diff options
author | Damien Miller <djm@mindrot.org> | 2003-05-14 13:47:37 +1000 |
---|---|---|
committer | Damien Miller <djm@mindrot.org> | 2003-05-14 13:47:37 +1000 |
commit | 3ab496b3dd961423bc5e312fd5dbbef975f4d238 (patch) | |
tree | ce75ad4df1cb1b5489d3fea1fdac5b3e13496aa8 /auth2-krb5.c | |
parent | fb7508edc8db9b5f445170237ec666beb3a3f6ac (diff) |
- markus@cvs.openbsd.org 2003/05/14 02:15:47
[auth2.c monitor.c sshconnect2.c auth2-krb5.c]
implement kerberos over ssh2 ("kerberos-2@ssh.com"); tested with jakob@
server interops with commercial client; ok jakob@ djm@
Diffstat (limited to 'auth2-krb5.c')
-rw-r--r-- | auth2-krb5.c | 66 |
1 files changed, 66 insertions, 0 deletions
diff --git a/auth2-krb5.c b/auth2-krb5.c new file mode 100644 index 000000000..ea4d76da0 --- /dev/null +++ b/auth2-krb5.c | |||
@@ -0,0 +1,66 @@ | |||
1 | /* | ||
2 | * Copyright (c) 2003 Markus Friedl. All rights reserved. | ||
3 | * | ||
4 | * Redistribution and use in source and binary forms, with or without | ||
5 | * modification, are permitted provided that the following conditions | ||
6 | * are met: | ||
7 | * 1. Redistributions of source code must retain the above copyright | ||
8 | * notice, this list of conditions and the following disclaimer. | ||
9 | * 2. Redistributions in binary form must reproduce the above copyright | ||
10 | * notice, this list of conditions and the following disclaimer in the | ||
11 | * documentation and/or other materials provided with the distribution. | ||
12 | * | ||
13 | * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR | ||
14 | * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES | ||
15 | * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. | ||
16 | * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT, | ||
17 | * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT | ||
18 | * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, | ||
19 | * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY | ||
20 | * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT | ||
21 | * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF | ||
22 | * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. | ||
23 | */ | ||
24 | |||
25 | #include "includes.h" | ||
26 | RCSID("$OpenBSD: auth2-krb5.c,v 1.1 2003/05/14 02:15:47 markus Exp $"); | ||
27 | |||
28 | #include <krb5.h> | ||
29 | |||
30 | #include "ssh2.h" | ||
31 | #include "xmalloc.h" | ||
32 | #include "packet.h" | ||
33 | #include "log.h" | ||
34 | #include "auth.h" | ||
35 | #include "monitor_wrap.h" | ||
36 | #include "servconf.h" | ||
37 | |||
38 | /* import */ | ||
39 | extern ServerOptions options; | ||
40 | |||
41 | static int | ||
42 | userauth_kerberos(Authctxt *authctxt) | ||
43 | { | ||
44 | krb5_data tkt, reply; | ||
45 | char *client = NULL; | ||
46 | int authenticated = 0; | ||
47 | |||
48 | tkt.data = packet_get_string(&tkt.length); | ||
49 | packet_check_eom(); | ||
50 | |||
51 | if (PRIVSEP(auth_krb5(authctxt, &tkt, &client, &reply))) { | ||
52 | authenticated = 1; | ||
53 | if (reply.length) | ||
54 | xfree(reply.data); | ||
55 | } | ||
56 | if (client) | ||
57 | xfree(client); | ||
58 | xfree(tkt.data); | ||
59 | return (authenticated); | ||
60 | } | ||
61 | |||
62 | Authmethod method_kerberos = { | ||
63 | "kerberos-2@ssh.com", | ||
64 | userauth_kerberos, | ||
65 | &options.kerberos_authentication | ||
66 | }; | ||