summaryrefslogtreecommitdiff
path: root/libexec/login_reject
AgeCommit message (Collapse)Author
2016-04-26Add missing "tty" promise to the pledge(2) callRicardo Mestre
This is needed since getpass(3) calls readpassphrase(3) which in turn tries to open(2) a tty in O_RDWR mode Problem reported by Kevin Chadwick <m8il1ists ! gmail.com> Cluebat stick provided by deraadt@, OK millert@
2015-11-19Call syslog() if login_* pledge fails; OK deraadt@Todd C. Miller
2015-10-22use crypt_checkpass("password", NULL) to fake a login instead of bcryptTed Unangst
2015-10-14pledge "stdio rpath" is good enough for these mainline BSD auth loginTheo de Raadt
programs. (I am very surprised pledge ended up working for programs like this) ok semarie millert
2014-11-03reduce dependency on passwd. just call bcrypt_newhash to do the dummy work.Ted Unangst
2014-04-23Remove more Kerberos cruft.Antoine Jacoutot
ok jca@ jmc@
2012-12-04remove some unnecessary sys/param.h inclusionsTheo de Raadt
2007-05-31convert to new .Dd format;Jason McIntyre
2007-02-06fix some dodgy displays;Jason McIntyre
2006-04-02some extern and gooTheo de Raadt
2006-03-09Foil potential timing attacks by using the correct password hashTodd C. Miller
instead of "xx". In practice this means bcrypt() will be used for non-existent users instead of DES crypt(). Adapted from a patch by Peter Philipp. OK deraadt@
2002-09-06ansi; ok millert pvalchevTheo de Raadt
2002-06-28minor indent cleanupTheo de Raadt
2002-06-02minor KNFTheo de Raadt
2002-03-13login(8) -> login(1)Marco S Hyman
2001-12-06Do not set handler for SIGINT and SIGQUIT to SIG_IGN since it preventsTodd C. Miller
getpass()/readpassphrase() from being able to restore the tty mode on keyboard interrupt. Along with the recent readpassphrase.c commit this means that if you ^C things that use login scripts (like su(1)) with a non-CBREAK shell your tty mode will be restored nicely. TODO: The various login scripts need to install handlers to avoid leaving turd files or otherwise ending in a bad state. It would also be nice to send BI_REJECT to the back channel.
2001-11-13o) fix bogus .Xr usage;Mike Pechkin
o) start new sentence on a new line; o) don't use .Xr instead of .Pa tag; o) minimal -mdoc design fixes; millert@ ok;
2001-10-24getopt(3) returns -1 when out of args, not EOF.Mike Pechkin
millert@ ok
2001-07-08Remove extraneous .Pp after .ShTodd C. Miller
2000-12-12reject login script; rejects attempted authenticationTodd C. Miller
will be used when BSD authentication is enabled