;;; GNU Guix --- Functional package management for GNU
;;; Copyright © 2012, 2013 Andreas Enge <>
;;; Copyright © 2014, 2015, 2016 Mark H Weaver <>
;;; Copyright © 2016, 2017 Leo Famulari <>
;;; Copyright © 2016 Efraim Flashner <>
;;; Copyright © 2012, 2013 Nikita Karetnikov <>
;;; Copyright © 2012, 2017 Ludovic Courtès <>
;;; Copyright © 2017, 2019 Ricardo Wurmus <>
;;; Copyright © 2018 Tobias Geerinckx-Rice <>
;;; Copyright © 2017 Alex Vong <>
;;; Copyright © 2019 Mathieu Othacehe <>
;;; Copyright © 2020 Jan (janneke) Nieuwenhuizen <>
(define-module (gnu packages kerberos)
#:use-module (gnu packages)
#:use-module (gnu packages autotools)
#:use-module (gnu packages bison)
#:use-module (gnu packages dbm)
#:use-module (gnu packages perl)
#:use-module (gnu packages gettext)
#:use-module (gnu packages gnupg)
#:use-module (gnu packages libidn)
#:use-module (gnu packages hurd)
#:use-module (gnu packages linux)
#:use-module (gnu packages pkg-config)
#:use-module (gnu packages compression)
#:use-module (gnu packages readline)
#:use-module (gnu packages sqlite)
#:use-module (gnu packages texinfo)
#:use-module (gnu packages tls)
#:use-module ((guix licenses) #:prefix license:)
#:use-module (guix packages)
#:use-module (guix download)
#:use-module (guix utils)
#:use-module (guix build-system gnu))
(define-public mit-krb5
(name "mit-krb5")
(version "1.18")
(source (origin
(method url-fetch)
(uri (list
(string-append ""
(version-major+minor version)
"/krb5-" version ".tar.gz")
(string-append ""
(version-major+minor version)
"/krb5-" version ".tar.gz")))
(patches (search-patches "mit-krb5-qualify-short-hostnames.patch"
(build-system gnu-build-system)
`(("bison" ,bison)
("perl" ,perl)))
`(;; XXX: On 32-bit systems, 'kdb5_util' hangs on an fcntl/F_SETLKW call
;; while running the tests in 'src/tests'. Also disable tests when
;; cross-compiling.
#:tests? ,(and (not (%current-target-system))
(string=? (%current-system) "x86_64-linux"))
,@(if (%current-target-system)
(list "--localstatedir=/var"
(list "--localstatedir=/var")))
(modify-phases %standard-phases
(add-after 'unpack 'enter-source-directory
(lambda _
(chdir "src")
(add-before 'check 'pre-check
(lambda* (#:key inputs native-inputs #:allow-other-keys)
(let ((perl (assoc-ref (or native-inputs inputs) "perl")))
(substitute* "plugins/kdb/db2/libdb2/test/run.test"
(("/bin/cat") (string-append perl "/bin/perl"))
(("D/bin/sh") (string-append "D" (which "sh")))
(("bindir=/bin/.") (string-append "bindir=" perl "/bin"))))
;; avoid service names since /etc/services is unavailable
(substitute* "tests/resolve/Makefile"
(("-p telnet") "-p 23"))
(synopsis "MIT Kerberos 5")
"Massachusetts Institute of Technology implementation of Kerberos.
Kerberos is a network authentication protocol designed to provide strong
authentication for client/server applications by using secret-key
(license (license:non-copyleft "file://NOTICE"
"See NOTICE in the distribution."))
(home-page "")
(properties '((cpe-name . "kerberos")))))
(define-public shishi
(name "shishi")
(version "1.0.2")
(method url-fetch)
(uri (string-append "mirror://gnu/shishi/shishi-"
version ".tar.gz"))
(patches (search-patches "shishi-fix-libgcrypt-detection.patch"))
(build-system gnu-build-system)
'(;; This is required since we patch some of the build scripts.
;; Remove first two items for the next Shishi release after 1.0.2 or
;; when removing 'shishi-fix-libgcrypt-detection.patch'.
'("ac_cv_libgcrypt=yes" "--disable-static"
"--with-key-dir=/etc/shishi" "--with-db-dir=/var/shishi")
(modify-phases %standard-phases
(add-after 'configure 'disable-automatic-key-generation
(lambda* (#:key outputs #:allow-other-keys)
(substitute* "Makefile"
(native-inputs `(("pkg-config" ,pkg-config)))
`(("gnutls" ,gnutls)
("libidn" ,libidn)
("linux-pam" ,linux-pam-1.2)
("zlib" ,zlib)
("libgcrypt" ,libgcrypt)
("libtasn1" ,libtasn1)))
(home-page "")
(synopsis "Implementation of the Kerberos 5 network security system")
"GNU Shishi is a free implementation of the Kerberos 5 network security
system. It is used to allow non-secure network nodes to communicate in a
secure manner through client-server mutual authentication via tickets.
After installation, the system administrator should generate keys using
@code{shisa -a /etc/shishi/shishi.keys}.")
(license license:gpl3+)))
(define-public heimdal
(name "heimdal")
(version "7.7.0")
(source (origin
(method url-fetch)
(uri (string-append
"heimdal-" version "/" "heimdal-" version ".tar.gz"))
(modules '((guix build utils)))
(substitute* "configure"
(("User=.*$") "User=Guix\n")
(("Host=.*$") "Host=GNU")
(("Date=.*$") "Date=2019\n"))
(build-system gnu-build-system)
'(#:configure-flags (list
;; Avoid 7 MiB of .a files.
;; Do not build libedit.
(assoc-ref %build-inputs "readline") "/lib")
(assoc-ref %build-inputs "readline") "/include")
;; Do not build sqlite.
(assoc-ref %build-inputs "sqlite")))
#:phases (modify-phases %standard-phases
(add-before 'configure 'pre-configure
(lambda _
(substitute* '("appl/afsutil/pagsh.c"
(("/bin/sh") (which "sh")))
(add-before 'check 'pre-check
(lambda _
;; For 'getxxyyy-test'.
(setenv "USER" (passwd:name (getpwuid (getuid))))
;; Skip 'db' and 'kdc' tests for now.
;; FIXME: figure out why 'kdc' tests fail.
(with-output-to-file "tests/db/"
(lambda ()
(format #t "#!~a~%exit 1~%" (which "sh"))))
;; Tests fail when run in parallel.
#:parallel-tests? #f))
(native-inputs `(("e2fsprogs" ,e2fsprogs) ;for 'compile_et'
("texinfo" ,texinfo)
("unzip" ,unzip))) ;for tests
(inputs `(("readline" ,readline)
("bdb" ,bdb)
("e2fsprogs" ,e2fsprogs) ;for libcom_err
("sqlite" ,sqlite)))
(home-page "")
(synopsis "Kerberos 5 network authentication")
"Heimdal is an implementation of Kerberos 5 network authentication
(license license:bsd-3)))