1 | /*
|
---|
2 | * Unix SMB/CIFS implementation.
|
---|
3 | * PAM error mapping functions
|
---|
4 | * Copyright (C) Andrew Bartlett 2002
|
---|
5 | *
|
---|
6 | * This program is free software; you can redistribute it and/or modify
|
---|
7 | * it under the terms of the GNU General Public License as published by
|
---|
8 | * the Free Software Foundation; either version 2 of the License, or
|
---|
9 | * (at your option) any later version.
|
---|
10 | *
|
---|
11 | * This program is distributed in the hope that it will be useful,
|
---|
12 | * but WITHOUT ANY WARRANTY; without even the implied warranty of
|
---|
13 | * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
---|
14 | * GNU General Public License for more details.
|
---|
15 | *
|
---|
16 | * You should have received a copy of the GNU General Public License
|
---|
17 | * along with this program; if not, write to the Free Software
|
---|
18 | * Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
|
---|
19 | */
|
---|
20 |
|
---|
21 | #include "includes.h"
|
---|
22 |
|
---|
23 | #ifdef WITH_PAM
|
---|
24 | #include <security/pam_appl.h>
|
---|
25 |
|
---|
26 | #if defined(PAM_AUTHTOK_RECOVERY_ERR) && !defined(PAM_AUTHTOK_RECOVER_ERR)
|
---|
27 | #define PAM_AUTHTOK_RECOVER_ERR PAM_AUTHTOK_RECOVERY_ERR
|
---|
28 | #endif
|
---|
29 |
|
---|
30 | /* PAM -> NT_STATUS map */
|
---|
31 | static const struct {
|
---|
32 | int pam_code;
|
---|
33 | NTSTATUS ntstatus;
|
---|
34 | } pam_to_nt_status_map[] = {
|
---|
35 | {PAM_OPEN_ERR, NT_STATUS_UNSUCCESSFUL},
|
---|
36 | {PAM_SYMBOL_ERR, NT_STATUS_UNSUCCESSFUL},
|
---|
37 | {PAM_SERVICE_ERR, NT_STATUS_UNSUCCESSFUL},
|
---|
38 | {PAM_SYSTEM_ERR, NT_STATUS_UNSUCCESSFUL},
|
---|
39 | {PAM_BUF_ERR, NT_STATUS_NO_MEMORY},
|
---|
40 | {PAM_PERM_DENIED, NT_STATUS_ACCESS_DENIED},
|
---|
41 | {PAM_AUTH_ERR, NT_STATUS_WRONG_PASSWORD},
|
---|
42 | {PAM_CRED_INSUFFICIENT, NT_STATUS_INSUFFICIENT_LOGON_INFO}, /* FIXME: Is this correct? */
|
---|
43 | {PAM_AUTHINFO_UNAVAIL, NT_STATUS_LOGON_FAILURE},
|
---|
44 | {PAM_USER_UNKNOWN, NT_STATUS_NO_SUCH_USER},
|
---|
45 | {PAM_MAXTRIES, NT_STATUS_REMOTE_SESSION_LIMIT}, /* FIXME: Is this correct? */
|
---|
46 | {PAM_NEW_AUTHTOK_REQD, NT_STATUS_PASSWORD_MUST_CHANGE},
|
---|
47 | {PAM_ACCT_EXPIRED, NT_STATUS_ACCOUNT_EXPIRED},
|
---|
48 | {PAM_SESSION_ERR, NT_STATUS_INSUFFICIENT_RESOURCES},
|
---|
49 | {PAM_CRED_UNAVAIL, NT_STATUS_NO_TOKEN}, /* FIXME: Is this correct? */
|
---|
50 | {PAM_CRED_EXPIRED, NT_STATUS_PASSWORD_EXPIRED}, /* FIXME: Is this correct? */
|
---|
51 | {PAM_CRED_ERR, NT_STATUS_UNSUCCESSFUL},
|
---|
52 | {PAM_AUTHTOK_ERR, NT_STATUS_UNSUCCESSFUL},
|
---|
53 | #ifdef PAM_AUTHTOK_RECOVER_ERR
|
---|
54 | {PAM_AUTHTOK_RECOVER_ERR, NT_STATUS_UNSUCCESSFUL},
|
---|
55 | #endif
|
---|
56 | {PAM_AUTHTOK_EXPIRED, NT_STATUS_PASSWORD_EXPIRED},
|
---|
57 | {PAM_SUCCESS, NT_STATUS_OK}
|
---|
58 | };
|
---|
59 |
|
---|
60 | /* NT_STATUS -> PAM map */
|
---|
61 | static const struct {
|
---|
62 | NTSTATUS ntstatus;
|
---|
63 | int pam_code;
|
---|
64 | } nt_status_to_pam_map[] = {
|
---|
65 | {NT_STATUS_UNSUCCESSFUL, PAM_SYSTEM_ERR},
|
---|
66 | {NT_STATUS_NO_SUCH_USER, PAM_USER_UNKNOWN},
|
---|
67 | {NT_STATUS_WRONG_PASSWORD, PAM_AUTH_ERR},
|
---|
68 | {NT_STATUS_LOGON_FAILURE, PAM_AUTH_ERR},
|
---|
69 | {NT_STATUS_ACCOUNT_EXPIRED, PAM_ACCT_EXPIRED},
|
---|
70 | {NT_STATUS_PASSWORD_EXPIRED, PAM_AUTHTOK_EXPIRED},
|
---|
71 | {NT_STATUS_PASSWORD_MUST_CHANGE, PAM_NEW_AUTHTOK_REQD},
|
---|
72 | {NT_STATUS_ACCOUNT_LOCKED_OUT, PAM_MAXTRIES},
|
---|
73 | {NT_STATUS_NO_MEMORY, PAM_BUF_ERR},
|
---|
74 | {NT_STATUS_PASSWORD_RESTRICTION, PAM_PERM_DENIED},
|
---|
75 | {NT_STATUS_BACKUP_CONTROLLER, PAM_AUTHINFO_UNAVAIL},
|
---|
76 | {NT_STATUS_DOMAIN_CONTROLLER_NOT_FOUND, PAM_AUTHINFO_UNAVAIL},
|
---|
77 | {NT_STATUS_NO_LOGON_SERVERS, PAM_AUTHINFO_UNAVAIL},
|
---|
78 | {NT_STATUS_INVALID_WORKSTATION, PAM_PERM_DENIED},
|
---|
79 | {NT_STATUS_NOLOGON_WORKSTATION_TRUST_ACCOUNT, PAM_AUTHINFO_UNAVAIL},
|
---|
80 | {NT_STATUS_NOLOGON_SERVER_TRUST_ACCOUNT, PAM_AUTHINFO_UNAVAIL},
|
---|
81 | {NT_STATUS_NOLOGON_INTERDOMAIN_TRUST_ACCOUNT, PAM_AUTHINFO_UNAVAIL},
|
---|
82 | {NT_STATUS_OK, PAM_SUCCESS}
|
---|
83 | };
|
---|
84 |
|
---|
85 | /*****************************************************************************
|
---|
86 | convert a PAM error to a NT status32 code
|
---|
87 | *****************************************************************************/
|
---|
88 | NTSTATUS pam_to_nt_status(int pam_error)
|
---|
89 | {
|
---|
90 | int i;
|
---|
91 | if (pam_error == 0) return NT_STATUS_OK;
|
---|
92 |
|
---|
93 | for (i=0; NT_STATUS_V(pam_to_nt_status_map[i].ntstatus); i++) {
|
---|
94 | if (pam_error == pam_to_nt_status_map[i].pam_code)
|
---|
95 | return pam_to_nt_status_map[i].ntstatus;
|
---|
96 | }
|
---|
97 | return NT_STATUS_UNSUCCESSFUL;
|
---|
98 | }
|
---|
99 |
|
---|
100 | /*****************************************************************************
|
---|
101 | convert an NT status32 code to a PAM error
|
---|
102 | *****************************************************************************/
|
---|
103 | int nt_status_to_pam(NTSTATUS nt_status)
|
---|
104 | {
|
---|
105 | int i;
|
---|
106 | if NT_STATUS_IS_OK(nt_status) return PAM_SUCCESS;
|
---|
107 |
|
---|
108 | for (i=0; NT_STATUS_V(nt_status_to_pam_map[i].ntstatus); i++) {
|
---|
109 | if (NT_STATUS_EQUAL(nt_status,nt_status_to_pam_map[i].ntstatus))
|
---|
110 | return nt_status_to_pam_map[i].pam_code;
|
---|
111 | }
|
---|
112 | return PAM_SYSTEM_ERR;
|
---|
113 | }
|
---|
114 |
|
---|
115 | #else
|
---|
116 |
|
---|
117 | /*****************************************************************************
|
---|
118 | convert a PAM error to a NT status32 code
|
---|
119 | *****************************************************************************/
|
---|
120 | NTSTATUS pam_to_nt_status(int pam_error)
|
---|
121 | {
|
---|
122 | if (pam_error == 0) return NT_STATUS_OK;
|
---|
123 | return NT_STATUS_UNSUCCESSFUL;
|
---|
124 | }
|
---|
125 |
|
---|
126 | /*****************************************************************************
|
---|
127 | convert an NT status32 code to a PAM error
|
---|
128 | *****************************************************************************/
|
---|
129 | int nt_status_to_pam(NTSTATUS nt_status)
|
---|
130 | {
|
---|
131 | if (NT_STATUS_EQUAL(nt_status, NT_STATUS_OK)) return 0;
|
---|
132 | return 4; /* PAM_SYSTEM_ERR */
|
---|
133 | }
|
---|
134 |
|
---|
135 | #endif
|
---|
136 |
|
---|