#!/bin/sh
env_setup="@env_setup@"
confdir="@confdir@"
testdir="@testdir@"
. ${env_setup}
KRB5_CONFIG="${1-${confdir}/krb5.conf}"
export KRB5_CONFIG
logfile=${testdir}/messages.log
testfailed="echo test failed; cat ${logfile}; exit 1"
${have_db} || exit 77
mkdir -p "${testdir}"
rm -rf "${testdir}/"*
R=TEST.H5L.SE
port=@port@
kadmin="${kadmin} -l -r $R"
kdc="${kdc} --addresses=localhost -P $port"
server=host/datan.test.h5l.se
cache="FILE:${testdir}/cache.krb5"
acache="FILE:${testdir}/acache.krb5"
kinit="${kinit} -c $cache ${afs_no_afslog}"
akinit="${kinit} -c $acache ${afs_no_afslog}"
klist="${klist} -c $cache"
aklist="${klist} -c $acache"
kgetcred="${kgetcred} -c $cache"
kdestroy="${kdestroy} -c $cache ${afs_no_unlog}"
rm -f ${testdir}/${keytabfile}
rm -f ${testdir}/current-db*
rm -f ${testdir}/out-*
rm -f ${testdir}/mkey.file*
> ${logfile}
echo Creating database
${kadmin} \
init \
--realm-max-ticket-life=1day \
--realm-max-renewable-life=1month \
${R} || exit 1
${kadmin} add -p foo --use-defaults foo@${R} || exit 1
${kadmin} add -p foo --use-defaults oldname@${R} || exit 1
${kadmin} rename oldname@${R} newname@${R}|| exit 1
${kadmin} add -p foo --use-defaults ${server}@${R} || exit 1
echo "Doing database check"
${kadmin} check ${R} || exit 1
echo foo > ${testdir}/foopassword
echo Starting kdc
env MallocStackLogging=1 MallocStackLoggingNoCompact=1 MallocErrorAbort=1 MallocLogFile=${testdir}/malloc-log \
${kdc} &
kdcpid=$!
sh ${wait_kdc} KDC ${logfile}
if [ "$?" != 0 ] ; then
kill -9 ${kdcpid}
exit 1
fi
trap "kill -9 ${kdcpid}; echo signal killing kdc; exit 1;" EXIT
ec=0
echo "Getting client initial tickets"; > ${logfile}
${kinit} --password-file=${testdir}/foopassword foo@$R || \
{ ec=1 ; eval "${testfailed}"; }
echo "Checking for FAST avail"
${klist} --hidden | grep fast_avail > /dev/null || { exit 1; }
echo "Getting tickets"; > ${logfile}
${kgetcred} ${server}@${R} || { ec=1 ; eval "${testfailed}"; }
echo "Listing tickets"; > ${logfile}
${klist} > /dev/null || { ec=1 ; eval "${testfailed}"; }
${kdestroy}
echo "Acquire host ticket to be used as an ARMOR ticket"
${akinit} --password-file=${testdir}/foopassword ${server}@${R} >/dev/null|| { exit 1; }
echo "Checking for FAST avail (in the FAST armor cache)"
${aklist} --hidden | grep fast_avail > /dev/null || { exit 1; }
echo "Getting client initial tickets with FAST armor ticket"; > ${logfile}
${kinit} --fast-armor-cache=${acache} \
--password-file=${testdir}/foopassword foo@$R || \
{ ec=1 ; eval "${testfailed}"; }
echo "Checking for FAST avail (in the FAST acquired cache)"
${klist} --hidden | grep fast_avail > /dev/null || { exit 1; }
echo "Getting service ticket"; > ${logfile}
${kgetcred} ${server}@${R} || { exit 1; }
${kdestroy}
echo "Getting client initial tickets (renamed -> not default salt) with FAST armor ticket"
${kinit} --fast-armor-cache=${acache} \
--password-file=${testdir}/foopassword newname@$R || \
{ ec=1 ; eval "${testfailed}"; }
echo "Checking for FAST avail (in the FAST acquired cache)"
${klist} --hidden | grep fast_avail > /dev/null || { exit 1; }
echo "Getting service ticket"; > ${logfile}
${kgetcred} ${server}@${R} || { exit 1; }
${kdestroy}
echo "Getting anonymous initial tickets for armor use"
${akinit} --anonymous $R || \
{ ec=1 ; eval "${testfailed}"; }
echo "Checking for FAST avail (in the FAST armor cache)"
${aklist} --hidden | grep fast_avail > /dev/null || { exit 1; }
echo "Getting client initial tickets with FAST PKINIT/anon armor ticket"
${kinit} --fast-armor-cache=${acache} \
--password-file=${testdir}/foopassword foo@$R || \
{ ec=1 ; eval "${testfailed}"; }
echo "Checking for FAST avail (in the FAST acquired cache)"
${klist} --hidden | grep fast_avail > /dev/null || { exit 1; }
mit=/usr/local/mitkerberos/bin
if [ -f ${mit}/kinit ] ; then
echo "Running MIT FAST tests"
KRB5_TRACE=${logfile}
export KRB5_TRACE
kinitpty=${testdir}/foopassword.rkpty
cat > ${kinitpty} <<EOF
expect Password
password foo\n
EOF
echo "Acquire host ticket"; > ${logfile}
${rkpty} ${kinitpty} ${mit}/kinit -c ${acache} ${server}@${R} >/dev/null|| { cat ${logfile}; exit 1; }
(${aklist} | grep ${server} > /dev/null ) || { cat ${logfile}; exit 1; }
echo "Checking for FAST avail"
${aklist} --hidden | grep fast_avail > /dev/null || { exit 1; }
echo "Using plain to get a initial ticket"; > ${logfile}
${rkpty} ${kinitpty} ${mit}/kinit -c ${cache} foo@${R} >/dev/null|| { cat ${logfile}; exit 1; }
(${klist} | grep foo > /dev/null ) || { cat ${logfile}; exit 1; }
echo "Using FAST to get a initial ticket"; > ${logfile}
${rkpty} ${kinitpty} ${mit}/kinit -c ${cache} -T ${acache} foo@${R} >/dev/null || { cat ${logfile}; exit 1; }
(${klist} | grep foo > /dev/null ) || { cat ${logfile}; exit 1; }
echo "Checking for FAST avail"
${klist} --hidden | grep fast_avail > /dev/null || { exit 1; }
echo "Getting service ticket"; > ${logfile}
${mit}/kvno -c ${cache} ${server}@${R} || { cat "${logfile}" ; exit 1; }
echo "${mit}/kinit -X X509_user_identity=${hx509_data}/pkinit.crt,${hx509_data}/pkinit.key foo@${R}"
echo "check for pkinit anonymous"; > ${logfile}
${mit}/kinit -c ${acache} -n @${R}
(${aklist} | grep "WELLKNOWN/ANONYMOUS@${R}" > /dev/null ) || { cat "${logfile}" ; exit 1; }
echo "Checking for FAST avail"; > ${logfile}
${aklist} --hidden | grep fast_avail > /dev/null || { cat "${logfile}" ; exit 1; }
echo "Using FAST/PKINIT to get a initial ticket"; > ${logfile}
${rkpty} ${kinitpty} ${mit}/kinit -c ${cache} -T ${acache} foo@${R} >/dev/null || { exit 1; }
(${klist} | grep foo > /dev/null ) || { exit 1; }
echo "Checking for FAST avail"; > ${logfile}
${klist} --hidden | grep fast_avail > /dev/null || { exit 1; }
fi
echo "killing kdc (${kdcpid})"
sh ${leaks_kill} kdc $kdcpid || exit 1
trap "" EXIT
exit $ec