APExchange_test.go 9.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346
  1. package service
  2. import (
  3. "encoding/hex"
  4. "github.com/stretchr/testify/assert"
  5. "gopkg.in/jcmturner/gokrb5.v2/client"
  6. "gopkg.in/jcmturner/gokrb5.v2/config"
  7. "gopkg.in/jcmturner/gokrb5.v2/credentials"
  8. "gopkg.in/jcmturner/gokrb5.v2/iana/errorcode"
  9. "gopkg.in/jcmturner/gokrb5.v2/iana/flags"
  10. "gopkg.in/jcmturner/gokrb5.v2/iana/nametype"
  11. "gopkg.in/jcmturner/gokrb5.v2/keytab"
  12. "gopkg.in/jcmturner/gokrb5.v2/messages"
  13. "gopkg.in/jcmturner/gokrb5.v2/testdata"
  14. "gopkg.in/jcmturner/gokrb5.v2/types"
  15. "testing"
  16. "time"
  17. )
  18. func TestValidateAPREQ(t *testing.T) {
  19. cl := getClient()
  20. sname := types.PrincipalName{
  21. NameType: nametype.KRB_NT_PRINCIPAL,
  22. NameString: []string{"HTTP", "host.test.gokrb5"},
  23. }
  24. b, _ := hex.DecodeString(testdata.HTTP_KEYTAB)
  25. kt, _ := keytab.Parse(b)
  26. st := time.Now().UTC()
  27. tkt, sessionKey, err := messages.NewTicket(cl.Credentials.CName, cl.Credentials.Realm,
  28. sname, "TEST.GOKRB5",
  29. types.NewKrbFlags(),
  30. kt,
  31. 18,
  32. 1,
  33. st,
  34. st,
  35. st.Add(time.Duration(24)*time.Hour),
  36. st.Add(time.Duration(48)*time.Hour),
  37. )
  38. if err != nil {
  39. t.Fatalf("Error getting test ticket: %v", err)
  40. }
  41. APReq, err := messages.NewAPReq(
  42. tkt,
  43. sessionKey,
  44. newTestAuthenticator(*cl.Credentials),
  45. )
  46. if err != nil {
  47. t.Fatalf("Error getting test AP_REQ: %v", err)
  48. }
  49. ok, _, err := ValidateAPREQ(APReq, kt, "", "127.0.0.1")
  50. if !ok || err != nil {
  51. t.Fatalf("Validation of AP_REQ failed when it should not have: %v", err)
  52. }
  53. }
  54. func TestValidateAPREQ_KRB_AP_ERR_BADMATCH(t *testing.T) {
  55. cl := getClient()
  56. sname := types.PrincipalName{
  57. NameType: nametype.KRB_NT_PRINCIPAL,
  58. NameString: []string{"HTTP", "host.test.gokrb5"},
  59. }
  60. b, _ := hex.DecodeString(testdata.HTTP_KEYTAB)
  61. kt, _ := keytab.Parse(b)
  62. st := time.Now().UTC()
  63. tkt, sessionKey, err := messages.NewTicket(cl.Credentials.CName, cl.Credentials.Realm,
  64. sname, "TEST.GOKRB5",
  65. types.NewKrbFlags(),
  66. kt,
  67. 18,
  68. 1,
  69. st,
  70. st,
  71. st.Add(time.Duration(24)*time.Hour),
  72. st.Add(time.Duration(48)*time.Hour),
  73. )
  74. if err != nil {
  75. t.Fatalf("Error getting test ticket: %v", err)
  76. }
  77. a := newTestAuthenticator(*cl.Credentials)
  78. a.CName = types.PrincipalName{
  79. NameType: nametype.KRB_NT_PRINCIPAL,
  80. NameString: []string{"BADMATCH"},
  81. }
  82. APReq, err := messages.NewAPReq(
  83. tkt,
  84. sessionKey,
  85. a,
  86. )
  87. if err != nil {
  88. t.Fatalf("Error getting test AP_REQ: %v", err)
  89. }
  90. ok, _, err := ValidateAPREQ(APReq, kt, "", "127.0.0.1")
  91. if ok || err == nil {
  92. t.Fatal("Validation of AP_REQ passed when it should not have")
  93. }
  94. if _, ok := err.(messages.KRBError); ok {
  95. assert.Equal(t, errorcode.KRB_AP_ERR_BADMATCH, err.(messages.KRBError).ErrorCode, "Error code not as expected")
  96. } else {
  97. t.Fatalf("Error is not a KRBError: %v", err)
  98. }
  99. }
  100. func TestValidateAPREQ_LargeClockSkew(t *testing.T) {
  101. cl := getClient()
  102. sname := types.PrincipalName{
  103. NameType: nametype.KRB_NT_PRINCIPAL,
  104. NameString: []string{"HTTP", "host.test.gokrb5"},
  105. }
  106. b, _ := hex.DecodeString(testdata.HTTP_KEYTAB)
  107. kt, _ := keytab.Parse(b)
  108. st := time.Now().UTC()
  109. tkt, sessionKey, err := messages.NewTicket(cl.Credentials.CName, cl.Credentials.Realm,
  110. sname, "TEST.GOKRB5",
  111. types.NewKrbFlags(),
  112. kt,
  113. 18,
  114. 1,
  115. st,
  116. st,
  117. st.Add(time.Duration(24)*time.Hour),
  118. st.Add(time.Duration(48)*time.Hour),
  119. )
  120. if err != nil {
  121. t.Fatalf("Error getting test ticket: %v", err)
  122. }
  123. a := newTestAuthenticator(*cl.Credentials)
  124. a.CTime = a.CTime.Add(time.Duration(-10) * time.Minute)
  125. APReq, err := messages.NewAPReq(
  126. tkt,
  127. sessionKey,
  128. a,
  129. )
  130. if err != nil {
  131. t.Fatalf("Error getting test AP_REQ: %v", err)
  132. }
  133. ok, _, err := ValidateAPREQ(APReq, kt, "", "127.0.0.1")
  134. if ok || err == nil {
  135. t.Fatal("Validation of AP_REQ passed when it should not have")
  136. }
  137. if _, ok := err.(messages.KRBError); ok {
  138. assert.Equal(t, errorcode.KRB_AP_ERR_SKEW, err.(messages.KRBError).ErrorCode, "Error code not as expected")
  139. } else {
  140. t.Fatalf("Error is not a KRBError: %v", err)
  141. }
  142. }
  143. func TestValidateAPREQ_Replay(t *testing.T) {
  144. cl := getClient()
  145. sname := types.PrincipalName{
  146. NameType: nametype.KRB_NT_PRINCIPAL,
  147. NameString: []string{"HTTP", "host.test.gokrb5"},
  148. }
  149. b, _ := hex.DecodeString(testdata.HTTP_KEYTAB)
  150. kt, _ := keytab.Parse(b)
  151. st := time.Now().UTC()
  152. tkt, sessionKey, err := messages.NewTicket(cl.Credentials.CName, cl.Credentials.Realm,
  153. sname, "TEST.GOKRB5",
  154. types.NewKrbFlags(),
  155. kt,
  156. 18,
  157. 1,
  158. st,
  159. st,
  160. st.Add(time.Duration(24)*time.Hour),
  161. st.Add(time.Duration(48)*time.Hour),
  162. )
  163. if err != nil {
  164. t.Fatalf("Error getting test ticket: %v", err)
  165. }
  166. APReq, err := messages.NewAPReq(
  167. tkt,
  168. sessionKey,
  169. newTestAuthenticator(*cl.Credentials),
  170. )
  171. if err != nil {
  172. t.Fatalf("Error getting test AP_REQ: %v", err)
  173. }
  174. ok, _, err := ValidateAPREQ(APReq, kt, "", "127.0.0.1")
  175. if !ok || err != nil {
  176. t.Fatalf("Validation of AP_REQ failed when it should not have: %v", err)
  177. }
  178. // Replay
  179. ok, _, err = ValidateAPREQ(APReq, kt, "", "127.0.0.1")
  180. if ok || err == nil {
  181. t.Fatal("Validation of AP_REQ passed when it should not have")
  182. }
  183. assert.IsType(t, messages.KRBError{}, err, "Error is not a KRBError")
  184. assert.Equal(t, errorcode.KRB_AP_ERR_REPEAT, err.(messages.KRBError).ErrorCode, "Error code not as expected")
  185. }
  186. func TestValidateAPREQ_FutureTicket(t *testing.T) {
  187. cl := getClient()
  188. sname := types.PrincipalName{
  189. NameType: nametype.KRB_NT_PRINCIPAL,
  190. NameString: []string{"HTTP", "host.test.gokrb5"},
  191. }
  192. b, _ := hex.DecodeString(testdata.HTTP_KEYTAB)
  193. kt, _ := keytab.Parse(b)
  194. st := time.Now().UTC()
  195. tkt, sessionKey, err := messages.NewTicket(cl.Credentials.CName, cl.Credentials.Realm,
  196. sname, "TEST.GOKRB5",
  197. types.NewKrbFlags(),
  198. kt,
  199. 18,
  200. 1,
  201. st,
  202. st.Add(time.Duration(60)*time.Minute),
  203. st.Add(time.Duration(24)*time.Hour),
  204. st.Add(time.Duration(48)*time.Hour),
  205. )
  206. if err != nil {
  207. t.Fatalf("Error getting test ticket: %v", err)
  208. }
  209. a := newTestAuthenticator(*cl.Credentials)
  210. APReq, err := messages.NewAPReq(
  211. tkt,
  212. sessionKey,
  213. a,
  214. )
  215. if err != nil {
  216. t.Fatalf("Error getting test AP_REQ: %v", err)
  217. }
  218. ok, _, err := ValidateAPREQ(APReq, kt, "", "127.0.0.1")
  219. if ok || err == nil {
  220. t.Fatal("Validation of AP_REQ passed when it should not have")
  221. }
  222. if _, ok := err.(messages.KRBError); ok {
  223. assert.Equal(t, errorcode.KRB_AP_ERR_TKT_NYV, err.(messages.KRBError).ErrorCode, "Error code not as expected")
  224. } else {
  225. t.Fatalf("Error is not a KRBError: %v", err)
  226. }
  227. }
  228. func TestValidateAPREQ_InvalidTicket(t *testing.T) {
  229. cl := getClient()
  230. sname := types.PrincipalName{
  231. NameType: nametype.KRB_NT_PRINCIPAL,
  232. NameString: []string{"HTTP", "host.test.gokrb5"},
  233. }
  234. b, _ := hex.DecodeString(testdata.HTTP_KEYTAB)
  235. kt, _ := keytab.Parse(b)
  236. st := time.Now().UTC()
  237. f := types.NewKrbFlags()
  238. types.SetFlag(&f, flags.Invalid)
  239. tkt, sessionKey, err := messages.NewTicket(cl.Credentials.CName, cl.Credentials.Realm,
  240. sname, "TEST.GOKRB5",
  241. f,
  242. kt,
  243. 18,
  244. 1,
  245. st,
  246. st,
  247. st.Add(time.Duration(24)*time.Hour),
  248. st.Add(time.Duration(48)*time.Hour),
  249. )
  250. if err != nil {
  251. t.Fatalf("Error getting test ticket: %v", err)
  252. }
  253. APReq, err := messages.NewAPReq(
  254. tkt,
  255. sessionKey,
  256. newTestAuthenticator(*cl.Credentials),
  257. )
  258. if err != nil {
  259. t.Fatalf("Error getting test AP_REQ: %v", err)
  260. }
  261. ok, _, err := ValidateAPREQ(APReq, kt, "", "127.0.0.1")
  262. if ok || err == nil {
  263. t.Fatal("Validation of AP_REQ passed when it should not have")
  264. }
  265. if _, ok := err.(messages.KRBError); ok {
  266. assert.Equal(t, errorcode.KRB_AP_ERR_TKT_NYV, err.(messages.KRBError).ErrorCode, "Error code not as expected")
  267. } else {
  268. t.Fatalf("Error is not a KRBError: %v", err)
  269. }
  270. }
  271. func TestValidateAPREQ_ExpiredTicket(t *testing.T) {
  272. cl := getClient()
  273. sname := types.PrincipalName{
  274. NameType: nametype.KRB_NT_PRINCIPAL,
  275. NameString: []string{"HTTP", "host.test.gokrb5"},
  276. }
  277. b, _ := hex.DecodeString(testdata.HTTP_KEYTAB)
  278. kt, _ := keytab.Parse(b)
  279. st := time.Now().UTC()
  280. tkt, sessionKey, err := messages.NewTicket(cl.Credentials.CName, cl.Credentials.Realm,
  281. sname, "TEST.GOKRB5",
  282. types.NewKrbFlags(),
  283. kt,
  284. 18,
  285. 1,
  286. st,
  287. st,
  288. st.Add(time.Duration(-30)*time.Minute),
  289. st.Add(time.Duration(48)*time.Hour),
  290. )
  291. if err != nil {
  292. t.Fatalf("Error getting test ticket: %v", err)
  293. }
  294. a := newTestAuthenticator(*cl.Credentials)
  295. APReq, err := messages.NewAPReq(
  296. tkt,
  297. sessionKey,
  298. a,
  299. )
  300. if err != nil {
  301. t.Fatalf("Error getting test AP_REQ: %v", err)
  302. }
  303. ok, _, err := ValidateAPREQ(APReq, kt, "", "127.0.0.1")
  304. if ok || err == nil {
  305. t.Fatal("Validation of AP_REQ passed when it should not have")
  306. }
  307. if _, ok := err.(messages.KRBError); ok {
  308. assert.Equal(t, errorcode.KRB_AP_ERR_TKT_EXPIRED, err.(messages.KRBError).ErrorCode, "Error code not as expected")
  309. } else {
  310. t.Fatalf("Error is not a KRBError: %v", err)
  311. }
  312. }
  313. func newTestAuthenticator(creds credentials.Credentials) types.Authenticator {
  314. auth, _ := types.NewAuthenticator(creds.Realm, creds.CName)
  315. auth.GenerateSeqNumberAndSubKey(18, 32)
  316. //auth.Cksum = types.Checksum{
  317. // CksumType: chksumtype.GSSAPI,
  318. // Checksum: newAuthenticatorChksum([]int{GSS_C_INTEG_FLAG, GSS_C_CONF_FLAG}),
  319. //}
  320. return auth
  321. }
  322. func getClient() client.Client {
  323. b, _ := hex.DecodeString(testdata.TESTUSER1_KEYTAB)
  324. kt, _ := keytab.Parse(b)
  325. c, _ := config.NewConfigFromString(testdata.TEST_KRB5CONF)
  326. cl := client.NewClientWithKeytab("testuser1", "TEST.GOKRB5", kt)
  327. cl.WithConfig(c)
  328. return cl
  329. }