1af57ed9fSAtsushi Murai /* 2af57ed9fSAtsushi Murai * PPP Secret Key Module 3af57ed9fSAtsushi Murai * 4af57ed9fSAtsushi Murai * Written by Toshiharu OHNO (tony-o@iij.ad.jp) 5af57ed9fSAtsushi Murai * 6af57ed9fSAtsushi Murai * Copyright (C) 1994, Internet Initiative Japan, Inc. All rights reserverd. 7af57ed9fSAtsushi Murai * 8af57ed9fSAtsushi Murai * Redistribution and use in source and binary forms are permitted 9af57ed9fSAtsushi Murai * provided that the above copyright notice and this paragraph are 10af57ed9fSAtsushi Murai * duplicated in all such forms and that any documentation, 11af57ed9fSAtsushi Murai * advertising materials, and other materials related to such 12af57ed9fSAtsushi Murai * distribution and use acknowledge that the software was developed 13af57ed9fSAtsushi Murai * by the Internet Initiative Japan, Inc. The name of the 14af57ed9fSAtsushi Murai * IIJ may not be used to endorse or promote products derived 15af57ed9fSAtsushi Murai * from this software without specific prior written permission. 16af57ed9fSAtsushi Murai * THIS SOFTWARE IS PROVIDED ``AS IS'' AND WITHOUT ANY EXPRESS OR 17af57ed9fSAtsushi Murai * IMPLIED WARRANTIES, INCLUDING, WITHOUT LIMITATION, THE IMPLIED 18af57ed9fSAtsushi Murai * WARRANTIES OF MERCHANTIBILITY AND FITNESS FOR A PARTICULAR PURPOSE. 19af57ed9fSAtsushi Murai * 2097d92980SPeter Wemm * $FreeBSD$ 21af57ed9fSAtsushi Murai * 22af57ed9fSAtsushi Murai * TODO: 23c3899f8dSAtsushi Murai * o Implement check against with registered IP addresses. 24af57ed9fSAtsushi Murai */ 25972a1bcfSBrian Somers #include <sys/param.h> 2675240ed1SBrian Somers #include <netinet/in.h> 27eaa4df37SBrian Somers #include <netinet/in_systm.h> 28eaa4df37SBrian Somers #include <netinet/ip.h> 291fa665f5SBrian Somers #include <sys/un.h> 3075240ed1SBrian Somers 31d5015272SBrian Somers #include <pwd.h> 3275240ed1SBrian Somers #include <stdio.h> 3375240ed1SBrian Somers #include <string.h> 34aceaed92SBrian Somers #include <termios.h> 3575240ed1SBrian Somers #include <unistd.h> 3675240ed1SBrian Somers 375d9e6103SBrian Somers #include "layer.h" 3875240ed1SBrian Somers #include "mbuf.h" 3975240ed1SBrian Somers #include "defs.h" 40aceaed92SBrian Somers #include "log.h" 4175240ed1SBrian Somers #include "timer.h" 42af57ed9fSAtsushi Murai #include "fsm.h" 4329e275ceSBrian Somers #include "iplist.h" 4429e275ceSBrian Somers #include "throughput.h" 45eaa4df37SBrian Somers #include "slcompress.h" 465a72b6edSBrian Somers #include "lqr.h" 475a72b6edSBrian Somers #include "hdlc.h" 48af57ed9fSAtsushi Murai #include "ipcp.h" 4953c9f6c0SAtsushi Murai #include "auth.h" 5075240ed1SBrian Somers #include "systems.h" 516140ba11SBrian Somers #include "lcp.h" 523b0f8d2eSBrian Somers #include "ccp.h" 536140ba11SBrian Somers #include "link.h" 5442d4d396SBrian Somers #include "descriptor.h" 55b6dec9f0SBrian Somers #include "chat.h" 565d9e6103SBrian Somers #include "proto.h" 575ca5389aSBrian Somers #include "filter.h" 583b0f8d2eSBrian Somers #include "mp.h" 59972a1bcfSBrian Somers #ifndef NORADIUS 60972a1bcfSBrian Somers #include "radius.h" 61972a1bcfSBrian Somers #endif 62aceaed92SBrian Somers #include "cbcp.h" 63aceaed92SBrian Somers #include "chap.h" 64aceaed92SBrian Somers #include "async.h" 65aceaed92SBrian Somers #include "physical.h" 66aceaed92SBrian Somers #include "datalink.h" 675828db6dSBrian Somers #include "bundle.h" 68af57ed9fSAtsushi Murai 69455aabc3SBrian Somers const char * 705e315498SBrian Somers Auth2Nam(u_short auth, u_char type) 71ed6a16c1SPoul-Henning Kamp { 725e315498SBrian Somers static char chap[10]; 735e315498SBrian Somers 74455aabc3SBrian Somers switch (auth) { 75455aabc3SBrian Somers case PROTO_PAP: 76455aabc3SBrian Somers return "PAP"; 77455aabc3SBrian Somers case PROTO_CHAP: 785e315498SBrian Somers snprintf(chap, sizeof chap, "CHAP 0x%02x", type); 795e315498SBrian Somers return chap; 80455aabc3SBrian Somers case 0: 81455aabc3SBrian Somers return "none"; 82d025849cSBrian Somers } 83455aabc3SBrian Somers return "unknown"; 8453c9f6c0SAtsushi Murai } 8553c9f6c0SAtsushi Murai 86d5015272SBrian Somers static int 87d5015272SBrian Somers auth_CheckPasswd(const char *name, const char *data, const char *key) 88d5015272SBrian Somers { 89d5015272SBrian Somers if (!strcmp(data, "*")) { 90d5015272SBrian Somers /* Then look up the real password database */ 91d5015272SBrian Somers struct passwd *pw; 92d5015272SBrian Somers int result; 93d5015272SBrian Somers 94d5015272SBrian Somers result = (pw = getpwnam(name)) && 95d5015272SBrian Somers !strcmp(crypt(key, pw->pw_passwd), pw->pw_passwd); 96d5015272SBrian Somers endpwent(); 97d5015272SBrian Somers return result; 98d5015272SBrian Somers } 99d5015272SBrian Somers 100d5015272SBrian Somers return !strcmp(data, key); 101d5015272SBrian Somers } 102d5015272SBrian Somers 1031ae349f5Scvs2svn int 10492b09558SBrian Somers auth_SetPhoneList(const char *name, char *phone, int phonelen) 10592b09558SBrian Somers { 10692b09558SBrian Somers FILE *fp; 10792b09558SBrian Somers int n; 10892b09558SBrian Somers char *vector[6]; 10992b09558SBrian Somers char buff[LINE_LEN]; 11092b09558SBrian Somers 11192b09558SBrian Somers fp = OpenSecret(SECRETFILE); 11292b09558SBrian Somers if (fp != NULL) { 11392b09558SBrian Somers while (fgets(buff, sizeof buff, fp)) { 11492b09558SBrian Somers if (buff[0] == '#') 11592b09558SBrian Somers continue; 11692b09558SBrian Somers buff[strlen(buff) - 1] = '\0'; 11792b09558SBrian Somers memset(vector, '\0', sizeof vector); 11892b09558SBrian Somers n = MakeArgs(buff, vector, VECSIZE(vector)); 11992b09558SBrian Somers if (n < 5) 12092b09558SBrian Somers continue; 12192b09558SBrian Somers if (strcmp(vector[0], name) == 0) { 12292b09558SBrian Somers CloseSecret(fp); 12392b09558SBrian Somers if (*vector[4] == '\0') 12492b09558SBrian Somers return 0; 12592b09558SBrian Somers strncpy(phone, vector[4], phonelen - 1); 12692b09558SBrian Somers phone[phonelen - 1] = '\0'; 12792b09558SBrian Somers return 1; /* Valid */ 12892b09558SBrian Somers } 12992b09558SBrian Somers } 13092b09558SBrian Somers CloseSecret(fp); 13192b09558SBrian Somers } 13292b09558SBrian Somers *phone = '\0'; 13392b09558SBrian Somers return 0; 13492b09558SBrian Somers } 13592b09558SBrian Somers 13692b09558SBrian Somers int 13792b09558SBrian Somers auth_Select(struct bundle *bundle, const char *name) 138944f7098SBrian Somers { 13953c9f6c0SAtsushi Murai FILE *fp; 14053c9f6c0SAtsushi Murai int n; 1411ae349f5Scvs2svn char *vector[5]; 14286e02934SBrian Somers char buff[LINE_LEN]; 14353c9f6c0SAtsushi Murai 144643f4904SBrian Somers if (*name == '\0') { 145972a1bcfSBrian Somers ipcp_Setup(&bundle->ncp.ipcp, INADDR_NONE); 146643f4904SBrian Somers return 1; 147643f4904SBrian Somers } 148643f4904SBrian Somers 149972a1bcfSBrian Somers #ifndef NORADIUS 150972a1bcfSBrian Somers if (bundle->radius.valid && bundle->radius.ip.s_addr != INADDR_NONE) { 151972a1bcfSBrian Somers /* We've got a radius IP - it overrides everything */ 152972a1bcfSBrian Somers if (!ipcp_UseHisIPaddr(bundle, bundle->radius.ip)) 153972a1bcfSBrian Somers return 0; 154972a1bcfSBrian Somers ipcp_Setup(&bundle->ncp.ipcp, bundle->radius.mask.s_addr); 155972a1bcfSBrian Somers /* Continue with ppp.secret in case we've got a new label */ 156972a1bcfSBrian Somers } 157972a1bcfSBrian Somers #endif 158972a1bcfSBrian Somers 159643f4904SBrian Somers fp = OpenSecret(SECRETFILE); 160d5015272SBrian Somers if (fp != NULL) { 16170ee81ffSBrian Somers while (fgets(buff, sizeof buff, fp)) { 16253c9f6c0SAtsushi Murai if (buff[0] == '#') 16353c9f6c0SAtsushi Murai continue; 164501f5480SBrian Somers buff[strlen(buff) - 1] = '\0'; 16570ee81ffSBrian Somers memset(vector, '\0', sizeof vector); 166e68d210eSBrian Somers n = MakeArgs(buff, vector, VECSIZE(vector)); 1671ae349f5Scvs2svn if (n < 2) 16853c9f6c0SAtsushi Murai continue; 169501f5480SBrian Somers if (strcmp(vector[0], name) == 0) { 1701ae349f5Scvs2svn CloseSecret(fp); 171972a1bcfSBrian Somers #ifndef NORADIUS 172972a1bcfSBrian Somers if (!bundle->radius.valid || bundle->radius.ip.s_addr == INADDR_NONE) { 173972a1bcfSBrian Somers #endif 17492b09558SBrian Somers if (n > 2 && *vector[2] && strcmp(vector[2], "*") && 17592b09558SBrian Somers !ipcp_UseHisaddr(bundle, vector[2], 1)) 176643f4904SBrian Somers return 0; 177972a1bcfSBrian Somers ipcp_Setup(&bundle->ncp.ipcp, INADDR_NONE); 178972a1bcfSBrian Somers #ifndef NORADIUS 179972a1bcfSBrian Somers } 180972a1bcfSBrian Somers #endif 18192b09558SBrian Somers if (n > 3 && *vector[3] && strcmp(vector[3], "*")) 18249052c95SBrian Somers bundle_SetLabel(bundle, vector[3]); 183d5015272SBrian Somers return 1; /* Valid */ 18453c9f6c0SAtsushi Murai } 185501f5480SBrian Somers } 18653c9f6c0SAtsushi Murai CloseSecret(fp); 187643f4904SBrian Somers } 188643f4904SBrian Somers 189643f4904SBrian Somers #ifndef NOPASSWDAUTH 190643f4904SBrian Somers /* Let 'em in anyway - they must have been in the passwd file */ 191972a1bcfSBrian Somers ipcp_Setup(&bundle->ncp.ipcp, INADDR_NONE); 192643f4904SBrian Somers return 1; 193643f4904SBrian Somers #else 194972a1bcfSBrian Somers #ifndef NORADIUS 195972a1bcfSBrian Somers if (bundle->radius.valid) 196972a1bcfSBrian Somers return 1; 197972a1bcfSBrian Somers #endif 198972a1bcfSBrian Somers 199972a1bcfSBrian Somers /* Disappeared from ppp.secret ??? */ 200643f4904SBrian Somers return 0; 201643f4904SBrian Somers #endif 20253c9f6c0SAtsushi Murai } 20353c9f6c0SAtsushi Murai 204af57ed9fSAtsushi Murai int 205972a1bcfSBrian Somers auth_Validate(struct bundle *bundle, const char *name, 206643f4904SBrian Somers const char *key, struct physical *physical) 207af57ed9fSAtsushi Murai { 208643f4904SBrian Somers /* Used by PAP routines */ 209643f4904SBrian Somers 210af57ed9fSAtsushi Murai FILE *fp; 211af57ed9fSAtsushi Murai int n; 2129c97abd8SBrian Somers char *vector[5]; 21386e02934SBrian Somers char buff[LINE_LEN]; 214af57ed9fSAtsushi Murai 215643f4904SBrian Somers fp = OpenSecret(SECRETFILE); 216643f4904SBrian Somers if (fp != NULL) { 21770ee81ffSBrian Somers while (fgets(buff, sizeof buff, fp)) { 218af57ed9fSAtsushi Murai if (buff[0] == '#') 219af57ed9fSAtsushi Murai continue; 220af57ed9fSAtsushi Murai buff[strlen(buff) - 1] = 0; 22170ee81ffSBrian Somers memset(vector, '\0', sizeof vector); 222e68d210eSBrian Somers n = MakeArgs(buff, vector, VECSIZE(vector)); 223af57ed9fSAtsushi Murai if (n < 2) 224af57ed9fSAtsushi Murai continue; 225972a1bcfSBrian Somers if (strcmp(vector[0], name) == 0) { 226af57ed9fSAtsushi Murai CloseSecret(fp); 227972a1bcfSBrian Somers return auth_CheckPasswd(name, vector[1], key); 228af57ed9fSAtsushi Murai } 229af57ed9fSAtsushi Murai } 230af57ed9fSAtsushi Murai CloseSecret(fp); 231d5015272SBrian Somers } 232d5015272SBrian Somers 233d5015272SBrian Somers #ifndef NOPASSWDAUTH 2341342caedSBrian Somers if (Enabled(bundle, OPT_PASSWDAUTH)) 235972a1bcfSBrian Somers return auth_CheckPasswd(name, "*", key); 236d5015272SBrian Somers #endif 237d5015272SBrian Somers 238d5015272SBrian Somers return 0; /* Invalid */ 239af57ed9fSAtsushi Murai } 240af57ed9fSAtsushi Murai 241af57ed9fSAtsushi Murai char * 242972a1bcfSBrian Somers auth_GetSecret(struct bundle *bundle, const char *name, int len, 243643f4904SBrian Somers struct physical *physical) 244af57ed9fSAtsushi Murai { 245d5015272SBrian Somers /* Used by CHAP routines */ 246d5015272SBrian Somers 247af57ed9fSAtsushi Murai FILE *fp; 248af57ed9fSAtsushi Murai int n; 2499c97abd8SBrian Somers char *vector[5]; 250c506ecd5SBrian Somers static char buff[LINE_LEN]; /* vector[] will point here when returned */ 251af57ed9fSAtsushi Murai 252643f4904SBrian Somers fp = OpenSecret(SECRETFILE); 253af57ed9fSAtsushi Murai if (fp == NULL) 254af57ed9fSAtsushi Murai return (NULL); 255d5015272SBrian Somers 25670ee81ffSBrian Somers while (fgets(buff, sizeof buff, fp)) { 257af57ed9fSAtsushi Murai if (buff[0] == '#') 258af57ed9fSAtsushi Murai continue; 259c506ecd5SBrian Somers n = strlen(buff) - 1; 260c506ecd5SBrian Somers if (buff[n] == '\n') 261c506ecd5SBrian Somers buff[n] = '\0'; /* Trim the '\n' */ 26270ee81ffSBrian Somers memset(vector, '\0', sizeof vector); 263e68d210eSBrian Somers n = MakeArgs(buff, vector, VECSIZE(vector)); 264af57ed9fSAtsushi Murai if (n < 2) 265af57ed9fSAtsushi Murai continue; 266972a1bcfSBrian Somers if (strlen(vector[0]) == len && strncmp(vector[0], name, len) == 0) { 267643f4904SBrian Somers CloseSecret(fp); 268d5015272SBrian Somers return vector[1]; 269af57ed9fSAtsushi Murai } 270af57ed9fSAtsushi Murai } 271af57ed9fSAtsushi Murai CloseSecret(fp); 272af57ed9fSAtsushi Murai return (NULL); /* Invalid */ 273af57ed9fSAtsushi Murai } 27453c9f6c0SAtsushi Murai 27553c9f6c0SAtsushi Murai static void 276b6e82f33SBrian Somers AuthTimeout(void *vauthp) 27753c9f6c0SAtsushi Murai { 278b6e82f33SBrian Somers struct authinfo *authp = (struct authinfo *)vauthp; 27953c9f6c0SAtsushi Murai 280dd7e2610SBrian Somers timer_Stop(&authp->authtimer); 28153c9f6c0SAtsushi Murai if (--authp->retry > 0) { 282f0cdd9c0SBrian Somers authp->id++; 283f0cdd9c0SBrian Somers (*authp->fn.req)(authp); 284dd7e2610SBrian Somers timer_Start(&authp->authtimer); 285aceaed92SBrian Somers } else { 286aceaed92SBrian Somers log_Printf(LogPHASE, "Auth: No response from server\n"); 287aceaed92SBrian Somers datalink_AuthNotOk(authp->physical->dl); 288aceaed92SBrian Somers } 28953c9f6c0SAtsushi Murai } 29053c9f6c0SAtsushi Murai 29153c9f6c0SAtsushi Murai void 292f0cdd9c0SBrian Somers auth_Init(struct authinfo *authp, struct physical *p, auth_func req, 293f0cdd9c0SBrian Somers auth_func success, auth_func failure) 29453c9f6c0SAtsushi Murai { 295f0cdd9c0SBrian Somers memset(authp, '\0', sizeof(struct authinfo)); 296479508cfSBrian Somers authp->cfg.fsm.timeout = DEF_FSMRETRY; 297479508cfSBrian Somers authp->cfg.fsm.maxreq = DEF_FSMAUTHTRIES; 298479508cfSBrian Somers authp->cfg.fsm.maxtrm = 0; /* not used */ 299f0cdd9c0SBrian Somers authp->fn.req = req; 300f0cdd9c0SBrian Somers authp->fn.success = success; 301f0cdd9c0SBrian Somers authp->fn.failure = failure; 302f0cdd9c0SBrian Somers authp->physical = p; 303e2ebb036SBrian Somers } 30453c9f6c0SAtsushi Murai 305e2ebb036SBrian Somers void 306f0cdd9c0SBrian Somers auth_StartReq(struct authinfo *authp) 307e2ebb036SBrian Somers { 308dd7e2610SBrian Somers timer_Stop(&authp->authtimer); 309e2ebb036SBrian Somers authp->authtimer.func = AuthTimeout; 3103b0f8d2eSBrian Somers authp->authtimer.name = "auth"; 311479508cfSBrian Somers authp->authtimer.load = authp->cfg.fsm.timeout * SECTICKS; 312e2ebb036SBrian Somers authp->authtimer.arg = (void *)authp; 313479508cfSBrian Somers authp->retry = authp->cfg.fsm.maxreq; 31453c9f6c0SAtsushi Murai authp->id = 1; 315f0cdd9c0SBrian Somers (*authp->fn.req)(authp); 316dd7e2610SBrian Somers timer_Start(&authp->authtimer); 31753c9f6c0SAtsushi Murai } 31853c9f6c0SAtsushi Murai 31953c9f6c0SAtsushi Murai void 320dd7e2610SBrian Somers auth_StopTimer(struct authinfo *authp) 32153c9f6c0SAtsushi Murai { 322dd7e2610SBrian Somers timer_Stop(&authp->authtimer); 323f0cdd9c0SBrian Somers } 324f0cdd9c0SBrian Somers 325f0cdd9c0SBrian Somers struct mbuf * 326f0cdd9c0SBrian Somers auth_ReadHeader(struct authinfo *authp, struct mbuf *bp) 327f0cdd9c0SBrian Somers { 328f0cdd9c0SBrian Somers int len; 329f0cdd9c0SBrian Somers 33026af0ae9SBrian Somers len = m_length(bp); 331f0cdd9c0SBrian Somers if (len >= sizeof authp->in.hdr) { 332f0cdd9c0SBrian Somers bp = mbuf_Read(bp, (u_char *)&authp->in.hdr, sizeof authp->in.hdr); 333f0cdd9c0SBrian Somers if (len >= ntohs(authp->in.hdr.length)) 334f0cdd9c0SBrian Somers return bp; 335b7ff18adSBrian Somers authp->in.hdr.length = htons(0); 336b31a24caSBrian Somers log_Printf(LogWARN, "auth_ReadHeader: Short packet (%d > %d) !\n", 337b31a24caSBrian Somers ntohs(authp->in.hdr.length), len); 338b7ff18adSBrian Somers } else { 339b7ff18adSBrian Somers authp->in.hdr.length = htons(0); 340b31a24caSBrian Somers log_Printf(LogWARN, "auth_ReadHeader: Short packet header (%d > %d) !\n", 341eb2d27cfSBrian Somers (int)(sizeof authp->in.hdr), len); 342b7ff18adSBrian Somers } 343f0cdd9c0SBrian Somers 34426af0ae9SBrian Somers m_freem(bp); 345f0cdd9c0SBrian Somers return NULL; 346f0cdd9c0SBrian Somers } 347f0cdd9c0SBrian Somers 348f0cdd9c0SBrian Somers struct mbuf * 349f0cdd9c0SBrian Somers auth_ReadName(struct authinfo *authp, struct mbuf *bp, int len) 350f0cdd9c0SBrian Somers { 351f0cdd9c0SBrian Somers if (len > sizeof authp->in.name - 1) 352b31a24caSBrian Somers log_Printf(LogWARN, "auth_ReadName: Name too long (%d) !\n", len); 353f0cdd9c0SBrian Somers else { 35426af0ae9SBrian Somers int mlen = m_length(bp); 355f0cdd9c0SBrian Somers 356f0cdd9c0SBrian Somers if (len > mlen) 357b31a24caSBrian Somers log_Printf(LogWARN, "auth_ReadName: Short packet (%d > %d) !\n", 358b31a24caSBrian Somers len, mlen); 359f0cdd9c0SBrian Somers else { 360f0cdd9c0SBrian Somers bp = mbuf_Read(bp, (u_char *)authp->in.name, len); 361f0cdd9c0SBrian Somers authp->in.name[len] = '\0'; 362f0cdd9c0SBrian Somers return bp; 363f0cdd9c0SBrian Somers } 364f0cdd9c0SBrian Somers } 365f0cdd9c0SBrian Somers 366f0cdd9c0SBrian Somers *authp->in.name = '\0'; 36726af0ae9SBrian Somers m_freem(bp); 368f0cdd9c0SBrian Somers return NULL; 36953c9f6c0SAtsushi Murai } 370