ImpersonateSecurityContext
関数シグネチャ
// SECUR32.dll
#include <windows.h>
HRESULT ImpersonateSecurityContext(
SecHandle* phContext
);パラメーター
| 名前 | 型 | 方向 | 説明 |
|---|---|---|---|
| phContext | SecHandle* | in | 偽装するコンテキストのハンドル。このハンドルは、 AcceptSecurityContext (General) 関数の呼び出しによって取得したものである必要があります。 |
戻り値の型: HRESULT
公式ドキュメント
AcceptSecurityContext (General) または QuerySecurityContextToken の呼び出しによって以前に取得したトークンを使用して、サーバーがクライアントを偽装できるようにします。
戻り値
関数が成功すると、SEC_E_OK を返します。
関数が失敗すると、次のエラー コードのいずれかを返します。
| リターン コード | 説明 |
|---|---|
| 関数に渡されたハンドルが無効です。 | |
| クライアントを偽装できませんでした。 | |
| この値は、この関数がサポートされていないことを示すために Schannel のカーネル モードから返されます。 |
解説(Remarks)
サーバー アプリケーションは、クライアントを偽装する必要があるときに ImpersonateSecurityContext 関数を呼び出します。その前に、サーバーは有効なコンテキスト ハンドルを取得しておく必要があります。コンテキスト ハンドルを取得するには、サーバーは AcceptSecurityContext (General) を呼び出して、クライアントから受信したセキュリティ トークンをセキュリティ システムに渡す必要があります。受信コンテキストが検証されると、サーバーはコンテキスト ハンドルを取得します。この関数は偽装トークンを作成し、スレッドまたはプロセスが偽装コンテキストで実行できるようにします。
Schannel セキュリティ サポート プロバイダー (SSP) を使用する場合、サーバー アプリケーションは AcceptSecurityContext (General) を呼び出す際に ASC_REQ_MUTUAL_AUTH フラグを渡す必要があります。これにより、SSL/TLS ハンドシェイク中にクライアントに対してクライアント証明書が要求されます。クライアント証明書を受信すると、Schannel パッケージはそのクライアント証明書を検証し、ユーザー アカウントへのマッピングを試みます。このマッピングが成功すると、クライアント ユーザー トークンが作成され、この関数は成功します。
アプリケーション サーバーは、処理を終えたとき、または自身のセキュリティ コンテキストを復元する必要があるときに、 RevertSecurityContext 関数を呼び出す必要があります。
ImpersonateSecurityContext は、すべてのプラットフォームのすべてのセキュリティ パッケージで利用できるわけではありません。通常は、偽装をサポートするプラットフォームおよびセキュリティ パッケージでのみ実装されています。セキュリティ パッケージが偽装をサポートしているかどうかを確認するには、 QuerySecurityPackageInfo 関数を呼び出します。
- トークンの要求された偽装レベルが SecurityImpersonation より低い (SecurityIdentification や SecurityAnonymous など)。
- 呼び出し元が SeImpersonatePrivilege 特権を持っている。
- プロセス (または呼び出し元のログオン セッション内の別のプロセス) が、LogonUser または LsaLogonUser 関数で明示的な資格情報を使用してそのトークンを作成した。
- 認証された ID が呼び出し元と同じである。
Windows XP: SeImpersonatePrivilege 特権は、Windows XP with Service Pack 2 (SP2) までサポートされていません。
Microsoft 公式リファレンス: 英語 (en-us) · 日本語 (ja-jp) · 原文ソース (GitHub)
各言語での呼び出し定義
// SECUR32.dll
#include <windows.h>
HRESULT ImpersonateSecurityContext(
SecHandle* phContext
);[DllImport("SECUR32.dll", ExactSpelling = true)]
static extern int ImpersonateSecurityContext(
IntPtr phContext // SecHandle*
);<DllImport("SECUR32.dll", ExactSpelling:=True)>
Public Shared Function ImpersonateSecurityContext(
phContext As IntPtr ' SecHandle*
) As Integer
End Function' phContext : SecHandle*
Declare PtrSafe Function ImpersonateSecurityContext Lib "secur32" ( _
ByVal phContext As LongPtr) As Long
' VBA7前提(PtrSafe)。32bit Office では LongPtr→Long。Integer=16bit / Long=32bit / LongLong=64bit。import ctypes
from ctypes import wintypes
ImpersonateSecurityContext = ctypes.windll.secur32.ImpersonateSecurityContext
ImpersonateSecurityContext.restype = ctypes.c_int
ImpersonateSecurityContext.argtypes = [
ctypes.c_void_p, # phContext : SecHandle*
]require 'fiddle'
require 'fiddle/import'
lib = Fiddle.dlopen('SECUR32.dll')
ImpersonateSecurityContext = Fiddle::Function.new(
lib['ImpersonateSecurityContext'],
[
Fiddle::TYPE_VOIDP, # phContext : SecHandle*
],
Fiddle::TYPE_INT)#[link(name = "secur32")]
extern "system" {
fn ImpersonateSecurityContext(
phContext: *mut SecHandle // SecHandle*
) -> i32;
}
// crates: windows-sys provides ready-made bindings for this API.$sig = @"
[DllImport("SECUR32.dll")]
public static extern int ImpersonateSecurityContext(IntPtr phContext);
"@
$api = Add-Type -MemberDefinition $sig -Name 'SECUR32_ImpersonateSecurityContext' -Namespace Win32 -PassThru
# $api::ImpersonateSecurityContext(phContext)#uselib "SECUR32.dll"
#func global ImpersonateSecurityContext "ImpersonateSecurityContext" sptr
; ImpersonateSecurityContext varptr(phContext) ; 戻り値は stat
; phContext : SecHandle* -> "sptr"
; ※HSP3.7は #func のため戻り値はシステム変数 stat に格納されます。#uselib "SECUR32.dll" #cfunc global ImpersonateSecurityContext "ImpersonateSecurityContext" var ; res = ImpersonateSecurityContext(phContext) ; phContext : SecHandle* -> "var" ; ※出力/バッファ引数は var 方式(変数を直接渡す)。varptr 方式にも切替可。#uselib "SECUR32.dll" #cfunc global ImpersonateSecurityContext "ImpersonateSecurityContext" sptr ; res = ImpersonateSecurityContext(varptr(phContext)) ; phContext : SecHandle* -> "sptr" ; ※出力/バッファ引数はポインタ方式(token=sptr / 呼び出しは varptr(変数))。
; HRESULT ImpersonateSecurityContext(SecHandle* phContext) #uselib "SECUR32.dll" #cfunc global ImpersonateSecurityContext "ImpersonateSecurityContext" var ; res = ImpersonateSecurityContext(phContext) ; phContext : SecHandle* -> "var" ; ※出力/バッファ引数は var 方式(変数を直接渡す)。varptr 方式にも切替可。; HRESULT ImpersonateSecurityContext(SecHandle* phContext) #uselib "SECUR32.dll" #cfunc global ImpersonateSecurityContext "ImpersonateSecurityContext" intptr ; res = ImpersonateSecurityContext(varptr(phContext)) ; phContext : SecHandle* -> "intptr" ; ※出力/バッファ引数はポインタ方式(token=intptr / 呼び出しは varptr(変数))。
import (
"golang.org/x/sys/windows"
"unsafe"
)
var (
secur32 = windows.NewLazySystemDLL("SECUR32.dll")
procImpersonateSecurityContext = secur32.NewProc("ImpersonateSecurityContext")
)
// phContext (SecHandle*)
r1, _, err := procImpersonateSecurityContext.Call(
uintptr(phContext),
)
_ = err // syscall.Errno (valid when the call sets last-error)
_ = r1 // HRESULTfunction ImpersonateSecurityContext(
phContext: Pointer // SecHandle*
): Integer; stdcall;
external 'SECUR32.dll' name 'ImpersonateSecurityContext';result := DllCall("SECUR32\ImpersonateSecurityContext"
, "Ptr", phContext ; SecHandle*
, "Int") ; return: HRESULT●ImpersonateSecurityContext(phContext) = DLL("SECUR32.dll", "int ImpersonateSecurityContext(void*)")
# 呼び出し: ImpersonateSecurityContext(phContext)
# phContext : SecHandle* -> "void*"
# なでしこ1は32bit・ANSI(Shift_JIS)。文字列=char*(ANSI)、ポインタ/ハンドル=void*(4byte)。const std = @import("std");
extern "secur32" fn ImpersonateSecurityContext(
phContext: [*c]SecHandle // SecHandle*
) callconv(std.os.windows.WINAPI) i32;proc ImpersonateSecurityContext(
phContext: ptr SecHandle # SecHandle*
): int32 {.importc: "ImpersonateSecurityContext", stdcall, dynlib: "SECUR32.dll".}pragma(lib, "secur32");
extern(Windows)
int ImpersonateSecurityContext(
SecHandle* phContext // SecHandle*
);ccall((:ImpersonateSecurityContext, "SECUR32.dll"), stdcall, Int32,
(Ptr{SecHandle},),
phContext)
# phContext : SecHandle* -> Ptr{SecHandle}
# stdcall は 32bit のみ意味を持つ(x64 では無視)。local ffi = require("ffi")
ffi.cdef[[
int32_t ImpersonateSecurityContext(
void* phContext);
]]
local secur32 = ffi.load("secur32")
-- secur32.ImpersonateSecurityContext(phContext)
-- phContext : SecHandle*
-- 構造体/GUIDへのポインタは cdef が通るよう void* で表記(実型は各引数コメント参照)。値渡し構造体・enum は対応する typedef を cdef に追加すること。const koffi = require('koffi');
const lib = koffi.load('SECUR32.dll');
const ImpersonateSecurityContext = lib.func('__stdcall', 'ImpersonateSecurityContext', 'int32_t', ['void *']);
// ImpersonateSecurityContext(phContext)
// phContext : SecHandle* -> 'void *'
// 出力ポインタは koffi.out(...) で包む。構造体は koffi.struct で定義。const lib = Deno.dlopen("SECUR32.dll", {
ImpersonateSecurityContext: { parameters: ["pointer"], result: "i32" },
});
// lib.symbols.ImpersonateSecurityContext(phContext)
// phContext : SecHandle* -> "pointer"
// 文字列引数は "buffer"(NUL 終端のバイト列を Uint8Array で渡す)。
// 値渡し構造体は { struct: [ ...field types... ] } を使用。<?php
$ffi = FFI::cdef(<<<C
int32_t ImpersonateSecurityContext(
void* phContext);
C, "SECUR32.dll");
// $ffi->ImpersonateSecurityContext(phContext);
// phContext : SecHandle*
// 構造体/GUIDへのポインタは cdef が通るよう void* で表記(実型は各引数コメント参照)。値渡し構造体・enum は対応する typedef を cdef に追加すること。
// WINAPI(stdcall): x64 では呼出規約が統一されるため問題なし。x86 では __stdcall 対応のラッパが必要な場合あり。import com.sun.jna.*;
import com.sun.jna.ptr.*;
import com.sun.jna.win32.StdCallLibrary;
import com.sun.jna.win32.W32APIOptions;
public interface Secur32 extends StdCallLibrary {
Secur32 INSTANCE = Native.load("secur32", Secur32.class);
int ImpersonateSecurityContext(
Pointer phContext // SecHandle*
);
}@[Link("secur32")]
lib LibSECUR32
fun ImpersonateSecurityContext = ImpersonateSecurityContext(
phContext : SecHandle* # SecHandle*
) : Int32
end
# 構造体/GUID/enum は lib 内に対応する型定義が必要。
# 呼出規約: x64 は規約統一のため OK。x86(32bit)は WINAPI=stdcall だが Crystal の fun に stdcall 付与構文がなく非対応。import 'dart:ffi';
import 'package:ffi/ffi.dart';
typedef ImpersonateSecurityContextNative = Int32 Function(Pointer<Void>);
typedef ImpersonateSecurityContextDart = int Function(Pointer<Void>);
final ImpersonateSecurityContext = DynamicLibrary.open('SECUR32.dll')
.lookupFunction<ImpersonateSecurityContextNative, ImpersonateSecurityContextDart>('ImpersonateSecurityContext');
// phContext : SecHandle* -> Pointer<Void>
// 文字列は package:ffi の "...".toNativeUtf16()/toNativeUtf8() で変換。{$mode objfpc}{$H+}
function ImpersonateSecurityContext(
phContext: Pointer // SecHandle*
): Integer; stdcall;
external 'SECUR32.dll' name 'ImpersonateSecurityContext';import Foreign
import Foreign.C.Types
import Foreign.C.String
foreign import stdcall safe "ImpersonateSecurityContext"
c_ImpersonateSecurityContext :: Ptr () -> IO Int32
-- phContext : SecHandle* -> Ptr ()
-- 要 GHC(Windows)。stdcall は x64 では ccall として扱われる。ブロックする API は safe 呼び出し推奨。open Ctypes
open Foreign
let impersonatesecuritycontext =
foreign "ImpersonateSecurityContext"
((ptr void) @-> returning int32_t)
(* phContext : SecHandle* -> (ptr void) *)
(* foreign は cdecl 前提。x64 Windows では WINAPI と一致。構造体は ctypes structure を定義のこと。 *)(cffi:define-foreign-library secur32 (t "SECUR32.dll"))
(cffi:use-foreign-library secur32)
(cffi:defcfun ("ImpersonateSecurityContext" impersonate-security-context :convention :stdcall) :int32
(ph-context :pointer)) ; SecHandle*
; isize/usize(INT_PTR/SIZE_T)は x64 前提で :int64/:uint64。x86 では :int32/:uint32。use Win32::API;
my $ImpersonateSecurityContext = Win32::API::More->new('SECUR32',
'int ImpersonateSecurityContext(LPVOID phContext)');
# my $ret = $ImpersonateSecurityContext->Call($phContext);
# phContext : SecHandle* -> LPVOID
# 値渡し構造体は pack() した文字列、または Win32::API::Struct を使用。関連項目
- f AcceptSecurityContext — サーバー側でセキュリティコンテキストを受け入れ確立する。
- f QuerySecurityPackageInfoW — 名前を指定してセキュリティパッケージの情報を取得する(Unicode版)。
- f RevertSecurityContext — セキュリティコンテキストのなりすましを元に戻す。