remove pam support
This commit is contained in:
parent
c99b599d4c
commit
a71f1d825d
6 changed files with 2 additions and 100 deletions
16
README.md
16
README.md
|
|
@ -40,12 +40,6 @@ cd sshpiper/sshpiperd/
|
||||||
go build
|
go build
|
||||||
```
|
```
|
||||||
|
|
||||||
with pam module support
|
|
||||||
|
|
||||||
```
|
|
||||||
go build -tags pam
|
|
||||||
```
|
|
||||||
|
|
||||||
### with [Docker image](https://registry.hub.docker.com/r/farmer1992/sshpiperd/)
|
### with [Docker image](https://registry.hub.docker.com/r/farmer1992/sshpiperd/)
|
||||||
|
|
||||||
```
|
```
|
||||||
|
|
@ -92,7 +86,6 @@ sudo snap restart sshpiperd
|
||||||
|
|
||||||
_NOTE:_
|
_NOTE:_
|
||||||
* Default working dir for snap verion is `/var/snap/sshpiperd/common`
|
* Default working dir for snap verion is `/var/snap/sshpiperd/common`
|
||||||
* use classic mode if PAM is not working: `sudo snap install --classic sshpiperd`
|
|
||||||
|
|
||||||
|
|
||||||
## Quick start
|
## Quick start
|
||||||
|
|
@ -221,15 +214,6 @@ This is useful when you want use publickey and something like [google-authentica
|
||||||
|
|
||||||
|
|
||||||
#### Available Challengers
|
#### Available Challengers
|
||||||
|
|
||||||
* pam
|
|
||||||
|
|
||||||
[Linux-PAM](http://www.linux-pam.org/) challenger
|
|
||||||
|
|
||||||
this module use the pam service called `sshpiperd`
|
|
||||||
|
|
||||||
you can configure the rule at `/etc/pam.d/sshpiperd`
|
|
||||||
|
|
||||||
* azdevcode
|
* azdevcode
|
||||||
|
|
||||||
Support Azure AD device code grant, [More info](https://docs.microsoft.com/en-us/azure/active-directory/develop/v2-oauth2-device-code)
|
Support Azure AD device code grant, [More info](https://docs.microsoft.com/en-us/azure/active-directory/develop/v2-oauth2-device-code)
|
||||||
|
|
|
||||||
4
go.mod
4
go.mod
|
|
@ -13,7 +13,6 @@ require (
|
||||||
github.com/Azure/go-autorest/autorest/adal v0.9.16
|
github.com/Azure/go-autorest/autorest/adal v0.9.16
|
||||||
github.com/Azure/go-autorest/autorest/to v0.4.0 // indirect
|
github.com/Azure/go-autorest/autorest/to v0.4.0 // indirect
|
||||||
github.com/Azure/go-autorest/autorest/validation v0.3.1 // indirect
|
github.com/Azure/go-autorest/autorest/validation v0.3.1 // indirect
|
||||||
github.com/bgentry/speakeasy v0.1.0 // indirect
|
|
||||||
github.com/dcu/go-authy v1.0.1
|
github.com/dcu/go-authy v1.0.1
|
||||||
github.com/denisenkom/go-mssqldb v0.11.0 // indirect
|
github.com/denisenkom/go-mssqldb v0.11.0 // indirect
|
||||||
github.com/go-sql-driver/mysql v1.6.0
|
github.com/go-sql-driver/mysql v1.6.0
|
||||||
|
|
@ -25,9 +24,7 @@ require (
|
||||||
github.com/jessevdk/go-flags v1.5.0
|
github.com/jessevdk/go-flags v1.5.0
|
||||||
github.com/jinzhu/gorm v1.9.16
|
github.com/jinzhu/gorm v1.9.16
|
||||||
github.com/json-iterator/go v1.1.12 // indirect
|
github.com/json-iterator/go v1.1.12 // indirect
|
||||||
github.com/lib/pq v1.10.3 // indirect
|
|
||||||
github.com/mattn/go-sqlite3 v2.0.3+incompatible // indirect
|
github.com/mattn/go-sqlite3 v2.0.3+incompatible // indirect
|
||||||
github.com/msteinert/pam v0.0.0-20201130170657-e61372126161
|
|
||||||
github.com/pockost/sshpipe-k8s-lib v0.0.3
|
github.com/pockost/sshpipe-k8s-lib v0.0.3
|
||||||
github.com/tg123/remotesigner v0.0.0-20210928104451-7c20285909d1
|
github.com/tg123/remotesigner v0.0.0-20210928104451-7c20285909d1
|
||||||
github.com/tg123/sshkey v0.0.0-20201202190454-3bb356f89f1f
|
github.com/tg123/sshkey v0.0.0-20201202190454-3bb356f89f1f
|
||||||
|
|
@ -57,6 +54,7 @@ require (
|
||||||
github.com/google/go-cmp v0.5.6 // indirect
|
github.com/google/go-cmp v0.5.6 // indirect
|
||||||
github.com/google/gofuzz v1.2.0 // indirect
|
github.com/google/gofuzz v1.2.0 // indirect
|
||||||
github.com/jinzhu/inflection v1.0.0 // indirect
|
github.com/jinzhu/inflection v1.0.0 // indirect
|
||||||
|
github.com/lib/pq v1.1.1 // indirect
|
||||||
github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd // indirect
|
github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd // indirect
|
||||||
github.com/modern-go/reflect2 v1.0.2 // indirect
|
github.com/modern-go/reflect2 v1.0.2 // indirect
|
||||||
github.com/pkg/errors v0.9.1 // indirect
|
github.com/pkg/errors v0.9.1 // indirect
|
||||||
|
|
|
||||||
7
go.sum
7
go.sum
|
|
@ -65,8 +65,6 @@ github.com/PuerkitoBio/urlesc v0.0.0-20170810143723-de5bf2ad4578/go.mod h1:uGdko
|
||||||
github.com/andybalholm/cascadia v1.1.0/go.mod h1:GsXiBklL0woXo1j/WYWtSYYC4ouU9PqHO0sqidkEA4Y=
|
github.com/andybalholm/cascadia v1.1.0/go.mod h1:GsXiBklL0woXo1j/WYWtSYYC4ouU9PqHO0sqidkEA4Y=
|
||||||
github.com/antihax/optional v1.0.0/go.mod h1:uupD/76wgC+ih3iEmQUL+0Ugr19nfwCT1kdvxnR2qWY=
|
github.com/antihax/optional v1.0.0/go.mod h1:uupD/76wgC+ih3iEmQUL+0Ugr19nfwCT1kdvxnR2qWY=
|
||||||
github.com/asaskevich/govalidator v0.0.0-20190424111038-f61b66f89f4a/go.mod h1:lB+ZfQJz7igIIfQNfa7Ml4HSf2uFQQRzpGGRXenZAgY=
|
github.com/asaskevich/govalidator v0.0.0-20190424111038-f61b66f89f4a/go.mod h1:lB+ZfQJz7igIIfQNfa7Ml4HSf2uFQQRzpGGRXenZAgY=
|
||||||
github.com/bgentry/speakeasy v0.1.0 h1:ByYyxL9InA1OWqxJqqp2A5pYHUrCiAL6K3J+LKSsQkY=
|
|
||||||
github.com/bgentry/speakeasy v0.1.0/go.mod h1:+zsyZBPWlz7T6j88CTgSN5bM796AkVf0kBD4zp0CCIs=
|
|
||||||
github.com/census-instrumentation/opencensus-proto v0.2.1/go.mod h1:f6KPmirojxKA12rnyqOA5BBL4O983OfeGPqjHWSTneU=
|
github.com/census-instrumentation/opencensus-proto v0.2.1/go.mod h1:f6KPmirojxKA12rnyqOA5BBL4O983OfeGPqjHWSTneU=
|
||||||
github.com/cespare/xxhash v1.1.0/go.mod h1:XrSqR1VqqWfGrhpAt58auRo0WTKS1nRRg3ghfAqPWnc=
|
github.com/cespare/xxhash v1.1.0/go.mod h1:XrSqR1VqqWfGrhpAt58auRo0WTKS1nRRg3ghfAqPWnc=
|
||||||
github.com/cespare/xxhash/v2 v2.1.1/go.mod h1:VGX0DQ3Q6kWi7AoAeZDth3/j3BFtOZR5XLFGgcrjCOs=
|
github.com/cespare/xxhash/v2 v2.1.1/go.mod h1:VGX0DQ3Q6kWi7AoAeZDth3/j3BFtOZR5XLFGgcrjCOs=
|
||||||
|
|
@ -230,9 +228,8 @@ github.com/kr/pty v1.1.5/go.mod h1:9r2w37qlBe7rQ6e1fg1S/9xpWHSnaqNdHD3WcMdbPDA=
|
||||||
github.com/kr/text v0.1.0/go.mod h1:4Jbv+DJW3UT/LiOwJeYQe1efqtUx/iVham/4vfdArNI=
|
github.com/kr/text v0.1.0/go.mod h1:4Jbv+DJW3UT/LiOwJeYQe1efqtUx/iVham/4vfdArNI=
|
||||||
github.com/kr/text v0.2.0 h1:5Nx0Ya0ZqY2ygV366QzturHI13Jq95ApcVaJBhpS+AY=
|
github.com/kr/text v0.2.0 h1:5Nx0Ya0ZqY2ygV366QzturHI13Jq95ApcVaJBhpS+AY=
|
||||||
github.com/kr/text v0.2.0/go.mod h1:eLer722TekiGuMkidMxC/pM04lWEeraHUUmBw8l2grE=
|
github.com/kr/text v0.2.0/go.mod h1:eLer722TekiGuMkidMxC/pM04lWEeraHUUmBw8l2grE=
|
||||||
|
github.com/lib/pq v1.1.1 h1:sJZmqHoEaY7f+NPP8pgLB/WxulyR3fewgCM2qaSlBb4=
|
||||||
github.com/lib/pq v1.1.1/go.mod h1:5WUZQaWbwv1U+lTReE5YruASi9Al49XbQIvNi/34Woo=
|
github.com/lib/pq v1.1.1/go.mod h1:5WUZQaWbwv1U+lTReE5YruASi9Al49XbQIvNi/34Woo=
|
||||||
github.com/lib/pq v1.10.3 h1:v9QZf2Sn6AmjXtQeFpdoq/eaNtYP6IN+7lcrygsIAtg=
|
|
||||||
github.com/lib/pq v1.10.3/go.mod h1:AlVN5x4E4T544tWzH6hKfbfQvm3HdbOxrmggDNAPY9o=
|
|
||||||
github.com/mailru/easyjson v0.0.0-20190614124828-94de47d64c63/go.mod h1:C1wdFJiN94OJF2b5HbByQZoLdCWB1Yqtg26g4irojpc=
|
github.com/mailru/easyjson v0.0.0-20190614124828-94de47d64c63/go.mod h1:C1wdFJiN94OJF2b5HbByQZoLdCWB1Yqtg26g4irojpc=
|
||||||
github.com/mailru/easyjson v0.0.0-20190626092158-b2ccc519800e/go.mod h1:C1wdFJiN94OJF2b5HbByQZoLdCWB1Yqtg26g4irojpc=
|
github.com/mailru/easyjson v0.0.0-20190626092158-b2ccc519800e/go.mod h1:C1wdFJiN94OJF2b5HbByQZoLdCWB1Yqtg26g4irojpc=
|
||||||
github.com/mattn/go-sqlite3 v1.14.0/go.mod h1:JIl7NbARA7phWnGvh0LKTyg7S9BA+6gx71ShQilpsus=
|
github.com/mattn/go-sqlite3 v1.14.0/go.mod h1:JIl7NbARA7phWnGvh0LKTyg7S9BA+6gx71ShQilpsus=
|
||||||
|
|
@ -247,8 +244,6 @@ github.com/modern-go/reflect2 v0.0.0-20180701023420-4b7aa43c6742/go.mod h1:bx2lN
|
||||||
github.com/modern-go/reflect2 v1.0.1/go.mod h1:bx2lNnkwVCuqBIxFjflWJWanXIb3RllmbCylyMrvgv0=
|
github.com/modern-go/reflect2 v1.0.1/go.mod h1:bx2lNnkwVCuqBIxFjflWJWanXIb3RllmbCylyMrvgv0=
|
||||||
github.com/modern-go/reflect2 v1.0.2 h1:xBagoLtFs94CBntxluKeaWgTMpvLxC4ur3nMaC9Gz0M=
|
github.com/modern-go/reflect2 v1.0.2 h1:xBagoLtFs94CBntxluKeaWgTMpvLxC4ur3nMaC9Gz0M=
|
||||||
github.com/modern-go/reflect2 v1.0.2/go.mod h1:yWuevngMOJpCy52FWWMvUC8ws7m/LJsjYzDa0/r8luk=
|
github.com/modern-go/reflect2 v1.0.2/go.mod h1:yWuevngMOJpCy52FWWMvUC8ws7m/LJsjYzDa0/r8luk=
|
||||||
github.com/msteinert/pam v0.0.0-20201130170657-e61372126161 h1:XQ1+fYPzaWZCVdu1xzjL917Xy9Yb7imLEU0wHelafKA=
|
|
||||||
github.com/msteinert/pam v0.0.0-20201130170657-e61372126161/go.mod h1:np1wUFZ6tyoke22qDJZY40URn9Ae51gX7ljIWXN5TJs=
|
|
||||||
github.com/munnerz/goautoneg v0.0.0-20120707110453-a547fc61f48d/go.mod h1:+n7T8mK8HuQTcFwEeznm/DIxMOiR9yIdICNftLE1DvQ=
|
github.com/munnerz/goautoneg v0.0.0-20120707110453-a547fc61f48d/go.mod h1:+n7T8mK8HuQTcFwEeznm/DIxMOiR9yIdICNftLE1DvQ=
|
||||||
github.com/mxk/go-flowrate v0.0.0-20140419014527-cca7078d478f/go.mod h1:ZdcZmHo+o7JKHSa8/e818NopupXU1YMK5fe1lsApnBw=
|
github.com/mxk/go-flowrate v0.0.0-20140419014527-cca7078d478f/go.mod h1:ZdcZmHo+o7JKHSa8/e818NopupXU1YMK5fe1lsApnBw=
|
||||||
github.com/niemeyer/pretty v0.0.0-20200227124842-a10e7caefd8e h1:fD57ERR4JtEqsWbfPhv4DMiApHyliiK5xCTNVSPiaAs=
|
github.com/niemeyer/pretty v0.0.0-20200227124842-a10e7caefd8e h1:fD57ERR4JtEqsWbfPhv4DMiApHyliiK5xCTNVSPiaAs=
|
||||||
|
|
|
||||||
|
|
@ -1 +0,0 @@
|
||||||
package pam
|
|
||||||
|
|
@ -1,73 +0,0 @@
|
||||||
// +build pam
|
|
||||||
|
|
||||||
package pam
|
|
||||||
|
|
||||||
import (
|
|
||||||
"errors"
|
|
||||||
"fmt"
|
|
||||||
"os"
|
|
||||||
|
|
||||||
"golang.org/x/crypto/ssh"
|
|
||||||
|
|
||||||
"github.com/msteinert/pam"
|
|
||||||
|
|
||||||
"github.com/tg123/sshpiper/sshpiperd/challenger"
|
|
||||||
)
|
|
||||||
|
|
||||||
const (
|
|
||||||
SSHPIPER_PAM_SERVICE_FILE = "/etc/pam.d/sshpiperd"
|
|
||||||
)
|
|
||||||
|
|
||||||
func pamChallenger(conn ssh.ConnMetadata, client ssh.KeyboardInteractiveChallenge) (ssh.AdditionalChallengeContext, error) {
|
|
||||||
|
|
||||||
user := conn.User()
|
|
||||||
|
|
||||||
sendQuesttion := func(question string, echo bool) (string, error) {
|
|
||||||
ans, err := client(user, "", []string{question}, []bool{echo})
|
|
||||||
|
|
||||||
if err != nil {
|
|
||||||
return "", err
|
|
||||||
}
|
|
||||||
|
|
||||||
return ans[0], nil
|
|
||||||
}
|
|
||||||
|
|
||||||
sendInstruction := func(instruction string) (string, error) {
|
|
||||||
_, err := client(user, instruction, nil, nil)
|
|
||||||
return "", err
|
|
||||||
}
|
|
||||||
|
|
||||||
t, err := pam.StartFunc("sshpiperd", user, func(style pam.Style, msg string) (string, error) {
|
|
||||||
switch style {
|
|
||||||
case pam.PromptEchoOff:
|
|
||||||
return sendQuesttion(msg, false)
|
|
||||||
case pam.PromptEchoOn:
|
|
||||||
return sendQuesttion(msg, true)
|
|
||||||
case pam.ErrorMsg:
|
|
||||||
return sendInstruction(fmt.Sprintf("Error: %s", msg))
|
|
||||||
case pam.TextInfo:
|
|
||||||
return sendInstruction(msg)
|
|
||||||
}
|
|
||||||
return "", errors.New("Unrecognized message style")
|
|
||||||
})
|
|
||||||
|
|
||||||
if err != nil {
|
|
||||||
return nil, err
|
|
||||||
}
|
|
||||||
|
|
||||||
err = t.Authenticate(0)
|
|
||||||
if err != nil {
|
|
||||||
return nil, err
|
|
||||||
}
|
|
||||||
|
|
||||||
return nil, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func init() {
|
|
||||||
if _, err := os.Stat(SSHPIPER_PAM_SERVICE_FILE); os.IsNotExist(err) {
|
|
||||||
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
challenger.Register("pam", challenger.NewFromHandler("pam", func() challenger.Handler { return pamChallenger }, nil, nil))
|
|
||||||
}
|
|
||||||
|
|
@ -9,7 +9,6 @@ import (
|
||||||
|
|
||||||
_ "github.com/tg123/sshpiper/sshpiperd/challenger/authy"
|
_ "github.com/tg123/sshpiper/sshpiperd/challenger/authy"
|
||||||
_ "github.com/tg123/sshpiper/sshpiperd/challenger/azdevicecode"
|
_ "github.com/tg123/sshpiper/sshpiperd/challenger/azdevicecode"
|
||||||
_ "github.com/tg123/sshpiper/sshpiperd/challenger/pam"
|
|
||||||
_ "github.com/tg123/sshpiper/sshpiperd/challenger/pome"
|
_ "github.com/tg123/sshpiper/sshpiperd/challenger/pome"
|
||||||
|
|
||||||
_ "github.com/tg123/sshpiper/sshpiperd/auditor/typescriptlogger"
|
_ "github.com/tg123/sshpiper/sshpiperd/auditor/typescriptlogger"
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue