mirror of
git://anongit.mindrot.org/openssh.git
synced 2024-11-23 18:23:25 +08:00
eba71bab9b
[README.openssh2] - interop w/ F-secure windows client - sync documentation - ssh_host_dsa_key not ssh_dsa_key [auth-rsa.c] - missing fclose [auth.c authfile.c compat.c dsa.c dsa.h hostfile.c key.c key.h radix.c] [readconf.c readconf.h ssh-add.c ssh-keygen.c ssh.c ssh.h sshconnect.c] [sshd.c uuencode.c uuencode.h authfile.h] - add DSA pubkey auth and other SSH2 fixes. use ssh-keygen -[xX] for trading keys with the real and the original SSH, directly from the people who invented the SSH protocol. [auth.c auth.h authfile.c sshconnect.c auth1.c auth2.c sshconnect.h] [sshconnect1.c sshconnect2.c] - split auth/sshconnect in one file per protocol version [sshconnect2.c] - remove debug [uuencode.c] - add trailing = [version.h] - OpenSSH-2.0 [ssh-keygen.1 ssh-keygen.c] - add -R flag: exit code indicates if RSA is alive [sshd.c] - remove unused silent if -Q is specified [ssh.h] - host key becomes /etc/ssh_host_dsa_key [readconf.c servconf.c ] - ssh/sshd default to proto 1 and 2 [uuencode.c] - remove debug [auth2.c ssh-keygen.c sshconnect2.c sshd.c] - xfree DSA blobs [auth2.c serverloop.c session.c] - cleanup logging for sshd/2, respect PasswordAuth no [sshconnect2.c] - less debug, respect .ssh/config [README.openssh2 channels.c channels.h] - clientloop.c session.c ssh.c - support for x11-fwding, client+server
121 lines
3.2 KiB
C
121 lines
3.2 KiB
C
/*
|
|
* Copyright (c) 1995 Tatu Ylonen <ylo@cs.hut.fi>, Espoo, Finland
|
|
* All rights reserved
|
|
* Copyright (c) 2000 Markus Friedl. All rights reserved.
|
|
*/
|
|
|
|
#include "includes.h"
|
|
RCSID("$OpenBSD: auth.c,v 1.6 2000/04/26 21:28:31 markus Exp $");
|
|
|
|
#include "xmalloc.h"
|
|
#include "rsa.h"
|
|
#include "ssh.h"
|
|
#include "pty.h"
|
|
#include "packet.h"
|
|
#include "buffer.h"
|
|
#include "cipher.h"
|
|
#include "mpaux.h"
|
|
#include "servconf.h"
|
|
#include "compat.h"
|
|
#include "channels.h"
|
|
#include "match.h"
|
|
|
|
#include "bufaux.h"
|
|
#include "ssh2.h"
|
|
#include "auth.h"
|
|
#include "session.h"
|
|
#include "dispatch.h"
|
|
|
|
|
|
/* import */
|
|
extern ServerOptions options;
|
|
extern char *forced_command;
|
|
|
|
/*
|
|
* Check if the user is allowed to log in via ssh. If user is listed in
|
|
* DenyUsers or user's primary group is listed in DenyGroups, false will
|
|
* be returned. If AllowUsers isn't empty and user isn't listed there, or
|
|
* if AllowGroups isn't empty and user isn't listed there, false will be
|
|
* returned.
|
|
* If the user's shell is not executable, false will be returned.
|
|
* Otherwise true is returned.
|
|
*/
|
|
int
|
|
allowed_user(struct passwd * pw)
|
|
{
|
|
struct stat st;
|
|
struct group *grp;
|
|
int i;
|
|
#ifdef WITH_AIXAUTHENTICATE
|
|
char *loginmsg;
|
|
#endif /* WITH_AIXAUTHENTICATE */
|
|
|
|
/* Shouldn't be called if pw is NULL, but better safe than sorry... */
|
|
if (!pw)
|
|
return 0;
|
|
|
|
/* deny if shell does not exists or is not executable */
|
|
if (stat(pw->pw_shell, &st) != 0)
|
|
return 0;
|
|
if (!((st.st_mode & S_IFREG) && (st.st_mode & (S_IXOTH|S_IXUSR|S_IXGRP))))
|
|
return 0;
|
|
|
|
/* Return false if user is listed in DenyUsers */
|
|
if (options.num_deny_users > 0) {
|
|
if (!pw->pw_name)
|
|
return 0;
|
|
for (i = 0; i < options.num_deny_users; i++)
|
|
if (match_pattern(pw->pw_name, options.deny_users[i]))
|
|
return 0;
|
|
}
|
|
/* Return false if AllowUsers isn't empty and user isn't listed there */
|
|
if (options.num_allow_users > 0) {
|
|
if (!pw->pw_name)
|
|
return 0;
|
|
for (i = 0; i < options.num_allow_users; i++)
|
|
if (match_pattern(pw->pw_name, options.allow_users[i]))
|
|
break;
|
|
/* i < options.num_allow_users iff we break for loop */
|
|
if (i >= options.num_allow_users)
|
|
return 0;
|
|
}
|
|
/* Get the primary group name if we need it. Return false if it fails */
|
|
if (options.num_deny_groups > 0 || options.num_allow_groups > 0) {
|
|
grp = getgrgid(pw->pw_gid);
|
|
if (!grp)
|
|
return 0;
|
|
|
|
/* Return false if user's group is listed in DenyGroups */
|
|
if (options.num_deny_groups > 0) {
|
|
if (!grp->gr_name)
|
|
return 0;
|
|
for (i = 0; i < options.num_deny_groups; i++)
|
|
if (match_pattern(grp->gr_name, options.deny_groups[i]))
|
|
return 0;
|
|
}
|
|
/*
|
|
* Return false if AllowGroups isn't empty and user's group
|
|
* isn't listed there
|
|
*/
|
|
if (options.num_allow_groups > 0) {
|
|
if (!grp->gr_name)
|
|
return 0;
|
|
for (i = 0; i < options.num_allow_groups; i++)
|
|
if (match_pattern(grp->gr_name, options.allow_groups[i]))
|
|
break;
|
|
/* i < options.num_allow_groups iff we break for
|
|
loop */
|
|
if (i >= options.num_allow_groups)
|
|
return 0;
|
|
}
|
|
}
|
|
|
|
#ifdef WITH_AIXAUTHENTICATE
|
|
if (loginrestrictions(pw->pw_name,S_LOGIN,NULL,&loginmsg) != 0)
|
|
return 0;
|
|
#endif /* WITH_AIXAUTHENTICATE */
|
|
|
|
/* We found no reason not to let this user try to log on... */
|
|
return 1;
|
|
}
|