pam_setcred.c revision 1.1 1 1.1 christos /*-
2 1.1 christos * Copyright (c) 2002-2003 Networks Associates Technology, Inc.
3 1.1 christos * Copyright (c) 2004-2011 Dag-Erling Smrgrav
4 1.1 christos * All rights reserved.
5 1.1 christos *
6 1.1 christos * This software was developed for the FreeBSD Project by ThinkSec AS and
7 1.1 christos * Network Associates Laboratories, the Security Research Division of
8 1.1 christos * Network Associates, Inc. under DARPA/SPAWAR contract N66001-01-C-8035
9 1.1 christos * ("CBOSS"), as part of the DARPA CHATS research program.
10 1.1 christos *
11 1.1 christos * Redistribution and use in source and binary forms, with or without
12 1.1 christos * modification, are permitted provided that the following conditions
13 1.1 christos * are met:
14 1.1 christos * 1. Redistributions of source code must retain the above copyright
15 1.1 christos * notice, this list of conditions and the following disclaimer.
16 1.1 christos * 2. Redistributions in binary form must reproduce the above copyright
17 1.1 christos * notice, this list of conditions and the following disclaimer in the
18 1.1 christos * documentation and/or other materials provided with the distribution.
19 1.1 christos * 3. The name of the author may not be used to endorse or promote
20 1.1 christos * products derived from this software without specific prior written
21 1.1 christos * permission.
22 1.1 christos *
23 1.1 christos * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
24 1.1 christos * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
25 1.1 christos * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
26 1.1 christos * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
27 1.1 christos * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
28 1.1 christos * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
29 1.1 christos * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
30 1.1 christos * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
31 1.1 christos * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
32 1.1 christos * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
33 1.1 christos * SUCH DAMAGE.
34 1.1 christos *
35 1.1 christos * Id: pam_setcred.c 648 2013-03-05 17:54:27Z des
36 1.1 christos */
37 1.1 christos
38 1.1 christos #ifdef HAVE_CONFIG_H
39 1.1 christos # include "config.h"
40 1.1 christos #endif
41 1.1 christos
42 1.1 christos #include <sys/param.h>
43 1.1 christos
44 1.1 christos #include <security/pam_appl.h>
45 1.1 christos
46 1.1 christos #include "openpam_impl.h"
47 1.1 christos
48 1.1 christos /*
49 1.1 christos * XSSO 4.2.1
50 1.1 christos * XSSO 6 page 57
51 1.1 christos *
52 1.1 christos * Modify / delete user credentials for an authentication service
53 1.1 christos */
54 1.1 christos
55 1.1 christos int
56 1.1 christos pam_setcred(pam_handle_t *pamh,
57 1.1 christos int flags)
58 1.1 christos {
59 1.1 christos int r;
60 1.1 christos
61 1.1 christos ENTER();
62 1.1 christos if (flags & ~(PAM_SILENT|PAM_ESTABLISH_CRED|PAM_DELETE_CRED|
63 1.1 christos PAM_REINITIALIZE_CRED|PAM_REFRESH_CRED))
64 1.1 christos RETURNC(PAM_SYMBOL_ERR);
65 1.1 christos /* XXX enforce exclusivity */
66 1.1 christos r = openpam_dispatch(pamh, PAM_SM_SETCRED, flags);
67 1.1 christos RETURNC(r);
68 1.1 christos }
69 1.1 christos
70 1.1 christos /*
71 1.1 christos * Error codes:
72 1.1 christos *
73 1.1 christos * =openpam_dispatch
74 1.1 christos * =pam_sm_setcred
75 1.1 christos * !PAM_IGNORE
76 1.1 christos * PAM_SYMBOL_ERR
77 1.1 christos */
78 1.1 christos
79 1.1 christos /**
80 1.1 christos * The =pam_setcred function manages the application's credentials.
81 1.1 christos *
82 1.1 christos * The =flags argument is the binary or of zero or more of the following
83 1.1 christos * values:
84 1.1 christos *
85 1.1 christos * =PAM_SILENT:
86 1.1 christos * Do not emit any messages.
87 1.1 christos * =PAM_ESTABLISH_CRED:
88 1.1 christos * Establish the credentials of the target user.
89 1.1 christos * =PAM_DELETE_CRED:
90 1.1 christos * Revoke all established credentials.
91 1.1 christos * =PAM_REINITIALIZE_CRED:
92 1.1 christos * Fully reinitialise credentials.
93 1.1 christos * =PAM_REFRESH_CRED:
94 1.1 christos * Refresh credentials.
95 1.1 christos *
96 1.1 christos * The latter four are mutually exclusive.
97 1.1 christos *
98 1.1 christos * If any other bits are set, =pam_setcred will return =PAM_SYMBOL_ERR.
99 1.1 christos */
100