From 11c0da1f9c5f3567bbf0d4f4a1f2f31880015f1c Mon Sep 17 00:00:00 2001 From: Bandie Date: Tue, 27 Mar 2018 18:45:21 +0200 Subject: [PATCH] Removable media -> (auth|panic) key --- README.md | 6 +++--- man/de/man8/pam_panic.8.gz | Bin 2014 -> 2120 bytes man/man8/pam_panic.8.gz | Bin 1766 -> 1863 bytes src/pam_panic.c | 12 ++++++------ 4 files changed, 9 insertions(+), 9 deletions(-) diff --git a/README.md b/README.md index ed0e90d..1c18371 100644 --- a/README.md +++ b/README.md @@ -5,9 +5,9 @@ The pam\_panic PAM module shall protect people who have value data on their computer. It provides a panic function. ## How it works -There exist a good and a bad flash drive. -The good flash drive will let you pass to the password prompt. -The bad flash drive will execute a reboot, poweroff and/or erase the luksHeader which will make your luksContainer undecryptable to anyone. +There are two removable media which work as keys: One is the auth key and one is the panic key. +The auth key will let you pass to the password prompt. +The panic key will execute a reboot, poweroff and/or erase the luksHeader which will make your luksContainer undecryptable to anyone. ## Installation You need gcc or something similar. diff --git a/man/de/man8/pam_panic.8.gz b/man/de/man8/pam_panic.8.gz index 5de4e833f5c260b045c733de507ced2a5d422048..1db9b1e6fff6a27bf63238d2c70120edf0a19036 100644 GIT binary patch literal 2120 zcmV-O2)FkiiwFov5>-SW#b+eUu8DpN-fNeF&CaX@JI#tx0X`Otn zg}?kW);?F~w2oJQtYf3+n~6^8v%;R!C#MwoOi{fv8Fz1oqdGY?_qs5jw|mf4?6Jp( zckj=d@4jn(_;E9H6Pq&5&uP%Pp#kq+jcn#eMQP{iTl2rgCN1L>^ViC*V#A}g*0@V` ztp8)s>Gv+{R6oP-?&P{m9&C1OsMgYorl!$Ksg*eDe5Gk4{#t9PJUFx&eIu4M|LTwI z@)p2(O4K4Qb5Dx`E_ts_`ie&++QqY6QTDjbl!-Y?wU)^a=Dw89>xG`nEH&bU2gs}c z;!i=jT6kK;Hr0j-lRuu+T5&@8tHN;8>GkRIwm**gV;YS+!|{l^(J-R7uXIeUH3CWc zotvm$+Y+0mP2t(9NJ_x)R9fM-b@!4+ry{-Xt`p#7*6R;SvxjCpW-|(9)6xK zdXq`-s&PFSpJ4bieX{Bc^6luvtSCG_tcwR_i^bwIC#%&(={Bo*;l{>`Xmr^fM!kzk z{~9(92DPi$?ecyfn}^aSO59DJW~mGTk_SCss@$K_Kv`E96`;Xr=5>lE zmIDKX$;~rBQ~D=mTJV%2M>DNF(m-jWc3_I0V1by06s3D*ACyV3@aaKm3CQz!oPyDc z;@r__p5=UuL(F&(2Jv29#B_$27gezE7|wO_){Edfx4%zmlD)-Z>Ha()aHZ_a39=((I*b-XGFD* z?c9RT%&Zq%v~sZZLED57DC~|1@QYm)C$RGgk@8qySOJG5_?gnvhT{{H*f}vMgbudK z20H8$tmJW%s#MJw;jnTW4H9E40c9vPzqC@Bg`BuqY$1Hu2_#KIWGY794#vIPe$)?a zgwLB47~=CYzH^E+l!a=-n;cAoFbzlaeQ=x$1RLU2lV1uj9M5nV4?cQo?518u|0Hnn zir$H7{ONrShC{%_x%q){`0K)ug=9~^D6rIuE|49 z9^)Y%sS7FC**m4-fuf$NPLs&%6?JBS$Y}2g;koNY1VtJ5Zf+ui?9ols>qlbmh{MJB z4I|l*BfAx`*9ooc$m)l8Px)yhfxH(ow_Pyjk0c?MRuU<1R+%VrVAFDiXze(D%4vXX zX3kRMMWUblpCPZykSd=%2nz^z1*tsM%2ZituLGECcZplEPJtl__=Q| zao@uOsB~%y%fWt*=HBjq1;dP`QHuW}&Mc?I-vVQ&gar@+Wl^ELOL_NFii#L`UsRsh zZT+0#Y&PUM4!eG6Pk4gn>_q07#GG=PNaw?j>}sgnE26%tX7nIsFHwIJGVE6);@&B; z+L)?ojctt3u*~eNZC=FlC7K6xVXGMCuzK7VHULLkLEM)VZqZJ5@P#7HX?z#;uR;z- zBkEN3da@Fx+;GbXB0ZJTu)&U1rI02xc_PK!46tNy)1X6RfncQHmOfo^if;GO$HzhqyG*8*dZK=rO1>E}``*HsVjfYaf!cdxySVx(LRp*=9 zC^^PBRQGDDzLwgde(=Ng^3jq?b{NJ^s+sBY_3sW%2FqsuTaTKrFP6kmKdbpeUazr zK(lZy+HMNPRXOY2amfgiE?f$#m;-BvFz^)t)NJN-)SPxjJE6mGTFr9JEiR78x#T~U z)!pHsA0P5H_VU;3&P8+=4aZTyg1>7SO)f8^(WnaN?`3NBVo_ZaQ^gvH^59$h>dUY7 zuKTzAC~rZv=%Yd@wBibSt5kWbf@o89e+g1^BaHf>y#a3KDk9UOLs-}Gs(JRv{V@W?&0{$g@n(KWz2Lw>+l zs3I$Hk+Q-CpeZtVf^MFOJYGVQ?|D5$nhOX>xuZF>)rQJrl|UEBd`_A7Yj@smr`l)b ztObc{U$BR2XZ*&pQ7`I7)R|m%w^zH}br#HQoSmFj--5I_a~eNvpTq1PDLa!fID{DO yb=wtL4!^sos3SoSU*iPx=%<^Z`;Naeb=uT=%JAVOG?s@>ua>d zm2Jin8q0z{;EP5c(B&d!`Ub7t1B=1uaA z4t~qOsrEUa(nhWS*eIiy+XubUXN5hbkB*sq#?nY2_Xc3rYvDeZeDQ?bIS?%I-HA8zmWQbWHZ>+2_)Eo#CoJPYbO{Tr^bVB`T9MS6+I;PQ? zfF#4-Rn%5i}k&+tQ>IgOwTG@G^6p$6&becHTM#39X^E z_JKvK_WRPT0=V^2*fKkd#*@K$e+q8(M>M~CHBZiVhtI$3xMH4+=k%&6TWTKv!%V?c$8AP zp}btV$STM5QNsO%c$=h3cMP_3_>mobRxw+8fU_Qk3Jd4%w2j5107Axk-f|8B#mc$x zUKIjDR^UT8-jdM_6^bQX&MZpBEtEx3qg0RptOtXwNJ5LOHm2s3vdSDw#0TEA&(v~- z2msO=N5JNSZwo7DBbr^{3pPN{2X_U*qir^?N7KReFd9~w1S(tljPdyiSAhXkr5TtP!#8oKnxh*e+qrOrdwKr9wF6d1-TRy#QAhQ}WVhVr9Ce~>Ur34Kx z+LhYD444$k>uGfb2CX&FbyyBBVsWIb*M9**&KHsdcV(k{dWP8t<;ZEyJPc^J(VV+G zd|+~g@Z^-5Z{L0Y!;e4x>!khf-r0HkB6|O(ElX`#lO?o>)4_iVPh(ZcrGUaj^m01z?&xbKyOWkOG*JG&|@!YU8o!zz6HHJ40y%|2RYhv z^^l?hddfMczG@tGLICUaCS)r(w2Ngc^C6Ze?35@HD4F{T>kcD)1eH!rVI|pzXg)Un zcOc9}|3VW?RAzB9Q)4Y4jQSi8z0?;4jJ=51kA2pLNAm8yNQMuRdq!Z>eX#=whl?W zlBotceketaBztRd*EyMHq*(_+l%6idES+CV84EiHUG~c^hNMp14Yf+Q6-cnNi@us8 z1Puqtk{zgi9gbpZ0a@dG`)Fi~)T;HGMT03AVEU~viB3x!w8O>q(J&yhl*oNO$smf| zd?p7}fd~}uL%GZr;Agpe;%gp5*H)4!1M=?18ZA@QU|Fo!g=s4^`7kwwA&;F?C-LG&Nl71RSGLkplAz0%>;&kW_wt7#EitzMLY!I+0u zu!0*Bs(CLKxVBYOSjxCL<*5X@6Y)$X2=8~;gEa;9g@(Yxs%bpq9c3C`oo>5U;J@Hd zU;Qk9DYb*L%a`4J+zCCxXTSU`JKdUgfes%uFLKnmb2uWGX8cgrLw`kr z8ke!$w9bFK?43n7(RdnFSje9PCbRSNXfmnO`FojKoh0>5CS}nlD7Wt%s)xKbxEx-~ z*YFl5cY4ogQZ|Hw2`6Q5xzba*sG3HlCP9Fo?K)!hs`uaNco1#9x%eu2!963zj-p>F z)alk#9q>hO8V$B%emB>P?(44OWofm)?>@do)`v|pWjUr|A^dEIg0DoRzQsT<5XD0o zBwWdKCcz#?&@G+qIx*A5eFq2P_sOHfPVkdH9JCJ9=LQkEC*GgUE^E40ur5#^h!v_R z3S6Y3a23!L8GM6o9tC+kha}(1eu%VOJwVDm&7rNf>I#+vbQPITDf52gPP^Sy`>b4a zAaUI@iIDfsZ#|m~qJBiZ*?E6=gWBIK!OYgl(Q$oI??~mee%yVpo*t00H=BY($kD+Z wT$APT^}41`NP6{`hRQwqc@h5q&oWbm+Z0~X5%aGHcWpWDe`iqhM8y*T04)9J;s5{u diff --git a/man/man8/pam_panic.8.gz b/man/man8/pam_panic.8.gz index b0d78eeecabd990c88f6733fee51c2cff70e8560..4276a692a380042a24eae53d9a17f01f4da1d11f 100644 GIT binary patch literal 1863 zcmV-N2e|kjiwFpmbh=ss18`w&UvOb=X=5%p0PR?7bJ|E2{m!qr#fLRc8AviOk85UX ziLJz{vVlUdv#yYuYETRHAk>PwWy1XWJ-1r|+3TI!+R4YI0)~Fv$GPV|l(S`*Y-fN^ ze$AE5>l}&YdMIVinWK&7q(PDl(nMGYPa&48)KOJSzjj)jM_Vt^~ z{_Ai0Z@+JL?nPdS?27JGUVZ6LNB1;k9rb#1D$-TCmVbWgPUM?PY;Y>bH<>aiFLws> zTk7J%Z`08@yzWx>67Q24UAOr}+Dl8Ffs(Y$dxH%PVnd_PwCst`oq^1}cg^aVGo}Am zUrx#^plB(UiKsG5i7t1-T9t3UqKa42wAW zSTY{n2i?w*=Cte+6Je+03OFDDB-U$b46Su;OPx_=5DqHkPCq)Rb~09CK)))Rk{6Lw zxl4pbMf5P9OrtOYp>C(N+@CFzcSnWGzYUCDCbK1-Rh^eM=%dIoz5jWcgo{OZ)B7-; zpJVwGeJthg$ha3bR$5zpDfC{JI!Qipx|T{;ra8?A8~bj8=z11T=iy`w6Q|S89BF+* zqy>jbVG9+dwopuk)CCszsisssN_rGoB`FqGfE8RDR0-5}MP+3PZz!~U^-;yrka&g_ z_8ZluB!Rcx>*pv#m0G8?*X5Rkp{+caE1KkzlyRjR;i9Ci0$91m?8?0sCKDbx# zCqu>^bcJIGGwAKF7y~^qTf8eQo8NlX2-Q-(lr=+h($+ZUZN4CtFoP1csY)4Nko+Ro zz{OA(F<+O5!Xodhg0gCBf>IbsA302)5T`CHpQrG}=>dA+;lZim)3;K@vLquCnK=gm z^G=GKT^G)=(#OQz&b6hL1h67@xWZkL9~dkA+38ZU1W${JV?^XB0V^9C&hY&i=a{Cw zQhu%!oI^F3Mf7dQnH;QK<4&TVd{vSdm`M>Yp0gKy^9kJq^I&!#jsv=X zaArh|Av-<`oCt>dnBD&~-Zd?Oxg#f+Ehm?Y10-DVuckt#$nMgdOc2Q{n&NJB6=?nFEC?xRZH&id6*sI3AW`hDKUp+qMHH$O|Bmpn5t(YR_uu zRZb_8w7CIr4FV&9RgR$HESvU#`nFS>6iNg%xzeDEcI6F|=X_w(GNT)fuEI8^KJn1m zjjEzHIe?3wL(!7?-@9+p%Eo%1e=PvsgV_jWRVsVn@@F(EBv*Zt>MDy#tWZ`3geEBX z-mn%vEpJYZw3V1XCy$9JpX4D(>KoV7l5LK-NiO&?=ha_!ldbGMoZQ-pEu-0L6f3db zqS4f;>!%s#ZmSiapFH-xfSG?Yp^z3)K;gU|6VN+w;}Lc`!|Ne|L3Ig^L|>L;Z|iygzi2g#xE85s#V+2M@rKr#$U#(FlVlTr=PJUp|A~B;`Gv1@pyh zO#c|&ErQxBemad7*VjQ5)lnJw=Zrnl8Whj%(?ZJU!w=&L|MbUm)Qu9{;yR$$>&jPN zKPlF!SQi+s5xz7Jo{PL6{c}DGgQ!)yo)6tD-;a%u6H6ZbPo~ulz7Ovj$A+0&4POnL zT04CDK+`mURPZRESIjHN&;~lq4+r%m&4Yg1;9+ITq2a5;oyegCpO;S*T;jd?qvZ@v zfPEXE|1E>xEj~1X;7NnME_4Yes}0aZs%m&&ZlvQea@z1rl3H7stKo2i8KqhcPzZ+a zP=}N}*+9pKz968{T{Jn4&!-_D-0EGPU(`=~114+lyW?-a+agc%|0}Jz%EkD_Cp2ac z=qEE>@O*Y4Zy^1&a)1Ahf~-xUEss&L{N?o6#iXgRI(3#3L^fVd=U;AP&fy;t004pX Bn@|7% literal 1766 zcmV?bJ|7}e&<)5;i1NvfO2V5*VA-L zY$eu=4Ge;|9+Sx|Xoa>GT1C4up})T0SxF!}Zl}}wv5bw;Ue4t^-?`wUMVD-6fOme) zluhL+W~f7AyJpr!GadF2x$B{A`^nlkjq9FuR~G zE_|8{N5NT_x+nNOn9+5c_oO|x)EOvAi>x|Le<1 zc?J|MMKTs;YAM#mMp&z|^%JUylo88RQnJevnF$VAXOJcL_I@voRk2#RUFwO57s$#l zc+-^1*wRK6Yn74C(%o@qARNDG_H8xiEwFBHQUq@}G?^Bzx4m)+IpEWf~zL zZn4+av=pmb*twKok*s-R6J^>?A2&f5JN&~c0C2Pk`V^lZM3_m@E9B==6*5BZO+)$? zz(H^%@6<{XA0|AOMn)BdQM6@d>wK=TKBpH>7k_%mSl~h`$Qmti}9~C8`HTz^QTwA$fv7oXGX}tvEx(UiC~QP z3G}Z)c2rpj0FC!FMkCv>H}#%}&TiBowax%s^bm@c%zy5_NlF{( zZT3_Eya$^R%Cb;)$HmfU)YILeDvBkFuz=9G(3{Gz7CtR+4*jW>j8z`)lTY5uJ&?4j z_V)|C+2ba;IYgXG|JlvGrB$(J#-5KUpn2$1Fsr*JIs`a<2l-B6-7^^smzYSAIj$@TJZV=RdhQ_dYSzQu!reZCH#}@dDvq&)h{7)R#XRSJx-P`VaA6@0 zt=w_5SgoCSQv<}IXNwM<+^~i)m*STBqAP^fG6Q7kgKkj^gfalh&akxkvdnDB9Xa46 z)LEY|xei>V1JgDG!_b3S12-YuZ5UHoieb|hYFVfF8hQQUTvkQ}>22Ot~xTY2t^cJ}uEr%7&xa2s7#|klbQw#5!hDhMK2dr+r<*v^) zzARN#Q|kIFi0j$PjaI3leoBwt_grM5z^RMHo#uq+c~HU-$Z@u4grOo_Gk{c2Rpzk) zwTDxGHlL2@m*M5yuf5_gYvKIt%n!plD#L2*-Xa}A@$5k&^7-JyXv~k*aSVz@0d8^r z>J=)IyFjjG*Qr<+2F~rOqz)d6yc+&Cn+AT^Dmf1(eJ8&f4k0I!JP996s~vnFTsDq* zsakr^yrxEa_vibja3_LWxLz`^977xEG|$S6F)Z2Y;3EEsHatrt*5>Ba^VXOx z%H;rsz= 3){ - pam_syslog(pamh, LOG_NOTICE, "Couldn't identify removable media. 3 tries."); + pam_syslog(pamh, LOG_NOTICE, "Couldn't identify any keys. 3 tries."); return (PAM_MAXTRIES); } } - // Allowed removable media? OK! + // Auth key? OK! if(access(allowed, F_OK) != -1) return (PAM_SUCCESS); - // Rejected removable media? PANIC!!1 + // Panic key? PANIC!!1 if(access(rejected, F_OK) != -1){ if(serious){