2009-01-13 15:08:21 +01:00
|
|
|
/* Written by Simon Josefsson <simon@yubico.com>.
|
2014-04-30 13:16:09 +02:00
|
|
|
* Copyright (c) 2006-2014 Yubico AB
|
2011-03-12 15:49:50 +01:00
|
|
|
* Copyright (c) 2011 Tollef Fog Heen <tfheen@err.no>
|
2009-01-13 15:08:21 +01:00
|
|
|
* All rights reserved.
|
2008-01-11 13:41:21 +01:00
|
|
|
*
|
|
|
|
* Redistribution and use in source and binary forms, with or without
|
2009-01-13 15:08:21 +01:00
|
|
|
* modification, are permitted provided that the following conditions are
|
|
|
|
* met:
|
2008-01-11 13:41:21 +01:00
|
|
|
*
|
2009-01-13 15:08:21 +01:00
|
|
|
* * Redistributions of source code must retain the above copyright
|
|
|
|
* notice, this list of conditions and the following disclaimer.
|
2008-01-11 13:41:21 +01:00
|
|
|
*
|
2009-01-13 15:08:21 +01:00
|
|
|
* * Redistributions in binary form must reproduce the above
|
|
|
|
* copyright notice, this list of conditions and the following
|
|
|
|
* disclaimer in the documentation and/or other materials provided
|
|
|
|
* with the distribution.
|
|
|
|
*
|
|
|
|
* THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
|
|
|
|
* "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
|
|
|
|
* LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
|
|
|
|
* A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT
|
|
|
|
* OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
|
|
|
|
* SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT
|
|
|
|
* LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
|
|
|
|
* DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
|
|
|
|
* THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
|
|
|
|
* (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
|
|
|
|
* OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
|
2008-01-11 13:41:21 +01:00
|
|
|
*/
|
|
|
|
|
|
|
|
#include <stdio.h>
|
|
|
|
#include <stdlib.h>
|
|
|
|
#include <stdarg.h>
|
|
|
|
#include <ctype.h>
|
2011-03-12 15:49:50 +01:00
|
|
|
#include <syslog.h>
|
2008-01-11 13:41:21 +01:00
|
|
|
|
2011-11-23 10:15:29 +01:00
|
|
|
#include <sys/types.h>
|
|
|
|
#include <sys/stat.h>
|
2012-01-28 00:30:34 +01:00
|
|
|
#include <fcntl.h>
|
2011-11-23 10:15:29 +01:00
|
|
|
#include <unistd.h>
|
|
|
|
#include <errno.h>
|
|
|
|
#include <string.h>
|
2013-09-20 10:31:25 +02:00
|
|
|
#include <pwd.h>
|
2011-11-23 10:15:29 +01:00
|
|
|
|
2011-03-17 14:36:19 +01:00
|
|
|
#include "util.h"
|
2011-11-23 10:15:29 +01:00
|
|
|
#include "drop_privs.h"
|
2011-03-17 14:36:19 +01:00
|
|
|
|
2014-08-27 09:44:49 +02:00
|
|
|
#include <ykclient.h>
|
|
|
|
|
2011-12-06 13:31:25 +01:00
|
|
|
#if HAVE_CR
|
2014-08-27 10:25:01 +02:00
|
|
|
/* for yubikey_hex_encode */
|
|
|
|
#include <yubikey.h>
|
2014-08-27 09:37:38 +02:00
|
|
|
/* for yubikey pbkdf2*/
|
2013-09-18 09:58:47 +02:00
|
|
|
#include <ykpbkdf2.h>
|
2011-12-06 13:31:25 +01:00
|
|
|
#endif /* HAVE_CR */
|
|
|
|
|
2008-01-11 13:41:21 +01:00
|
|
|
/* Libtool defines PIC for shared objects */
|
|
|
|
#ifndef PIC
|
|
|
|
#define PAM_STATIC
|
|
|
|
#endif
|
|
|
|
|
|
|
|
/* These #defines must be present according to PAM documentation. */
|
|
|
|
#define PAM_SM_AUTH
|
|
|
|
|
|
|
|
#ifdef HAVE_SECURITY_PAM_APPL_H
|
|
|
|
#include <security/pam_appl.h>
|
|
|
|
#endif
|
|
|
|
#ifdef HAVE_SECURITY_PAM_MODULES_H
|
|
|
|
#include <security/pam_modules.h>
|
|
|
|
#endif
|
|
|
|
|
2009-02-11 17:35:29 +01:00
|
|
|
#ifdef HAVE_LIBLDAP
|
2011-03-03 10:19:55 +01:00
|
|
|
/* Some functions like ldap_init, ldap_simple_bind_s, ldap_unbind are
|
|
|
|
deprecated but still available. We will drop support for 'ldapserver'
|
|
|
|
(in favour of 'ldap_uri' and update to using the new functions instead
|
|
|
|
soon.
|
|
|
|
*/
|
|
|
|
#define LDAP_DEPRECATED 1
|
|
|
|
|
2009-02-11 17:35:29 +01:00
|
|
|
#include <ldap.h>
|
2009-02-11 17:50:04 +01:00
|
|
|
#define PORT_NUMBER LDAP_PORT
|
2009-02-11 17:35:29 +01:00
|
|
|
#endif
|
|
|
|
|
2008-01-11 13:41:21 +01:00
|
|
|
#ifndef PAM_EXTERN
|
|
|
|
#ifdef PAM_STATIC
|
|
|
|
#define PAM_EXTERN static
|
|
|
|
#else
|
|
|
|
#define PAM_EXTERN extern
|
|
|
|
#endif
|
|
|
|
#endif
|
|
|
|
|
Use unsigned, fix printf conversion spec warnings
Some of the printf conversion specifications were wrong when used on
size_t, causing
> pam_yubico.c:957:57: warning: format specifies type 'int' but the argument has type 'size_t' (aka 'unsigned long') [-Wformat]
> DBG (("OTP too short to be considered : %i < %i", password_len, (cfg->token_id_length + TOKEN_OTP_LEN)));
> ~~ ^~~~~~~~~~~~
> %zu
> pam_yubico.c:132:36: note: expanded from macro 'DBG'
> #define DBG(x) if (cfg->debug) { D(x); }
> ^
> ./util.h:47:12: note: expanded from macro 'D'
> printf x; \
> ^
and
> pam_yubico.c:967:14: warning: format specifies type 'int' but the argument has type 'size_t' (aka 'unsigned long') [-Wformat]
> skip_bytes, password_len, cfg->token_id_length, TOKEN_OTP_LEN));
> ^~~~~~~~~~~~
> pam_yubico.c:132:36: note: expanded from macro 'DBG'
> #define DBG(x) if (cfg->debug) { D(x); }
> ^
> ./util.h:47:12: note: expanded from macro 'D'
> printf x; \
> ^
Fix these by using the appropriate %zu conversions for size_t. While
looking through the code, there are a couple more places where format
string specifiers could be improved, e.g. using %zu instead of casting
the result of sizeof(x) or strlen(x) to unsigned long.
In addition, convert TOKEN_OTP_LEN, MAX_TOKEN_ID_LEN and
DEFAULT_TOKEN_ID_LEN to unsigned numbers, because negative values would
not make any sense for those.
2015-03-28 13:10:35 +01:00
|
|
|
#define TOKEN_OTP_LEN 32u
|
|
|
|
#define MAX_TOKEN_ID_LEN 16u
|
|
|
|
#define DEFAULT_TOKEN_ID_LEN 12u
|
2008-09-01 15:13:07 +02:00
|
|
|
|
2011-04-15 15:24:50 +02:00
|
|
|
enum key_mode {
|
|
|
|
CHRESP,
|
|
|
|
CLIENT
|
|
|
|
};
|
|
|
|
|
|
|
|
struct cfg
|
|
|
|
{
|
2015-03-04 08:59:55 +01:00
|
|
|
unsigned int client_id;
|
2014-07-29 09:25:39 +02:00
|
|
|
const char *client_key;
|
2011-04-15 15:24:50 +02:00
|
|
|
int debug;
|
|
|
|
int alwaysok;
|
|
|
|
int verbose_otp;
|
|
|
|
int try_first_pass;
|
|
|
|
int use_first_pass;
|
2014-07-29 09:25:39 +02:00
|
|
|
const char *auth_file;
|
|
|
|
const char *capath;
|
|
|
|
const char *url;
|
|
|
|
const char *urllist;
|
|
|
|
const char *ldapserver;
|
|
|
|
const char *ldap_uri;
|
2014-10-28 16:27:28 +01:00
|
|
|
const char *ldap_bind_user;
|
|
|
|
const char *ldap_bind_password;
|
|
|
|
const char *ldap_filter;
|
2014-11-20 22:40:55 +01:00
|
|
|
const char *ldap_cacertfile;
|
2014-07-29 09:25:39 +02:00
|
|
|
const char *ldapdn;
|
|
|
|
const char *user_attr;
|
|
|
|
const char *yubi_attr;
|
|
|
|
const char *yubi_attr_prefix;
|
2015-03-04 14:52:16 +01:00
|
|
|
unsigned int token_id_length;
|
2011-04-15 15:24:50 +02:00
|
|
|
enum key_mode mode;
|
2014-07-29 09:25:39 +02:00
|
|
|
const char *chalresp_path;
|
2011-04-15 15:24:50 +02:00
|
|
|
};
|
|
|
|
|
|
|
|
#ifdef DBG
|
|
|
|
#undef DBG
|
|
|
|
#endif
|
|
|
|
#define DBG(x) if (cfg->debug) { D(x); }
|
|
|
|
|
2008-09-01 15:13:07 +02:00
|
|
|
/*
|
2009-03-24 16:21:09 +01:00
|
|
|
* Authorize authenticated OTP_ID for login as USERNAME using
|
2013-01-26 16:59:23 +01:00
|
|
|
* AUTHFILE. Return -2 if the user is unknown, -1 if the OTP_ID does not match, 0 on internal failures, otherwise success.
|
2008-09-01 15:13:07 +02:00
|
|
|
*/
|
|
|
|
static int
|
2011-04-15 15:24:50 +02:00
|
|
|
authorize_user_token (struct cfg *cfg,
|
2009-03-24 16:11:54 +01:00
|
|
|
const char *username,
|
2011-11-23 13:27:37 +01:00
|
|
|
const char *otp_id,
|
|
|
|
pam_handle_t *pamh)
|
2008-09-01 15:13:07 +02:00
|
|
|
{
|
2009-03-24 16:21:09 +01:00
|
|
|
int retval;
|
2008-09-01 15:13:07 +02:00
|
|
|
|
2011-04-15 15:24:50 +02:00
|
|
|
if (cfg->auth_file)
|
2008-09-01 15:14:33 +02:00
|
|
|
{
|
2008-09-01 15:13:07 +02:00
|
|
|
/* Administrator had configured the file and specified is name
|
2008-09-01 15:14:33 +02:00
|
|
|
as an argument for this module.
|
|
|
|
*/
|
2011-12-13 16:56:04 +01:00
|
|
|
DBG (("Using system-wide auth_file %s", cfg->auth_file));
|
2014-08-27 10:45:42 +02:00
|
|
|
retval = check_user_token (cfg->auth_file, username, otp_id, cfg->debug);
|
2008-09-01 15:14:33 +02:00
|
|
|
}
|
2008-09-01 15:13:07 +02:00
|
|
|
else
|
2008-09-01 15:14:33 +02:00
|
|
|
{
|
2011-03-17 14:36:19 +01:00
|
|
|
char *userfile = NULL;
|
2011-12-13 16:56:04 +01:00
|
|
|
struct passwd *p;
|
2013-09-20 10:31:25 +02:00
|
|
|
PAM_MODUTIL_DEF_PRIVS(privs);
|
2011-12-13 16:56:04 +01:00
|
|
|
|
|
|
|
p = getpwnam (username);
|
|
|
|
if (p == NULL) {
|
|
|
|
DBG (("getpwnam: %s", strerror(errno)));
|
|
|
|
return 0;
|
|
|
|
}
|
2011-03-17 14:36:19 +01:00
|
|
|
|
2008-09-01 15:13:07 +02:00
|
|
|
/* Getting file from user home directory
|
2008-09-01 15:14:33 +02:00
|
|
|
..... i.e. ~/.yubico/authorized_yubikeys
|
|
|
|
*/
|
2011-12-13 16:56:04 +01:00
|
|
|
if (! get_user_cfgfile_path (NULL, "authorized_yubikeys", username, &userfile)) {
|
|
|
|
D (("Failed figuring out per-user cfgfile"));
|
2011-03-17 14:36:19 +01:00
|
|
|
return 0;
|
2011-12-13 16:56:04 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
DBG (("Dropping privileges"));
|
2013-09-20 10:31:25 +02:00
|
|
|
if(pam_modutil_drop_priv(pamh, &privs, p)) {
|
|
|
|
DBG (("could not drop privileges"));
|
2013-04-20 13:50:51 +02:00
|
|
|
retval = 0;
|
|
|
|
goto free_out;
|
2011-12-13 16:56:04 +01:00
|
|
|
}
|
2009-03-24 16:21:09 +01:00
|
|
|
|
2014-08-27 10:45:42 +02:00
|
|
|
retval = check_user_token (userfile, username, otp_id, cfg->debug);
|
2009-03-24 16:21:09 +01:00
|
|
|
|
2013-09-20 10:31:25 +02:00
|
|
|
if(pam_modutil_regain_priv(pamh, &privs)) {
|
|
|
|
DBG (("could not restore privileges"));
|
|
|
|
retval = 0;
|
|
|
|
goto free_out;
|
|
|
|
}
|
2008-09-01 15:13:07 +02:00
|
|
|
|
2013-04-20 13:50:51 +02:00
|
|
|
free_out:
|
2011-12-13 16:56:04 +01:00
|
|
|
free (userfile);
|
2011-11-23 10:15:29 +01:00
|
|
|
}
|
|
|
|
|
2008-09-01 15:13:07 +02:00
|
|
|
return retval;
|
|
|
|
}
|
|
|
|
|
2009-02-11 17:35:29 +01:00
|
|
|
/*
|
|
|
|
* This function will look in ldap id the token correspond to the
|
|
|
|
* requested user. It will returns 0 for failure and 1 for success.
|
|
|
|
*
|
2014-11-20 22:40:55 +01:00
|
|
|
* ldaps is only supported for ldap_uri based connections.
|
|
|
|
* ldap_cacertfile usually needs to be set for this to work.
|
|
|
|
*
|
|
|
|
* ldap serve can be on a remote host.
|
2009-02-11 17:35:29 +01:00
|
|
|
*
|
|
|
|
* You need the following parameters in you pam config:
|
2010-04-14 10:29:39 +02:00
|
|
|
* ldapserver= OR ldap_uri=
|
2009-02-11 17:35:29 +01:00
|
|
|
* ldapdn=
|
|
|
|
* user_attr=
|
|
|
|
* yubi_attr=
|
|
|
|
*
|
2014-11-20 22:40:55 +01:00
|
|
|
* If using ldap_uri, you can specify multiple failover hosts
|
|
|
|
* eg.
|
|
|
|
* ldap_uri=ldaps://host1.fqdn.example.com,ldaps://host2.fqdn.example.com
|
2009-02-11 17:35:29 +01:00
|
|
|
*/
|
2009-02-11 17:50:04 +01:00
|
|
|
static int
|
2011-04-15 15:24:50 +02:00
|
|
|
authorize_user_token_ldap (struct cfg *cfg,
|
2010-04-14 10:29:39 +02:00
|
|
|
const char *user,
|
2011-04-15 15:24:50 +02:00
|
|
|
const char *token_id)
|
2009-02-11 17:35:29 +01:00
|
|
|
{
|
|
|
|
int retval = 0;
|
|
|
|
#ifdef HAVE_LIBLDAP
|
2015-03-04 09:57:22 +01:00
|
|
|
/* LDAPv2 is historical -- RFC3494. */
|
|
|
|
int protocol = LDAP_VERSION3;
|
2012-02-01 09:29:05 +01:00
|
|
|
int yubi_attr_prefix_len = 0;
|
2011-03-03 12:48:43 +01:00
|
|
|
LDAP *ld = NULL;
|
|
|
|
LDAPMessage *result = NULL, *e;
|
2009-02-11 17:50:04 +01:00
|
|
|
BerElement *ber;
|
|
|
|
char *a;
|
2011-03-03 14:14:54 +01:00
|
|
|
char *attrs[2] = {NULL, NULL};
|
2010-04-13 21:58:35 +02:00
|
|
|
|
2009-08-11 11:29:44 +02:00
|
|
|
struct berval **vals;
|
2009-02-11 17:50:04 +01:00
|
|
|
int i, rc;
|
2009-08-11 11:29:44 +02:00
|
|
|
|
2014-10-29 13:25:29 +01:00
|
|
|
char *filter = NULL;
|
2011-11-22 11:17:29 +01:00
|
|
|
char *find = NULL;
|
2014-10-28 16:27:28 +01:00
|
|
|
int scope = LDAP_SCOPE_BASE;
|
2013-09-18 10:22:00 +02:00
|
|
|
#endif
|
|
|
|
DBG(("called"));
|
|
|
|
#ifdef HAVE_LIBLDAP
|
2011-04-15 15:24:50 +02:00
|
|
|
if (cfg->yubi_attr == NULL) {
|
2011-04-15 14:17:23 +02:00
|
|
|
DBG (("Trying to look up user to YubiKey mapping in LDAP, but yubi_attr not set!"));
|
2011-03-03 10:58:34 +01:00
|
|
|
return 0;
|
|
|
|
}
|
2015-03-04 11:11:32 +01:00
|
|
|
if (cfg->user_attr && cfg->ldapdn == NULL) {
|
|
|
|
DBG (("Trying to look up user to YubiKey mapping in LDAP, user_attr set but ldapdn not set!"));
|
2011-03-03 10:58:34 +01:00
|
|
|
return 0;
|
|
|
|
}
|
2009-08-11 11:29:44 +02:00
|
|
|
|
2009-02-11 17:50:04 +01:00
|
|
|
/* Get a handle to an LDAP connection. */
|
2011-04-15 15:24:50 +02:00
|
|
|
if (cfg->ldap_uri)
|
2009-02-11 17:50:04 +01:00
|
|
|
{
|
2011-04-15 15:24:50 +02:00
|
|
|
rc = ldap_initialize (&ld, cfg->ldap_uri);
|
2010-04-14 10:29:39 +02:00
|
|
|
if (rc != LDAP_SUCCESS)
|
|
|
|
{
|
2014-11-20 22:40:55 +01:00
|
|
|
DBG (("ldap_initialize: %s", ldap_err2string (rc)));
|
2011-03-03 12:48:43 +01:00
|
|
|
retval = 0;
|
|
|
|
goto done;
|
2010-04-14 10:29:39 +02:00
|
|
|
}
|
|
|
|
}
|
|
|
|
else
|
|
|
|
{
|
2011-04-15 15:24:50 +02:00
|
|
|
if ((ld = ldap_init (cfg->ldapserver, PORT_NUMBER)) == NULL)
|
2010-07-13 18:53:24 +02:00
|
|
|
{
|
2011-04-15 14:17:23 +02:00
|
|
|
DBG (("ldap_init"));
|
2011-03-03 12:48:43 +01:00
|
|
|
retval = 0;
|
|
|
|
goto done;
|
2010-07-13 18:53:24 +02:00
|
|
|
}
|
2009-02-11 17:35:29 +01:00
|
|
|
}
|
|
|
|
|
2014-10-29 13:25:29 +01:00
|
|
|
ldap_set_option(ld, LDAP_OPT_REFERRALS, LDAP_OPT_OFF);
|
2011-03-03 10:31:30 +01:00
|
|
|
ldap_set_option (ld, LDAP_OPT_PROTOCOL_VERSION, &protocol);
|
|
|
|
|
2014-11-20 22:40:55 +01:00
|
|
|
if (cfg->ldap_uri && cfg->ldap_cacertfile) {
|
|
|
|
/* Set CA CERTFILE. This makes ldaps work when using ldap_uri */
|
|
|
|
ldap_set_option (0, LDAP_OPT_X_TLS_CACERTFILE, cfg->ldap_cacertfile);
|
|
|
|
}
|
2009-02-11 17:50:04 +01:00
|
|
|
/* Bind anonymously to the LDAP server. */
|
2014-10-28 16:27:28 +01:00
|
|
|
if (cfg->ldap_bind_user && cfg->ldap_bind_password) {
|
2014-11-20 22:40:55 +01:00
|
|
|
DBG (("try bind with: %s:[%s]", cfg->ldap_bind_user, cfg->ldap_bind_password));
|
2014-10-28 16:27:28 +01:00
|
|
|
rc = ldap_simple_bind_s (ld, cfg->ldap_bind_user, cfg->ldap_bind_password);
|
|
|
|
} else {
|
|
|
|
DBG (("try bind anonymous"));
|
|
|
|
rc = ldap_simple_bind_s (ld, NULL, NULL);
|
|
|
|
}
|
2009-02-11 17:50:04 +01:00
|
|
|
if (rc != LDAP_SUCCESS)
|
|
|
|
{
|
2011-04-15 14:17:23 +02:00
|
|
|
DBG (("ldap_simple_bind_s: %s", ldap_err2string (rc)));
|
2011-03-03 12:48:43 +01:00
|
|
|
retval = 0;
|
|
|
|
goto done;
|
2009-02-11 17:50:04 +01:00
|
|
|
}
|
2009-02-11 17:35:29 +01:00
|
|
|
|
2011-03-03 14:14:54 +01:00
|
|
|
/* Allocation of memory for search strings depending on input size */
|
2015-03-04 11:11:32 +01:00
|
|
|
if (cfg->user_attr && cfg->yubi_attr && cfg->ldapdn) {
|
2014-10-28 16:27:28 +01:00
|
|
|
i = (strlen(cfg->user_attr) + strlen(cfg->ldapdn) + strlen(user) + 3) * sizeof(char);
|
|
|
|
if ((find = malloc(i)) == NULL) {
|
|
|
|
DBG (("Failed allocating %i bytes", i));
|
|
|
|
retval = 0;
|
|
|
|
goto done;
|
|
|
|
}
|
|
|
|
sprintf (find, "%s=%s,%s", cfg->user_attr, user, cfg->ldapdn);
|
|
|
|
filter = NULL;
|
2015-03-04 11:11:32 +01:00
|
|
|
} else if (cfg->ldapdn) {
|
2015-03-04 08:46:52 +01:00
|
|
|
find = strdup(cfg->ldapdn); /* allow free later */
|
2014-11-20 22:40:55 +01:00
|
|
|
}
|
2014-10-28 16:27:28 +01:00
|
|
|
if (cfg->ldap_filter) {
|
|
|
|
filter = filter_printf(cfg->ldap_filter, user);
|
|
|
|
scope = LDAP_SCOPE_SUBTREE;
|
2011-11-22 11:08:28 +01:00
|
|
|
}
|
2011-04-15 15:24:50 +02:00
|
|
|
attrs[0] = (char *) cfg->yubi_attr;
|
2009-02-11 17:50:04 +01:00
|
|
|
|
2014-11-20 22:40:55 +01:00
|
|
|
DBG(("LDAP : look up object base='%s' filter='%s', ask for attribute '%s'", find,
|
2014-10-28 16:27:28 +01:00
|
|
|
filter ? filter:"(null)", cfg->yubi_attr));
|
2011-03-03 14:14:54 +01:00
|
|
|
|
|
|
|
/* Search for the entry. */
|
2014-10-28 16:27:28 +01:00
|
|
|
if ((rc = ldap_search_ext_s (ld, find, scope,
|
|
|
|
filter, attrs, 0, NULL, NULL, LDAP_NO_LIMIT,
|
2009-02-11 17:50:04 +01:00
|
|
|
LDAP_NO_LIMIT, &result)) != LDAP_SUCCESS)
|
|
|
|
{
|
2011-04-15 14:17:23 +02:00
|
|
|
DBG (("ldap_search_ext_s: %s", ldap_err2string (rc)));
|
2009-02-11 17:50:04 +01:00
|
|
|
|
2011-03-03 12:48:43 +01:00
|
|
|
retval = 0;
|
|
|
|
goto done;
|
2009-02-11 17:50:04 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
e = ldap_first_entry (ld, result);
|
2011-03-03 14:14:54 +01:00
|
|
|
if (e == NULL)
|
2009-02-11 17:50:04 +01:00
|
|
|
{
|
2011-04-15 14:17:23 +02:00
|
|
|
DBG (("No result from LDAP search"));
|
2013-01-26 16:59:23 +01:00
|
|
|
retval = -2;
|
2011-03-03 14:14:54 +01:00
|
|
|
}
|
|
|
|
else
|
|
|
|
{
|
2013-01-26 16:59:23 +01:00
|
|
|
retval = -1;
|
2011-03-03 14:14:54 +01:00
|
|
|
/* Iterate through each returned attribute. */
|
2009-02-11 17:50:04 +01:00
|
|
|
for (a = ldap_first_attribute (ld, e, &ber);
|
|
|
|
a != NULL; a = ldap_next_attribute (ld, e, ber))
|
|
|
|
{
|
2009-08-11 11:29:44 +02:00
|
|
|
if ((vals = ldap_get_values_len (ld, e, a)) != NULL)
|
2009-02-11 17:50:04 +01:00
|
|
|
{
|
2012-02-01 09:29:05 +01:00
|
|
|
yubi_attr_prefix_len = cfg->yubi_attr_prefix ? strlen(cfg->yubi_attr_prefix) : 0;
|
2012-01-18 17:04:58 +01:00
|
|
|
|
2011-03-03 14:14:54 +01:00
|
|
|
/* Compare each value for the attribute against the token id. */
|
2009-02-11 17:50:04 +01:00
|
|
|
for (i = 0; vals[i] != NULL; i++)
|
|
|
|
{
|
2014-10-29 13:25:29 +01:00
|
|
|
DBG(("LDAP : Found %i values - checking if any of them match '%s:%s:%s'",
|
2014-11-20 22:40:55 +01:00
|
|
|
ldap_count_values_len(vals),
|
2014-10-29 13:25:29 +01:00
|
|
|
vals[i]->bv_val,
|
|
|
|
cfg->yubi_attr_prefix ? cfg->yubi_attr_prefix : "", token_id));
|
|
|
|
|
2012-01-24 17:42:49 +01:00
|
|
|
/* Only values containing this prefix are considered. */
|
2012-02-01 09:29:05 +01:00
|
|
|
if ((!cfg->yubi_attr_prefix || !strncmp (cfg->yubi_attr_prefix, vals[i]->bv_val, yubi_attr_prefix_len)))
|
2011-03-03 14:14:54 +01:00
|
|
|
{
|
2012-02-01 09:29:05 +01:00
|
|
|
if(!strncmp (token_id, vals[i]->bv_val + yubi_attr_prefix_len, strlen (token_id)))
|
2012-01-18 17:04:58 +01:00
|
|
|
{
|
2012-02-01 09:29:05 +01:00
|
|
|
DBG (("Token Found :: %s", vals[i]->bv_val));
|
2012-01-18 17:04:58 +01:00
|
|
|
retval = 1;
|
|
|
|
}
|
2011-03-03 14:14:54 +01:00
|
|
|
}
|
2009-02-11 17:50:04 +01:00
|
|
|
}
|
2011-03-03 10:11:16 +01:00
|
|
|
ldap_value_free_len (vals);
|
2009-02-11 17:50:04 +01:00
|
|
|
}
|
|
|
|
ldap_memfree (a);
|
|
|
|
}
|
|
|
|
if (ber != NULL)
|
|
|
|
ber_free (ber, 0);
|
|
|
|
}
|
|
|
|
|
2011-03-03 12:48:43 +01:00
|
|
|
done:
|
|
|
|
if (result != NULL)
|
|
|
|
ldap_msgfree (result);
|
|
|
|
if (ld != NULL)
|
|
|
|
ldap_unbind (ld);
|
2009-08-11 11:29:44 +02:00
|
|
|
|
|
|
|
/* free memory allocated for search strings */
|
2011-03-03 12:48:43 +01:00
|
|
|
if (find != NULL)
|
|
|
|
free(find);
|
2014-10-28 16:27:28 +01:00
|
|
|
if (filter != NULL)
|
|
|
|
free(filter);
|
2009-08-11 11:29:44 +02:00
|
|
|
|
2009-02-11 17:35:29 +01:00
|
|
|
#else
|
2011-04-15 14:17:23 +02:00
|
|
|
DBG (("Trying to use LDAP, but this function is not compiled in pam_yubico!!"));
|
|
|
|
DBG (("Install libldap-dev and then recompile pam_yubico."));
|
2009-02-11 17:35:29 +01:00
|
|
|
#endif
|
|
|
|
return retval;
|
|
|
|
}
|
|
|
|
|
2011-11-23 13:26:02 +01:00
|
|
|
#if HAVE_CR
|
2011-03-14 10:17:12 +01:00
|
|
|
static int
|
2013-09-18 10:22:00 +02:00
|
|
|
display_error(pam_handle_t *pamh, const char *message) {
|
2011-03-18 23:05:26 +01:00
|
|
|
struct pam_conv *conv;
|
2013-09-18 10:22:00 +02:00
|
|
|
const struct pam_message *pmsg[1];
|
|
|
|
struct pam_message msg[1];
|
2011-03-18 23:05:26 +01:00
|
|
|
struct pam_response *resp = NULL;
|
|
|
|
int retval;
|
|
|
|
|
|
|
|
retval = pam_get_item (pamh, PAM_CONV, (const void **) &conv);
|
|
|
|
if (retval != PAM_SUCCESS) {
|
|
|
|
D(("get conv returned error: %s", pam_strerror (pamh, retval)));
|
|
|
|
return retval;
|
|
|
|
}
|
|
|
|
|
|
|
|
pmsg[0] = &msg[0];
|
2015-03-28 12:57:30 +01:00
|
|
|
msg[0].msg = (char *) message; /* on some systems, pam_message.msg isn't const */
|
2011-03-18 23:05:26 +01:00
|
|
|
msg[0].msg_style = PAM_ERROR_MSG;
|
2013-09-18 10:22:00 +02:00
|
|
|
retval = conv->conv(1, pmsg, &resp, conv->appdata_ptr);
|
2011-03-18 23:05:26 +01:00
|
|
|
|
|
|
|
if (retval != PAM_SUCCESS) {
|
|
|
|
D(("conv returned error: %s", pam_strerror (pamh, retval)));
|
|
|
|
return retval;
|
|
|
|
}
|
|
|
|
|
2015-01-21 09:57:02 +01:00
|
|
|
if (resp)
|
|
|
|
{
|
2015-03-04 10:20:40 +01:00
|
|
|
D(("conv returned: '%s'", resp->resp));
|
2015-01-21 09:57:02 +01:00
|
|
|
if (resp->resp)
|
|
|
|
free (resp->resp);
|
|
|
|
free (resp);
|
|
|
|
}
|
2011-03-18 23:05:26 +01:00
|
|
|
return retval;
|
|
|
|
}
|
2011-11-23 13:26:02 +01:00
|
|
|
#endif /* HAVE_CR */
|
2011-03-18 23:05:26 +01:00
|
|
|
|
2011-11-23 13:26:02 +01:00
|
|
|
#if HAVE_CR
|
2011-03-18 23:05:26 +01:00
|
|
|
static int
|
|
|
|
do_challenge_response(pam_handle_t *pamh, struct cfg *cfg, const char *username)
|
2011-03-14 10:17:12 +01:00
|
|
|
{
|
2011-03-16 22:44:25 +01:00
|
|
|
char *userfile = NULL, *tmpfile = NULL;
|
2011-03-12 15:49:50 +01:00
|
|
|
FILE *f = NULL;
|
2011-12-06 11:56:52 +01:00
|
|
|
char buf[CR_RESPONSE_SIZE + 16], response_hex[CR_RESPONSE_SIZE * 2 + 1];
|
2011-11-23 13:55:44 +01:00
|
|
|
int ret, fd;
|
2011-03-12 15:49:50 +01:00
|
|
|
|
|
|
|
unsigned int response_len = 0;
|
|
|
|
YK_KEY *yk = NULL;
|
2011-03-17 16:10:42 +01:00
|
|
|
CR_STATE state;
|
|
|
|
|
2013-09-18 10:22:00 +02:00
|
|
|
const char *errstr = NULL;
|
2011-03-12 15:49:50 +01:00
|
|
|
|
2011-11-23 10:15:29 +01:00
|
|
|
struct passwd *p;
|
2011-11-23 13:55:44 +01:00
|
|
|
struct stat st;
|
2011-11-23 10:15:29 +01:00
|
|
|
|
2013-09-23 08:31:17 +02:00
|
|
|
/* we must declare two sepparate privs structures as they can't be reused */
|
2013-09-20 10:31:25 +02:00
|
|
|
PAM_MODUTIL_DEF_PRIVS(privs);
|
2013-09-23 08:31:17 +02:00
|
|
|
PAM_MODUTIL_DEF_PRIVS(privs2);
|
2013-09-20 10:31:25 +02:00
|
|
|
|
2011-03-12 15:49:50 +01:00
|
|
|
ret = PAM_AUTH_ERR;
|
|
|
|
|
2011-03-17 17:55:04 +01:00
|
|
|
if (! init_yubikey(&yk)) {
|
2013-05-13 15:47:59 +02:00
|
|
|
DBG(("Failed initializing YubiKey"));
|
2011-03-17 17:55:04 +01:00
|
|
|
goto out;
|
|
|
|
}
|
|
|
|
|
|
|
|
if (! check_firmware_version(yk, false, true)) {
|
2013-05-13 15:47:59 +02:00
|
|
|
DBG(("YubiKey does not support Challenge-Response (version 2.2 required)"));
|
2011-03-17 17:55:04 +01:00
|
|
|
goto out;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
if (! get_user_challenge_file (yk, cfg->chalresp_path, username, &userfile)) {
|
2013-05-13 15:47:59 +02:00
|
|
|
DBG(("Failed getting user challenge file for user %s", username));
|
2011-03-12 15:49:50 +01:00
|
|
|
goto out;
|
2011-03-14 10:17:12 +01:00
|
|
|
}
|
2011-03-12 15:49:50 +01:00
|
|
|
|
2011-04-15 16:28:00 +02:00
|
|
|
DBG(("Loading challenge from file %s", userfile));
|
2011-03-14 10:17:12 +01:00
|
|
|
|
2011-11-23 10:15:29 +01:00
|
|
|
p = getpwnam (username);
|
|
|
|
if (p == NULL) {
|
|
|
|
DBG (("getpwnam: %s", strerror(errno)));
|
|
|
|
goto out;
|
|
|
|
}
|
|
|
|
|
|
|
|
/* Drop privileges before opening user file. */
|
2013-09-20 10:31:25 +02:00
|
|
|
if (pam_modutil_drop_priv(pamh, &privs, p)) {
|
|
|
|
DBG (("could not drop privileges"));
|
2011-11-23 10:15:29 +01:00
|
|
|
goto out;
|
|
|
|
}
|
|
|
|
|
2011-11-23 13:55:44 +01:00
|
|
|
fd = open(userfile, O_RDONLY, 0);
|
|
|
|
if (fd < 0) {
|
|
|
|
DBG (("Cannot open file: %s (%s)", userfile, strerror(errno)));
|
2013-04-20 13:50:51 +02:00
|
|
|
goto restpriv_out;
|
2011-11-23 13:55:44 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
if (fstat(fd, &st) < 0) {
|
|
|
|
DBG (("Cannot stat file: %s (%s)", userfile, strerror(errno)));
|
|
|
|
close(fd);
|
2013-04-20 13:50:51 +02:00
|
|
|
goto restpriv_out;
|
2011-11-23 13:55:44 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
if (!S_ISREG(st.st_mode)) {
|
|
|
|
DBG (("%s is not a regular file", userfile));
|
|
|
|
close(fd);
|
2013-04-20 13:50:51 +02:00
|
|
|
goto restpriv_out;
|
2011-11-23 13:55:44 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
f = fdopen(fd, "r");
|
|
|
|
if (f == NULL) {
|
|
|
|
DBG (("fdopen: %s", strerror(errno)));
|
|
|
|
close(fd);
|
2013-04-20 13:50:51 +02:00
|
|
|
goto restpriv_out;
|
2011-11-23 13:55:44 +01:00
|
|
|
}
|
2011-03-12 15:49:50 +01:00
|
|
|
|
2012-02-13 14:24:31 +01:00
|
|
|
if (! load_chalresp_state(f, &state, cfg->debug))
|
2013-04-20 13:50:51 +02:00
|
|
|
goto restpriv_out;
|
2011-03-12 15:49:50 +01:00
|
|
|
|
2011-03-18 23:01:46 +01:00
|
|
|
if (fclose(f) < 0) {
|
|
|
|
f = NULL;
|
2013-04-20 13:50:51 +02:00
|
|
|
goto restpriv_out;
|
2011-11-23 10:15:29 +01:00
|
|
|
}
|
2012-01-27 12:33:53 +01:00
|
|
|
f = NULL;
|
2011-11-23 10:15:29 +01:00
|
|
|
|
2013-09-20 10:31:25 +02:00
|
|
|
if (pam_modutil_regain_priv(pamh, &privs)) {
|
2011-11-23 10:15:29 +01:00
|
|
|
DBG (("could not restore privileges"));
|
|
|
|
goto out;
|
2011-03-18 23:01:46 +01:00
|
|
|
}
|
|
|
|
|
2011-03-17 16:10:42 +01:00
|
|
|
if (! challenge_response(yk, state.slot, state.challenge, state.challenge_len,
|
2013-09-18 09:57:52 +02:00
|
|
|
true, true, false,
|
2011-03-17 16:10:42 +01:00
|
|
|
buf, sizeof(buf), &response_len)) {
|
2013-05-13 15:47:59 +02:00
|
|
|
DBG(("Challenge-response FAILED"));
|
2011-03-12 15:49:50 +01:00
|
|
|
goto out;
|
2011-03-17 15:04:29 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Check YubiKey response against the expected response
|
|
|
|
*/
|
|
|
|
|
2011-12-06 11:56:52 +01:00
|
|
|
yubikey_hex_encode(response_hex, buf, response_len);
|
2015-03-04 08:47:11 +01:00
|
|
|
if(state.salt_len > 0) { /* the expected response has gone through pbkdf2 */
|
2013-09-18 09:58:47 +02:00
|
|
|
YK_PRF_METHOD prf_method = {20, yk_hmac_sha1};
|
2013-09-18 10:22:00 +02:00
|
|
|
yk_pbkdf2(response_hex, (unsigned char*)state.salt, state.salt_len, state.iterations,
|
|
|
|
(unsigned char*)buf, response_len, &prf_method);
|
2013-09-18 09:58:47 +02:00
|
|
|
}
|
2011-03-17 15:04:29 +01:00
|
|
|
|
2013-09-18 09:58:47 +02:00
|
|
|
if (memcmp(buf, state.response, state.response_len) == 0) {
|
2011-03-12 15:49:50 +01:00
|
|
|
ret = PAM_SUCCESS;
|
2011-03-14 12:44:57 +01:00
|
|
|
} else {
|
2013-05-13 15:47:59 +02:00
|
|
|
DBG(("Unexpected C/R response : %s", response_hex));
|
2011-03-14 12:44:57 +01:00
|
|
|
goto out;
|
|
|
|
}
|
2011-03-12 15:49:50 +01:00
|
|
|
|
Use unsigned, fix printf conversion spec warnings
Some of the printf conversion specifications were wrong when used on
size_t, causing
> pam_yubico.c:957:57: warning: format specifies type 'int' but the argument has type 'size_t' (aka 'unsigned long') [-Wformat]
> DBG (("OTP too short to be considered : %i < %i", password_len, (cfg->token_id_length + TOKEN_OTP_LEN)));
> ~~ ^~~~~~~~~~~~
> %zu
> pam_yubico.c:132:36: note: expanded from macro 'DBG'
> #define DBG(x) if (cfg->debug) { D(x); }
> ^
> ./util.h:47:12: note: expanded from macro 'D'
> printf x; \
> ^
and
> pam_yubico.c:967:14: warning: format specifies type 'int' but the argument has type 'size_t' (aka 'unsigned long') [-Wformat]
> skip_bytes, password_len, cfg->token_id_length, TOKEN_OTP_LEN));
> ^~~~~~~~~~~~
> pam_yubico.c:132:36: note: expanded from macro 'DBG'
> #define DBG(x) if (cfg->debug) { D(x); }
> ^
> ./util.h:47:12: note: expanded from macro 'D'
> printf x; \
> ^
Fix these by using the appropriate %zu conversions for size_t. While
looking through the code, there are a couple more places where format
string specifiers could be improved, e.g. using %zu instead of casting
the result of sizeof(x) or strlen(x) to unsigned long.
In addition, convert TOKEN_OTP_LEN, MAX_TOKEN_ID_LEN and
DEFAULT_TOKEN_ID_LEN to unsigned numbers, because negative values would
not make any sense for those.
2015-03-28 13:10:35 +01:00
|
|
|
DBG(("Got the expected response, generating new challenge (%u bytes).", CR_CHALLENGE_SIZE));
|
2011-03-12 15:49:50 +01:00
|
|
|
|
2011-03-18 23:05:26 +01:00
|
|
|
errstr = "Error generating new challenge, please check syslog or contact your system administrator";
|
2011-03-17 16:10:42 +01:00
|
|
|
if (generate_random(state.challenge, sizeof(state.challenge))) {
|
2013-05-13 15:47:59 +02:00
|
|
|
DBG(("Failed generating new challenge!"));
|
2011-03-12 15:49:50 +01:00
|
|
|
goto out;
|
2011-03-14 14:31:22 +01:00
|
|
|
}
|
|
|
|
|
2011-03-18 23:05:26 +01:00
|
|
|
errstr = "Error communicating with Yubikey, please check syslog or contact your system administrator";
|
2011-03-17 16:10:42 +01:00
|
|
|
if (! challenge_response(yk, state.slot, state.challenge, CR_CHALLENGE_SIZE,
|
2013-09-18 09:57:52 +02:00
|
|
|
true, true, false,
|
2011-03-17 16:10:42 +01:00
|
|
|
buf, sizeof(buf), &response_len)) {
|
2013-05-13 15:47:59 +02:00
|
|
|
DBG(("Second challenge-response FAILED"));
|
2011-03-12 15:49:50 +01:00
|
|
|
goto out;
|
2011-03-17 15:04:29 +01:00
|
|
|
}
|
2011-03-14 15:06:36 +01:00
|
|
|
|
2012-06-08 13:20:07 +02:00
|
|
|
/* There is a bug that makes the YubiKey 2.2 send the same response for all challenges
|
|
|
|
unless HMAC_LT64 is set, check for that here */
|
2013-09-18 09:58:47 +02:00
|
|
|
if (memcmp(buf, state.response, state.response_len) == 0) {
|
2012-06-14 09:25:38 +02:00
|
|
|
errstr = "Same response for second challenge, YubiKey should be reconfigured with the option HMAC_LT64";
|
|
|
|
goto out;
|
2012-06-08 13:20:07 +02:00
|
|
|
}
|
|
|
|
|
2011-03-14 12:48:32 +01:00
|
|
|
/* the yk_* functions leave 'junk' in errno */
|
|
|
|
errno = 0;
|
|
|
|
|
2011-03-17 15:04:29 +01:00
|
|
|
/*
|
|
|
|
* Write the challenge and response we will expect the next time to the state file.
|
|
|
|
*/
|
2011-03-18 23:01:46 +01:00
|
|
|
if (response_len > sizeof(state.response)) {
|
Use unsigned, fix printf conversion spec warnings
Some of the printf conversion specifications were wrong when used on
size_t, causing
> pam_yubico.c:957:57: warning: format specifies type 'int' but the argument has type 'size_t' (aka 'unsigned long') [-Wformat]
> DBG (("OTP too short to be considered : %i < %i", password_len, (cfg->token_id_length + TOKEN_OTP_LEN)));
> ~~ ^~~~~~~~~~~~
> %zu
> pam_yubico.c:132:36: note: expanded from macro 'DBG'
> #define DBG(x) if (cfg->debug) { D(x); }
> ^
> ./util.h:47:12: note: expanded from macro 'D'
> printf x; \
> ^
and
> pam_yubico.c:967:14: warning: format specifies type 'int' but the argument has type 'size_t' (aka 'unsigned long') [-Wformat]
> skip_bytes, password_len, cfg->token_id_length, TOKEN_OTP_LEN));
> ^~~~~~~~~~~~
> pam_yubico.c:132:36: note: expanded from macro 'DBG'
> #define DBG(x) if (cfg->debug) { D(x); }
> ^
> ./util.h:47:12: note: expanded from macro 'D'
> printf x; \
> ^
Fix these by using the appropriate %zu conversions for size_t. While
looking through the code, there are a couple more places where format
string specifiers could be improved, e.g. using %zu instead of casting
the result of sizeof(x) or strlen(x) to unsigned long.
In addition, convert TOKEN_OTP_LEN, MAX_TOKEN_ID_LEN and
DEFAULT_TOKEN_ID_LEN to unsigned numbers, because negative values would
not make any sense for those.
2015-03-28 13:10:35 +01:00
|
|
|
DBG(("Got too long response ??? (%u/%zu)", response_len, sizeof(state.response)));
|
2011-03-16 22:44:25 +01:00
|
|
|
goto out;
|
|
|
|
}
|
2011-03-18 23:01:46 +01:00
|
|
|
memcpy (state.response, buf, response_len);
|
|
|
|
state.response_len = response_len;
|
2011-03-16 22:44:25 +01:00
|
|
|
|
2013-09-23 08:31:17 +02:00
|
|
|
/* point to the fresh privs structure.. */
|
|
|
|
privs = privs2;
|
2011-11-23 13:56:01 +01:00
|
|
|
/* Drop privileges before creating new challenge file. */
|
2013-09-20 10:31:25 +02:00
|
|
|
if (pam_modutil_drop_priv(pamh, &privs, p)) {
|
|
|
|
DBG (("could not drop privileges"));
|
2011-11-23 13:56:01 +01:00
|
|
|
goto out;
|
|
|
|
}
|
|
|
|
|
2011-03-18 23:01:46 +01:00
|
|
|
/* Write out the new file */
|
2011-03-16 22:44:25 +01:00
|
|
|
tmpfile = malloc(strlen(userfile) + 1 + 4);
|
|
|
|
if (! tmpfile)
|
2013-04-20 13:50:51 +02:00
|
|
|
goto restpriv_out;
|
2011-03-16 22:44:25 +01:00
|
|
|
strcpy(tmpfile, userfile);
|
|
|
|
strcat(tmpfile, ".tmp");
|
|
|
|
|
2012-06-08 10:45:59 +02:00
|
|
|
fd = open(tmpfile, O_WRONLY | O_CREAT | O_TRUNC, S_IRUSR | S_IWUSR);
|
|
|
|
if (fd < 0) {
|
|
|
|
DBG (("Cannot open file: %s (%s)", tmpfile, strerror(errno)));
|
2013-04-20 13:50:51 +02:00
|
|
|
goto restpriv_out;
|
2012-06-08 10:45:59 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
f = fdopen(fd, "w");
|
|
|
|
if (! f) {
|
|
|
|
close(fd);
|
2013-04-20 13:50:51 +02:00
|
|
|
goto restpriv_out;
|
2012-06-08 10:45:59 +02:00
|
|
|
}
|
2011-03-16 22:44:25 +01:00
|
|
|
|
2011-03-18 23:05:26 +01:00
|
|
|
errstr = "Error updating Yubikey challenge, please check syslog or contact your system administrator";
|
2011-03-17 16:10:42 +01:00
|
|
|
if (! write_chalresp_state (f, &state))
|
2011-03-12 15:49:50 +01:00
|
|
|
goto out;
|
2011-03-16 22:44:25 +01:00
|
|
|
if (fclose(f) < 0) {
|
|
|
|
f = NULL;
|
2013-04-20 13:50:51 +02:00
|
|
|
goto restpriv_out;
|
2011-03-16 22:44:25 +01:00
|
|
|
}
|
|
|
|
f = NULL;
|
|
|
|
if (rename(tmpfile, userfile) < 0) {
|
2013-04-20 13:50:51 +02:00
|
|
|
goto restpriv_out;
|
2011-03-16 22:44:25 +01:00
|
|
|
}
|
2011-03-12 15:49:50 +01:00
|
|
|
|
2013-09-20 10:31:25 +02:00
|
|
|
if (pam_modutil_regain_priv(pamh, &privs)) {
|
2011-11-23 13:56:01 +01:00
|
|
|
DBG (("could not restore privileges"));
|
|
|
|
goto out;
|
|
|
|
}
|
|
|
|
|
2011-04-15 16:28:00 +02:00
|
|
|
DBG(("Challenge-response success!"));
|
2011-03-18 23:05:26 +01:00
|
|
|
errstr = NULL;
|
2012-02-10 15:13:42 +01:00
|
|
|
errno = 0;
|
2013-04-20 13:50:51 +02:00
|
|
|
goto out;
|
|
|
|
|
|
|
|
restpriv_out:
|
2013-09-20 10:31:25 +02:00
|
|
|
if (pam_modutil_regain_priv(pamh, &privs)) {
|
2013-04-20 13:50:51 +02:00
|
|
|
DBG (("could not restore privileges"));
|
|
|
|
}
|
2011-03-14 12:48:32 +01:00
|
|
|
|
2011-03-12 15:49:50 +01:00
|
|
|
out:
|
|
|
|
if (yk_errno) {
|
|
|
|
if (yk_errno == YK_EUSBERR) {
|
|
|
|
syslog(LOG_ERR, "USB error: %s", yk_usb_strerror());
|
2013-05-13 15:47:59 +02:00
|
|
|
DBG(("USB error: %s", yk_usb_strerror()));
|
2011-03-12 15:49:50 +01:00
|
|
|
} else {
|
|
|
|
syslog(LOG_ERR, "Yubikey core error: %s", yk_strerror(yk_errno));
|
2013-05-13 15:47:59 +02:00
|
|
|
DBG(("Yubikey core error: %s", yk_strerror(yk_errno)));
|
2011-03-12 15:49:50 +01:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2011-03-18 23:05:26 +01:00
|
|
|
if (errstr)
|
|
|
|
display_error(pamh, errstr);
|
|
|
|
|
2011-03-12 15:49:50 +01:00
|
|
|
if (errno) {
|
|
|
|
syslog(LOG_ERR, "Challenge response failed: %s", strerror(errno));
|
2013-05-13 15:47:59 +02:00
|
|
|
DBG(("Challenge response failed: %s", strerror(errno)));
|
2011-03-12 15:49:50 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
if (yk)
|
|
|
|
yk_close_key(yk);
|
|
|
|
yk_release();
|
|
|
|
|
|
|
|
if (f)
|
|
|
|
fclose(f);
|
|
|
|
|
|
|
|
free(userfile);
|
2011-03-16 22:44:25 +01:00
|
|
|
free(tmpfile);
|
2011-03-12 15:49:50 +01:00
|
|
|
return ret;
|
|
|
|
}
|
2011-11-23 13:26:02 +01:00
|
|
|
#endif /* HAVE_CR */
|
2011-03-12 15:49:50 +01:00
|
|
|
|
2009-03-24 15:20:52 +01:00
|
|
|
static void
|
|
|
|
parse_cfg (int flags, int argc, const char **argv, struct cfg *cfg)
|
2008-01-11 13:41:21 +01:00
|
|
|
{
|
|
|
|
int i;
|
2009-03-24 15:20:52 +01:00
|
|
|
|
2011-04-15 16:30:06 +02:00
|
|
|
memset (cfg, 0, sizeof(struct cfg));
|
2015-03-04 08:59:55 +01:00
|
|
|
cfg->client_id = 0;
|
2011-02-28 17:09:08 +01:00
|
|
|
cfg->token_id_length = DEFAULT_TOKEN_ID_LEN;
|
2011-03-12 15:49:50 +01:00
|
|
|
cfg->mode = CLIENT;
|
2008-01-11 13:41:21 +01:00
|
|
|
|
|
|
|
for (i = 0; i < argc; i++)
|
|
|
|
{
|
|
|
|
if (strncmp (argv[i], "id=", 3) == 0)
|
2009-03-24 15:20:52 +01:00
|
|
|
sscanf (argv[i], "id=%d", &cfg->client_id);
|
2009-05-11 12:05:20 +02:00
|
|
|
if (strncmp (argv[i], "key=", 4) == 0)
|
2014-07-29 09:25:39 +02:00
|
|
|
cfg->client_key = argv[i] + 4;
|
2008-01-11 13:41:21 +01:00
|
|
|
if (strcmp (argv[i], "debug") == 0)
|
2009-03-24 15:20:52 +01:00
|
|
|
cfg->debug = 1;
|
2008-01-11 13:41:21 +01:00
|
|
|
if (strcmp (argv[i], "alwaysok") == 0)
|
2009-03-24 15:20:52 +01:00
|
|
|
cfg->alwaysok = 1;
|
2010-04-14 11:07:48 +02:00
|
|
|
if (strcmp (argv[i], "verbose_otp") == 0)
|
|
|
|
cfg->verbose_otp = 1;
|
2009-03-24 12:13:57 +01:00
|
|
|
if (strcmp (argv[i], "try_first_pass") == 0)
|
2009-03-24 15:20:52 +01:00
|
|
|
cfg->try_first_pass = 1;
|
2009-03-24 12:13:57 +01:00
|
|
|
if (strcmp (argv[i], "use_first_pass") == 0)
|
2009-03-24 15:20:52 +01:00
|
|
|
cfg->use_first_pass = 1;
|
2008-09-01 15:13:07 +02:00
|
|
|
if (strncmp (argv[i], "authfile=", 9) == 0)
|
2014-07-29 09:25:39 +02:00
|
|
|
cfg->auth_file = argv[i] + 9;
|
2011-02-11 16:28:46 +01:00
|
|
|
if (strncmp (argv[i], "capath=", 7) == 0)
|
2014-07-29 09:25:39 +02:00
|
|
|
cfg->capath = argv[i] + 7;
|
2008-09-15 16:25:14 +02:00
|
|
|
if (strncmp (argv[i], "url=", 4) == 0)
|
2014-07-29 09:25:39 +02:00
|
|
|
cfg->url = argv[i] + 4;
|
2014-03-26 09:40:01 +01:00
|
|
|
if (strncmp (argv[i], "urllist=", 8) == 0)
|
2014-07-29 09:25:39 +02:00
|
|
|
cfg->urllist = argv[i] + 8;
|
2010-04-14 10:29:39 +02:00
|
|
|
if (strncmp (argv[i], "ldapserver=", 11) == 0)
|
2014-07-29 09:25:39 +02:00
|
|
|
cfg->ldapserver = argv[i] + 11;
|
2009-08-11 11:29:44 +02:00
|
|
|
if (strncmp (argv[i], "ldap_uri=", 9) == 0)
|
2014-07-29 09:25:39 +02:00
|
|
|
cfg->ldap_uri = argv[i] + 9;
|
2015-03-04 08:45:03 +01:00
|
|
|
if (strncmp (argv[i], "ldap_bind_user=", 15) == 0)
|
|
|
|
cfg->ldap_bind_user = argv[i] + 15;
|
|
|
|
if (strncmp (argv[i], "ldap_bind_password=", 19) == 0)
|
|
|
|
cfg->ldap_bind_password = argv[i] + 19;
|
|
|
|
if (strncmp (argv[i], "ldap_filter=", 12) == 0)
|
|
|
|
cfg->ldap_filter = argv[i] + 12;
|
|
|
|
if (strncmp (argv[i], "ldap_cacertfile=", 16) == 0)
|
2015-03-04 09:11:09 +01:00
|
|
|
cfg->ldap_cacertfile = argv[i] + 16;
|
2009-02-11 17:35:29 +01:00
|
|
|
if (strncmp (argv[i], "ldapdn=", 7) == 0)
|
2014-07-29 09:25:39 +02:00
|
|
|
cfg->ldapdn = argv[i] + 7;
|
2009-02-11 17:35:29 +01:00
|
|
|
if (strncmp (argv[i], "user_attr=", 10) == 0)
|
2014-07-29 09:25:39 +02:00
|
|
|
cfg->user_attr = argv[i] + 10;
|
2009-02-11 17:35:29 +01:00
|
|
|
if (strncmp (argv[i], "yubi_attr=", 10) == 0)
|
2014-07-29 09:25:39 +02:00
|
|
|
cfg->yubi_attr = argv[i] + 10;
|
2012-02-01 09:29:05 +01:00
|
|
|
if (strncmp (argv[i], "yubi_attr_prefix=", 17) == 0)
|
2014-07-29 09:25:39 +02:00
|
|
|
cfg->yubi_attr_prefix = argv[i] + 17;
|
2011-03-03 15:06:15 +01:00
|
|
|
if (strncmp (argv[i], "token_id_length=", 16) == 0)
|
2015-03-04 14:52:16 +01:00
|
|
|
sscanf (argv[i], "token_id_length=%u", &cfg->token_id_length);
|
2011-03-12 15:49:50 +01:00
|
|
|
if (strcmp (argv[i], "mode=challenge-response") == 0)
|
|
|
|
cfg->mode = CHRESP;
|
|
|
|
if (strcmp (argv[i], "mode=client") == 0)
|
|
|
|
cfg->mode = CLIENT;
|
2011-03-14 10:17:12 +01:00
|
|
|
if (strncmp (argv[i], "chalresp_path=", 14) == 0)
|
2014-07-29 09:25:39 +02:00
|
|
|
cfg->chalresp_path = argv[i] + 14;
|
2008-01-11 13:41:21 +01:00
|
|
|
}
|
|
|
|
|
2009-03-24 15:20:52 +01:00
|
|
|
if (cfg->debug)
|
2008-01-11 13:41:21 +01:00
|
|
|
{
|
|
|
|
D (("called."));
|
|
|
|
D (("flags %d argc %d", flags, argc));
|
|
|
|
for (i = 0; i < argc; i++)
|
|
|
|
D (("argv[%d]=%s", i, argv[i]));
|
2015-03-04 08:59:55 +01:00
|
|
|
D (("id=%u", cfg->client_id));
|
2009-05-11 12:05:20 +02:00
|
|
|
D (("key=%s", cfg->client_key ? cfg->client_key : "(null)"));
|
2009-03-24 15:20:52 +01:00
|
|
|
D (("debug=%d", cfg->debug));
|
|
|
|
D (("alwaysok=%d", cfg->alwaysok));
|
2010-04-14 11:07:48 +02:00
|
|
|
D (("verbose_otp=%d", cfg->verbose_otp));
|
2009-03-24 15:20:52 +01:00
|
|
|
D (("try_first_pass=%d", cfg->try_first_pass));
|
|
|
|
D (("use_first_pass=%d", cfg->use_first_pass));
|
|
|
|
D (("authfile=%s", cfg->auth_file ? cfg->auth_file : "(null)"));
|
2010-04-14 10:29:39 +02:00
|
|
|
D (("ldapserver=%s", cfg->ldapserver ? cfg->ldapserver : "(null)"));
|
2009-08-11 11:29:44 +02:00
|
|
|
D (("ldap_uri=%s", cfg->ldap_uri ? cfg->ldap_uri : "(null)"));
|
2014-10-28 16:27:28 +01:00
|
|
|
D (("ldap_bind_user=%s", cfg->ldap_bind_user ? cfg->ldap_bind_user : "(null)"));
|
|
|
|
D (("ldap_bind_password=%s", cfg->ldap_bind_password ? cfg->ldap_bind_password : "(null)"));
|
|
|
|
D (("ldap_filter=%s", cfg->ldap_filter ? cfg->ldap_filter : "(null)"));
|
2014-11-20 22:40:55 +01:00
|
|
|
D (("ldap_cacertfile=%s", cfg->ldap_cacertfile ? cfg->ldap_cacertfile : "(null)"));
|
2009-03-24 15:20:52 +01:00
|
|
|
D (("ldapdn=%s", cfg->ldapdn ? cfg->ldapdn : "(null)"));
|
|
|
|
D (("user_attr=%s", cfg->user_attr ? cfg->user_attr : "(null)"));
|
|
|
|
D (("yubi_attr=%s", cfg->yubi_attr ? cfg->yubi_attr : "(null)"));
|
2012-02-01 09:29:05 +01:00
|
|
|
D (("yubi_attr_prefix=%s", cfg->yubi_attr_prefix ? cfg->yubi_attr_prefix : "(null)"));
|
2011-02-28 15:42:56 +01:00
|
|
|
D (("url=%s", cfg->url ? cfg->url : "(null)"));
|
2014-03-12 14:59:02 +01:00
|
|
|
D (("urllist=%s", cfg->urllist ? cfg->urllist : "(null)"));
|
2011-02-28 15:42:56 +01:00
|
|
|
D (("capath=%s", cfg->capath ? cfg->capath : "(null)"));
|
2011-02-28 17:09:08 +01:00
|
|
|
D (("token_id_length=%d", cfg->token_id_length));
|
2011-03-12 15:49:50 +01:00
|
|
|
D (("mode=%s", cfg->mode == CLIENT ? "client" : "chresp" ));
|
2012-02-06 11:37:42 +01:00
|
|
|
D (("chalresp_path=%s", cfg->chalresp_path ? cfg->chalresp_path : "(null)"));
|
2008-01-11 13:41:21 +01:00
|
|
|
}
|
2009-03-24 15:20:52 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
PAM_EXTERN int
|
|
|
|
pam_sm_authenticate (pam_handle_t * pamh,
|
|
|
|
int flags, int argc, const char **argv)
|
|
|
|
{
|
|
|
|
int retval, rc;
|
|
|
|
const char *user = NULL;
|
|
|
|
const char *password = NULL;
|
2011-02-28 17:09:08 +01:00
|
|
|
char otp[MAX_TOKEN_ID_LEN + TOKEN_OTP_LEN + 1] = { 0 };
|
|
|
|
char otp_id[MAX_TOKEN_ID_LEN + 1] = { 0 };
|
2015-03-04 14:52:16 +01:00
|
|
|
size_t password_len = 0;
|
2011-02-28 17:09:08 +01:00
|
|
|
int skip_bytes = 0;
|
2009-03-24 15:20:52 +01:00
|
|
|
int valid_token = 0;
|
|
|
|
struct pam_conv *conv;
|
2013-09-18 10:22:00 +02:00
|
|
|
const struct pam_message *pmsg[1];
|
|
|
|
struct pam_message msg[1];
|
2015-01-16 10:14:22 +01:00
|
|
|
struct pam_response *resp = NULL;
|
2009-03-24 15:20:52 +01:00
|
|
|
int nargs = 1;
|
2009-03-25 11:15:13 +01:00
|
|
|
ykclient_t *ykc = NULL;
|
2011-04-15 15:24:50 +02:00
|
|
|
struct cfg cfg_st;
|
|
|
|
struct cfg *cfg = &cfg_st; /* for DBG macro */
|
2014-03-26 10:52:46 +01:00
|
|
|
size_t templates = 0;
|
|
|
|
char *urls[10];
|
2014-07-29 09:23:10 +02:00
|
|
|
char *tmpurl = NULL;
|
2014-10-29 13:25:29 +01:00
|
|
|
char *onlypasswd = NULL;
|
2009-03-24 15:20:52 +01:00
|
|
|
|
2011-04-15 15:24:50 +02:00
|
|
|
parse_cfg (flags, argc, argv, cfg);
|
2008-01-11 13:41:21 +01:00
|
|
|
|
2015-02-13 12:33:43 +01:00
|
|
|
DBG (("pam_yubico version: %s", VERSION));
|
|
|
|
|
2012-08-06 23:53:33 +02:00
|
|
|
if (cfg->token_id_length > MAX_TOKEN_ID_LEN)
|
|
|
|
{
|
Use unsigned, fix printf conversion spec warnings
Some of the printf conversion specifications were wrong when used on
size_t, causing
> pam_yubico.c:957:57: warning: format specifies type 'int' but the argument has type 'size_t' (aka 'unsigned long') [-Wformat]
> DBG (("OTP too short to be considered : %i < %i", password_len, (cfg->token_id_length + TOKEN_OTP_LEN)));
> ~~ ^~~~~~~~~~~~
> %zu
> pam_yubico.c:132:36: note: expanded from macro 'DBG'
> #define DBG(x) if (cfg->debug) { D(x); }
> ^
> ./util.h:47:12: note: expanded from macro 'D'
> printf x; \
> ^
and
> pam_yubico.c:967:14: warning: format specifies type 'int' but the argument has type 'size_t' (aka 'unsigned long') [-Wformat]
> skip_bytes, password_len, cfg->token_id_length, TOKEN_OTP_LEN));
> ^~~~~~~~~~~~
> pam_yubico.c:132:36: note: expanded from macro 'DBG'
> #define DBG(x) if (cfg->debug) { D(x); }
> ^
> ./util.h:47:12: note: expanded from macro 'D'
> printf x; \
> ^
Fix these by using the appropriate %zu conversions for size_t. While
looking through the code, there are a couple more places where format
string specifiers could be improved, e.g. using %zu instead of casting
the result of sizeof(x) or strlen(x) to unsigned long.
In addition, convert TOKEN_OTP_LEN, MAX_TOKEN_ID_LEN and
DEFAULT_TOKEN_ID_LEN to unsigned numbers, because negative values would
not make any sense for those.
2015-03-28 13:10:35 +01:00
|
|
|
DBG (("configuration error: token_id_length too long. Maximum acceptable value : %u", MAX_TOKEN_ID_LEN));
|
2012-08-06 23:53:33 +02:00
|
|
|
retval = PAM_AUTHINFO_UNAVAIL;
|
|
|
|
goto done;
|
|
|
|
}
|
|
|
|
|
2008-01-11 13:41:21 +01:00
|
|
|
retval = pam_get_user (pamh, &user, NULL);
|
|
|
|
if (retval != PAM_SUCCESS)
|
|
|
|
{
|
2009-03-24 15:20:52 +01:00
|
|
|
DBG (("get user returned error: %s", pam_strerror (pamh, retval)));
|
2008-01-11 13:41:21 +01:00
|
|
|
goto done;
|
|
|
|
}
|
2009-03-24 15:20:52 +01:00
|
|
|
DBG (("get user returned: %s", user));
|
2008-01-11 13:41:21 +01:00
|
|
|
|
2011-04-15 15:24:50 +02:00
|
|
|
if (cfg->mode == CHRESP) {
|
2011-11-23 13:26:02 +01:00
|
|
|
#if HAVE_CR
|
2011-04-15 15:24:50 +02:00
|
|
|
return do_challenge_response(pamh, cfg, user);
|
2011-06-07 00:34:40 +02:00
|
|
|
#else
|
|
|
|
DBG (("no support for challenge/response"));
|
|
|
|
retval = PAM_AUTH_ERR;
|
|
|
|
goto done;
|
|
|
|
#endif
|
2011-03-12 15:49:50 +01:00
|
|
|
}
|
|
|
|
|
2011-04-15 15:24:50 +02:00
|
|
|
if (cfg->try_first_pass || cfg->use_first_pass)
|
2008-01-11 13:41:21 +01:00
|
|
|
{
|
2009-03-24 12:13:57 +01:00
|
|
|
retval = pam_get_item (pamh, PAM_AUTHTOK, (const void **) &password);
|
|
|
|
if (retval != PAM_SUCCESS)
|
|
|
|
{
|
2009-03-24 15:20:52 +01:00
|
|
|
DBG (("get password returned error: %s",
|
|
|
|
pam_strerror (pamh, retval)));
|
2009-03-24 12:13:57 +01:00
|
|
|
goto done;
|
|
|
|
}
|
2009-03-24 15:20:52 +01:00
|
|
|
DBG (("get password returned: %s", password));
|
2009-03-24 12:13:57 +01:00
|
|
|
}
|
|
|
|
|
2011-04-15 15:24:50 +02:00
|
|
|
if (cfg->use_first_pass && password == NULL)
|
2009-03-24 12:13:57 +01:00
|
|
|
{
|
2009-03-24 15:20:52 +01:00
|
|
|
DBG (("use_first_pass set and no password, giving up"));
|
2009-03-24 12:13:57 +01:00
|
|
|
retval = PAM_AUTH_ERR;
|
2008-01-11 13:41:21 +01:00
|
|
|
goto done;
|
|
|
|
}
|
|
|
|
|
2015-02-16 08:19:59 +01:00
|
|
|
if(ykclient_global_init() != YKCLIENT_OK)
|
|
|
|
{
|
|
|
|
DBG (("Failed initializing ykclient library"));
|
|
|
|
retval = PAM_AUTHINFO_UNAVAIL;
|
|
|
|
goto done;
|
|
|
|
}
|
2015-03-04 08:50:08 +01:00
|
|
|
rc = ykclient_init (&ykc);
|
|
|
|
if (rc != YKCLIENT_OK)
|
2009-03-24 15:28:21 +01:00
|
|
|
{
|
2009-03-25 11:15:13 +01:00
|
|
|
DBG (("ykclient_init() failed (%d): %s", rc, ykclient_strerror (rc)));
|
2009-03-24 15:28:21 +01:00
|
|
|
retval = PAM_AUTHINFO_UNAVAIL;
|
|
|
|
goto done;
|
|
|
|
}
|
|
|
|
|
2011-04-15 15:24:50 +02:00
|
|
|
rc = ykclient_set_client_b64 (ykc, cfg->client_id, cfg->client_key);
|
2009-05-11 12:05:20 +02:00
|
|
|
if (rc != YKCLIENT_OK)
|
|
|
|
{
|
|
|
|
DBG (("ykclient_set_client_b64() failed (%d): %s",
|
|
|
|
rc, ykclient_strerror (rc)));
|
|
|
|
retval = PAM_AUTHINFO_UNAVAIL;
|
|
|
|
goto done;
|
|
|
|
}
|
|
|
|
|
2011-11-08 21:08:54 +01:00
|
|
|
if (cfg->client_key)
|
|
|
|
ykclient_set_verify_signature (ykc, 1);
|
|
|
|
|
2011-04-15 15:24:50 +02:00
|
|
|
if (cfg->capath)
|
|
|
|
ykclient_set_ca_path (ykc, cfg->capath);
|
2011-02-11 16:28:46 +01:00
|
|
|
|
2011-04-15 15:24:50 +02:00
|
|
|
if (cfg->url)
|
2014-03-12 14:59:02 +01:00
|
|
|
{
|
|
|
|
rc = ykclient_set_url_template (ykc, cfg->url);
|
|
|
|
if (rc != YKCLIENT_OK)
|
|
|
|
{
|
|
|
|
DBG (("ykclient_set_url_template() failed (%d): %s",
|
|
|
|
rc, ykclient_strerror (rc)));
|
|
|
|
retval = PAM_AUTHINFO_UNAVAIL;
|
|
|
|
goto done;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
if (cfg->urllist)
|
|
|
|
{
|
|
|
|
char *saveptr = NULL;
|
|
|
|
char *part = NULL;
|
2014-07-29 09:23:10 +02:00
|
|
|
tmpurl = strdup(cfg->urllist);
|
2014-03-12 14:59:02 +01:00
|
|
|
|
2014-07-29 09:23:10 +02:00
|
|
|
while ((part = strtok_r(templates == 0 ? tmpurl : NULL, ";", &saveptr)))
|
2014-03-12 14:59:02 +01:00
|
|
|
{
|
|
|
|
if(templates == 10)
|
|
|
|
{
|
|
|
|
DBG (("maximum 10 urls supported in list."));
|
|
|
|
retval = PAM_AUTHINFO_UNAVAIL;
|
|
|
|
goto done;
|
|
|
|
}
|
2014-03-26 10:52:46 +01:00
|
|
|
urls[templates] = strdup(part);
|
2014-03-12 14:59:02 +01:00
|
|
|
templates++;
|
|
|
|
}
|
2014-03-26 10:52:46 +01:00
|
|
|
rc = ykclient_set_url_bases (ykc, templates, (const char **)urls);
|
2014-03-12 14:59:02 +01:00
|
|
|
if (rc != YKCLIENT_OK)
|
|
|
|
{
|
|
|
|
DBG (("ykclient_set_url_bases() failed (%d): %s",
|
|
|
|
rc, ykclient_strerror (rc)));
|
|
|
|
retval = PAM_AUTHINFO_UNAVAIL;
|
|
|
|
goto done;
|
|
|
|
}
|
|
|
|
}
|
2009-03-24 15:30:57 +01:00
|
|
|
|
2008-01-11 13:41:21 +01:00
|
|
|
if (password == NULL)
|
|
|
|
{
|
|
|
|
retval = pam_get_item (pamh, PAM_CONV, (const void **) &conv);
|
|
|
|
if (retval != PAM_SUCCESS)
|
|
|
|
{
|
2009-03-24 15:20:52 +01:00
|
|
|
DBG (("get conv returned error: %s", pam_strerror (pamh, retval)));
|
2008-01-11 13:41:21 +01:00
|
|
|
goto done;
|
|
|
|
}
|
|
|
|
|
|
|
|
pmsg[0] = &msg[0];
|
2009-01-13 11:44:02 +01:00
|
|
|
{
|
2013-09-18 10:22:00 +02:00
|
|
|
#define QUERY_TEMPLATE "YubiKey for `%s': "
|
|
|
|
size_t len = strlen (QUERY_TEMPLATE) + strlen (user);
|
2012-02-06 11:31:23 +01:00
|
|
|
int wrote;
|
2009-01-13 11:44:02 +01:00
|
|
|
|
|
|
|
msg[0].msg = malloc (len);
|
|
|
|
if (!msg[0].msg)
|
|
|
|
{
|
|
|
|
retval = PAM_BUF_ERR;
|
|
|
|
goto done;
|
|
|
|
}
|
|
|
|
|
2013-09-18 10:22:00 +02:00
|
|
|
wrote = snprintf ((char *) msg[0].msg, len, QUERY_TEMPLATE, user);
|
2009-01-13 11:44:02 +01:00
|
|
|
if (wrote < 0 || wrote >= len)
|
|
|
|
{
|
|
|
|
retval = PAM_BUF_ERR;
|
|
|
|
goto done;
|
|
|
|
}
|
|
|
|
}
|
2011-04-15 15:24:50 +02:00
|
|
|
msg[0].msg_style = cfg->verbose_otp ? PAM_PROMPT_ECHO_ON : PAM_PROMPT_ECHO_OFF;
|
2008-01-11 13:41:21 +01:00
|
|
|
|
2013-09-18 10:22:00 +02:00
|
|
|
retval = conv->conv (nargs, pmsg, &resp, conv->appdata_ptr);
|
2008-01-11 13:41:21 +01:00
|
|
|
|
|
|
|
free ((char *) msg[0].msg);
|
|
|
|
|
|
|
|
if (retval != PAM_SUCCESS)
|
|
|
|
{
|
2009-03-24 15:20:52 +01:00
|
|
|
DBG (("conv returned error: %s", pam_strerror (pamh, retval)));
|
2008-01-11 13:41:21 +01:00
|
|
|
goto done;
|
|
|
|
}
|
|
|
|
|
2010-09-09 22:28:20 +02:00
|
|
|
if (resp->resp == NULL)
|
|
|
|
{
|
|
|
|
DBG (("conv returned NULL passwd?"));
|
2011-08-26 13:32:03 +02:00
|
|
|
retval = PAM_AUTH_ERR;
|
2010-09-09 22:28:20 +02:00
|
|
|
goto done;
|
|
|
|
}
|
|
|
|
|
Use unsigned, fix printf conversion spec warnings
Some of the printf conversion specifications were wrong when used on
size_t, causing
> pam_yubico.c:957:57: warning: format specifies type 'int' but the argument has type 'size_t' (aka 'unsigned long') [-Wformat]
> DBG (("OTP too short to be considered : %i < %i", password_len, (cfg->token_id_length + TOKEN_OTP_LEN)));
> ~~ ^~~~~~~~~~~~
> %zu
> pam_yubico.c:132:36: note: expanded from macro 'DBG'
> #define DBG(x) if (cfg->debug) { D(x); }
> ^
> ./util.h:47:12: note: expanded from macro 'D'
> printf x; \
> ^
and
> pam_yubico.c:967:14: warning: format specifies type 'int' but the argument has type 'size_t' (aka 'unsigned long') [-Wformat]
> skip_bytes, password_len, cfg->token_id_length, TOKEN_OTP_LEN));
> ^~~~~~~~~~~~
> pam_yubico.c:132:36: note: expanded from macro 'DBG'
> #define DBG(x) if (cfg->debug) { D(x); }
> ^
> ./util.h:47:12: note: expanded from macro 'D'
> printf x; \
> ^
Fix these by using the appropriate %zu conversions for size_t. While
looking through the code, there are a couple more places where format
string specifiers could be improved, e.g. using %zu instead of casting
the result of sizeof(x) or strlen(x) to unsigned long.
In addition, convert TOKEN_OTP_LEN, MAX_TOKEN_ID_LEN and
DEFAULT_TOKEN_ID_LEN to unsigned numbers, because negative values would
not make any sense for those.
2015-03-28 13:10:35 +01:00
|
|
|
DBG (("conv returned %zu bytes", strlen(resp->resp)));
|
2008-01-11 13:41:21 +01:00
|
|
|
|
|
|
|
password = resp->resp;
|
2009-03-24 16:11:54 +01:00
|
|
|
}
|
2008-01-11 13:41:21 +01:00
|
|
|
|
2009-03-24 16:11:54 +01:00
|
|
|
password_len = strlen (password);
|
2011-04-15 15:24:50 +02:00
|
|
|
if (password_len < (cfg->token_id_length + TOKEN_OTP_LEN))
|
2009-03-24 16:11:54 +01:00
|
|
|
{
|
Use unsigned, fix printf conversion spec warnings
Some of the printf conversion specifications were wrong when used on
size_t, causing
> pam_yubico.c:957:57: warning: format specifies type 'int' but the argument has type 'size_t' (aka 'unsigned long') [-Wformat]
> DBG (("OTP too short to be considered : %i < %i", password_len, (cfg->token_id_length + TOKEN_OTP_LEN)));
> ~~ ^~~~~~~~~~~~
> %zu
> pam_yubico.c:132:36: note: expanded from macro 'DBG'
> #define DBG(x) if (cfg->debug) { D(x); }
> ^
> ./util.h:47:12: note: expanded from macro 'D'
> printf x; \
> ^
and
> pam_yubico.c:967:14: warning: format specifies type 'int' but the argument has type 'size_t' (aka 'unsigned long') [-Wformat]
> skip_bytes, password_len, cfg->token_id_length, TOKEN_OTP_LEN));
> ^~~~~~~~~~~~
> pam_yubico.c:132:36: note: expanded from macro 'DBG'
> #define DBG(x) if (cfg->debug) { D(x); }
> ^
> ./util.h:47:12: note: expanded from macro 'D'
> printf x; \
> ^
Fix these by using the appropriate %zu conversions for size_t. While
looking through the code, there are a couple more places where format
string specifiers could be improved, e.g. using %zu instead of casting
the result of sizeof(x) or strlen(x) to unsigned long.
In addition, convert TOKEN_OTP_LEN, MAX_TOKEN_ID_LEN and
DEFAULT_TOKEN_ID_LEN to unsigned numbers, because negative values would
not make any sense for those.
2015-03-28 13:10:35 +01:00
|
|
|
DBG (("OTP too short to be considered : %zu < %u", password_len, (cfg->token_id_length + TOKEN_OTP_LEN)));
|
2009-03-24 16:11:54 +01:00
|
|
|
retval = PAM_AUTH_ERR;
|
|
|
|
goto done;
|
2008-01-11 13:41:21 +01:00
|
|
|
}
|
|
|
|
|
2011-02-28 17:09:08 +01:00
|
|
|
/* In case the input was systempassword+YubiKeyOTP, we want to skip over
|
|
|
|
"systempassword" when copying the token_id and OTP to separate buffers */
|
2011-04-15 15:24:50 +02:00
|
|
|
skip_bytes = password_len - (cfg->token_id_length + TOKEN_OTP_LEN);
|
2011-02-28 17:09:08 +01:00
|
|
|
|
Use unsigned, fix printf conversion spec warnings
Some of the printf conversion specifications were wrong when used on
size_t, causing
> pam_yubico.c:957:57: warning: format specifies type 'int' but the argument has type 'size_t' (aka 'unsigned long') [-Wformat]
> DBG (("OTP too short to be considered : %i < %i", password_len, (cfg->token_id_length + TOKEN_OTP_LEN)));
> ~~ ^~~~~~~~~~~~
> %zu
> pam_yubico.c:132:36: note: expanded from macro 'DBG'
> #define DBG(x) if (cfg->debug) { D(x); }
> ^
> ./util.h:47:12: note: expanded from macro 'D'
> printf x; \
> ^
and
> pam_yubico.c:967:14: warning: format specifies type 'int' but the argument has type 'size_t' (aka 'unsigned long') [-Wformat]
> skip_bytes, password_len, cfg->token_id_length, TOKEN_OTP_LEN));
> ^~~~~~~~~~~~
> pam_yubico.c:132:36: note: expanded from macro 'DBG'
> #define DBG(x) if (cfg->debug) { D(x); }
> ^
> ./util.h:47:12: note: expanded from macro 'D'
> printf x; \
> ^
Fix these by using the appropriate %zu conversions for size_t. While
looking through the code, there are a couple more places where format
string specifiers could be improved, e.g. using %zu instead of casting
the result of sizeof(x) or strlen(x) to unsigned long.
In addition, convert TOKEN_OTP_LEN, MAX_TOKEN_ID_LEN and
DEFAULT_TOKEN_ID_LEN to unsigned numbers, because negative values would
not make any sense for those.
2015-03-28 13:10:35 +01:00
|
|
|
DBG (("Skipping first %i bytes. Length is %zu, token_id set to %u and token OTP always %u.",
|
2011-04-15 15:24:50 +02:00
|
|
|
skip_bytes, password_len, cfg->token_id_length, TOKEN_OTP_LEN));
|
2011-02-28 17:09:08 +01:00
|
|
|
|
|
|
|
/* Copy full YubiKey output (public ID + OTP) into otp */
|
|
|
|
strncpy (otp, password + skip_bytes, sizeof (otp) - 1);
|
|
|
|
/* Copy only public ID into otp_id. Destination buffer is zeroed. */
|
2011-04-15 15:24:50 +02:00
|
|
|
strncpy (otp_id, password + skip_bytes, cfg->token_id_length);
|
2008-09-01 15:13:07 +02:00
|
|
|
|
2009-03-24 16:11:54 +01:00
|
|
|
DBG (("OTP: %s ID: %s ", otp, otp_id));
|
2008-09-01 15:13:07 +02:00
|
|
|
|
2009-03-24 16:11:54 +01:00
|
|
|
/* user entered their system password followed by generated OTP? */
|
2011-04-15 15:24:50 +02:00
|
|
|
if (password_len > TOKEN_OTP_LEN + cfg->token_id_length)
|
2008-09-01 15:14:33 +02:00
|
|
|
{
|
2014-10-28 16:27:28 +01:00
|
|
|
onlypasswd = strdup (password);
|
2008-09-01 15:13:07 +02:00
|
|
|
|
2011-11-22 11:08:53 +01:00
|
|
|
if (! onlypasswd) {
|
|
|
|
retval = PAM_BUF_ERR;
|
|
|
|
goto done;
|
|
|
|
}
|
|
|
|
|
2011-04-15 15:24:50 +02:00
|
|
|
onlypasswd[password_len - (TOKEN_OTP_LEN + cfg->token_id_length)] = '\0';
|
2008-09-01 15:13:07 +02:00
|
|
|
|
2011-03-03 14:51:25 +01:00
|
|
|
DBG (("Extracted a probable system password entered before the OTP - "
|
|
|
|
"setting item PAM_AUTHTOK"));
|
2009-03-24 16:11:54 +01:00
|
|
|
|
|
|
|
retval = pam_set_item (pamh, PAM_AUTHTOK, onlypasswd);
|
2008-09-01 15:13:07 +02:00
|
|
|
if (retval != PAM_SUCCESS)
|
2008-09-01 15:14:33 +02:00
|
|
|
{
|
2009-03-24 15:20:52 +01:00
|
|
|
DBG (("set_item returned error: %s", pam_strerror (pamh, retval)));
|
2008-09-01 15:14:33 +02:00
|
|
|
goto done;
|
|
|
|
}
|
2008-09-01 15:13:07 +02:00
|
|
|
}
|
2009-03-24 16:11:54 +01:00
|
|
|
else
|
|
|
|
password = NULL;
|
2008-09-01 15:13:07 +02:00
|
|
|
|
2009-03-25 11:15:13 +01:00
|
|
|
rc = ykclient_request (ykc, otp);
|
2008-09-01 15:13:07 +02:00
|
|
|
|
2009-03-25 11:15:13 +01:00
|
|
|
DBG (("ykclient return value (%d): %s", rc,
|
|
|
|
ykclient_strerror (rc)));
|
2009-03-24 15:30:57 +01:00
|
|
|
|
2009-03-24 16:11:54 +01:00
|
|
|
switch (rc)
|
|
|
|
{
|
2009-03-25 11:15:13 +01:00
|
|
|
case YKCLIENT_OK:
|
2009-03-24 16:11:54 +01:00
|
|
|
break;
|
|
|
|
|
2009-03-25 11:15:13 +01:00
|
|
|
case YKCLIENT_BAD_OTP:
|
|
|
|
case YKCLIENT_REPLAYED_OTP:
|
2009-03-24 16:11:54 +01:00
|
|
|
retval = PAM_AUTH_ERR;
|
|
|
|
goto done;
|
|
|
|
|
|
|
|
default:
|
|
|
|
retval = PAM_AUTHINFO_UNAVAIL;
|
|
|
|
goto done;
|
|
|
|
}
|
|
|
|
|
|
|
|
/* authorize the user with supplied token id */
|
2011-04-15 15:24:50 +02:00
|
|
|
if (cfg->ldapserver != NULL || cfg->ldap_uri != NULL)
|
|
|
|
valid_token = authorize_user_token_ldap (cfg, user, otp_id);
|
2009-03-24 16:11:54 +01:00
|
|
|
else
|
2011-11-23 13:27:37 +01:00
|
|
|
valid_token = authorize_user_token (cfg, user, otp_id, pamh);
|
2008-09-01 15:13:07 +02:00
|
|
|
|
2013-01-26 16:59:23 +01:00
|
|
|
switch(valid_token)
|
2008-01-11 13:41:21 +01:00
|
|
|
{
|
2013-01-26 16:59:23 +01:00
|
|
|
case 1:
|
|
|
|
retval = PAM_SUCCESS;
|
|
|
|
break;
|
|
|
|
case 0:
|
|
|
|
DBG (("Internal error while validating user"));
|
|
|
|
retval = PAM_AUTHINFO_UNAVAIL;
|
|
|
|
break;
|
|
|
|
case -1:
|
|
|
|
DBG (("Unauthorized token for this user"));
|
|
|
|
retval = PAM_AUTH_ERR;
|
|
|
|
break;
|
|
|
|
case -2:
|
|
|
|
DBG (("Unknown user"));
|
|
|
|
retval = PAM_USER_UNKNOWN;
|
|
|
|
break;
|
|
|
|
default:
|
|
|
|
DBG (("Unhandled value for token-user validation"))
|
2009-03-24 16:11:54 +01:00
|
|
|
retval = PAM_AUTHINFO_UNAVAIL;
|
2008-01-11 13:41:21 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
done:
|
2014-10-29 13:25:29 +01:00
|
|
|
if (onlypasswd)
|
|
|
|
free(onlypasswd);
|
2014-03-26 10:52:46 +01:00
|
|
|
if (templates > 0)
|
|
|
|
{
|
|
|
|
size_t i;
|
|
|
|
for(i = 0; i < templates; i++)
|
|
|
|
{
|
2014-06-02 12:32:08 +02:00
|
|
|
free(urls[i]);
|
2014-03-26 10:52:46 +01:00
|
|
|
}
|
|
|
|
}
|
2014-07-29 09:23:10 +02:00
|
|
|
if (tmpurl)
|
|
|
|
free(tmpurl);
|
2009-03-24 15:30:57 +01:00
|
|
|
if (ykc)
|
2015-02-16 08:19:59 +01:00
|
|
|
{
|
|
|
|
ykclient_done (&ykc);
|
|
|
|
ykclient_global_done();
|
|
|
|
}
|
2011-04-15 15:24:50 +02:00
|
|
|
if (cfg->alwaysok && retval != PAM_SUCCESS)
|
2008-01-11 13:41:21 +01:00
|
|
|
{
|
2009-03-24 15:20:52 +01:00
|
|
|
DBG (("alwaysok needed (otherwise return with %d)", retval));
|
2008-01-11 13:41:21 +01:00
|
|
|
retval = PAM_SUCCESS;
|
|
|
|
}
|
2009-03-24 15:20:52 +01:00
|
|
|
DBG (("done. [%s]", pam_strerror (pamh, retval)));
|
2014-11-20 22:40:55 +01:00
|
|
|
pam_set_data (pamh, "yubico_setcred_return", (void*)(intptr_t)retval, NULL);
|
2008-01-11 13:41:21 +01:00
|
|
|
|
2015-01-16 10:14:22 +01:00
|
|
|
if (resp)
|
2015-01-21 09:57:02 +01:00
|
|
|
{
|
|
|
|
if (resp->resp)
|
|
|
|
free (resp->resp);
|
|
|
|
free (resp);
|
|
|
|
}
|
2015-01-16 10:14:22 +01:00
|
|
|
|
2008-01-11 13:41:21 +01:00
|
|
|
return retval;
|
|
|
|
}
|
|
|
|
|
|
|
|
PAM_EXTERN int
|
|
|
|
pam_sm_setcred (pam_handle_t * pamh, int flags, int argc, const char **argv)
|
|
|
|
{
|
2011-03-12 14:34:45 +01:00
|
|
|
return PAM_SUCCESS;
|
2008-01-11 13:41:21 +01:00
|
|
|
}
|
|
|
|
|
2014-10-29 13:25:29 +01:00
|
|
|
PAM_EXTERN int
|
2014-11-20 22:40:55 +01:00
|
|
|
pam_sm_acct_mgmt(pam_handle_t *pamh, int flags, int argc, const char **argv)
|
2014-10-29 13:25:29 +01:00
|
|
|
{
|
2015-03-04 09:14:14 +01:00
|
|
|
int retval;
|
|
|
|
int rc = pam_get_data(pamh, "yubico_setcred_return", (const void**)&retval);
|
|
|
|
if (rc == PAM_SUCCESS && retval == PAM_SUCCESS) {
|
|
|
|
D (("pam_sm_acct_mgmt returing PAM_SUCCESS"));
|
|
|
|
return PAM_SUCCESS;
|
2014-10-29 13:25:29 +01:00
|
|
|
}
|
2015-03-04 09:14:14 +01:00
|
|
|
D (("pam_sm_acct_mgmt returing PAM_AUTH_ERR:%d", rc));
|
2014-10-29 13:25:29 +01:00
|
|
|
return PAM_AUTH_ERR;
|
|
|
|
}
|
|
|
|
|
|
|
|
PAM_EXTERN int
|
|
|
|
pam_sm_open_session(pam_handle_t *pamh, int flags,
|
|
|
|
int argc, const char *argv[])
|
|
|
|
{
|
|
|
|
|
|
|
|
D(("pam_sm_open_session"));
|
|
|
|
return (PAM_SUCCESS);
|
|
|
|
}
|
|
|
|
|
|
|
|
PAM_EXTERN int
|
|
|
|
pam_sm_close_session(pam_handle_t *pamh, int flags,
|
|
|
|
int argc, const char *argv[])
|
|
|
|
{
|
|
|
|
D(("pam_sm_close_session"));
|
|
|
|
return (PAM_SUCCESS);
|
|
|
|
}
|
|
|
|
|
|
|
|
PAM_EXTERN int
|
|
|
|
pam_sm_chauthtok(pam_handle_t *pamh, int flags,
|
|
|
|
int argc, const char *argv[])
|
|
|
|
{
|
|
|
|
D(("pam_sm_chauthtok"));
|
|
|
|
return (PAM_SERVICE_ERR);
|
|
|
|
}
|
|
|
|
|
|
|
|
|
2008-01-11 13:41:21 +01:00
|
|
|
#ifdef PAM_STATIC
|
|
|
|
|
|
|
|
struct pam_module _pam_yubico_modstruct = {
|
|
|
|
"pam_yubico",
|
|
|
|
pam_sm_authenticate,
|
|
|
|
pam_sm_setcred,
|
2014-10-29 13:25:29 +01:00
|
|
|
pam_sm_acct_mgmt,
|
|
|
|
pam_sm_open_session,
|
|
|
|
pam_sm_close_session,
|
|
|
|
pam_sm_chauthtok
|
2008-01-11 13:41:21 +01:00
|
|
|
};
|
|
|
|
|
|
|
|
#endif
|