network.go 6.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226
  1. package client
  2. import (
  3. "bytes"
  4. "encoding/binary"
  5. "errors"
  6. "fmt"
  7. "io"
  8. "net"
  9. "time"
  10. "gopkg.in/jcmturner/gokrb5.v7/iana/errorcode"
  11. "gopkg.in/jcmturner/gokrb5.v7/messages"
  12. )
  13. // SendToKDC performs network actions to send data to the KDC.
  14. func (cl *Client) sendToKDC(b []byte, realm string) ([]byte, error) {
  15. var rb []byte
  16. if cl.Config.LibDefaults.UDPPreferenceLimit == 1 {
  17. //1 means we should always use TCP
  18. rb, errtcp := cl.sendKDCTCP(realm, b)
  19. if errtcp != nil {
  20. if e, ok := errtcp.(messages.KRBError); ok {
  21. return rb, e
  22. }
  23. return rb, fmt.Errorf("communication error with KDC via TCP: %v", errtcp)
  24. }
  25. return rb, nil
  26. }
  27. if len(b) <= cl.Config.LibDefaults.UDPPreferenceLimit {
  28. //Try UDP first, TCP second
  29. rb, errudp := cl.sendKDCUDP(realm, b)
  30. if errudp != nil {
  31. if e, ok := errudp.(messages.KRBError); ok && e.ErrorCode != errorcode.KRB_ERR_RESPONSE_TOO_BIG {
  32. // Got a KRBError from KDC
  33. // If this is not a KRB_ERR_RESPONSE_TOO_BIG we will return immediately otherwise will try TCP.
  34. return rb, e
  35. }
  36. // Try TCP
  37. r, errtcp := cl.sendKDCTCP(realm, b)
  38. if errtcp != nil {
  39. if e, ok := errtcp.(messages.KRBError); ok {
  40. // Got a KRBError
  41. return r, e
  42. }
  43. return r, fmt.Errorf("failed to communicate with KDC. Attempts made with UDP (%v) and then TCP (%v)", errudp, errtcp)
  44. }
  45. rb = r
  46. }
  47. return rb, nil
  48. }
  49. //Try TCP first, UDP second
  50. rb, errtcp := cl.sendKDCTCP(realm, b)
  51. if errtcp != nil {
  52. if e, ok := errtcp.(messages.KRBError); ok {
  53. // Got a KRBError from KDC so returning and not trying UDP.
  54. return rb, e
  55. }
  56. rb, errudp := cl.sendKDCUDP(realm, b)
  57. if errudp != nil {
  58. if e, ok := errudp.(messages.KRBError); ok {
  59. // Got a KRBError
  60. return rb, e
  61. }
  62. return rb, fmt.Errorf("failed to communicate with KDC. Attempts made with TCP (%v) and then UDP (%v)", errtcp, errudp)
  63. }
  64. }
  65. return rb, nil
  66. }
  67. // dialKDCTCP establishes a UDP connection to a KDC.
  68. func dialKDCUDP(count int, kdcs map[int]string) (conn *net.UDPConn, err error) {
  69. i := 1
  70. for i <= count {
  71. udpAddr, e := net.ResolveUDPAddr("udp", kdcs[i])
  72. if e != nil {
  73. err = fmt.Errorf("error resolving KDC address: %v", e)
  74. return
  75. }
  76. conn, err = net.DialUDP("udp", nil, udpAddr)
  77. if err == nil {
  78. err = conn.SetDeadline(time.Now().Add(5 * time.Second))
  79. if err != nil {
  80. return
  81. }
  82. return
  83. }
  84. i++
  85. }
  86. err = errors.New("error in getting a UDP connection to any of the KDCs")
  87. return
  88. }
  89. // dialKDCTCP establishes a TCP connection to a KDC.
  90. func dialKDCTCP(count int, kdcs map[int]string) (conn *net.TCPConn, err error) {
  91. i := 1
  92. for i <= count {
  93. tcpAddr, e := net.ResolveTCPAddr("tcp", kdcs[i])
  94. if e != nil {
  95. err = fmt.Errorf("error resolving KDC address: %v", e)
  96. return
  97. }
  98. conn, err = net.DialTCP("tcp", nil, tcpAddr)
  99. if err == nil {
  100. err = conn.SetDeadline(time.Now().Add(5 * time.Second))
  101. if err != nil {
  102. return
  103. }
  104. return
  105. }
  106. i++
  107. }
  108. err = errors.New("error in getting a TCP connection to any of the KDCs")
  109. return
  110. }
  111. // sendKDCUDP sends bytes to the KDC via UDP.
  112. func (cl *Client) sendKDCUDP(realm string, b []byte) ([]byte, error) {
  113. var r []byte
  114. count, kdcs, err := cl.Config.GetKDCs(realm, false)
  115. if err != nil {
  116. return r, err
  117. }
  118. conn, err := dialKDCUDP(count, kdcs)
  119. if err != nil {
  120. return r, err
  121. }
  122. r, err = cl.sendUDP(conn, b)
  123. if err != nil {
  124. return r, err
  125. }
  126. return checkForKRBError(r)
  127. }
  128. // sendKDCTCP sends bytes to the KDC via TCP.
  129. func (cl *Client) sendKDCTCP(realm string, b []byte) ([]byte, error) {
  130. var r []byte
  131. count, kdcs, err := cl.Config.GetKDCs(realm, true)
  132. if err != nil {
  133. return r, err
  134. }
  135. conn, err := dialKDCTCP(count, kdcs)
  136. if err != nil {
  137. return r, err
  138. }
  139. rb, err := cl.sendTCP(conn, b)
  140. if err != nil {
  141. return r, err
  142. }
  143. return checkForKRBError(rb)
  144. }
  145. // sendUDP sends bytes to connection over UDP.
  146. func (cl *Client) sendUDP(conn *net.UDPConn, b []byte) ([]byte, error) {
  147. var r []byte
  148. defer conn.Close()
  149. _, err := conn.Write(b)
  150. if err != nil {
  151. return r, fmt.Errorf("error sending to (%s): %v", conn.RemoteAddr().String(), err)
  152. }
  153. udpbuf := make([]byte, 4096)
  154. n, _, err := conn.ReadFrom(udpbuf)
  155. r = udpbuf[:n]
  156. if err != nil {
  157. return r, fmt.Errorf("sending over UDP failed to %s: %v", conn.RemoteAddr().String(), err)
  158. }
  159. if len(r) < 1 {
  160. return r, fmt.Errorf("no response data from %s", conn.RemoteAddr().String())
  161. }
  162. return r, nil
  163. }
  164. // sendTCP sends bytes to connection over TCP.
  165. func (cl *Client) sendTCP(conn *net.TCPConn, b []byte) ([]byte, error) {
  166. defer conn.Close()
  167. var r []byte
  168. /*
  169. RFC https://tools.ietf.org/html/rfc4120#section-7.2.2
  170. Each request (KRB_KDC_REQ) and response (KRB_KDC_REP or KRB_ERROR)
  171. sent over the TCP stream is preceded by the length of the request as
  172. 4 octets in network byte order. The high bit of the length is
  173. reserved for future expansion and MUST currently be set to zero. If
  174. a KDC that does not understand how to interpret a set high bit of the
  175. length encoding receives a request with the high order bit of the
  176. length set, it MUST return a KRB-ERROR message with the error
  177. KRB_ERR_FIELD_TOOLONG and MUST close the TCP stream.
  178. NB: network byte order == big endian
  179. */
  180. var buf bytes.Buffer
  181. err := binary.Write(&buf, binary.BigEndian, uint32(len(b)))
  182. if err != nil {
  183. return r, err
  184. }
  185. b = append(buf.Bytes(), b...)
  186. _, err = conn.Write(b)
  187. if err != nil {
  188. return r, fmt.Errorf("error sending to KDC (%s): %v", conn.RemoteAddr().String(), err)
  189. }
  190. sh := make([]byte, 4, 4)
  191. _, err = conn.Read(sh)
  192. if err != nil {
  193. return r, fmt.Errorf("error reading response size header: %v", err)
  194. }
  195. s := binary.BigEndian.Uint32(sh)
  196. rb := make([]byte, s, s)
  197. _, err = io.ReadFull(conn, rb)
  198. if err != nil {
  199. return r, fmt.Errorf("error reading response: %v", err)
  200. }
  201. if len(rb) < 1 {
  202. return r, fmt.Errorf("no response data from KDC %s", conn.RemoteAddr().String())
  203. }
  204. return rb, nil
  205. }
  206. // checkForKRBError checks if the response bytes from the KDC are a KRBError.
  207. func checkForKRBError(b []byte) ([]byte, error) {
  208. var KRBErr messages.KRBError
  209. if err := KRBErr.Unmarshal(b); err == nil {
  210. return b, KRBErr
  211. }
  212. return b, nil
  213. }