|
ProtoCore v1.0.16
Deterministic, zero-heap network stack for embedded targets
|
RFC 4252 user authentication. More...
Go to the source code of this file.
Classes | |
| struct | SshAuthReq |
| Parsed SSH_MSG_USERAUTH_REQUEST. More... | |
| struct | SshAuthMsgArgs |
| Install the publickey-authorization callback (nullptr → all fail). More... | |
| struct | SshAuthOutArgs |
| Where a reply is written, either as a buffer or as a span. More... | |
| struct | SshUserauthArgs |
| RFC 4252 sec 5 / sec 7: the names one USERAUTH_REQUEST carries, and the key it offers. More... | |
| struct | SshAuthCbs |
| RFC 4252 sec 7 / sec 8: what an attempt of each method is checked against. More... | |
| struct | SshAuthVars |
| struct | SshAuthNs |
| The entries. More... | |
Typedefs | |
| typedef proto_bool(* | SshPasswordCb) (const char *user, const char *password) |
| Application callback that validates a username/password pair. | |
| typedef void(* | SshPasswordChangeCb) (uint8_t slot, const char *user, const char *old_password, const char *new_password) |
| Install the password-verification callback (nullptr → all fail). | |
| typedef proto_bool(* | SshPubkeyCb) (const char *user, const uint8_t *blob, size_t blob_len) |
| Drop a parked password change without replying to it. | |
Enumerations | |
| enum | SshPwChange { PROTOCORE_SSH_PW_CHANGE_NONE , PROTOCORE_SSH_PW_CHANGE_BUSY , PROTOCORE_SSH_PW_CHANGE_OK , PROTOCORE_SSH_PW_CHANGE_FAIL } |
| A slot's password-change state: idle, handed to the application, or finished either way. More... | |
Variables | |
| SshAuthVars | SshAuthV |
| The operands and the outcome. | |
RFC 4252 user authentication.
After NEWKEYS the client requests the "ssh-userauth" service; the server accepts it and then drives SSH_MSG_USERAUTH_REQUEST exchanges until a method succeeds or the connection is dropped. The "none" method is always answered with a failure that advertises what may continue (RFC 4252 sec 5.2), which is how a client discovers the supported methods.
Definition in file auth.h.
| typedef proto_bool(* SshPasswordCb) (const char *user, const char *password) |
| typedef void(* SshPasswordChangeCb) (uint8_t slot, const char *user, const char *old_password, const char *new_password) |
Install the password-verification callback (nullptr → all fail).
Application callback that STARTS a password change (RFC 4252 sec 8) for slot slot.
The application owns the store and its encryption, and a store can be slow (flash). This callback must not block: it copies what it needs, kicks off its own work, and returns. When the change has finished (or failed to verify old_password) the application reports the outcome with protocore_ssh_auth_pw_change_report(); the reply to the client is deferred until then, so the SSH worker is never held on the store. old_password / new_password are wiped once this returns.
| typedef proto_bool(* SshPubkeyCb) (const char *user, const uint8_t *blob, size_t blob_len) |
Drop a parked password change without replying to it.
RFC 4252 sec 5.1 sends SSH_MSG_USERAUTH_SUCCESS once, so a change whose answer arrives after some other method already succeeded is discarded rather than answered.
Drop slot i's half-finished authentication state and wipe its username.
A keyboard-interactive exchange is armed by the USERAUTH_REQUEST and consumed by the matching INFO_RESPONSE. A connection that leaves between the two ends here.
Application callback that decides whether a public key is authorized for user. blob is the "ssh-rsa" public-key blob.
| enum SshPwChange |
| SshPwChange protocore_ssh_auth_pw_change_take | ( | uint8_t | i | ) |
Install the password-change start callback (nullptr → change requests are refused busy).
Report the outcome of the change the start callback began for slot slot.
ok true when the old password verified and the new one was stored. Moves the slot to OK or FAIL, which the next poll drains into the deferred reply. A no-op when no change is in flight (a stale report after the connection left).
Take slot i's finished change outcome, clearing it back to NONE.
Write the "publickey" USERAUTH_REQUEST body that RFC 4252 sec 7 signs and sends.
sec 7 gives one field order and uses it twice: the signature covers
string session identifier byte SSH_MSG_USERAUTH_REQUEST string user name string service name string "publickey" boolean TRUE string public key algorithm name string public key to be used for authentication
and the request that carries the signature is the same bytes from SSH_MSG_USERAUTH_REQUEST on, with the signature appended. Writing it in one place is what keeps the two identical - a verifier hashes what arrived, so any divergence here is a signature that never validates.
| w | Span written into. |
| sid | Session identifier, or null to start at SSH_MSG_USERAUTH_REQUEST (the request form). |
| sid_len | Length of sid; ignored when sid is null. |
| user | User name. |
| service | Service name, normally "ssh-connection". |
| pk_algo | Public key algorithm name. |
| pk_blob | Public key blob. |
| pk_len | Length of pk_blob. |
True once slot i has gone too long without authenticating (RFC 4252 sec 4).
"The server SHOULD have a timeout for authentication and disconnect if the authentication has not been accepted within the timeout period. The RECOMMENDED timeout period is 10 minutes." The clock starts on the first call for a slot and stops once authentication completes; SSH_AUTH_TIMEOUT_MS of 0 disables it. Poll it, and disconnect when it answers true.
| void protocore_ssh_auth_set_password_cb | ( | uint8_t * | work | ) |
| void protocore_ssh_auth_set_password_change_cb | ( | uint8_t * | work | ) |
| void protocore_ssh_auth_set_pubkey_cb | ( | uint8_t * | work | ) |
| void protocore_ssh_auth_pw_change_report | ( | uint8_t * | work | ) |
| void protocore_ssh_auth_pw_change_clear | ( | uint8_t * | work | ) |
| void protocore_ssh_auth_passwd_change_reply | ( | uint8_t * | work | ) |
| void protocore_ssh_auth_write_publickey_request | ( | uint8_t * | work | ) |
| void protocore_ssh_auth_timed_out | ( | uint8_t * | work | ) |
| void protocore_ssh_auth_reset | ( | uint8_t * | work | ) |
| void protocore_ssh_auth_parse_request | ( | uint8_t * | work | ) |
| void protocore_ssh_auth_build_failure | ( | uint8_t * | work | ) |
| void protocore_ssh_auth_build_success | ( | uint8_t * | work | ) |
| void protocore_ssh_auth_handle_request | ( | uint8_t * | work | ) |
| void protocore_ssh_auth_dispatch | ( | uint8_t * | work | ) |
| uint8_t * protocore_ssh_auth_span | ( | void | ) |
The PROTOCORE_SSH_AUTH_BORROW bytes this module's state lives in.
Stated beside the namespace rather than on it: an entry takes a borrow, and this is where that borrow comes from. Taken once from the end of the pool, which no mark and no release walks, so the state lasts the life of the program.
|
extern |
The operands and the outcome.