11305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood/* $OpenBSD: auth2-passwd.c,v 1.9 2006/08/03 03:34:41 deraadt Exp $ */
21305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood/*
31305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood * Copyright (c) 2000 Markus Friedl.  All rights reserved.
41305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood *
51305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood * Redistribution and use in source and binary forms, with or without
61305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood * modification, are permitted provided that the following conditions
71305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood * are met:
81305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood * 1. Redistributions of source code must retain the above copyright
91305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood *    notice, this list of conditions and the following disclaimer.
101305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood * 2. Redistributions in binary form must reproduce the above copyright
111305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood *    notice, this list of conditions and the following disclaimer in the
121305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood *    documentation and/or other materials provided with the distribution.
131305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood *
141305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
151305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
161305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
171305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
181305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
191305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
201305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
211305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
221305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
231305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
241305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood */
251305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood
261305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood#include "includes.h"
271305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood
281305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood#include <sys/types.h>
291305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood
301305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood#include <string.h>
311305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood#include <stdarg.h>
321305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood
331305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood#include "xmalloc.h"
341305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood#include "packet.h"
351305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood#include "log.h"
361305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood#include "key.h"
371305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood#include "hostfile.h"
381305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood#include "auth.h"
391305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood#include "buffer.h"
401305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood#ifdef GSSAPI
411305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood#include "ssh-gss.h"
421305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood#endif
431305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood#include "monitor_wrap.h"
441305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood#include "servconf.h"
451305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood
461305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood/* import */
471305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwoodextern ServerOptions options;
481305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood
491305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwoodstatic int
501305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwooduserauth_passwd(Authctxt *authctxt)
511305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood{
521305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood	char *password, *newpass;
531305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood	int authenticated = 0;
541305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood	int change;
551305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood	u_int len, newlen;
561305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood
571305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood	change = packet_get_char();
581305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood	password = packet_get_string(&len);
591305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood	if (change) {
601305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood		/* discard new password from packet */
611305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood		newpass = packet_get_string(&newlen);
621305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood		memset(newpass, 0, newlen);
631305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood		xfree(newpass);
641305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood	}
651305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood	packet_check_eom();
661305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood
671305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood	if (change)
681305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood		logit("password change not supported");
691b6cc98e30329f380546d5f22b1c9c975e3df4f8Mike Lockwood#ifndef ANDROID
701b6cc98e30329f380546d5f22b1c9c975e3df4f8Mike Lockwood	/* no password authentication in android */
711305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood	else if (PRIVSEP(auth_password(authctxt, password)) == 1)
721305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood		authenticated = 1;
731b6cc98e30329f380546d5f22b1c9c975e3df4f8Mike Lockwood#endif
741305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood	memset(password, 0, len);
751305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood	xfree(password);
761305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood	return authenticated;
771305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood}
781305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood
791305e95ba6ff9fa202d0818caf10405df4b0f648Mike LockwoodAuthmethod method_passwd = {
801305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood	"password",
811305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood	userauth_passwd,
821305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood	&options.password_authentication
831305e95ba6ff9fa202d0818caf10405df4b0f648Mike Lockwood};
84