xref: /freebsd-src/crypto/heimdal/lib/kadm5/sample_passwd_check.c (revision 6a068746777241722b2b32c5d0bc443a2a64d80b)
1b528cefcSMark Murray /*
2*ae771770SStanislav Sedov  * Copyright (c) 1999 Kungliga Tekniska Högskolan
3b528cefcSMark Murray  * (Royal Institute of Technology, Stockholm, Sweden).
4b528cefcSMark Murray  * All rights reserved.
5b528cefcSMark Murray  *
6b528cefcSMark Murray  * Redistribution and use in source and binary forms, with or without
7b528cefcSMark Murray  * modification, are permitted provided that the following conditions
8b528cefcSMark Murray  * are met:
9b528cefcSMark Murray  *
10b528cefcSMark Murray  * 1. Redistributions of source code must retain the above copyright
11b528cefcSMark Murray  *    notice, this list of conditions and the following disclaimer.
12b528cefcSMark Murray  *
13b528cefcSMark Murray  * 2. Redistributions in binary form must reproduce the above copyright
14b528cefcSMark Murray  *    notice, this list of conditions and the following disclaimer in the
15b528cefcSMark Murray  *    documentation and/or other materials provided with the distribution.
16b528cefcSMark Murray  *
17b528cefcSMark Murray  * 3. Neither the name of KTH nor the names of its contributors may be
18b528cefcSMark Murray  *    used to endorse or promote products derived from this software without
19b528cefcSMark Murray  *    specific prior written permission.
20b528cefcSMark Murray  *
21b528cefcSMark Murray  * THIS SOFTWARE IS PROVIDED BY KTH AND ITS CONTRIBUTORS ``AS IS'' AND ANY
22b528cefcSMark Murray  * EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
23b528cefcSMark Murray  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
24b528cefcSMark Murray  * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL KTH OR ITS CONTRIBUTORS BE
25b528cefcSMark Murray  * LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
26b528cefcSMark Murray  * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
27b528cefcSMark Murray  * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR
28b528cefcSMark Murray  * BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY,
29b528cefcSMark Murray  * WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR
30b528cefcSMark Murray  * OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF
31b528cefcSMark Murray  * ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. */
32b528cefcSMark Murray 
33*ae771770SStanislav Sedov /* $Id$ */
34b528cefcSMark Murray 
35b528cefcSMark Murray #include <string.h>
36b528cefcSMark Murray #include <stdlib.h>
37b528cefcSMark Murray #include <krb5.h>
38b528cefcSMark Murray 
39c19800e8SDoug Rabson const char* check_length(krb5_context, krb5_principal, krb5_data *);
40c19800e8SDoug Rabson 
41b528cefcSMark Murray /* specify the api-version this library conforms to */
42b528cefcSMark Murray 
43b528cefcSMark Murray int version = 0;
44b528cefcSMark Murray 
45b528cefcSMark Murray /* just check the length of the password, this is what the default
46b528cefcSMark Murray    check does, but this lets you specify the minimum length in
47b528cefcSMark Murray    krb5.conf */
48b528cefcSMark Murray const char*
check_length(krb5_context context,krb5_principal prinipal,krb5_data * password)49b528cefcSMark Murray check_length(krb5_context context,
50b528cefcSMark Murray              krb5_principal prinipal,
51b528cefcSMark Murray              krb5_data *password)
52b528cefcSMark Murray {
53b528cefcSMark Murray     int min_length = krb5_config_get_int_default(context, NULL, 6,
54b528cefcSMark Murray 						 "password_quality",
55b528cefcSMark Murray 						 "min_length",
56b528cefcSMark Murray 						 NULL);
57b528cefcSMark Murray     if(password->length < min_length)
58b528cefcSMark Murray 	return "Password too short";
59b528cefcSMark Murray     return NULL;
60b528cefcSMark Murray }
61b528cefcSMark Murray 
62b528cefcSMark Murray #ifdef DICTPATH
63b528cefcSMark Murray 
64b528cefcSMark Murray /* use cracklib to check password quality; this requires a patch for
65b528cefcSMark Murray    cracklib that can be found at
66b528cefcSMark Murray    ftp://ftp.pdc.kth.se/pub/krb/src/cracklib.patch */
67b528cefcSMark Murray 
68b528cefcSMark Murray const char*
check_cracklib(krb5_context context,krb5_principal principal,krb5_data * password)69b528cefcSMark Murray check_cracklib(krb5_context context,
70b528cefcSMark Murray 	       krb5_principal principal,
71b528cefcSMark Murray 	       krb5_data *password)
72b528cefcSMark Murray {
73b528cefcSMark Murray     char *s = malloc(password->length + 1);
74b528cefcSMark Murray     char *msg;
75b528cefcSMark Murray     char *strings[2];
76b528cefcSMark Murray     if(s == NULL)
77b528cefcSMark Murray 	return NULL; /* XXX */
78b528cefcSMark Murray     strings[0] = principal->name.name_string.val[0]; /* XXX */
79b528cefcSMark Murray     strings[1] = NULL;
80b528cefcSMark Murray     memcpy(s, password->data, password->length);
81b528cefcSMark Murray     s[password->length] = '\0';
82b528cefcSMark Murray     msg = FascistCheck(s, DICTPATH, strings);
83b528cefcSMark Murray     memset(s, 0, password->length);
84b528cefcSMark Murray     free(s);
85b528cefcSMark Murray     return msg;
86b528cefcSMark Murray }
87b528cefcSMark Murray #endif
88