summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorOndrej Kos <okos@redhat.com>2013-07-17 13:42:57 +0200
committerJakub Hrozek <jhrozek@redhat.com>2013-07-18 16:04:42 +0200
commitfeece80b0f52ebe883d8e211cfe8faa93bd991f7 (patch)
tree1cd02e55c8a281bbca79d0f411d9e3a337210ae0
parent3df593099ecb4b7570548bc14ca58960f79bc9b2 (diff)
downloadsssd-feece80b0f52ebe883d8e211cfe8faa93bd991f7.tar.gz
sssd-feece80b0f52ebe883d8e211cfe8faa93bd991f7.tar.xz
sssd-feece80b0f52ebe883d8e211cfe8faa93bd991f7.zip
KRB: Handle empty password gracefully
https://fedorahosted.org/sssd/ticket/1814 Return authentication error when empty password is passed.
-rw-r--r--src/providers/krb5/krb5_auth.c11
1 files changed, 11 insertions, 0 deletions
diff --git a/src/providers/krb5/krb5_auth.c b/src/providers/krb5/krb5_auth.c
index 22495f570..4c2fe0f24 100644
--- a/src/providers/krb5/krb5_auth.c
+++ b/src/providers/krb5/krb5_auth.c
@@ -495,6 +495,17 @@ struct tevent_req *krb5_auth_send(TALLOC_CTX *mem_ctx,
case SSS_PAM_AUTHENTICATE:
case SSS_PAM_CHAUTHTOK:
if (sss_authtok_get_type(pd->authtok) != SSS_AUTHTOK_TYPE_PASSWORD) {
+ /* handle empty password gracefully */
+ if (sss_authtok_get_type(pd->authtok) == SSS_AUTHTOK_TYPE_EMPTY) {
+ DEBUG(SSSDBG_CRIT_FAILURE,
+ ("Illegal zero-length authtok for user [%s]\n",
+ pd->user));
+ state->pam_status = PAM_AUTH_ERR;
+ state->dp_err = DP_ERR_OK;
+ ret = EOK;
+ goto done;
+ }
+
DEBUG(SSSDBG_CRIT_FAILURE,
("Wrong authtok type for user [%s]. " \
"Expected [%d], got [%d]\n", pd->user,