[openssh-commits] [openssh] 01/02: upstream: handle max-pk-ok path identically when the incoming user
git+noreply at mindrot.org
git+noreply at mindrot.org
Thu Oct 1 13:23:25 AEST 2026
This is an automated email from the git hooks/post-receive script.
djm pushed a commit to branch master
in repository openssh.
commit 39cba820eda49ea084c9270917dfb5efc03f08cc
Author: djm at openbsd.org <djm at openbsd.org>
AuthorDate: Thu Oct 1 02:01:51 2026 +0000
upstream: handle max-pk-ok path identically when the incoming user
is invalid; avoids max-pk-ok feature presenting a username validity oracle
analysis and patch from Chris Rohlf in collaboration with Claude and
Anthropic Research
OpenBSD-Commit-ID: c05d01b1724c76c9e30ed5e0f06686820f94bce8
---
auth2-pubkey.c | 14 ++++++++------
1 file changed, 8 insertions(+), 6 deletions(-)
diff --git a/auth2-pubkey.c b/auth2-pubkey.c
index 0e914116b..1a4afd473 100644
--- a/auth2-pubkey.c
+++ b/auth2-pubkey.c
@@ -1,4 +1,4 @@
-/* $OpenBSD: auth2-pubkey.c,v 1.130 2026/09/16 07:47:29 jsg Exp $ */
+/* $OpenBSD: auth2-pubkey.c,v 1.131 2026/10/01 02:01:51 djm Exp $ */
/*
* Copyright (c) 2000 Markus Friedl. All rights reserved.
* Copyright (c) 2010 Damien Miller. All rights reserved.
@@ -292,10 +292,6 @@ userauth_pubkey(struct ssh *ssh, const char *method)
if ((r = sshpkt_get_end(ssh)) != 0)
fatal_fr(r, "parse packet");
- if (!authctxt->valid || authctxt->user == NULL) {
- debug2_f("disabled because of invalid user");
- goto done;
- }
/* XXX fake reply and always send PK_OK ? */
/*
* XXX this allows testing whether a user is allowed
@@ -304,7 +300,8 @@ userauth_pubkey(struct ssh *ssh, const char *method)
* if a user is not allowed to login. is this an
* issue? -markus
*/
- if (mm_user_key_allowed(ssh, pw, key, 0, NULL)) {
+ if (authctxt->valid && authctxt->user != NULL &&
+ mm_user_key_allowed(ssh, pw, key, 0, NULL)) {
if ((r = sshpkt_start(ssh, SSH2_MSG_USERAUTH_PK_OK))
!= 0 ||
(r = sshpkt_put_cstring(ssh, pkalg)) != 0 ||
@@ -314,6 +311,11 @@ userauth_pubkey(struct ssh *ssh, const char *method)
fatal_fr(r, "send packet");
authctxt->postponed = 1;
} else {
+ /*
+ * NB. invalid users must be accounted for in exactly
+ * the same way as valid users whose key was refused,
+ * otherwise MaxAuthTries becomes a username oracle.
+ */
/*
* Don't count this as an authentication failure
* unless we have already used up the separate
--
To stop receiving notification emails like this one, please contact
djm at mindrot.org.
More information about the openssh-commits
mailing list