From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from [140.186.70.92] (port=41807 helo=eggs.gnu.org) by lists.gnu.org with esmtp (Exim 4.43) id 1PLIl4-0007B3-Qv for qemu-devel@nongnu.org; Wed, 24 Nov 2010 12:03:52 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1PLIl3-0001Ro-Lz for qemu-devel@nongnu.org; Wed, 24 Nov 2010 12:03:50 -0500 Received: from mx1.redhat.com ([209.132.183.28]:60257) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1PLIl3-0001RH-F3 for qemu-devel@nongnu.org; Wed, 24 Nov 2010 12:03:49 -0500 Received: from int-mx12.intmail.prod.int.phx2.redhat.com (int-mx12.intmail.prod.int.phx2.redhat.com [10.5.11.25]) by mx1.redhat.com (8.13.8/8.13.8) with ESMTP id oAOH3mja026425 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=OK) for ; Wed, 24 Nov 2010 12:03:48 -0500 From: Gerd Hoffmann Date: Wed, 24 Nov 2010 18:03:44 +0100 Message-Id: <1290618225-28879-3-git-send-email-kraxel@redhat.com> In-Reply-To: <1290618225-28879-1-git-send-email-kraxel@redhat.com> References: <1290618225-28879-1-git-send-email-kraxel@redhat.com> Subject: [Qemu-devel] [PATCH 2/3] vnc: support password expire List-Id: qemu-devel.nongnu.org List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: qemu-devel@nongnu.org Cc: Gerd Hoffmann This patch adds support for expiring passwords to vnc. It adds a new vnc_display_pw_expire() function which specifies the time when the password will expire. Signed-off-by: Gerd Hoffmann --- console.h | 1 + qemu-common.h | 3 +++ ui/vnc.c | 14 ++++++++++++++ ui/vnc.h | 1 + 4 files changed, 19 insertions(+), 0 deletions(-) diff --git a/console.h b/console.h index aafb031..b2fc908 100644 --- a/console.h +++ b/console.h @@ -369,6 +369,7 @@ void vnc_display_init(DisplayState *ds); void vnc_display_close(DisplayState *ds); int vnc_display_open(DisplayState *ds, const char *display); int vnc_display_password(DisplayState *ds, const char *password); +int vnc_display_pw_expire(DisplayState *ds, time_t expires); void do_info_vnc_print(Monitor *mon, const QObject *data); void do_info_vnc(Monitor *mon, QObject **ret_data); char *vnc_display_local_addr(DisplayState *ds); diff --git a/qemu-common.h b/qemu-common.h index b3957f1..d0ab116 100644 --- a/qemu-common.h +++ b/qemu-common.h @@ -50,6 +50,9 @@ typedef struct DeviceState DeviceState; #if !defined(ENOTSUP) #define ENOTSUP 4096 #endif +#ifndef TIME_MAX +#define TIME_MAX LONG_MAX +#endif #ifndef CONFIG_IOVEC #define CONFIG_IOVEC diff --git a/ui/vnc.c b/ui/vnc.c index da70757..495d6d6 100644 --- a/ui/vnc.c +++ b/ui/vnc.c @@ -2082,11 +2082,16 @@ static int protocol_client_auth_vnc(VncState *vs, uint8_t *data, size_t len) unsigned char response[VNC_AUTH_CHALLENGE_SIZE]; int i, j, pwlen; unsigned char key[8]; + time_t now = time(NULL); if (!vs->vd->password || !vs->vd->password[0]) { VNC_DEBUG("No password configured on server"); goto reject; } + if (vs->vd->expires < now) { + VNC_DEBUG("Password is expired"); + goto reject; + } memcpy(response, vs->challenge, VNC_AUTH_CHALLENGE_SIZE); @@ -2432,6 +2437,7 @@ void vnc_display_init(DisplayState *ds) vs->ds = ds; QTAILQ_INIT(&vs->clients); + vs->expires = TIME_MAX; if (keyboard_layout) vs->kbd_layout = init_keyboard_layout(name2keysym, keyboard_layout); @@ -2503,6 +2509,14 @@ int vnc_display_password(DisplayState *ds, const char *password) return 0; } +int vnc_display_pw_expire(DisplayState *ds, time_t expires) +{ + VncDisplay *vs = ds ? (VncDisplay *)ds->opaque : vnc_display; + + vs->expires = expires; + return 0; +} + char *vnc_display_local_addr(DisplayState *ds) { VncDisplay *vs = ds ? (VncDisplay *)ds->opaque : vnc_display; diff --git a/ui/vnc.h b/ui/vnc.h index 9619b24..4f895be 100644 --- a/ui/vnc.h +++ b/ui/vnc.h @@ -120,6 +120,7 @@ struct VncDisplay char *display; char *password; + time_t expires; int auth; bool lossy; #ifdef CONFIG_VNC_TLS -- 1.7.1