From fa0f0f255039d4f905d4c2b1e113347014c32eee Mon Sep 17 00:00:00 2001 From: Jakub Hrozek Date: Wed, 7 Nov 2012 18:28:29 +0100 Subject: Do not always return PAM_SYSTEM_ERR when offline krb5 authentication fails --- src/util/auth_utils.h | 42 ++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 42 insertions(+) create mode 100644 src/util/auth_utils.h (limited to 'src/util') diff --git a/src/util/auth_utils.h b/src/util/auth_utils.h new file mode 100644 index 000000000..e9e60a085 --- /dev/null +++ b/src/util/auth_utils.h @@ -0,0 +1,42 @@ +/* + SSSD + + Authentication utility functions + + Authors: + Jakub Hrozek + + Copyright (C) 2012 Red Hat + + This program is free software; you can redistribute it and/or modify + it under the terms of the GNU General Public License as published by + the Free Software Foundation; either version 3 of the License, or + (at your option) any later version. + + This program is distributed in the hope that it will be useful, + but WITHOUT ANY WARRANTY; without even the implied warranty of + MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the + GNU General Public License for more details. + + You should have received a copy of the GNU General Public License + along with this program. If not, see . +*/ + +#include +#include + +static inline int cached_login_pam_status(int auth_res) +{ + switch (auth_res) { + case EOK: + return PAM_SUCCESS; + case ENOENT: + return PAM_AUTHINFO_UNAVAIL; + case EINVAL: + return PAM_AUTH_ERR; + case EACCES: + return PAM_PERM_DENIED; + } + + return PAM_SYSTEM_ERR; +} -- cgit