1b528cefcSMark Murray /*
2*ae771770SStanislav Sedov * Copyright (c) 1999 Kungliga Tekniska Högskolan
3b528cefcSMark Murray * (Royal Institute of Technology, Stockholm, Sweden).
4b528cefcSMark Murray * All rights reserved.
5b528cefcSMark Murray *
6b528cefcSMark Murray * Redistribution and use in source and binary forms, with or without
7b528cefcSMark Murray * modification, are permitted provided that the following conditions
8b528cefcSMark Murray * are met:
9b528cefcSMark Murray *
10b528cefcSMark Murray * 1. Redistributions of source code must retain the above copyright
11b528cefcSMark Murray * notice, this list of conditions and the following disclaimer.
12b528cefcSMark Murray *
13b528cefcSMark Murray * 2. Redistributions in binary form must reproduce the above copyright
14b528cefcSMark Murray * notice, this list of conditions and the following disclaimer in the
15b528cefcSMark Murray * documentation and/or other materials provided with the distribution.
16b528cefcSMark Murray *
17b528cefcSMark Murray * 3. Neither the name of KTH nor the names of its contributors may be
18b528cefcSMark Murray * used to endorse or promote products derived from this software without
19b528cefcSMark Murray * specific prior written permission.
20b528cefcSMark Murray *
21b528cefcSMark Murray * THIS SOFTWARE IS PROVIDED BY KTH AND ITS CONTRIBUTORS ``AS IS'' AND ANY
22b528cefcSMark Murray * EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
23b528cefcSMark Murray * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
24b528cefcSMark Murray * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL KTH OR ITS CONTRIBUTORS BE
25b528cefcSMark Murray * LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
26b528cefcSMark Murray * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
27b528cefcSMark Murray * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR
28b528cefcSMark Murray * BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY,
29b528cefcSMark Murray * WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR
30b528cefcSMark Murray * OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF
31b528cefcSMark Murray * ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. */
32b528cefcSMark Murray
33*ae771770SStanislav Sedov /* $Id$ */
34b528cefcSMark Murray
35b528cefcSMark Murray #include <string.h>
36b528cefcSMark Murray #include <stdlib.h>
37b528cefcSMark Murray #include <krb5.h>
38b528cefcSMark Murray
39c19800e8SDoug Rabson const char* check_length(krb5_context, krb5_principal, krb5_data *);
40c19800e8SDoug Rabson
41b528cefcSMark Murray /* specify the api-version this library conforms to */
42b528cefcSMark Murray
43b528cefcSMark Murray int version = 0;
44b528cefcSMark Murray
45b528cefcSMark Murray /* just check the length of the password, this is what the default
46b528cefcSMark Murray check does, but this lets you specify the minimum length in
47b528cefcSMark Murray krb5.conf */
48b528cefcSMark Murray const char*
check_length(krb5_context context,krb5_principal prinipal,krb5_data * password)49b528cefcSMark Murray check_length(krb5_context context,
50b528cefcSMark Murray krb5_principal prinipal,
51b528cefcSMark Murray krb5_data *password)
52b528cefcSMark Murray {
53b528cefcSMark Murray int min_length = krb5_config_get_int_default(context, NULL, 6,
54b528cefcSMark Murray "password_quality",
55b528cefcSMark Murray "min_length",
56b528cefcSMark Murray NULL);
57b528cefcSMark Murray if(password->length < min_length)
58b528cefcSMark Murray return "Password too short";
59b528cefcSMark Murray return NULL;
60b528cefcSMark Murray }
61b528cefcSMark Murray
62b528cefcSMark Murray #ifdef DICTPATH
63b528cefcSMark Murray
64b528cefcSMark Murray /* use cracklib to check password quality; this requires a patch for
65b528cefcSMark Murray cracklib that can be found at
66b528cefcSMark Murray ftp://ftp.pdc.kth.se/pub/krb/src/cracklib.patch */
67b528cefcSMark Murray
68b528cefcSMark Murray const char*
check_cracklib(krb5_context context,krb5_principal principal,krb5_data * password)69b528cefcSMark Murray check_cracklib(krb5_context context,
70b528cefcSMark Murray krb5_principal principal,
71b528cefcSMark Murray krb5_data *password)
72b528cefcSMark Murray {
73b528cefcSMark Murray char *s = malloc(password->length + 1);
74b528cefcSMark Murray char *msg;
75b528cefcSMark Murray char *strings[2];
76b528cefcSMark Murray if(s == NULL)
77b528cefcSMark Murray return NULL; /* XXX */
78b528cefcSMark Murray strings[0] = principal->name.name_string.val[0]; /* XXX */
79b528cefcSMark Murray strings[1] = NULL;
80b528cefcSMark Murray memcpy(s, password->data, password->length);
81b528cefcSMark Murray s[password->length] = '\0';
82b528cefcSMark Murray msg = FascistCheck(s, DICTPATH, strings);
83b528cefcSMark Murray memset(s, 0, password->length);
84b528cefcSMark Murray free(s);
85b528cefcSMark Murray return msg;
86b528cefcSMark Murray }
87b528cefcSMark Murray #endif
88