YoushouldhavereceivedacopyoftheGNUGeneralPublicLicense alongwiththisprogram;ifnot,writetotheFreeSoftware
Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1335 USA */
if (vio->write_packet(vio, &perform_full_authentication, 1)) return CR_ERROR;
if ((pkt_len= vio->read_packet(vio, &pkt)) <= 0) return CR_ERROR;
vio->info(vio, &vio_info); /* secure transport, as in MySQL. SSL is "secure" even if not verified */ if (vio_info.protocol == MYSQL_VIO_TCP && !vio_info.tls)
{ if (!private_key || !public_key_len)
{
my_printf_error(1, SELF ": Authentication requires either RSA keys " "or secure transport", ME_ERROR_LOG_ONLY); return CR_AUTH_PLUGIN_ERROR;
}
if (pkt_len == 1 && *pkt == request_public_key)
{ if (vio->write_packet(vio, (unsignedchar *)public_key,
(int)public_key_len)) return CR_ERROR; if ((pkt_len= vio->read_packet(vio, &pkt)) <= 0) return CR_ERROR;
}
if (ssl_decrypt(private_key, pkt, pkt_len, plain_text, &plain_text_len)) return CR_ERROR;
for (size_t i=0; i < plain_text_len; i++)
plain_text[i]^= scramble[i % SCRAMBLE_LENGTH];
pkt= plain_text;
pkt_len= (int)plain_text_len; if (pkt_len <= 0 || pkt[pkt_len-1]) return CR_ERROR;
} /* now pkt contains plaintext password */
authstr= (struct digest*)info->auth_string;
sha256_crypt_r(pkt, pkt_len-1, authstr->salt, sizeof(authstr->salt),
to, authstr->iterations);
if (memcmp(to, authstr->crypted, SHA256CRYPT_LEN)) return CR_AUTH_USER_CREDENTIALS; return CR_OK;
}
static MYSQL_SYSVAR_STR(private_key_path, private_key_path, PLUGIN_VAR_READONLY, "A path to the private RSA key used for authentication",
NULL, NULL, "private_key.pem");
static MYSQL_SYSVAR_STR(public_key_path, public_key_path, PLUGIN_VAR_READONLY, "A path to the public RSA key used for authentication",
NULL, NULL, "public_key.pem");
static MYSQL_SYSVAR_BOOL(auto_generate_rsa_keys, auto_generate_keys,
PLUGIN_VAR_READONLY | PLUGIN_VAR_OPCMDARG, "Auto generate RSA keys at server startup if key paths " "are not explicitly set and key files are not present " "at their default locations", NULL, NULL, 1);
static MYSQL_SYSVAR_UINT(digest_rounds, digest_rounds, PLUGIN_VAR_READONLY, "Number of SHA2 rounds to be performed when computing a password hash",
NULL, NULL, 5000, 5000, 0xfff * ITERATION_MULTIPLIER, 1);
Die Informationen auf dieser Webseite wurden
nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit,
noch Qualität der bereit gestellten Informationen zugesichert.
Bemerkung:
Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.