[16800] | 1 | /* |
---|
| 2 | * Author: Tatu Ylonen <ylo@cs.hut.fi> |
---|
| 3 | * Copyright (c) 1995 Tatu Ylonen <ylo@cs.hut.fi>, Espoo, Finland |
---|
| 4 | * All rights reserved |
---|
| 5 | * Rhosts or /etc/hosts.equiv authentication combined with RSA host |
---|
| 6 | * authentication. |
---|
| 7 | * |
---|
| 8 | * As far as I am concerned, the code I have written for this software |
---|
| 9 | * can be used freely for any purpose. Any derived versions of this |
---|
| 10 | * software must be clearly marked as such, and if the derived work is |
---|
| 11 | * incompatible with the protocol description in the RFC file, it must be |
---|
| 12 | * called by a name other than "ssh" or "Secure Shell". |
---|
| 13 | */ |
---|
| 14 | |
---|
| 15 | #include "includes.h" |
---|
[18758] | 16 | RCSID("$OpenBSD: auth-rh-rsa.c,v 1.34 2002/03/25 09:25:06 markus Exp $"); |
---|
[16800] | 17 | |
---|
| 18 | #include "packet.h" |
---|
| 19 | #include "uidswap.h" |
---|
| 20 | #include "log.h" |
---|
| 21 | #include "servconf.h" |
---|
| 22 | #include "key.h" |
---|
| 23 | #include "hostfile.h" |
---|
| 24 | #include "pathnames.h" |
---|
| 25 | #include "auth.h" |
---|
| 26 | #include "canohost.h" |
---|
| 27 | |
---|
[18758] | 28 | #include "monitor_wrap.h" |
---|
[16800] | 29 | |
---|
[18758] | 30 | /* import */ |
---|
| 31 | extern ServerOptions options; |
---|
| 32 | |
---|
[16800] | 33 | int |
---|
[18758] | 34 | auth_rhosts_rsa_key_allowed(struct passwd *pw, char *cuser, char *chost, |
---|
| 35 | Key *client_host_key) |
---|
[16800] | 36 | { |
---|
| 37 | HostStatus host_status; |
---|
| 38 | |
---|
| 39 | /* Check if we would accept it using rhosts authentication. */ |
---|
[18758] | 40 | if (!auth_rhosts(pw, cuser)) |
---|
[16800] | 41 | return 0; |
---|
| 42 | |
---|
[18758] | 43 | host_status = check_key_in_hostfiles(pw, client_host_key, |
---|
| 44 | chost, _PATH_SSH_SYSTEM_HOSTFILE, |
---|
| 45 | options.ignore_user_known_hosts ? NULL : _PATH_SSH_USER_HOSTFILE); |
---|
[16800] | 46 | |
---|
[18758] | 47 | return (host_status == HOST_OK); |
---|
| 48 | } |
---|
[16800] | 49 | |
---|
[18758] | 50 | /* |
---|
| 51 | * Tries to authenticate the user using the .rhosts file and the host using |
---|
| 52 | * its host key. Returns true if authentication succeeds. |
---|
| 53 | */ |
---|
| 54 | int |
---|
| 55 | auth_rhosts_rsa(struct passwd *pw, char *cuser, Key *client_host_key) |
---|
| 56 | { |
---|
| 57 | char *chost; |
---|
[16800] | 58 | |
---|
[18758] | 59 | debug("Trying rhosts with RSA host authentication for client user %.100s", |
---|
| 60 | cuser); |
---|
[16800] | 61 | |
---|
[18758] | 62 | if (pw == NULL || client_host_key == NULL || |
---|
| 63 | client_host_key->rsa == NULL) |
---|
| 64 | return 0; |
---|
[16800] | 65 | |
---|
[18758] | 66 | chost = (char *)get_canonical_hostname(options.verify_reverse_mapping); |
---|
| 67 | debug("Rhosts RSA authentication: canonical host %.900s", chost); |
---|
| 68 | |
---|
| 69 | if (!PRIVSEP(auth_rhosts_rsa_key_allowed(pw, cuser, chost, client_host_key))) { |
---|
[16800] | 70 | debug("Rhosts with RSA host authentication denied: unknown or invalid host key"); |
---|
| 71 | packet_send_debug("Your host key cannot be verified: unknown or invalid host key."); |
---|
| 72 | return 0; |
---|
| 73 | } |
---|
| 74 | /* A matching host key was found and is known. */ |
---|
| 75 | |
---|
| 76 | /* Perform the challenge-response dialog with the client for the host key. */ |
---|
| 77 | if (!auth_rsa_challenge_dialog(client_host_key)) { |
---|
| 78 | log("Client on %.800s failed to respond correctly to host authentication.", |
---|
[18758] | 79 | chost); |
---|
[16800] | 80 | return 0; |
---|
| 81 | } |
---|
| 82 | /* |
---|
| 83 | * We have authenticated the user using .rhosts or /etc/hosts.equiv, |
---|
| 84 | * and the host using RSA. We accept the authentication. |
---|
| 85 | */ |
---|
| 86 | |
---|
| 87 | verbose("Rhosts with RSA host authentication accepted for %.100s, %.100s on %.700s.", |
---|
[18758] | 88 | pw->pw_name, cuser, chost); |
---|
[16800] | 89 | packet_send_debug("Rhosts with RSA host authentication accepted."); |
---|
| 90 | return 1; |
---|
| 91 | } |
---|