File: //opt/saltstack/salt/lib/python3.10/site-packages/salt/auth/__pycache__/pam.cpython-310.pyc
o
;j�0 � @ s� d Z ddlZddlZddlZddlZddlZddlmZmZm Z m
Z
mZmZm
Z
mZmZmZmZmZ ddlmZ dZzddlZW n eyK dZY nw e�e�Zzeed��ZejZee_eege_ ej!Z"ege"_#e e�e"_W n e$y� ej%ddd � dZ&Y nw dZ&d
Z'dZ(dZ)d
Z*G dd� de
�Z+G dd� de
�Z,G dd� de
�Z-ee
e
e e e,��e e e-��e�Z.G dd� de
�Z/z:eed��Z0e0j1Z2e
e2_eee e/�e e+�ge2_ e0j3Z4e
e4_e+e
ge4_ e0j5Z6e
e6_e+e
ge6_ e0j7Z8e
e8_e+e
ge8_ W n e$�y
ej%ddd � dZ9Y nw dZ9dd� Z:d-dd�Z;da<dZ=dd� Z>d d!� Z?d"d#� Z@d$d%� ZAd&d'� ZBed(k�rSe;ejCd) ejCd* ejCd+ ejCd, ��rLe�Dd� e�Dd
� dS dS ).a�
Authenticate against PAM
Provides an authenticate function that will allow the caller to authenticate
a user against the Pluggable Authentication Modules (PAM) on the system.
Implemented using ctypes, so no compilation is necessary.
There is one extra configuration option for pam. The `pam_service` that is
authenticated against. This defaults to `login`
.. code-block:: yaml
auth.pam.service: login
.. note:: Solaris-like (SmartOS, OmniOS, ...) systems may need ``auth.pam.service`` set to ``other``.
.. note:: PAM authentication will not work for the ``root`` user.
The Python interface to PAM does not support authenticating as ``root``.
.. note:: This module executes itself in a subprocess in order to user the system python
and pam libraries. We do this to avoid openssl version conflicts when
running under a salt onedir build.
.. note:: Running ``salt-master`` as a non-root user (the 3006.x packaging
default is the ``salt`` user) and using PAM eauth requires extra
privileges so that PAM's ``unix_chkpwd`` helper can validate other
users' passwords. ``unix_chkpwd`` refuses to authenticate users other
than the caller unless the caller can read ``/etc/shadow``. The two
standard remediations are:
1. **Debian-derived distributions:** add the master's user to the
``shadow`` group (e.g. ``usermod -a -G shadow salt``) so the master
process can read ``/etc/shadow`` indirectly via the setgid-shadow
``unix_chkpwd`` helper.
2. **RPM-based distributions:** revert the master to run as ``root``
(``user: root`` in ``/etc/salt/master``); ``/etc/shadow`` cannot be
made readable to a non-root group safely there.
When PAM auth fails and the master is running as a non-root user
without ``/etc/shadow`` access, a CRITICAL log entry naming the cause
and the two remediations is emitted (once per process). See
https://github.com/saltstack/salt/issues/64275 for the full
discussion.
� N)�CDLL� CFUNCTYPE�POINTER� Structure�c_char�c_char_p�c_int�c_uint�c_void_p�cast�pointer�sizeof)�find_libraryTF�cz Failed to load libc using ctypes)�exc_info� � � � c @ s"