrapper.QueryBlittableContextAttributes(GlobalSSPI.SSPIAuth, _securityCon |
| | 0 | 80 | | using (sspiHandle) |
| | 0 | 81 | | { |
| | 0 | 82 | | negotiationAuthenticationPackage = success ? NegotiationInfoClass.GetAuthenticationPacka |
| | 0 | 83 | | } |
| | 0 | 84 | | if (_isAuthenticated) |
| | 0 | 85 | | { |
| | 0 | 86 | | _protocolName = negotiationAuthenticationPackage; |
| | 0 | 87 | | } |
| | 0 | 88 | | } |
| | | 89 | | |
| | 0 | 90 | | return negotiationAuthenticationPackage ?? string.Empty; |
| | | 91 | | } |
| | | 92 | | |
| | 0 | 93 | | return _protocolName; |
| | 0 | 94 | | } |
| | | 95 | | } |
| | | 96 | | |
| | | 97 | | public override string? TargetName |
| | | 98 | | { |
| | | 99 | | get |
| | 0 | 100 | | { |
| | 0 | 101 | | if (_isServer && _spn == null) |
| | 0 | 102 | | { |
| | 0 | 103 | | Debug.Assert(_securityContext is not null && _isAuthenticated, "Trying to get the client SPN bef |
| | 0 | 104 | | _spn = SSPIWrapper.QueryStringContextAttributes(GlobalSSPI.SSPIAuth, _securityContext, Interop.S |
| | 0 | 105 | | if (NetEventSource.Log.IsEnabled()) NetEventSource.Info(this, $"The client specified SPN is [{_s |
| | 0 | 106 | | } |
| | 0 | 107 | | return _spn; |
| | 0 | 108 | | } |
| | | 109 | | } |
| | | 110 | | |
| | | 111 | | public override IIdentity RemoteIdentity |
| | | 112 | | { |
| | | 113 | | get |
| | 0 | 114 | | { |
| | | 115 | | IIdentity? result; |
| | 0 | 116 | | string? name = _isServer ? null : TargetName; |
| | 0 | 117 | | string protocol = Package; |
| | | 118 | | |
| | 0 | 119 | | Debug.Assert(_securityContext is not null); |
| | | 120 | | |
| | 0 | 121 | | if (_isServer) |
| | 0 | 122 | | { |
| | 0 | 123 | | SecurityContextTokenHandle? token = null; |
| | | 124 | | try |
| | 0 | 125 | | { |
| | 0 | 126 | | name = SSPIWrapper.QueryStringContextAttributes(GlobalSSPI.SSPIAuth, _securityContext, Inter |
| | 0 | 127 | | if (NetEventSource.Log.IsEnabled()) NetEventSource.Info(this, $"NTAuthentication: The contex |
| | | 128 | | |
| | | 129 | | // This will return a client token when conducted authentication on server side. |
| | | 130 | | // This token can be used for impersonation. We use it to create a WindowsIdentity and hand |
| | 0 | 131 | | Interop.SECURITY_STATUS winStatus = (Interop.SECURITY_STATUS)SSPIWrapper.QuerySecurityContex |
| | 0 | 132 | | GlobalSSPI.SSPIAuth, |
| | 0 | 133 | | _securityContext, |
| | 0 | 134 | | out token); |
| | 0 | 135 | | if (winStatus != Interop.SECURITY_STATUS.OK) |
| | 0 | 136 | | { |
| | 0 | 137 | | throw new Win32Exception((int)winStatus); |
| | | 138 | | } |
| | | 139 | | |
| | | 140 | | // The following call was also specifying WindowsAccountType.Normal, true. |
| | | 141 | | // WindowsIdentity.IsAuthenticated is no longer supported in .NET Core |
| | 0 | 142 | | result = new WindowsIdentity(token.DangerousGetHandle(), protocol); |
| | 0 | 143 | | return result; |
| | | 144 | | } |
| | 0 | 145 | | catch (SecurityException) |
| | 0 | 146 | | { |
| | | 147 | | // Ignore and construct generic Identity if failed due to security problem. |
| | 0 | 148 | | } |
| | | 149 | | finally |
| | 0 | 150 | | { |
| | 0 | 151 | | token?.Dispose(); |
| | 0 | 152 | | } |
| | 0 | 153 | | } |
| | | 154 | | |
| | | 155 | | // On the client we don't have access to the remote side identity. |
| | 0 | 156 | | result = new GenericIdentity(name ?? string.Empty, protocol); |
| | 0 | 157 | | return result; |
| | 0 | 158 | | } |
| | | 159 | | } |
| | | 160 | | |
| | | 161 | | public override System.Security.Principal.TokenImpersonationLevel ImpersonationLevel |
| | | 162 | | { |
| | | 163 | | get |
| | 0 | 164 | | { |
| | 0 | 165 | | return |
| | 0 | 166 | | (_contextFlags & Interop.SspiCli.ContextFlags.Delegate) != 0 && Package != NegotiationInfoClass. |
| | 0 | 167 | | (_contextFlags & (_isServer ? Interop.SspiCli.ContextFlags.AcceptIdentify : Interop.SspiCli.Cont |
| | 0 | 168 | | TokenImpersonationLevel.Impersonation; |
| | 0 | 169 | | } |
| | | 170 | | } |
| | | 171 | | |
| | 0 | 172 | | public WindowsNegotiateAuthenticationPal(NegotiateAuthenticationClientOptions clientOptions) |
| | 0 | 173 | | { |
| | 0 | 174 | | Interop.SspiCli.ContextFlags contextFlags = Interop.SspiCli.ContextFlags.Connection; |
| | | 175 | | |
| | 0 | 176 | | contextFlags |= clientOptions.RequiredProtectionLevel switch |
| | 0 | 177 | | { |
| | 0 | 178 | | ProtectionLevel.Sign => Interop.SspiCli.ContextFlags.InitIntegrity, |
| | 0 | 179 | | ProtectionLevel.EncryptAndSign => Interop.SspiCli.ContextFlags.InitIntegrity | Interop.SspiCli.Conte |
| | 0 | 180 | | _ => 0 |
| | 0 | 181 | | }; |
| | | 182 | | |
| | 0 | 183 | | contextFlags |= clientOptions.RequireMutualAuthentication ? Interop.SspiCli.ContextFlags.MutualAuth : 0; |
| | | 184 | | |
| | 0 | 185 | | contextFlags |= clientOptions.AllowedImpersonationLevel switch |
| | 0 | 186 | | { |
| | 0 | 187 | | TokenImpersonationLevel.Identification => Interop.SspiCli.ContextFlags.InitIdentify, |
| | 0 | 188 | | TokenImpersonationLevel.Delegation => Interop.SspiCli.ContextFlags.Delegate, |
| | 0 | 189 | | _ => 0 |
| | 0 | 190 | | }; |
| | | 191 | | |
| | 0 | 192 | | _isServer = false; |
| | 0 | 193 | | _tokenSize = SSPIWrapper.GetVerifyPackageInfo(GlobalSSPI.SSPIAuth, clientOptions.Package, true)!.MaxToke |
| | 0 | 194 | | _spn = clientOptions.TargetName; |
| | 0 | 195 | | _securityContext = null; |
| | 0 | 196 | | _requestedContextFlags = contextFlags; |
| | 0 | 197 | | _package = clientOptions.Package; |
| | 0 | 198 | | _channelBinding = clientOptions.Binding; |
| | | 199 | | |
| | 0 | 200 | | if (NetEventSource.Log.IsEnabled()) NetEventSource.Info(this, $"Peer SPN-> '{_spn}'"); |
| | | 201 | | |
| | | 202 | | // |
| | | 203 | | // Check if we're using DefaultCredentials. |
| | | 204 | | // |
| | | 205 | | |
| | 0 | 206 | | Debug.Assert(CredentialCache.DefaultCredentials == CredentialCache.DefaultNetworkCredentials); |
| | 0 | 207 | | if (clientOptions.Credential == CredentialCache.DefaultCredentials) |
| | 0 | 208 | | { |
| | 0 | 209 | | if (NetEventSource.Log.IsEnabled()) NetEventSource.Info(this, "using DefaultCredentials"); |
| | 0 | 210 | | _credentialsHandle = AcquireDefaultCredential(_package, _isServer); |
| | 0 | 211 | | } |
| | | 212 | | else |
| | 0 | 213 | | { |
| | 0 | 214 | | _credentialsHandle = AcquireCredentialsHandle(_package, _isServer, clientOptions.Credential); |
| | 0 | 215 | | } |
| | 0 | 216 | | } |
| | | 217 | | |
| | 0 | 218 | | public WindowsNegotiateAuthenticationPal(NegotiateAuthenticationServerOptions serverOptions) |
| | 0 | 219 | | { |
| | 0 | 220 | | Interop.SspiCli.ContextFlags contextFlags = serverOptions.RequiredProtectionLevel switch |
| | 0 | 221 | | { |
| | 0 | 222 | | ProtectionLevel.Sign => Interop.SspiCli.ContextFlags.AcceptIntegrity, |
| | 0 | 223 | | ProtectionLevel.EncryptAndSign => Interop.SspiCli.ContextFlags.AcceptIntegrity | Interop.SspiCli.Con |
| | 0 | 224 | | _ => 0 |
| | 0 | 225 | | } | Interop.SspiCli.ContextFlags.Connection; |
| | | 226 | | |
| | 0 | 227 | | if (serverOptions.Policy is not null) |
| | 0 | 228 | | { |
| | 0 | 229 | | if (serverOptions.Policy.PolicyEnforcement == PolicyEnforcement.WhenSupported) |
| | 0 | 230 | | { |
| | 0 | 231 | | contextFlags |= Interop.SspiCli.ContextFlags.AllowMissingBindings; |
| | 0 | 232 | | } |
| | | 233 | | |
| | 0 | 234 | | if (serverOptions.Policy.PolicyEnforcement != PolicyEnforcement.Never && |
| | 0 | 235 | | serverOptions.Policy.ProtectionScenario == ProtectionScenario.TrustedProxy) |
| | 0 | 236 | | { |
| | 0 | 237 | | contextFlags |= Interop.SspiCli.ContextFlags.ProxyBindings; |
| | 0 | 238 | | } |
| | 0 | 239 | | } |
| | | 240 | | |
| | 0 | 241 | | _isServer = true; |
| | 0 | 242 | | _tokenSize = SSPIWrapper.GetVerifyPackageInfo(GlobalSSPI.SSPIAuth, serverOptions.Package, true)!.MaxToke |
| | 0 | 243 | | _securityContext = null; |
| | 0 | 244 | | _requestedContextFlags = contextFlags; |
| | 0 | 245 | | _package = serverOptions.Package; |
| | 0 | 246 | | _channelBinding = serverOptions.Binding; |
| | | 247 | | |
| | 0 | 248 | | if (NetEventSource.Log.IsEnabled()) NetEventSource.Info(this, $"Peer SPN-> '{_spn}'"); |
| | | 249 | | |
| | | 250 | | // |
| | | 251 | | // Check if we're using DefaultCredentials. |
| | | 252 | | // |
| | | 253 | | |
| | 0 | 254 | | Debug.Assert(CredentialCache.DefaultCredentials == CredentialCache.DefaultNetworkCredentials); |
| | 0 | 255 | | if (serverOptions.Credential == CredentialCache.DefaultCredentials) |
| | 0 | 256 | | { |
| | 0 | 257 | | if (NetEventSource.Log.IsEnabled()) NetEventSource.Info(this, "using DefaultCredentials"); |
| | 0 | 258 | | _credentialsHandle = AcquireDefaultCredential(_package, _isServer); |
| | 0 | 259 | | } |
| | | 260 | | else |
| | 0 | 261 | | { |
| | 0 | 262 | | _credentialsHandle = AcquireCredentialsHandle(_package, _isServer, serverOptions.Credential); |
| | 0 | 263 | | } |
| | 0 | 264 | | } |
| | | 265 | | |
| | | 266 | | public override void Dispose() |
| | 0 | 267 | | { |
| | 0 | 268 | | _securityContext?.Dispose(); |
| | 0 | 269 | | } |
| | | 270 | | |
| | | 271 | | public override byte[]? GetOutgoingBlob(ReadOnlySpan<byte> incomingBlob, out NegotiateAuthenticationStatusCo |
| | 0 | 272 | | { |
| | 0 | 273 | | _tokenBuffer ??= _tokenSize == 0 ? Array.Empty<byte>() : new byte[_tokenSize]; |
| | | 274 | | |
| | 0 | 275 | | bool firstTime = _securityContext == null; |
| | | 276 | | int resultBlobLength; |
| | | 277 | | SecurityStatusPal platformStatusCode; |
| | | 278 | | try |
| | 0 | 279 | | { |
| | 0 | 280 | | if (!_isServer) |
| | 0 | 281 | | { |
| | | 282 | | // client session |
| | 0 | 283 | | platformStatusCode = InitializeSecurityContext( |
| | 0 | 284 | | ref _credentialsHandle!, |
| | 0 | 285 | | ref _securityContext, |
| | 0 | 286 | | _spn, |
| | 0 | 287 | | _requestedContextFlags, |
| | 0 | 288 | | incomingBlob, |
| | 0 | 289 | | _channelBinding, |
| | 0 | 290 | | ref _tokenBuffer, |
| | 0 | 291 | | out resultBlobLength, |
| | 0 | 292 | | ref _contextFlags); |
| | | 293 | | |
| | 0 | 294 | | if (NetEventSource.Log.IsEnabled()) NetEventSource.Info(this, $"SSPIWrapper.InitializeSecurityCo |
| | | 295 | | |
| | 0 | 296 | | if (platformStatusCode.ErrorCode == SecurityStatusPalErrorCode.CompleteNeeded) |
| | 0 | 297 | | { |
| | 0 | 298 | | platformStatusCode = CompleteAuthToken(ref _securityContext, _tokenBuffer.AsSpan(0, resultBl |
| | | 299 | | |
| | 0 | 300 | | if (NetEventSource.Log.IsEnabled()) NetEventSource.Info(this, $"SSPIWrapper.CompleteAuthToke |
| | | 301 | | |
| | 0 | 302 | | resultBlobLength = 0; |
| | 0 | 303 | | } |
| | 0 | 304 | | } |
| | | 305 | | else |
| | 0 | 306 | | { |
| | | 307 | | // Server session. |
| | 0 | 308 | | platformStatusCode = AcceptSecurityContext( |
| | 0 | 309 | | _credentialsHandle, |
| | 0 | 310 | | ref _securityContext, |
| | 0 | 311 | | _requestedContextFlags, |
| | 0 | 312 | | incomingBlob, |
| | 0 | 313 | | _channelBinding, |
| | 0 | 314 | | ref _tokenBuffer, |
| | 0 | 315 | | out resultBlobLength, |
| | 0 | 316 | | ref _contextFlags); |
| | | 317 | | |
| | 0 | 318 | | if (NetEventSource.Log.IsEnabled()) NetEventSource.Info(this, $"SSPIWrapper.AcceptSecurityContex |
| | 0 | 319 | | } |
| | 0 | 320 | | } |
| | | 321 | | finally |
| | 0 | 322 | | { |
| | | 323 | | // |
| | | 324 | | // Assuming the ISC or ASC has referenced the credential on the first successful call, |
| | | 325 | | // we want to decrement the effective ref count by "disposing" it. |
| | | 326 | | // The real dispose will happen when the security context is closed. |
| | | 327 | | // Note if the first call was not successful the handle is physically destroyed here. |
| | | 328 | | // |
| | 0 | 329 | | if (firstTime) |
| | 0 | 330 | | { |
| | 0 | 331 | | _credentialsHandle?.Dispose(); |
| | 0 | 332 | | } |
| | 0 | 333 | | } |
| | | 334 | | |
| | | 335 | | // Map error codes |
| | | 336 | | // TODO: Remove double mapping from Win32 codes |
| | 0 | 337 | | statusCode = platformStatusCode.ErrorCode switch |
| | 0 | 338 | | { |
| | 0 | 339 | | SecurityStatusPalErrorCode.OK => NegotiateAuthenticationStatusCode.Completed, |
| | 0 | 340 | | SecurityStatusPalErrorCode.ContinueNeeded => NegotiateAuthenticationStatusCode.ContinueNeeded, |
| | 0 | 341 | | |
| | 0 | 342 | | // These code should never be returned and they should be handled internally |
| | 0 | 343 | | SecurityStatusPalErrorCode.CompleteNeeded => NegotiateAuthenticationStatusCode.Completed, |
| | 0 | 344 | | SecurityStatusPalErrorCode.CompAndContinue => NegotiateAuthenticationStatusCode.ContinueNeeded, |
| | 0 | 345 | | |
| | 0 | 346 | | SecurityStatusPalErrorCode.ContextExpired => NegotiateAuthenticationStatusCode.ContextExpired, |
| | 0 | 347 | | SecurityStatusPalErrorCode.Unsupported => NegotiateAuthenticationStatusCode.Unsupported, |
| | 0 | 348 | | SecurityStatusPalErrorCode.PackageNotFound => NegotiateAuthenticationStatusCode.Unsupported, |
| | 0 | 349 | | SecurityStatusPalErrorCode.CannotInstall => NegotiateAuthenticationStatusCode.Unsupported, |
| | 0 | 350 | | SecurityStatusPalErrorCode.InvalidToken => NegotiateAuthenticationStatusCode.InvalidToken, |
| | 0 | 351 | | SecurityStatusPalErrorCode.QopNotSupported => NegotiateAuthenticationStatusCode.QopNotSupported, |
| | 0 | 352 | | SecurityStatusPalErrorCode.NoImpersonation => NegotiateAuthenticationStatusCode.UnknownCredentials, |
| | 0 | 353 | | SecurityStatusPalErrorCode.LogonDenied => NegotiateAuthenticationStatusCode.UnknownCredentials, |
| | 0 | 354 | | SecurityStatusPalErrorCode.UnknownCredentials => NegotiateAuthenticationStatusCode.UnknownCredential |
| | 0 | 355 | | SecurityStatusPalErrorCode.NoCredentials => NegotiateAuthenticationStatusCode.UnknownCredentials, |
| | 0 | 356 | | SecurityStatusPalErrorCode.MessageAltered => NegotiateAuthenticationStatusCode.MessageAltered, |
| | 0 | 357 | | SecurityStatusPalErrorCode.OutOfSequence => NegotiateAuthenticationStatusCode.OutOfSequence, |
| | 0 | 358 | | SecurityStatusPalErrorCode.NoAuthenticatingAuthority => NegotiateAuthenticationStatusCode.InvalidCre |
| | 0 | 359 | | SecurityStatusPalErrorCode.IncompleteCredentials => NegotiateAuthenticationStatusCode.InvalidCredent |
| | 0 | 360 | | SecurityStatusPalErrorCode.IllegalMessage => NegotiateAuthenticationStatusCode.InvalidToken, |
| | 0 | 361 | | SecurityStatusPalErrorCode.CertExpired => NegotiateAuthenticationStatusCode.CredentialsExpired, |
| | 0 | 362 | | SecurityStatusPalErrorCode.SecurityQosFailed => NegotiateAuthenticationStatusCode.QopNotSupported, |
| | 0 | 363 | | SecurityStatusPalErrorCode.UnsupportedPreauth => NegotiateAuthenticationStatusCode.InvalidToken, |
| | 0 | 364 | | SecurityStatusPalErrorCode.BadBinding => NegotiateAuthenticationStatusCode.BadBinding, |
| | 0 | 365 | | SecurityStatusPalErrorCode.UntrustedRoot => NegotiateAuthenticationStatusCode.UnknownCredentials, |
| | 0 | 366 | | SecurityStatusPalErrorCode.SmartcardLogonRequired => NegotiateAuthenticationStatusCode.UnknownCreden |
| | 0 | 367 | | SecurityStatusPalErrorCode.WrongPrincipal => NegotiateAuthenticationStatusCode.UnknownCredentials, |
| | 0 | 368 | | SecurityStatusPalErrorCode.CannotPack => NegotiateAuthenticationStatusCode.InvalidToken, |
| | 0 | 369 | | SecurityStatusPalErrorCode.TimeSkew => NegotiateAuthenticationStatusCode.InvalidToken, |
| | 0 | 370 | | SecurityStatusPalErrorCode.AlgorithmMismatch => NegotiateAuthenticationStatusCode.InvalidToken, |
| | 0 | 371 | | SecurityStatusPalErrorCode.CertUnknown => NegotiateAuthenticationStatusCode.UnknownCredentials, |
| | 0 | 372 | | SecurityStatusPalErrorCode.TargetUnknown => NegotiateAuthenticationStatusCode.TargetUnknown, |
| | 0 | 373 | | |
| | 0 | 374 | | // Processing partial inputs is not supported, so this is result of incorrect input |
| | 0 | 375 | | SecurityStatusPalErrorCode.IncompleteMessage => NegotiateAuthenticationStatusCode.InvalidToken, |
| | 0 | 376 | | |
| | 0 | 377 | | _ => NegotiateAuthenticationStatusCode.GenericFailure, |
| | 0 | 378 | | }; |
| | | 379 | | |
| | 0 | 380 | | if (((int)platformStatusCode.ErrorCode >= (int)SecurityStatusPalErrorCode.OutOfMemory)) |
| | 0 | 381 | | { |
| | | 382 | | //CloseContext(); |
| | 0 | 383 | | _securityContext?.Dispose(); |
| | 0 | 384 | | _isAuthenticated = true; |
| | 0 | 385 | | _tokenBuffer = null; |
| | 0 | 386 | | return null; |
| | | 387 | | } |
| | 0 | 388 | | else if (firstTime && _credentialsHandle != null) |
| | 0 | 389 | | { |
| | | 390 | | // Cache until it is pushed out by newly incoming handles. |
| | 0 | 391 | | SSPIHandleCache.CacheCredential(_credentialsHandle); |
| | 0 | 392 | | } |
| | | 393 | | |
| | 0 | 394 | | byte[]? result = |
| | 0 | 395 | | resultBlobLength == 0 || _tokenBuffer == null ? null : |
| | 0 | 396 | | _tokenBuffer.Length == resultBlobLength ? _tokenBuffer : |
| | 0 | 397 | | _tokenBuffer[0..resultBlobLength]; |
| | | 398 | | |
| | | 399 | | // The return value will tell us correctly if the handshake is over or not |
| | 0 | 400 | | if (platformStatusCode.ErrorCode == SecurityStatusPalErrorCode.OK |
| | 0 | 401 | | || (_isServer && platformStatusCode.ErrorCode == SecurityStatusPalErrorCode.CompleteNeeded)) |
| | 0 | 402 | | { |
| | | 403 | | // Success. |
| | 0 | 404 | | _isAuthenticated = true; |
| | 0 | 405 | | _tokenBuffer = null; |
| | 0 | 406 | | } |
| | | 407 | | else |
| | 0 | 408 | | { |
| | | 409 | | // We need to continue. |
| | 0 | 410 | | if (NetEventSource.Log.IsEnabled()) NetEventSource.Info(this, $"need continue statusCode:0x{((int)pl |
| | 0 | 411 | | } |
| | | 412 | | |
| | 0 | 413 | | return result; |
| | 0 | 414 | | } |
| | | 415 | | |
| | | 416 | | public override unsafe NegotiateAuthenticationStatusCode Wrap(ReadOnlySpan<byte> input, IBufferWriter<byte> |
| | 0 | 417 | | { |
| | 0 | 418 | | Debug.Assert(_securityContext is not null); |
| | | 419 | | |
| | 0 | 420 | | SecPkgContext_Sizes sizes = default; |
| | 0 | 421 | | bool success = SSPIWrapper.QueryBlittableContextAttributes(GlobalSSPI.SSPIAuth, _securityContext, Intero |
| | 0 | 422 | | Debug.Assert(success); |
| | | 423 | | |
| | | 424 | | // alloc new output buffer if not supplied or too small |
| | 0 | 425 | | int resultSize = input.Length + sizes.cbSecurityTrailer + sizes.cbBlockSize; |
| | 0 | 426 | | Span<byte> outputBuffer = outputWriter.GetSpan(resultSize); |
| | | 427 | | |
| | | 428 | | // make a copy of user data for in-place encryption |
| | 0 | 429 | | input.CopyTo(outputBuffer.Slice(sizes.cbSecurityTrailer, input.Length)); |
| | | 430 | | |
| | 0 | 431 | | isEncrypted = requestEncryption; |
| | | 432 | | |
| | 0 | 433 | | fixed (byte* outputPtr = outputBuffer) |
| | 0 | 434 | | { |
| | | 435 | | // Prepare buffers TOKEN(signature), DATA and Padding. |
| | 0 | 436 | | Interop.SspiCli.SecBuffer* unmanagedBuffer = stackalloc Interop.SspiCli.SecBuffer[3]; |
| | 0 | 437 | | Interop.SspiCli.SecBuffer* tokenBuffer = &unmanagedBuffer[0]; |
| | 0 | 438 | | Interop.SspiCli.SecBuffer* dataBuffer = &unmanagedBuffer[1]; |
| | 0 | 439 | | Interop.SspiCli.SecBuffer* paddingBuffer = &unmanagedBuffer[2]; |
| | 0 | 440 | | tokenBuffer->BufferType = SecurityBufferType.SECBUFFER_TOKEN; |
| | 0 | 441 | | tokenBuffer->pvBuffer = (IntPtr)(outputPtr); |
| | 0 | 442 | | tokenBuffer->cbBuffer = sizes.cbSecurityTrailer; |
| | 0 | 443 | | dataBuffer->BufferType = SecurityBufferType.SECBUFFER_DATA; |
| | 0 | 444 | | dataBuffer->pvBuffer = (IntPtr)(outputPtr + sizes.cbSecurityTrailer); |
| | 0 | 445 | | dataBuffer->cbBuffer = input.Length; |
| | 0 | 446 | | paddingBuffer->BufferType = SecurityBufferType.SECBUFFER_PADDING; |
| | 0 | 447 | | paddingBuffer->pvBuffer = (IntPtr)(outputPtr + sizes.cbSecurityTrailer + input.Length); |
| | 0 | 448 | | paddingBuffer->cbBuffer = sizes.cbBlockSize; |
| | | 449 | | |
| | 0 | 450 | | Interop.SspiCli.SecBufferDesc sdcInOut = new Interop.SspiCli.SecBufferDesc(3) |
| | 0 | 451 | | { |
| | 0 | 452 | | pBuffers = unmanagedBuffer |
| | 0 | 453 | | }; |
| | | 454 | | |
| | 0 | 455 | | uint qop = requestEncryption ? 0 : Interop.SspiCli.SECQOP_WRAP_NO_ENCRYPT; |
| | 0 | 456 | | int errorCode = GlobalSSPI.SSPIAuth.EncryptMessage(_securityContext, ref sdcInOut, qop); |
| | | 457 | | |
| | 0 | 458 | | if (errorCode != 0) |
| | 0 | 459 | | { |
| | 0 | 460 | | return errorCode switch |
| | 0 | 461 | | { |
| | 0 | 462 | | (int)Interop.SECURITY_STATUS.ContextExpired => NegotiateAuthenticationStatusCode.ContextExpi |
| | 0 | 463 | | (int)Interop.SECURITY_STATUS.QopNotSupported => NegotiateAuthenticationStatusCode.QopNotSupp |
| | 0 | 464 | | _ => NegotiateAuthenticationStatusCode.GenericFailure, |
| | 0 | 465 | | }; |
| | | 466 | | } |
| | | 467 | | |
| | | 468 | | // Compact the result |
| | 0 | 469 | | if (tokenBuffer->cbBuffer != sizes.cbSecurityTrailer) |
| | 0 | 470 | | { |
| | 0 | 471 | | outputBuffer.Slice(sizes.cbSecurityTrailer, dataBuffer->cbBuffer).CopyTo( |
| | 0 | 472 | | outputBuffer.Slice(tokenBuffer->cbBuffer, dataBuffer->cbBuffer)); |
| | 0 | 473 | | } |
| | 0 | 474 | | if (tokenBuffer->cbBuffer != sizes.cbSecurityTrailer || |
| | 0 | 475 | | paddingBuffer->cbBuffer != sizes.cbBlockSize) |
| | 0 | 476 | | { |
| | 0 | 477 | | outputBuffer.Slice(sizes.cbSecurityTrailer + input.Length, paddingBuffer->cbBuffer).CopyTo( |
| | 0 | 478 | | outputBuffer.Slice(tokenBuffer->cbBuffer + dataBuffer->cbBuffer, paddingBuffer->cbBuffer)); |
| | 0 | 479 | | } |
| | | 480 | | |
| | 0 | 481 | | outputWriter.Advance(tokenBuffer->cbBuffer + dataBuffer->cbBuffer + paddingBuffer->cbBuffer); |
| | 0 | 482 | | return NegotiateAuthenticationStatusCode.Completed; |
| | | 483 | | } |
| | 0 | 484 | | } |
| | | 485 | | |
| | | 486 | | public override NegotiateAuthenticationStatusCode Unwrap(ReadOnlySpan<byte> input, IBufferWriter<byte> outpu |
| | 0 | 487 | | { |
| | 0 | 488 | | Span<byte> outputBuffer = outputWriter.GetSpan(input.Length).Slice(0, input.Length); |
| | | 489 | | NegotiateAuthenticationStatusCode statusCode; |
| | | 490 | | |
| | 0 | 491 | | input.CopyTo(outputBuffer); |
| | 0 | 492 | | statusCode = UnwrapInPlace(outputBuffer, out int unwrappedOffset, out int unwrappedLength, out wasEncryp |
| | | 493 | | |
| | 0 | 494 | | if (statusCode == NegotiateAuthenticationStatusCode.Completed) |
| | 0 | 495 | | { |
| | 0 | 496 | | if (unwrappedOffset > 0) |
| | 0 | 497 | | { |
| | 0 | 498 | | outputBuffer.Slice(unwrappedOffset, unwrappedLength).CopyTo(outputBuffer); |
| | 0 | 499 | | } |
| | 0 | 500 | | outputWriter.Advance(unwrappedLength); |
| | 0 | 501 | | } |
| | | 502 | | |
| | 0 | 503 | | return statusCode; |
| | 0 | 504 | | } |
| | | 505 | | |
| | | 506 | | public override unsafe NegotiateAuthenticationStatusCode UnwrapInPlace(Span<byte> input, out int unwrappedOf |
| | 0 | 507 | | { |
| | 0 | 508 | | Debug.Assert(_securityContext is not null); |
| | | 509 | | |
| | 0 | 510 | | fixed (byte* inputPtr = input) |
| | 0 | 511 | | { |
| | 0 | 512 | | Interop.SspiCli.SecBuffer* unmanagedBuffer = stackalloc Interop.SspiCli.SecBuffer[2]; |
| | 0 | 513 | | Interop.SspiCli.SecBuffer* streamBuffer = &unmanagedBuffer[0]; |
| | 0 | 514 | | Interop.SspiCli.SecBuffer* dataBuffer = &unmanagedBuffer[1]; |
| | 0 | 515 | | streamBuffer->BufferType = SecurityBufferType.SECBUFFER_STREAM; |
| | 0 | 516 | | streamBuffer->pvBuffer = (IntPtr)inputPtr; |
| | 0 | 517 | | streamBuffer->cbBuffer = input.Length; |
| | 0 | 518 | | dataBuffer->BufferType = SecurityBufferType.SECBUFFER_DATA; |
| | 0 | 519 | | dataBuffer->pvBuffer = IntPtr.Zero; |
| | 0 | 520 | | dataBuffer->cbBuffer = 0; |
| | | 521 | | |
| | 0 | 522 | | Interop.SspiCli.SecBufferDesc sdcInOut = new Interop.SspiCli.SecBufferDesc(2) |
| | 0 | 523 | | { |
| | 0 | 524 | | pBuffers = unmanagedBuffer |
| | 0 | 525 | | }; |
| | | 526 | | |
| | | 527 | | uint qop; |
| | 0 | 528 | | int errorCode = GlobalSSPI.SSPIAuth.DecryptMessage(_securityContext, ref sdcInOut, out qop); |
| | 0 | 529 | | if (errorCode != 0) |
| | 0 | 530 | | { |
| | 0 | 531 | | unwrappedOffset = 0; |
| | 0 | 532 | | unwrappedLength = 0; |
| | 0 | 533 | | wasEncrypted = false; |
| | 0 | 534 | | return errorCode switch |
| | 0 | 535 | | { |
| | 0 | 536 | | (int)Interop.SECURITY_STATUS.MessageAltered => NegotiateAuthenticationStatusCode.MessageAlte |
| | 0 | 537 | | _ => NegotiateAuthenticationStatusCode.InvalidToken |
| | 0 | 538 | | }; |
| | | 539 | | } |
| | | 540 | | |
| | 0 | 541 | | if (dataBuffer->BufferType != SecurityBufferType.SECBUFFER_DATA) |
| | 0 | 542 | | { |
| | 0 | 543 | | throw new InternalException(dataBuffer->BufferType); |
| | | 544 | | } |
| | | 545 | | |
| | 0 | 546 | | wasEncrypted = qop != Interop.SspiCli.SECQOP_WRAP_NO_ENCRYPT; |
| | | 547 | | |
| | 0 | 548 | | Debug.Assert((nint)dataBuffer->pvBuffer >= (nint)inputPtr); |
| | 0 | 549 | | Debug.Assert((nint)dataBuffer->pvBuffer + dataBuffer->cbBuffer <= (nint)inputPtr + input.Length); |
| | 0 | 550 | | unwrappedOffset = (int)((byte*)dataBuffer->pvBuffer - inputPtr); |
| | 0 | 551 | | unwrappedLength = dataBuffer->cbBuffer; |
| | 0 | 552 | | return NegotiateAuthenticationStatusCode.Completed; |
| | | 553 | | } |
| | 0 | 554 | | } |
| | | 555 | | |
| | | 556 | | public override unsafe void GetMIC(ReadOnlySpan<byte> message, IBufferWriter<byte> signature) |
| | 0 | 557 | | { |
| | 0 | 558 | | bool refAdded = false; |
| | | 559 | | |
| | 0 | 560 | | Debug.Assert(_securityContext is not null); |
| | | 561 | | |
| | | 562 | | try |
| | 0 | 563 | | { |
| | 0 | 564 | | _securityContext.DangerousAddRef(ref refAdded); |
| | | 565 | | |
| | 0 | 566 | | SecPkgContext_Sizes sizes = default; |
| | 0 | 567 | | bool success = SSPIWrapper.QueryBlittableContextAttributes(GlobalSSPI.SSPIAuth, _securityContext, In |
| | 0 | 568 | | Debug.Assert(success); |
| | | 569 | | |
| | 0 | 570 | | Span<byte> signatureBuffer = signature.GetSpan(sizes.cbMaxSignature); |
| | | 571 | | |
| | 0 | 572 | | fixed (byte* messagePtr = message) |
| | 0 | 573 | | fixed (byte* signaturePtr = signatureBuffer) |
| | 0 | 574 | | { |
| | | 575 | | // Prepare buffers TOKEN(signature), DATA. |
| | 0 | 576 | | Interop.SspiCli.SecBuffer* unmanagedBuffer = stackalloc Interop.SspiCli.SecBuffer[2]; |
| | 0 | 577 | | Interop.SspiCli.SecBuffer* tokenBuffer = &unmanagedBuffer[0]; |
| | 0 | 578 | | Interop.SspiCli.SecBuffer* dataBuffer = &unmanagedBuffer[1]; |
| | 0 | 579 | | tokenBuffer->BufferType = SecurityBufferType.SECBUFFER_TOKEN; |
| | 0 | 580 | | tokenBuffer->pvBuffer = (IntPtr)signaturePtr; |
| | 0 | 581 | | tokenBuffer->cbBuffer = sizes.cbMaxSignature; |
| | 0 | 582 | | dataBuffer->BufferType = SecurityBufferType.SECBUFFER_DATA; |
| | 0 | 583 | | dataBuffer->pvBuffer = (IntPtr)messagePtr; |
| | 0 | 584 | | dataBuffer->cbBuffer = message.Length; |
| | | 585 | | |
| | 0 | 586 | | Interop.SspiCli.SecBufferDesc sdcInOut = new Interop.SspiCli.SecBufferDesc(2) |
| | 0 | 587 | | { |
| | 0 | 588 | | pBuffers = unmanagedBuffer |
| | 0 | 589 | | }; |
| | | 590 | | |
| | 0 | 591 | | int errorCode = Interop.SspiCli.MakeSignature(ref _securityContext._handle, 0, ref sdcInOut, 0); |
| | | 592 | | |
| | 0 | 593 | | if (errorCode != 0) |
| | 0 | 594 | | { |
| | 0 | 595 | | Exception e = new Win32Exception(errorCode); |
| | 0 | 596 | | if (NetEventSource.Log.IsEnabled()) NetEventSource.Error(null, e); |
| | 0 | 597 | | throw new Win32Exception(errorCode); |
| | | 598 | | } |
| | | 599 | | |
| | 0 | 600 | | signature.Advance(tokenBuffer->cbBuffer); |
| | 0 | 601 | | } |
| | 0 | 602 | | } |
| | | 603 | | finally |
| | 0 | 604 | | { |
| | 0 | 605 | | if (refAdded) |
| | 0 | 606 | | { |
| | 0 | 607 | | _securityContext.DangerousRelease(); |
| | 0 | 608 | | } |
| | 0 | 609 | | } |
| | 0 | 610 | | } |
| | | 611 | | |
| | | 612 | | public override unsafe bool VerifyMIC(ReadOnlySpan<byte> message, ReadOnlySpan<byte> signature) |
| | 0 | 613 | | { |
| | 0 | 614 | | bool refAdded = false; |
| | | 615 | | |
| | 0 | 616 | | Debug.Assert(_securityContext is not null); |
| | | 617 | | |
| | | 618 | | try |
| | 0 | 619 | | { |
| | 0 | 620 | | _securityContext.DangerousAddRef(ref refAdded); |
| | | 621 | | |
| | 0 | 622 | | fixed (byte* messagePtr = message) |
| | 0 | 623 | | fixed (byte* signaturePtr = signature) |
| | 0 | 624 | | { |
| | 0 | 625 | | Interop.SspiCli.SecBuffer* unmanagedBuffer = stackalloc Interop.SspiCli.SecBuffer[2]; |
| | 0 | 626 | | Interop.SspiCli.SecBuffer* tokenBuffer = &unmanagedBuffer[0]; |
| | 0 | 627 | | Interop.SspiCli.SecBuffer* dataBuffer = &unmanagedBuffer[1]; |
| | 0 | 628 | | tokenBuffer->BufferType = SecurityBufferType.SECBUFFER_TOKEN; |
| | 0 | 629 | | tokenBuffer->pvBuffer = (IntPtr)signaturePtr; |
| | 0 | 630 | | tokenBuffer->cbBuffer = signature.Length; |
| | 0 | 631 | | dataBuffer->BufferType = SecurityBufferType.SECBUFFER_DATA; |
| | 0 | 632 | | dataBuffer->pvBuffer = (IntPtr)messagePtr; |
| | 0 | 633 | | dataBuffer->cbBuffer = message.Length; |
| | | 634 | | |
| | 0 | 635 | | Interop.SspiCli.SecBufferDesc sdcIn = new Interop.SspiCli.SecBufferDesc(2) |
| | 0 | 636 | | { |
| | 0 | 637 | | pBuffers = unmanagedBuffer |
| | 0 | 638 | | }; |
| | | 639 | | |
| | | 640 | | uint qop; |
| | 0 | 641 | | int errorCode = Interop.SspiCli.VerifySignature(ref _securityContext._handle, in sdcIn, 0, &qop) |
| | | 642 | | |
| | 0 | 643 | | if (errorCode != 0) |
| | 0 | 644 | | { |
| | 0 | 645 | | Exception e = new Win32Exception(errorCode); |
| | 0 | 646 | | if (NetEventSource.Log.IsEnabled()) NetEventSource.Error(null, e); |
| | 0 | 647 | | throw new Win32Exception(errorCode); |
| | | 648 | | } |
| | | 649 | | |
| | 0 | 650 | | if (IsEncrypted && qop == Interop.SspiCli.SECQOP_WRAP_NO_ENCRYPT) |
| | 0 | 651 | | { |
| | 0 | 652 | | Debug.Fail($"Expected qop = 0, returned value = {qop}"); |
| | | 653 | | throw new InvalidOperationException(SR.net_auth_message_not_encrypted); |
| | | 654 | | } |
| | | 655 | | |
| | 0 | 656 | | return true; |
| | | 657 | | } |
| | | 658 | | } |
| | | 659 | | finally |
| | 0 | 660 | | { |
| | 0 | 661 | | if (refAdded) |
| | 0 | 662 | | { |
| | 0 | 663 | | _securityContext.DangerousRelease(); |
| | 0 | 664 | | } |
| | 0 | 665 | | } |
| | 0 | 666 | | } |
| | | 667 | | |
| | | 668 | | private static SafeFreeCredentials AcquireDefaultCredential(string package, bool isServer) |
| | 0 | 669 | | { |
| | 0 | 670 | | return SSPIWrapper.AcquireDefaultCredential( |
| | 0 | 671 | | GlobalSSPI.SSPIAuth, |
| | 0 | 672 | | package, |
| | 0 | 673 | | (isServer ? Interop.SspiCli.CredentialUse.SECPKG_CRED_INBOUND : Interop.SspiCli.CredentialUse.SECPKG |
| | 0 | 674 | | } |
| | | 675 | | |
| | | 676 | | private static SafeFreeCredentials AcquireCredentialsHandle(string package, bool isServer, NetworkCredential |
| | 0 | 677 | | { |
| | 0 | 678 | | SafeSspiAuthDataHandle? authData = null; |
| | | 679 | | try |
| | 0 | 680 | | { |
| | 0 | 681 | | Interop.SECURITY_STATUS result = Interop.SspiCli.SspiEncodeStringsAsAuthIdentity( |
| | 0 | 682 | | credential.UserName, credential.Domain, |
| | 0 | 683 | | credential.Password, out authData); |
| | | 684 | | |
| | 0 | 685 | | if (result != Interop.SECURITY_STATUS.OK) |
| | 0 | 686 | | { |
| | 0 | 687 | | if (NetEventSource.Log.IsEnabled()) NetEventSource.Error(null, SR.Format(SR.net_log_operation_fa |
| | 0 | 688 | | throw new Win32Exception((int)result); |
| | | 689 | | } |
| | | 690 | | |
| | 0 | 691 | | return SSPIWrapper.AcquireCredentialsHandle(GlobalSSPI.SSPIAuth, |
| | 0 | 692 | | package, (isServer ? Interop.SspiCli.CredentialUse.SECPKG_CRED_INBOUND : Interop.SspiCli.Credent |
| | | 693 | | } |
| | | 694 | | finally |
| | 0 | 695 | | { |
| | 0 | 696 | | authData?.Dispose(); |
| | 0 | 697 | | } |
| | 0 | 698 | | } |
| | | 699 | | |
| | | 700 | | private static SecurityStatusPal InitializeSecurityContext( |
| | | 701 | | ref SafeFreeCredentials? credentialsHandle, |
| | | 702 | | ref SafeDeleteContext? securityContext, |
| | | 703 | | string? spn, |
| | | 704 | | Interop.SspiCli.ContextFlags requestedContextFlags, |
| | | 705 | | ReadOnlySpan<byte> incomingBlob, |
| | | 706 | | ChannelBinding? channelBinding, |
| | | 707 | | ref byte[]? resultBlob, |
| | | 708 | | out int resultBlobLength, |
| | | 709 | | ref Interop.SspiCli.ContextFlags contextFlags) |
| | 0 | 710 | | { |
| | | 711 | | |
| | 0 | 712 | | InputSecurityBuffers inputBuffers = default; |
| | 0 | 713 | | if (!incomingBlob.IsEmpty) |
| | 0 | 714 | | { |
| | 0 | 715 | | inputBuffers.SetNextBuffer(new InputSecurityBuffer(incomingBlob, SecurityBufferType.SECBUFFER_TOKEN) |
| | 0 | 716 | | } |
| | | 717 | | |
| | 0 | 718 | | if (channelBinding != null) |
| | 0 | 719 | | { |
| | 0 | 720 | | inputBuffers.SetNextBuffer(new InputSecurityBuffer(channelBinding)); |
| | 0 | 721 | | } |
| | | 722 | | |
| | 0 | 723 | | ProtocolToken token = default; |
| | 0 | 724 | | if (resultBlob != null) |
| | 0 | 725 | | { |
| | 0 | 726 | | token.Payload = resultBlob; |
| | 0 | 727 | | token.Size = resultBlob.Length; |
| | 0 | 728 | | } |
| | | 729 | | |
| | 0 | 730 | | contextFlags = Interop.SspiCli.ContextFlags.Zero; |
| | | 731 | | // There is only one SafeDeleteContext type on Windows which is SafeDeleteSslContext so this cast is saf |
| | 0 | 732 | | SafeDeleteSslContext? sslContext = (SafeDeleteSslContext?)securityContext; |
| | 0 | 733 | | Interop.SECURITY_STATUS winStatus = (Interop.SECURITY_STATUS)SSPIWrapper.InitializeSecurityContext( |
| | 0 | 734 | | GlobalSSPI.SSPIAuth, |
| | 0 | 735 | | ref credentialsHandle, |
| | 0 | 736 | | ref sslContext, |
| | 0 | 737 | | spn, |
| | 0 | 738 | | requestedContextFlags, |
| | 0 | 739 | | Interop.SspiCli.Endianness.SECURITY_NETWORK_DREP, |
| | 0 | 740 | | ref inputBuffers, |
| | 0 | 741 | | ref token, |
| | 0 | 742 | | ref contextFlags); |
| | 0 | 743 | | securityContext = sslContext; |
| | 0 | 744 | | resultBlob = token.Payload; |
| | 0 | 745 | | resultBlobLength = token.Size; |
| | | 746 | | |
| | 0 | 747 | | return SecurityStatusAdapterPal.GetSecurityStatusPalFromInterop(winStatus); |
| | 0 | 748 | | } |
| | | 749 | | |
| | | 750 | | private static SecurityStatusPal CompleteAuthToken( |
| | | 751 | | ref SafeDeleteContext? securityContext, |
| | | 752 | | ReadOnlySpan<byte> incomingBlob) |
| | 0 | 753 | | { |
| | | 754 | | // There is only one SafeDeleteContext type on Windows which is SafeDeleteSslContext so this cast is saf |
| | 0 | 755 | | SafeDeleteSslContext? sslContext = (SafeDeleteSslContext?)securityContext; |
| | 0 | 756 | | var inSecurityBuffer = new InputSecurityBuffer(incomingBlob, SecurityBufferType.SECBUFFER_TOKEN); |
| | 0 | 757 | | Interop.SECURITY_STATUS winStatus = (Interop.SECURITY_STATUS)SSPIWrapper.CompleteAuthToken( |
| | 0 | 758 | | GlobalSSPI.SSPIAuth, |
| | 0 | 759 | | ref sslContext, |
| | 0 | 760 | | in inSecurityBuffer); |
| | 0 | 761 | | securityContext = sslContext; |
| | 0 | 762 | | return SecurityStatusAdapterPal.GetSecurityStatusPalFromInterop(winStatus); |
| | 0 | 763 | | } |
| | | 764 | | |
| | | 765 | | private static SecurityStatusPal AcceptSecurityContext( |
| | | 766 | | SafeFreeCredentials? credentialsHandle, |
| | | 767 | | ref SafeDeleteContext? securityContext, |
| | | 768 | | Interop.SspiCli.ContextFlags requestedContextFlags, |
| | | 769 | | ReadOnlySpan<byte> incomingBlob, |
| | | 770 | | ChannelBinding? channelBinding, |
| | | 771 | | ref byte[]? resultBlob, |
| | | 772 | | out int resultBlobLength, |
| | | 773 | | ref Interop.SspiCli.ContextFlags contextFlags) |
| | 0 | 774 | | { |
| | 0 | 775 | | InputSecurityBuffers inputBuffers = default; |
| | 0 | 776 | | if (!incomingBlob.IsEmpty) |
| | 0 | 777 | | { |
| | 0 | 778 | | inputBuffers.SetNextBuffer(new InputSecurityBuffer(incomingBlob, SecurityBufferType.SECBUFFER_TOKEN) |
| | 0 | 779 | | } |
| | | 780 | | |
| | 0 | 781 | | if (channelBinding != null) |
| | 0 | 782 | | { |
| | 0 | 783 | | inputBuffers.SetNextBuffer(new InputSecurityBuffer(channelBinding)); |
| | 0 | 784 | | } |
| | | 785 | | |
| | 0 | 786 | | ProtocolToken token = default; |
| | 0 | 787 | | if (resultBlob != null) |
| | 0 | 788 | | { |
| | 0 | 789 | | token.Payload = resultBlob; |
| | 0 | 790 | | token.Size = resultBlob.Length; |
| | 0 | 791 | | } |
| | | 792 | | |
| | 0 | 793 | | contextFlags = Interop.SspiCli.ContextFlags.Zero; |
| | | 794 | | // There is only one SafeDeleteContext type on Windows which is SafeDeleteSslContext so this cast is saf |
| | 0 | 795 | | SafeDeleteSslContext? sslContext = (SafeDeleteSslContext?)securityContext; |
| | 0 | 796 | | Interop.SECURITY_STATUS winStatus = (Interop.SECURITY_STATUS)SSPIWrapper.AcceptSecurityContext( |
| | 0 | 797 | | GlobalSSPI.SSPIAuth, |
| | 0 | 798 | | credentialsHandle, |
| | 0 | 799 | | ref sslContext, |
| | 0 | 800 | | requestedContextFlags, |
| | 0 | 801 | | Interop.SspiCli.Endianness.SECURITY_NETWORK_DREP, |
| | 0 | 802 | | ref inputBuffers, |
| | 0 | 803 | | ref token, |
| | 0 | 804 | | ref contextFlags); |
| | | 805 | | |
| | | 806 | | // SSPI Workaround |
| | | 807 | | // If a client sends up a blob on the initial request, Negotiate returns SEC_E_INVALID_HANDLE |
| | | 808 | | // when it should return SEC_E_INVALID_TOKEN. |
| | 0 | 809 | | if (winStatus == Interop.SECURITY_STATUS.InvalidHandle && securityContext == null && !incomingBlob.IsEmp |
| | 0 | 810 | | { |
| | 0 | 811 | | winStatus = Interop.SECURITY_STATUS.InvalidToken; |
| | 0 | 812 | | } |
| | | 813 | | |
| | 0 | 814 | | resultBlob = token.Payload; |
| | 0 | 815 | | resultBlobLength = token.Size; |
| | | 816 | | |
| | 0 | 817 | | securityContext = sslContext; |
| | 0 | 818 | | return SecurityStatusAdapterPal.GetSecurityStatusPalFromInterop(winStatus); |
| | 0 | 819 | | } |
| | | 820 | | } |
| | | 821 | | } |
| | | 822 | | } |
| | | 823 | | |