1
0
mirror of https://github.com/Yubico/yubico-pam.git synced 2024-11-29 09:24:22 +01:00
Commit Graph

212 Commits

Author SHA1 Message Date
Tollef Fog Heen
72d1f4bba9 Move code around slightly to make merging with Fredrik easier 2011-03-18 23:01:46 +01:00
Fredrik Thulin
b20c0ed678 Make get_user_challenge_file() also include YubiKey serial number,
and move it to util.c.
2011-03-18 22:57:22 +01:00
Fredrik Thulin
69ec1bf8a0 Further cleanups to challenge response code, and move more code to util.c. 2011-03-18 22:56:41 +01:00
Fredrik Thulin
cb16817047 Revert "Wait with declaring PAM_SUCCESS on challenge-response until new"
Tollef has argued that the login should not fail if, for example, the
disk is full. I'd rather fail on the cautious side and make sure we
don't end up always sending the same challenge to the YubiKey, but I'll
leave it up to Tollef to decide for now.

This reverts commit 14e917ffae.

Conflicts:

	pam_yubico.c
2011-03-18 22:50:23 +01:00
Fredrik Thulin
721866df0b Move more challenge-response code to util.c. 2011-03-18 21:52:07 +01:00
Fredrik Thulin
c557249503 Move soon-to-be commonly used code to util.c 2011-03-18 21:49:23 +01:00
Fredrik Thulin
3abc5b2d81 Remove hard coded values for challenge/responses.
Also do some input validation on what we read from the C/R file.
2011-03-16 22:52:36 +01:00
Fredrik Thulin
d73618f271 generate_challenge() only generated half as many bytes as it should.
Changed generate_challenge() to generating bytes instead of a hex
encoded string, to not have to decode what we just encoded - instead
just generate plain bytes of randomness and then encode them once.
2011-03-16 22:49:57 +01:00
Tollef Fog Heen
1364b39db7 Use a temporary file to ensure we always have a challenge
If we use ftruncate we might end up in the situation that we do not
have a challenge on disk, leading to the user being unable to log in.
By using a temporary file, fsync and rename we avoid this problem.
2011-03-16 22:49:51 +01:00
Fredrik Thulin
dc6cd95a98 fsync() wants file descriptor
Also, truncate file before writing if the challenge length has
changed (became shorter) or garbage has otherwise been appended.
2011-03-16 22:28:33 +01:00
Fredrik Thulin
ee2e8b42da Don't generate new challenge on bad response. 2011-03-16 22:28:02 +01:00
Fredrik Thulin
7360223a14 Support challenge-response files outside user's home directory.
Having the challege-response data inside the home directory won't
work very well if the YubiKey is to unlock an ecryptfs encrypted
home directory.
2011-03-16 22:27:02 +01:00
Tollef Fog Heen
d9ee08b97f Add challenge-response authentication 2011-03-12 15:57:07 +01:00
Tollef Fog Heen
ed1ce7e6e7 Undef USERFILE when we don't need it any more 2011-03-12 15:57:02 +01:00
Tollef Fog Heen
49c923a99d Get rid of unimplemented PAM functions 2011-03-12 15:56:48 +01:00
Fredrik Thulin
e338807cc8 Merge branch 'fix/various_ldap_fixes' 2011-03-10 20:50:48 +01:00
Fredrik Thulin
a59c6c4d71 Ignore errors from pam_get_data(). 2011-03-04 15:52:02 +01:00
Fredrik Thulin
f91a7dc99a Correct debug log message for too short OTPs. 2011-03-03 15:45:00 +01:00
Fredrik Thulin
a5594fa09c Merge branch 'devel/avoid_logging_passwords' 2011-03-03 15:07:53 +01:00
Fredrik Thulin
702ac98b21 Bugfix getting option token_id_length. 2011-03-03 15:06:15 +01:00
Fredrik Thulin
ac76947e8a Avoid logging passwords when debug is enabled.
Problem reported in
http://code.google.com/p/yubico-pam/issues/detail?id=28
2011-03-03 15:00:05 +01:00
Fredrik Thulin
abb0b7e4e4 authorize_user_token_ldap: Only fetch the attribute we're interested in.
Previous version fetched ALL attributes of the identified object,
and treated them all equal when looking for the YubiKey token identifier.
2011-03-03 14:18:00 +01:00
Fredrik Thulin
a9ef97ea4c authorize_user_token_ldap: Don't leak memory on failures. 2011-03-03 12:48:43 +01:00
Fredrik Thulin
0bb1630abf authorize_user_token_ldap: sr was under-allocated by one byte.
Also change strcat's to sprintf to make code easier to maintain.
2011-03-03 12:38:34 +01:00
Fredrik Thulin
bfd8efd682 Don't segfault on unset LDAP parameters.
When ldapserver / ldap_uri was specified, but not for example
user_attr, authorize_user_token_ldap() used to cause a segmentation
fault.
2011-03-03 10:58:34 +01:00
Fredrik Thulin
01897ebb9e Use LDAPv3 instead of LDAPv2.
LDAPv2 was declared historical in 2003, and is now not supported by
for example Mac OS X Server's Open Directory.
Patch by maxsanna81@gmail.com.
2011-03-03 10:31:30 +01:00
Fredrik Thulin
90a7fd0f0a Avoid LDAP warnings about deprecated functions.
Patch by judas.iscariote.
2011-03-03 10:19:55 +01:00
Fredrik Thulin
6a0c8fc82b authorize_user_token_ldap: Use correct LDAP free function.
Patch by judas.iscariote.
2011-03-03 10:11:16 +01:00
Fredrik Thulin
336f794b42 Make length of public ID part of tokens configurable.
Now that we support setting URL, not all public ID's can be expected
to be six bytes (the length used in the YubiCloud validation service).

Unfortunately we can't support OTPs of different lengths at once,
because there is code supporting users entering their (other)
password followed by the OTP from the YubiKey.

Patch by fraser.scott@gmail.com in
http://code.google.com/p/yubico-pam/issues/detail?id=19
2011-03-02 22:08:58 +01:00
Fredrik Thulin
bdfa3891e2 Add debug output of url and capath. 2011-02-28 15:42:56 +01:00
Remi Mollon
d122f27825 Add capath parameter to PAM module 2011-02-14 17:20:48 +08:00
Simon Josefsson
2fee6c1fcf Fix segmentation fault on 64-bit systems.
Reported by multiple people in Issue #11
<http://code.google.com/p/yubico-pam/issues/detail?id=11>.
2010-09-09 21:40:38 +00:00
Simon Josefsson
075cb5663f Handle ^D at su prompt. 2010-09-09 20:28:20 +00:00
Simon Josefsson
e6bed0bfcd Make deprecated "ldapserver" work again.
Reported by giovannibajo in Issue #27:
<http://code.google.com/p/yubico-pam/issues/detail?id=27>.
2010-07-13 16:53:24 +00:00
Simon Josefsson
d51da376c7 New keyword "verbose_otp" to allow displaying OTP characters.
Contributed by qistoph reported in Issue #22:
<http://code.google.com/p/yubico-pam/issues/detail?id=22>.
2010-04-14 09:07:48 +00:00
Simon Josefsson
adcf7e2c4e Add deprecated support for old ldapserver keyword. 2010-04-14 08:29:39 +00:00
Simon Josefsson
0aa245a9b2 Doc fix. 2010-04-13 19:58:35 +00:00
zubrick433
15cae15f1c Corrections in ldap part:Â
Removed deprecated ldap functions. New functions need a ldap uri instead of a hostname. changed configuration parameter ldapserver to ldap_uri to reflect change and avoid errors in configuration.

Search string are now of variable size depending on configuration parameters length, instead of an arbitrary fixed length.

Modified README for the new ldap_uri configuration parameter
2009-08-11 09:29:44 +00:00
Simon Josefsson
246253c379 Add new key parameter to set verification key. 2009-05-11 10:05:20 +00:00
Simon Josefsson
b6d7807da7 Don't output debug information unconditionally. 2009-05-11 08:59:22 +00:00
Simon Josefsson
35b4a6187e Avoid warning. 2009-03-30 08:11:26 +00:00
Simon Josefsson
b18d8ef79a Use and require libykclient v2.0+. 2009-03-25 10:15:13 +00:00
Simon Josefsson
a077ae56ad Improve matching logic. 2009-03-24 16:41:11 +00:00
Simon Josefsson
81d5c71a4b Fix crash on memory errors. 2009-03-24 15:21:09 +00:00
Simon Josefsson
d20569dcc3 Fix parsing of password+otp into id/otp/passwd. Fix return codes. Fix setcred. 2009-03-24 15:11:54 +00:00
Simon Josefsson
7f1a398141 Fix ykc handling. 2009-03-24 14:30:57 +00:00
Simon Josefsson
751962c4b5 Reduce failure points with live unverified OTP. 2009-03-24 14:28:21 +00:00
Simon Josefsson
8bc4f7b37d Split off configuration parsing. 2009-03-24 14:20:52 +00:00
Simon Josefsson
8d7e013726 Don't pass integers via pam_set_data/pam_get_data. 2009-03-24 13:38:33 +00:00
Simon Josefsson
0991ea610a Support use_first_pass and try_first_pass. 2009-03-24 11:13:57 +00:00
Simon Josefsson
a6043192e6 Fix typo. 2009-02-11 16:52:41 +00:00
Simon Josefsson
32e76effae Indent code. Add FIXME note. Handle NULL values in debug strings. 2009-02-11 16:50:04 +00:00
zubrick433
3abd8adc95 Added ldap support 2009-02-11 16:35:29 +00:00
Simon Josefsson
9d0ff9eafd Change license to 2-clause BSD. 2009-01-13 14:08:21 +00:00
Simon Josefsson
fc87a76136 Support debugging even on non-Linux. 2009-01-13 11:10:16 +00:00
Simon Josefsson
4711cf7c12 Avoid use of asprintf, to fix Solaris.
Suggested by Martin Englund <Martin.Englund@Sun.COM>.
2009-01-13 10:44:02 +00:00
Simon Josefsson
3338b6eb0c Add new parameter 'url' to specify the server template URL. 2008-09-15 14:25:14 +00:00
Simon Josefsson
02c8dce53f Indent. 2008-09-01 13:14:33 +00:00
Simon Josefsson
af09b5499c Merge in Samir's work. Support two-factor mode. Support user configurations. 2008-09-01 13:13:07 +00:00
Simon Josefsson
454d5b1bab Use libyubikey-client instead of curl directly. 2008-06-25 13:40:19 +00:00
Simon Josefsson
07840f52ac Remove obsolete comments. 2008-01-11 13:11:30 +00:00
Simon Josefsson
c28c90d068 Import from private CVS repository. 2008-01-11 12:41:21 +00:00