Commit a8ba660761

a8ba660761cb99e71d7357d894c98f436f891c12

parent: 32a5f76e5b

Verified · cmc

cmc <hello@cleberg.net> · 2026-09-28 08:17 UTC

sshd: an expired key counts against the auth limiter

Ref #277

Layout: unified · split

internal/sshd/revoke_test.go +9
@@ -166,4 +166,13 @@ func TestExpiredKeyRefusedAtAuth(t *testing.T) {
166166 if err == nil {
167167 t.Fatal("an expired key authenticated")
168168 }
169 // Anyone holding only the public key can offer it; each offer
170 // counts against the address like an unknown key.
171 ip := remoteIP(ts.client.LocalAddr())
172 ts.srv.authLimiter.mu.Lock()
173 w := ts.srv.authLimiter.seen[ip]
174 ts.srv.authLimiter.mu.Unlock()
175 if w == nil || w.count < 1 {
176 t.Fatalf("an expired key's attempt from %s did not count against the limiter", ip)
177 }
169178}
internal/sshd/sshd.go +1
@@ -163,6 +163,7 @@ func (s *Server) authenticate(meta ssh.ConnMetadata, pub ssh.PublicKey) (*ssh.Pe
163163 return nil, fmt.Errorf("unknown key %s", fp)
164164 }
165165 if key.Expired(time.Now()) {
166 s.authLimiter.fail(ip)
166167 s.st.Audit(key.UserID, "auth.expired", map[string]any{"ip": ip, "fingerprint": fp})
167168 return nil, fmt.Errorf("key %s has expired", fp)
168169 }