Merge remote-tracking branch 'origin/master'
[unleashed/lotheac.git] / usr / src / lib / pam_modules / roles / roles.c
blob540e3a9a9829dd0add0daad7214191d23e40027c
1 /*
2 * CDDL HEADER START
4 * The contents of this file are subject to the terms of the
5 * Common Development and Distribution License (the "License").
6 * You may not use this file except in compliance with the License.
8 * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
9 * or http://www.opensolaris.org/os/licensing.
10 * See the License for the specific language governing permissions
11 * and limitations under the License.
13 * When distributing Covered Code, include this CDDL HEADER in each
14 * file and include the License file at usr/src/OPENSOLARIS.LICENSE.
15 * If applicable, add the following below this CDDL HEADER, with the
16 * fields enclosed by brackets "[]" replaced with your own identifying
17 * information: Portions Copyright [yyyy] [name of copyright owner]
19 * CDDL HEADER END
22 * Copyright 2009 Sun Microsystems, Inc. All rights reserved.
23 * Use is subject to license terms.
26 #include <syslog.h>
27 #include <pwd.h>
28 #include <unistd.h>
29 #include <strings.h>
30 #include <security/pam_appl.h>
31 #include <security/pam_modules.h>
32 #include <libintl.h>
33 #include <pwd.h>
34 #include <user_attr.h>
35 #include <secdb.h>
36 #include <nss_dbdefs.h>
37 #include <security/pam_impl.h>
39 static int roleinlist();
42 * pam_sm_acct_mgmt():
43 * Account management module
44 * This module disallows roles for primary logins and adds special
45 * checks to allow roles for secondary logins.
48 /*ARGSUSED*/
49 int
50 pam_sm_acct_mgmt(pam_handle_t *pamh, int flags, int argc, const char **argv)
52 uid_t uid;
53 userattr_t *user_entry;
54 char *kva_value;
55 char *username;
56 char *auser;
57 char *rhost;
58 char messages[PAM_MAX_NUM_MSG][PAM_MAX_MSG_SIZE];
59 struct passwd *pw_entry, pwd;
60 char buf[NSS_BUFLEN_PASSWD];
62 int i;
63 int debug = 0;
64 int allow_remote = 0;
66 (void) pam_get_item(pamh, PAM_USER, (void **)&username);
67 (void) pam_get_item(pamh, PAM_AUSER, (void **)&auser);
68 (void) pam_get_item(pamh, PAM_RHOST, (void **)&rhost);
70 for (i = 0; i < argc; i++) {
71 if (strcmp(argv[i], "allow_remote") == 0) {
72 allow_remote = 1;
73 } else if (strcmp(argv[i], "debug") == 0) {
74 debug = 1;
75 } else {
76 __pam_log(LOG_AUTH | LOG_ERR,
77 "pam_roles:pam_sm_acct_mgmt: illegal module "
78 "option %s", argv[i]);
82 if (debug) {
83 char *ruser;
84 char *service;
86 (void) pam_get_item(pamh, PAM_RUSER, (void **)&ruser);
87 (void) pam_get_item(pamh, PAM_SERVICE, (void **)&service);
88 __pam_log(LOG_AUTH | LOG_DEBUG, "pam_roles:pam_sm_acct_mgmt: "
89 "service = %s, allow_remote = %d, user = %s auser = %s "
90 "ruser = %s rhost = %s\n", (service) ? service : "not set",
91 allow_remote, (username) ? username : "not set",
92 (auser) ? auser: "not set", (ruser) ? ruser: "not set",
93 (rhost) ? rhost: "not set");
96 if (username == NULL)
97 return (PAM_USER_UNKNOWN);
99 /* stop masquerades by mapping username to uid to username */
101 getpwnam_r(username, &pwd, buf, sizeof (buf), &pw_entry);
102 if (!pw_entry)
103 return (PAM_USER_UNKNOWN);
104 getpwuid_r(pw_entry->pw_uid, &pwd, buf, sizeof (buf), &pw_entry);
105 if (!pw_entry)
106 return (PAM_USER_UNKNOWN);
108 * If there's no user_attr entry for the primary user or it's not a
109 * role, no further checks are needed.
112 if (((user_entry = getusernam(pw_entry->pw_name)) == NULL) ||
113 ((kva_value = kva_match((kva_t *)user_entry->attr,
114 USERATTR_TYPE_KW)) == NULL) ||
115 ((strcmp(kva_value, USERATTR_TYPE_NONADMIN_KW) != 0) &&
116 (strcmp(kva_value, USERATTR_TYPE_ADMIN_KW) != 0))) {
117 free_userattr(user_entry);
118 return (PAM_IGNORE);
120 free_userattr(user_entry);
122 /* username is a role */
124 if (strcmp(username, pw_entry->pw_name) != 0) {
125 __pam_log(LOG_AUTH | LOG_ALERT,
126 "pam_roles:pam_sm_acct_mgmt: user name %s "
127 "maps to user id %d which is user name %s",
128 username, pw_entry->pw_uid, pw_entry->pw_name);
132 /* Who's the user requesting the role? */
134 if (auser != NULL && *auser != '\0') {
135 /* authenticated requesting user */
137 user_entry = getusernam(auser);
138 } else {
139 /* user is implied by real UID */
141 if ((uid = getuid()) == 0) {
143 * Root user_attr entry cannot have roles.
144 * Force error and deny access.
146 user_entry = NULL;
147 } else {
148 getpwuid_r(uid, &pwd, buf, sizeof (buf), &pw_entry);
149 if (!pw_entry)
150 return (PAM_USER_UNKNOWN);
151 user_entry = getusernam(pw_entry->pw_name);
155 if ((rhost != NULL && *rhost != '\0') &&
156 allow_remote == 0) {
157 /* don't allow remote roles for this service */
159 free_userattr(user_entry);
160 return (PAM_PERM_DENIED);
164 * If the original user does not have a user_attr entry or isn't
165 * assigned the role being assumed, fail.
168 if ((user_entry == NULL) ||
169 ((kva_value = kva_match((kva_t *)user_entry->attr,
170 USERATTR_ROLES_KW)) == NULL) ||
171 (roleinlist(kva_value, username) == 0)) {
172 free_userattr(user_entry);
173 (void) strlcpy(messages[0], dgettext(TEXT_DOMAIN,
174 "Roles can only be assumed by authorized users"),
175 sizeof (messages[0]));
176 (void) __pam_display_msg(pamh, PAM_ERROR_MSG, 1, messages,
177 NULL);
178 return (PAM_PERM_DENIED);
181 free_userattr(user_entry);
182 return (PAM_IGNORE);
186 roleinlist(char *list, char *role)
188 char *lasts = NULL;
189 char *rolename = (char *)strtok_r(list, ",", &lasts);
191 while (rolename) {
192 if (strcmp(rolename, role) == 0)
193 return (1);
194 else
195 rolename = (char *)strtok_r(NULL, ",", &lasts);
197 return (0);