1 /* $OpenBSD: authfile.c,v 1.151 2026/06/29 09:14:25 djm Exp $ */ 2 /* 3 * Copyright (c) 2000, 2013 Markus Friedl. All rights reserved. 4 * 5 * Redistribution and use in source and binary forms, with or without 6 * modification, are permitted provided that the following conditions 7 * are met: 8 * 1. Redistributions of source code must retain the above copyright 9 * notice, this list of conditions and the following disclaimer. 10 * 2. Redistributions in binary form must reproduce the above copyright 11 * notice, this list of conditions and the following disclaimer in the 12 * documentation and/or other materials provided with the distribution. 13 * 14 * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR 15 * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES 16 * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. 17 * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT, 18 * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT 19 * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, 20 * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY 21 * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT 22 * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF 23 * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. 24 */ 25 26 #include "includes.h" 27 28 #include <sys/types.h> 29 #include <sys/stat.h> 30 31 #include <errno.h> 32 #include <fcntl.h> 33 #include <stdio.h> 34 #include <stdarg.h> 35 #include <stdlib.h> 36 #include <string.h> 37 #include <unistd.h> 38 39 #include "log.h" 40 #include "authfile.h" 41 #include "sshkey.h" 42 #include "sshbuf.h" 43 #include "ssherr.h" 44 #include "krl.h" 45 46 /* Save a key blob to a file */ 47 static int 48 sshkey_save_private_blob(struct sshbuf *keybuf, const char *filename) 49 { 50 int r; 51 mode_t omask; 52 53 omask = umask(077); 54 r = sshbuf_write_file(filename, keybuf); 55 umask(omask); 56 return r; 57 } 58 59 int 60 sshkey_save_private(struct sshkey *key, const char *filename, 61 const char *passphrase, const char *comment, 62 int format, const char *openssh_format_cipher, int openssh_format_rounds) 63 { 64 struct sshbuf *keyblob = NULL; 65 int r; 66 67 if ((keyblob = sshbuf_new()) == NULL) 68 return SSH_ERR_ALLOC_FAIL; 69 if ((r = sshkey_private_to_fileblob(key, keyblob, passphrase, comment, 70 format, openssh_format_cipher, openssh_format_rounds)) != 0) 71 goto out; 72 if ((r = sshkey_save_private_blob(keyblob, filename)) != 0) 73 goto out; 74 r = 0; 75 out: 76 sshbuf_free(keyblob); 77 return r; 78 } 79 80 /* XXX remove error() calls from here? */ 81 int 82 sshkey_perm_ok(int fd, const char *filename) 83 { 84 struct stat st; 85 86 if (fstat(fd, &st) == -1) 87 return SSH_ERR_SYSTEM_ERROR; 88 /* 89 * if a key owned by the user is accessed, then we check the 90 * permissions of the file. if the key owned by a different user, 91 * then we don't care. 92 */ 93 #ifdef HAVE_CYGWIN 94 if (check_ntsec(filename)) 95 #endif 96 if ((st.st_uid == getuid()) && (st.st_mode & 077) != 0) { 97 error("@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@"); 98 error("@ WARNING: UNPROTECTED PRIVATE KEY FILE! @"); 99 error("@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@"); 100 error("Permissions 0%3.3o for '%s' are too open.", 101 (u_int)st.st_mode & 0777, filename); 102 error("It is required that your private key files are NOT accessible by others."); 103 error("This private key will be ignored."); 104 return SSH_ERR_KEY_BAD_PERMISSIONS; 105 } 106 return 0; 107 } 108 109 int 110 sshkey_load_private_type(int type, const char *filename, const char *passphrase, 111 struct sshkey **keyp, char **commentp) 112 { 113 int fd, r; 114 115 if (keyp != NULL) 116 *keyp = NULL; 117 if (commentp != NULL) 118 *commentp = NULL; 119 120 if ((fd = open(filename, O_RDONLY)) == -1) 121 return SSH_ERR_SYSTEM_ERROR; 122 123 r = sshkey_perm_ok(fd, filename); 124 if (r != 0) 125 goto out; 126 127 r = sshkey_load_private_type_fd(fd, type, passphrase, keyp, commentp); 128 out: 129 close(fd); 130 return r; 131 } 132 133 int 134 sshkey_load_private(const char *filename, const char *passphrase, 135 struct sshkey **keyp, char **commentp) 136 { 137 return sshkey_load_private_type(KEY_UNSPEC, filename, passphrase, 138 keyp, commentp); 139 } 140 141 int 142 sshkey_load_private_type_fd(int fd, int type, const char *passphrase, 143 struct sshkey **keyp, char **commentp) 144 { 145 struct sshbuf *buffer = NULL; 146 int r; 147 148 if (keyp != NULL) 149 *keyp = NULL; 150 if ((r = sshbuf_load_fd(fd, &buffer)) != 0 || 151 (r = sshkey_parse_private_fileblob_type(buffer, type, 152 passphrase, keyp, commentp)) != 0) 153 goto out; 154 155 /* success */ 156 r = 0; 157 out: 158 sshbuf_free(buffer); 159 return r; 160 } 161 162 /* Load a pubkey from the unencrypted envelope of a new-format private key */ 163 static int 164 sshkey_load_pubkey_from_private(const char *filename, struct sshkey **pubkeyp) 165 { 166 struct sshbuf *buffer = NULL; 167 struct sshkey *pubkey = NULL; 168 int r, fd; 169 170 if (pubkeyp != NULL) 171 *pubkeyp = NULL; 172 173 if ((fd = open(filename, O_RDONLY)) == -1) 174 return SSH_ERR_SYSTEM_ERROR; 175 if ((r = sshbuf_load_fd(fd, &buffer)) != 0 || 176 (r = sshkey_parse_pubkey_from_private_fileblob_type(buffer, 177 KEY_UNSPEC, &pubkey)) != 0) 178 goto out; 179 /* success */ 180 if (pubkeyp != NULL) { 181 *pubkeyp = pubkey; 182 pubkey = NULL; 183 } 184 r = 0; 185 out: 186 close(fd); 187 sshbuf_free(buffer); 188 sshkey_free(pubkey); 189 return r; 190 } 191 192 static int 193 sshkey_try_load_public(struct sshkey **kp, const char *filename, 194 char **commentp) 195 { 196 FILE *f; 197 char *line = NULL, *cp; 198 size_t linesize = 0; 199 int r; 200 struct stat st; 201 struct sshkey *k = NULL; 202 203 if (kp == NULL) 204 return SSH_ERR_INVALID_ARGUMENT; 205 *kp = NULL; 206 if (commentp != NULL) 207 *commentp = NULL; 208 if ((f = fopen(filename, "r")) == NULL) 209 return SSH_ERR_SYSTEM_ERROR; 210 if (stat(filename, &st) == 0 && S_ISREG(st.st_mode) && 211 st.st_size > SSHBUF_SIZE_MAX) { 212 fclose(f); 213 return SSH_ERR_INVALID_FORMAT; 214 } 215 if ((k = sshkey_new(KEY_UNSPEC)) == NULL) { 216 fclose(f); 217 return SSH_ERR_ALLOC_FAIL; 218 } 219 while (getline(&line, &linesize, f) != -1) { 220 cp = line; 221 switch (*cp) { 222 case '#': 223 case '\n': 224 case '\0': 225 continue; 226 } 227 /* Abort loading if this looks like a private key */ 228 if (strncmp(cp, "-----BEGIN", 10) == 0 || 229 strcmp(cp, "SSH PRIVATE KEY FILE") == 0) 230 break; 231 /* Skip leading whitespace. */ 232 for (; *cp && (*cp == ' ' || *cp == '\t'); cp++) 233 ; 234 if (*cp) { 235 if ((r = sshkey_read(k, &cp)) == 0) { 236 cp[strcspn(cp, "\r\n")] = '\0'; 237 if (commentp) { 238 *commentp = strdup(*cp ? 239 cp : filename); 240 if (*commentp == NULL) 241 r = SSH_ERR_ALLOC_FAIL; 242 } 243 /* success */ 244 *kp = k; 245 free(line); 246 fclose(f); 247 return r; 248 } 249 } 250 } 251 free(k); 252 free(line); 253 fclose(f); 254 return SSH_ERR_INVALID_FORMAT; 255 } 256 257 /* load public key from any pubkey file */ 258 int 259 sshkey_load_public(const char *filename, struct sshkey **keyp, char **commentp) 260 { 261 char *pubfile = NULL; 262 int r, oerrno; 263 264 if (keyp != NULL) 265 *keyp = NULL; 266 if (commentp != NULL) 267 *commentp = NULL; 268 269 if ((r = sshkey_try_load_public(keyp, filename, commentp)) == 0) 270 goto out; 271 272 /* try .pub suffix */ 273 if (asprintf(&pubfile, "%s.pub", filename) == -1) 274 return SSH_ERR_ALLOC_FAIL; 275 if ((r = sshkey_try_load_public(keyp, pubfile, commentp)) == 0) 276 goto out; 277 278 /* finally, try to extract public key from private key file */ 279 if ((r = sshkey_load_pubkey_from_private(filename, keyp)) == 0) 280 goto out; 281 282 /* Pretend we couldn't find the key */ 283 r = SSH_ERR_SYSTEM_ERROR; 284 errno = ENOENT; 285 286 out: 287 oerrno = errno; 288 free(pubfile); 289 errno = oerrno; 290 return r; 291 } 292 293 /* Load the certificate associated with the named private key */ 294 int 295 sshkey_load_cert(const char *filename, struct sshkey **keyp) 296 { 297 struct sshkey *pub = NULL; 298 char *file = NULL; 299 int r = SSH_ERR_INTERNAL_ERROR; 300 301 if (keyp != NULL) 302 *keyp = NULL; 303 304 if (asprintf(&file, "%s-cert.pub", filename) == -1) 305 return SSH_ERR_ALLOC_FAIL; 306 307 r = sshkey_try_load_public(keyp, file, NULL); 308 free(file); 309 sshkey_free(pub); 310 return r; 311 } 312 313 /* Load private key and certificate */ 314 int 315 sshkey_load_private_cert(int type, const char *filename, const char *passphrase, 316 struct sshkey **keyp) 317 { 318 struct sshkey *key = NULL, *cert = NULL; 319 int r; 320 321 if (keyp != NULL) 322 *keyp = NULL; 323 324 switch (type) { 325 #ifdef WITH_OPENSSL 326 case KEY_RSA: 327 case KEY_ECDSA: 328 #endif /* WITH_OPENSSL */ 329 case KEY_ED25519: 330 case KEY_MLDSA44_ED25519: 331 case KEY_UNSPEC: 332 break; 333 default: 334 return SSH_ERR_KEY_TYPE_UNKNOWN; 335 } 336 337 if ((r = sshkey_load_private_type(type, filename, 338 passphrase, &key, NULL)) != 0 || 339 (r = sshkey_load_cert(filename, &cert)) != 0) 340 goto out; 341 342 /* Make sure the private key matches the certificate */ 343 if (sshkey_equal_public(key, cert) == 0) { 344 r = SSH_ERR_KEY_CERT_MISMATCH; 345 goto out; 346 } 347 348 if ((r = sshkey_to_certified(key)) != 0 || 349 (r = sshkey_cert_copy(cert, key)) != 0) 350 goto out; 351 r = 0; 352 if (keyp != NULL) { 353 *keyp = key; 354 key = NULL; 355 } 356 out: 357 sshkey_free(key); 358 sshkey_free(cert); 359 return r; 360 } 361 362 /* 363 * Returns success if the specified "key" is listed in the file "filename", 364 * SSH_ERR_KEY_NOT_FOUND: if the key is not listed or another error. 365 * If "strict_type" is set then the key type must match exactly, 366 * otherwise a comparison that ignores certificate data is performed. 367 * If "check_ca" is set and "key" is a certificate, then its CA key is 368 * also checked and sshkey_in_file() will return success if either is found. 369 */ 370 int 371 sshkey_in_file(struct sshkey *key, const char *filename, int strict_type, 372 int check_ca) 373 { 374 FILE *f; 375 char *line = NULL, *cp; 376 size_t linesize = 0; 377 int r = 0; 378 struct sshkey *pub = NULL; 379 380 int (*sshkey_compare)(const struct sshkey *, const struct sshkey *) = 381 strict_type ? sshkey_equal : sshkey_equal_public; 382 383 if ((f = fopen(filename, "r")) == NULL) 384 return SSH_ERR_SYSTEM_ERROR; 385 386 while (getline(&line, &linesize, f) != -1) { 387 sshkey_free(pub); 388 pub = NULL; 389 cp = line; 390 391 /* Skip leading whitespace. */ 392 for (; *cp && (*cp == ' ' || *cp == '\t'); cp++) 393 ; 394 395 /* Skip comments and empty lines */ 396 switch (*cp) { 397 case '#': 398 case '\n': 399 case '\0': 400 continue; 401 } 402 403 if ((pub = sshkey_new(KEY_UNSPEC)) == NULL) { 404 r = SSH_ERR_ALLOC_FAIL; 405 goto out; 406 } 407 switch (r = sshkey_read(pub, &cp)) { 408 case 0: 409 break; 410 case SSH_ERR_KEY_LENGTH: 411 continue; 412 default: 413 goto out; 414 } 415 if (sshkey_compare(key, pub) || 416 (check_ca && sshkey_is_cert(key) && 417 sshkey_compare(key->cert->signature_key, pub))) { 418 r = 0; 419 goto out; 420 } 421 } 422 r = SSH_ERR_KEY_NOT_FOUND; 423 out: 424 free(line); 425 sshkey_free(pub); 426 fclose(f); 427 return r; 428 } 429 430 /* 431 * Checks whether the specified key is revoked, returning 0 if not, 432 * SSH_ERR_KEY_REVOKED if it is or another error code if something 433 * unexpected happened. 434 * This will check both the key and, if it is a certificate, its CA key too. 435 * "revoked_keys_file" may be a KRL or a one-per-line list of public keys. 436 */ 437 int 438 sshkey_check_revoked(struct sshkey *key, const char *revoked_keys_file) 439 { 440 int r; 441 442 r = ssh_krl_file_contains_key(revoked_keys_file, key); 443 /* If this was not a KRL to begin with then continue below */ 444 if (r != SSH_ERR_KRL_BAD_MAGIC) 445 return r; 446 447 /* 448 * If the file is not a KRL or we can't handle KRLs then attempt to 449 * parse the file as a flat list of keys. 450 */ 451 switch ((r = sshkey_in_file(key, revoked_keys_file, 0, 1))) { 452 case 0: 453 /* Key found => revoked */ 454 return SSH_ERR_KEY_REVOKED; 455 case SSH_ERR_KEY_NOT_FOUND: 456 /* Key not found => not revoked */ 457 return 0; 458 default: 459 /* Some other error occurred */ 460 return r; 461 } 462 } 463 464 /* 465 * Advanced *cpp past the end of key options, defined as the first unquoted 466 * whitespace character. Returns 0 on success or -1 on failure (e.g. 467 * unterminated quotes). 468 */ 469 int 470 sshkey_advance_past_options(char **cpp) 471 { 472 char *cp = *cpp; 473 int quoted = 0; 474 475 for (; *cp && (quoted || (*cp != ' ' && *cp != '\t')); cp++) { 476 if (*cp == '\\' && cp[1] == '"') 477 cp++; /* Skip both */ 478 else if (*cp == '"') 479 quoted = !quoted; 480 } 481 *cpp = cp; 482 /* return failure for unterminated quotes */ 483 return (*cp == '\0' && quoted) ? -1 : 0; 484 } 485 486 /* Save a public key */ 487 int 488 sshkey_save_public(const struct sshkey *key, const char *path, 489 const char *comment) 490 { 491 int fd, oerrno; 492 FILE *f = NULL; 493 int r = SSH_ERR_INTERNAL_ERROR; 494 495 if ((fd = open(path, O_WRONLY|O_CREAT|O_TRUNC, 0644)) == -1) 496 return SSH_ERR_SYSTEM_ERROR; 497 if ((f = fdopen(fd, "w")) == NULL) { 498 r = SSH_ERR_SYSTEM_ERROR; 499 close(fd); 500 goto fail; 501 } 502 if ((r = sshkey_write(key, f)) != 0) 503 goto fail; 504 fprintf(f, " %s\n", comment); 505 if (ferror(f)) { 506 r = SSH_ERR_SYSTEM_ERROR; 507 goto fail; 508 } 509 if (fclose(f) != 0) { 510 r = SSH_ERR_SYSTEM_ERROR; 511 f = NULL; 512 fail: 513 if (f != NULL) { 514 oerrno = errno; 515 fclose(f); 516 errno = oerrno; 517 } 518 return r; 519 } 520 return 0; 521 } 522