2007-10-07 11:44:44 +00:00
|
|
|
#include <config.h>
|
|
|
|
|
2007-11-10 23:46:11 +00:00
|
|
|
#ident "$Id$"
|
2007-10-07 11:47:01 +00:00
|
|
|
|
2007-10-07 11:46:34 +00:00
|
|
|
#include <pwd.h>
|
|
|
|
#include <stdio.h>
|
2007-10-07 11:44:44 +00:00
|
|
|
#include "prototypes.h"
|
|
|
|
#include "defines.h"
|
|
|
|
#include "pwauth.h"
|
|
|
|
#ifdef HAVE_SHADOW_H
|
|
|
|
#include <shadow.h>
|
|
|
|
#endif
|
|
|
|
#ifdef USE_PAM
|
|
|
|
#include "pam_defs.h"
|
|
|
|
#endif
|
|
|
|
#define WRONGPWD2 "incorrect password for `%s'"
|
2007-10-07 11:46:07 +00:00
|
|
|
void passwd_check (const char *user, const char *passwd, const char *progname)
|
2007-10-07 11:44:44 +00:00
|
|
|
{
|
|
|
|
#ifdef USE_PAM
|
|
|
|
pam_handle_t *pamh = NULL;
|
|
|
|
int retcode;
|
|
|
|
|
2007-10-07 11:45:23 +00:00
|
|
|
if (pam_start (progname, user, &conv, &pamh)) {
|
|
|
|
bailout:
|
|
|
|
SYSLOG ((LOG_WARN, WRONGPWD2, user));
|
|
|
|
sleep (1);
|
|
|
|
fprintf (stderr, _("Incorrect password for %s.\n"), user);
|
|
|
|
exit (1);
|
2007-10-07 11:44:44 +00:00
|
|
|
}
|
2007-10-07 11:45:23 +00:00
|
|
|
if (pam_authenticate (pamh, 0))
|
2007-10-07 11:44:44 +00:00
|
|
|
goto bailout;
|
|
|
|
|
2007-10-07 11:45:23 +00:00
|
|
|
retcode = pam_acct_mgmt (pamh, 0);
|
2007-10-07 11:45:40 +00:00
|
|
|
if (retcode == PAM_NEW_AUTHTOK_REQD)
|
2007-10-07 11:45:23 +00:00
|
|
|
retcode = pam_chauthtok (pamh, PAM_CHANGE_EXPIRED_AUTHTOK);
|
2007-10-07 11:45:49 +00:00
|
|
|
if (retcode)
|
2007-10-07 11:44:44 +00:00
|
|
|
goto bailout;
|
|
|
|
|
2007-10-07 11:45:23 +00:00
|
|
|
if (pam_setcred (pamh, 0))
|
2007-10-07 11:44:44 +00:00
|
|
|
goto bailout;
|
|
|
|
|
|
|
|
/* no need to establish a session; this isn't a session-oriented
|
|
|
|
* activity... */
|
|
|
|
|
2007-10-07 11:45:23 +00:00
|
|
|
#else /* !USE_PAM */
|
2007-10-07 11:44:44 +00:00
|
|
|
|
|
|
|
struct spwd *sp;
|
|
|
|
|
2007-10-07 11:45:23 +00:00
|
|
|
if ((sp = getspnam (user)))
|
2007-10-07 11:44:44 +00:00
|
|
|
passwd = sp->sp_pwdp;
|
2007-10-07 11:45:23 +00:00
|
|
|
endspent ();
|
|
|
|
if (pw_auth (passwd, user, PW_LOGIN, (char *) 0) != 0) {
|
|
|
|
SYSLOG ((LOG_WARN, WRONGPWD2, user));
|
|
|
|
sleep (1);
|
|
|
|
fprintf (stderr, _("Incorrect password for %s.\n"), user);
|
|
|
|
exit (1);
|
2007-10-07 11:44:44 +00:00
|
|
|
}
|
2007-10-07 11:45:23 +00:00
|
|
|
#endif /* !USE_PAM */
|
2007-10-07 11:44:44 +00:00
|
|
|
}
|