1 /* $OpenBSD: authfile.c,v 1.151 2026/06/29 09:14:25 djm Exp $ */
2 /*
3 * Copyright (c) 2000, 2013 Markus Friedl. All rights reserved.
4 *
5 * Redistribution and use in source and binary forms, with or without
6 * modification, are permitted provided that the following conditions
7 * are met:
8 * 1. Redistributions of source code must retain the above copyright
9 * notice, this list of conditions and the following disclaimer.
10 * 2. Redistributions in binary form must reproduce the above copyright
11 * notice, this list of conditions and the following disclaimer in the
12 * documentation and/or other materials provided with the distribution.
13 *
14 * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
15 * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
16 * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
17 * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
18 * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
19 * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
20 * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
21 * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
22 * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
23 * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
24 */
25
26 #include "includes.h"
27
28 #include <sys/types.h>
29 #include <sys/stat.h>
30
31 #include <errno.h>
32 #include <fcntl.h>
33 #include <stdio.h>
34 #include <stdarg.h>
35 #include <stdlib.h>
36 #include <string.h>
37 #include <unistd.h>
38
39 #include "log.h"
40 #include "authfile.h"
41 #include "sshkey.h"
42 #include "sshbuf.h"
43 #include "ssherr.h"
44 #include "krl.h"
45
46 /* Save a key blob to a file */
47 static int
sshkey_save_private_blob(struct sshbuf * keybuf,const char * filename)48 sshkey_save_private_blob(struct sshbuf *keybuf, const char *filename)
49 {
50 int r;
51 mode_t omask;
52
53 omask = umask(077);
54 r = sshbuf_write_file(filename, keybuf);
55 umask(omask);
56 return r;
57 }
58
59 int
sshkey_save_private(struct sshkey * key,const char * filename,const char * passphrase,const char * comment,int format,const char * openssh_format_cipher,int openssh_format_rounds)60 sshkey_save_private(struct sshkey *key, const char *filename,
61 const char *passphrase, const char *comment,
62 int format, const char *openssh_format_cipher, int openssh_format_rounds)
63 {
64 struct sshbuf *keyblob = NULL;
65 int r;
66
67 if ((keyblob = sshbuf_new()) == NULL)
68 return SSH_ERR_ALLOC_FAIL;
69 if ((r = sshkey_private_to_fileblob(key, keyblob, passphrase, comment,
70 format, openssh_format_cipher, openssh_format_rounds)) != 0)
71 goto out;
72 if ((r = sshkey_save_private_blob(keyblob, filename)) != 0)
73 goto out;
74 r = 0;
75 out:
76 sshbuf_free(keyblob);
77 return r;
78 }
79
80 /* XXX remove error() calls from here? */
81 int
sshkey_perm_ok(int fd,const char * filename)82 sshkey_perm_ok(int fd, const char *filename)
83 {
84 struct stat st;
85
86 if (fstat(fd, &st) == -1)
87 return SSH_ERR_SYSTEM_ERROR;
88 /*
89 * if a key owned by the user is accessed, then we check the
90 * permissions of the file. if the key owned by a different user,
91 * then we don't care.
92 */
93 #ifdef HAVE_CYGWIN
94 if (check_ntsec(filename))
95 #endif
96 if ((st.st_uid == getuid()) && (st.st_mode & 077) != 0) {
97 error("@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@");
98 error("@ WARNING: UNPROTECTED PRIVATE KEY FILE! @");
99 error("@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@");
100 error("Permissions 0%3.3o for '%s' are too open.",
101 (u_int)st.st_mode & 0777, filename);
102 error("It is required that your private key files are NOT accessible by others.");
103 error("This private key will be ignored.");
104 return SSH_ERR_KEY_BAD_PERMISSIONS;
105 }
106 return 0;
107 }
108
109 int
sshkey_load_private_type(int type,const char * filename,const char * passphrase,struct sshkey ** keyp,char ** commentp)110 sshkey_load_private_type(int type, const char *filename, const char *passphrase,
111 struct sshkey **keyp, char **commentp)
112 {
113 int fd, r;
114
115 if (keyp != NULL)
116 *keyp = NULL;
117 if (commentp != NULL)
118 *commentp = NULL;
119
120 if ((fd = open(filename, O_RDONLY)) == -1)
121 return SSH_ERR_SYSTEM_ERROR;
122
123 r = sshkey_perm_ok(fd, filename);
124 if (r != 0)
125 goto out;
126
127 r = sshkey_load_private_type_fd(fd, type, passphrase, keyp, commentp);
128 out:
129 close(fd);
130 return r;
131 }
132
133 int
sshkey_load_private(const char * filename,const char * passphrase,struct sshkey ** keyp,char ** commentp)134 sshkey_load_private(const char *filename, const char *passphrase,
135 struct sshkey **keyp, char **commentp)
136 {
137 return sshkey_load_private_type(KEY_UNSPEC, filename, passphrase,
138 keyp, commentp);
139 }
140
141 int
sshkey_load_private_type_fd(int fd,int type,const char * passphrase,struct sshkey ** keyp,char ** commentp)142 sshkey_load_private_type_fd(int fd, int type, const char *passphrase,
143 struct sshkey **keyp, char **commentp)
144 {
145 struct sshbuf *buffer = NULL;
146 int r;
147
148 if (keyp != NULL)
149 *keyp = NULL;
150 if ((r = sshbuf_load_fd(fd, &buffer)) != 0 ||
151 (r = sshkey_parse_private_fileblob_type(buffer, type,
152 passphrase, keyp, commentp)) != 0)
153 goto out;
154
155 /* success */
156 r = 0;
157 out:
158 sshbuf_free(buffer);
159 return r;
160 }
161
162 /* Load a pubkey from the unencrypted envelope of a new-format private key */
163 static int
sshkey_load_pubkey_from_private(const char * filename,struct sshkey ** pubkeyp)164 sshkey_load_pubkey_from_private(const char *filename, struct sshkey **pubkeyp)
165 {
166 struct sshbuf *buffer = NULL;
167 struct sshkey *pubkey = NULL;
168 int r, fd;
169
170 if (pubkeyp != NULL)
171 *pubkeyp = NULL;
172
173 if ((fd = open(filename, O_RDONLY)) == -1)
174 return SSH_ERR_SYSTEM_ERROR;
175 if ((r = sshbuf_load_fd(fd, &buffer)) != 0 ||
176 (r = sshkey_parse_pubkey_from_private_fileblob_type(buffer,
177 KEY_UNSPEC, &pubkey)) != 0)
178 goto out;
179 /* success */
180 if (pubkeyp != NULL) {
181 *pubkeyp = pubkey;
182 pubkey = NULL;
183 }
184 r = 0;
185 out:
186 close(fd);
187 sshbuf_free(buffer);
188 sshkey_free(pubkey);
189 return r;
190 }
191
192 static int
sshkey_try_load_public(struct sshkey ** kp,const char * filename,char ** commentp)193 sshkey_try_load_public(struct sshkey **kp, const char *filename,
194 char **commentp)
195 {
196 FILE *f;
197 char *line = NULL, *cp;
198 size_t linesize = 0;
199 int r;
200 struct stat st;
201 struct sshkey *k = NULL;
202
203 if (kp == NULL)
204 return SSH_ERR_INVALID_ARGUMENT;
205 *kp = NULL;
206 if (commentp != NULL)
207 *commentp = NULL;
208 if ((f = fopen(filename, "r")) == NULL)
209 return SSH_ERR_SYSTEM_ERROR;
210 if (stat(filename, &st) == 0 && S_ISREG(st.st_mode) &&
211 st.st_size > SSHBUF_SIZE_MAX) {
212 fclose(f);
213 return SSH_ERR_INVALID_FORMAT;
214 }
215 if ((k = sshkey_new(KEY_UNSPEC)) == NULL) {
216 fclose(f);
217 return SSH_ERR_ALLOC_FAIL;
218 }
219 while (getline(&line, &linesize, f) != -1) {
220 cp = line;
221 switch (*cp) {
222 case '#':
223 case '\n':
224 case '\0':
225 continue;
226 }
227 /* Abort loading if this looks like a private key */
228 if (strncmp(cp, "-----BEGIN", 10) == 0 ||
229 strcmp(cp, "SSH PRIVATE KEY FILE") == 0)
230 break;
231 /* Skip leading whitespace. */
232 for (; *cp && (*cp == ' ' || *cp == '\t'); cp++)
233 ;
234 if (*cp) {
235 if ((r = sshkey_read(k, &cp)) == 0) {
236 cp[strcspn(cp, "\r\n")] = '\0';
237 if (commentp) {
238 *commentp = strdup(*cp ?
239 cp : filename);
240 if (*commentp == NULL)
241 r = SSH_ERR_ALLOC_FAIL;
242 }
243 /* success */
244 *kp = k;
245 free(line);
246 fclose(f);
247 return r;
248 }
249 }
250 }
251 free(k);
252 free(line);
253 fclose(f);
254 return SSH_ERR_INVALID_FORMAT;
255 }
256
257 /* load public key from any pubkey file */
258 int
sshkey_load_public(const char * filename,struct sshkey ** keyp,char ** commentp)259 sshkey_load_public(const char *filename, struct sshkey **keyp, char **commentp)
260 {
261 char *pubfile = NULL;
262 int r, oerrno;
263
264 if (keyp != NULL)
265 *keyp = NULL;
266 if (commentp != NULL)
267 *commentp = NULL;
268
269 if ((r = sshkey_try_load_public(keyp, filename, commentp)) == 0)
270 goto out;
271
272 /* try .pub suffix */
273 if (asprintf(&pubfile, "%s.pub", filename) == -1)
274 return SSH_ERR_ALLOC_FAIL;
275 if ((r = sshkey_try_load_public(keyp, pubfile, commentp)) == 0)
276 goto out;
277
278 /* finally, try to extract public key from private key file */
279 if ((r = sshkey_load_pubkey_from_private(filename, keyp)) == 0)
280 goto out;
281
282 /* Pretend we couldn't find the key */
283 r = SSH_ERR_SYSTEM_ERROR;
284 errno = ENOENT;
285
286 out:
287 oerrno = errno;
288 free(pubfile);
289 errno = oerrno;
290 return r;
291 }
292
293 /* Load the certificate associated with the named private key */
294 int
sshkey_load_cert(const char * filename,struct sshkey ** keyp)295 sshkey_load_cert(const char *filename, struct sshkey **keyp)
296 {
297 struct sshkey *pub = NULL;
298 char *file = NULL;
299 int r = SSH_ERR_INTERNAL_ERROR;
300
301 if (keyp != NULL)
302 *keyp = NULL;
303
304 if (asprintf(&file, "%s-cert.pub", filename) == -1)
305 return SSH_ERR_ALLOC_FAIL;
306
307 r = sshkey_try_load_public(keyp, file, NULL);
308 free(file);
309 sshkey_free(pub);
310 return r;
311 }
312
313 /* Load private key and certificate */
314 int
sshkey_load_private_cert(int type,const char * filename,const char * passphrase,struct sshkey ** keyp)315 sshkey_load_private_cert(int type, const char *filename, const char *passphrase,
316 struct sshkey **keyp)
317 {
318 struct sshkey *key = NULL, *cert = NULL;
319 int r;
320
321 if (keyp != NULL)
322 *keyp = NULL;
323
324 switch (type) {
325 #ifdef WITH_OPENSSL
326 case KEY_RSA:
327 case KEY_ECDSA:
328 #endif /* WITH_OPENSSL */
329 case KEY_ED25519:
330 case KEY_MLDSA44_ED25519:
331 case KEY_UNSPEC:
332 break;
333 default:
334 return SSH_ERR_KEY_TYPE_UNKNOWN;
335 }
336
337 if ((r = sshkey_load_private_type(type, filename,
338 passphrase, &key, NULL)) != 0 ||
339 (r = sshkey_load_cert(filename, &cert)) != 0)
340 goto out;
341
342 /* Make sure the private key matches the certificate */
343 if (sshkey_equal_public(key, cert) == 0) {
344 r = SSH_ERR_KEY_CERT_MISMATCH;
345 goto out;
346 }
347
348 if ((r = sshkey_to_certified(key)) != 0 ||
349 (r = sshkey_cert_copy(cert, key)) != 0)
350 goto out;
351 r = 0;
352 if (keyp != NULL) {
353 *keyp = key;
354 key = NULL;
355 }
356 out:
357 sshkey_free(key);
358 sshkey_free(cert);
359 return r;
360 }
361
362 /*
363 * Returns success if the specified "key" is listed in the file "filename",
364 * SSH_ERR_KEY_NOT_FOUND: if the key is not listed or another error.
365 * If "strict_type" is set then the key type must match exactly,
366 * otherwise a comparison that ignores certificate data is performed.
367 * If "check_ca" is set and "key" is a certificate, then its CA key is
368 * also checked and sshkey_in_file() will return success if either is found.
369 */
370 int
sshkey_in_file(struct sshkey * key,const char * filename,int strict_type,int check_ca)371 sshkey_in_file(struct sshkey *key, const char *filename, int strict_type,
372 int check_ca)
373 {
374 FILE *f;
375 char *line = NULL, *cp;
376 size_t linesize = 0;
377 int r = 0;
378 struct sshkey *pub = NULL;
379
380 int (*sshkey_compare)(const struct sshkey *, const struct sshkey *) =
381 strict_type ? sshkey_equal : sshkey_equal_public;
382
383 if ((f = fopen(filename, "r")) == NULL)
384 return SSH_ERR_SYSTEM_ERROR;
385
386 while (getline(&line, &linesize, f) != -1) {
387 sshkey_free(pub);
388 pub = NULL;
389 cp = line;
390
391 /* Skip leading whitespace. */
392 for (; *cp && (*cp == ' ' || *cp == '\t'); cp++)
393 ;
394
395 /* Skip comments and empty lines */
396 switch (*cp) {
397 case '#':
398 case '\n':
399 case '\0':
400 continue;
401 }
402
403 if ((pub = sshkey_new(KEY_UNSPEC)) == NULL) {
404 r = SSH_ERR_ALLOC_FAIL;
405 goto out;
406 }
407 switch (r = sshkey_read(pub, &cp)) {
408 case 0:
409 break;
410 case SSH_ERR_KEY_LENGTH:
411 continue;
412 default:
413 goto out;
414 }
415 if (sshkey_compare(key, pub) ||
416 (check_ca && sshkey_is_cert(key) &&
417 sshkey_compare(key->cert->signature_key, pub))) {
418 r = 0;
419 goto out;
420 }
421 }
422 r = SSH_ERR_KEY_NOT_FOUND;
423 out:
424 free(line);
425 sshkey_free(pub);
426 fclose(f);
427 return r;
428 }
429
430 /*
431 * Checks whether the specified key is revoked, returning 0 if not,
432 * SSH_ERR_KEY_REVOKED if it is or another error code if something
433 * unexpected happened.
434 * This will check both the key and, if it is a certificate, its CA key too.
435 * "revoked_keys_file" may be a KRL or a one-per-line list of public keys.
436 */
437 int
sshkey_check_revoked(struct sshkey * key,const char * revoked_keys_file)438 sshkey_check_revoked(struct sshkey *key, const char *revoked_keys_file)
439 {
440 int r;
441
442 r = ssh_krl_file_contains_key(revoked_keys_file, key);
443 /* If this was not a KRL to begin with then continue below */
444 if (r != SSH_ERR_KRL_BAD_MAGIC)
445 return r;
446
447 /*
448 * If the file is not a KRL or we can't handle KRLs then attempt to
449 * parse the file as a flat list of keys.
450 */
451 switch ((r = sshkey_in_file(key, revoked_keys_file, 0, 1))) {
452 case 0:
453 /* Key found => revoked */
454 return SSH_ERR_KEY_REVOKED;
455 case SSH_ERR_KEY_NOT_FOUND:
456 /* Key not found => not revoked */
457 return 0;
458 default:
459 /* Some other error occurred */
460 return r;
461 }
462 }
463
464 /*
465 * Advanced *cpp past the end of key options, defined as the first unquoted
466 * whitespace character. Returns 0 on success or -1 on failure (e.g.
467 * unterminated quotes).
468 */
469 int
sshkey_advance_past_options(char ** cpp)470 sshkey_advance_past_options(char **cpp)
471 {
472 char *cp = *cpp;
473 int quoted = 0;
474
475 for (; *cp && (quoted || (*cp != ' ' && *cp != '\t')); cp++) {
476 if (*cp == '\\' && cp[1] == '"')
477 cp++; /* Skip both */
478 else if (*cp == '"')
479 quoted = !quoted;
480 }
481 *cpp = cp;
482 /* return failure for unterminated quotes */
483 return (*cp == '\0' && quoted) ? -1 : 0;
484 }
485
486 /* Save a public key */
487 int
sshkey_save_public(const struct sshkey * key,const char * path,const char * comment)488 sshkey_save_public(const struct sshkey *key, const char *path,
489 const char *comment)
490 {
491 int fd, oerrno;
492 FILE *f = NULL;
493 int r = SSH_ERR_INTERNAL_ERROR;
494
495 if ((fd = open(path, O_WRONLY|O_CREAT|O_TRUNC, 0644)) == -1)
496 return SSH_ERR_SYSTEM_ERROR;
497 if ((f = fdopen(fd, "w")) == NULL) {
498 r = SSH_ERR_SYSTEM_ERROR;
499 close(fd);
500 goto fail;
501 }
502 if ((r = sshkey_write(key, f)) != 0)
503 goto fail;
504 fprintf(f, " %s\n", comment);
505 if (ferror(f)) {
506 r = SSH_ERR_SYSTEM_ERROR;
507 goto fail;
508 }
509 if (fclose(f) != 0) {
510 r = SSH_ERR_SYSTEM_ERROR;
511 f = NULL;
512 fail:
513 if (f != NULL) {
514 oerrno = errno;
515 fclose(f);
516 errno = oerrno;
517 }
518 return r;
519 }
520 return 0;
521 }
522