WS_NAMEDPIPE_SSPI_TRANSPORT_SECURITY_BINDING
構造体サイズ=各フィールドのバイト数(x64/x86 で異なる場合は x64/x86 と併記)。x64/x86 列=フィールドのバイトオフセット(HSPで dupptr / lpoke / wpoke 等に使用)。
フィールド
| フィールド | 型 | サイズ | x64 | x86 | 説明 |
|---|---|---|---|---|---|
| binding | WS_SECURITY_BINDING | 24/12 | +0 | +0 | このセキュリティバインディングのサブタイプと、その他すべてのセキュリティバインディングのサブタイプの派生元となる基本型です。 |
| clientCredential | WS_WINDOWS_INTEGRATED_AUTH_CREDENTIAL* | 8/4 | +24 | +12 | クライアントの認証に使用される WS_WINDOWS_INTEGRATED_AUTH_CREDENTIAL 構造体です。これはクライアントでは必須であり、サーバーでは指定してはなりません。 |
公式ドキュメント
名前付きパイプトランスポートで Windows 統合認証プロトコル (Kerberos、NTLM、SPNEGO など) を使用することを指定するためのセキュリティバインディングのサブタイプです。特定の SSP パッケージは、セキュリティバインディングのプロパティ WS_SECURITY_BINDING_PROPERTY_WINDOWS_INTEGRATED_AUTH_PACKAGE を使用して選択できます。このプロパティが指定されない場合は、既定で SPNEGO が使用されます。
このセキュリティバインディングはトランスポートセキュリティのレベルで動作し、WS_NAMEDPIPE_CHANNEL_BINDING でのみサポートされます。名前付きパイプと Windows SSPI の組み合わせでは、NegotiateStream プロトコルおよび .Net Message Framing 仕様で定義されたワイヤー形式が使用されます。
クライアント側では、対象となるサーバーのセキュリティ ID は、WsOpenChannel で指定する WS_ENDPOINT_ADDRESS パラメーターの identity フィールドを使用して指定します。
名前付きパイプのバインディングは、このトランスポートセキュリティバインディング 1 つのみをサポートし、メッセージセキュリティバインディングはサポートしません。
このセキュリティバインディングでは、次のセキュリティバインディングのプロパティを指定できます。
- WS_SECURITY_BINDING_PROPERTY_WINDOWS_INTEGRATED_AUTH_PACKAGE
- WS_SECURITY_BINDING_PROPERTY_REQUIRE_SERVER_AUTH (クライアント側のみ)
- WS_SECURITY_BINDING_PROPERTY_ALLOW_ANONYMOUS_CLIENTS (サーバー側のみ)
- WS_SECURITY_BINDING_PROPERTY_ALLOWED_IMPERSONATION_LEVEL (クライアント側のみ)
Microsoft 公式リファレンス: 英語 (en-us) · 日本語 (ja-jp) · 原文ソース (GitHub)
各言語での定義
#include <windows.h>
// WS_SECURITY_BINDING (x64 24 / x86 12 バイト)
typedef struct WS_SECURITY_BINDING {
WS_SECURITY_BINDING_TYPE bindingType;
WS_SECURITY_BINDING_PROPERTY* properties;
DWORD propertyCount;
} WS_SECURITY_BINDING;
// WS_NAMEDPIPE_SSPI_TRANSPORT_SECURITY_BINDING (x64 32 / x86 16 バイト)
typedef struct WS_NAMEDPIPE_SSPI_TRANSPORT_SECURITY_BINDING {
WS_SECURITY_BINDING binding;
WS_WINDOWS_INTEGRATED_AUTH_CREDENTIAL* clientCredential;
} WS_NAMEDPIPE_SSPI_TRANSPORT_SECURITY_BINDING;using System;
using System.Runtime.InteropServices;
[StructLayout(LayoutKind.Sequential, CharSet = CharSet.Unicode)]
public struct WS_SECURITY_BINDING
{
public int bindingType;
public IntPtr properties;
public uint propertyCount;
}
[StructLayout(LayoutKind.Sequential, CharSet = CharSet.Unicode)]
public struct WS_NAMEDPIPE_SSPI_TRANSPORT_SECURITY_BINDING
{
public WS_SECURITY_BINDING binding;
public IntPtr clientCredential;
}Imports System.Runtime.InteropServices
<StructLayout(LayoutKind.Sequential, CharSet:=CharSet.Unicode)>
Public Structure WS_SECURITY_BINDING
Public bindingType As Integer
Public properties As IntPtr
Public propertyCount As UInteger
End Structure
<StructLayout(LayoutKind.Sequential, CharSet:=CharSet.Unicode)>
Public Structure WS_NAMEDPIPE_SSPI_TRANSPORT_SECURITY_BINDING
Public binding As WS_SECURITY_BINDING
Public clientCredential As IntPtr
End Structureimport ctypes
from ctypes import wintypes
class WS_SECURITY_BINDING(ctypes.Structure):
_fields_ = [
("bindingType", ctypes.c_int),
("properties", ctypes.c_void_p),
("propertyCount", wintypes.DWORD),
]
class WS_NAMEDPIPE_SSPI_TRANSPORT_SECURITY_BINDING(ctypes.Structure):
_fields_ = [
("binding", WS_SECURITY_BINDING),
("clientCredential", ctypes.c_void_p),
]#[repr(C)]
pub struct WS_SECURITY_BINDING {
pub bindingType: i32,
pub properties: *mut core::ffi::c_void,
pub propertyCount: u32,
}
#[repr(C)]
pub struct WS_NAMEDPIPE_SSPI_TRANSPORT_SECURITY_BINDING {
pub binding: WS_SECURITY_BINDING,
pub clientCredential: *mut core::ffi::c_void,
}import "golang.org/x/sys/windows"
type WS_SECURITY_BINDING struct {
bindingType int32
properties uintptr
propertyCount uint32
}
type WS_NAMEDPIPE_SSPI_TRANSPORT_SECURITY_BINDING struct {
binding WS_SECURITY_BINDING
clientCredential uintptr
}type
WS_SECURITY_BINDING = record
bindingType: Integer;
properties: Pointer;
propertyCount: DWORD;
end;
WS_NAMEDPIPE_SSPI_TRANSPORT_SECURITY_BINDING = record
binding: WS_SECURITY_BINDING;
clientCredential: Pointer;
end;const WS_SECURITY_BINDING = extern struct {
bindingType: i32,
properties: ?*anyopaque,
propertyCount: u32,
};
const WS_NAMEDPIPE_SSPI_TRANSPORT_SECURITY_BINDING = extern struct {
binding: WS_SECURITY_BINDING,
clientCredential: ?*anyopaque,
};type
WS_SECURITY_BINDING {.bycopy.} = object
bindingType: int32
properties: pointer
propertyCount: uint32
WS_NAMEDPIPE_SSPI_TRANSPORT_SECURITY_BINDING {.bycopy.} = object
binding: WS_SECURITY_BINDING
clientCredential: pointerstruct WS_SECURITY_BINDING
{
int bindingType;
void* properties;
uint propertyCount;
}
struct WS_NAMEDPIPE_SSPI_TRANSPORT_SECURITY_BINDING
{
WS_SECURITY_BINDING binding;
void* clientCredential;
}HSP用 定義
HSP3.7/3.8 は構造体機能が無いため4byte整数配列(dim)+peek/poke で操作(32/64bitでサイズ・位置が異なる場合はタブで分割)。IronHSP は NSTRUCT(#defstruct/stdim/->)で32/64bit共通。
; HSP3.7/3.8 は構造体機能が無いため、4byte整数の配列変数で操作します。(x86 レイアウト)
; WS_NAMEDPIPE_SSPI_TRANSPORT_SECURITY_BINDING サイズ: 16 バイト(x86)
dim st, 4 ; 4byte整数×4(構造体サイズ 16 / 4 切り上げ)
; binding : WS_SECURITY_BINDING (+0, 12byte) varptr(st)+0 を基点に操作(12byte:入れ子/配列)
; clientCredential : WS_WINDOWS_INTEGRATED_AUTH_CREDENTIAL* (+12, 4byte) varptr(st)+12 を基点に操作(4byte:入れ子/配列)
; ※4byte境界の整数は添字 st.N(N=オフセット/4)で読み書き可。それ以外は peek/poke 系を使用。; HSP3.7/3.8 は構造体機能が無いため、4byte整数の配列変数で操作します。(x64 レイアウト)
; WS_NAMEDPIPE_SSPI_TRANSPORT_SECURITY_BINDING サイズ: 32 バイト(x64)
dim st, 8 ; 4byte整数×8(構造体サイズ 32 / 4 切り上げ)
; binding : WS_SECURITY_BINDING (+0, 24byte) varptr(st)+0 を基点に操作(24byte:入れ子/配列)
; clientCredential : WS_WINDOWS_INTEGRATED_AUTH_CREDENTIAL* (+24, 8byte) varptr(st)+24 を基点に操作(8byte:入れ子/配列)
; ※4byte境界の整数は添字 st.N(N=オフセット/4)で読み書き可。それ以外は peek/poke 系を使用。; IronHSP は NSTRUCT(構造体)をサポート。32bit/64bit どちらでも同じコードで動作します。
; ※GUID・入れ子構造体はデフォルト型でないため、依存する #defstruct を先に定義(下記に同梱)。
#defstruct global WS_SECURITY_BINDING
#field int bindingType
#field intptr properties
#field int propertyCount
#endstruct
#defstruct global WS_NAMEDPIPE_SSPI_TRANSPORT_SECURITY_BINDING
#field WS_SECURITY_BINDING binding
#field intptr clientCredential
#endstruct
stdim st, WS_NAMEDPIPE_SSPI_TRANSPORT_SECURITY_BINDING ; NSTRUCT 変数を確保