1af57ed9fSAtsushi Murai /* 2af57ed9fSAtsushi Murai * PPP Secret Key Module 3af57ed9fSAtsushi Murai * 4af57ed9fSAtsushi Murai * Written by Toshiharu OHNO (tony-o@iij.ad.jp) 5af57ed9fSAtsushi Murai * 6af57ed9fSAtsushi Murai * Copyright (C) 1994, Internet Initiative Japan, Inc. All rights reserverd. 7af57ed9fSAtsushi Murai * 8af57ed9fSAtsushi Murai * Redistribution and use in source and binary forms are permitted 9af57ed9fSAtsushi Murai * provided that the above copyright notice and this paragraph are 10af57ed9fSAtsushi Murai * duplicated in all such forms and that any documentation, 11af57ed9fSAtsushi Murai * advertising materials, and other materials related to such 12af57ed9fSAtsushi Murai * distribution and use acknowledge that the software was developed 13af57ed9fSAtsushi Murai * by the Internet Initiative Japan, Inc. The name of the 14af57ed9fSAtsushi Murai * IIJ may not be used to endorse or promote products derived 15af57ed9fSAtsushi Murai * from this software without specific prior written permission. 16af57ed9fSAtsushi Murai * THIS SOFTWARE IS PROVIDED ``AS IS'' AND WITHOUT ANY EXPRESS OR 17af57ed9fSAtsushi Murai * IMPLIED WARRANTIES, INCLUDING, WITHOUT LIMITATION, THE IMPLIED 18af57ed9fSAtsushi Murai * WARRANTIES OF MERCHANTIBILITY AND FITNESS FOR A PARTICULAR PURPOSE. 19af57ed9fSAtsushi Murai * 20479508cfSBrian Somers * $Id: auth.c,v 1.41 1999/02/20 01:12:45 brian Exp $ 21af57ed9fSAtsushi Murai * 22af57ed9fSAtsushi Murai * TODO: 23c3899f8dSAtsushi Murai * o Implement check against with registered IP addresses. 24af57ed9fSAtsushi Murai */ 25972a1bcfSBrian Somers #include <sys/param.h> 2675240ed1SBrian Somers #include <netinet/in.h> 27eaa4df37SBrian Somers #include <netinet/in_systm.h> 28eaa4df37SBrian Somers #include <netinet/ip.h> 291fa665f5SBrian Somers #include <sys/un.h> 3075240ed1SBrian Somers 31d5015272SBrian Somers #include <pwd.h> 3275240ed1SBrian Somers #include <stdio.h> 3375240ed1SBrian Somers #include <string.h> 34aceaed92SBrian Somers #include <termios.h> 3575240ed1SBrian Somers #include <unistd.h> 3675240ed1SBrian Somers 3775240ed1SBrian Somers #include "mbuf.h" 3875240ed1SBrian Somers #include "defs.h" 39aceaed92SBrian Somers #include "log.h" 4075240ed1SBrian Somers #include "timer.h" 41af57ed9fSAtsushi Murai #include "fsm.h" 4229e275ceSBrian Somers #include "iplist.h" 4329e275ceSBrian Somers #include "throughput.h" 44eaa4df37SBrian Somers #include "slcompress.h" 455a72b6edSBrian Somers #include "lqr.h" 465a72b6edSBrian Somers #include "hdlc.h" 47af57ed9fSAtsushi Murai #include "ipcp.h" 4853c9f6c0SAtsushi Murai #include "auth.h" 4975240ed1SBrian Somers #include "systems.h" 506140ba11SBrian Somers #include "lcp.h" 513b0f8d2eSBrian Somers #include "ccp.h" 526140ba11SBrian Somers #include "link.h" 5342d4d396SBrian Somers #include "descriptor.h" 54b6dec9f0SBrian Somers #include "chat.h" 55455aabc3SBrian Somers #include "lcpproto.h" 565ca5389aSBrian Somers #include "filter.h" 573b0f8d2eSBrian Somers #include "mp.h" 58972a1bcfSBrian Somers #ifndef NORADIUS 59972a1bcfSBrian Somers #include "radius.h" 60972a1bcfSBrian Somers #endif 61aceaed92SBrian Somers #include "cbcp.h" 62aceaed92SBrian Somers #include "chap.h" 63aceaed92SBrian Somers #include "async.h" 64aceaed92SBrian Somers #include "physical.h" 65aceaed92SBrian Somers #include "datalink.h" 665828db6dSBrian Somers #include "bundle.h" 67af57ed9fSAtsushi Murai 68455aabc3SBrian Somers const char * 695e315498SBrian Somers Auth2Nam(u_short auth, u_char type) 70ed6a16c1SPoul-Henning Kamp { 715e315498SBrian Somers static char chap[10]; 725e315498SBrian Somers 73455aabc3SBrian Somers switch (auth) { 74455aabc3SBrian Somers case PROTO_PAP: 75455aabc3SBrian Somers return "PAP"; 76455aabc3SBrian Somers case PROTO_CHAP: 775e315498SBrian Somers snprintf(chap, sizeof chap, "CHAP 0x%02x", type); 785e315498SBrian Somers return chap; 79455aabc3SBrian Somers case 0: 80455aabc3SBrian Somers return "none"; 81d025849cSBrian Somers } 82455aabc3SBrian Somers return "unknown"; 8353c9f6c0SAtsushi Murai } 8453c9f6c0SAtsushi Murai 85d5015272SBrian Somers static int 86d5015272SBrian Somers auth_CheckPasswd(const char *name, const char *data, const char *key) 87d5015272SBrian Somers { 88d5015272SBrian Somers if (!strcmp(data, "*")) { 89d5015272SBrian Somers /* Then look up the real password database */ 90d5015272SBrian Somers struct passwd *pw; 91d5015272SBrian Somers int result; 92d5015272SBrian Somers 93d5015272SBrian Somers result = (pw = getpwnam(name)) && 94d5015272SBrian Somers !strcmp(crypt(key, pw->pw_passwd), pw->pw_passwd); 95d5015272SBrian Somers endpwent(); 96d5015272SBrian Somers return result; 97d5015272SBrian Somers } 98d5015272SBrian Somers 99d5015272SBrian Somers return !strcmp(data, key); 100d5015272SBrian Somers } 101d5015272SBrian Somers 1021ae349f5Scvs2svn int 10392b09558SBrian Somers auth_SetPhoneList(const char *name, char *phone, int phonelen) 10492b09558SBrian Somers { 10592b09558SBrian Somers FILE *fp; 10692b09558SBrian Somers int n; 10792b09558SBrian Somers char *vector[6]; 10892b09558SBrian Somers char buff[LINE_LEN]; 10992b09558SBrian Somers 11092b09558SBrian Somers fp = OpenSecret(SECRETFILE); 11192b09558SBrian Somers if (fp != NULL) { 11292b09558SBrian Somers while (fgets(buff, sizeof buff, fp)) { 11392b09558SBrian Somers if (buff[0] == '#') 11492b09558SBrian Somers continue; 11592b09558SBrian Somers buff[strlen(buff) - 1] = '\0'; 11692b09558SBrian Somers memset(vector, '\0', sizeof vector); 11792b09558SBrian Somers n = MakeArgs(buff, vector, VECSIZE(vector)); 11892b09558SBrian Somers if (n < 5) 11992b09558SBrian Somers continue; 12092b09558SBrian Somers if (strcmp(vector[0], name) == 0) { 12192b09558SBrian Somers CloseSecret(fp); 12292b09558SBrian Somers if (*vector[4] == '\0') 12392b09558SBrian Somers return 0; 12492b09558SBrian Somers strncpy(phone, vector[4], phonelen - 1); 12592b09558SBrian Somers phone[phonelen - 1] = '\0'; 12692b09558SBrian Somers return 1; /* Valid */ 12792b09558SBrian Somers } 12892b09558SBrian Somers } 12992b09558SBrian Somers CloseSecret(fp); 13092b09558SBrian Somers } 13192b09558SBrian Somers *phone = '\0'; 13292b09558SBrian Somers return 0; 13392b09558SBrian Somers } 13492b09558SBrian Somers 13592b09558SBrian Somers int 13692b09558SBrian Somers auth_Select(struct bundle *bundle, const char *name) 137944f7098SBrian Somers { 13853c9f6c0SAtsushi Murai FILE *fp; 13953c9f6c0SAtsushi Murai int n; 1401ae349f5Scvs2svn char *vector[5]; 14186e02934SBrian Somers char buff[LINE_LEN]; 14253c9f6c0SAtsushi Murai 143643f4904SBrian Somers if (*name == '\0') { 144972a1bcfSBrian Somers ipcp_Setup(&bundle->ncp.ipcp, INADDR_NONE); 145643f4904SBrian Somers return 1; 146643f4904SBrian Somers } 147643f4904SBrian Somers 148972a1bcfSBrian Somers #ifndef NORADIUS 149972a1bcfSBrian Somers if (bundle->radius.valid && bundle->radius.ip.s_addr != INADDR_NONE) { 150972a1bcfSBrian Somers /* We've got a radius IP - it overrides everything */ 151972a1bcfSBrian Somers if (!ipcp_UseHisIPaddr(bundle, bundle->radius.ip)) 152972a1bcfSBrian Somers return 0; 153972a1bcfSBrian Somers ipcp_Setup(&bundle->ncp.ipcp, bundle->radius.mask.s_addr); 154972a1bcfSBrian Somers /* Continue with ppp.secret in case we've got a new label */ 155972a1bcfSBrian Somers } 156972a1bcfSBrian Somers #endif 157972a1bcfSBrian Somers 158643f4904SBrian Somers fp = OpenSecret(SECRETFILE); 159d5015272SBrian Somers if (fp != NULL) { 16070ee81ffSBrian Somers while (fgets(buff, sizeof buff, fp)) { 16153c9f6c0SAtsushi Murai if (buff[0] == '#') 16253c9f6c0SAtsushi Murai continue; 163501f5480SBrian Somers buff[strlen(buff) - 1] = '\0'; 16470ee81ffSBrian Somers memset(vector, '\0', sizeof vector); 165e68d210eSBrian Somers n = MakeArgs(buff, vector, VECSIZE(vector)); 1661ae349f5Scvs2svn if (n < 2) 16753c9f6c0SAtsushi Murai continue; 168501f5480SBrian Somers if (strcmp(vector[0], name) == 0) { 1691ae349f5Scvs2svn CloseSecret(fp); 170972a1bcfSBrian Somers #ifndef NORADIUS 171972a1bcfSBrian Somers if (!bundle->radius.valid || bundle->radius.ip.s_addr == INADDR_NONE) { 172972a1bcfSBrian Somers #endif 17392b09558SBrian Somers if (n > 2 && *vector[2] && strcmp(vector[2], "*") && 17492b09558SBrian Somers !ipcp_UseHisaddr(bundle, vector[2], 1)) 175643f4904SBrian Somers return 0; 176972a1bcfSBrian Somers ipcp_Setup(&bundle->ncp.ipcp, INADDR_NONE); 177972a1bcfSBrian Somers #ifndef NORADIUS 178972a1bcfSBrian Somers } 179972a1bcfSBrian Somers #endif 18092b09558SBrian Somers if (n > 3 && *vector[3] && strcmp(vector[3], "*")) 18149052c95SBrian Somers bundle_SetLabel(bundle, vector[3]); 182d5015272SBrian Somers return 1; /* Valid */ 18353c9f6c0SAtsushi Murai } 184501f5480SBrian Somers } 18553c9f6c0SAtsushi Murai CloseSecret(fp); 186643f4904SBrian Somers } 187643f4904SBrian Somers 188643f4904SBrian Somers #ifndef NOPASSWDAUTH 189643f4904SBrian Somers /* Let 'em in anyway - they must have been in the passwd file */ 190972a1bcfSBrian Somers ipcp_Setup(&bundle->ncp.ipcp, INADDR_NONE); 191643f4904SBrian Somers return 1; 192643f4904SBrian Somers #else 193972a1bcfSBrian Somers #ifndef NORADIUS 194972a1bcfSBrian Somers if (bundle->radius.valid) 195972a1bcfSBrian Somers return 1; 196972a1bcfSBrian Somers #endif 197972a1bcfSBrian Somers 198972a1bcfSBrian Somers /* Disappeared from ppp.secret ??? */ 199643f4904SBrian Somers return 0; 200643f4904SBrian Somers #endif 20153c9f6c0SAtsushi Murai } 20253c9f6c0SAtsushi Murai 203af57ed9fSAtsushi Murai int 204972a1bcfSBrian Somers auth_Validate(struct bundle *bundle, const char *name, 205643f4904SBrian Somers const char *key, struct physical *physical) 206af57ed9fSAtsushi Murai { 207643f4904SBrian Somers /* Used by PAP routines */ 208643f4904SBrian Somers 209af57ed9fSAtsushi Murai FILE *fp; 210af57ed9fSAtsushi Murai int n; 2119c97abd8SBrian Somers char *vector[5]; 21286e02934SBrian Somers char buff[LINE_LEN]; 213af57ed9fSAtsushi Murai 214643f4904SBrian Somers fp = OpenSecret(SECRETFILE); 215643f4904SBrian Somers if (fp != NULL) { 21670ee81ffSBrian Somers while (fgets(buff, sizeof buff, fp)) { 217af57ed9fSAtsushi Murai if (buff[0] == '#') 218af57ed9fSAtsushi Murai continue; 219af57ed9fSAtsushi Murai buff[strlen(buff) - 1] = 0; 22070ee81ffSBrian Somers memset(vector, '\0', sizeof vector); 221e68d210eSBrian Somers n = MakeArgs(buff, vector, VECSIZE(vector)); 222af57ed9fSAtsushi Murai if (n < 2) 223af57ed9fSAtsushi Murai continue; 224972a1bcfSBrian Somers if (strcmp(vector[0], name) == 0) { 225af57ed9fSAtsushi Murai CloseSecret(fp); 226972a1bcfSBrian Somers return auth_CheckPasswd(name, vector[1], key); 227af57ed9fSAtsushi Murai } 228af57ed9fSAtsushi Murai } 229af57ed9fSAtsushi Murai CloseSecret(fp); 230d5015272SBrian Somers } 231d5015272SBrian Somers 232d5015272SBrian Somers #ifndef NOPASSWDAUTH 2331342caedSBrian Somers if (Enabled(bundle, OPT_PASSWDAUTH)) 234972a1bcfSBrian Somers return auth_CheckPasswd(name, "*", key); 235d5015272SBrian Somers #endif 236d5015272SBrian Somers 237d5015272SBrian Somers return 0; /* Invalid */ 238af57ed9fSAtsushi Murai } 239af57ed9fSAtsushi Murai 240af57ed9fSAtsushi Murai char * 241972a1bcfSBrian Somers auth_GetSecret(struct bundle *bundle, const char *name, int len, 242643f4904SBrian Somers struct physical *physical) 243af57ed9fSAtsushi Murai { 244d5015272SBrian Somers /* Used by CHAP routines */ 245d5015272SBrian Somers 246af57ed9fSAtsushi Murai FILE *fp; 247af57ed9fSAtsushi Murai int n; 2489c97abd8SBrian Somers char *vector[5]; 2492ff64793SBrian Somers static char buff[LINE_LEN]; 250af57ed9fSAtsushi Murai 251643f4904SBrian Somers fp = OpenSecret(SECRETFILE); 252af57ed9fSAtsushi Murai if (fp == NULL) 253af57ed9fSAtsushi Murai return (NULL); 254d5015272SBrian Somers 25570ee81ffSBrian Somers while (fgets(buff, sizeof buff, fp)) { 256af57ed9fSAtsushi Murai if (buff[0] == '#') 257af57ed9fSAtsushi Murai continue; 258af57ed9fSAtsushi Murai buff[strlen(buff) - 1] = 0; 25970ee81ffSBrian Somers memset(vector, '\0', sizeof vector); 260e68d210eSBrian Somers n = MakeArgs(buff, vector, VECSIZE(vector)); 261af57ed9fSAtsushi Murai if (n < 2) 262af57ed9fSAtsushi Murai continue; 263972a1bcfSBrian Somers if (strlen(vector[0]) == len && strncmp(vector[0], name, len) == 0) { 264643f4904SBrian Somers CloseSecret(fp); 265d5015272SBrian Somers return vector[1]; 266af57ed9fSAtsushi Murai } 267af57ed9fSAtsushi Murai } 268af57ed9fSAtsushi Murai CloseSecret(fp); 269af57ed9fSAtsushi Murai return (NULL); /* Invalid */ 270af57ed9fSAtsushi Murai } 27153c9f6c0SAtsushi Murai 27253c9f6c0SAtsushi Murai static void 273b6e82f33SBrian Somers AuthTimeout(void *vauthp) 27453c9f6c0SAtsushi Murai { 275b6e82f33SBrian Somers struct authinfo *authp = (struct authinfo *)vauthp; 27653c9f6c0SAtsushi Murai 277dd7e2610SBrian Somers timer_Stop(&authp->authtimer); 27853c9f6c0SAtsushi Murai if (--authp->retry > 0) { 279f0cdd9c0SBrian Somers authp->id++; 280f0cdd9c0SBrian Somers (*authp->fn.req)(authp); 281dd7e2610SBrian Somers timer_Start(&authp->authtimer); 282aceaed92SBrian Somers } else { 283aceaed92SBrian Somers log_Printf(LogPHASE, "Auth: No response from server\n"); 284aceaed92SBrian Somers datalink_AuthNotOk(authp->physical->dl); 285aceaed92SBrian Somers } 28653c9f6c0SAtsushi Murai } 28753c9f6c0SAtsushi Murai 28853c9f6c0SAtsushi Murai void 289f0cdd9c0SBrian Somers auth_Init(struct authinfo *authp, struct physical *p, auth_func req, 290f0cdd9c0SBrian Somers auth_func success, auth_func failure) 29153c9f6c0SAtsushi Murai { 292f0cdd9c0SBrian Somers memset(authp, '\0', sizeof(struct authinfo)); 293479508cfSBrian Somers authp->cfg.fsm.timeout = DEF_FSMRETRY; 294479508cfSBrian Somers authp->cfg.fsm.maxreq = DEF_FSMAUTHTRIES; 295479508cfSBrian Somers authp->cfg.fsm.maxtrm = 0; /* not used */ 296f0cdd9c0SBrian Somers authp->fn.req = req; 297f0cdd9c0SBrian Somers authp->fn.success = success; 298f0cdd9c0SBrian Somers authp->fn.failure = failure; 299f0cdd9c0SBrian Somers authp->physical = p; 300e2ebb036SBrian Somers } 30153c9f6c0SAtsushi Murai 302e2ebb036SBrian Somers void 303f0cdd9c0SBrian Somers auth_StartReq(struct authinfo *authp) 304e2ebb036SBrian Somers { 305dd7e2610SBrian Somers timer_Stop(&authp->authtimer); 306e2ebb036SBrian Somers authp->authtimer.func = AuthTimeout; 3073b0f8d2eSBrian Somers authp->authtimer.name = "auth"; 308479508cfSBrian Somers authp->authtimer.load = authp->cfg.fsm.timeout * SECTICKS; 309e2ebb036SBrian Somers authp->authtimer.arg = (void *)authp; 310479508cfSBrian Somers authp->retry = authp->cfg.fsm.maxreq; 31153c9f6c0SAtsushi Murai authp->id = 1; 312f0cdd9c0SBrian Somers (*authp->fn.req)(authp); 313dd7e2610SBrian Somers timer_Start(&authp->authtimer); 31453c9f6c0SAtsushi Murai } 31553c9f6c0SAtsushi Murai 31653c9f6c0SAtsushi Murai void 317dd7e2610SBrian Somers auth_StopTimer(struct authinfo *authp) 31853c9f6c0SAtsushi Murai { 319dd7e2610SBrian Somers timer_Stop(&authp->authtimer); 320f0cdd9c0SBrian Somers } 321f0cdd9c0SBrian Somers 322f0cdd9c0SBrian Somers struct mbuf * 323f0cdd9c0SBrian Somers auth_ReadHeader(struct authinfo *authp, struct mbuf *bp) 324f0cdd9c0SBrian Somers { 325f0cdd9c0SBrian Somers int len; 326f0cdd9c0SBrian Somers 327f0cdd9c0SBrian Somers len = mbuf_Length(bp); 328f0cdd9c0SBrian Somers if (len >= sizeof authp->in.hdr) { 329f0cdd9c0SBrian Somers bp = mbuf_Read(bp, (u_char *)&authp->in.hdr, sizeof authp->in.hdr); 330f0cdd9c0SBrian Somers if (len >= ntohs(authp->in.hdr.length)) 331f0cdd9c0SBrian Somers return bp; 332b7ff18adSBrian Somers authp->in.hdr.length = htons(0); 333b31a24caSBrian Somers log_Printf(LogWARN, "auth_ReadHeader: Short packet (%d > %d) !\n", 334b31a24caSBrian Somers ntohs(authp->in.hdr.length), len); 335b7ff18adSBrian Somers } else { 336b7ff18adSBrian Somers authp->in.hdr.length = htons(0); 337b31a24caSBrian Somers log_Printf(LogWARN, "auth_ReadHeader: Short packet header (%d > %d) !\n", 338b31a24caSBrian Somers sizeof authp->in.hdr, len); 339b7ff18adSBrian Somers } 340f0cdd9c0SBrian Somers 341f0cdd9c0SBrian Somers mbuf_Free(bp); 342f0cdd9c0SBrian Somers return NULL; 343f0cdd9c0SBrian Somers } 344f0cdd9c0SBrian Somers 345f0cdd9c0SBrian Somers struct mbuf * 346f0cdd9c0SBrian Somers auth_ReadName(struct authinfo *authp, struct mbuf *bp, int len) 347f0cdd9c0SBrian Somers { 348f0cdd9c0SBrian Somers if (len > sizeof authp->in.name - 1) 349b31a24caSBrian Somers log_Printf(LogWARN, "auth_ReadName: Name too long (%d) !\n", len); 350f0cdd9c0SBrian Somers else { 351f0cdd9c0SBrian Somers int mlen = mbuf_Length(bp); 352f0cdd9c0SBrian Somers 353f0cdd9c0SBrian Somers if (len > mlen) 354b31a24caSBrian Somers log_Printf(LogWARN, "auth_ReadName: Short packet (%d > %d) !\n", 355b31a24caSBrian Somers len, mlen); 356f0cdd9c0SBrian Somers else { 357f0cdd9c0SBrian Somers bp = mbuf_Read(bp, (u_char *)authp->in.name, len); 358f0cdd9c0SBrian Somers authp->in.name[len] = '\0'; 359f0cdd9c0SBrian Somers return bp; 360f0cdd9c0SBrian Somers } 361f0cdd9c0SBrian Somers } 362f0cdd9c0SBrian Somers 363f0cdd9c0SBrian Somers *authp->in.name = '\0'; 364f0cdd9c0SBrian Somers mbuf_Free(bp); 365f0cdd9c0SBrian Somers return NULL; 36653c9f6c0SAtsushi Murai } 367