ProtoCore v1.0.16
Deterministic, zero-heap network stack for embedded targets
Loading...
Searching...
No Matches
spnego.h File Reference

SPNEGO (RFC 4178) GSS-API wrapping of the NTLMSSP tokens for the SMB2 client (PROTOCORE_ENABLE_SMB). More...

#include "protocore_config.h"

Go to the source code of this file.

Classes

struct  SpnegoNs
 Dispatch table. Addressed by offset, so the layout is asserted below. More...
 

Functions

 PROTOCORE_NS_LAYOUT (SpnegoNs, wrap_negotiate, parse_response, wrap_authenticate)
 
size_t protocore_spnego_wrap_negotiate (uint8_t *work, const uint8_t *ntlm, size_t protocore_ntlm_len, uint8_t *out, size_t cap)
 Wrap an NTLMSSP NEGOTIATE token in a SPNEGO GSS-API .
 
proto_bool protocore_spnego_parse_response (uint8_t *work, const uint8_t *blob, size_t len, const uint8_t **protocore_resp_token, size_t *protocore_resp_len)
 Extract the responseToken (the NTLMSSP CHALLENGE) from a server .
 
size_t protocore_spnego_wrap_authenticate (uint8_t *work, const uint8_t *ntlm, size_t protocore_ntlm_len, uint8_t *out, size_t cap)
 Wrap an NTLMSSP AUTHENTICATE token in a SPNEGO NegTokenResp (the .
 

Variables

PROTOCORE_NS SpnegoNs Spnego PROTOCORE_UNUSED
 Module namespace.
 

Detailed Description

SPNEGO (RFC 4178) GSS-API wrapping of the NTLMSSP tokens for the SMB2 client (PROTOCORE_ENABLE_SMB).

SMB2 SESSION_SETUP carries the NTLM handshake tokens inside a SPNEGO negotiation token. This is the minimal ASN.1 DER layer that a client needs:

  • the first client token is a GSS-API InitialContextToken: [APPLICATION 0] { SPNEGO-OID, NegTokenInit [0] { mechTypes [0] { NTLM-OID }, mechToken [2] OCTET STRING(NTLMSSP NEGOTIATE) } };
  • the server replies with a bare NegTokenResp [1] { ..., responseToken [2] OCTET STRING(NTLMSSP CHALLENGE) }, from which the client extracts the CHALLENGE;
  • the client's second token is a NegTokenResp [1] { responseToken [2] OCTET STRING(NTLMSSP AUTHENTICATE) }.

Pure DER, zero heap, definite-length only. The NTLM tokens come from ntlmssp.h.

work is bytes the CALLER holds. This module reads none of them: it carries nothing between calls, so there is no state to keep and nothing to wipe. The parameter is there so a caller drives every namespace the same way.

Author
Douglas Quigg (dstroy0)
Date
2026

Definition in file spnego.h.

Function Documentation

◆ PROTOCORE_NS_LAYOUT()

PROTOCORE_NS_LAYOUT ( SpnegoNs  ,
wrap_negotiate  ,
parse_response  ,
wrap_authenticate   
)

◆ protocore_spnego_wrap_negotiate()

size_t protocore_spnego_wrap_negotiate ( uint8_t *  work,
const uint8_t *  ntlm,
size_t  protocore_ntlm_len,
uint8_t *  out,
size_t  cap 
)

Wrap an NTLMSSP NEGOTIATE token in a SPNEGO GSS-API .

Parameters
workPROTOCORE_SPNEGO_BORROW bytes the caller took. Not held past the call.
ntlmNtlm
protocore_ntlm_lenProtocore ntlm len
outOut
capCap
Returns
The size_t.

◆ protocore_spnego_parse_response()

proto_bool protocore_spnego_parse_response ( uint8_t *  work,
const uint8_t *  blob,
size_t  len,
const uint8_t **  protocore_resp_token,
size_t *  protocore_resp_len 
)

Extract the responseToken (the NTLMSSP CHALLENGE) from a server .

Parameters
workPROTOCORE_SPNEGO_BORROW bytes the caller took. Not held past the call.
blobBlob
lenLen
protocore_resp_tokenreceives a pointer INTO blob; protocore_resp_len its length
protocore_resp_lenProtocore resp len
Returns
PROTO_TRUE on success.

◆ protocore_spnego_wrap_authenticate()

size_t protocore_spnego_wrap_authenticate ( uint8_t *  work,
const uint8_t *  ntlm,
size_t  protocore_ntlm_len,
uint8_t *  out,
size_t  cap 
)

Wrap an NTLMSSP AUTHENTICATE token in a SPNEGO NegTokenResp (the .

Parameters
workPROTOCORE_SPNEGO_BORROW bytes the caller took. Not held past the call.
ntlmNtlm
protocore_ntlm_lenProtocore ntlm len
outOut
capCap
Returns
The size_t.

Variable Documentation

◆ PROTOCORE_UNUSED

PROTOCORE_NS SpnegoNs Spnego PROTOCORE_UNUSED
Initial value:
= {.wrap_negotiate = protocore_spnego_wrap_negotiate,
.wrap_authenticate = protocore_spnego_wrap_authenticate}
proto_bool protocore_spnego_parse_response(uint8_t *work, const uint8_t *blob, size_t len, const uint8_t **protocore_resp_token, size_t *protocore_resp_len)
Extract the responseToken (the NTLMSSP CHALLENGE) from a server .
size_t protocore_spnego_wrap_authenticate(uint8_t *work, const uint8_t *ntlm, size_t protocore_ntlm_len, uint8_t *out, size_t cap)
Wrap an NTLMSSP AUTHENTICATE token in a SPNEGO NegTokenResp (the .
size_t protocore_spnego_wrap_negotiate(uint8_t *work, const uint8_t *ntlm, size_t protocore_ntlm_len, uint8_t *out, size_t cap)
Wrap an NTLMSSP NEGOTIATE token in a SPNEGO GSS-API .

Module namespace.

Definition at line 83 of file spnego.h.