Win32 API 日本語リファレンス
ホーム › Security.Authentication.Identity › InitializeSecurityContextW

InitializeSecurityContextW

関数
クライアント側のセキュリティコンテキストを初期化する(Unicode版)。
DLLSECUR32.dll文字セットUnicode (-W)呼出規約winapi対応OSWindows XP 以降

シグネチャ

// SECUR32.dll  (Unicode / -W)
#include <windows.h>

HRESULT InitializeSecurityContextW(
    SecHandle* phCredential,   // optional
    SecHandle* phContext,   // optional
    WORD* pszTargetName,   // optional
    ISC_REQ_FLAGS fContextReq,
    DWORD Reserved1,
    DWORD TargetDataRep,
    SecBufferDesc* pInput,   // optional
    DWORD Reserved2,
    SecHandle* phNewContext,   // optional
    SecBufferDesc* pOutput,   // optional
    DWORD* pfContextAttr,
    LONGLONG* ptsExpiry   // optional
);

パラメーター

名前型方向説明
phCredentialSecHandle*inoptionalAcquireCredentialsHandle (General) が返した資格情報へのハンドル。このハンドルはセキュリティコンテキストの構築に使用されます。InitializeSecurityContext (General) 関数には、少なくとも OUTBOUND の資格情報が必要です。
phContextSecHandle*inoptional

CtxtHandle 構造体へのポインター。InitializeSecurityContext (General) の最初の呼び出しでは、このポインターは NULL です。2 回目の呼び出しでは、このパラメーターは、最初の呼び出しで phNewContext パラメーターに返された、部分的に構築されたコンテキストのハンドルへのポインターになります。

このパラメーターは Microsoft Digest SSP では省略可能で、NULL を設定できます。

Schannel SSP を使用する場合、InitializeSecurityContext (General) の最初の呼び出しでは NULL を指定します。以降の呼び出しでは、この関数の最初の呼び出し後に phNewContext パラメーターで受け取ったトークンを指定します。

pszTargetNameWORD*inoptional認証対象のターゲット名(サーバーのSPN等)を示すワイド文字列へのポインタ。
fContextReqISC_REQ_FLAGSin

コンテキストに対する要求を示すビットフラグ。すべてのパッケージがすべての要件をサポートできるわけではありません。このパラメーターに使用するフラグには ISC_REQ_ というプレフィックスが付きます (例: ISC_REQ_DELEGATE)。このパラメーターには、次の属性フラグを 1 つ以上指定できます。

値 意味
ISC_REQ_ALLOCATE_MEMORY
セキュリティパッケージが出力バッファーを割り当てます。出力バッファーの使用が終わったら、FreeContextBuffer 関数を呼び出して解放してください。
ISC_REQ_CONFIDENTIALITY
EncryptMessage 関数を使用してメッセージを暗号化します。
ISC_REQ_CONNECTION
セキュリティコンテキストはメッセージの書式設定を扱いません。この値は Kerberos、Negotiate、NTLM の各セキュリティパッケージの既定値です。
ISC_REQ_DELEGATE
サーバーはこのコンテキストを使用して、クライアントとして他のサーバーに対する認証を行えます。このフラグが機能するには ISC_REQ_MUTUAL_AUTH フラグを設定する必要があります。Kerberos で有効です。制約付き委任ではこのフラグを無視してください。
ISC_REQ_EXTENDED_ERROR
エラーが発生したときに、リモート側に通知されます。
ISC_REQ_HTTP
HTTP に対して Digest を使用します。Digest を SASL メカニズムとして使用する場合は、このフラグを指定しないでください。
ISC_REQ_INTEGRITY
EncryptMessage 関数と MakeSignature 関数を使用して、メッセージの署名と署名の検証を行います。
ISC_REQ_MANUAL_CRED_VALIDATION
Schannel はサーバーを自動的に認証してはなりません。
ISC_REQ_MUTUAL_AUTH
サービスの相互認証ポリシーが満たされます。
注意 これは必ずしも相互認証が実行されることを意味するものではなく、サービスの認証ポリシーが満たされることだけを意味します。相互認証が実行されたことを確認するには、QueryContextAttributes (General) 関数を呼び出してください。
ISC_REQ_NO_INTEGRITY
このフラグが設定されている場合、ISC_REQ_INTEGRITY フラグは無視されます。

この値は Negotiate と Kerberos のセキュリティパッケージでのみサポートされます。

ISC_REQ_REPLAY_DETECT
EncryptMessage 関数または MakeSignature 関数でエンコードされたメッセージのリプレイを検出します。
ISC_REQ_SEQUENCE_DETECT
順序どおりに受信されなかったメッセージを検出します。
ISC_REQ_STREAM
ストリーム指向の接続をサポートします。
ISC_REQ_USE_SESSION_KEY
新しいセッションキーをネゴシエートする必要があります。

この値は Kerberos セキュリティパッケージでのみサポートされます。

ISC_REQ_USE_SUPPLIED_CREDS
Schannel はクライアントの資格情報を自動的に提供しようとしてはなりません。

要求した属性がクライアントでサポートされない場合があります。詳細については、pfContextAttr パラメーターを参照してください。

各種属性の詳細な説明については、Context Requirements を参照してください。

Reserved1DWORDinこのパラメーターは予約されており、0 を設定する必要があります。
TargetDataRepDWORDin

バイトオーダーなど、ターゲットにおけるデータ表現。このパラメーターには SECURITY_NATIVE_DREP または SECURITY_NETWORK_DREP のいずれかを指定できます。

このパラメーターは Digest および Schannel では使用されません。0 を設定してください。

pInputSecBufferDesc*inoptionalパッケージへの入力として渡されるバッファーへのポインターを含む SecBufferDesc 構造体へのポインター。クライアントコンテキストがサーバーによって開始された場合を除き、この関数の最初の呼び出しではこのパラメーターの値は NULL でなければなりません。以降の呼び出し、またはクライアントコンテキストがサーバーによって開始された場合、このパラメーターの値は、リモートコンピューターから返されたトークンを保持するのに十分なメモリを割り当てたバッファーへのポインターになります。
Reserved2DWORDinこのパラメーターは予約されており、0 を設定する必要があります。
phNewContextSecHandle*inoutoptional

CtxtHandle 構造体へのポインター。InitializeSecurityContext (General) の最初の呼び出しでは、このポインターが新しいコンテキストハンドルを受け取ります。2 回目の呼び出しでは、phNewContext に phContext パラメーターで指定したハンドルと同じものを指定できます。

Schannel SSP を使用する場合、2 回目以降の呼び出しでは、ここで返されたハンドルを phContext パラメーターとして渡し、phNewContext には NULL を指定します。

pOutputSecBufferDesc*inoutoptional

出力データを受け取る SecBuffer 構造体へのポインターを含む SecBufferDesc 構造体へのポインター。入力で SEC_READWRITE 型として指定されたバッファーは、出力にもそのまま存在します。要求された場合 (ISC_REQ_ALLOCATE_MEMORY による指定)、システムはセキュリティトークン用のバッファーを割り当て、そのアドレスをセキュリティトークンのバッファー記述子に設定します。

Microsoft Digest SSP を使用する場合、このパラメーターは、サーバーに送信する必要があるチャレンジ応答を受け取ります。

Schannel SSP を使用する場合、ISC_REQ_ALLOCATE_MEMORY フラグを指定すると、Schannel SSP がバッファー用のメモリを割り当て、SecBufferDesc に適切な情報を設定します。さらに、呼び出し元は SECBUFFER_ALERT 型のバッファーを渡す必要があります。出力時にアラートが生成された場合、このバッファーにはそのアラートに関する情報が格納され、関数は失敗します。

pfContextAttrDWORD*out

確立されたコンテキストの属性を示すビットフラグのセットを受け取る変数へのポインター。各種属性の説明については、Context Requirements を参照してください。

このパラメーターに使用するフラグには ISC_RET というプレフィックスが付きます (例: ISC_RET_DELEGATE)。

有効な値の一覧については、fContextReq パラメーターを参照してください。

セキュリティ関連の属性は、最後の関数呼び出しが成功して戻るまで確認しないでください。ASC_RET_ALLOCATED_MEMORY フラグなど、セキュリティに関連しない属性フラグは、最後の戻り値より前に確認できます。

注 一部のコンテキスト属性は、リモートピアとのネゴシエーション中に変化することがあります。
ptsExpiryLONGLONG*outoptional

コンテキストの有効期限を受け取る TimeStamp 構造体へのポインター。セキュリティパッケージは、この値を常にローカル時刻で返すことが推奨されます。このパラメーターは省略可能であり、短時間しか存在しないクライアントでは NULL を渡してください。

Microsoft Digest SSP のセキュリティコンテキストや資格情報には有効期限がありません。

戻り値の型: HRESULT

公式ドキュメント

資格情報ハンドルから、クライアント側の送信 (アウトバウンド) セキュリティコンテキストを開始します。(Unicode)

戻り値

関数が成功した場合は、次の成功コードのいずれかを返します。

戻り値 説明
SEC_I_COMPLETE_AND_CONTINUE
クライアントは CompleteAuthToken を呼び出し、その出力をサーバーに渡す必要があります。その後、クライアントは返されるトークンを待ち、それを別の呼び出しで InitializeSecurityContext (General) に渡します。
SEC_I_COMPLETE_NEEDED
クライアントはメッセージの構築を完了し、その後 CompleteAuthToken 関数を呼び出す必要があります。
SEC_I_CONTINUE_NEEDED
クライアントは出力トークンをサーバーに送信し、返されるトークンを待つ必要があります。返されたトークンは、その後 InitializeSecurityContext (General) の別の呼び出しに渡します。出力トークンは空の場合もあります。
SEC_I_INCOMPLETE_CREDENTIALS
Schannel で使用されます。サーバーがクライアント認証を要求しましたが、指定された資格情報に証明書が含まれていないか、その証明書がサーバーの信頼する証明機関から発行されたものではありません。詳細については、「解説」を参照してください。
SEC_E_INCOMPLETE_MESSAGE
Schannel で使用されます。メッセージ全体のデータがネットワークから読み取られていません。

この値が返された場合、pInput バッファーには、BufferType メンバーが SECBUFFER_MISSING である SecBuffer 構造体が格納されます。SecBuffer の cbBuffer メンバーには、この関数が成功するまでにクライアントから追加で読み取る必要があるバイト数を示す値が格納されます。この数値は常に正確とは限りませんが、これを利用することでこの関数を何度も呼び出すことを避け、パフォーマンスを向上させることができます。

SEC_E_OK
セキュリティコンテキストが正常に初期化されました。InitializeSecurityContext (General) を再度呼び出す必要はありません。この関数が出力トークンを返した場合、つまり pOutput 内の SECBUFFER_TOKEN の長さが 0 でない場合は、そのトークンをサーバーに送信する必要があります。

関数が失敗した場合は、次のエラーコードのいずれかを返します。

戻り値 説明
SEC_E_INSUFFICIENT_MEMORY
要求された処理を完了するのに十分なメモリがありません。
SEC_E_INTERNAL_ERROR
SSPI エラーコードに対応付けられないエラーが発生しました。
SEC_E_INVALID_HANDLE
関数に渡されたハンドルが無効です。
SEC_E_INVALID_TOKEN
入力トークンの形式が不正なことによるエラーです。転送中に破損したトークン、サイズが正しくないトークン、誤ったセキュリティパッケージに渡されたトークンなどが原因です。クライアントとサーバーが適切なセキュリティパッケージをネゴシエートしなかった場合に、誤ったパッケージにトークンが渡されることがあります。
SEC_E_LOGON_DENIED
ログオンに失敗しました。
SEC_E_NO_AUTHENTICATING_AUTHORITY
認証のために接続できる機関がありませんでした。認証を行う側のドメイン名が誤っている、ドメインに到達できない、または信頼関係に問題がある可能性があります。
SEC_E_NO_CREDENTIALS
セキュリティパッケージに利用可能な資格情報がありません。
SEC_E_TARGET_UNKNOWN
ターゲットが認識されませんでした。
SEC_E_UNSUPPORTED_FUNCTION
無効なコンテキスト属性フラグ (ISC_REQ_DELEGATE または ISC_REQ_PROMPT_FOR_CREDS) が fContextReq パラメーターに指定されました。
SEC_E_WRONG_PRINCIPAL
認証要求を受け取ったプリンシパルが、pszTargetName パラメーターに渡されたものと異なります。これは相互認証が失敗したことを示します。

解説(Remarks)

最終的なコンテキスト属性が十分であるかどうかを判断するのは、呼び出し元の責任です。たとえば、機密性を要求したにもかかわらず確立できなかった場合、アプリケーションによっては直ちに接続を切断することを選択することもあります。

セキュリティコンテキストの属性が十分でない場合、クライアントは DeleteSecurityContext 関数を呼び出して、部分的に作成されたコンテキストを解放する必要があります。

InitializeSecurityContext (General) 関数は、クライアントが送信方向のコンテキストを初期化するために使用します。

2 段階 (two-leg) のセキュリティコンテキストの場合、呼び出しの順序は次のとおりです。

  1. クライアントは phContext に NULL を設定して関数を呼び出し、バッファー記述子に入力メッセージを設定します。
  2. セキュリティパッケージはパラメーターを検査して不透明なトークンを構築し、それをバッファー配列内の TOKEN 要素に格納します。fContextReq パラメーターに ISC_REQ_ALLOCATE_MEMORY フラグが含まれている場合、セキュリティパッケージがメモリを割り当て、そのポインターを TOKEN 要素に返します。
  3. クライアントは pOutput バッファーで返されたトークンをターゲットサーバーに送信します。サーバーはそのトークンを AcceptSecurityContext (General) 関数の呼び出しの入力引数として渡します。
  4. 最初の呼び出しが SEC_I_CONTINUE_NEEDED を返した場合、AcceptSecurityContext (General) がトークンを返すことがあり、サーバーはそれをクライアントに送信して、2 回目の InitializeSecurityContext (General) の呼び出しに使用させます。
相互認証など、複数段階 (multiple-leg) のセキュリティコンテキストの場合、呼び出しの順序は次のとおりです。
  1. クライアントは前述のとおり関数を呼び出しますが、パッケージは成功コード SEC_I_CONTINUE_NEEDED を返します。
  2. クライアントは出力トークンをサーバーに送信し、サーバーからの応答を待ちます。
  3. サーバーの応答を受け取ると、クライアントは phContext に前回の呼び出しで返されたハンドルを設定して、InitializeSecurityContext (General) を再度呼び出します。サーバーから受け取ったトークンは pInput パラメーターで指定します。
サーバーが正常に応答した場合、セキュリティパッケージは SEC_E_OK を返し、セキュアなセッションが確立されます。

関数がエラー応答のいずれかを返した場合、サーバーの応答は受け入れられず、セッションは確立されません。

関数が SEC_I_CONTINUE_NEEDED、SEC_I_COMPLETE_NEEDED、または SEC_I_COMPLETE_AND_CONTINUE を返した場合は、手順 2 と 3 を繰り返します。

セキュリティコンテキストを初期化するには、基盤となる認証メカニズムや fContextReq パラメーターで指定した選択内容に応じて、この関数を複数回呼び出す必要がある場合があります。

fContextReq パラメーターと pfContextAttributes パラメーターは、さまざまなコンテキスト属性を表すビットマスクです。各種属性の説明については、Context Requirements を参照してください。pfContextAttributes パラメーターは成功して戻るたびに有効ですが、コンテキストのセキュリティ面に関わるフラグを確認するのは、最後に成功して戻ったときだけにしてください。途中の戻り値でも、たとえば ISC_RET_ALLOCATED_MEMORY フラグが設定されることがあります。

ISC_REQ_USE_SUPPLIED_CREDS フラグが設定されている場合、セキュリティパッケージは pInput 入力バッファー内で SECBUFFER_PKG_PARAMS バッファー型を探す必要があります。これは汎用的な解決策ではありませんが、適切な場合にセキュリティパッケージとアプリケーションを強く結び付けることができます。

ISC_REQ_ALLOCATE_MEMORY を指定した場合、呼び出し元は FreeContextBuffer 関数を呼び出してメモリを解放する必要があります。

たとえば、入力トークンが LAN Manager からのチャレンジであることがあります。この場合、出力トークンはそのチャレンジに対する NTLM で暗号化された応答になります。

クライアントが取るべき動作は、この関数の戻り値によって決まります。戻り値が SEC_E_OK の場合、2 回目の InitializeSecurityContext (General) の呼び出しは不要で、サーバーからの応答も想定されません。戻り値が SEC_I_CONTINUE_NEEDED の場合、クライアントはサーバーからの応答としてトークンを受け取り、それを 2 回目の InitializeSecurityContext (General) の呼び出しに渡します。戻り値 SEC_I_COMPLETE_NEEDED は、クライアントがメッセージの構築を完了し、CompleteAuthToken 関数を呼び出す必要があることを示します。SEC_I_COMPLETE_AND_CONTINUE はこれら両方の動作を含みます。

InitializeSecurityContext (General) が最初の (または唯一の) 呼び出しで成功を返した場合、認証交換の後続の段階で呼び出しが失敗したとしても、呼び出し元は最終的に、返されたハンドルに対して DeleteSecurityContext 関数を呼び出す必要があります。

クライアントは、InitializeSecurityContext (General) が正常に完了した後に、再度この関数を呼び出すこともできます。これは、セキュリティパッケージに対して再認証を要求することを示します。

カーネルモードの呼び出し元には次の違いがあります。ターゲット名は Unicode 文字列であり、VirtualAlloc を使用して仮想メモリに割り当てる必要があります。プールから割り当ててはなりません。pInput および pOutput で渡すバッファーは、プールではなく仮想メモリ上になければなりません。

Schannel SSP を使用する場合、この関数が SEC_I_INCOMPLETE_CREDENTIALS を返したときは、資格情報に有効で信頼された証明書を指定したかどうかを確認してください。証明書は AcquireCredentialsHandle (General) 関数を呼び出すときに指定します。証明書は、サーバーが信頼する証明機関 (CA) が発行したクライアント認証証明書でなければなりません。サーバーが信頼する CA の一覧を取得するには、QueryContextAttributes (General) 関数を呼び出し、SECPKG_ATTR_ISSUER_LIST_EX 属性を指定します。

Schannel SSP を使用する場合、クライアントアプリケーションはサーバーが信頼する CA から認証証明書を受け取った後、AcquireCredentialsHandle (General) 関数を呼び出して新しい資格情報を作成し、その新しい資格情報を phCredential パラメーターに指定して InitializeSecurityContext (General) を再度呼び出します。

メモ

sspi.h ヘッダーは InitializeSecurityContext を、UNICODE プリプロセッサ定数の定義に基づいてこの関数の ANSI 版と Unicode 版を自動的に選択するエイリアスとして定義しています。エンコーディング中立のエイリアスの使用と、エンコーディング中立でないコードを混在させると、コンパイルエラーや実行時エラーの原因となる不一致が生じる可能性があります。詳細については、関数プロトタイプの規則を参照してください。

出典・ライセンス: 上記「公式ドキュメント」の内容は Microsoft の Win32 API ドキュメント(MicrosoftDocs/sdk-api)を日本語に翻訳・改変したものです。© Microsoft Corporation. CC BY 4.0 で提供。
Microsoft 公式リファレンス: 英語 (en-us) · 日本語 (ja-jp) · 原文ソース (GitHub)

各言語での呼び出し定義

// SECUR32.dll  (Unicode / -W)
#include <windows.h>

HRESULT InitializeSecurityContextW(
    SecHandle* phCredential,   // optional
    SecHandle* phContext,   // optional
    WORD* pszTargetName,   // optional
    ISC_REQ_FLAGS fContextReq,
    DWORD Reserved1,
    DWORD TargetDataRep,
    SecBufferDesc* pInput,   // optional
    DWORD Reserved2,
    SecHandle* phNewContext,   // optional
    SecBufferDesc* pOutput,   // optional
    DWORD* pfContextAttr,
    LONGLONG* ptsExpiry   // optional
);
[DllImport("SECUR32.dll", CharSet = CharSet.Unicode, ExactSpelling = true)]
static extern int InitializeSecurityContextW(
    IntPtr phCredential,   // SecHandle* optional
    IntPtr phContext,   // SecHandle* optional
    IntPtr pszTargetName,   // WORD* optional
    uint fContextReq,   // ISC_REQ_FLAGS
    uint Reserved1,   // DWORD
    uint TargetDataRep,   // DWORD
    IntPtr pInput,   // SecBufferDesc* optional
    uint Reserved2,   // DWORD
    IntPtr phNewContext,   // SecHandle* optional, in/out
    IntPtr pOutput,   // SecBufferDesc* optional, in/out
    out uint pfContextAttr,   // DWORD* out
    IntPtr ptsExpiry   // LONGLONG* optional, out
);
<DllImport("SECUR32.dll", CharSet:=CharSet.Unicode, ExactSpelling:=True)>
Public Shared Function InitializeSecurityContextW(
    phCredential As IntPtr,   ' SecHandle* optional
    phContext As IntPtr,   ' SecHandle* optional
    pszTargetName As IntPtr,   ' WORD* optional
    fContextReq As UInteger,   ' ISC_REQ_FLAGS
    Reserved1 As UInteger,   ' DWORD
    TargetDataRep As UInteger,   ' DWORD
    pInput As IntPtr,   ' SecBufferDesc* optional
    Reserved2 As UInteger,   ' DWORD
    phNewContext As IntPtr,   ' SecHandle* optional, in/out
    pOutput As IntPtr,   ' SecBufferDesc* optional, in/out
    <Out> ByRef pfContextAttr As UInteger,   ' DWORD* out
    ptsExpiry As IntPtr   ' LONGLONG* optional, out
) As Integer
End Function
' phCredential : SecHandle* optional
' phContext : SecHandle* optional
' pszTargetName : WORD* optional
' fContextReq : ISC_REQ_FLAGS
' Reserved1 : DWORD
' TargetDataRep : DWORD
' pInput : SecBufferDesc* optional
' Reserved2 : DWORD
' phNewContext : SecHandle* optional, in/out
' pOutput : SecBufferDesc* optional, in/out
' pfContextAttr : DWORD* out
' ptsExpiry : LONGLONG* optional, out
Declare PtrSafe Function InitializeSecurityContextW Lib "secur32" ( _
    ByVal phCredential As LongPtr, _
    ByVal phContext As LongPtr, _
    ByVal pszTargetName As LongPtr, _
    ByVal fContextReq As Long, _
    ByVal Reserved1 As Long, _
    ByVal TargetDataRep As Long, _
    ByVal pInput As LongPtr, _
    ByVal Reserved2 As Long, _
    ByVal phNewContext As LongPtr, _
    ByVal pOutput As LongPtr, _
    ByRef pfContextAttr As Long, _
    ByVal ptsExpiry As LongPtr) As Long
' Unicode(W): 文字列は ByVal As LongPtr とし StrPtr(unicodeStr) を渡す
' VBA7前提(PtrSafe)。32bit Office では LongPtr→Long。Integer=16bit / Long=32bit / LongLong=64bit。
import ctypes
from ctypes import wintypes

InitializeSecurityContextW = ctypes.windll.secur32.InitializeSecurityContextW
InitializeSecurityContextW.restype = ctypes.c_int
InitializeSecurityContextW.argtypes = [
    ctypes.c_void_p,  # phCredential : SecHandle* optional
    ctypes.c_void_p,  # phContext : SecHandle* optional
    ctypes.POINTER(ctypes.c_ushort),  # pszTargetName : WORD* optional
    wintypes.DWORD,  # fContextReq : ISC_REQ_FLAGS
    wintypes.DWORD,  # Reserved1 : DWORD
    wintypes.DWORD,  # TargetDataRep : DWORD
    ctypes.c_void_p,  # pInput : SecBufferDesc* optional
    wintypes.DWORD,  # Reserved2 : DWORD
    ctypes.c_void_p,  # phNewContext : SecHandle* optional, in/out
    ctypes.c_void_p,  # pOutput : SecBufferDesc* optional, in/out
    ctypes.POINTER(wintypes.DWORD),  # pfContextAttr : DWORD* out
    ctypes.POINTER(ctypes.c_longlong),  # ptsExpiry : LONGLONG* optional, out
]
require 'fiddle'
require 'fiddle/import'

lib = Fiddle.dlopen('SECUR32.dll')
InitializeSecurityContextW = Fiddle::Function.new(
  lib['InitializeSecurityContextW'],
  [
    Fiddle::TYPE_VOIDP,  # phCredential : SecHandle* optional
    Fiddle::TYPE_VOIDP,  # phContext : SecHandle* optional
    Fiddle::TYPE_VOIDP,  # pszTargetName : WORD* optional
    -Fiddle::TYPE_INT,  # fContextReq : ISC_REQ_FLAGS
    -Fiddle::TYPE_INT,  # Reserved1 : DWORD
    -Fiddle::TYPE_INT,  # TargetDataRep : DWORD
    Fiddle::TYPE_VOIDP,  # pInput : SecBufferDesc* optional
    -Fiddle::TYPE_INT,  # Reserved2 : DWORD
    Fiddle::TYPE_VOIDP,  # phNewContext : SecHandle* optional, in/out
    Fiddle::TYPE_VOIDP,  # pOutput : SecBufferDesc* optional, in/out
    Fiddle::TYPE_VOIDP,  # pfContextAttr : DWORD* out
    Fiddle::TYPE_VOIDP,  # ptsExpiry : LONGLONG* optional, out
  ],
  Fiddle::TYPE_INT)
# Wide strings: pass str.encode("UTF-16LE") + "\x00\x00"
#[link(name = "secur32")]
extern "system" {
    fn InitializeSecurityContextW(
        phCredential: *mut SecHandle,  // SecHandle* optional
        phContext: *mut SecHandle,  // SecHandle* optional
        pszTargetName: *mut u16,  // WORD* optional
        fContextReq: u32,  // ISC_REQ_FLAGS
        Reserved1: u32,  // DWORD
        TargetDataRep: u32,  // DWORD
        pInput: *mut SecBufferDesc,  // SecBufferDesc* optional
        Reserved2: u32,  // DWORD
        phNewContext: *mut SecHandle,  // SecHandle* optional, in/out
        pOutput: *mut SecBufferDesc,  // SecBufferDesc* optional, in/out
        pfContextAttr: *mut u32,  // DWORD* out
        ptsExpiry: *mut i64  // LONGLONG* optional, out
    ) -> i32;
}
// crates: windows-sys provides ready-made bindings for this API.
$sig = @"
[DllImport("SECUR32.dll", CharSet = CharSet.Unicode)]
public static extern int InitializeSecurityContextW(IntPtr phCredential, IntPtr phContext, IntPtr pszTargetName, uint fContextReq, uint Reserved1, uint TargetDataRep, IntPtr pInput, uint Reserved2, IntPtr phNewContext, IntPtr pOutput, out uint pfContextAttr, IntPtr ptsExpiry);
"@
$api = Add-Type -MemberDefinition $sig -Name 'SECUR32_InitializeSecurityContextW' -Namespace Win32 -PassThru
# $api::InitializeSecurityContextW(phCredential, phContext, pszTargetName, fContextReq, Reserved1, TargetDataRep, pInput, Reserved2, phNewContext, pOutput, pfContextAttr, ptsExpiry)
#uselib "SECUR32.dll"
#func global InitializeSecurityContextW "InitializeSecurityContextW" wptr, wptr, wptr, wptr, wptr, wptr, wptr, wptr, wptr, wptr, wptr, wptr
; InitializeSecurityContextW varptr(phCredential), varptr(phContext), varptr(pszTargetName), fContextReq, Reserved1, TargetDataRep, varptr(pInput), Reserved2, varptr(phNewContext), varptr(pOutput), varptr(pfContextAttr), varptr(ptsExpiry)   ; 戻り値は stat
; phCredential : SecHandle* optional -> "wptr"
; phContext : SecHandle* optional -> "wptr"
; pszTargetName : WORD* optional -> "wptr"
; fContextReq : ISC_REQ_FLAGS -> "wptr"
; Reserved1 : DWORD -> "wptr"
; TargetDataRep : DWORD -> "wptr"
; pInput : SecBufferDesc* optional -> "wptr"
; Reserved2 : DWORD -> "wptr"
; phNewContext : SecHandle* optional, in/out -> "wptr"
; pOutput : SecBufferDesc* optional, in/out -> "wptr"
; pfContextAttr : DWORD* out -> "wptr"
; ptsExpiry : LONGLONG* optional, out -> "wptr"
; ※HSP3.7は #func のため戻り値はシステム変数 stat に格納されます。
出力引数:
#uselib "SECUR32.dll"
#cfunc global InitializeSecurityContextW "InitializeSecurityContextW" var, var, var, int, int, int, var, int, var, var, var, var
; res = InitializeSecurityContextW(phCredential, phContext, pszTargetName, fContextReq, Reserved1, TargetDataRep, pInput, Reserved2, phNewContext, pOutput, pfContextAttr, ptsExpiry)
; phCredential : SecHandle* optional -> "var"
; phContext : SecHandle* optional -> "var"
; pszTargetName : WORD* optional -> "var"
; fContextReq : ISC_REQ_FLAGS -> "int"
; Reserved1 : DWORD -> "int"
; TargetDataRep : DWORD -> "int"
; pInput : SecBufferDesc* optional -> "var"
; Reserved2 : DWORD -> "int"
; phNewContext : SecHandle* optional, in/out -> "var"
; pOutput : SecBufferDesc* optional, in/out -> "var"
; pfContextAttr : DWORD* out -> "var"
; ptsExpiry : LONGLONG* optional, out -> "var"
; ※出力/バッファ引数は var 方式(変数を直接渡す)。varptr 方式にも切替可。
出力引数:
; HRESULT InitializeSecurityContextW(SecHandle* phCredential, SecHandle* phContext, WORD* pszTargetName, ISC_REQ_FLAGS fContextReq, DWORD Reserved1, DWORD TargetDataRep, SecBufferDesc* pInput, DWORD Reserved2, SecHandle* phNewContext, SecBufferDesc* pOutput, DWORD* pfContextAttr, LONGLONG* ptsExpiry)
#uselib "SECUR32.dll"
#cfunc global InitializeSecurityContextW "InitializeSecurityContextW" var, var, var, int, int, int, var, int, var, var, var, var
; res = InitializeSecurityContextW(phCredential, phContext, pszTargetName, fContextReq, Reserved1, TargetDataRep, pInput, Reserved2, phNewContext, pOutput, pfContextAttr, ptsExpiry)
; phCredential : SecHandle* optional -> "var"
; phContext : SecHandle* optional -> "var"
; pszTargetName : WORD* optional -> "var"
; fContextReq : ISC_REQ_FLAGS -> "int"
; Reserved1 : DWORD -> "int"
; TargetDataRep : DWORD -> "int"
; pInput : SecBufferDesc* optional -> "var"
; Reserved2 : DWORD -> "int"
; phNewContext : SecHandle* optional, in/out -> "var"
; pOutput : SecBufferDesc* optional, in/out -> "var"
; pfContextAttr : DWORD* out -> "var"
; ptsExpiry : LONGLONG* optional, out -> "var"
; ※出力/バッファ引数は var 方式(変数を直接渡す)。varptr 方式にも切替可。
import (
	"golang.org/x/sys/windows"
	"unsafe"
)

var (
	secur32 = windows.NewLazySystemDLL("SECUR32.dll")
	procInitializeSecurityContextW = secur32.NewProc("InitializeSecurityContextW")
)

// phCredential (SecHandle* optional), phContext (SecHandle* optional), pszTargetName (WORD* optional), fContextReq (ISC_REQ_FLAGS), Reserved1 (DWORD), TargetDataRep (DWORD), pInput (SecBufferDesc* optional), Reserved2 (DWORD), phNewContext (SecHandle* optional, in/out), pOutput (SecBufferDesc* optional, in/out), pfContextAttr (DWORD* out), ptsExpiry (LONGLONG* optional, out)
r1, _, err := procInitializeSecurityContextW.Call(
	uintptr(phCredential),
	uintptr(phContext),
	uintptr(pszTargetName),
	uintptr(fContextReq),
	uintptr(Reserved1),
	uintptr(TargetDataRep),
	uintptr(pInput),
	uintptr(Reserved2),
	uintptr(phNewContext),
	uintptr(pOutput),
	uintptr(pfContextAttr),
	uintptr(ptsExpiry),
)
_ = err  // syscall.Errno (valid when the call sets last-error)
_ = r1   // HRESULT
function InitializeSecurityContextW(
  phCredential: Pointer;   // SecHandle* optional
  phContext: Pointer;   // SecHandle* optional
  pszTargetName: Pointer;   // WORD* optional
  fContextReq: DWORD;   // ISC_REQ_FLAGS
  Reserved1: DWORD;   // DWORD
  TargetDataRep: DWORD;   // DWORD
  pInput: Pointer;   // SecBufferDesc* optional
  Reserved2: DWORD;   // DWORD
  phNewContext: Pointer;   // SecHandle* optional, in/out
  pOutput: Pointer;   // SecBufferDesc* optional, in/out
  pfContextAttr: Pointer;   // DWORD* out
  ptsExpiry: Pointer   // LONGLONG* optional, out
): Integer; stdcall;
  external 'SECUR32.dll' name 'InitializeSecurityContextW';
result := DllCall("SECUR32\InitializeSecurityContextW"
    , "Ptr", phCredential   ; SecHandle* optional
    , "Ptr", phContext   ; SecHandle* optional
    , "Ptr", pszTargetName   ; WORD* optional
    , "UInt", fContextReq   ; ISC_REQ_FLAGS
    , "UInt", Reserved1   ; DWORD
    , "UInt", TargetDataRep   ; DWORD
    , "Ptr", pInput   ; SecBufferDesc* optional
    , "UInt", Reserved2   ; DWORD
    , "Ptr", phNewContext   ; SecHandle* optional, in/out
    , "Ptr", pOutput   ; SecBufferDesc* optional, in/out
    , "Ptr", pfContextAttr   ; DWORD* out
    , "Ptr", ptsExpiry   ; LONGLONG* optional, out
    , "Int")   ; return: HRESULT
●InitializeSecurityContextW(phCredential, phContext, pszTargetName, fContextReq, Reserved1, TargetDataRep, pInput, Reserved2, phNewContext, pOutput, pfContextAttr, ptsExpiry) = DLL("SECUR32.dll", "int InitializeSecurityContextW(void*, void*, void*, dword, dword, dword, void*, dword, void*, void*, void*, void*)")
# 呼び出し: InitializeSecurityContextW(phCredential, phContext, pszTargetName, fContextReq, Reserved1, TargetDataRep, pInput, Reserved2, phNewContext, pOutput, pfContextAttr, ptsExpiry)
# phCredential : SecHandle* optional -> "void*"
# phContext : SecHandle* optional -> "void*"
# pszTargetName : WORD* optional -> "void*"
# fContextReq : ISC_REQ_FLAGS -> "dword"
# Reserved1 : DWORD -> "dword"
# TargetDataRep : DWORD -> "dword"
# pInput : SecBufferDesc* optional -> "void*"
# Reserved2 : DWORD -> "dword"
# phNewContext : SecHandle* optional, in/out -> "void*"
# pOutput : SecBufferDesc* optional, in/out -> "void*"
# pfContextAttr : DWORD* out -> "void*"
# ptsExpiry : LONGLONG* optional, out -> "void*"
# なでしこ1は32bit・ANSI(Shift_JIS)。文字列=char*(ANSI)、ポインタ/ハンドル=void*(4byte)。
# ※-W(Unicode)関数。なでしこ1はANSIのため -A 版の利用を推奨。
const std = @import("std");

extern "secur32" fn InitializeSecurityContextW(
    phCredential: [*c]SecHandle, // SecHandle* optional
    phContext: [*c]SecHandle, // SecHandle* optional
    pszTargetName: [*c]u16, // WORD* optional
    fContextReq: u32, // ISC_REQ_FLAGS
    Reserved1: u32, // DWORD
    TargetDataRep: u32, // DWORD
    pInput: [*c]SecBufferDesc, // SecBufferDesc* optional
    Reserved2: u32, // DWORD
    phNewContext: [*c]SecHandle, // SecHandle* optional, in/out
    pOutput: [*c]SecBufferDesc, // SecBufferDesc* optional, in/out
    pfContextAttr: [*c]u32, // DWORD* out
    ptsExpiry: [*c]i64 // LONGLONG* optional, out
) callconv(std.os.windows.WINAPI) i32;
// Unicode(-W): UTF-16LE のヌル終端バッファ([*c]const u16)を渡す。
proc InitializeSecurityContextW(
    phCredential: ptr SecHandle,  # SecHandle* optional
    phContext: ptr SecHandle,  # SecHandle* optional
    pszTargetName: ptr uint16,  # WORD* optional
    fContextReq: uint32,  # ISC_REQ_FLAGS
    Reserved1: uint32,  # DWORD
    TargetDataRep: uint32,  # DWORD
    pInput: ptr SecBufferDesc,  # SecBufferDesc* optional
    Reserved2: uint32,  # DWORD
    phNewContext: ptr SecHandle,  # SecHandle* optional, in/out
    pOutput: ptr SecBufferDesc,  # SecBufferDesc* optional, in/out
    pfContextAttr: ptr uint32,  # DWORD* out
    ptsExpiry: ptr int64  # LONGLONG* optional, out
): int32 {.importc: "InitializeSecurityContextW", stdcall, dynlib: "SECUR32.dll".}
# Unicode(-W): WideCString は newWideCString("...") で生成。
pragma(lib, "secur32");
extern(Windows)
int InitializeSecurityContextW(
    SecHandle* phCredential,   // SecHandle* optional
    SecHandle* phContext,   // SecHandle* optional
    ushort* pszTargetName,   // WORD* optional
    uint fContextReq,   // ISC_REQ_FLAGS
    uint Reserved1,   // DWORD
    uint TargetDataRep,   // DWORD
    SecBufferDesc* pInput,   // SecBufferDesc* optional
    uint Reserved2,   // DWORD
    SecHandle* phNewContext,   // SecHandle* optional, in/out
    SecBufferDesc* pOutput,   // SecBufferDesc* optional, in/out
    uint* pfContextAttr,   // DWORD* out
    long* ptsExpiry   // LONGLONG* optional, out
);
ccall((:InitializeSecurityContextW, "SECUR32.dll"), stdcall, Int32,
      (Ptr{SecHandle}, Ptr{SecHandle}, Ptr{UInt16}, UInt32, UInt32, UInt32, Ptr{SecBufferDesc}, UInt32, Ptr{SecHandle}, Ptr{SecBufferDesc}, Ptr{UInt32}, Ptr{Int64}),
      phCredential, phContext, pszTargetName, fContextReq, Reserved1, TargetDataRep, pInput, Reserved2, phNewContext, pOutput, pfContextAttr, ptsExpiry)
# phCredential : SecHandle* optional -> Ptr{SecHandle}
# phContext : SecHandle* optional -> Ptr{SecHandle}
# pszTargetName : WORD* optional -> Ptr{UInt16}
# fContextReq : ISC_REQ_FLAGS -> UInt32
# Reserved1 : DWORD -> UInt32
# TargetDataRep : DWORD -> UInt32
# pInput : SecBufferDesc* optional -> Ptr{SecBufferDesc}
# Reserved2 : DWORD -> UInt32
# phNewContext : SecHandle* optional, in/out -> Ptr{SecHandle}
# pOutput : SecBufferDesc* optional, in/out -> Ptr{SecBufferDesc}
# pfContextAttr : DWORD* out -> Ptr{UInt32}
# ptsExpiry : LONGLONG* optional, out -> Ptr{Int64}
# stdcall は 32bit のみ意味を持つ(x64 では無視)。
# Unicode(-W): Cwstring には transcode(UInt16, "...") 等で UTF-16 を渡す。
local ffi = require("ffi")
ffi.cdef[[
int32_t InitializeSecurityContextW(
    void* phCredential,
    void* phContext,
    uint16_t* pszTargetName,
    uint32_t fContextReq,
    uint32_t Reserved1,
    uint32_t TargetDataRep,
    void* pInput,
    uint32_t Reserved2,
    void* phNewContext,
    void* pOutput,
    uint32_t* pfContextAttr,
    int64_t* ptsExpiry);
]]
local secur32 = ffi.load("secur32")
-- secur32.InitializeSecurityContextW(phCredential, phContext, pszTargetName, fContextReq, Reserved1, TargetDataRep, pInput, Reserved2, phNewContext, pOutput, pfContextAttr, ptsExpiry)
-- phCredential : SecHandle* optional
-- phContext : SecHandle* optional
-- pszTargetName : WORD* optional
-- fContextReq : ISC_REQ_FLAGS
-- Reserved1 : DWORD
-- TargetDataRep : DWORD
-- pInput : SecBufferDesc* optional
-- Reserved2 : DWORD
-- phNewContext : SecHandle* optional, in/out
-- pOutput : SecBufferDesc* optional, in/out
-- pfContextAttr : DWORD* out
-- ptsExpiry : LONGLONG* optional, out
-- 構造体/GUIDへのポインタは cdef が通るよう void* で表記(実型は各引数コメント参照)。値渡し構造体・enum は対応する typedef を cdef に追加すること。
-- Unicode(-W): uint16_t* には UTF-16LE のバッファ(ffi.new("uint16_t[?]", ...))を渡す。
const koffi = require('koffi');
const lib = koffi.load('SECUR32.dll');
const InitializeSecurityContextW = lib.func('__stdcall', 'InitializeSecurityContextW', 'int32_t', ['void *', 'void *', 'uint16_t *', 'uint32_t', 'uint32_t', 'uint32_t', 'void *', 'uint32_t', 'void *', 'void *', 'uint32_t *', 'int64_t *']);
// InitializeSecurityContextW(phCredential, phContext, pszTargetName, fContextReq, Reserved1, TargetDataRep, pInput, Reserved2, phNewContext, pOutput, pfContextAttr, ptsExpiry)
// phCredential : SecHandle* optional -> 'void *'
// phContext : SecHandle* optional -> 'void *'
// pszTargetName : WORD* optional -> 'uint16_t *'
// fContextReq : ISC_REQ_FLAGS -> 'uint32_t'
// Reserved1 : DWORD -> 'uint32_t'
// TargetDataRep : DWORD -> 'uint32_t'
// pInput : SecBufferDesc* optional -> 'void *'
// Reserved2 : DWORD -> 'uint32_t'
// phNewContext : SecHandle* optional, in/out -> 'void *'
// pOutput : SecBufferDesc* optional, in/out -> 'void *'
// pfContextAttr : DWORD* out -> 'uint32_t *'
// ptsExpiry : LONGLONG* optional, out -> 'int64_t *'
// 出力ポインタは koffi.out(...) で包む。構造体は koffi.struct で定義。
const lib = Deno.dlopen("SECUR32.dll", {
  InitializeSecurityContextW: { parameters: ["pointer", "pointer", "pointer", "u32", "u32", "u32", "pointer", "u32", "pointer", "pointer", "pointer", "pointer"], result: "i32" },
});
// lib.symbols.InitializeSecurityContextW(phCredential, phContext, pszTargetName, fContextReq, Reserved1, TargetDataRep, pInput, Reserved2, phNewContext, pOutput, pfContextAttr, ptsExpiry)
// phCredential : SecHandle* optional -> "pointer"
// phContext : SecHandle* optional -> "pointer"
// pszTargetName : WORD* optional -> "pointer"
// fContextReq : ISC_REQ_FLAGS -> "u32"
// Reserved1 : DWORD -> "u32"
// TargetDataRep : DWORD -> "u32"
// pInput : SecBufferDesc* optional -> "pointer"
// Reserved2 : DWORD -> "u32"
// phNewContext : SecHandle* optional, in/out -> "pointer"
// pOutput : SecBufferDesc* optional, in/out -> "pointer"
// pfContextAttr : DWORD* out -> "pointer"
// ptsExpiry : LONGLONG* optional, out -> "pointer"
// 文字列は "buffer"。Unicode(-W) は new TextEncoder() ではなく UTF-16LE のバイト列(末尾に \x00\x00)を Uint8Array で渡す。
// 値渡し構造体は { struct: [ ...field types... ] } を使用。
<?php
$ffi = FFI::cdef(<<<C
int32_t InitializeSecurityContextW(
    void* phCredential,
    void* phContext,
    uint16_t* pszTargetName,
    uint32_t fContextReq,
    uint32_t Reserved1,
    uint32_t TargetDataRep,
    void* pInput,
    uint32_t Reserved2,
    void* phNewContext,
    void* pOutput,
    uint32_t* pfContextAttr,
    int64_t* ptsExpiry);
C, "SECUR32.dll");
// $ffi->InitializeSecurityContextW(phCredential, phContext, pszTargetName, fContextReq, Reserved1, TargetDataRep, pInput, Reserved2, phNewContext, pOutput, pfContextAttr, ptsExpiry);
// phCredential : SecHandle* optional
// phContext : SecHandle* optional
// pszTargetName : WORD* optional
// fContextReq : ISC_REQ_FLAGS
// Reserved1 : DWORD
// TargetDataRep : DWORD
// pInput : SecBufferDesc* optional
// Reserved2 : DWORD
// phNewContext : SecHandle* optional, in/out
// pOutput : SecBufferDesc* optional, in/out
// pfContextAttr : DWORD* out
// ptsExpiry : LONGLONG* optional, out
// 構造体/GUIDへのポインタは cdef が通るよう void* で表記(実型は各引数コメント参照)。値渡し構造体・enum は対応する typedef を cdef に追加すること。
// WINAPI(stdcall): x64 では呼出規約が統一されるため問題なし。x86 では __stdcall 対応のラッパが必要な場合あり。
import com.sun.jna.*;
import com.sun.jna.ptr.*;
import com.sun.jna.win32.StdCallLibrary;
import com.sun.jna.win32.W32APIOptions;

public interface Secur32 extends StdCallLibrary {
    Secur32 INSTANCE = Native.load("secur32", Secur32.class, W32APIOptions.UNICODE_OPTIONS);
    int InitializeSecurityContextW(
        Pointer phCredential,   // SecHandle* optional
        Pointer phContext,   // SecHandle* optional
        ShortByReference pszTargetName,   // WORD* optional
        int fContextReq,   // ISC_REQ_FLAGS
        int Reserved1,   // DWORD
        int TargetDataRep,   // DWORD
        Pointer pInput,   // SecBufferDesc* optional
        int Reserved2,   // DWORD
        Pointer phNewContext,   // SecHandle* optional, in/out
        Pointer pOutput,   // SecBufferDesc* optional, in/out
        IntByReference pfContextAttr,   // DWORD* out
        LongByReference ptsExpiry   // LONGLONG* optional, out
    );
}
// Unicode(-W): WString(入力)/char[](出力)で UTF-16 をマーシャリング。
@[Link("secur32")]
lib LibSECUR32
  fun InitializeSecurityContextW = InitializeSecurityContextW(
    phCredential : SecHandle*,   # SecHandle* optional
    phContext : SecHandle*,   # SecHandle* optional
    pszTargetName : UInt16*,   # WORD* optional
    fContextReq : UInt32,   # ISC_REQ_FLAGS
    Reserved1 : UInt32,   # DWORD
    TargetDataRep : UInt32,   # DWORD
    pInput : SecBufferDesc*,   # SecBufferDesc* optional
    Reserved2 : UInt32,   # DWORD
    phNewContext : SecHandle*,   # SecHandle* optional, in/out
    pOutput : SecBufferDesc*,   # SecBufferDesc* optional, in/out
    pfContextAttr : UInt32*,   # DWORD* out
    ptsExpiry : Int64*   # LONGLONG* optional, out
  ) : Int32
end
# 構造体/GUID/enum は lib 内に対応する型定義が必要。
# 呼出規約: x64 は規約統一のため OK。x86(32bit)は WINAPI=stdcall だが Crystal の fun に stdcall 付与構文がなく非対応。
import 'dart:ffi';
import 'package:ffi/ffi.dart';

typedef InitializeSecurityContextWNative = Int32 Function(Pointer<Void>, Pointer<Void>, Pointer<Uint16>, Uint32, Uint32, Uint32, Pointer<Void>, Uint32, Pointer<Void>, Pointer<Void>, Pointer<Uint32>, Pointer<Int64>);
typedef InitializeSecurityContextWDart = int Function(Pointer<Void>, Pointer<Void>, Pointer<Uint16>, int, int, int, Pointer<Void>, int, Pointer<Void>, Pointer<Void>, Pointer<Uint32>, Pointer<Int64>);
final InitializeSecurityContextW = DynamicLibrary.open('SECUR32.dll')
    .lookupFunction<InitializeSecurityContextWNative, InitializeSecurityContextWDart>('InitializeSecurityContextW');
// phCredential : SecHandle* optional -> Pointer<Void>
// phContext : SecHandle* optional -> Pointer<Void>
// pszTargetName : WORD* optional -> Pointer<Uint16>
// fContextReq : ISC_REQ_FLAGS -> Uint32
// Reserved1 : DWORD -> Uint32
// TargetDataRep : DWORD -> Uint32
// pInput : SecBufferDesc* optional -> Pointer<Void>
// Reserved2 : DWORD -> Uint32
// phNewContext : SecHandle* optional, in/out -> Pointer<Void>
// pOutput : SecBufferDesc* optional, in/out -> Pointer<Void>
// pfContextAttr : DWORD* out -> Pointer<Uint32>
// ptsExpiry : LONGLONG* optional, out -> Pointer<Int64>
// 文字列は package:ffi の "...".toNativeUtf16()/toNativeUtf8() で変換。
{$mode objfpc}{$H+}
function InitializeSecurityContextW(
  phCredential: Pointer;   // SecHandle* optional
  phContext: Pointer;   // SecHandle* optional
  pszTargetName: Pointer;   // WORD* optional
  fContextReq: DWORD;   // ISC_REQ_FLAGS
  Reserved1: DWORD;   // DWORD
  TargetDataRep: DWORD;   // DWORD
  pInput: Pointer;   // SecBufferDesc* optional
  Reserved2: DWORD;   // DWORD
  phNewContext: Pointer;   // SecHandle* optional, in/out
  pOutput: Pointer;   // SecBufferDesc* optional, in/out
  pfContextAttr: Pointer;   // DWORD* out
  ptsExpiry: Pointer   // LONGLONG* optional, out
): Integer; stdcall;
  external 'SECUR32.dll' name 'InitializeSecurityContextW';
import Foreign
import Foreign.C.Types
import Foreign.C.String

foreign import stdcall safe "InitializeSecurityContextW"
  c_InitializeSecurityContextW :: Ptr () -> Ptr () -> Ptr Word16 -> Word32 -> Word32 -> Word32 -> Ptr () -> Word32 -> Ptr () -> Ptr () -> Ptr Word32 -> Ptr Int64 -> IO Int32
-- phCredential : SecHandle* optional -> Ptr ()
-- phContext : SecHandle* optional -> Ptr ()
-- pszTargetName : WORD* optional -> Ptr Word16
-- fContextReq : ISC_REQ_FLAGS -> Word32
-- Reserved1 : DWORD -> Word32
-- TargetDataRep : DWORD -> Word32
-- pInput : SecBufferDesc* optional -> Ptr ()
-- Reserved2 : DWORD -> Word32
-- phNewContext : SecHandle* optional, in/out -> Ptr ()
-- pOutput : SecBufferDesc* optional, in/out -> Ptr ()
-- pfContextAttr : DWORD* out -> Ptr Word32
-- ptsExpiry : LONGLONG* optional, out -> Ptr Int64
-- 要 GHC(Windows)。stdcall は x64 では ccall として扱われる。ブロックする API は safe 呼び出し推奨。
open Ctypes
open Foreign

let initializesecuritycontextw =
  foreign "InitializeSecurityContextW"
    ((ptr void) @-> (ptr void) @-> (ptr uint16_t) @-> uint32_t @-> uint32_t @-> uint32_t @-> (ptr void) @-> uint32_t @-> (ptr void) @-> (ptr void) @-> (ptr uint32_t) @-> (ptr int64_t) @-> returning int32_t)
(* phCredential : SecHandle* optional -> (ptr void) *)
(* phContext : SecHandle* optional -> (ptr void) *)
(* pszTargetName : WORD* optional -> (ptr uint16_t) *)
(* fContextReq : ISC_REQ_FLAGS -> uint32_t *)
(* Reserved1 : DWORD -> uint32_t *)
(* TargetDataRep : DWORD -> uint32_t *)
(* pInput : SecBufferDesc* optional -> (ptr void) *)
(* Reserved2 : DWORD -> uint32_t *)
(* phNewContext : SecHandle* optional, in/out -> (ptr void) *)
(* pOutput : SecBufferDesc* optional, in/out -> (ptr void) *)
(* pfContextAttr : DWORD* out -> (ptr uint32_t) *)
(* ptsExpiry : LONGLONG* optional, out -> (ptr int64_t) *)
(* foreign は cdecl 前提。x64 Windows では WINAPI と一致。構造体は ctypes structure を定義のこと。 *)
(cffi:define-foreign-library secur32 (t "SECUR32.dll"))
(cffi:use-foreign-library secur32)

(cffi:defcfun ("InitializeSecurityContextW" initialize-security-context-w :convention :stdcall) :int32
  (ph-credential :pointer)   ; SecHandle* optional
  (ph-context :pointer)   ; SecHandle* optional
  (psz-target-name :pointer)   ; WORD* optional
  (f-context-req :uint32)   ; ISC_REQ_FLAGS
  (reserved1 :uint32)   ; DWORD
  (target-data-rep :uint32)   ; DWORD
  (p-input :pointer)   ; SecBufferDesc* optional
  (reserved2 :uint32)   ; DWORD
  (ph-new-context :pointer)   ; SecHandle* optional, in/out
  (p-output :pointer)   ; SecBufferDesc* optional, in/out
  (pf-context-attr :pointer)   ; DWORD* out
  (pts-expiry :pointer))   ; LONGLONG* optional, out
; isize/usize(INT_PTR/SIZE_T)は x64 前提で :int64/:uint64。x86 では :int32/:uint32。
use Win32::API;
my $InitializeSecurityContextW = Win32::API::More->new('SECUR32',
    'int InitializeSecurityContextW(LPVOID phCredential, LPVOID phContext, LPVOID pszTargetName, DWORD fContextReq, DWORD Reserved1, DWORD TargetDataRep, LPVOID pInput, DWORD Reserved2, LPVOID phNewContext, LPVOID pOutput, LPVOID pfContextAttr, LPVOID ptsExpiry)');
# my $ret = $InitializeSecurityContextW->Call($phCredential, $phContext, $pszTargetName, $fContextReq, $Reserved1, $TargetDataRep, $pInput, $Reserved2, $phNewContext, $pOutput, $pfContextAttr, $ptsExpiry);
# phCredential : SecHandle* optional -> LPVOID
# phContext : SecHandle* optional -> LPVOID
# pszTargetName : WORD* optional -> LPVOID
# fContextReq : ISC_REQ_FLAGS -> DWORD
# Reserved1 : DWORD -> DWORD
# TargetDataRep : DWORD -> DWORD
# pInput : SecBufferDesc* optional -> LPVOID
# Reserved2 : DWORD -> DWORD
# phNewContext : SecHandle* optional, in/out -> LPVOID
# pOutput : SecBufferDesc* optional, in/out -> LPVOID
# pfContextAttr : DWORD* out -> LPVOID
# ptsExpiry : LONGLONG* optional, out -> LPVOID
# 値渡し構造体は pack() した文字列、または Win32::API::Struct を使用。
# Unicode(-W): LPCWSTR/LPWSTR は Win32::API が UTF-16 変換を行う。

関連項目

文字セット違い
公式の関連項目
使用する型