14#ifndef PROTOCORE_AUTH_AUTH_H
15#define PROTOCORE_AUTH_AUTH_H
62typedef void (*
SshPasswordChangeCb)(uint8_t slot,
const char *user,
const char *old_password,
const char *new_password);
170#if PROTOCORE_ENABLE_SSH_KEYBOARD_INTERACTIVE
267#if PROTOCORE_ENABLE_SSH_KEYBOARD_INTERACTIVE
277 void (*
const set_password_cb)(uint8_t *work);
278 void (*
const set_password_change_cb)(uint8_t *work);
279 void (*
const set_pubkey_cb)(uint8_t *work);
280 void (*
const pw_change_report)(uint8_t *work);
281 void (*
const pw_change_clear)(uint8_t *work);
282 void (*
const passwd_change_reply)(uint8_t *work);
283 void (*
const write_publickey_request)(uint8_t *work);
284 void (*
const timed_out)(uint8_t *work);
285 void (*
const reset)(uint8_t *work);
286 void (*
const parse_request)(uint8_t *work);
287 void (*
const build_failure)(uint8_t *work);
288 void (*
const build_success)(uint8_t *work);
289 void (*
const handle_request)(uint8_t *work);
290 void (*
const handle_info_response)(uint8_t *work);
291 void (*
const dispatch)(uint8_t *work);
309#if PROTOCORE_ENABLE_SSH_KEYBOARD_INTERACTIVE
310void protocore_ssh_auth_handle_info_response(uint8_t *work);
318static const SshAuthNs SshAuth __attribute__((unused)) = {
332#if PROTOCORE_ENABLE_SSH_KEYBOARD_INTERACTIVE
333 .handle_info_response = protocore_ssh_auth_handle_info_response,
#define SSH_AUTH_PASS_MAX
Max stored password length.
#define SSH_AUTH_ALGO_MAX
Max stored public-key algorithm name ("rsa-sha2-512", "ecdsa-sha2-nistp256", RFC 4253 sec 6....
#define SSH_AUTH_USER_MAX
Max stored user name (RFC 4252 imposes no limit; we cap for BSS).
Root infrastructure: fixed widths, serializers, opcodes and sizes, for every layer above.
void protocore_ssh_auth_build_success(uint8_t *work)
proto_bool(* SshPubkeyCb)(const char *user, const uint8_t *blob, size_t blob_len)
Drop a parked password change without replying to it.
void protocore_ssh_auth_timed_out(uint8_t *work)
SshPwChange
A slot's password-change state: idle, handed to the application, or finished either way.
@ PROTOCORE_SSH_PW_CHANGE_NONE
@ PROTOCORE_SSH_PW_CHANGE_FAIL
@ PROTOCORE_SSH_PW_CHANGE_BUSY
@ PROTOCORE_SSH_PW_CHANGE_OK
SshPwChange protocore_ssh_auth_pw_change_take(uint8_t i)
Install the password-change start callback (nullptr → change requests are refused busy).
proto_bool(* SshPasswordCb)(const char *user, const char *password)
Application callback that validates a username/password pair.
void protocore_ssh_auth_pw_change_report(uint8_t *work)
void protocore_ssh_auth_passwd_change_reply(uint8_t *work)
void protocore_ssh_auth_set_password_change_cb(uint8_t *work)
void protocore_ssh_auth_handle_request(uint8_t *work)
void protocore_ssh_auth_write_publickey_request(uint8_t *work)
void protocore_ssh_auth_parse_request(uint8_t *work)
void protocore_ssh_auth_set_pubkey_cb(uint8_t *work)
uint8_t * protocore_ssh_auth_span(void)
The PROTOCORE_SSH_AUTH_BORROW bytes this module's state lives in.
void protocore_ssh_auth_build_failure(uint8_t *work)
SshAuthVars SshAuthV
The operands and the outcome.
void(* SshPasswordChangeCb)(uint8_t slot, const char *user, const char *old_password, const char *new_password)
Install the password-verification callback (nullptr → all fail).
void protocore_ssh_auth_set_password_cb(uint8_t *work)
void protocore_ssh_auth_pw_change_clear(uint8_t *work)
void protocore_ssh_auth_dispatch(uint8_t *work)
void protocore_ssh_auth_reset(uint8_t *work)
RFC 4252 sec 7 / sec 8: what an attempt of each method is checked against.
SshPubkeyCb pubkey_cb
what a public key is checked against
SshPasswordCb password_cb
what a password attempt is checked against
SshPasswordChangeCb password_change_cb
what a change request is handed to
Install the publickey-authorization callback (nullptr → all fail).
size_t len
how many bytes it has
const uint8_t * payload
the message body
void(*const set_password_cb)(uint8_t *work)
Where a reply is written, either as a buffer or as a span.
size_t out_len
what was written
size_t cap
how much room it has
uint8_t * out
where a reply is written
mmgr_span * w
the span a publickey request is built in
Parsed SSH_MSG_USERAUTH_REQUEST.
const uint8_t * signature
Raw signature bytes (points into the payload).
proto_bool is_pw_change
True if the request set the change-password flag.
proto_bool is_password
True if a password method-request was parsed.
proto_bool is_pubkey
True if a publickey method-request was parsed.
proto_bool is_kbdint
True if a keyboard-interactive method-request was parsed (RFC 4256).
uint32_t pk_blob_len
Length of pk_blob.
size_t signed_prefix_len
Length of signed_prefix (payload up to the signature).
const uint8_t * pk_blob
Public-key blob (points into the payload).
const uint8_t * signed_prefix
Bytes of the request that the signature covers.
proto_bool has_signature
True if the request carried a signature.
uint32_t signature_len
Length of signature.
SshAuthMsgArgs msg
sec 5 the message body a dispatch is given
uint8_t slot
the SSH slot a call acts on
SshAuthReq * req
where a parse lands the request (sec 5)
uint8_t msg_type
the message a dispatch routes
SshAuthOutArgs out_args
where a reply is written
SshAuthCbs cbs
what an attempt is checked against
SshUserauthArgs userauth
sec 5 / sec 7 the fields one request names
proto_bool partial
the failure is a partial success (sec 5.1)
RFC 4252 sec 5 / sec 7: the names one USERAUTH_REQUEST carries, and the key it offers.
const char * user
the user name
const char * service
the service name, normally "ssh-connection"
size_t sid_len
its length; ignored when sid is NULL
const uint8_t * pk_blob
the public key blob
const char * pk_algo
the public key algorithm name
const uint8_t * sid
the session identifier it signs over, or NULL for the request form
#define PROTOCORE_BEGIN_DECLS
Give a header's declarations C linkage, so their symbol names carry no parameter types.
_Bool proto_bool
The truth value.
#define PROTOCORE_END_DECLS