-
Notifications
You must be signed in to change notification settings - Fork 9
/
pam_nfc.c
138 lines (112 loc) · 3.35 KB
/
pam_nfc.c
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
/* pam_nfc module
* Copyright (C) 2009 Romuald Conty <[email protected]>
*
* Many thanks to Denis Bodor <[email protected]>
* Author of "crypt2g" which been used as template for this pam module.
*
* And many thanks to Roel Verdult <[email protected]>
* Author of "libnfc" which is the library this module based on.
*
* This program is free software; you can redistribute it and/or modify
* it under the terms of the GNU General Public License as published by
* the Free Software Foundation; either version 2 of the License, or
* (at your option) any later version.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU General Public License for more details.
*
* You should have received a copy of the GNU General Public License
* along with this program; if not, write to the Free Software
* Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA.
*
*/
#include <sys/stat.h>
#include <sys/types.h>
#include <pwd.h>
#include <stdarg.h>
#include <stdio.h>
#include <stdlib.h>
#include <string.h>
#include <syslog.h>
#include <unistd.h>
#if defined(HAVE_SYS_PERM_H)
#include <sys/perm.h>
#endif /* HAVE_SYS_PERM_H */
#if defined(HAVE_CRYPT_H)
#include <crypt.h>
#endif /* HAVE_CRYPT_H */
#include "nfcauth.h"
/*
* here, we make a definition for the externally accessible function
* in this file (this definition is required for static a module
* but strongly encouraged generally) it is used to instruct the
* modules include file to define the function prototypes.
*/
#define PAM_SM_AUTH
#if defined(HAVE_SECURITY_PAM_MODULES_H)
#include <security/pam_modules.h>
#endif /* HAVE_SECURITY_PAM_MODULES_H */
#if defined(HAVE_SECURITY_PAM__MACROS_H)
#include <security/_pam_macros.h>
#endif /* HAVE_SECURITY_PAM__MACROS_H */
#if defined(HAVE_SECURITY_OPENPAM_H)
# include <security/openpam.h>
#endif /* HAVE_SECURITY_OPENPAM_H */
#if defined(HAVE_SECURITY_PAM_APPL_H)
# include <security/pam_appl.h>
#endif /* HAVE_SECURITY_PAM_APPL_H */
/* some syslogging */
static void _pam_log ( int err, const char *format, ... )
{
va_list args;
va_start ( args, format );
openlog ( "pam_nfc", LOG_CONS|LOG_PID, LOG_AUTH );
vsyslog ( err, format, args );
va_end ( args );
closelog();
}
/* --- authentication management functions (only) --- */
PAM_EXTERN
int pam_sm_authenticate ( pam_handle_t *pamh,int flags,int argc
,const char **argv )
{
int retval = PAM_AUTH_ERR;
char confline[256];
const char *user = NULL;
retval = pam_get_user ( pamh, &user, NULL );
if ( retval != PAM_SUCCESS )
{
_pam_log ( LOG_ERR, "get user returned error: %s",
pam_strerror ( pamh,retval ) );
return retval;
}
if ( user == NULL || *user == '\0' )
{
_pam_log ( LOG_ERR, "username not known" );
return retval;
}
if (!(nfcauth_check ())) return PAM_SERVICE_ERR;
return (nfcauth_authorize (user)) ? PAM_SUCCESS : PAM_AUTH_ERR;
}
PAM_EXTERN
int pam_sm_setcred ( pam_handle_t *pamh,int flags,int argc
,const char **argv )
{
return PAM_SUCCESS;
}
#ifdef PAM_STATIC
/* static module data */
struct pam_module _pam_nfc_modstruct =
{
"pam_nfc",
pam_sm_authenticate,
pam_sm_setcred,
NULL,
NULL,
NULL,
NULL,
};
#endif
/* end of module definition */