vnc: support password expire

This patch adds support for expiring passwords to vnc.  It adds a new
vnc_display_pw_expire() function which specifies the time when the
password will expire.

Signed-off-by: Gerd Hoffmann <kraxel@redhat.com>
This commit is contained in:
Gerd Hoffmann 2010-10-07 11:50:45 +02:00
parent 6bffdf0f83
commit 3c9405a0f7
4 changed files with 19 additions and 0 deletions

View File

@ -369,6 +369,7 @@ void vnc_display_init(DisplayState *ds);
void vnc_display_close(DisplayState *ds); void vnc_display_close(DisplayState *ds);
int vnc_display_open(DisplayState *ds, const char *display); int vnc_display_open(DisplayState *ds, const char *display);
int vnc_display_password(DisplayState *ds, const char *password); int vnc_display_password(DisplayState *ds, const char *password);
int vnc_display_pw_expire(DisplayState *ds, time_t expires);
void do_info_vnc_print(Monitor *mon, const QObject *data); void do_info_vnc_print(Monitor *mon, const QObject *data);
void do_info_vnc(Monitor *mon, QObject **ret_data); void do_info_vnc(Monitor *mon, QObject **ret_data);
char *vnc_display_local_addr(DisplayState *ds); char *vnc_display_local_addr(DisplayState *ds);

View File

@ -50,6 +50,9 @@ typedef struct DeviceState DeviceState;
#if !defined(ENOTSUP) #if !defined(ENOTSUP)
#define ENOTSUP 4096 #define ENOTSUP 4096
#endif #endif
#ifndef TIME_MAX
#define TIME_MAX LONG_MAX
#endif
#ifndef CONFIG_IOVEC #ifndef CONFIG_IOVEC
#define CONFIG_IOVEC #define CONFIG_IOVEC

View File

@ -2082,11 +2082,16 @@ static int protocol_client_auth_vnc(VncState *vs, uint8_t *data, size_t len)
unsigned char response[VNC_AUTH_CHALLENGE_SIZE]; unsigned char response[VNC_AUTH_CHALLENGE_SIZE];
int i, j, pwlen; int i, j, pwlen;
unsigned char key[8]; unsigned char key[8];
time_t now = time(NULL);
if (!vs->vd->password || !vs->vd->password[0]) { if (!vs->vd->password || !vs->vd->password[0]) {
VNC_DEBUG("No password configured on server"); VNC_DEBUG("No password configured on server");
goto reject; goto reject;
} }
if (vs->vd->expires < now) {
VNC_DEBUG("Password is expired");
goto reject;
}
memcpy(response, vs->challenge, VNC_AUTH_CHALLENGE_SIZE); memcpy(response, vs->challenge, VNC_AUTH_CHALLENGE_SIZE);
@ -2432,6 +2437,7 @@ void vnc_display_init(DisplayState *ds)
vs->ds = ds; vs->ds = ds;
QTAILQ_INIT(&vs->clients); QTAILQ_INIT(&vs->clients);
vs->expires = TIME_MAX;
if (keyboard_layout) if (keyboard_layout)
vs->kbd_layout = init_keyboard_layout(name2keysym, keyboard_layout); vs->kbd_layout = init_keyboard_layout(name2keysym, keyboard_layout);
@ -2503,6 +2509,14 @@ int vnc_display_password(DisplayState *ds, const char *password)
return 0; return 0;
} }
int vnc_display_pw_expire(DisplayState *ds, time_t expires)
{
VncDisplay *vs = ds ? (VncDisplay *)ds->opaque : vnc_display;
vs->expires = expires;
return 0;
}
char *vnc_display_local_addr(DisplayState *ds) char *vnc_display_local_addr(DisplayState *ds)
{ {
VncDisplay *vs = ds ? (VncDisplay *)ds->opaque : vnc_display; VncDisplay *vs = ds ? (VncDisplay *)ds->opaque : vnc_display;

View File

@ -120,6 +120,7 @@ struct VncDisplay
char *display; char *display;
char *password; char *password;
time_t expires;
int auth; int auth;
bool lossy; bool lossy;
#ifdef CONFIG_VNC_TLS #ifdef CONFIG_VNC_TLS