version 1.1, 2001/06/26 16:15:23 |
version 1.1.6.4, 2002/10/11 14:53:06 |
|
|
/* |
/* |
* Kerberos v5 authentication and ticket-passing routines. |
* Kerberos v5 authentication and ticket-passing routines. |
* |
* |
* $FreeBSD: src/crypto/openssh/auth-krb5.c,v 1.6 2001/02/13 16:58:04 assar Exp $ |
* $FreeBSD: src/crypto/openssh/auth-krb5.c,v 1.6 2001/02/13 16:58:04 assar Exp $ |
* $OpenBSD$ |
|
*/ |
*/ |
|
/* |
|
* Copyright (c) 2002 Daniel Kouril. All rights reserved. |
|
* |
|
* Redistribution and use in source and binary forms, with or without |
|
* modification, are permitted provided that the following conditions |
|
* are met: |
|
* 1. Redistributions of source code must retain the above copyright |
|
* notice, this list of conditions and the following disclaimer. |
|
* 2. Redistributions in binary form must reproduce the above copyright |
|
* notice, this list of conditions and the following disclaimer in the |
|
* documentation and/or other materials provided with the distribution. |
|
* |
|
* THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR |
|
* IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES |
|
* OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. |
|
* IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT, |
|
* INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT |
|
* NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, |
|
* DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY |
|
* THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT |
|
* (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF |
|
* THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. |
|
*/ |
|
|
#include "includes.h" |
#include "includes.h" |
|
RCSID("$OpenBSD$"); |
|
|
#include "ssh.h" |
#include "ssh.h" |
#include "ssh1.h" |
#include "ssh1.h" |
#include "packet.h" |
#include "packet.h" |
|
|
Authctxt *authctxt = (Authctxt *)context; |
Authctxt *authctxt = (Authctxt *)context; |
krb5_error_code problem; |
krb5_error_code problem; |
static int cleanup_registered = 0; |
static int cleanup_registered = 0; |
|
|
if (authctxt->krb5_ctx == NULL) { |
if (authctxt->krb5_ctx == NULL) { |
problem = krb5_init_context(&authctxt->krb5_ctx); |
problem = krb5_init_context(&authctxt->krb5_ctx); |
if (problem) |
if (problem) |
|
|
* only, in auth is received ticket, in client is returned principal |
* only, in auth is received ticket, in client is returned principal |
* from the ticket |
* from the ticket |
*/ |
*/ |
int |
int |
auth_krb5(Authctxt *authctxt, krb5_data *auth, char **client) |
auth_krb5(Authctxt *authctxt, krb5_data *auth, char **client, krb5_data *reply) |
{ |
{ |
krb5_error_code problem; |
krb5_error_code problem; |
krb5_principal server; |
krb5_principal server; |
krb5_data reply; |
|
krb5_ticket *ticket; |
krb5_ticket *ticket; |
int fd; |
int fd, ret; |
|
|
|
ret = 0; |
server = NULL; |
server = NULL; |
ticket = NULL; |
ticket = NULL; |
reply.length = 0; |
reply->length = 0; |
|
|
problem = krb5_init(authctxt); |
problem = krb5_init(authctxt); |
if (problem) |
if (problem) |
goto err; |
goto err; |
|
|
problem = krb5_auth_con_init(authctxt->krb5_ctx, |
problem = krb5_auth_con_init(authctxt->krb5_ctx, |
&authctxt->krb5_auth_ctx); |
&authctxt->krb5_auth_ctx); |
if (problem) |
if (problem) |
goto err; |
goto err; |
|
|
fd = packet_get_connection_in(); |
fd = packet_get_connection_in(); |
problem = krb5_auth_con_setaddrs_from_fd(authctxt->krb5_ctx, |
problem = krb5_auth_con_setaddrs_from_fd(authctxt->krb5_ctx, |
authctxt->krb5_auth_ctx, &fd); |
authctxt->krb5_auth_ctx, &fd); |
if (problem) |
if (problem) |
goto err; |
goto err; |
|
|
problem = krb5_sname_to_principal(authctxt->krb5_ctx, NULL, NULL , |
problem = krb5_sname_to_principal(authctxt->krb5_ctx, NULL, NULL , |
KRB5_NT_SRV_HST, &server); |
KRB5_NT_SRV_HST, &server); |
if (problem) |
if (problem) |
goto err; |
goto err; |
|
|
problem = krb5_rd_req(authctxt->krb5_ctx, &authctxt->krb5_auth_ctx, |
problem = krb5_rd_req(authctxt->krb5_ctx, &authctxt->krb5_auth_ctx, |
auth, server, NULL, NULL, &ticket); |
auth, server, NULL, NULL, &ticket); |
if (problem) |
if (problem) |
goto err; |
goto err; |
|
|
problem = krb5_copy_principal(authctxt->krb5_ctx, ticket->client, |
problem = krb5_copy_principal(authctxt->krb5_ctx, ticket->client, |
&authctxt->krb5_user); |
&authctxt->krb5_user); |
if (problem) |
if (problem) |
goto err; |
goto err; |
|
|
/* if client wants mutual auth */ |
/* if client wants mutual auth */ |
problem = krb5_mk_rep(authctxt->krb5_ctx, authctxt->krb5_auth_ctx, |
problem = krb5_mk_rep(authctxt->krb5_ctx, authctxt->krb5_auth_ctx, |
&reply); |
reply); |
if (problem) |
if (problem) |
goto err; |
goto err; |
|
|
/* Check .k5login authorization now. */ |
/* Check .k5login authorization now. */ |
if (!krb5_kuserok(authctxt->krb5_ctx, authctxt->krb5_user, |
if (!krb5_kuserok(authctxt->krb5_ctx, authctxt->krb5_user, |
authctxt->pw->pw_name)) |
authctxt->pw->pw_name)) |
goto err; |
goto err; |
|
|
if (client) |
if (client) |
krb5_unparse_name(authctxt->krb5_ctx, authctxt->krb5_user, |
krb5_unparse_name(authctxt->krb5_ctx, authctxt->krb5_user, |
client); |
client); |
|
|
packet_start(SSH_SMSG_AUTH_KERBEROS_RESPONSE); |
ret = 1; |
packet_put_string((char *) reply.data, reply.length); |
|
packet_send(); |
|
packet_write_wait(); |
|
|
|
err: |
err: |
if (server) |
if (server) |
krb5_free_principal(authctxt->krb5_ctx, server); |
krb5_free_principal(authctxt->krb5_ctx, server); |
if (ticket) |
if (ticket) |
krb5_free_ticket(authctxt->krb5_ctx, ticket); |
krb5_free_ticket(authctxt->krb5_ctx, ticket); |
if (reply.length) |
if (!ret && reply->length) { |
xfree(reply.data); |
xfree(reply->data); |
|
memset(reply, 0, sizeof(*reply)); |
|
} |
|
|
if (problem) { |
if (problem) { |
debug("Kerberos v5 authentication failed: %s", |
if (authctxt->krb5_ctx != NULL) |
krb5_get_err_text(authctxt->krb5_ctx, problem)); |
debug("Kerberos v5 authentication failed: %s", |
return (0); |
krb5_get_err_text(authctxt->krb5_ctx, problem)); |
|
else |
|
debug("Kerberos v5 authentication failed: %d", |
|
problem); |
} |
} |
return (1); |
|
|
return (ret); |
} |
} |
|
|
int |
int |
|
|
krb5_error_code problem; |
krb5_error_code problem; |
krb5_ccache ccache = NULL; |
krb5_ccache ccache = NULL; |
char *pname; |
char *pname; |
|
|
if (authctxt->pw == NULL || authctxt->krb5_user == NULL) |
if (authctxt->pw == NULL || authctxt->krb5_user == NULL) |
return (0); |
return (0); |
|
|
temporarily_use_uid(authctxt->pw); |
temporarily_use_uid(authctxt->pw); |
|
|
problem = krb5_cc_gen_new(authctxt->krb5_ctx, &krb5_fcc_ops, &ccache); |
problem = krb5_cc_gen_new(authctxt->krb5_ctx, &krb5_fcc_ops, &ccache); |
if (problem) |
if (problem) |
goto fail; |
goto fail; |
|
|
problem = krb5_cc_initialize(authctxt->krb5_ctx, ccache, |
problem = krb5_cc_initialize(authctxt->krb5_ctx, ccache, |
authctxt->krb5_user); |
authctxt->krb5_user); |
if (problem) |
if (problem) |
goto fail; |
goto fail; |
|
|
problem = krb5_rd_cred2(authctxt->krb5_ctx, authctxt->krb5_auth_ctx, |
problem = krb5_rd_cred2(authctxt->krb5_ctx, authctxt->krb5_auth_ctx, |
ccache, tgt); |
ccache, tgt); |
if (problem) |
if (problem) |
goto fail; |
goto fail; |
|
|
authctxt->krb5_fwd_ccache = ccache; |
authctxt->krb5_fwd_ccache = ccache; |
ccache = NULL; |
ccache = NULL; |
|
|
authctxt->krb5_ticket_file = (char *)krb5_cc_get_name(authctxt->krb5_ctx, authctxt->krb5_fwd_ccache); |
authctxt->krb5_ticket_file = (char *)krb5_cc_get_name(authctxt->krb5_ctx, authctxt->krb5_fwd_ccache); |
|
|
problem = krb5_unparse_name(authctxt->krb5_ctx, authctxt->krb5_user, |
problem = krb5_unparse_name(authctxt->krb5_ctx, authctxt->krb5_user, |
&pname); |
&pname); |
if (problem) |
if (problem) |
goto fail; |
goto fail; |
|
|
debug("Kerberos v5 TGT accepted (%s)", pname); |
debug("Kerberos v5 TGT accepted (%s)", pname); |
|
|
restore_uid(); |
restore_uid(); |
|
|
return (1); |
return (1); |
|
|
fail: |
fail: |
if (problem) |
if (problem) |
debug("Kerberos v5 TGT passing failed: %s", |
debug("Kerberos v5 TGT passing failed: %s", |
krb5_get_err_text(authctxt->krb5_ctx, problem)); |
krb5_get_err_text(authctxt->krb5_ctx, problem)); |
if (ccache) |
if (ccache) |
krb5_cc_destroy(authctxt->krb5_ctx, ccache); |
krb5_cc_destroy(authctxt->krb5_ctx, ccache); |
|
|
restore_uid(); |
restore_uid(); |
|
|
return (0); |
return (0); |
} |
} |
|
|
|
|
auth_krb5_password(Authctxt *authctxt, const char *password) |
auth_krb5_password(Authctxt *authctxt, const char *password) |
{ |
{ |
krb5_error_code problem; |
krb5_error_code problem; |
|
|
if (authctxt->pw == NULL) |
if (authctxt->pw == NULL) |
return (0); |
return (0); |
|
|
temporarily_use_uid(authctxt->pw); |
temporarily_use_uid(authctxt->pw); |
|
|
problem = krb5_init(authctxt); |
problem = krb5_init(authctxt); |
if (problem) |
if (problem) |
goto out; |
goto out; |
|
|
problem = krb5_parse_name(authctxt->krb5_ctx, authctxt->pw->pw_name, |
problem = krb5_parse_name(authctxt->krb5_ctx, authctxt->pw->pw_name, |
&authctxt->krb5_user); |
&authctxt->krb5_user); |
if (problem) |
if (problem) |
goto out; |
goto out; |
|
|
problem = krb5_cc_gen_new(authctxt->krb5_ctx, &krb5_mcc_ops, |
problem = krb5_cc_gen_new(authctxt->krb5_ctx, &krb5_mcc_ops, |
&authctxt->krb5_fwd_ccache); |
&authctxt->krb5_fwd_ccache); |
if (problem) |
if (problem) |
goto out; |
goto out; |
|
|
problem = krb5_cc_initialize(authctxt->krb5_ctx, |
problem = krb5_cc_initialize(authctxt->krb5_ctx, |
authctxt->krb5_fwd_ccache, authctxt->krb5_user); |
authctxt->krb5_fwd_ccache, authctxt->krb5_user); |
if (problem) |
if (problem) |
goto out; |
goto out; |
|
|
|
restore_uid(); |
problem = krb5_verify_user(authctxt->krb5_ctx, authctxt->krb5_user, |
problem = krb5_verify_user(authctxt->krb5_ctx, authctxt->krb5_user, |
authctxt->krb5_fwd_ccache, password, 1, NULL); |
authctxt->krb5_fwd_ccache, password, 1, NULL); |
|
temporarily_use_uid(authctxt->pw); |
|
|
if (problem) |
if (problem) |
goto out; |
goto out; |
|
|
authctxt->krb5_ticket_file = (char *)krb5_cc_get_name(authctxt->krb5_ctx, authctxt->krb5_fwd_ccache); |
authctxt->krb5_ticket_file = (char *)krb5_cc_get_name(authctxt->krb5_ctx, authctxt->krb5_fwd_ccache); |
|
|
out: |
out: |
restore_uid(); |
restore_uid(); |
|
|
if (problem) { |
if (problem) { |
debug("Kerberos password authentication failed: %s", |
if (authctxt->krb5_ctx != NULL) |
krb5_get_err_text(authctxt->krb5_ctx, problem)); |
debug("Kerberos password authentication failed: %s", |
|
krb5_get_err_text(authctxt->krb5_ctx, problem)); |
|
else |
|
debug("Kerberos password authentication failed: %d", |
|
problem); |
|
|
krb5_cleanup_proc(authctxt); |
krb5_cleanup_proc(authctxt); |
|
|
if (options.kerberos_or_local_passwd) |
if (options.kerberos_or_local_passwd) |
return (-1); |
return (-1); |
else |
else |
|
|
krb5_cleanup_proc(void *context) |
krb5_cleanup_proc(void *context) |
{ |
{ |
Authctxt *authctxt = (Authctxt *)context; |
Authctxt *authctxt = (Authctxt *)context; |
|
|
debug("krb5_cleanup_proc called"); |
debug("krb5_cleanup_proc called"); |
if (authctxt->krb5_fwd_ccache) { |
if (authctxt->krb5_fwd_ccache) { |
krb5_cc_destroy(authctxt->krb5_ctx, authctxt->krb5_fwd_ccache); |
krb5_cc_destroy(authctxt->krb5_ctx, authctxt->krb5_fwd_ccache); |