Commit a8ba660761
Verified · cmc
Layout: unified · split
internal/sshd/revoke_test.go +9
| @@ -166,4 +166,13 @@ func TestExpiredKeyRefusedAtAuth(t *testing.T) { | |||
| 166 | if err == nil { | 166 | if err == nil { |
| 167 | t.Fatal("an expired key authenticated") | 167 | t.Fatal("an expired key authenticated") |
| 168 | } | 168 | } |
| 169 | // Anyone holding only the public key can offer it; each offer | ||
| 170 | // counts against the address like an unknown key. | ||
| 171 | ip := remoteIP(ts.client.LocalAddr()) | ||
| 172 | ts.srv.authLimiter.mu.Lock() | ||
| 173 | w := ts.srv.authLimiter.seen[ip] | ||
| 174 | ts.srv.authLimiter.mu.Unlock() | ||
| 175 | if w == nil || w.count < 1 { | ||
| 176 | t.Fatalf("an expired key's attempt from %s did not count against the limiter", ip) | ||
| 177 | } | ||
| 169 | } | 178 | } |
internal/sshd/sshd.go +1
| @@ -163,6 +163,7 @@ func (s *Server) authenticate(meta ssh.ConnMetadata, pub ssh.PublicKey) (*ssh.Pe | |||
| 163 | return nil, fmt.Errorf("unknown key %s", fp) | 163 | return nil, fmt.Errorf("unknown key %s", fp) |
| 164 | } | 164 | } |
| 165 | if key.Expired(time.Now()) { | 165 | if key.Expired(time.Now()) { |
| 166 | s.authLimiter.fail(ip) | ||
| 166 | s.st.Audit(key.UserID, "auth.expired", map[string]any{"ip": ip, "fingerprint": fp}) | 167 | s.st.Audit(key.UserID, "auth.expired", map[string]any{"ip": ip, "fingerprint": fp}) |
| 167 | return nil, fmt.Errorf("key %s has expired", fp) | 168 | return nil, fmt.Errorf("key %s has expired", fp) |
| 168 | } | 169 | } |