]> andersk Git - gssapi-openssh.git/blobdiff - openssh/auth-passwd.c
The man2html from jbasney on pkilab2 works whereas the standard one doesn't.
[gssapi-openssh.git] / openssh / auth-passwd.c
index 971c7ba19d9be09cc4efdd1d37f0c9dfc6c13f53..988297cb464a4bbd01a681bf17cf2771eab44665 100644 (file)
  */
 
 #include "includes.h"
-RCSID("$OpenBSD: auth-passwd.c,v 1.29 2003/08/26 09:58:43 markus Exp $");
+RCSID("$OpenBSD: auth-passwd.c,v 1.23 2001/06/26 16:15:23 dugsong Exp $");
+
+#if !defined(USE_PAM) && !defined(HAVE_OSF_SIA)
 
 #include "packet.h"
+#include "xmalloc.h"
 #include "log.h"
 #include "servconf.h"
 #include "auth.h"
+
+#ifdef HAVE_CRYPT_H
+# include <crypt.h>
+#endif
 #ifdef WITH_AIXAUTHENTICATE
-# include "buffer.h"
-# include "canohost.h"
-extern Buffer loginmsg;
+# include <login.h>
+#endif
+#ifdef __hpux
+# include <hpsecurity.h>
+# include <prot.h>
+#endif
+#ifdef HAVE_SCO_PROTECTED_PW
+# include <sys/security.h>
+# include <sys/audit.h>
+# include <prot.h>
+#endif /* HAVE_SCO_PROTECTED_PW */
+#if defined(HAVE_SHADOW_H) && !defined(DISABLE_SHADOW)
+# include <shadow.h>
+#endif
+#if defined(HAVE_GETPWANAM) && !defined(DISABLE_SHADOW)
+# include <sys/label.h>
+# include <sys/audit.h>
+# include <pwdadj.h>
+#endif
+#if defined(HAVE_MD5_PASSWORDS) && !defined(HAVE_MD5_CRYPT)
+# include "md5crypt.h"
+#endif /* defined(HAVE_MD5_PASSWORDS) && !defined(HAVE_MD5_CRYPT) */
+
+#ifdef HAVE_CYGWIN
+#undef ERROR
+#include <windows.h>
+#include <sys/cygwin.h>
+#define is_winnt       (GetVersion() < 0x80000000)
 #endif
 
+
 extern ServerOptions options;
 
 /*
@@ -58,106 +91,132 @@ int
 auth_password(Authctxt *authctxt, const char *password)
 {
        struct passwd * pw = authctxt->pw;
-       int ok = authctxt->valid;
+       char *encrypted_password;
+       char *pw_password;
+       char *salt;
+#ifdef __hpux
+       struct pr_passwd *spw;
+#endif
+#ifdef HAVE_SCO_PROTECTED_PW
+       struct pr_passwd *spw;
+#endif /* HAVE_SCO_PROTECTED_PW */
+#if defined(HAVE_SHADOW_H) && !defined(DISABLE_SHADOW)
+       struct spwd *spw;
+#endif
+#if defined(HAVE_GETPWANAM) && !defined(DISABLE_SHADOW)
+       struct passwd_adjunct *spw;
+#endif
+#ifdef WITH_AIXAUTHENTICATE
+       char *authmsg;
+       char *loginmsg;
+       int reenter = 1;
+#endif
 
        /* deny if no user. */
        if (pw == NULL)
                return 0;
 #ifndef HAVE_CYGWIN
-       if (pw && pw->pw_uid == 0 && options.permit_root_login != PERMIT_YES)
-               ok = 0;
+       if (pw->pw_uid == 0 && options.permit_root_login != PERMIT_YES)
+               return 0;
+#endif
+#ifdef HAVE_CYGWIN
+       /*
+        * Empty password is only possible on NT if the user has _really_
+        * an empty password and authentication is done, though.
+        */
+       if (!is_winnt)
 #endif
        if (*password == '\0' && options.permit_empty_passwd == 0)
                return 0;
-
-#if defined(HAVE_OSF_SIA)
-       return auth_sia_password(authctxt, password) && ok;
-#else
-# ifdef KRB5
+#ifdef KRB5
        if (options.kerberos_authentication == 1) {
                int ret = auth_krb5_password(authctxt, password);
                if (ret == 1 || ret == 0)
-                       return ret && ok;
+                       return ret;
                /* Fall back to ordinary passwd authentication. */
        }
-# endif
-# ifdef HAVE_CYGWIN
+#endif
+#ifdef HAVE_CYGWIN
        if (is_winnt) {
                HANDLE hToken = cygwin_logon_user(pw, password);
 
                if (hToken == INVALID_HANDLE_VALUE)
                        return 0;
                cygwin_set_impersonation_token(hToken);
-               return ok;
+               return 1;
        }
-# endif
-# ifdef WITH_AIXAUTHENTICATE
-       {
-               char *authmsg = NULL;
-               int reenter = 1;
-               int authsuccess = 0;
-
-               if (authenticate(pw->pw_name, password, &reenter,
-                   &authmsg) == 0 && ok) {
-                       char *msg;
-                       char *host = 
-                           (char *)get_canonical_hostname(options.use_dns);
-
-                       authsuccess = 1;
-                       aix_remove_embedded_newlines(authmsg);  
-
-                       debug3("AIX/authenticate succeeded for user %s: %.100s",
-                               pw->pw_name, authmsg);
-
-                       /* No pty yet, so just label the line as "ssh" */
-                       aix_setauthdb(authctxt->user);
-                       if (loginsuccess(authctxt->user, host, "ssh", 
-                           &msg) == 0) {
-                               if (msg != NULL) {
-                                       debug("%s: msg %s", __func__, msg);
-                                       buffer_append(&loginmsg, msg, 
-                                           strlen(msg));
-                                       xfree(msg);
-                               }
-                       }
-               } else {
-                       debug3("AIX/authenticate failed for user %s: %.100s",
-                           pw->pw_name, authmsg);
-               }
-
-               if (authmsg != NULL)
-                       xfree(authmsg);
-
-               return authsuccess;
+#endif
+#ifdef WITH_AIXAUTHENTICATE
+       return (authenticate(pw->pw_name,password,&reenter,&authmsg) == 0);
+#endif
+#ifdef KRB4
+       if (options.kerberos_authentication == 1) {
+               int ret = auth_krb4_password(authctxt, password);
+               if (ret == 1 || ret == 0)
+                       return ret;
+               /* Fall back to ordinary passwd authentication. */
        }
-# endif
-# ifdef BSD_AUTH
+#endif
+#ifdef BSD_AUTH
        if (auth_userokay(pw->pw_name, authctxt->style, "auth-ssh",
            (char *)password) == 0)
                return 0;
        else
-               return ok;
-# else
-       {
-       /* Just use the supplied fake password if authctxt is invalid */
-       char *pw_password = authctxt->valid ? shadow_pw(pw) : pw->pw_passwd;
+               return 1;
+#endif
+       pw_password = pw->pw_passwd;
+
+       /*
+        * Various interfaces to shadow or protected password data
+        */
+#if defined(HAVE_SHADOW_H) && !defined(DISABLE_SHADOW)
+       spw = getspnam(pw->pw_name);
+       if (spw != NULL)
+               pw_password = spw->sp_pwdp;
+#endif /* defined(HAVE_SHADOW_H) && !defined(DISABLE_SHADOW) */
+
+#ifdef HAVE_SCO_PROTECTED_PW
+       spw = getprpwnam(pw->pw_name);
+       if (spw != NULL)
+               pw_password = spw->ufld.fd_encrypt;
+#endif /* HAVE_SCO_PROTECTED_PW */
+
+#if defined(HAVE_GETPWANAM) && !defined(DISABLE_SHADOW)
+       if (issecure() && (spw = getpwanam(pw->pw_name)) != NULL)
+               pw_password = spw->pwa_passwd;
+#endif /* defined(HAVE_GETPWANAM) && !defined(DISABLE_SHADOW) */
+
+#if defined(__hpux)
+       if (iscomsec() && (spw = getprpwnam(pw->pw_name)) != NULL)
+               pw_password = spw->ufld.fd_encrypt;
+#endif /* defined(__hpux) */
 
        /* Check for users with no password. */
-       if (strcmp(pw_password, "") == 0 && strcmp(password, "") == 0)
-               return ok;
-       else {
-               /* Encrypt the candidate password using the proper salt. */
-               char *encrypted_password = xcrypt(password,
-                   (pw_password[0] && pw_password[1]) ? pw_password : "xx");
-
-               /*
-                * Authentication is accepted if the encrypted passwords
-                * are identical.
-                */
-               return (strcmp(encrypted_password, pw_password) == 0) && ok;
-       }
+       if ((password[0] == '\0') && (pw_password[0] == '\0'))
+               return 1;
 
-       }
-# endif
-#endif /* !HAVE_OSF_SIA */
+       if (pw_password[0] != '\0')
+               salt = pw_password;
+       else
+               salt = "xx";
+
+#ifdef HAVE_MD5_PASSWORDS
+       if (is_md5_salt(salt))
+               encrypted_password = md5_crypt(password, salt);
+       else
+               encrypted_password = crypt(password, salt);
+#else /* HAVE_MD5_PASSWORDS */
+# ifdef __hpux
+       if (iscomsec())
+               encrypted_password = bigcrypt(password, salt);
+       else
+               encrypted_password = crypt(password, salt);
+# else
+       encrypted_password = crypt(password, salt);
+# endif /* __hpux */
+#endif /* HAVE_MD5_PASSWORDS */
+
+       /* Authentication is accepted if the encrypted passwords are identical. */
+       return (strcmp(encrypted_password, pw_password) == 0);
 }
+#endif /* !USE_PAM && !HAVE_OSF_SIA */
This page took 0.38643 seconds and 4 git commands to generate.