ProtoCore v1.0.16
Deterministic, zero-heap network stack for embedded targets
Loading...
Searching...
No Matches
auth.h File Reference

RFC 4252 user authentication. More...

Go to the source code of this file.

Classes

struct  SshAuthReq
 Parsed SSH_MSG_USERAUTH_REQUEST. More...
 
struct  SshAuthMsgArgs
 Install the publickey-authorization callback (nullptr → all fail). More...
 
struct  SshAuthOutArgs
 Where a reply is written, either as a buffer or as a span. More...
 
struct  SshUserauthArgs
 RFC 4252 sec 5 / sec 7: the names one USERAUTH_REQUEST carries, and the key it offers. More...
 
struct  SshAuthCbs
 RFC 4252 sec 7 / sec 8: what an attempt of each method is checked against. More...
 
struct  SshAuthVars
 
struct  SshAuthNs
 The entries. More...
 

Typedefs

typedef proto_bool(* SshPasswordCb) (const char *user, const char *password)
 Application callback that validates a username/password pair.
 
typedef void(* SshPasswordChangeCb) (uint8_t slot, const char *user, const char *old_password, const char *new_password)
 Install the password-verification callback (nullptr → all fail).
 
typedef proto_bool(* SshPubkeyCb) (const char *user, const uint8_t *blob, size_t blob_len)
 Drop a parked password change without replying to it.
 

Enumerations

enum  SshPwChange { PROTOCORE_SSH_PW_CHANGE_NONE , PROTOCORE_SSH_PW_CHANGE_BUSY , PROTOCORE_SSH_PW_CHANGE_OK , PROTOCORE_SSH_PW_CHANGE_FAIL }
 A slot's password-change state: idle, handed to the application, or finished either way. More...
 

Functions

SshPwChange protocore_ssh_auth_pw_change_take (uint8_t i)
 Install the password-change start callback (nullptr → change requests are refused busy).
 
void protocore_ssh_auth_set_password_cb (uint8_t *work)
 
void protocore_ssh_auth_set_password_change_cb (uint8_t *work)
 
void protocore_ssh_auth_set_pubkey_cb (uint8_t *work)
 
void protocore_ssh_auth_pw_change_report (uint8_t *work)
 
void protocore_ssh_auth_pw_change_clear (uint8_t *work)
 
void protocore_ssh_auth_passwd_change_reply (uint8_t *work)
 
void protocore_ssh_auth_write_publickey_request (uint8_t *work)
 
void protocore_ssh_auth_timed_out (uint8_t *work)
 
void protocore_ssh_auth_reset (uint8_t *work)
 
void protocore_ssh_auth_parse_request (uint8_t *work)
 
void protocore_ssh_auth_build_failure (uint8_t *work)
 
void protocore_ssh_auth_build_success (uint8_t *work)
 
void protocore_ssh_auth_handle_request (uint8_t *work)
 
void protocore_ssh_auth_dispatch (uint8_t *work)
 
uint8_t * protocore_ssh_auth_span (void)
 The PROTOCORE_SSH_AUTH_BORROW bytes this module's state lives in.
 

Variables

SshAuthVars SshAuthV
 The operands and the outcome.
 

Detailed Description

RFC 4252 user authentication.

After NEWKEYS the client requests the "ssh-userauth" service; the server accepts it and then drives SSH_MSG_USERAUTH_REQUEST exchanges until a method succeeds or the connection is dropped. The "none" method is always answered with a failure that advertises what may continue (RFC 4252 sec 5.2), which is how a client discovers the supported methods.

Definition in file auth.h.

Typedef Documentation

◆ SshPasswordCb

typedef proto_bool(* SshPasswordCb) (const char *user, const char *password)

Application callback that validates a username/password pair.

Returns
true to accept the credentials.

Definition at line 49 of file auth.h.

◆ SshPasswordChangeCb

typedef void(* SshPasswordChangeCb) (uint8_t slot, const char *user, const char *old_password, const char *new_password)

Install the password-verification callback (nullptr → all fail).

Application callback that STARTS a password change (RFC 4252 sec 8) for slot slot.

The application owns the store and its encryption, and a store can be slow (flash). This callback must not block: it copies what it needs, kicks off its own work, and returns. When the change has finished (or failed to verify old_password) the application reports the outcome with protocore_ssh_auth_pw_change_report(); the reply to the client is deferred until then, so the SSH worker is never held on the store. old_password / new_password are wiped once this returns.

Definition at line 62 of file auth.h.

◆ SshPubkeyCb

typedef proto_bool(* SshPubkeyCb) (const char *user, const uint8_t *blob, size_t blob_len)

Drop a parked password change without replying to it.

RFC 4252 sec 5.1 sends SSH_MSG_USERAUTH_SUCCESS once, so a change whose answer arrives after some other method already succeeded is discarded rather than answered.

Drop slot i's half-finished authentication state and wipe its username.

A keyboard-interactive exchange is armed by the USERAUTH_REQUEST and consumed by the matching INFO_RESPONSE. A connection that leaves between the two ends here.

Application callback that decides whether a public key is authorized for user. blob is the "ssh-rsa" public-key blob.

Returns
true if the key may authenticate this user.

Definition at line 146 of file auth.h.

Enumeration Type Documentation

◆ SshPwChange

A slot's password-change state: idle, handed to the application, or finished either way.

Enumerator
PROTOCORE_SSH_PW_CHANGE_NONE 
PROTOCORE_SSH_PW_CHANGE_BUSY 
PROTOCORE_SSH_PW_CHANGE_OK 
PROTOCORE_SSH_PW_CHANGE_FAIL 

Definition at line 65 of file auth.h.

Function Documentation

◆ protocore_ssh_auth_pw_change_take()

SshPwChange protocore_ssh_auth_pw_change_take ( uint8_t  i)

Install the password-change start callback (nullptr → change requests are refused busy).

Report the outcome of the change the start callback began for slot slot.

ok true when the old password verified and the new one was stored. Moves the slot to OK or FAIL, which the next poll drains into the deferred reply. A no-op when no change is in flight (a stale report after the connection left).

Take slot i's finished change outcome, clearing it back to NONE.

Returns
OK or FAIL once the application has reported, NONE while idle or still in flight.

Write the "publickey" USERAUTH_REQUEST body that RFC 4252 sec 7 signs and sends.

sec 7 gives one field order and uses it twice: the signature covers

string    session identifier
byte      SSH_MSG_USERAUTH_REQUEST
string    user name
string    service name
string    "publickey"
boolean   TRUE
string    public key algorithm name
string    public key to be used for authentication

and the request that carries the signature is the same bytes from SSH_MSG_USERAUTH_REQUEST on, with the signature appended. Writing it in one place is what keeps the two identical - a verifier hashes what arrived, so any divergence here is a signature that never validates.

Parameters
wSpan written into.
sidSession identifier, or null to start at SSH_MSG_USERAUTH_REQUEST (the request form).
sid_lenLength of sid; ignored when sid is null.
userUser name.
serviceService name, normally "ssh-connection".
pk_algoPublic key algorithm name.
pk_blobPublic key blob.
pk_lenLength of pk_blob.

True once slot i has gone too long without authenticating (RFC 4252 sec 4).

"The server SHOULD have a timeout for authentication and disconnect if the authentication has not been accepted within the timeout period. The RECOMMENDED timeout period is 10 minutes." The clock starts on the first call for a slot and stops once authentication completes; SSH_AUTH_TIMEOUT_MS of 0 disables it. Poll it, and disconnect when it answers true.

◆ protocore_ssh_auth_set_password_cb()

void protocore_ssh_auth_set_password_cb ( uint8_t *  work)

◆ protocore_ssh_auth_set_password_change_cb()

void protocore_ssh_auth_set_password_change_cb ( uint8_t *  work)

◆ protocore_ssh_auth_set_pubkey_cb()

void protocore_ssh_auth_set_pubkey_cb ( uint8_t *  work)

◆ protocore_ssh_auth_pw_change_report()

void protocore_ssh_auth_pw_change_report ( uint8_t *  work)

◆ protocore_ssh_auth_pw_change_clear()

void protocore_ssh_auth_pw_change_clear ( uint8_t *  work)

◆ protocore_ssh_auth_passwd_change_reply()

void protocore_ssh_auth_passwd_change_reply ( uint8_t *  work)

◆ protocore_ssh_auth_write_publickey_request()

void protocore_ssh_auth_write_publickey_request ( uint8_t *  work)

◆ protocore_ssh_auth_timed_out()

void protocore_ssh_auth_timed_out ( uint8_t *  work)

◆ protocore_ssh_auth_reset()

void protocore_ssh_auth_reset ( uint8_t *  work)

◆ protocore_ssh_auth_parse_request()

void protocore_ssh_auth_parse_request ( uint8_t *  work)

◆ protocore_ssh_auth_build_failure()

void protocore_ssh_auth_build_failure ( uint8_t *  work)

◆ protocore_ssh_auth_build_success()

void protocore_ssh_auth_build_success ( uint8_t *  work)

◆ protocore_ssh_auth_handle_request()

void protocore_ssh_auth_handle_request ( uint8_t *  work)

◆ protocore_ssh_auth_dispatch()

void protocore_ssh_auth_dispatch ( uint8_t *  work)

◆ protocore_ssh_auth_span()

uint8_t * protocore_ssh_auth_span ( void  )

The PROTOCORE_SSH_AUTH_BORROW bytes this module's state lives in.

Stated beside the namespace rather than on it: an entry takes a borrow, and this is where that borrow comes from. Taken once from the end of the pool, which no mark and no release walks, so the state lasts the life of the program.

Returns
the span.

Variable Documentation

◆ SshAuthV

SshAuthVars SshAuthV
extern

The operands and the outcome.