<feed xmlns='http://www.w3.org/2005/Atom'>
<title>BMC/Intel-BMC/provingground.git/virtual-media/src/utils.hpp, branch master</title>
<subtitle>Intel BMC provingground (mirror)</subtitle>
<id>https://git.radix-linux.su/BMC/Intel-BMC/provingground.git/atom?h=master</id>
<link rel='self' href='https://git.radix-linux.su/BMC/Intel-BMC/provingground.git/atom?h=master'/>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/Intel-BMC/provingground.git/'/>
<updated>2020-02-06T09:10:36+00:00</updated>
<entry>
<title>Authentication support for Legacy mode</title>
<updated>2020-02-06T09:10:36+00:00</updated>
<author>
<name>Agata Olender</name>
<email>agata.olender@intel.com</email>
</author>
<published>2020-01-13T16:51:24+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/Intel-BMC/provingground.git/commit/?id=c33ba00b914c267d14f395a1127aca5dda17fee2'/>
<id>urn:sha1:c33ba00b914c267d14f395a1127aca5dda17fee2</id>
<content type='text'>
This change introduces new 'Mount' API argument - UNIX_FD for named pipe.
This named pipe is utilized to securely send secret data over D-Bus.
Currently data consists of null-terminated char buffers with username and
password.

Data on receiving side is encapsulated into classes whose role is to:
- keep secret as short-lived as possible
- erase secret from memory when it's not needed
- pass secrets (and format them) to another secure container with above
  capabilities

New classes:
- Credentials: is a class encapsulating login and password. It zeroes them
  at destruction.
- CredentialProvider: contains Credentials, specifies SecureBuffer, allows
  to store credentials in SecureBuffer
- SecureBuffer: char vector which zeroes itself at destruction,
  used to provision secret data
- VolatileFile: class creating temporary file with 'owner-only' permissions
  in /tmp; at destruction overwrites it's contents with '*' and removes it

New behavior:
- when UNIX_FD is provided over D-Bus it's treated as open unix pipe. Data
  is read from this pipe and stored securely into CredentialsProvider
- credentials are stored in applications inside CredentialsProvider object,
  encapsulated by unique_ptr for as long as it's needed
- strings containing secrets are zeroed immediately after use
- VolatileFile is used to securely pass credentials to nbdkit curl plugin
  instead of command line parameters.

Tested:
Manual and automated tests on WilsonCity platform:
- positive and negative tests for authentication on both CIFS and HTTPS
  resources
- error injection (ill-formed data transfered over pipe, pipe broken etc.)

Change-Id: I608ae0380b8ad57110bc0939f71eb48604e7dc99
Signed-off-by: Adrian Ambrożewicz &lt;adrian.ambrozewicz@linux.intel.com&gt;
Signed-off-by: Agata Olender &lt;agata.olender@intel.com&gt;
</content>
</entry>
</feed>
