xauth-pam: Make trimming of email addresses optional

Fixes #430.
This commit is contained in:
Tobias Brunner
2013-10-04 10:49:54 +02:00
parent d2e4dd75b7
commit 3e3db3743e
2 changed files with 13 additions and 4 deletions
+4
View File
@@ -757,6 +757,10 @@ EAP plugin to be used as backend for XAuth credential verification
.TP
.BR charon.plugins.xauth-pam.pam_service " [login]"
PAM service to be used for authentication
.TP
.BR charon.plugins.xauth-pam.trim_email " [yes]"
If an email address is given as an XAuth username, trim it to just the
username part.
.SS libstrongswan section
.TP
.BR libstrongswan.cert_cache " [yes]"
+9 -4
View File
@@ -134,12 +134,17 @@ METHOD(xauth_method_t, process, status_t,
switch (attr->get_type(attr))
{
case XAUTH_USER_NAME:
/* trim to username part if email address given */
chunk = attr->get_chunk(attr);
pos = memchr(chunk.ptr, '@', chunk.len);
if (pos)
/* trim to username part if email address given */
if (lib->settings->get_bool(lib->settings,
"%s.plugins.xauth-pam.trim_email",
TRUE, charon->name))
{
chunk.len = (u_char*)pos - chunk.ptr;
pos = memchr(chunk.ptr, '@', chunk.len);
if (pos)
{
chunk.len = (u_char*)pos - chunk.ptr;
}
}
attr2string(user, sizeof(user), chunk);
break;