Home | History | Annotate | Line # | Download | only in libradius
radlib.c revision 1.8
      1  1.8  christos /* $NetBSD: radlib.c,v 1.8 2005/11/25 23:20:00 christos Exp $ */
      2  1.1      manu 
      3  1.1      manu /*-
      4  1.1      manu  * Copyright 1998 Juniper Networks, Inc.
      5  1.1      manu  * All rights reserved.
      6  1.1      manu  *
      7  1.1      manu  * Redistribution and use in source and binary forms, with or without
      8  1.1      manu  * modification, are permitted provided that the following conditions
      9  1.1      manu  * are met:
     10  1.1      manu  * 1. Redistributions of source code must retain the above copyright
     11  1.1      manu  *    notice, this list of conditions and the following disclaimer.
     12  1.1      manu  * 2. Redistributions in binary form must reproduce the above copyright
     13  1.1      manu  *    notice, this list of conditions and the following disclaimer in the
     14  1.1      manu  *    documentation and/or other materials provided with the distribution.
     15  1.1      manu  *
     16  1.1      manu  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
     17  1.1      manu  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
     18  1.1      manu  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
     19  1.1      manu  * ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
     20  1.1      manu  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
     21  1.1      manu  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
     22  1.1      manu  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
     23  1.1      manu  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
     24  1.1      manu  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
     25  1.1      manu  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
     26  1.1      manu  * SUCH DAMAGE.
     27  1.1      manu  */
     28  1.1      manu 
     29  1.1      manu #include <sys/cdefs.h>
     30  1.1      manu #ifdef __FreeBSD__
     31  1.1      manu __FBSDID("$FreeBSD: /repoman/r/ncvs/src/lib/libradius/radlib.c,v 1.12 2004/06/14 20:55:30 stefanf Exp $");
     32  1.1      manu #else
     33  1.8  christos __RCSID("$NetBSD: radlib.c,v 1.8 2005/11/25 23:20:00 christos Exp $");
     34  1.1      manu #endif
     35  1.1      manu 
     36  1.1      manu #include <sys/types.h>
     37  1.1      manu #include <sys/socket.h>
     38  1.1      manu #include <sys/time.h>
     39  1.1      manu #include <netinet/in.h>
     40  1.1      manu #include <arpa/inet.h>
     41  1.1      manu #ifdef WITH_SSL
     42  1.1      manu #include <openssl/hmac.h>
     43  1.1      manu #include <openssl/md5.h>
     44  1.1      manu #define MD5Init MD5_Init
     45  1.1      manu #define MD5Update MD5_Update
     46  1.1      manu #define MD5Final MD5_Final
     47  1.7  christos #define MD5Len size_t
     48  1.6  christos #define MD5Buf const void *
     49  1.1      manu #else
     50  1.1      manu #define MD5_DIGEST_LENGTH 16
     51  1.2  christos #define MD5Len unsigned int
     52  1.6  christos #define MD5Buf const unsigned char *
     53  1.1      manu #include <md5.h>
     54  1.1      manu #endif
     55  1.1      manu 
     56  1.1      manu /* We need the MPPE_KEY_LEN define */
     57  1.1      manu #ifdef __FreeBSD__
     58  1.1      manu #include <netgraph/ng_mppc.h>
     59  1.1      manu #else
     60  1.1      manu #define MPPE_KEY_LEN 16
     61  1.1      manu #endif
     62  1.1      manu 
     63  1.1      manu #include <errno.h>
     64  1.1      manu #include <netdb.h>
     65  1.1      manu #include <stdarg.h>
     66  1.1      manu #include <stddef.h>
     67  1.1      manu #include <stdio.h>
     68  1.1      manu #include <stdlib.h>
     69  1.1      manu #include <string.h>
     70  1.1      manu #include <unistd.h>
     71  1.1      manu 
     72  1.1      manu #include "radlib_private.h"
     73  1.1      manu #if !defined(__printflike)
     74  1.1      manu #define __printflike(fmtarg, firstvararg)				\
     75  1.1      manu 	__attribute__((__format__ (__printf__, fmtarg, firstvararg)))
     76  1.1      manu #endif
     77  1.1      manu 
     78  1.1      manu #ifdef __NetBSD__
     79  1.1      manu #define srandomdev(x)
     80  1.1      manu #define random arc4random
     81  1.1      manu #endif
     82  1.1      manu 
     83  1.1      manu static void	 clear_password(struct rad_handle *);
     84  1.1      manu static void	 generr(struct rad_handle *, const char *, ...)
     85  1.1      manu 		    __printflike(2, 3);
     86  1.1      manu static void	 insert_scrambled_password(struct rad_handle *, int);
     87  1.1      manu static void	 insert_request_authenticator(struct rad_handle *, int);
     88  1.1      manu static void	 insert_message_authenticator(struct rad_handle *, int);
     89  1.1      manu static int	 is_valid_response(struct rad_handle *, int,
     90  1.1      manu 		    const struct sockaddr_in *);
     91  1.1      manu static int	 put_password_attr(struct rad_handle *, int,
     92  1.1      manu 		    const void *, size_t);
     93  1.1      manu static int	 put_raw_attr(struct rad_handle *, int,
     94  1.1      manu 		    const void *, size_t);
     95  1.3  christos static int	 split(char *, const char *[], size_t, char *, size_t);
     96  1.1      manu 
     97  1.1      manu static void
     98  1.1      manu clear_password(struct rad_handle *h)
     99  1.1      manu {
    100  1.1      manu 	if (h->pass_len != 0) {
    101  1.3  christos 		(void)memset(h->pass, 0, h->pass_len);
    102  1.1      manu 		h->pass_len = 0;
    103  1.1      manu 	}
    104  1.1      manu 	h->pass_pos = 0;
    105  1.1      manu }
    106  1.1      manu 
    107  1.1      manu static void
    108  1.1      manu generr(struct rad_handle *h, const char *format, ...)
    109  1.1      manu {
    110  1.1      manu 	va_list		 ap;
    111  1.1      manu 
    112  1.1      manu 	va_start(ap, format);
    113  1.3  christos 	vsnprintf(h->errmsg, (size_t)ERRSIZE, format, ap);
    114  1.1      manu 	va_end(ap);
    115  1.1      manu }
    116  1.1      manu 
    117  1.1      manu static void
    118  1.1      manu insert_scrambled_password(struct rad_handle *h, int srv)
    119  1.1      manu {
    120  1.1      manu 	MD5_CTX ctx;
    121  1.1      manu 	unsigned char md5[MD5_DIGEST_LENGTH];
    122  1.1      manu 	const struct rad_server *srvp;
    123  1.3  christos 	size_t padded_len, pos;
    124  1.1      manu 
    125  1.1      manu 	srvp = &h->servers[srv];
    126  1.3  christos 	padded_len = h->pass_len == 0 ? (size_t)16 : (h->pass_len+15) & ~0xf;
    127  1.1      manu 
    128  1.3  christos 	(void)memcpy(md5, &h->request[POS_AUTH], (size_t)LEN_AUTH);
    129  1.1      manu 	for (pos = 0;  pos < padded_len;  pos += 16) {
    130  1.1      manu 		int i;
    131  1.1      manu 
    132  1.1      manu 		/* Calculate the new scrambler */
    133  1.1      manu 		MD5Init(&ctx);
    134  1.6  christos 		MD5Update(&ctx, (MD5Buf)srvp->secret,
    135  1.2  christos 		    (MD5Len)strlen(srvp->secret));
    136  1.2  christos 		MD5Update(&ctx, md5, (MD5Len)16);
    137  1.1      manu 		MD5Final(md5, &ctx);
    138  1.1      manu 
    139  1.1      manu 		/*
    140  1.1      manu 		 * Mix in the current chunk of the password, and copy
    141  1.1      manu 		 * the result into the right place in the request.  Also
    142  1.1      manu 		 * modify the scrambler in place, since we will use this
    143  1.1      manu 		 * in calculating the scrambler for next time.
    144  1.1      manu 		 */
    145  1.1      manu 		for (i = 0;  i < 16;  i++)
    146  1.1      manu 			h->request[h->pass_pos + pos + i] =
    147  1.1      manu 			    md5[i] ^= h->pass[pos + i];
    148  1.1      manu 	}
    149  1.1      manu }
    150  1.1      manu 
    151  1.1      manu static void
    152  1.1      manu insert_request_authenticator(struct rad_handle *h, int srv)
    153  1.1      manu {
    154  1.1      manu 	MD5_CTX ctx;
    155  1.1      manu 	const struct rad_server *srvp;
    156  1.1      manu 
    157  1.1      manu 	srvp = &h->servers[srv];
    158  1.1      manu 
    159  1.1      manu 	/* Create the request authenticator */
    160  1.1      manu 	MD5Init(&ctx);
    161  1.2  christos 	MD5Update(&ctx, &h->request[POS_CODE],
    162  1.2  christos 	    (MD5Len)(POS_AUTH - POS_CODE));
    163  1.2  christos 	MD5Update(&ctx, memset(&h->request[POS_AUTH], 0, (size_t)LEN_AUTH),
    164  1.2  christos 	    (MD5Len)LEN_AUTH);
    165  1.2  christos 	MD5Update(&ctx, &h->request[POS_ATTRS],
    166  1.2  christos 	    (MD5Len)(h->req_len - POS_ATTRS));
    167  1.6  christos 	MD5Update(&ctx, (MD5Buf)srvp->secret,
    168  1.2  christos 	    (MD5Len)strlen(srvp->secret));
    169  1.1      manu 	MD5Final(&h->request[POS_AUTH], &ctx);
    170  1.1      manu }
    171  1.1      manu 
    172  1.1      manu static void
    173  1.6  christos /*ARGSUSED*/
    174  1.1      manu insert_message_authenticator(struct rad_handle *h, int srv)
    175  1.1      manu {
    176  1.1      manu #ifdef WITH_SSL
    177  1.1      manu 	u_char md[EVP_MAX_MD_SIZE];
    178  1.1      manu 	u_int md_len;
    179  1.1      manu 	const struct rad_server *srvp;
    180  1.1      manu 	HMAC_CTX ctx;
    181  1.1      manu 	srvp = &h->servers[srv];
    182  1.1      manu 
    183  1.1      manu 	if (h->authentic_pos != 0) {
    184  1.1      manu 		HMAC_CTX_init(&ctx);
    185  1.2  christos 		HMAC_Init(&ctx, srvp->secret,
    186  1.2  christos 		    (int)strlen(srvp->secret), EVP_md5());
    187  1.8  christos 		HMAC_Update(&ctx, &h->request[POS_CODE], (size_t)(POS_AUTH - POS_CODE));
    188  1.8  christos 		HMAC_Update(&ctx, &h->request[POS_AUTH], (size_t)LEN_AUTH);
    189  1.1      manu 		HMAC_Update(&ctx, &h->request[POS_ATTRS],
    190  1.7  christos 		    (size_t)(h->req_len - POS_ATTRS));
    191  1.1      manu 		HMAC_Final(&ctx, md, &md_len);
    192  1.1      manu 		HMAC_CTX_cleanup(&ctx);
    193  1.1      manu 		HMAC_cleanup(&ctx);
    194  1.3  christos 		(void)memcpy(&h->request[h->authentic_pos + 2], md,
    195  1.3  christos 		    (size_t)md_len);
    196  1.1      manu 	}
    197  1.1      manu #endif
    198  1.1      manu }
    199  1.1      manu 
    200  1.1      manu /*
    201  1.1      manu  * Return true if the current response is valid for a request to the
    202  1.1      manu  * specified server.
    203  1.1      manu  */
    204  1.1      manu static int
    205  1.1      manu is_valid_response(struct rad_handle *h, int srv,
    206  1.1      manu     const struct sockaddr_in *from)
    207  1.1      manu {
    208  1.1      manu 	MD5_CTX ctx;
    209  1.1      manu 	unsigned char md5[MD5_DIGEST_LENGTH];
    210  1.1      manu 	const struct rad_server *srvp;
    211  1.1      manu 	int len;
    212  1.1      manu #ifdef WITH_SSL
    213  1.1      manu 	HMAC_CTX hctx;
    214  1.1      manu 	u_char resp[MSGSIZE], md[EVP_MAX_MD_SIZE];
    215  1.2  christos 	int pos;
    216  1.2  christos 	u_int md_len;
    217  1.1      manu #endif
    218  1.1      manu 
    219  1.1      manu 	srvp = &h->servers[srv];
    220  1.1      manu 
    221  1.1      manu 	/* Check the source address */
    222  1.1      manu 	if (from->sin_family != srvp->addr.sin_family ||
    223  1.1      manu 	    from->sin_addr.s_addr != srvp->addr.sin_addr.s_addr ||
    224  1.1      manu 	    from->sin_port != srvp->addr.sin_port)
    225  1.1      manu 		return 0;
    226  1.1      manu 
    227  1.1      manu 	/* Check the message length */
    228  1.1      manu 	if (h->resp_len < POS_ATTRS)
    229  1.1      manu 		return 0;
    230  1.1      manu 	len = h->response[POS_LENGTH] << 8 | h->response[POS_LENGTH+1];
    231  1.1      manu 	if (len > h->resp_len)
    232  1.1      manu 		return 0;
    233  1.1      manu 
    234  1.1      manu 	/* Check the response authenticator */
    235  1.1      manu 	MD5Init(&ctx);
    236  1.2  christos 	MD5Update(&ctx, &h->response[POS_CODE],
    237  1.2  christos 	    (MD5Len)(POS_AUTH - POS_CODE));
    238  1.2  christos 	MD5Update(&ctx, &h->request[POS_AUTH],
    239  1.2  christos 	    (MD5Len)LEN_AUTH);
    240  1.2  christos 	MD5Update(&ctx, &h->response[POS_ATTRS],
    241  1.2  christos 	    (MD5Len)(len - POS_ATTRS));
    242  1.6  christos 	MD5Update(&ctx, (MD5Buf)srvp->secret,
    243  1.2  christos 	    (MD5Len)strlen(srvp->secret));
    244  1.1      manu 	MD5Final(md5, &ctx);
    245  1.1      manu 	if (memcmp(&h->response[POS_AUTH], md5, sizeof md5) != 0)
    246  1.1      manu 		return 0;
    247  1.1      manu 
    248  1.1      manu #ifdef WITH_SSL
    249  1.1      manu 	/*
    250  1.1      manu 	 * For non accounting responses check the message authenticator,
    251  1.1      manu 	 * if any.
    252  1.1      manu 	 */
    253  1.1      manu 	if (h->response[POS_CODE] != RAD_ACCOUNTING_RESPONSE) {
    254  1.1      manu 
    255  1.3  christos 		(void)memcpy(resp, h->response, (size_t)MSGSIZE);
    256  1.1      manu 		pos = POS_ATTRS;
    257  1.1      manu 
    258  1.1      manu 		/* Search and verify the Message-Authenticator */
    259  1.1      manu 		while (pos < len - 2) {
    260  1.1      manu 
    261  1.1      manu 			if (h->response[pos] == RAD_MESSAGE_AUTHENTIC) {
    262  1.1      manu 				/* zero fill the Message-Authenticator */
    263  1.3  christos 				(void)memset(&resp[pos + 2], 0,
    264  1.3  christos 				    (size_t)MD5_DIGEST_LENGTH);
    265  1.1      manu 
    266  1.1      manu 				HMAC_CTX_init(&hctx);
    267  1.1      manu 				HMAC_Init(&hctx, srvp->secret,
    268  1.2  christos 				    (int)strlen(srvp->secret), EVP_md5());
    269  1.1      manu 				HMAC_Update(&hctx, &h->response[POS_CODE],
    270  1.8  christos 				    (size_t)(POS_AUTH - POS_CODE));
    271  1.1      manu 				HMAC_Update(&hctx, &h->request[POS_AUTH],
    272  1.8  christos 				    (size_t)LEN_AUTH);
    273  1.1      manu 				HMAC_Update(&hctx, &resp[POS_ATTRS],
    274  1.7  christos 				    (size_t)(h->resp_len - POS_ATTRS));
    275  1.1      manu 				HMAC_Final(&hctx, md, &md_len);
    276  1.1      manu 				HMAC_CTX_cleanup(&hctx);
    277  1.1      manu 				HMAC_cleanup(&hctx);
    278  1.1      manu 				if (memcmp(md, &h->response[pos + 2],
    279  1.3  christos 				    (size_t)MD5_DIGEST_LENGTH) != 0)
    280  1.1      manu 					return 0;
    281  1.1      manu 				break;
    282  1.1      manu 			}
    283  1.1      manu 			pos += h->response[pos + 1];
    284  1.1      manu 		}
    285  1.1      manu 	}
    286  1.1      manu #endif
    287  1.1      manu 	return 1;
    288  1.1      manu }
    289  1.1      manu 
    290  1.1      manu static int
    291  1.1      manu put_password_attr(struct rad_handle *h, int type, const void *value, size_t len)
    292  1.1      manu {
    293  1.2  christos 	size_t padded_len;
    294  1.2  christos 	size_t pad_len;
    295  1.1      manu 
    296  1.1      manu 	if (h->pass_pos != 0) {
    297  1.1      manu 		generr(h, "Multiple User-Password attributes specified");
    298  1.1      manu 		return -1;
    299  1.1      manu 	}
    300  1.1      manu 	if (len > PASSSIZE)
    301  1.1      manu 		len = PASSSIZE;
    302  1.2  christos 	padded_len = len == 0 ? 16 : (len + 15) & ~0xf;
    303  1.1      manu 	pad_len = padded_len - len;
    304  1.1      manu 
    305  1.1      manu 	/*
    306  1.1      manu 	 * Put in a place-holder attribute containing all zeros, and
    307  1.1      manu 	 * remember where it is so we can fill it in later.
    308  1.1      manu 	 */
    309  1.1      manu 	clear_password(h);
    310  1.1      manu 	put_raw_attr(h, type, h->pass, padded_len);
    311  1.4        he 	h->pass_pos = (int)(h->req_len - padded_len);
    312  1.1      manu 
    313  1.1      manu 	/* Save the cleartext password, padded as necessary */
    314  1.2  christos 	(void)memcpy(h->pass, value, len);
    315  1.1      manu 	h->pass_len = len;
    316  1.2  christos 	(void)memset(h->pass + len, 0, pad_len);
    317  1.1      manu 	return 0;
    318  1.1      manu }
    319  1.1      manu 
    320  1.1      manu static int
    321  1.1      manu put_raw_attr(struct rad_handle *h, int type, const void *value, size_t len)
    322  1.1      manu {
    323  1.1      manu 	if (len > 253) {
    324  1.1      manu 		generr(h, "Attribute too long");
    325  1.1      manu 		return -1;
    326  1.1      manu 	}
    327  1.1      manu 	if (h->req_len + 2 + len > MSGSIZE) {
    328  1.1      manu 		generr(h, "Maximum message length exceeded");
    329  1.1      manu 		return -1;
    330  1.1      manu 	}
    331  1.1      manu 	h->request[h->req_len++] = type;
    332  1.3  christos 	h->request[h->req_len++] = (unsigned char)(len + 2);
    333  1.2  christos 	(void)memcpy(&h->request[h->req_len], value, len);
    334  1.1      manu 	h->req_len += len;
    335  1.1      manu 	return 0;
    336  1.1      manu }
    337  1.1      manu 
    338  1.1      manu int
    339  1.1      manu rad_add_server(struct rad_handle *h, const char *host, int port,
    340  1.1      manu     const char *secret, int timeout, int tries)
    341  1.1      manu {
    342  1.1      manu 	struct rad_server *srvp;
    343  1.1      manu 
    344  1.1      manu 	if (h->num_servers >= MAXSERVERS) {
    345  1.1      manu 		generr(h, "Too many RADIUS servers specified");
    346  1.1      manu 		return -1;
    347  1.1      manu 	}
    348  1.1      manu 	srvp = &h->servers[h->num_servers];
    349  1.1      manu 
    350  1.3  christos 	(void)memset(&srvp->addr, 0, sizeof srvp->addr);
    351  1.1      manu 	srvp->addr.sin_len = sizeof srvp->addr;
    352  1.1      manu 	srvp->addr.sin_family = AF_INET;
    353  1.1      manu 	if (!inet_aton(host, &srvp->addr.sin_addr)) {
    354  1.1      manu 		struct hostent *hent;
    355  1.1      manu 
    356  1.1      manu 		if ((hent = gethostbyname(host)) == NULL) {
    357  1.1      manu 			generr(h, "%s: host not found", host);
    358  1.1      manu 			return -1;
    359  1.1      manu 		}
    360  1.3  christos 		(void)memcpy(&srvp->addr.sin_addr, hent->h_addr,
    361  1.1      manu 		    sizeof srvp->addr.sin_addr);
    362  1.1      manu 	}
    363  1.1      manu 	if (port != 0)
    364  1.1      manu 		srvp->addr.sin_port = htons((u_short)port);
    365  1.1      manu 	else {
    366  1.1      manu 		struct servent *sent;
    367  1.1      manu 
    368  1.1      manu 		if (h->type == RADIUS_AUTH)
    369  1.1      manu 			srvp->addr.sin_port =
    370  1.1      manu 			    (sent = getservbyname("radius", "udp")) != NULL ?
    371  1.1      manu 				sent->s_port : htons(RADIUS_PORT);
    372  1.1      manu 		else
    373  1.1      manu 			srvp->addr.sin_port =
    374  1.1      manu 			    (sent = getservbyname("radacct", "udp")) != NULL ?
    375  1.1      manu 				sent->s_port : htons(RADACCT_PORT);
    376  1.1      manu 	}
    377  1.1      manu 	if ((srvp->secret = strdup(secret)) == NULL) {
    378  1.1      manu 		generr(h, "Out of memory");
    379  1.1      manu 		return -1;
    380  1.1      manu 	}
    381  1.1      manu 	srvp->timeout = timeout;
    382  1.1      manu 	srvp->max_tries = tries;
    383  1.1      manu 	srvp->num_tries = 0;
    384  1.1      manu 	h->num_servers++;
    385  1.1      manu 	return 0;
    386  1.1      manu }
    387  1.1      manu 
    388  1.1      manu void
    389  1.1      manu rad_close(struct rad_handle *h)
    390  1.1      manu {
    391  1.1      manu 	int srv;
    392  1.1      manu 
    393  1.1      manu 	if (h->fd != -1)
    394  1.1      manu 		close(h->fd);
    395  1.1      manu 	for (srv = 0;  srv < h->num_servers;  srv++) {
    396  1.3  christos 		(void)memset(h->servers[srv].secret, 0,
    397  1.1      manu 		    strlen(h->servers[srv].secret));
    398  1.1      manu 		free(h->servers[srv].secret);
    399  1.1      manu 	}
    400  1.1      manu 	clear_password(h);
    401  1.1      manu 	free(h);
    402  1.1      manu }
    403  1.1      manu 
    404  1.1      manu int
    405  1.1      manu rad_config(struct rad_handle *h, const char *path)
    406  1.1      manu {
    407  1.1      manu 	FILE *fp;
    408  1.1      manu 	char buf[MAXCONFLINE];
    409  1.1      manu 	int linenum;
    410  1.1      manu 	int retval;
    411  1.1      manu 
    412  1.1      manu 	if (path == NULL)
    413  1.1      manu 		path = PATH_RADIUS_CONF;
    414  1.1      manu 	if ((fp = fopen(path, "r")) == NULL) {
    415  1.1      manu 		generr(h, "Cannot open \"%s\": %s", path, strerror(errno));
    416  1.1      manu 		return -1;
    417  1.1      manu 	}
    418  1.1      manu 	retval = 0;
    419  1.1      manu 	linenum = 0;
    420  1.3  christos 	while (fgets(buf, (int)sizeof buf, fp) != NULL) {
    421  1.3  christos 		size_t len;
    422  1.2  christos 		const char *fields[5];
    423  1.1      manu 		int nfields;
    424  1.1      manu 		char msg[ERRSIZE];
    425  1.2  christos 		const char *type;
    426  1.2  christos 		const char *host;
    427  1.2  christos 		char *res;
    428  1.2  christos 		const char *port_str;
    429  1.2  christos 		const char *secret;
    430  1.2  christos 		const char *timeout_str;
    431  1.2  christos 		const char *maxtries_str;
    432  1.1      manu 		char *end;
    433  1.2  christos 		const char *wanttype;
    434  1.1      manu 		unsigned long timeout;
    435  1.1      manu 		unsigned long maxtries;
    436  1.1      manu 		int port;
    437  1.3  christos 		size_t i;
    438  1.1      manu 
    439  1.1      manu 		linenum++;
    440  1.1      manu 		len = strlen(buf);
    441  1.1      manu 		/* We know len > 0, else fgets would have returned NULL. */
    442  1.1      manu 		if (buf[len - 1] != '\n') {
    443  1.1      manu 			if (len == sizeof buf - 1)
    444  1.1      manu 				generr(h, "%s:%d: line too long", path,
    445  1.1      manu 				    linenum);
    446  1.1      manu 			else
    447  1.1      manu 				generr(h, "%s:%d: missing newline", path,
    448  1.1      manu 				    linenum);
    449  1.1      manu 			retval = -1;
    450  1.1      manu 			break;
    451  1.1      manu 		}
    452  1.1      manu 		buf[len - 1] = '\0';
    453  1.1      manu 
    454  1.1      manu 		/* Extract the fields from the line. */
    455  1.2  christos 		nfields = split(buf, fields, sizeof(fields) / sizeof(fields[0]),
    456  1.2  christos 		    msg, sizeof msg);
    457  1.1      manu 		if (nfields == -1) {
    458  1.1      manu 			generr(h, "%s:%d: %s", path, linenum, msg);
    459  1.1      manu 			retval = -1;
    460  1.1      manu 			break;
    461  1.1      manu 		}
    462  1.1      manu 		if (nfields == 0)
    463  1.1      manu 			continue;
    464  1.1      manu 		/*
    465  1.1      manu 		 * The first field should contain "auth" or "acct" for
    466  1.1      manu 		 * authentication or accounting, respectively.  But older
    467  1.1      manu 		 * versions of the file didn't have that field.  Default
    468  1.1      manu 		 * it to "auth" for backward compatibility.
    469  1.1      manu 		 */
    470  1.1      manu 		if (strcmp(fields[0], "auth") != 0 &&
    471  1.1      manu 		    strcmp(fields[0], "acct") != 0) {
    472  1.1      manu 			if (nfields >= 5) {
    473  1.1      manu 				generr(h, "%s:%d: invalid service type", path,
    474  1.1      manu 				    linenum);
    475  1.1      manu 				retval = -1;
    476  1.1      manu 				break;
    477  1.1      manu 			}
    478  1.1      manu 			nfields++;
    479  1.1      manu 			for (i = nfields;  --i > 0;  )
    480  1.1      manu 				fields[i] = fields[i - 1];
    481  1.1      manu 			fields[0] = "auth";
    482  1.1      manu 		}
    483  1.1      manu 		if (nfields < 3) {
    484  1.1      manu 			generr(h, "%s:%d: missing shared secret", path,
    485  1.1      manu 			    linenum);
    486  1.1      manu 			retval = -1;
    487  1.1      manu 			break;
    488  1.1      manu 		}
    489  1.1      manu 		type = fields[0];
    490  1.1      manu 		host = fields[1];
    491  1.1      manu 		secret = fields[2];
    492  1.1      manu 		timeout_str = fields[3];
    493  1.1      manu 		maxtries_str = fields[4];
    494  1.1      manu 
    495  1.1      manu 		/* Ignore the line if it is for the wrong service type. */
    496  1.1      manu 		wanttype = h->type == RADIUS_AUTH ? "auth" : "acct";
    497  1.1      manu 		if (strcmp(type, wanttype) != 0)
    498  1.1      manu 			continue;
    499  1.1      manu 
    500  1.1      manu 		/* Parse and validate the fields. */
    501  1.2  christos 		res = __UNCONST(host);
    502  1.1      manu 		host = strsep(&res, ":");
    503  1.1      manu 		port_str = strsep(&res, ":");
    504  1.1      manu 		if (port_str != NULL) {
    505  1.3  christos 			port = (int)strtoul(port_str, &end, 10);
    506  1.1      manu 			if (*end != '\0') {
    507  1.1      manu 				generr(h, "%s:%d: invalid port", path,
    508  1.1      manu 				    linenum);
    509  1.1      manu 				retval = -1;
    510  1.1      manu 				break;
    511  1.1      manu 			}
    512  1.1      manu 		} else
    513  1.1      manu 			port = 0;
    514  1.1      manu 		if (timeout_str != NULL) {
    515  1.1      manu 			timeout = strtoul(timeout_str, &end, 10);
    516  1.1      manu 			if (*end != '\0') {
    517  1.1      manu 				generr(h, "%s:%d: invalid timeout", path,
    518  1.1      manu 				    linenum);
    519  1.1      manu 				retval = -1;
    520  1.1      manu 				break;
    521  1.1      manu 			}
    522  1.1      manu 		} else
    523  1.1      manu 			timeout = TIMEOUT;
    524  1.1      manu 		if (maxtries_str != NULL) {
    525  1.1      manu 			maxtries = strtoul(maxtries_str, &end, 10);
    526  1.1      manu 			if (*end != '\0') {
    527  1.1      manu 				generr(h, "%s:%d: invalid maxtries", path,
    528  1.1      manu 				    linenum);
    529  1.1      manu 				retval = -1;
    530  1.1      manu 				break;
    531  1.1      manu 			}
    532  1.1      manu 		} else
    533  1.1      manu 			maxtries = MAXTRIES;
    534  1.1      manu 
    535  1.2  christos 		if (rad_add_server(h, host, port, secret, (int)timeout,
    536  1.2  christos 		    (int)maxtries) == -1) {
    537  1.2  christos 			(void)strcpy(msg, h->errmsg);
    538  1.1      manu 			generr(h, "%s:%d: %s", path, linenum, msg);
    539  1.1      manu 			retval = -1;
    540  1.1      manu 			break;
    541  1.1      manu 		}
    542  1.1      manu 	}
    543  1.1      manu 	/* Clear out the buffer to wipe a possible copy of a shared secret */
    544  1.3  christos 	(void)memset(buf, 0, sizeof buf);
    545  1.1      manu 	fclose(fp);
    546  1.1      manu 	return retval;
    547  1.1      manu }
    548  1.1      manu 
    549  1.1      manu /*
    550  1.1      manu  * rad_init_send_request() must have previously been called.
    551  1.1      manu  * Returns:
    552  1.1      manu  *   0     The application should select on *fd with a timeout of tv before
    553  1.1      manu  *         calling rad_continue_send_request again.
    554  1.1      manu  *   < 0   Failure
    555  1.1      manu  *   > 0   Success
    556  1.1      manu  */
    557  1.1      manu int
    558  1.1      manu rad_continue_send_request(struct rad_handle *h, int selected, int *fd,
    559  1.1      manu                           struct timeval *tv)
    560  1.1      manu {
    561  1.3  christos 	ssize_t n;
    562  1.1      manu 
    563  1.1      manu 	if (selected) {
    564  1.1      manu 		struct sockaddr_in from;
    565  1.2  christos 		socklen_t fromlen;
    566  1.2  christos 		ssize_t rv;
    567  1.1      manu 
    568  1.1      manu 		fromlen = sizeof from;
    569  1.3  christos 		rv = recvfrom(h->fd, h->response, (size_t)MSGSIZE,
    570  1.3  christos 		    MSG_WAITALL, (struct sockaddr *)(void *)&from, &fromlen);
    571  1.2  christos 		if (rv == -1) {
    572  1.1      manu 			generr(h, "recvfrom: %s", strerror(errno));
    573  1.1      manu 			return -1;
    574  1.1      manu 		}
    575  1.2  christos 		h->resp_len = rv;
    576  1.1      manu 		if (is_valid_response(h, h->srv, &from)) {
    577  1.1      manu 			h->resp_len = h->response[POS_LENGTH] << 8 |
    578  1.1      manu 			    h->response[POS_LENGTH+1];
    579  1.1      manu 			h->resp_pos = POS_ATTRS;
    580  1.1      manu 			return h->response[POS_CODE];
    581  1.1      manu 		}
    582  1.1      manu 	}
    583  1.1      manu 
    584  1.1      manu 	if (h->try == h->total_tries) {
    585  1.1      manu 		generr(h, "No valid RADIUS responses received");
    586  1.1      manu 		return -1;
    587  1.1      manu 	}
    588  1.1      manu 
    589  1.1      manu 	/*
    590  1.1      manu          * Scan round-robin to the next server that has some
    591  1.1      manu          * tries left.  There is guaranteed to be one, or we
    592  1.1      manu          * would have exited this loop by now.
    593  1.1      manu 	 */
    594  1.1      manu 	while (h->servers[h->srv].num_tries >= h->servers[h->srv].max_tries)
    595  1.1      manu 		if (++h->srv >= h->num_servers)
    596  1.1      manu 			h->srv = 0;
    597  1.1      manu 
    598  1.1      manu 	if (h->request[POS_CODE] == RAD_ACCOUNTING_REQUEST)
    599  1.1      manu 		/* Insert the request authenticator into the request */
    600  1.1      manu 		insert_request_authenticator(h, h->srv);
    601  1.1      manu 	else
    602  1.1      manu 		/* Insert the scrambled password into the request */
    603  1.1      manu 		if (h->pass_pos != 0)
    604  1.1      manu 			insert_scrambled_password(h, h->srv);
    605  1.1      manu 
    606  1.1      manu 	insert_message_authenticator(h, h->srv);
    607  1.1      manu 
    608  1.1      manu 	/* Send the request */
    609  1.1      manu 	n = sendto(h->fd, h->request, h->req_len, 0,
    610  1.2  christos 	    (const struct sockaddr *)(void *)&h->servers[h->srv].addr,
    611  1.2  christos 	    (socklen_t)sizeof h->servers[h->srv].addr);
    612  1.3  christos 	if (n != (ssize_t)h->req_len) {
    613  1.1      manu 		if (n == -1)
    614  1.1      manu 			generr(h, "sendto: %s", strerror(errno));
    615  1.1      manu 		else
    616  1.1      manu 			generr(h, "sendto: short write");
    617  1.1      manu 		return -1;
    618  1.1      manu 	}
    619  1.1      manu 
    620  1.1      manu 	h->try++;
    621  1.1      manu 	h->servers[h->srv].num_tries++;
    622  1.1      manu 	tv->tv_sec = h->servers[h->srv].timeout;
    623  1.1      manu 	tv->tv_usec = 0;
    624  1.1      manu 	*fd = h->fd;
    625  1.1      manu 
    626  1.1      manu 	return 0;
    627  1.1      manu }
    628  1.1      manu 
    629  1.1      manu int
    630  1.1      manu rad_create_request(struct rad_handle *h, int code)
    631  1.1      manu {
    632  1.1      manu 	int i;
    633  1.1      manu 
    634  1.1      manu 	h->request[POS_CODE] = code;
    635  1.1      manu 	h->request[POS_IDENT] = ++h->ident;
    636  1.1      manu 	/* Create a random authenticator */
    637  1.1      manu 	for (i = 0;  i < LEN_AUTH;  i += 2) {
    638  1.2  christos 		uint32_t r;
    639  1.2  christos 		r = (uint32_t)random();
    640  1.1      manu 		h->request[POS_AUTH+i] = (u_char)r;
    641  1.1      manu 		h->request[POS_AUTH+i+1] = (u_char)(r >> 8);
    642  1.1      manu 	}
    643  1.1      manu 	h->req_len = POS_ATTRS;
    644  1.1      manu 	clear_password(h);
    645  1.1      manu 	h->request_created = 1;
    646  1.1      manu 	return 0;
    647  1.1      manu }
    648  1.1      manu 
    649  1.1      manu struct in_addr
    650  1.1      manu rad_cvt_addr(const void *data)
    651  1.1      manu {
    652  1.1      manu 	struct in_addr value;
    653  1.1      manu 
    654  1.3  christos 	(void)memcpy(&value.s_addr, data, sizeof value.s_addr);
    655  1.1      manu 	return value;
    656  1.1      manu }
    657  1.1      manu 
    658  1.1      manu u_int32_t
    659  1.1      manu rad_cvt_int(const void *data)
    660  1.1      manu {
    661  1.1      manu 	u_int32_t value;
    662  1.1      manu 
    663  1.3  christos 	(void)memcpy(&value, data, sizeof value);
    664  1.1      manu 	return ntohl(value);
    665  1.1      manu }
    666  1.1      manu 
    667  1.1      manu char *
    668  1.1      manu rad_cvt_string(const void *data, size_t len)
    669  1.1      manu {
    670  1.1      manu 	char *s;
    671  1.1      manu 
    672  1.1      manu 	s = malloc(len + 1);
    673  1.1      manu 	if (s != NULL) {
    674  1.3  christos 		(void)memcpy(s, data, len);
    675  1.1      manu 		s[len] = '\0';
    676  1.1      manu 	}
    677  1.1      manu 	return s;
    678  1.1      manu }
    679  1.1      manu 
    680  1.1      manu /*
    681  1.1      manu  * Returns the attribute type.  If none are left, returns 0.  On failure,
    682  1.1      manu  * returns -1.
    683  1.1      manu  */
    684  1.1      manu int
    685  1.1      manu rad_get_attr(struct rad_handle *h, const void **value, size_t *len)
    686  1.1      manu {
    687  1.1      manu 	int type;
    688  1.1      manu 
    689  1.1      manu 	if (h->resp_pos >= h->resp_len)
    690  1.1      manu 		return 0;
    691  1.1      manu 	if (h->resp_pos + 2 > h->resp_len) {
    692  1.1      manu 		generr(h, "Malformed attribute in response");
    693  1.1      manu 		return -1;
    694  1.1      manu 	}
    695  1.1      manu 	type = h->response[h->resp_pos++];
    696  1.1      manu 	*len = h->response[h->resp_pos++] - 2;
    697  1.1      manu 	if (h->resp_pos + (int)*len > h->resp_len) {
    698  1.1      manu 		generr(h, "Malformed attribute in response");
    699  1.1      manu 		return -1;
    700  1.1      manu 	}
    701  1.1      manu 	*value = &h->response[h->resp_pos];
    702  1.4        he 	h->resp_pos += (int)*len;
    703  1.1      manu 	return type;
    704  1.1      manu }
    705  1.1      manu 
    706  1.1      manu /*
    707  1.1      manu  * Returns -1 on error, 0 to indicate no event and >0 for success
    708  1.1      manu  */
    709  1.1      manu int
    710  1.1      manu rad_init_send_request(struct rad_handle *h, int *fd, struct timeval *tv)
    711  1.1      manu {
    712  1.1      manu 	int srv;
    713  1.1      manu 
    714  1.1      manu 	/* Make sure we have a socket to use */
    715  1.1      manu 	if (h->fd == -1) {
    716  1.1      manu 		struct sockaddr_in saddr;
    717  1.1      manu 
    718  1.1      manu 		if ((h->fd = socket(PF_INET, SOCK_DGRAM, IPPROTO_UDP)) == -1) {
    719  1.1      manu 			generr(h, "Cannot create socket: %s", strerror(errno));
    720  1.1      manu 			return -1;
    721  1.1      manu 		}
    722  1.3  christos 		(void)memset(&saddr, 0, sizeof saddr);
    723  1.1      manu 		saddr.sin_len = sizeof saddr;
    724  1.1      manu 		saddr.sin_family = AF_INET;
    725  1.1      manu 		saddr.sin_addr.s_addr = INADDR_ANY;
    726  1.1      manu 		saddr.sin_port = htons(0);
    727  1.2  christos 		if (bind(h->fd, (const struct sockaddr *)(void *)&saddr,
    728  1.3  christos 		    (socklen_t)sizeof saddr) == -1) {
    729  1.1      manu 			generr(h, "bind: %s", strerror(errno));
    730  1.1      manu 			close(h->fd);
    731  1.1      manu 			h->fd = -1;
    732  1.1      manu 			return -1;
    733  1.1      manu 		}
    734  1.1      manu 	}
    735  1.1      manu 
    736  1.1      manu 	if (h->request[POS_CODE] == RAD_ACCOUNTING_REQUEST) {
    737  1.1      manu 		/* Make sure no password given */
    738  1.1      manu 		if (h->pass_pos || h->chap_pass) {
    739  1.1      manu 			generr(h, "User or Chap Password"
    740  1.1      manu 			    " in accounting request");
    741  1.1      manu 			return -1;
    742  1.1      manu 		}
    743  1.1      manu 	} else {
    744  1.1      manu 		if (h->eap_msg == 0) {
    745  1.1      manu 			/* Make sure the user gave us a password */
    746  1.1      manu 			if (h->pass_pos == 0 && !h->chap_pass) {
    747  1.1      manu 				generr(h, "No User or Chap Password"
    748  1.1      manu 				    " attributes given");
    749  1.1      manu 				return -1;
    750  1.1      manu 			}
    751  1.1      manu 			if (h->pass_pos != 0 && h->chap_pass) {
    752  1.1      manu 				generr(h, "Both User and Chap Password"
    753  1.1      manu 				    " attributes given");
    754  1.1      manu 				return -1;
    755  1.1      manu 			}
    756  1.1      manu 		}
    757  1.1      manu 	}
    758  1.1      manu 
    759  1.1      manu 	/* Fill in the length field in the message */
    760  1.3  christos 	h->request[POS_LENGTH] = (unsigned char)(h->req_len >> 8);
    761  1.3  christos 	h->request[POS_LENGTH+1] = (unsigned char)h->req_len;
    762  1.1      manu 
    763  1.1      manu 	/*
    764  1.1      manu 	 * Count the total number of tries we will make, and zero the
    765  1.1      manu 	 * counter for each server.
    766  1.1      manu 	 */
    767  1.1      manu 	h->total_tries = 0;
    768  1.1      manu 	for (srv = 0;  srv < h->num_servers;  srv++) {
    769  1.1      manu 		h->total_tries += h->servers[srv].max_tries;
    770  1.1      manu 		h->servers[srv].num_tries = 0;
    771  1.1      manu 	}
    772  1.1      manu 	if (h->total_tries == 0) {
    773  1.1      manu 		generr(h, "No RADIUS servers specified");
    774  1.1      manu 		return -1;
    775  1.1      manu 	}
    776  1.1      manu 
    777  1.1      manu 	h->try = h->srv = 0;
    778  1.1      manu 
    779  1.1      manu 	return rad_continue_send_request(h, 0, fd, tv);
    780  1.1      manu }
    781  1.1      manu 
    782  1.1      manu /*
    783  1.1      manu  * Create and initialize a rad_handle structure, and return it to the
    784  1.1      manu  * caller.  Can fail only if the necessary memory cannot be allocated.
    785  1.1      manu  * In that case, it returns NULL.
    786  1.1      manu  */
    787  1.1      manu struct rad_handle *
    788  1.1      manu rad_auth_open(void)
    789  1.1      manu {
    790  1.1      manu 	struct rad_handle *h;
    791  1.1      manu 
    792  1.1      manu 	h = (struct rad_handle *)malloc(sizeof(struct rad_handle));
    793  1.1      manu 	if (h != NULL) {
    794  1.5        he 		srandomdev(0);
    795  1.1      manu 		h->fd = -1;
    796  1.1      manu 		h->num_servers = 0;
    797  1.1      manu 		h->ident = random();
    798  1.1      manu 		h->errmsg[0] = '\0';
    799  1.3  christos 		(void)memset(h->pass, 0, sizeof h->pass);
    800  1.1      manu 		h->pass_len = 0;
    801  1.1      manu 		h->pass_pos = 0;
    802  1.1      manu 		h->chap_pass = 0;
    803  1.1      manu 		h->authentic_pos = 0;
    804  1.1      manu 		h->type = RADIUS_AUTH;
    805  1.1      manu 		h->request_created = 0;
    806  1.1      manu 		h->eap_msg = 0;
    807  1.1      manu 	}
    808  1.1      manu 	return h;
    809  1.1      manu }
    810  1.1      manu 
    811  1.1      manu struct rad_handle *
    812  1.1      manu rad_acct_open(void)
    813  1.1      manu {
    814  1.1      manu 	struct rad_handle *h;
    815  1.1      manu 
    816  1.1      manu 	h = rad_open();
    817  1.1      manu 	if (h != NULL)
    818  1.1      manu 	        h->type = RADIUS_ACCT;
    819  1.1      manu 	return h;
    820  1.1      manu }
    821  1.1      manu 
    822  1.1      manu struct rad_handle *
    823  1.1      manu rad_open(void)
    824  1.1      manu {
    825  1.1      manu     return rad_auth_open();
    826  1.1      manu }
    827  1.1      manu 
    828  1.1      manu int
    829  1.1      manu rad_put_addr(struct rad_handle *h, int type, struct in_addr addr)
    830  1.1      manu {
    831  1.1      manu 	return rad_put_attr(h, type, &addr.s_addr, sizeof addr.s_addr);
    832  1.1      manu }
    833  1.1      manu 
    834  1.1      manu int
    835  1.1      manu rad_put_attr(struct rad_handle *h, int type, const void *value, size_t len)
    836  1.1      manu {
    837  1.1      manu 	int result;
    838  1.1      manu 
    839  1.1      manu 	if (!h->request_created) {
    840  1.1      manu 		generr(h, "Please call rad_create_request()"
    841  1.1      manu 		    " before putting attributes");
    842  1.1      manu 		return -1;
    843  1.1      manu 	}
    844  1.1      manu 
    845  1.1      manu 	if (h->request[POS_CODE] == RAD_ACCOUNTING_REQUEST) {
    846  1.1      manu 		if (type == RAD_EAP_MESSAGE) {
    847  1.1      manu 			generr(h, "EAP-Message attribute is not valid"
    848  1.1      manu 			    " in accounting requests");
    849  1.1      manu 			return -1;
    850  1.1      manu 		}
    851  1.1      manu 	}
    852  1.1      manu 
    853  1.1      manu 	/*
    854  1.1      manu 	 * When proxying EAP Messages, the Message Authenticator
    855  1.1      manu 	 * MUST be present; see RFC 3579.
    856  1.1      manu 	 */
    857  1.1      manu 	if (type == RAD_EAP_MESSAGE) {
    858  1.1      manu 		if (rad_put_message_authentic(h) == -1)
    859  1.1      manu 			return -1;
    860  1.1      manu 	}
    861  1.1      manu 
    862  1.1      manu 	if (type == RAD_USER_PASSWORD) {
    863  1.1      manu 		result = put_password_attr(h, type, value, len);
    864  1.1      manu 	} else if (type == RAD_MESSAGE_AUTHENTIC) {
    865  1.1      manu 		result = rad_put_message_authentic(h);
    866  1.1      manu 	} else {
    867  1.1      manu 		result = put_raw_attr(h, type, value, len);
    868  1.1      manu 		if (result == 0) {
    869  1.1      manu 			if (type == RAD_CHAP_PASSWORD)
    870  1.1      manu 				h->chap_pass = 1;
    871  1.1      manu 			else if (type == RAD_EAP_MESSAGE)
    872  1.1      manu 				h->eap_msg = 1;
    873  1.1      manu 		}
    874  1.1      manu 	}
    875  1.1      manu 
    876  1.1      manu 	return result;
    877  1.1      manu }
    878  1.1      manu 
    879  1.1      manu int
    880  1.1      manu rad_put_int(struct rad_handle *h, int type, u_int32_t value)
    881  1.1      manu {
    882  1.1      manu 	u_int32_t nvalue;
    883  1.1      manu 
    884  1.1      manu 	nvalue = htonl(value);
    885  1.1      manu 	return rad_put_attr(h, type, &nvalue, sizeof nvalue);
    886  1.1      manu }
    887  1.1      manu 
    888  1.1      manu int
    889  1.1      manu rad_put_string(struct rad_handle *h, int type, const char *str)
    890  1.1      manu {
    891  1.1      manu 	return rad_put_attr(h, type, str, strlen(str));
    892  1.1      manu }
    893  1.1      manu 
    894  1.1      manu int
    895  1.1      manu rad_put_message_authentic(struct rad_handle *h)
    896  1.1      manu {
    897  1.1      manu #ifdef WITH_SSL
    898  1.1      manu 	u_char md_zero[MD5_DIGEST_LENGTH];
    899  1.1      manu 
    900  1.1      manu 	if (h->request[POS_CODE] == RAD_ACCOUNTING_REQUEST) {
    901  1.1      manu 		generr(h, "Message-Authenticator is not valid"
    902  1.1      manu 		    " in accounting requests");
    903  1.1      manu 		return -1;
    904  1.1      manu 	}
    905  1.1      manu 
    906  1.1      manu 	if (h->authentic_pos == 0) {
    907  1.4        he 		h->authentic_pos = (int)h->req_len;
    908  1.3  christos 		(void)memset(md_zero, 0, sizeof(md_zero));
    909  1.1      manu 		return (put_raw_attr(h, RAD_MESSAGE_AUTHENTIC, md_zero,
    910  1.1      manu 		    sizeof(md_zero)));
    911  1.1      manu 	}
    912  1.1      manu 	return 0;
    913  1.1      manu #else
    914  1.1      manu 	generr(h, "Message Authenticator not supported,"
    915  1.1      manu 	    " please recompile libradius with SSL support");
    916  1.1      manu 	return -1;
    917  1.1      manu #endif
    918  1.1      manu }
    919  1.1      manu 
    920  1.1      manu /*
    921  1.1      manu  * Returns the response type code on success, or -1 on failure.
    922  1.1      manu  */
    923  1.1      manu int
    924  1.1      manu rad_send_request(struct rad_handle *h)
    925  1.1      manu {
    926  1.1      manu 	struct timeval timelimit;
    927  1.1      manu 	struct timeval tv;
    928  1.1      manu 	int fd;
    929  1.1      manu 	int n;
    930  1.1      manu 
    931  1.1      manu 	n = rad_init_send_request(h, &fd, &tv);
    932  1.1      manu 
    933  1.1      manu 	if (n != 0)
    934  1.1      manu 		return n;
    935  1.1      manu 
    936  1.1      manu 	gettimeofday(&timelimit, NULL);
    937  1.1      manu 	timeradd(&tv, &timelimit, &timelimit);
    938  1.1      manu 
    939  1.1      manu 	for ( ; ; ) {
    940  1.1      manu 		fd_set readfds;
    941  1.1      manu 
    942  1.1      manu 		FD_ZERO(&readfds);
    943  1.1      manu 		FD_SET(fd, &readfds);
    944  1.1      manu 
    945  1.1      manu 		n = select(fd + 1, &readfds, NULL, NULL, &tv);
    946  1.1      manu 
    947  1.1      manu 		if (n == -1) {
    948  1.1      manu 			generr(h, "select: %s", strerror(errno));
    949  1.1      manu 			return -1;
    950  1.1      manu 		}
    951  1.1      manu 
    952  1.1      manu 		if (!FD_ISSET(fd, &readfds)) {
    953  1.1      manu 			/* Compute a new timeout */
    954  1.1      manu 			gettimeofday(&tv, NULL);
    955  1.1      manu 			timersub(&timelimit, &tv, &tv);
    956  1.1      manu 			if (tv.tv_sec > 0 || (tv.tv_sec == 0 && tv.tv_usec > 0))
    957  1.1      manu 				/* Continue the select */
    958  1.1      manu 				continue;
    959  1.1      manu 		}
    960  1.1      manu 
    961  1.1      manu 		n = rad_continue_send_request(h, n, &fd, &tv);
    962  1.1      manu 
    963  1.1      manu 		if (n != 0)
    964  1.1      manu 			return n;
    965  1.1      manu 
    966  1.1      manu 		gettimeofday(&timelimit, NULL);
    967  1.1      manu 		timeradd(&tv, &timelimit, &timelimit);
    968  1.1      manu 	}
    969  1.1      manu }
    970  1.1      manu 
    971  1.1      manu const char *
    972  1.1      manu rad_strerror(struct rad_handle *h)
    973  1.1      manu {
    974  1.1      manu 	return h->errmsg;
    975  1.1      manu }
    976  1.1      manu 
    977  1.1      manu /*
    978  1.1      manu  * Destructively split a string into fields separated by white space.
    979  1.1      manu  * `#' at the beginning of a field begins a comment that extends to the
    980  1.1      manu  * end of the string.  Fields may be quoted with `"'.  Inside quoted
    981  1.1      manu  * strings, the backslash escapes `\"' and `\\' are honored.
    982  1.1      manu  *
    983  1.1      manu  * Pointers to up to the first maxfields fields are stored in the fields
    984  1.1      manu  * array.  Missing fields get NULL pointers.
    985  1.1      manu  *
    986  1.1      manu  * The return value is the actual number of fields parsed, and is always
    987  1.1      manu  * <= maxfields.
    988  1.1      manu  *
    989  1.1      manu  * On a syntax error, places a message in the msg string, and returns -1.
    990  1.1      manu  */
    991  1.1      manu static int
    992  1.3  christos split(char *str, const char *fields[], size_t maxfields, char *msg,
    993  1.3  christos     size_t msglen)
    994  1.1      manu {
    995  1.1      manu 	char *p;
    996  1.1      manu 	int i;
    997  1.1      manu 	static const char ws[] = " \t";
    998  1.1      manu 
    999  1.1      manu 	for (i = 0;  i < maxfields;  i++)
   1000  1.1      manu 		fields[i] = NULL;
   1001  1.1      manu 	p = str;
   1002  1.1      manu 	i = 0;
   1003  1.1      manu 	while (*p != '\0') {
   1004  1.1      manu 		p += strspn(p, ws);
   1005  1.1      manu 		if (*p == '#' || *p == '\0')
   1006  1.1      manu 			break;
   1007  1.1      manu 		if (i >= maxfields) {
   1008  1.1      manu 			snprintf(msg, msglen, "line has too many fields");
   1009  1.1      manu 			return -1;
   1010  1.1      manu 		}
   1011  1.1      manu 		if (*p == '"') {
   1012  1.1      manu 			char *dst;
   1013  1.1      manu 
   1014  1.1      manu 			dst = ++p;
   1015  1.1      manu 			fields[i] = dst;
   1016  1.1      manu 			while (*p != '"') {
   1017  1.1      manu 				if (*p == '\\') {
   1018  1.1      manu 					p++;
   1019  1.1      manu 					if (*p != '"' && *p != '\\' &&
   1020  1.1      manu 					    *p != '\0') {
   1021  1.1      manu 						snprintf(msg, msglen,
   1022  1.1      manu 						    "invalid `\\' escape");
   1023  1.1      manu 						return -1;
   1024  1.1      manu 					}
   1025  1.1      manu 				}
   1026  1.1      manu 				if (*p == '\0') {
   1027  1.1      manu 					snprintf(msg, msglen,
   1028  1.1      manu 					    "unterminated quoted string");
   1029  1.1      manu 					return -1;
   1030  1.1      manu 				}
   1031  1.1      manu 				*dst++ = *p++;
   1032  1.1      manu 			}
   1033  1.1      manu 			*dst = '\0';
   1034  1.1      manu 			p++;
   1035  1.1      manu 			if (*fields[i] == '\0') {
   1036  1.1      manu 				snprintf(msg, msglen,
   1037  1.1      manu 				    "empty quoted string not permitted");
   1038  1.1      manu 				return -1;
   1039  1.1      manu 			}
   1040  1.1      manu 			if (*p != '\0' && strspn(p, ws) == 0) {
   1041  1.1      manu 				snprintf(msg, msglen, "quoted string not"
   1042  1.1      manu 				    " followed by white space");
   1043  1.1      manu 				return -1;
   1044  1.1      manu 			}
   1045  1.1      manu 		} else {
   1046  1.1      manu 			fields[i] = p;
   1047  1.1      manu 			p += strcspn(p, ws);
   1048  1.1      manu 			if (*p != '\0')
   1049  1.1      manu 				*p++ = '\0';
   1050  1.1      manu 		}
   1051  1.1      manu 		i++;
   1052  1.1      manu 	}
   1053  1.1      manu 	return i;
   1054  1.1      manu }
   1055  1.1      manu 
   1056  1.1      manu int
   1057  1.1      manu rad_get_vendor_attr(u_int32_t *vendor, const void **data, size_t *len)
   1058  1.1      manu {
   1059  1.2  christos 	const struct vendor_attribute *attr;
   1060  1.1      manu 
   1061  1.2  christos 	attr = (const struct vendor_attribute *)*data;
   1062  1.1      manu 	*vendor = ntohl(attr->vendor_value);
   1063  1.1      manu 	*data = attr->attrib_data;
   1064  1.1      manu 	*len = attr->attrib_len - 2;
   1065  1.1      manu 
   1066  1.1      manu 	return (attr->attrib_type);
   1067  1.1      manu }
   1068  1.1      manu 
   1069  1.1      manu int
   1070  1.1      manu rad_put_vendor_addr(struct rad_handle *h, int vendor, int type,
   1071  1.1      manu     struct in_addr addr)
   1072  1.1      manu {
   1073  1.1      manu 	return (rad_put_vendor_attr(h, vendor, type, &addr.s_addr,
   1074  1.1      manu 	    sizeof addr.s_addr));
   1075  1.1      manu }
   1076  1.1      manu 
   1077  1.1      manu int
   1078  1.1      manu rad_put_vendor_attr(struct rad_handle *h, int vendor, int type,
   1079  1.1      manu     const void *value, size_t len)
   1080  1.1      manu {
   1081  1.1      manu 	struct vendor_attribute *attr;
   1082  1.1      manu 	int res;
   1083  1.1      manu 
   1084  1.1      manu 	if (!h->request_created) {
   1085  1.1      manu 		generr(h, "Please call rad_create_request()"
   1086  1.1      manu 		    " before putting attributes");
   1087  1.1      manu 		return -1;
   1088  1.1      manu 	}
   1089  1.1      manu 
   1090  1.1      manu 	if ((attr = malloc(len + 6)) == NULL) {
   1091  1.1      manu 		generr(h, "malloc failure (%zu bytes)", len + 6);
   1092  1.1      manu 		return -1;
   1093  1.1      manu 	}
   1094  1.1      manu 
   1095  1.2  christos 	attr->vendor_value = htonl((uint32_t)vendor);
   1096  1.1      manu 	attr->attrib_type = type;
   1097  1.3  christos 	attr->attrib_len = (unsigned char)(len + 2);
   1098  1.3  christos 	(void)memcpy(attr->attrib_data, value, len);
   1099  1.1      manu 
   1100  1.1      manu 	res = put_raw_attr(h, RAD_VENDOR_SPECIFIC, attr, len + 6);
   1101  1.1      manu 	free(attr);
   1102  1.1      manu 	if (res == 0 && vendor == RAD_VENDOR_MICROSOFT
   1103  1.1      manu 	    && (type == RAD_MICROSOFT_MS_CHAP_RESPONSE
   1104  1.1      manu 	    || type == RAD_MICROSOFT_MS_CHAP2_RESPONSE)) {
   1105  1.1      manu 		h->chap_pass = 1;
   1106  1.1      manu 	}
   1107  1.1      manu 	return (res);
   1108  1.1      manu }
   1109  1.1      manu 
   1110  1.1      manu int
   1111  1.1      manu rad_put_vendor_int(struct rad_handle *h, int vendor, int type, u_int32_t i)
   1112  1.1      manu {
   1113  1.1      manu 	u_int32_t value;
   1114  1.1      manu 
   1115  1.1      manu 	value = htonl(i);
   1116  1.1      manu 	return (rad_put_vendor_attr(h, vendor, type, &value, sizeof value));
   1117  1.1      manu }
   1118  1.1      manu 
   1119  1.1      manu int
   1120  1.1      manu rad_put_vendor_string(struct rad_handle *h, int vendor, int type,
   1121  1.1      manu     const char *str)
   1122  1.1      manu {
   1123  1.1      manu 	return (rad_put_vendor_attr(h, vendor, type, str, strlen(str)));
   1124  1.1      manu }
   1125  1.1      manu 
   1126  1.1      manu ssize_t
   1127  1.1      manu rad_request_authenticator(struct rad_handle *h, char *buf, size_t len)
   1128  1.1      manu {
   1129  1.1      manu 	if (len < LEN_AUTH)
   1130  1.1      manu 		return (-1);
   1131  1.3  christos 	(void)memcpy(buf, h->request + POS_AUTH, (size_t)LEN_AUTH);
   1132  1.1      manu 	if (len > LEN_AUTH)
   1133  1.1      manu 		buf[LEN_AUTH] = '\0';
   1134  1.1      manu 	return (LEN_AUTH);
   1135  1.1      manu }
   1136  1.1      manu 
   1137  1.1      manu u_char *
   1138  1.1      manu rad_demangle(struct rad_handle *h, const void *mangled, size_t mlen)
   1139  1.1      manu {
   1140  1.1      manu 	char R[LEN_AUTH];
   1141  1.1      manu 	const char *S;
   1142  1.1      manu 	int i, Ppos;
   1143  1.1      manu 	MD5_CTX Context;
   1144  1.2  christos 	u_char b[MD5_DIGEST_LENGTH], *demangled;
   1145  1.2  christos 	const u_char *C;
   1146  1.1      manu 
   1147  1.1      manu 	if ((mlen % 16 != 0) || mlen > 128) {
   1148  1.1      manu 		generr(h, "Cannot interpret mangled data of length %lu",
   1149  1.1      manu 		    (u_long)mlen);
   1150  1.1      manu 		return NULL;
   1151  1.1      manu 	}
   1152  1.1      manu 
   1153  1.2  christos 	C = (const u_char *)mangled;
   1154  1.1      manu 
   1155  1.1      manu 	/* We need the shared secret as Salt */
   1156  1.1      manu 	S = rad_server_secret(h);
   1157  1.1      manu 
   1158  1.1      manu 	/* We need the request authenticator */
   1159  1.1      manu 	if (rad_request_authenticator(h, R, sizeof R) != LEN_AUTH) {
   1160  1.1      manu 		generr(h, "Cannot obtain the RADIUS request authenticator");
   1161  1.1      manu 		return NULL;
   1162  1.1      manu 	}
   1163  1.1      manu 
   1164  1.1      manu 	demangled = malloc(mlen);
   1165  1.1      manu 	if (!demangled)
   1166  1.1      manu 		return NULL;
   1167  1.1      manu 
   1168  1.1      manu 	MD5Init(&Context);
   1169  1.6  christos 	MD5Update(&Context, (MD5Buf)S, (MD5Len)strlen(S));
   1170  1.6  christos 	MD5Update(&Context, (MD5Buf)R, (MD5Len)LEN_AUTH);
   1171  1.1      manu 	MD5Final(b, &Context);
   1172  1.1      manu 	Ppos = 0;
   1173  1.1      manu 	while (mlen) {
   1174  1.1      manu 
   1175  1.1      manu 		mlen -= 16;
   1176  1.1      manu 		for (i = 0; i < 16; i++)
   1177  1.1      manu 			demangled[Ppos++] = C[i] ^ b[i];
   1178  1.1      manu 
   1179  1.1      manu 		if (mlen) {
   1180  1.1      manu 			MD5Init(&Context);
   1181  1.6  christos 			MD5Update(&Context, (MD5Buf)S, (MD5Len)strlen(S));
   1182  1.6  christos 			MD5Update(&Context, (MD5Buf)C, (MD5Len)16);
   1183  1.1      manu 			MD5Final(b, &Context);
   1184  1.1      manu 		}
   1185  1.1      manu 
   1186  1.1      manu 		C += 16;
   1187  1.1      manu 	}
   1188  1.1      manu 
   1189  1.1      manu 	return demangled;
   1190  1.1      manu }
   1191  1.1      manu 
   1192  1.1      manu u_char *
   1193  1.1      manu rad_demangle_mppe_key(struct rad_handle *h, const void *mangled,
   1194  1.1      manu     size_t mlen, size_t *len)
   1195  1.1      manu {
   1196  1.1      manu 	char R[LEN_AUTH];    /* variable names as per rfc2548 */
   1197  1.1      manu 	const char *S;
   1198  1.1      manu 	u_char b[MD5_DIGEST_LENGTH], *demangled;
   1199  1.1      manu 	const u_char *A, *C;
   1200  1.1      manu 	MD5_CTX Context;
   1201  1.2  christos 	size_t Slen, Clen, i, Ppos;
   1202  1.1      manu 	u_char *P;
   1203  1.1      manu 
   1204  1.1      manu 	if (mlen % 16 != SALT_LEN) {
   1205  1.1      manu 		generr(h, "Cannot interpret mangled data of length %lu",
   1206  1.1      manu 		    (u_long)mlen);
   1207  1.1      manu 		return NULL;
   1208  1.1      manu 	}
   1209  1.1      manu 
   1210  1.1      manu 	/* We need the RADIUS Request-Authenticator */
   1211  1.1      manu 	if (rad_request_authenticator(h, R, sizeof R) != LEN_AUTH) {
   1212  1.1      manu 		generr(h, "Cannot obtain the RADIUS request authenticator");
   1213  1.1      manu 		return NULL;
   1214  1.1      manu 	}
   1215  1.1      manu 
   1216  1.1      manu 	A = (const u_char *)mangled;      /* Salt comes first */
   1217  1.1      manu 	C = (const u_char *)mangled + SALT_LEN;  /* Then the ciphertext */
   1218  1.1      manu 	Clen = mlen - SALT_LEN;
   1219  1.1      manu 	S = rad_server_secret(h);    /* We need the RADIUS secret */
   1220  1.1      manu 	Slen = strlen(S);
   1221  1.1      manu 	P = alloca(Clen);        /* We derive our plaintext */
   1222  1.1      manu 
   1223  1.1      manu 	MD5Init(&Context);
   1224  1.6  christos 	MD5Update(&Context, (MD5Buf)S, (MD5Len)Slen);
   1225  1.6  christos 	MD5Update(&Context, (MD5Buf)R, (MD5Len)LEN_AUTH);
   1226  1.6  christos 	MD5Update(&Context, (MD5Buf)A, (MD5Len)SALT_LEN);
   1227  1.1      manu 	MD5Final(b, &Context);
   1228  1.1      manu 	Ppos = 0;
   1229  1.1      manu 
   1230  1.1      manu 	while (Clen) {
   1231  1.1      manu 		Clen -= 16;
   1232  1.1      manu 
   1233  1.1      manu 		for (i = 0; i < 16; i++)
   1234  1.1      manu 		    P[Ppos++] = C[i] ^ b[i];
   1235  1.1      manu 
   1236  1.1      manu 		if (Clen) {
   1237  1.1      manu 			MD5Init(&Context);
   1238  1.6  christos 			MD5Update(&Context, (MD5Buf)S, (MD5Len)Slen);
   1239  1.6  christos 			MD5Update(&Context, (MD5Buf)C, (MD5Len)16);
   1240  1.1      manu 			MD5Final(b, &Context);
   1241  1.1      manu 		}
   1242  1.1      manu 
   1243  1.1      manu 		C += 16;
   1244  1.1      manu 	}
   1245  1.1      manu 
   1246  1.1      manu 	/*
   1247  1.1      manu 	* The resulting plain text consists of a one-byte length, the text and
   1248  1.1      manu 	* maybe some padding.
   1249  1.1      manu 	*/
   1250  1.1      manu 	*len = *P;
   1251  1.1      manu 	if (*len > mlen - 1) {
   1252  1.1      manu 		generr(h, "Mangled data seems to be garbage %zu %zu",
   1253  1.1      manu 		    *len, mlen-1);
   1254  1.1      manu 		return NULL;
   1255  1.1      manu 	}
   1256  1.1      manu 
   1257  1.1      manu 	if (*len > MPPE_KEY_LEN * 2) {
   1258  1.1      manu 		generr(h, "Key to long (%zu) for me max. %d",
   1259  1.1      manu 		    *len, MPPE_KEY_LEN * 2);
   1260  1.1      manu 		return NULL;
   1261  1.1      manu 	}
   1262  1.1      manu 	demangled = malloc(*len);
   1263  1.1      manu 	if (!demangled)
   1264  1.1      manu 		return NULL;
   1265  1.1      manu 
   1266  1.3  christos 	(void)memcpy(demangled, P + 1, *len);
   1267  1.1      manu 	return demangled;
   1268  1.1      manu }
   1269  1.1      manu 
   1270  1.1      manu const char *
   1271  1.1      manu rad_server_secret(struct rad_handle *h)
   1272  1.1      manu {
   1273  1.1      manu 	return (h->servers[h->srv].secret);
   1274  1.1      manu }
   1275