Commit a8ba660761
Verified · cmc
Layout: unified · split
internal/sshd/revoke_test.go +9
| @@ -166,4 +166,13 @@ func TestExpiredKeyRefusedAtAuth(t *testing.T) { | ||
| 166 | 166 | if err == nil { |
| 167 | 167 | t.Fatal("an expired key authenticated") |
| 168 | 168 | } |
| 169 | // Anyone holding only the public key can offer it; each offer | |
| 170 | // counts against the address like an unknown key. | |
| 171 | ip := remoteIP(ts.client.LocalAddr()) | |
| 172 | ts.srv.authLimiter.mu.Lock() | |
| 173 | w := ts.srv.authLimiter.seen[ip] | |
| 174 | ts.srv.authLimiter.mu.Unlock() | |
| 175 | if w == nil || w.count < 1 { | |
| 176 | t.Fatalf("an expired key's attempt from %s did not count against the limiter", ip) | |
| 177 | } | |
| 169 | 178 | } |
internal/sshd/sshd.go +1
| @@ -163,6 +163,7 @@ func (s *Server) authenticate(meta ssh.ConnMetadata, pub ssh.PublicKey) (*ssh.Pe | ||
| 163 | 163 | return nil, fmt.Errorf("unknown key %s", fp) |
| 164 | 164 | } |
| 165 | 165 | if key.Expired(time.Now()) { |
| 166 | s.authLimiter.fail(ip) | |
| 166 | 167 | s.st.Audit(key.UserID, "auth.expired", map[string]any{"ip": ip, "fingerprint": fp}) |
| 167 | 168 | return nil, fmt.Errorf("key %s has expired", fp) |
| 168 | 169 | } |