Back to home page

EIC code displayed by LXR

 
 

    


File indexing completed on 2026-10-10 09:38:25

0001 // @(#)root/auth:$Id$
0002 // Author: Fons Rademakers   26/11/2000
0003 
0004 /*************************************************************************
0005  * Copyright (C) 1995-2000, Rene Brun and Fons Rademakers.               *
0006  * All rights reserved.                                                  *
0007  *                                                                       *
0008  * For the licensing terms see $ROOTSYS/LICENSE.                         *
0009  * For the list of contributors see $ROOTSYS/README/CREDITS.             *
0010  *************************************************************************/
0011 
0012 #ifndef ROOT_TAuthenticate
0013 #define ROOT_TAuthenticate
0014 
0015 
0016 //////////////////////////////////////////////////////////////////////////
0017 //                                                                      //
0018 // TAuthenticate                                                        //
0019 //                                                                      //
0020 // An authentication module for ROOT based network services, like rootd.//                                                          //
0021 //                                                                      //
0022 //////////////////////////////////////////////////////////////////////////
0023 
0024 #include "TObject.h"
0025 #include "TString.h"
0026 #include "TList.h"
0027 #include "TDatime.h"
0028 #ifndef ROOT_rsafun
0029 //#include "rsafun.h"
0030 #endif
0031 #include "AuthConst.h"
0032 
0033 class TPluginHandler;
0034 class TSocket;
0035 class TVirtualMutex;
0036 
0037 namespace ROOT::Deprecated {
0038 
0039 struct R__rsa_KEY; // opaque replacement for rsa_KEY
0040 struct R__rsa_KEY_export; // opaque replacement for rsa_KEY_export
0041 struct R__rsa_NUMBER; // opaque replacement for rsa_NUMBER
0042 
0043 R__EXTERN TVirtualMutex *gAuthenticateMutex;
0044 
0045 class TAuthenticate;
0046 class THostAuth;
0047 class TRootAuth;
0048 class TRootSecContext;
0049 
0050 typedef Int_t (*CheckSecCtx_t)(const char *subj, ROOT::Deprecated::TRootSecContext *ctx);
0051 typedef Int_t (*GlobusAuth_t)(ROOT::Deprecated::TAuthenticate *auth, TString &user, TString &det);
0052 typedef Int_t (*Krb5Auth_t)(ROOT::Deprecated::TAuthenticate *auth, TString &user, TString &det, Int_t version);
0053 typedef Int_t (*SecureAuth_t)(ROOT::Deprecated::TAuthenticate *auth, const char *user, const char *passwd,
0054                               const char *remote, TString &det, Int_t version);
0055 
0056 class TAuthenticate : public TObject {
0057 
0058 friend class ROOT::Deprecated::TRootAuth;
0059 friend class ROOT::Deprecated::TRootSecContext;
0060 
0061 public:
0062    enum ESecurity {
0063 // clang++ <v20 (-Wshadow) complains about shadowing Getline.h global enum EGetLineMode. Let's silence warning:
0064 #if defined(__clang__) && __clang_major__ < 20
0065 #pragma clang diagnostic push
0066 #pragma clang diagnostic ignored "-Wshadow"
0067 #endif
0068       kClear,
0069 #if defined(__clang__) && __clang_major__ < 20
0070 #pragma clang diagnostic pop
0071 #endif
0072       kUnsupported, kKrb5, kGlobus, kSSH, kRfio }; // type of authentication
0073 
0074 private:
0075    TString      fDetails;     // logon details (method dependent ...)
0076    THostAuth   *fHostAuth;    // pointer to relevant authentication info
0077    TString      fPasswd;      // user's password
0078    TString      fProtocol;    // remote service (rootd)
0079    Bool_t       fPwHash;      // kTRUE if fPasswd is a passwd hash
0080    TString      fRemote;      // remote host to which we want to connect
0081    Int_t        fRSAKey;      // Type of RSA key used
0082    TRootSecContext *fSecContext;  // pointer to relevant sec context
0083    ESecurity    fSecurity;    // actual logon security level
0084    TSocket     *fSocket;      // connection to remote daemon
0085    Int_t        fVersion;     // 0,1,2, ... accordingly to remote daemon version
0086    TString      fUser;        // user to be authenticated
0087    Int_t        fTimeOut;     // timeout flag
0088 
0089    Int_t        GenRSAKeys();
0090    Bool_t       GetPwHash() const { return fPwHash; }
0091    Int_t        GetRSAKey() const { return fRSAKey; }
0092    ESecurity    GetSecurity() const { return fSecurity; }
0093    Bool_t       GetSRPPwd() const { return false; }
0094    const char  *GetSshUser(TString user) const;
0095    Int_t        GetVersion() const { return fVersion; }
0096    Int_t        ClearAuth(TString &user, TString &passwd, Bool_t &pwhash);
0097    Bool_t       GetUserPasswd(TString &user, TString &passwd,
0098                               Bool_t &pwhash, Bool_t srppwd);
0099    char        *GetRandString(Int_t Opt,Int_t Len);
0100    Int_t        RfioAuth(TString &user);
0101    void         SetEnvironment();
0102    Int_t        SshAuth(TString &user);
0103    Int_t        SshError(const char *errfile);
0104 
0105    static TList          *fgAuthInfo;
0106    static TString         fgAuthMeth[kMAXSEC];
0107    static Bool_t          fgAuthReUse;      // kTRUE is ReUse required
0108    static TString         fgDefaultUser;    // Default user information
0109    static TDatime         fgExpDate;        // Expiring date for new security contexts
0110    static GlobusAuth_t    fgGlobusAuthHook;
0111    static Krb5Auth_t      fgKrb5AuthHook;
0112    static TString         fgKrb5Principal;  // Principal for Krb5 ticket
0113    static TDatime         fgLastAuthrc;     // Time of last reading of fgRootAuthrc
0114    static TString         fgPasswd;
0115    static TPluginHandler *fgPasswdDialog;   // Passwd dialog GUI plugin
0116    static Bool_t          fgPromptUser;     // kTRUE if user prompt required
0117    static Bool_t          fgPwHash;         // kTRUE if fgPasswd is a passwd hash
0118    static Bool_t          fgReadHomeAuthrc; // kTRUE to look for $HOME/.rootauthrc
0119    static TString         fgRootAuthrc;     // Path to last rootauthrc-like file read
0120    static Int_t           fgRSAKey;         // Default type of RSA key to be tried
0121    static Int_t           fgRSAInit;
0122    static R__rsa_KEY         fgRSAPriKey;
0123    static R__rsa_KEY         fgRSAPubKey;
0124    static R__rsa_KEY_export* fgRSAPubExport; // array of size [2]
0125    static SecureAuth_t    fgSecAuthHook;
0126    static TString         fgUser;
0127    static Bool_t          fgUsrPwdCrypt;    // kTRUE if encryption for UsrPwd is required
0128    static Int_t           fgLastError;      // Last error code processed by AuthError()
0129    static Int_t           fgAuthTO;         // if > 0, timeout in sec
0130    static Int_t           fgProcessID;      // ID of the main thread as unique identifier
0131 
0132    static Bool_t          CheckHost(const char *Host, const char *host);
0133 
0134    static void            FileExpand(const char *fin, FILE *ftmp);
0135    static void            RemoveSecContext(TRootSecContext *ctx);
0136 
0137 public:
0138    TAuthenticate(TSocket *sock, const char *remote, const char *proto,
0139                  const char *user = "");
0140    virtual ~TAuthenticate() {}
0141 
0142    Bool_t             Authenticate();
0143    Int_t              AuthExists(TString User, Int_t method, const char *Options,
0144                           Int_t *Message, Int_t *Rflag, CheckSecCtx_t funcheck);
0145    void               CatchTimeOut();
0146    Bool_t             CheckNetrc(TString &user, TString &passwd);
0147    Bool_t             CheckNetrc(TString &user, TString &passwd,
0148                                  Bool_t &pwhash, Bool_t srppwd);
0149    THostAuth         *GetHostAuth() const { return fHostAuth; }
0150    const char        *GetProtocol() const { return fProtocol; }
0151    const char        *GetRemoteHost() const { return fRemote; }
0152    Int_t              GetRSAKeyType() const { return fRSAKey; }
0153    TRootSecContext       *GetSecContext() const { return fSecContext; }
0154    TSocket           *GetSocket() const { return fSocket; }
0155    const char        *GetUser() const { return fUser; }
0156    Int_t              HasTimedOut() const { return fTimeOut; }
0157    void               SetRSAKeyType(Int_t key) { fRSAKey = key; }
0158    void               SetSecContext(TRootSecContext *ctx) { fSecContext = ctx; }
0159 
0160    static void        AuthError(const char *where, Int_t error);
0161 
0162    static Int_t       DecodeRSAPublic(const char *rsapubexport, R__rsa_NUMBER &n,
0163                                       R__rsa_NUMBER &d, char **rsassl = nullptr);
0164 
0165    static TList      *GetAuthInfo();
0166    static const char *GetAuthMethod(Int_t idx);
0167    static Int_t       GetAuthMethodIdx(const char *meth);
0168    static Bool_t      GetAuthReUse();
0169    static Int_t       GetClientProtocol();
0170    static char       *GetDefaultDetails(Int_t method, Int_t opt, const char *user);
0171    static const char *GetDefaultUser();
0172    static TDatime     GetGlobalExpDate();
0173    static Bool_t      GetGlobalPwHash();
0174    static Bool_t      GetGlobalSRPPwd();
0175    static const char *GetGlobalUser();
0176    static GlobusAuth_t GetGlobusAuthHook();
0177    static THostAuth  *GetHostAuth(const char *host, const char *user="",
0178                                                     Option_t *opt = "R", Int_t *Exact = nullptr);
0179    static const char *GetKrb5Principal();
0180    static Bool_t      GetPromptUser();
0181    static Int_t       GetRSAInit();
0182    static const char *GetRSAPubExport(Int_t key = 0);
0183    static THostAuth  *HasHostAuth(const char *host, const char *user,
0184                                                     Option_t *opt = "R");
0185    static void        InitRandom();
0186    static void        MergeHostAuthList(TList *Std, TList *New, Option_t *Opt = "");
0187    static char       *PromptPasswd(const char *prompt = "Password: ");
0188    static char       *PromptUser(const char *remote);
0189    static Int_t       ReadRootAuthrc();
0190    static void        RemoveHostAuth(THostAuth *ha, Option_t *opt = "");
0191    static Int_t       SecureRecv(TSocket *Socket, Int_t dec,
0192                                  Int_t KeyType, char **Out);
0193    static Int_t       SecureSend(TSocket *Socket, Int_t enc,
0194                                  Int_t KeyType, const char *In);
0195    static Int_t       SendRSAPublicKey(TSocket *Socket, Int_t key = 0);
0196    static void        SetAuthReUse(Bool_t authreuse);
0197    static void        SetDefaultUser(const char *defaultuser);
0198    static void        SetGlobalExpDate(TDatime expdate);
0199    static void        SetGlobalPasswd(const char *passwd);
0200    static void        SetGlobalPwHash(Bool_t pwhash);
0201    static void        SetGlobalSRPPwd(Bool_t srppwd);
0202    static void        SetGlobalUser(const char *user);
0203    static void        SetGlobusAuthHook(GlobusAuth_t func);
0204    static void        SetKrb5AuthHook(Krb5Auth_t func);
0205    static void        SetPromptUser(Bool_t promptuser);
0206    static void        SetDefaultRSAKeyType(Int_t key);
0207    static void        SetRSAInit(Int_t init = 1);
0208    static Int_t       SetRSAPublic(const char *rsapubexport, Int_t klen);
0209    static void        SetSecureAuthHook(SecureAuth_t func);
0210    static void        SetTimeOut(Int_t to);
0211    static void        Show(Option_t *opt="S");
0212 
0213    ClassDefOverride(TAuthenticate,0)  // Class providing remote authentication service
0214 };
0215 
0216 } // namespace ROOT::Deprecated
0217 
0218 R__EXTERN TVirtualMutex *&gAuthenticateMutex R__DEPRECATED(6, 42, "the RootAuth library is deprecated");
0219 
0220 using CheckSecCtx_t R__DEPRECATED(6, 42, "the RootAuth library is deprecated") = ROOT::Deprecated::CheckSecCtx_t;
0221 using GlobusAuth_t R__DEPRECATED(6, 42, "the RootAuth library is deprecated") = ROOT::Deprecated::GlobusAuth_t;
0222 using Krb5Auth_t R__DEPRECATED(6, 42, "the RootAuth library is deprecated") = ROOT::Deprecated::Krb5Auth_t;
0223 using SecureAuth_t R__DEPRECATED(6, 42, "the RootAuth library is deprecated") = ROOT::Deprecated::SecureAuth_t;
0224 using TAuthenticate R__DEPRECATED(6, 42, "the RootAuth library is deprecated") = ROOT::Deprecated::TAuthenticate;
0225 
0226 #endif