1/*	$NetBSD$	*/
2
3/*-
4 * Copyright (c) 2001,2003 Networks Associates Technology, Inc.
5 * All rights reserved.
6 *
7 * This software was developed for the FreeBSD Project by ThinkSec AS and
8 * NAI Labs, the Security Research Division of Network Associates, Inc.
9 * under DARPA/SPAWAR contract N66001-01-C-8035 ("CBOSS"), as part of the
10 * DARPA CHATS research program.
11 *
12 * Redistribution and use in source and binary forms, with or without
13 * modification, are permitted provided that the following conditions
14 * are met:
15 * 1. Redistributions of source code must retain the above copyright
16 *    notice, this list of conditions and the following disclaimer.
17 * 2. Redistributions in binary form must reproduce the above copyright
18 *    notice, this list of conditions and the following disclaimer in the
19 *    documentation and/or other materials provided with the distribution.
20 * 3. The name of the author may not be used to endorse or promote
21 *    products derived from this software without specific prior written
22 *    permission.
23 *
24 * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
25 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
26 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
27 * ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
28 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
29 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
30 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
31 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
32 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
33 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
34 * SUCH DAMAGE.
35 */
36
37#include <sys/cdefs.h>
38#ifdef __FreeBSD__
39__FBSDID("$FreeBSD: src/lib/libpam/modules/pam_echo/pam_echo.c,v 1.4 2003/12/11 13:55:15 des Exp $");
40#else
41__RCSID("$NetBSD$");
42#endif
43
44#include <stdio.h>
45#include <stdlib.h>
46#include <string.h>
47
48#include <security/pam_appl.h>
49#include <security/pam_modules.h>
50#include <security/openpam.h>
51
52static int
53_pam_echo(pam_handle_t *pamh, int flags,
54    int argc, const char *argv[])
55{
56	char msg[PAM_MAX_MSG_SIZE];
57	const void *str;
58	const char *p, *q;
59	int err, i, item;
60	size_t len;
61
62	if (flags & PAM_SILENT)
63		return (PAM_SUCCESS);
64	for (i = 0, len = 0; i < argc && len < sizeof(msg) - 1; ++i) {
65		if (i > 0)
66			msg[len++] = ' ';
67		for (p = argv[i]; *p != '\0' && len < sizeof(msg) - 1; ++p) {
68			if (*p != '%' || p[1] == '\0') {
69				msg[len++] = *p;
70				continue;
71			}
72			switch (*++p) {
73			case 'H':
74				item = PAM_RHOST;
75				break;
76			case 'h':
77				/* not implemented */
78				item = -1;
79				break;
80			case 's':
81				item = PAM_SERVICE;
82				break;
83			case 't':
84				item = PAM_TTY;
85				break;
86			case 'U':
87				item = PAM_RUSER;
88				break;
89			case 'u':
90				item = PAM_USER;
91				break;
92			default:
93				item = -1;
94				msg[len++] = *p;
95				break;
96			}
97			if (item == -1)
98				continue;
99			err = pam_get_item(pamh, item, &str);
100			if (err != PAM_SUCCESS)
101				return (err);
102			if (str == NULL)
103				str = "(null)";
104			for (q = str; *q != '\0' && len < sizeof(msg) - 1; ++q)
105				msg[len++] = *q;
106		}
107	}
108	msg[len] = '\0';
109	return (pam_info(pamh, "%s", msg));
110}
111
112PAM_EXTERN int
113pam_sm_authenticate(pam_handle_t *pamh, int flags,
114    int argc, const char *argv[])
115{
116
117	return (_pam_echo(pamh, flags, argc, argv));
118}
119
120PAM_EXTERN int
121pam_sm_setcred(pam_handle_t *pamh __unused, int flags __unused,
122    int argc __unused, const char *argv[] __unused)
123{
124
125	return (PAM_SUCCESS);
126}
127
128PAM_EXTERN int
129pam_sm_acct_mgmt(pam_handle_t *pamh, int flags,
130    int argc, const char *argv[])
131{
132
133	return (_pam_echo(pamh, flags, argc, argv));
134}
135
136PAM_EXTERN int
137pam_sm_open_session(pam_handle_t *pamh, int flags,
138    int argc, const char *argv[])
139{
140
141	return (_pam_echo(pamh, flags, argc, argv));
142}
143
144PAM_EXTERN int
145pam_sm_close_session(pam_handle_t *pamh, int flags,
146    int argc, const char *argv[])
147{
148
149	return (_pam_echo(pamh, flags, argc, argv));
150}
151
152PAM_EXTERN int
153pam_sm_chauthtok(pam_handle_t *pamh, int flags,
154    int argc, const char *argv[])
155{
156
157	if (flags & PAM_PRELIM_CHECK)
158		return (PAM_SUCCESS);
159	return (_pam_echo(pamh, flags, argc, argv));
160}
161
162PAM_MODULE_ENTRY("pam_echo");
163