Win32 API 日本語リファレンス
ホーム › Security.Authentication.Identity › InitializeSecurityContextA

InitializeSecurityContextA

関数
クライアント側のセキュリティコンテキストを初期化する(ANSI版)。
DLLSECUR32.dll文字セットANSI (-A)呼出規約winapi対応OSWindows XP 以降

シグネチャ

// SECUR32.dll  (ANSI / -A)
#include <windows.h>

HRESULT InitializeSecurityContextA(
    SecHandle* phCredential,   // optional
    SecHandle* phContext,   // optional
    CHAR* pszTargetName,   // optional
    ISC_REQ_FLAGS fContextReq,
    DWORD Reserved1,
    DWORD TargetDataRep,
    SecBufferDesc* pInput,   // optional
    DWORD Reserved2,
    SecHandle* phNewContext,   // optional
    SecBufferDesc* pOutput,   // optional
    DWORD* pfContextAttr,
    LONGLONG* ptsExpiry   // optional
);

パラメーター

名前型方向説明
phCredentialSecHandle*inoptional資格情報へのハンドル。 AcquireCredentialsHandle (General) によって返されます。このハンドルはセキュリティコンテキストの構築に使用されます。InitializeSecurityContext (General) 関数には、少なくとも OUTBOUND の資格情報が必要です。
phContextSecHandle*inoptional

CtxtHandle 構造体へのポインター。InitializeSecurityContext (General) の最初の呼び出しでは、このポインターは NULL です。2 回目の呼び出しでは、このパラメーターは、最初の呼び出しで phNewContext パラメーターに返された、部分的に形成されたコンテキストのハンドルへのポインターになります。

このパラメーターは Microsoft Digest SSP では省略可能であり、NULL を設定できます。

Schannel SSP を使用する場合、InitializeSecurityContext (General) の最初の呼び出しでは NULL を指定します。以降の呼び出しでは、この関数の最初の呼び出し後に phNewContext パラメーターで受け取ったトークンを指定します。

pszTargetNameCHAR*inoptional未定 (TBD)
fContextReqISC_REQ_FLAGSin

コンテキストに対する要求を示すビットフラグ。すべてのパッケージがすべての要件をサポートできるわけではありません。このパラメーターで使用するフラグには ISC_REQ_ というプレフィックスが付きます (例: ISC_REQ_DELEGATE)。このパラメーターには、次の属性フラグの 1 つ以上を指定できます。

値 意味
ISC_REQ_ALLOCATE_MEMORY
セキュリティパッケージが出力バッファーを割り当てます。出力バッファーの使用が終わったら、 FreeContextBuffer 関数を呼び出して解放してください。
ISC_REQ_CONFIDENTIALITY
EncryptMessage 関数を使用してメッセージを暗号化します。
ISC_REQ_CONNECTION
セキュリティコンテキストはメッセージのフォーマット処理を行いません。この値は、Kerberos、Negotiate、NTLM の各セキュリティパッケージの既定値です。
ISC_REQ_DELEGATE
サーバーは、このコンテキストを使用してクライアントとして他のサーバーに対して認証できます。このフラグを機能させるには、ISC_REQ_MUTUAL_AUTH フラグを設定する必要があります。Kerberos で有効です。制約付き委任では、このフラグは無視してください。
ISC_REQ_EXTENDED_ERROR
エラーが発生した場合、リモート側に通知されます。
ISC_REQ_HTTP
HTTP 用に Digest を使用します。Digest を SASL メカニズムとして使用する場合は、このフラグを省略します。
ISC_REQ_INTEGRITY
EncryptMessage 関数および MakeSignature 関数を使用して、メッセージへの署名と署名の検証を行います。
ISC_REQ_MANUAL_CRED_VALIDATION
Schannel はサーバーを自動的に認証してはなりません。
ISC_REQ_MUTUAL_AUTH
サービスの相互認証ポリシーが満たされます。
注意 これは、必ずしも相互認証が実行されることを意味するものではなく、サービスの認証ポリシーが満たされることのみを意味します。相互認証が実際に実行されたことを確認するには、QueryContextAttributes (General) 関数を呼び出してください。
ISC_REQ_NO_INTEGRITY
このフラグが設定されている場合、ISC_REQ_INTEGRITY フラグは無視されます。

この値は、Negotiate および Kerberos のセキュリティパッケージでのみサポートされます。

ISC_REQ_REPLAY_DETECT
EncryptMessage 関数または MakeSignature 関数を使用してエンコードされた、再生 (リプレイ) されたメッセージを検出します。
ISC_REQ_SEQUENCE_DETECT
順序どおりに受信されなかったメッセージを検出します。
ISC_REQ_STREAM
ストリーム指向の接続をサポートします。
ISC_REQ_USE_SESSION_KEY
新しいセッションキーをネゴシエートする必要があります。

この値は、Kerberos セキュリティパッケージでのみサポートされます。

ISC_REQ_USE_SUPPLIED_CREDS
Schannel はクライアントの資格情報を自動的に提供しようとしてはなりません。

要求した属性がクライアントでサポートされない場合があります。詳細については、pfContextAttr パラメーターを参照してください。

各種属性のさらに詳しい説明については、 Context Requirements を参照してください。

Reserved1DWORDinこのパラメーターは予約されており、0 を設定する必要があります。
TargetDataRepDWORDin

ターゲット上のバイト順序などのデータ表現。このパラメーターには、SECURITY_NATIVE_DREP または SECURITY_NETWORK_DREP のいずれかを指定できます。

このパラメーターは Digest および Schannel では使用されません。0 を設定してください。

pInputSecBufferDesc*inoptionalパッケージへの入力として渡されるバッファーへのポインターを含む SecBufferDesc 構造体へのポインター。クライアントコンテキストがサーバーによって開始された場合を除き、このパラメーターの値は、関数の最初の呼び出しでは NULL でなければなりません。以降の呼び出しでは、またはクライアントコンテキストがサーバーによって開始された場合は、このパラメーターの値は、リモートコンピューターから返されたトークンを保持できるだけのメモリが割り当てられたバッファーへのポインターになります。
Reserved2DWORDinこのパラメーターは予約されており、0 を設定する必要があります。
phNewContextSecHandle*inoutoptional

CtxtHandle 構造体へのポインター。InitializeSecurityContext (General) の最初の呼び出しでは、このポインターが新しいコンテキストハンドルを受け取ります。2 回目の呼び出しでは、phNewContext に phContext パラメーターで指定したハンドルと同じものを指定できます。

Schannel SSP を使用する場合、2 回目以降の呼び出しでは、ここで返されたハンドルを phContext パラメーターとして渡し、phNewContext には NULL を指定します。

pOutputSecBufferDesc*inoutoptional

出力データを受け取る SecBuffer 構造体へのポインターを含む SecBufferDesc 構造体へのポインター。入力で SEC_READWRITE として型指定されたバッファーは、出力にも存在します。(ISC_REQ_ALLOCATE_MEMORY によって) 要求された場合、システムはセキュリティトークン用のバッファーを割り当て、セキュリティトークンのバッファー記述子にそのアドレスを設定します。

Microsoft Digest SSP を使用する場合、このパラメーターは、サーバーに送信する必要があるチャレンジ応答を受け取ります。

Schannel SSP を使用する場合、ISC_REQ_ALLOCATE_MEMORY フラグが指定されていると、Schannel SSP はバッファー用のメモリを割り当て、適切な情報を SecBufferDesc に設定します。さらに、呼び出し元は SECBUFFER_ALERT 型のバッファーを渡す必要があります。出力時にアラートが生成された場合、このバッファーにはそのアラートに関する情報が格納され、関数は失敗します。

pfContextAttrDWORD*out

確立されたコンテキストの属性を示すビットフラグのセットを受け取る変数へのポインター。各種属性の説明については、 Context Requirements を参照してください。

このパラメーターで使用するフラグには、ISC_RET_DELEGATE のように ISC_RET というプレフィックスが付きます。

有効な値の一覧については、fContextReq パラメーターを参照してください。

最後の関数呼び出しが成功して戻るまでは、セキュリティ関連の属性を確認しないでください。ASC_RET_ALLOCATED_MEMORY フラグなど、セキュリティに関連しない属性フラグは、最後に戻る前でも確認できます。

メモ 特定のコンテキスト属性は、リモートピアとのネゴシエーション中に変化することがあります。
ptsExpiryLONGLONG*outoptional

コンテキストの有効期限を受け取る TimeStamp 構造体へのポインター。セキュリティパッケージは、この値を常にローカル時刻で返すことが推奨されます。このパラメーターは省略可能で、短時間のみ動作するクライアントでは NULL を渡してください。

Microsoft Digest SSP のセキュリティコンテキストや資格情報には、有効期限はありません。

- pTargetName [in, optional]

コンテキストのターゲットを示す、null で終わる文字列へのポインター。文字列の内容は、次の表に示すようにセキュリティパッケージごとに異なります。この一覧はすべてを網羅したものではありません。システムには、追加のシステム SSP やサードパーティ製 SSP を追加できます。

使用する SSP 意味
Digest
要求されたリソースの URI を一意に識別する、null で終わる文字列。この文字列は URI で使用が許可される文字で構成され、US ASCII コードセットで表現できる必要があります。US ASCII コードセット以外の文字を表すには、パーセントエンコーディングを使用できます。
Kerberos または Negotiate
宛先サーバーのサービスプリンシパル名 (SPN) またはセキュリティコンテキスト。
NTLM
宛先サーバーのサービスプリンシパル名 (SPN) またはセキュリティコンテキスト。
Schannel/SSL
ターゲットサーバーを一意に識別する、null で終わる文字列。Schannel はこの値を使用してサーバー証明書を検証します。また、接続を再確立する際に、セッションキャッシュ内のセッションを特定するためにもこの値を使用します。キャッシュされたセッションが使用されるのは、次の条件がすべて満たされる場合のみです。
  • ターゲット名が同じである。
  • キャッシュエントリの有効期限が切れていない。
  • 関数を呼び出すアプリケーションプロセスが同じである。
  • ログオンセッションが同じである。
  • 資格情報ハンドルが同じである。

戻り値の型: HRESULT

公式ドキュメント

資格情報ハンドルから、クライアント側の送信 (outbound) セキュリティコンテキストを開始します。(ANSI)

戻り値

関数が成功した場合、次のいずれかの成功コードを返します。

戻り値 説明
SEC_I_COMPLETE_AND_CONTINUE
クライアントは CompleteAuthToken を呼び出し、その出力をサーバーに渡す必要があります。その後、クライアントは返されるトークンを待ち、別の呼び出しでそのトークンを InitializeSecurityContext (General) に渡します。
SEC_I_COMPLETE_NEEDED
クライアントはメッセージの構築を完了し、 CompleteAuthToken 関数を呼び出す必要があります。
SEC_I_CONTINUE_NEEDED
クライアントは出力トークンをサーバーに送信し、返されるトークンを待つ必要があります。返されたトークンは、別の InitializeSecurityContext (General) の呼び出しに渡されます。出力トークンは空の場合もあります。
SEC_I_INCOMPLETE_CREDENTIALS
Schannel で使用されます。サーバーがクライアント認証を要求しましたが、指定された資格情報に証明書が含まれていないか、その証明書がサーバーの信頼する証明機関によって発行されたものではありません。詳細については、「解説」を参照してください。
SEC_E_INCOMPLETE_MESSAGE
Schannel で使用されます。メッセージ全体のデータがネットワークから読み取られていません。

この値が返された場合、pInput バッファーには、BufferType メンバーが SECBUFFER_MISSING である SecBuffer 構造体が格納されます。SecBuffer の cbBuffer メンバーには、この関数が成功するまでにクライアントから追加で読み取る必要があるバイト数を示す値が格納されます。この数値は必ずしも正確ではありませんが、これを利用することで、この関数を何度も呼び出すことを避け、パフォーマンスを向上させることができます。

SEC_E_OK
セキュリティコンテキストが正常に初期化されました。InitializeSecurityContext (General) を再度呼び出す必要はありません。関数が出力トークンを返した場合、つまり pOutput 内の SECBUFFER_TOKEN の長さが 0 以外の場合は、そのトークンをサーバーに送信する必要があります。

関数が失敗した場合、次のいずれかのエラーコードを返します。

戻り値 説明
SEC_E_INSUFFICIENT_MEMORY
要求された処理を完了するために使用できるメモリが不足しています。
SEC_E_INTERNAL_ERROR
SSPI のエラーコードに対応付けられないエラーが発生しました。
SEC_E_INVALID_HANDLE
関数に渡されたハンドルが無効です。
SEC_E_INVALID_TOKEN
入力トークンの形式が不正であることが原因のエラーです。たとえば、転送中に破損したトークン、サイズが正しくないトークン、誤ったセキュリティパッケージに渡されたトークンなどです。クライアントとサーバーが適切なセキュリティパッケージをネゴシエートしなかった場合に、誤ったパッケージにトークンが渡されることがあります。
SEC_E_LOGON_DENIED
ログオンに失敗しました。
SEC_E_NO_AUTHENTICATING_AUTHORITY
認証のために接続できる機関がありませんでした。認証を行う側のドメイン名が誤っているか、ドメインに到達できないか、または信頼関係の障害が発生している可能性があります。
SEC_E_NO_CREDENTIALS
セキュリティパッケージに使用できる資格情報がありません。
SEC_E_TARGET_UNKNOWN
ターゲットが認識されませんでした。
SEC_E_UNSUPPORTED_FUNCTION
無効なコンテキスト属性フラグ (ISC_REQ_DELEGATE または ISC_REQ_PROMPT_FOR_CREDS) が fContextReq パラメーターに指定されました。
SEC_E_WRONG_PRINCIPAL
認証要求を受け取ったプリンシパルが、pszTargetName パラメーターに渡されたプリンシパルと異なります。これは相互認証の失敗を示します。

解説(Remarks)

最終的なコンテキスト属性が十分かどうかを判断する責任は、呼び出し元にあります。たとえば、機密性を要求したにもかかわらず確立できなかった場合、アプリケーションによっては直ちに接続を終了することを選択できます。

セキュリティコンテキストの属性が十分でない場合、クライアントは DeleteSecurityContext 関数を呼び出して、部分的に作成されたコンテキストを解放する必要があります。

InitializeSecurityContext (General) 関数は、クライアントが送信 (outbound) コンテキストを初期化するために使用します。

2 段階 (two-leg) のセキュリティコンテキストの場合、呼び出しの手順は次のとおりです。

  1. クライアントは phContext に NULL を設定して関数を呼び出し、バッファー記述子に入力メッセージを設定します。
  2. セキュリティパッケージはパラメーターを検査して不透明 (opaque) なトークンを構築し、バッファー配列の TOKEN 要素に格納します。fContextReq パラメーターに ISC_REQ_ALLOCATE_MEMORY フラグが含まれている場合、セキュリティパッケージがメモリを割り当て、TOKEN 要素にそのポインターを返します。
  3. クライアントは、pOutput バッファーに返されたトークンをターゲットサーバーに送信します。次に、サーバーはそのトークンを入力引数として AcceptSecurityContext (General) 関数の呼び出しに渡します。
  4. AcceptSecurityContext (General) はトークンを返すことがあります。最初の呼び出しが SEC_I_CONTINUE_NEEDED を返した場合、サーバーはそのトークンをクライアントに送信し、クライアントは 2 回目の InitializeSecurityContext (General) の呼び出しに使用します。
相互認証など、複数段階 (multiple-leg) のセキュリティコンテキストの場合、呼び出しの手順は次のとおりです。
  1. クライアントは前述のとおり関数を呼び出しますが、パッケージは成功コード SEC_I_CONTINUE_NEEDED を返します。
  2. クライアントは出力トークンをサーバーに送信し、サーバーからの応答を待ちます。
  3. サーバーの応答を受け取ったら、クライアントは、前回の呼び出しで返されたハンドルを phContext に設定して InitializeSecurityContext (General) を再度呼び出します。サーバーから受け取ったトークンは pInput パラメーターで指定します。
サーバーが正常に応答した場合、セキュリティパッケージは SEC_E_OK を返し、セキュアなセッションが確立されます。

関数がいずれかのエラー応答を返した場合、サーバーの応答は受け入れられず、セッションは確立されません。

関数が SEC_I_CONTINUE_NEEDED、SEC_I_COMPLETE_NEEDED、または SEC_I_COMPLETE_AND_CONTINUE を返した場合は、手順 2 と 3 を繰り返します。

セキュリティコンテキストを初期化するには、基盤となる認証メカニズムや fContextReq パラメーターで指定した内容に応じて、この関数を複数回呼び出す必要がある場合があります。

fContextReq パラメーターと pfContextAttributes パラメーターは、各種のコンテキスト属性を表すビットマスクです。各種属性の説明については、 Context Requirements を参照してください。pfContextAttributes パラメーターは、成功して戻るたびに有効ですが、コンテキストのセキュリティ面に関わるフラグを確認するのは、最後に成功して戻ったときだけにしてください。途中の戻り値でも、たとえば ISC_RET_ALLOCATED_MEMORY フラグが設定されることがあります。

ISC_REQ_USE_SUPPLIED_CREDS フラグが設定されている場合、セキュリティパッケージは pInput 入力バッファー内で SECBUFFER_PKG_PARAMS バッファー型を探す必要があります。これは汎用的な仕組みではありませんが、必要に応じてセキュリティパッケージとアプリケーションを強く結び付けることができます。

ISC_REQ_ALLOCATE_MEMORY を指定した場合、呼び出し元は FreeContextBuffer 関数を呼び出してメモリを解放する必要があります。

たとえば、入力トークンが LAN Manager からのチャレンジである場合があります。この場合、出力トークンは、そのチャレンジに対する NTLM で暗号化された応答になります。

クライアントが行う処理は、この関数の戻り値によって異なります。戻り値が SEC_E_OK の場合、2 回目の InitializeSecurityContext (General) の呼び出しは行われず、サーバーからの応答も想定されません。戻り値が SEC_I_CONTINUE_NEEDED の場合、クライアントはサーバーからの応答トークンを待ち、それを 2 回目の InitializeSecurityContext (General) の呼び出しに渡します。戻り値 SEC_I_COMPLETE_NEEDED は、クライアントがメッセージの構築を完了して CompleteAuthToken 関数を呼び出す必要があることを示します。SEC_I_COMPLETE_AND_CONTINUE は、これら両方の処理が必要であることを示します。

InitializeSecurityContext (General) が最初の (または唯一の) 呼び出しで成功を返した場合、呼び出し元は、認証のやり取りの後続の段階で呼び出しが失敗したとしても、最終的には返されたハンドルに対して DeleteSecurityContext 関数を呼び出す必要があります。

クライアントは、正常に完了した後で InitializeSecurityContext (General) を再度呼び出すことができます。これは、再認証を行いたいことをセキュリティパッケージに示します。

カーネルモードの呼び出し元には次の違いがあります。ターゲット名は Unicode 文字列であり、VirtualAlloc を使用して仮想メモリに割り当てる必要があります。プールから割り当ててはなりません。pInput および pOutput で渡すバッファーも、プールではなく仮想メモリ上になければなりません。

Schannel SSP を使用する場合、関数が SEC_I_INCOMPLETE_CREDENTIALS を返したときは、資格情報に有効で信頼された証明書を指定しているかどうかを確認してください。証明書は AcquireCredentialsHandle (General) 関数の呼び出し時に指定します。証明書は、サーバーが信頼する証明機関 (CA) によって発行されたクライアント認証証明書である必要があります。サーバーが信頼する CA の一覧を取得するには、QueryContextAttributes (General) 関数を呼び出し、SECPKG_ATTR_ISSUER_LIST_EX 属性を指定します。

Schannel SSP を使用する場合、クライアントアプリケーションは、サーバーが信頼する CA から認証証明書を受け取った後、AcquireCredentialsHandle (General) 関数を呼び出して新しい資格情報を作成し、その新しい資格情報を phCredential パラメーターに指定して InitializeSecurityContext (General) を再度呼び出します。

メモ

sspi.h ヘッダーは、UNICODE プリプロセッサ定数の定義に基づいて、この関数の ANSI 版または Unicode 版を自動的に選択するエイリアスとして InitializeSecurityContext を定義しています。エンコードに依存しないエイリアスと、エンコードに依存するコードを混在させて使用すると、不一致が生じてコンパイルエラーや実行時エラーの原因になることがあります。詳細については、Conventions for Function Prototypes を参照してください。

出典・ライセンス: 上記「公式ドキュメント」の内容は Microsoft の Win32 API ドキュメント(MicrosoftDocs/sdk-api)を日本語に翻訳・改変したものです。© Microsoft Corporation. CC BY 4.0 で提供。
Microsoft 公式リファレンス: 英語 (en-us) · 日本語 (ja-jp) · 原文ソース (GitHub)

各言語での呼び出し定義

// SECUR32.dll  (ANSI / -A)
#include <windows.h>

HRESULT InitializeSecurityContextA(
    SecHandle* phCredential,   // optional
    SecHandle* phContext,   // optional
    CHAR* pszTargetName,   // optional
    ISC_REQ_FLAGS fContextReq,
    DWORD Reserved1,
    DWORD TargetDataRep,
    SecBufferDesc* pInput,   // optional
    DWORD Reserved2,
    SecHandle* phNewContext,   // optional
    SecBufferDesc* pOutput,   // optional
    DWORD* pfContextAttr,
    LONGLONG* ptsExpiry   // optional
);
[DllImport("SECUR32.dll", CharSet = CharSet.Ansi, ExactSpelling = true)]
static extern int InitializeSecurityContextA(
    IntPtr phCredential,   // SecHandle* optional
    IntPtr phContext,   // SecHandle* optional
    IntPtr pszTargetName,   // CHAR* optional
    uint fContextReq,   // ISC_REQ_FLAGS
    uint Reserved1,   // DWORD
    uint TargetDataRep,   // DWORD
    IntPtr pInput,   // SecBufferDesc* optional
    uint Reserved2,   // DWORD
    IntPtr phNewContext,   // SecHandle* optional, in/out
    IntPtr pOutput,   // SecBufferDesc* optional, in/out
    out uint pfContextAttr,   // DWORD* out
    IntPtr ptsExpiry   // LONGLONG* optional, out
);
<DllImport("SECUR32.dll", CharSet:=CharSet.Ansi, ExactSpelling:=True)>
Public Shared Function InitializeSecurityContextA(
    phCredential As IntPtr,   ' SecHandle* optional
    phContext As IntPtr,   ' SecHandle* optional
    pszTargetName As IntPtr,   ' CHAR* optional
    fContextReq As UInteger,   ' ISC_REQ_FLAGS
    Reserved1 As UInteger,   ' DWORD
    TargetDataRep As UInteger,   ' DWORD
    pInput As IntPtr,   ' SecBufferDesc* optional
    Reserved2 As UInteger,   ' DWORD
    phNewContext As IntPtr,   ' SecHandle* optional, in/out
    pOutput As IntPtr,   ' SecBufferDesc* optional, in/out
    <Out> ByRef pfContextAttr As UInteger,   ' DWORD* out
    ptsExpiry As IntPtr   ' LONGLONG* optional, out
) As Integer
End Function
' phCredential : SecHandle* optional
' phContext : SecHandle* optional
' pszTargetName : CHAR* optional
' fContextReq : ISC_REQ_FLAGS
' Reserved1 : DWORD
' TargetDataRep : DWORD
' pInput : SecBufferDesc* optional
' Reserved2 : DWORD
' phNewContext : SecHandle* optional, in/out
' pOutput : SecBufferDesc* optional, in/out
' pfContextAttr : DWORD* out
' ptsExpiry : LONGLONG* optional, out
Declare PtrSafe Function InitializeSecurityContextA Lib "secur32" ( _
    ByVal phCredential As LongPtr, _
    ByVal phContext As LongPtr, _
    ByVal pszTargetName As LongPtr, _
    ByVal fContextReq As Long, _
    ByVal Reserved1 As Long, _
    ByVal TargetDataRep As Long, _
    ByVal pInput As LongPtr, _
    ByVal Reserved2 As Long, _
    ByVal phNewContext As LongPtr, _
    ByVal pOutput As LongPtr, _
    ByRef pfContextAttr As Long, _
    ByVal ptsExpiry As LongPtr) As Long
' VBA7前提(PtrSafe)。32bit Office では LongPtr→Long。Integer=16bit / Long=32bit / LongLong=64bit。
import ctypes
from ctypes import wintypes

InitializeSecurityContextA = ctypes.windll.secur32.InitializeSecurityContextA
InitializeSecurityContextA.restype = ctypes.c_int
InitializeSecurityContextA.argtypes = [
    ctypes.c_void_p,  # phCredential : SecHandle* optional
    ctypes.c_void_p,  # phContext : SecHandle* optional
    ctypes.POINTER(ctypes.c_byte),  # pszTargetName : CHAR* optional
    wintypes.DWORD,  # fContextReq : ISC_REQ_FLAGS
    wintypes.DWORD,  # Reserved1 : DWORD
    wintypes.DWORD,  # TargetDataRep : DWORD
    ctypes.c_void_p,  # pInput : SecBufferDesc* optional
    wintypes.DWORD,  # Reserved2 : DWORD
    ctypes.c_void_p,  # phNewContext : SecHandle* optional, in/out
    ctypes.c_void_p,  # pOutput : SecBufferDesc* optional, in/out
    ctypes.POINTER(wintypes.DWORD),  # pfContextAttr : DWORD* out
    ctypes.POINTER(ctypes.c_longlong),  # ptsExpiry : LONGLONG* optional, out
]
require 'fiddle'
require 'fiddle/import'

lib = Fiddle.dlopen('SECUR32.dll')
InitializeSecurityContextA = Fiddle::Function.new(
  lib['InitializeSecurityContextA'],
  [
    Fiddle::TYPE_VOIDP,  # phCredential : SecHandle* optional
    Fiddle::TYPE_VOIDP,  # phContext : SecHandle* optional
    Fiddle::TYPE_VOIDP,  # pszTargetName : CHAR* optional
    -Fiddle::TYPE_INT,  # fContextReq : ISC_REQ_FLAGS
    -Fiddle::TYPE_INT,  # Reserved1 : DWORD
    -Fiddle::TYPE_INT,  # TargetDataRep : DWORD
    Fiddle::TYPE_VOIDP,  # pInput : SecBufferDesc* optional
    -Fiddle::TYPE_INT,  # Reserved2 : DWORD
    Fiddle::TYPE_VOIDP,  # phNewContext : SecHandle* optional, in/out
    Fiddle::TYPE_VOIDP,  # pOutput : SecBufferDesc* optional, in/out
    Fiddle::TYPE_VOIDP,  # pfContextAttr : DWORD* out
    Fiddle::TYPE_VOIDP,  # ptsExpiry : LONGLONG* optional, out
  ],
  Fiddle::TYPE_INT)
#[link(name = "secur32")]
extern "system" {
    fn InitializeSecurityContextA(
        phCredential: *mut SecHandle,  // SecHandle* optional
        phContext: *mut SecHandle,  // SecHandle* optional
        pszTargetName: *mut i8,  // CHAR* optional
        fContextReq: u32,  // ISC_REQ_FLAGS
        Reserved1: u32,  // DWORD
        TargetDataRep: u32,  // DWORD
        pInput: *mut SecBufferDesc,  // SecBufferDesc* optional
        Reserved2: u32,  // DWORD
        phNewContext: *mut SecHandle,  // SecHandle* optional, in/out
        pOutput: *mut SecBufferDesc,  // SecBufferDesc* optional, in/out
        pfContextAttr: *mut u32,  // DWORD* out
        ptsExpiry: *mut i64  // LONGLONG* optional, out
    ) -> i32;
}
// crates: windows-sys provides ready-made bindings for this API.
$sig = @"
[DllImport("SECUR32.dll", CharSet = CharSet.Ansi)]
public static extern int InitializeSecurityContextA(IntPtr phCredential, IntPtr phContext, IntPtr pszTargetName, uint fContextReq, uint Reserved1, uint TargetDataRep, IntPtr pInput, uint Reserved2, IntPtr phNewContext, IntPtr pOutput, out uint pfContextAttr, IntPtr ptsExpiry);
"@
$api = Add-Type -MemberDefinition $sig -Name 'SECUR32_InitializeSecurityContextA' -Namespace Win32 -PassThru
# $api::InitializeSecurityContextA(phCredential, phContext, pszTargetName, fContextReq, Reserved1, TargetDataRep, pInput, Reserved2, phNewContext, pOutput, pfContextAttr, ptsExpiry)
#uselib "SECUR32.dll"
#func global InitializeSecurityContextA "InitializeSecurityContextA" sptr, sptr, sptr, sptr, sptr, sptr, sptr, sptr, sptr, sptr, sptr, sptr
; InitializeSecurityContextA varptr(phCredential), varptr(phContext), varptr(pszTargetName), fContextReq, Reserved1, TargetDataRep, varptr(pInput), Reserved2, varptr(phNewContext), varptr(pOutput), varptr(pfContextAttr), varptr(ptsExpiry)   ; 戻り値は stat
; phCredential : SecHandle* optional -> "sptr"
; phContext : SecHandle* optional -> "sptr"
; pszTargetName : CHAR* optional -> "sptr"
; fContextReq : ISC_REQ_FLAGS -> "sptr"
; Reserved1 : DWORD -> "sptr"
; TargetDataRep : DWORD -> "sptr"
; pInput : SecBufferDesc* optional -> "sptr"
; Reserved2 : DWORD -> "sptr"
; phNewContext : SecHandle* optional, in/out -> "sptr"
; pOutput : SecBufferDesc* optional, in/out -> "sptr"
; pfContextAttr : DWORD* out -> "sptr"
; ptsExpiry : LONGLONG* optional, out -> "sptr"
; ※HSP3.7は #func のため戻り値はシステム変数 stat に格納されます。
出力引数:
#uselib "SECUR32.dll"
#cfunc global InitializeSecurityContextA "InitializeSecurityContextA" var, var, var, int, int, int, var, int, var, var, var, var
; res = InitializeSecurityContextA(phCredential, phContext, pszTargetName, fContextReq, Reserved1, TargetDataRep, pInput, Reserved2, phNewContext, pOutput, pfContextAttr, ptsExpiry)
; phCredential : SecHandle* optional -> "var"
; phContext : SecHandle* optional -> "var"
; pszTargetName : CHAR* optional -> "var"
; fContextReq : ISC_REQ_FLAGS -> "int"
; Reserved1 : DWORD -> "int"
; TargetDataRep : DWORD -> "int"
; pInput : SecBufferDesc* optional -> "var"
; Reserved2 : DWORD -> "int"
; phNewContext : SecHandle* optional, in/out -> "var"
; pOutput : SecBufferDesc* optional, in/out -> "var"
; pfContextAttr : DWORD* out -> "var"
; ptsExpiry : LONGLONG* optional, out -> "var"
; ※出力/バッファ引数は var 方式(変数を直接渡す)。varptr 方式にも切替可。
出力引数:
; HRESULT InitializeSecurityContextA(SecHandle* phCredential, SecHandle* phContext, CHAR* pszTargetName, ISC_REQ_FLAGS fContextReq, DWORD Reserved1, DWORD TargetDataRep, SecBufferDesc* pInput, DWORD Reserved2, SecHandle* phNewContext, SecBufferDesc* pOutput, DWORD* pfContextAttr, LONGLONG* ptsExpiry)
#uselib "SECUR32.dll"
#cfunc global InitializeSecurityContextA "InitializeSecurityContextA" var, var, var, int, int, int, var, int, var, var, var, var
; res = InitializeSecurityContextA(phCredential, phContext, pszTargetName, fContextReq, Reserved1, TargetDataRep, pInput, Reserved2, phNewContext, pOutput, pfContextAttr, ptsExpiry)
; phCredential : SecHandle* optional -> "var"
; phContext : SecHandle* optional -> "var"
; pszTargetName : CHAR* optional -> "var"
; fContextReq : ISC_REQ_FLAGS -> "int"
; Reserved1 : DWORD -> "int"
; TargetDataRep : DWORD -> "int"
; pInput : SecBufferDesc* optional -> "var"
; Reserved2 : DWORD -> "int"
; phNewContext : SecHandle* optional, in/out -> "var"
; pOutput : SecBufferDesc* optional, in/out -> "var"
; pfContextAttr : DWORD* out -> "var"
; ptsExpiry : LONGLONG* optional, out -> "var"
; ※出力/バッファ引数は var 方式(変数を直接渡す)。varptr 方式にも切替可。
import (
	"golang.org/x/sys/windows"
	"unsafe"
)

var (
	secur32 = windows.NewLazySystemDLL("SECUR32.dll")
	procInitializeSecurityContextA = secur32.NewProc("InitializeSecurityContextA")
)

// phCredential (SecHandle* optional), phContext (SecHandle* optional), pszTargetName (CHAR* optional), fContextReq (ISC_REQ_FLAGS), Reserved1 (DWORD), TargetDataRep (DWORD), pInput (SecBufferDesc* optional), Reserved2 (DWORD), phNewContext (SecHandle* optional, in/out), pOutput (SecBufferDesc* optional, in/out), pfContextAttr (DWORD* out), ptsExpiry (LONGLONG* optional, out)
r1, _, err := procInitializeSecurityContextA.Call(
	uintptr(phCredential),
	uintptr(phContext),
	uintptr(pszTargetName),
	uintptr(fContextReq),
	uintptr(Reserved1),
	uintptr(TargetDataRep),
	uintptr(pInput),
	uintptr(Reserved2),
	uintptr(phNewContext),
	uintptr(pOutput),
	uintptr(pfContextAttr),
	uintptr(ptsExpiry),
)
_ = err  // syscall.Errno (valid when the call sets last-error)
_ = r1   // HRESULT
function InitializeSecurityContextA(
  phCredential: Pointer;   // SecHandle* optional
  phContext: Pointer;   // SecHandle* optional
  pszTargetName: Pointer;   // CHAR* optional
  fContextReq: DWORD;   // ISC_REQ_FLAGS
  Reserved1: DWORD;   // DWORD
  TargetDataRep: DWORD;   // DWORD
  pInput: Pointer;   // SecBufferDesc* optional
  Reserved2: DWORD;   // DWORD
  phNewContext: Pointer;   // SecHandle* optional, in/out
  pOutput: Pointer;   // SecBufferDesc* optional, in/out
  pfContextAttr: Pointer;   // DWORD* out
  ptsExpiry: Pointer   // LONGLONG* optional, out
): Integer; stdcall;
  external 'SECUR32.dll' name 'InitializeSecurityContextA';
result := DllCall("SECUR32\InitializeSecurityContextA"
    , "Ptr", phCredential   ; SecHandle* optional
    , "Ptr", phContext   ; SecHandle* optional
    , "Ptr", pszTargetName   ; CHAR* optional
    , "UInt", fContextReq   ; ISC_REQ_FLAGS
    , "UInt", Reserved1   ; DWORD
    , "UInt", TargetDataRep   ; DWORD
    , "Ptr", pInput   ; SecBufferDesc* optional
    , "UInt", Reserved2   ; DWORD
    , "Ptr", phNewContext   ; SecHandle* optional, in/out
    , "Ptr", pOutput   ; SecBufferDesc* optional, in/out
    , "Ptr", pfContextAttr   ; DWORD* out
    , "Ptr", ptsExpiry   ; LONGLONG* optional, out
    , "Int")   ; return: HRESULT
●InitializeSecurityContextA(phCredential, phContext, pszTargetName, fContextReq, Reserved1, TargetDataRep, pInput, Reserved2, phNewContext, pOutput, pfContextAttr, ptsExpiry) = DLL("SECUR32.dll", "int InitializeSecurityContextA(void*, void*, void*, dword, dword, dword, void*, dword, void*, void*, void*, void*)")
# 呼び出し: InitializeSecurityContextA(phCredential, phContext, pszTargetName, fContextReq, Reserved1, TargetDataRep, pInput, Reserved2, phNewContext, pOutput, pfContextAttr, ptsExpiry)
# phCredential : SecHandle* optional -> "void*"
# phContext : SecHandle* optional -> "void*"
# pszTargetName : CHAR* optional -> "void*"
# fContextReq : ISC_REQ_FLAGS -> "dword"
# Reserved1 : DWORD -> "dword"
# TargetDataRep : DWORD -> "dword"
# pInput : SecBufferDesc* optional -> "void*"
# Reserved2 : DWORD -> "dword"
# phNewContext : SecHandle* optional, in/out -> "void*"
# pOutput : SecBufferDesc* optional, in/out -> "void*"
# pfContextAttr : DWORD* out -> "void*"
# ptsExpiry : LONGLONG* optional, out -> "void*"
# なでしこ1は32bit・ANSI(Shift_JIS)。文字列=char*(ANSI)、ポインタ/ハンドル=void*(4byte)。
const std = @import("std");

extern "secur32" fn InitializeSecurityContextA(
    phCredential: [*c]SecHandle, // SecHandle* optional
    phContext: [*c]SecHandle, // SecHandle* optional
    pszTargetName: [*c]i8, // CHAR* optional
    fContextReq: u32, // ISC_REQ_FLAGS
    Reserved1: u32, // DWORD
    TargetDataRep: u32, // DWORD
    pInput: [*c]SecBufferDesc, // SecBufferDesc* optional
    Reserved2: u32, // DWORD
    phNewContext: [*c]SecHandle, // SecHandle* optional, in/out
    pOutput: [*c]SecBufferDesc, // SecBufferDesc* optional, in/out
    pfContextAttr: [*c]u32, // DWORD* out
    ptsExpiry: [*c]i64 // LONGLONG* optional, out
) callconv(std.os.windows.WINAPI) i32;
proc InitializeSecurityContextA(
    phCredential: ptr SecHandle,  # SecHandle* optional
    phContext: ptr SecHandle,  # SecHandle* optional
    pszTargetName: ptr int8,  # CHAR* optional
    fContextReq: uint32,  # ISC_REQ_FLAGS
    Reserved1: uint32,  # DWORD
    TargetDataRep: uint32,  # DWORD
    pInput: ptr SecBufferDesc,  # SecBufferDesc* optional
    Reserved2: uint32,  # DWORD
    phNewContext: ptr SecHandle,  # SecHandle* optional, in/out
    pOutput: ptr SecBufferDesc,  # SecBufferDesc* optional, in/out
    pfContextAttr: ptr uint32,  # DWORD* out
    ptsExpiry: ptr int64  # LONGLONG* optional, out
): int32 {.importc: "InitializeSecurityContextA", stdcall, dynlib: "SECUR32.dll".}
pragma(lib, "secur32");
extern(Windows)
int InitializeSecurityContextA(
    SecHandle* phCredential,   // SecHandle* optional
    SecHandle* phContext,   // SecHandle* optional
    byte* pszTargetName,   // CHAR* optional
    uint fContextReq,   // ISC_REQ_FLAGS
    uint Reserved1,   // DWORD
    uint TargetDataRep,   // DWORD
    SecBufferDesc* pInput,   // SecBufferDesc* optional
    uint Reserved2,   // DWORD
    SecHandle* phNewContext,   // SecHandle* optional, in/out
    SecBufferDesc* pOutput,   // SecBufferDesc* optional, in/out
    uint* pfContextAttr,   // DWORD* out
    long* ptsExpiry   // LONGLONG* optional, out
);
ccall((:InitializeSecurityContextA, "SECUR32.dll"), stdcall, Int32,
      (Ptr{SecHandle}, Ptr{SecHandle}, Ptr{Int8}, UInt32, UInt32, UInt32, Ptr{SecBufferDesc}, UInt32, Ptr{SecHandle}, Ptr{SecBufferDesc}, Ptr{UInt32}, Ptr{Int64}),
      phCredential, phContext, pszTargetName, fContextReq, Reserved1, TargetDataRep, pInput, Reserved2, phNewContext, pOutput, pfContextAttr, ptsExpiry)
# phCredential : SecHandle* optional -> Ptr{SecHandle}
# phContext : SecHandle* optional -> Ptr{SecHandle}
# pszTargetName : CHAR* optional -> Ptr{Int8}
# fContextReq : ISC_REQ_FLAGS -> UInt32
# Reserved1 : DWORD -> UInt32
# TargetDataRep : DWORD -> UInt32
# pInput : SecBufferDesc* optional -> Ptr{SecBufferDesc}
# Reserved2 : DWORD -> UInt32
# phNewContext : SecHandle* optional, in/out -> Ptr{SecHandle}
# pOutput : SecBufferDesc* optional, in/out -> Ptr{SecBufferDesc}
# pfContextAttr : DWORD* out -> Ptr{UInt32}
# ptsExpiry : LONGLONG* optional, out -> Ptr{Int64}
# stdcall は 32bit のみ意味を持つ(x64 では無視)。
local ffi = require("ffi")
ffi.cdef[[
int32_t InitializeSecurityContextA(
    void* phCredential,
    void* phContext,
    int8_t* pszTargetName,
    uint32_t fContextReq,
    uint32_t Reserved1,
    uint32_t TargetDataRep,
    void* pInput,
    uint32_t Reserved2,
    void* phNewContext,
    void* pOutput,
    uint32_t* pfContextAttr,
    int64_t* ptsExpiry);
]]
local secur32 = ffi.load("secur32")
-- secur32.InitializeSecurityContextA(phCredential, phContext, pszTargetName, fContextReq, Reserved1, TargetDataRep, pInput, Reserved2, phNewContext, pOutput, pfContextAttr, ptsExpiry)
-- phCredential : SecHandle* optional
-- phContext : SecHandle* optional
-- pszTargetName : CHAR* optional
-- fContextReq : ISC_REQ_FLAGS
-- Reserved1 : DWORD
-- TargetDataRep : DWORD
-- pInput : SecBufferDesc* optional
-- Reserved2 : DWORD
-- phNewContext : SecHandle* optional, in/out
-- pOutput : SecBufferDesc* optional, in/out
-- pfContextAttr : DWORD* out
-- ptsExpiry : LONGLONG* optional, out
-- 構造体/GUIDへのポインタは cdef が通るよう void* で表記(実型は各引数コメント参照)。値渡し構造体・enum は対応する typedef を cdef に追加すること。
const koffi = require('koffi');
const lib = koffi.load('SECUR32.dll');
const InitializeSecurityContextA = lib.func('__stdcall', 'InitializeSecurityContextA', 'int32_t', ['void *', 'void *', 'int8_t *', 'uint32_t', 'uint32_t', 'uint32_t', 'void *', 'uint32_t', 'void *', 'void *', 'uint32_t *', 'int64_t *']);
// InitializeSecurityContextA(phCredential, phContext, pszTargetName, fContextReq, Reserved1, TargetDataRep, pInput, Reserved2, phNewContext, pOutput, pfContextAttr, ptsExpiry)
// phCredential : SecHandle* optional -> 'void *'
// phContext : SecHandle* optional -> 'void *'
// pszTargetName : CHAR* optional -> 'int8_t *'
// fContextReq : ISC_REQ_FLAGS -> 'uint32_t'
// Reserved1 : DWORD -> 'uint32_t'
// TargetDataRep : DWORD -> 'uint32_t'
// pInput : SecBufferDesc* optional -> 'void *'
// Reserved2 : DWORD -> 'uint32_t'
// phNewContext : SecHandle* optional, in/out -> 'void *'
// pOutput : SecBufferDesc* optional, in/out -> 'void *'
// pfContextAttr : DWORD* out -> 'uint32_t *'
// ptsExpiry : LONGLONG* optional, out -> 'int64_t *'
// 出力ポインタは koffi.out(...) で包む。構造体は koffi.struct で定義。
const lib = Deno.dlopen("SECUR32.dll", {
  InitializeSecurityContextA: { parameters: ["pointer", "pointer", "pointer", "u32", "u32", "u32", "pointer", "u32", "pointer", "pointer", "pointer", "pointer"], result: "i32" },
});
// lib.symbols.InitializeSecurityContextA(phCredential, phContext, pszTargetName, fContextReq, Reserved1, TargetDataRep, pInput, Reserved2, phNewContext, pOutput, pfContextAttr, ptsExpiry)
// phCredential : SecHandle* optional -> "pointer"
// phContext : SecHandle* optional -> "pointer"
// pszTargetName : CHAR* optional -> "pointer"
// fContextReq : ISC_REQ_FLAGS -> "u32"
// Reserved1 : DWORD -> "u32"
// TargetDataRep : DWORD -> "u32"
// pInput : SecBufferDesc* optional -> "pointer"
// Reserved2 : DWORD -> "u32"
// phNewContext : SecHandle* optional, in/out -> "pointer"
// pOutput : SecBufferDesc* optional, in/out -> "pointer"
// pfContextAttr : DWORD* out -> "pointer"
// ptsExpiry : LONGLONG* optional, out -> "pointer"
// 文字列は "buffer"。ANSI(-A) は new TextEncoder() で UTF-8/ANSI バイト列(末尾に \x00)を渡す。
// 値渡し構造体は { struct: [ ...field types... ] } を使用。
<?php
$ffi = FFI::cdef(<<<C
int32_t InitializeSecurityContextA(
    void* phCredential,
    void* phContext,
    int8_t* pszTargetName,
    uint32_t fContextReq,
    uint32_t Reserved1,
    uint32_t TargetDataRep,
    void* pInput,
    uint32_t Reserved2,
    void* phNewContext,
    void* pOutput,
    uint32_t* pfContextAttr,
    int64_t* ptsExpiry);
C, "SECUR32.dll");
// $ffi->InitializeSecurityContextA(phCredential, phContext, pszTargetName, fContextReq, Reserved1, TargetDataRep, pInput, Reserved2, phNewContext, pOutput, pfContextAttr, ptsExpiry);
// phCredential : SecHandle* optional
// phContext : SecHandle* optional
// pszTargetName : CHAR* optional
// fContextReq : ISC_REQ_FLAGS
// Reserved1 : DWORD
// TargetDataRep : DWORD
// pInput : SecBufferDesc* optional
// Reserved2 : DWORD
// phNewContext : SecHandle* optional, in/out
// pOutput : SecBufferDesc* optional, in/out
// pfContextAttr : DWORD* out
// ptsExpiry : LONGLONG* optional, out
// 構造体/GUIDへのポインタは cdef が通るよう void* で表記(実型は各引数コメント参照)。値渡し構造体・enum は対応する typedef を cdef に追加すること。
// WINAPI(stdcall): x64 では呼出規約が統一されるため問題なし。x86 では __stdcall 対応のラッパが必要な場合あり。
import com.sun.jna.*;
import com.sun.jna.ptr.*;
import com.sun.jna.win32.StdCallLibrary;
import com.sun.jna.win32.W32APIOptions;

public interface Secur32 extends StdCallLibrary {
    Secur32 INSTANCE = Native.load("secur32", Secur32.class, W32APIOptions.ASCII_OPTIONS);
    int InitializeSecurityContextA(
        Pointer phCredential,   // SecHandle* optional
        Pointer phContext,   // SecHandle* optional
        byte[] pszTargetName,   // CHAR* optional
        int fContextReq,   // ISC_REQ_FLAGS
        int Reserved1,   // DWORD
        int TargetDataRep,   // DWORD
        Pointer pInput,   // SecBufferDesc* optional
        int Reserved2,   // DWORD
        Pointer phNewContext,   // SecHandle* optional, in/out
        Pointer pOutput,   // SecBufferDesc* optional, in/out
        IntByReference pfContextAttr,   // DWORD* out
        LongByReference ptsExpiry   // LONGLONG* optional, out
    );
}
@[Link("secur32")]
lib LibSECUR32
  fun InitializeSecurityContextA = InitializeSecurityContextA(
    phCredential : SecHandle*,   # SecHandle* optional
    phContext : SecHandle*,   # SecHandle* optional
    pszTargetName : Int8*,   # CHAR* optional
    fContextReq : UInt32,   # ISC_REQ_FLAGS
    Reserved1 : UInt32,   # DWORD
    TargetDataRep : UInt32,   # DWORD
    pInput : SecBufferDesc*,   # SecBufferDesc* optional
    Reserved2 : UInt32,   # DWORD
    phNewContext : SecHandle*,   # SecHandle* optional, in/out
    pOutput : SecBufferDesc*,   # SecBufferDesc* optional, in/out
    pfContextAttr : UInt32*,   # DWORD* out
    ptsExpiry : Int64*   # LONGLONG* optional, out
  ) : Int32
end
# 構造体/GUID/enum は lib 内に対応する型定義が必要。
# 呼出規約: x64 は規約統一のため OK。x86(32bit)は WINAPI=stdcall だが Crystal の fun に stdcall 付与構文がなく非対応。
import 'dart:ffi';
import 'package:ffi/ffi.dart';

typedef InitializeSecurityContextANative = Int32 Function(Pointer<Void>, Pointer<Void>, Pointer<Int8>, Uint32, Uint32, Uint32, Pointer<Void>, Uint32, Pointer<Void>, Pointer<Void>, Pointer<Uint32>, Pointer<Int64>);
typedef InitializeSecurityContextADart = int Function(Pointer<Void>, Pointer<Void>, Pointer<Int8>, int, int, int, Pointer<Void>, int, Pointer<Void>, Pointer<Void>, Pointer<Uint32>, Pointer<Int64>);
final InitializeSecurityContextA = DynamicLibrary.open('SECUR32.dll')
    .lookupFunction<InitializeSecurityContextANative, InitializeSecurityContextADart>('InitializeSecurityContextA');
// phCredential : SecHandle* optional -> Pointer<Void>
// phContext : SecHandle* optional -> Pointer<Void>
// pszTargetName : CHAR* optional -> Pointer<Int8>
// fContextReq : ISC_REQ_FLAGS -> Uint32
// Reserved1 : DWORD -> Uint32
// TargetDataRep : DWORD -> Uint32
// pInput : SecBufferDesc* optional -> Pointer<Void>
// Reserved2 : DWORD -> Uint32
// phNewContext : SecHandle* optional, in/out -> Pointer<Void>
// pOutput : SecBufferDesc* optional, in/out -> Pointer<Void>
// pfContextAttr : DWORD* out -> Pointer<Uint32>
// ptsExpiry : LONGLONG* optional, out -> Pointer<Int64>
// 文字列は package:ffi の "...".toNativeUtf16()/toNativeUtf8() で変換。
{$mode objfpc}{$H+}
function InitializeSecurityContextA(
  phCredential: Pointer;   // SecHandle* optional
  phContext: Pointer;   // SecHandle* optional
  pszTargetName: Pointer;   // CHAR* optional
  fContextReq: DWORD;   // ISC_REQ_FLAGS
  Reserved1: DWORD;   // DWORD
  TargetDataRep: DWORD;   // DWORD
  pInput: Pointer;   // SecBufferDesc* optional
  Reserved2: DWORD;   // DWORD
  phNewContext: Pointer;   // SecHandle* optional, in/out
  pOutput: Pointer;   // SecBufferDesc* optional, in/out
  pfContextAttr: Pointer;   // DWORD* out
  ptsExpiry: Pointer   // LONGLONG* optional, out
): Integer; stdcall;
  external 'SECUR32.dll' name 'InitializeSecurityContextA';
import Foreign
import Foreign.C.Types
import Foreign.C.String

foreign import stdcall safe "InitializeSecurityContextA"
  c_InitializeSecurityContextA :: Ptr () -> Ptr () -> Ptr Int8 -> Word32 -> Word32 -> Word32 -> Ptr () -> Word32 -> Ptr () -> Ptr () -> Ptr Word32 -> Ptr Int64 -> IO Int32
-- phCredential : SecHandle* optional -> Ptr ()
-- phContext : SecHandle* optional -> Ptr ()
-- pszTargetName : CHAR* optional -> Ptr Int8
-- fContextReq : ISC_REQ_FLAGS -> Word32
-- Reserved1 : DWORD -> Word32
-- TargetDataRep : DWORD -> Word32
-- pInput : SecBufferDesc* optional -> Ptr ()
-- Reserved2 : DWORD -> Word32
-- phNewContext : SecHandle* optional, in/out -> Ptr ()
-- pOutput : SecBufferDesc* optional, in/out -> Ptr ()
-- pfContextAttr : DWORD* out -> Ptr Word32
-- ptsExpiry : LONGLONG* optional, out -> Ptr Int64
-- 要 GHC(Windows)。stdcall は x64 では ccall として扱われる。ブロックする API は safe 呼び出し推奨。
open Ctypes
open Foreign

let initializesecuritycontexta =
  foreign "InitializeSecurityContextA"
    ((ptr void) @-> (ptr void) @-> (ptr int8_t) @-> uint32_t @-> uint32_t @-> uint32_t @-> (ptr void) @-> uint32_t @-> (ptr void) @-> (ptr void) @-> (ptr uint32_t) @-> (ptr int64_t) @-> returning int32_t)
(* phCredential : SecHandle* optional -> (ptr void) *)
(* phContext : SecHandle* optional -> (ptr void) *)
(* pszTargetName : CHAR* optional -> (ptr int8_t) *)
(* fContextReq : ISC_REQ_FLAGS -> uint32_t *)
(* Reserved1 : DWORD -> uint32_t *)
(* TargetDataRep : DWORD -> uint32_t *)
(* pInput : SecBufferDesc* optional -> (ptr void) *)
(* Reserved2 : DWORD -> uint32_t *)
(* phNewContext : SecHandle* optional, in/out -> (ptr void) *)
(* pOutput : SecBufferDesc* optional, in/out -> (ptr void) *)
(* pfContextAttr : DWORD* out -> (ptr uint32_t) *)
(* ptsExpiry : LONGLONG* optional, out -> (ptr int64_t) *)
(* foreign は cdecl 前提。x64 Windows では WINAPI と一致。構造体は ctypes structure を定義のこと。 *)
(cffi:define-foreign-library secur32 (t "SECUR32.dll"))
(cffi:use-foreign-library secur32)

(cffi:defcfun ("InitializeSecurityContextA" initialize-security-context-a :convention :stdcall) :int32
  (ph-credential :pointer)   ; SecHandle* optional
  (ph-context :pointer)   ; SecHandle* optional
  (psz-target-name :pointer)   ; CHAR* optional
  (f-context-req :uint32)   ; ISC_REQ_FLAGS
  (reserved1 :uint32)   ; DWORD
  (target-data-rep :uint32)   ; DWORD
  (p-input :pointer)   ; SecBufferDesc* optional
  (reserved2 :uint32)   ; DWORD
  (ph-new-context :pointer)   ; SecHandle* optional, in/out
  (p-output :pointer)   ; SecBufferDesc* optional, in/out
  (pf-context-attr :pointer)   ; DWORD* out
  (pts-expiry :pointer))   ; LONGLONG* optional, out
; isize/usize(INT_PTR/SIZE_T)は x64 前提で :int64/:uint64。x86 では :int32/:uint32。
use Win32::API;
my $InitializeSecurityContextA = Win32::API::More->new('SECUR32',
    'int InitializeSecurityContextA(LPVOID phCredential, LPVOID phContext, LPVOID pszTargetName, DWORD fContextReq, DWORD Reserved1, DWORD TargetDataRep, LPVOID pInput, DWORD Reserved2, LPVOID phNewContext, LPVOID pOutput, LPVOID pfContextAttr, LPVOID ptsExpiry)');
# my $ret = $InitializeSecurityContextA->Call($phCredential, $phContext, $pszTargetName, $fContextReq, $Reserved1, $TargetDataRep, $pInput, $Reserved2, $phNewContext, $pOutput, $pfContextAttr, $ptsExpiry);
# phCredential : SecHandle* optional -> LPVOID
# phContext : SecHandle* optional -> LPVOID
# pszTargetName : CHAR* optional -> LPVOID
# fContextReq : ISC_REQ_FLAGS -> DWORD
# Reserved1 : DWORD -> DWORD
# TargetDataRep : DWORD -> DWORD
# pInput : SecBufferDesc* optional -> LPVOID
# Reserved2 : DWORD -> DWORD
# phNewContext : SecHandle* optional, in/out -> LPVOID
# pOutput : SecBufferDesc* optional, in/out -> LPVOID
# pfContextAttr : DWORD* out -> LPVOID
# ptsExpiry : LONGLONG* optional, out -> LPVOID
# 値渡し構造体は pack() した文字列、または Win32::API::Struct を使用。

関連項目

文字セット違い
公式の関連項目
使用する型