author | Tomas Kuthan <tomas.kuthan@oracle.com> |
Thu, 18 Jun 2015 07:01:42 -0700 | |
changeset 4503 | bf30d46ab06e |
parent 4130 | b2f7921b1d1c |
child 5818 | 5f0e7a0f17c2 |
permissions | -rw-r--r-- |
4130
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
1 |
# |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
2 |
# Enable login to a role for hostbased authentication if allowed by PAM. |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
3 |
# |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
4 |
# Sets PAM_AUSER item to user who is asserting a new identity before |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
5 |
# calling do_pam_account(). Implemented using existing static variable |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
6 |
# hostbased_cuser. The change is protected by new HAVE_PAM_AUSER ifdef-guard, |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
7 |
# which is set to defined on Solaris. |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
8 |
# |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
9 |
# Patch offered upstream: |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
10 |
# https://bugzilla.mindrot.org/show_bug.cgi?id=2378 |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
11 |
# |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
12 |
diff -pur old/auth-pam.c new/auth-pam.c |
4503
bf30d46ab06e
PSARC/2015/179 OpenSSH 6.8
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
4130
diff
changeset
|
13 |
--- old/auth-pam.c 2015-05-21 04:08:41.910932322 -0700 |
bf30d46ab06e
PSARC/2015/179 OpenSSH 6.8
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
4130
diff
changeset
|
14 |
+++ new/auth-pam.c 2015-05-21 04:08:42.024831668 -0700 |
4130
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
15 |
@@ -1038,6 +1038,20 @@ do_pam_account(void) |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
16 |
return (sshpam_account_status); |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
17 |
} |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
18 |
|
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
19 |
+#ifdef HAVE_PAM_AUSER |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
20 |
+void |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
21 |
+do_pam_set_auser(const char* auser) |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
22 |
+{ |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
23 |
+ if (auser != NULL) { |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
24 |
+ debug("PAM: setting PAM_AUSER to \"%s\"", auser); |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
25 |
+ sshpam_err = pam_set_item(sshpam_handle, PAM_AUSER, auser); |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
26 |
+ if (sshpam_err != PAM_SUCCESS) |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
27 |
+ error("PAM: failed to set PAM_AUSER: %s", |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
28 |
+ pam_strerror(sshpam_handle, sshpam_err)); |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
29 |
+ } |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
30 |
+} |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
31 |
+#endif |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
32 |
+ |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
33 |
void |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
34 |
do_pam_set_tty(const char *tty) |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
35 |
{ |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
36 |
diff -pur old/auth-pam.h new/auth-pam.h |
4503
bf30d46ab06e
PSARC/2015/179 OpenSSH 6.8
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
4130
diff
changeset
|
37 |
--- old/auth-pam.h 2015-03-16 22:49:20.000000000 -0700 |
bf30d46ab06e
PSARC/2015/179 OpenSSH 6.8
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
4130
diff
changeset
|
38 |
+++ new/auth-pam.h 2015-05-21 04:08:42.025160216 -0700 |
4130
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
39 |
@@ -35,6 +35,9 @@ void start_pam(Authctxt *); |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
40 |
void finish_pam(void); |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
41 |
u_int do_pam_account(void); |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
42 |
void do_pam_session(void); |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
43 |
+#ifdef HAVE_PAM_AUSER |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
44 |
+void do_pam_set_auser(const char *); |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
45 |
+#endif |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
46 |
void do_pam_set_tty(const char *); |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
47 |
void do_pam_setcred(int ); |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
48 |
void do_pam_chauthtok(void); |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
49 |
diff -pur old/auth.h new/auth.h |
4503
bf30d46ab06e
PSARC/2015/179 OpenSSH 6.8
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
4130
diff
changeset
|
50 |
--- old/auth.h 2015-05-21 04:08:41.911346027 -0700 |
bf30d46ab06e
PSARC/2015/179 OpenSSH 6.8
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
4130
diff
changeset
|
51 |
+++ new/auth.h 2015-05-21 04:08:42.025504068 -0700 |
bf30d46ab06e
PSARC/2015/179 OpenSSH 6.8
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
4130
diff
changeset
|
52 |
@@ -84,6 +84,9 @@ struct Authctxt { |
4130
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
53 |
#ifdef PAM_ENHANCEMENT |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
54 |
char *authmethod_name; |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
55 |
#endif |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
56 |
+#ifdef HAVE_PAM_AUSER |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
57 |
+ char *auser; |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
58 |
+#endif |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
59 |
}; |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
60 |
/* |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
61 |
* Every authentication method has to handle authentication requests for |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
62 |
diff -pur old/auth2-hostbased.c new/auth2-hostbased.c |
4503
bf30d46ab06e
PSARC/2015/179 OpenSSH 6.8
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
4130
diff
changeset
|
63 |
--- old/auth2-hostbased.c 2015-03-16 22:49:20.000000000 -0700 |
bf30d46ab06e
PSARC/2015/179 OpenSSH 6.8
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
4130
diff
changeset
|
64 |
+++ new/auth2-hostbased.c 2015-05-21 04:08:42.026208843 -0700 |
bf30d46ab06e
PSARC/2015/179 OpenSSH 6.8
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
4130
diff
changeset
|
65 |
@@ -85,6 +85,9 @@ userauth_hostbased(Authctxt *authctxt) |
4130
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
66 |
buffer_dump(&b); |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
67 |
buffer_free(&b); |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
68 |
#endif |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
69 |
+#ifdef HAVE_PAM_AUSER |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
70 |
+ authctxt->auser = NULL; |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
71 |
+#endif |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
72 |
pktype = key_type_from_name(pkalg); |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
73 |
if (pktype == KEY_UNSPEC) { |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
74 |
/* this is perfectly legal */ |
4503
bf30d46ab06e
PSARC/2015/179 OpenSSH 6.8
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
4130
diff
changeset
|
75 |
@@ -143,6 +146,13 @@ userauth_hostbased(Authctxt *authctxt) |
4130
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
76 |
buffer_len(&b))) == 1) |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
77 |
authenticated = 1; |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
78 |
|
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
79 |
+#ifdef HAVE_PAM_AUSER |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
80 |
+ if (authenticated) { |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
81 |
+ authctxt->auser = cuser; |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
82 |
+ cuser = NULL; |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
83 |
+ } |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
84 |
+#endif |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
85 |
+ |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
86 |
buffer_free(&b); |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
87 |
done: |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
88 |
debug2("userauth_hostbased: authenticated %d", authenticated); |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
89 |
diff -pur old/auth2.c new/auth2.c |
4503
bf30d46ab06e
PSARC/2015/179 OpenSSH 6.8
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
4130
diff
changeset
|
90 |
--- old/auth2.c 2015-05-21 04:08:41.947286493 -0700 |
bf30d46ab06e
PSARC/2015/179 OpenSSH 6.8
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
4130
diff
changeset
|
91 |
+++ new/auth2.c 2015-05-21 04:08:42.026846014 -0700 |
bf30d46ab06e
PSARC/2015/179 OpenSSH 6.8
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
4130
diff
changeset
|
92 |
@@ -339,6 +339,14 @@ userauth_finish(Authctxt *authctxt, int |
4130
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
93 |
#endif |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
94 |
} |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
95 |
|
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
96 |
+#ifdef HAVE_PAM_AUSER |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
97 |
+ if (!use_privsep) { |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
98 |
+ do_pam_set_auser(authctxt->auser); |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
99 |
+ free(authctxt->auser); |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
100 |
+ authctxt->auser = NULL; |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
101 |
+ } |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
102 |
+#endif |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
103 |
+ |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
104 |
if (authenticated && options.num_auth_methods != 0) { |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
105 |
|
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
106 |
#if defined(USE_PAM) && defined(PAM_ENHANCEMENT) |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
107 |
diff -pur old/config.h.in new/config.h.in |
4503
bf30d46ab06e
PSARC/2015/179 OpenSSH 6.8
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
4130
diff
changeset
|
108 |
--- old/config.h.in 2015-05-21 04:08:41.938119429 -0700 |
bf30d46ab06e
PSARC/2015/179 OpenSSH 6.8
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
4130
diff
changeset
|
109 |
+++ new/config.h.in 2015-05-21 04:08:42.027796887 -0700 |
bf30d46ab06e
PSARC/2015/179 OpenSSH 6.8
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
4130
diff
changeset
|
110 |
@@ -827,6 +827,9 @@ |
4130
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
111 |
/* Define if you have Digital Unix Security Integration Architecture */ |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
112 |
#undef HAVE_OSF_SIA |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
113 |
|
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
114 |
+/* Define if you have PAM_AUSER PAM item */ |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
115 |
+#undef HAVE_PAM_AUSER |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
116 |
+ |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
117 |
/* Define to 1 if you have the `pam_getenvlist' function. */ |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
118 |
#undef HAVE_PAM_GETENVLIST |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
119 |
|
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
120 |
diff -pur old/configure new/configure |
4503
bf30d46ab06e
PSARC/2015/179 OpenSSH 6.8
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
4130
diff
changeset
|
121 |
--- old/configure 2015-05-21 04:08:41.952127851 -0700 |
bf30d46ab06e
PSARC/2015/179 OpenSSH 6.8
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
4130
diff
changeset
|
122 |
+++ new/configure 2015-05-21 04:09:34.214165539 -0700 |
bf30d46ab06e
PSARC/2015/179 OpenSSH 6.8
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
4130
diff
changeset
|
123 |
@@ -10872,6 +10872,7 @@ fi |
bf30d46ab06e
PSARC/2015/179 OpenSSH 6.8
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
4130
diff
changeset
|
124 |
cat >>confdefs.h <<\_ACEOF |
bf30d46ab06e
PSARC/2015/179 OpenSSH 6.8
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
4130
diff
changeset
|
125 |
#define USE_GSS_STORE_CRED 1 |
bf30d46ab06e
PSARC/2015/179 OpenSSH 6.8
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
4130
diff
changeset
|
126 |
#define GSSAPI_STORECREDS_NEEDS_RUID 1 |
bf30d46ab06e
PSARC/2015/179 OpenSSH 6.8
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
4130
diff
changeset
|
127 |
+#define HAVE_PAM_AUSER 1 |
bf30d46ab06e
PSARC/2015/179 OpenSSH 6.8
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
4130
diff
changeset
|
128 |
_ACEOF |
4130
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
129 |
|
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
130 |
TEST_SHELL=$SHELL # let configure find us a capable shell |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
131 |
diff -pur old/configure.ac new/configure.ac |
4503
bf30d46ab06e
PSARC/2015/179 OpenSSH 6.8
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
4130
diff
changeset
|
132 |
--- old/configure.ac 2015-05-21 04:08:41.886514252 -0700 |
bf30d46ab06e
PSARC/2015/179 OpenSSH 6.8
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
4130
diff
changeset
|
133 |
+++ new/configure.ac 2015-05-21 04:08:42.052981088 -0700 |
bf30d46ab06e
PSARC/2015/179 OpenSSH 6.8
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
4130
diff
changeset
|
134 |
@@ -904,6 +904,7 @@ mips-sony-bsd|mips-sony-newsos4) |
4130
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
135 |
TEST_SHELL=$SHELL # let configure find us a capable shell |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
136 |
AC_DEFINE([USE_GSS_STORE_CRED]) |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
137 |
AC_DEFINE([GSSAPI_STORECREDS_NEEDS_RUID]) |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
138 |
+ AC_DEFINE([HAVE_PAM_AUSER]) |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
139 |
;; |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
140 |
*-*-sunos4*) |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
141 |
CPPFLAGS="$CPPFLAGS -DSUNOS4" |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
142 |
diff -pur old/monitor.c new/monitor.c |
4503
bf30d46ab06e
PSARC/2015/179 OpenSSH 6.8
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
4130
diff
changeset
|
143 |
--- old/monitor.c 2015-05-21 04:08:41.964048305 -0700 |
bf30d46ab06e
PSARC/2015/179 OpenSSH 6.8
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
4130
diff
changeset
|
144 |
+++ new/monitor.c 2015-05-21 04:08:42.054374639 -0700 |
bf30d46ab06e
PSARC/2015/179 OpenSSH 6.8
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
4130
diff
changeset
|
145 |
@@ -461,6 +461,12 @@ monitor_child_preauth(Authctxt *_authctx |
bf30d46ab06e
PSARC/2015/179 OpenSSH 6.8
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
4130
diff
changeset
|
146 |
} |
4130
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
147 |
} |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
148 |
|
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
149 |
+#if defined(HAVE_PAM_AUSER) && defined(USE_PAM) |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
150 |
+ if (hostbased_cuser != NULL) { |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
151 |
+ free(hostbased_cuser); |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
152 |
+ hostbased_cuser = NULL; |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
153 |
+ } |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
154 |
+#endif |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
155 |
if (!authctxt->valid) |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
156 |
fatal("%s: authenticated invalid user", __func__); |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
157 |
if (strcmp(auth_method, "unknown") == 0) |
4503
bf30d46ab06e
PSARC/2015/179 OpenSSH 6.8
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
4130
diff
changeset
|
158 |
@@ -694,12 +700,14 @@ monitor_reset_key_state(void) |
4130
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
159 |
{ |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
160 |
/* reset state */ |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
161 |
free(key_blob); |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
162 |
+#if !defined(HAVE_PAM_AUSER) || !defined(USE_PAM) |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
163 |
free(hostbased_cuser); |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
164 |
+ hostbased_cuser = NULL; |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
165 |
+#endif |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
166 |
free(hostbased_chost); |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
167 |
key_blob = NULL; |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
168 |
key_bloblen = 0; |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
169 |
key_blobtype = MM_NOKEY; |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
170 |
- hostbased_cuser = NULL; |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
171 |
hostbased_chost = NULL; |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
172 |
} |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
173 |
|
4503
bf30d46ab06e
PSARC/2015/179 OpenSSH 6.8
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
4130
diff
changeset
|
174 |
@@ -1146,6 +1154,11 @@ mm_answer_pam_account(int sock, Buffer * |
4130
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
175 |
if (!options.use_pam) |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
176 |
fatal("UsePAM not set, but ended up in %s anyway", __func__); |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
177 |
|
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
178 |
+#ifdef HAVE_PAM_AUSER |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
179 |
+ if (hostbased_cuser != NULL) |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
180 |
+ do_pam_set_auser(hostbased_cuser); |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
181 |
+#endif |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
182 |
+ |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
183 |
ret = do_pam_account(); |
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
184 |
|
b2f7921b1d1c
20711463 OpenSSH wants to be able to login to a role too
Tomas Kuthan <tomas.kuthan@oracle.com>
parents:
diff
changeset
|
185 |
buffer_put_int(m, ret); |