AuthenticationTests.cs 19 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444
  1. using Renci.SshNet.Common;
  2. using Renci.SshNet.IntegrationTests.Common;
  3. namespace Renci.SshNet.IntegrationTests
  4. {
  5. [TestClass]
  6. public class AuthenticationTests : IntegrationTestBase
  7. {
  8. private AuthenticationMethodFactory _authenticationMethodFactory;
  9. private IConnectionInfoFactory _connectionInfoFactory;
  10. private IConnectionInfoFactory _adminConnectionInfoFactory;
  11. private RemoteSshdConfig _remoteSshdConfig;
  12. [TestInitialize]
  13. public void SetUp()
  14. {
  15. _authenticationMethodFactory = new AuthenticationMethodFactory();
  16. _connectionInfoFactory = new LinuxVMConnectionFactory(SshServerHostName, SshServerPort, _authenticationMethodFactory);
  17. _adminConnectionInfoFactory = new LinuxAdminConnectionFactory(SshServerHostName, SshServerPort);
  18. _remoteSshdConfig = new RemoteSshd(_adminConnectionInfoFactory).OpenConfig();
  19. }
  20. [TestCleanup]
  21. public void TearDown()
  22. {
  23. _remoteSshdConfig?.Reset();
  24. using (var client = new SshClient(_adminConnectionInfoFactory.Create()))
  25. {
  26. client.Connect();
  27. // Reset the password back to the "regular" password.
  28. using (var cmd = client.RunCommand($"echo \"{Users.Regular.Password}\n{Users.Regular.Password}\" | sudo passwd " + Users.Regular.UserName))
  29. {
  30. Assert.AreEqual(0, cmd.ExitStatus, cmd.Error);
  31. }
  32. // Remove password expiration
  33. using (var cmd = client.RunCommand($"sudo chage --expiredate -1 " + Users.Regular.UserName))
  34. {
  35. Assert.AreEqual(0, cmd.ExitStatus, cmd.Error);
  36. }
  37. }
  38. }
  39. [TestMethod]
  40. public void Multifactor_PublicKey()
  41. {
  42. _remoteSshdConfig.WithAuthenticationMethods(Users.Regular.UserName, "publickey")
  43. .Update()
  44. .Restart();
  45. var connectionInfo = _connectionInfoFactory.Create(_authenticationMethodFactory.CreateRegularUserPrivateKeyAuthenticationMethod());
  46. using (var client = new SftpClient(connectionInfo))
  47. {
  48. client.Connect();
  49. }
  50. }
  51. [TestMethod]
  52. [TestCategory("Authentication")]
  53. public void Multifactor_PublicKey_Connect_Then_Reconnect()
  54. {
  55. _remoteSshdConfig.WithAuthenticationMethods(Users.Regular.UserName, "publickey")
  56. .Update()
  57. .Restart();
  58. var connectionInfo = _connectionInfoFactory.Create(_authenticationMethodFactory.CreateRegularUserPrivateKeyAuthenticationMethod());
  59. using (var client = new SftpClient(connectionInfo))
  60. {
  61. client.Connect();
  62. client.Disconnect();
  63. client.Connect();
  64. client.Disconnect();
  65. }
  66. }
  67. [TestMethod]
  68. public void Multifactor_PublicKeyWithPassPhrase()
  69. {
  70. _remoteSshdConfig.WithAuthenticationMethods(Users.Regular.UserName, "publickey")
  71. .Update()
  72. .Restart();
  73. var connectionInfo = _connectionInfoFactory.Create(_authenticationMethodFactory.CreateRegularUserPrivateKeyWithPassPhraseAuthenticationMethod());
  74. using (var client = new SftpClient(connectionInfo))
  75. {
  76. client.Connect();
  77. }
  78. }
  79. [TestMethod]
  80. public void Multifactor_PublicKey_MultiplePrivateKey()
  81. {
  82. _remoteSshdConfig.WithAuthenticationMethods(Users.Regular.UserName, "publickey")
  83. .Update()
  84. .Restart();
  85. var connectionInfo = _connectionInfoFactory.Create(_authenticationMethodFactory.CreateRegularUserMultiplePrivateKeyAuthenticationMethod());
  86. using (var client = new SftpClient(connectionInfo))
  87. {
  88. client.Connect();
  89. }
  90. }
  91. [TestMethod]
  92. public void Multifactor_PublicKey_MultipleAuthenticationMethod()
  93. {
  94. _remoteSshdConfig.WithAuthenticationMethods(Users.Regular.UserName, "publickey")
  95. .Update()
  96. .Restart();
  97. var connectionInfo = _connectionInfoFactory.Create(_authenticationMethodFactory.CreateRegularUserPrivateKeyAuthenticationMethod(),
  98. _authenticationMethodFactory.CreateRegularUserPrivateKeyAuthenticationMethod());
  99. using (var client = new SftpClient(connectionInfo))
  100. {
  101. client.Connect();
  102. }
  103. }
  104. [TestMethod]
  105. public void Multifactor_KeyboardInteractiveAndPublicKey()
  106. {
  107. _remoteSshdConfig.WithAuthenticationMethods(Users.Regular.UserName, "keyboard-interactive,publickey")
  108. .WithChallengeResponseAuthentication(true)
  109. .WithKeyboardInteractiveAuthentication(true)
  110. .WithUsePAM(true)
  111. .Update()
  112. .Restart();
  113. var connectionInfo = _connectionInfoFactory.Create(_authenticationMethodFactory.CreateRegularUserPasswordAuthenticationMethodWithBadPassword(),
  114. _authenticationMethodFactory.CreateRegularUserKeyboardInteractiveAuthenticationMethod(),
  115. _authenticationMethodFactory.CreateRegularUserPrivateKeyAuthenticationMethod());
  116. using (var client = new SftpClient(connectionInfo))
  117. {
  118. client.Connect();
  119. }
  120. }
  121. [TestMethod]
  122. public void Multifactor_Password_ExceedsPartialSuccessLimit()
  123. {
  124. // configure server to require more successfull authentications from a given method than our partial
  125. // success limit (5) allows
  126. _remoteSshdConfig.WithAuthenticationMethods(Users.Regular.UserName, "password,password,password,password,password,password")
  127. .Update()
  128. .Restart();
  129. var connectionInfo = _connectionInfoFactory.Create(_authenticationMethodFactory.CreateRegularUserPasswordAuthenticationMethod());
  130. using (var client = new SftpClient(connectionInfo))
  131. {
  132. try
  133. {
  134. client.Connect();
  135. Assert.Fail();
  136. }
  137. catch (SshAuthenticationException ex)
  138. {
  139. Assert.IsNull(ex.InnerException);
  140. Assert.AreEqual("Reached authentication attempt limit for method (password).", ex.Message);
  141. }
  142. }
  143. }
  144. [TestMethod]
  145. public void Multifactor_Password_MatchPartialSuccessLimit()
  146. {
  147. // configure server to require a number of successfull authentications from a given method that exactly
  148. // matches our partial success limit (5)
  149. _remoteSshdConfig.WithAuthenticationMethods(Users.Regular.UserName, "password,password,password,password,password")
  150. .Update()
  151. .Restart();
  152. var connectionInfo = _connectionInfoFactory.Create(_authenticationMethodFactory.CreateRegularUserPasswordAuthenticationMethod());
  153. using (var client = new SftpClient(connectionInfo))
  154. {
  155. client.Connect();
  156. }
  157. }
  158. [TestMethod]
  159. public void Multifactor_Password_Or_PublicKeyAndKeyboardInteractive()
  160. {
  161. _remoteSshdConfig.WithAuthenticationMethods(Users.Regular.UserName, "password publickey,keyboard-interactive")
  162. .WithChallengeResponseAuthentication(true)
  163. .WithKeyboardInteractiveAuthentication(true)
  164. .WithUsePAM(true)
  165. .Update()
  166. .Restart();
  167. var connectionInfo = _connectionInfoFactory.Create(_authenticationMethodFactory.CreateRegularUserPrivateKeyAuthenticationMethod(),
  168. _authenticationMethodFactory.CreateRegularUserPasswordAuthenticationMethod());
  169. using (var client = new SftpClient(connectionInfo))
  170. {
  171. client.Connect();
  172. }
  173. }
  174. [TestMethod]
  175. public void Multifactor_Password_Or_PublicKeyAndPassword_BadPassword()
  176. {
  177. _remoteSshdConfig.WithAuthenticationMethods(Users.Regular.UserName, "password publickey,password")
  178. .Update()
  179. .Restart();
  180. var connectionInfo = _connectionInfoFactory.Create(_authenticationMethodFactory.CreateRegularUserPasswordAuthenticationMethodWithBadPassword(),
  181. _authenticationMethodFactory.CreateRegularUserPrivateKeyAuthenticationMethod());
  182. using (var client = new SftpClient(connectionInfo))
  183. {
  184. try
  185. {
  186. client.Connect();
  187. Assert.Fail();
  188. }
  189. catch (SshAuthenticationException ex)
  190. {
  191. Assert.IsNull(ex.InnerException);
  192. Assert.AreEqual("Permission denied (password).", ex.Message);
  193. }
  194. }
  195. }
  196. [TestMethod]
  197. public void Multifactor_PasswordAndPublicKey_Or_PasswordAndPassword()
  198. {
  199. _remoteSshdConfig.WithAuthenticationMethods(Users.Regular.UserName, "password,publickey password,password")
  200. .Update()
  201. .Restart();
  202. var connectionInfo = _connectionInfoFactory.Create(_authenticationMethodFactory.CreateRegularUserPasswordAuthenticationMethod(),
  203. _authenticationMethodFactory.CreateRegularUserPrivateKeyAuthenticationMethodWithBadKey());
  204. using (var client = new SftpClient(connectionInfo))
  205. {
  206. client.Connect();
  207. }
  208. connectionInfo = _connectionInfoFactory.Create(_authenticationMethodFactory.CreateRegularUserPasswordAuthenticationMethodWithBadPassword(),
  209. _authenticationMethodFactory.CreateRegularUserPrivateKeyAuthenticationMethod());
  210. using (var client = new SftpClient(connectionInfo))
  211. {
  212. try
  213. {
  214. client.Connect();
  215. Assert.Fail();
  216. }
  217. catch (SshAuthenticationException ex)
  218. {
  219. Assert.IsNull(ex.InnerException);
  220. Assert.AreEqual("Permission denied (password).", ex.Message);
  221. }
  222. }
  223. }
  224. [TestMethod]
  225. public void Multifactor_PasswordAndPassword_Or_PublicKey()
  226. {
  227. _remoteSshdConfig.WithAuthenticationMethods(Users.Regular.UserName, "password,password publickey")
  228. .Update()
  229. .Restart();
  230. var connectionInfo = _connectionInfoFactory.Create(_authenticationMethodFactory.CreateRegularUserPasswordAuthenticationMethod(),
  231. _authenticationMethodFactory.CreateRegularUserPrivateKeyAuthenticationMethodWithBadKey());
  232. using (var client = new SftpClient(connectionInfo))
  233. {
  234. client.Connect();
  235. }
  236. connectionInfo = _connectionInfoFactory.Create(_authenticationMethodFactory.CreateRegularUserPasswordAuthenticationMethod());
  237. using (var client = new SftpClient(connectionInfo))
  238. {
  239. client.Connect();
  240. }
  241. }
  242. [TestMethod]
  243. public void Multifactor_Password_Or_Password()
  244. {
  245. _remoteSshdConfig.WithAuthenticationMethods(Users.Regular.UserName, "password password")
  246. .Update()
  247. .Restart();
  248. var connectionInfo = _connectionInfoFactory.Create(_authenticationMethodFactory.CreateRegularUserPasswordAuthenticationMethod());
  249. using (var client = new SftpClient(connectionInfo))
  250. {
  251. client.Connect();
  252. }
  253. connectionInfo = _connectionInfoFactory.Create(_authenticationMethodFactory.CreateRegularUserPasswordAuthenticationMethod(),
  254. _authenticationMethodFactory.CreateRegularUserPrivateKeyAuthenticationMethodWithBadKey());
  255. using (var client = new SftpClient(connectionInfo))
  256. {
  257. client.Connect();
  258. }
  259. }
  260. [TestMethod]
  261. public void KeyboardInteractive_PasswordExpired()
  262. {
  263. var temporaryPassword = new Random().Next().ToString();
  264. using (var client = new SshClient(_adminConnectionInfoFactory.Create()))
  265. {
  266. client.Connect();
  267. // Temporarity modify password so that when we expire this password, we change reset the password back to
  268. // the "regular" password.
  269. using (var cmd = client.RunCommand($"echo \"{temporaryPassword}\n{temporaryPassword}\" | sudo passwd " + Users.Regular.UserName))
  270. {
  271. Assert.AreEqual(0, cmd.ExitStatus, cmd.Error);
  272. }
  273. // Force the password to expire immediately
  274. using (var cmd = client.RunCommand($"sudo chage -d 0 " + Users.Regular.UserName))
  275. {
  276. Assert.AreEqual(0, cmd.ExitStatus, cmd.Error);
  277. }
  278. }
  279. _remoteSshdConfig.WithAuthenticationMethods(Users.Regular.UserName, "keyboard-interactive")
  280. .WithChallengeResponseAuthentication(true)
  281. .WithKeyboardInteractiveAuthentication(true)
  282. .WithUsePAM(true)
  283. .Update()
  284. .Restart();
  285. var keyboardInteractive = new KeyboardInteractiveAuthenticationMethod(Users.Regular.UserName);
  286. int authenticationPromptCount = 0;
  287. keyboardInteractive.AuthenticationPrompt += (sender, args) =>
  288. {
  289. Console.WriteLine(args.Instruction);
  290. foreach (var authenticationPrompt in args.Prompts)
  291. {
  292. Console.WriteLine(authenticationPrompt.Request);
  293. switch (authenticationPromptCount)
  294. {
  295. case 0:
  296. // Regular password prompt
  297. authenticationPrompt.Response = temporaryPassword;
  298. break;
  299. case 1:
  300. // Password expired, provide current password
  301. authenticationPrompt.Response = temporaryPassword;
  302. break;
  303. case 2:
  304. // Password expired, provide new password
  305. authenticationPrompt.Response = Users.Regular.Password;
  306. break;
  307. case 3:
  308. // Password expired, retype new password
  309. authenticationPrompt.Response = Users.Regular.Password;
  310. break;
  311. default:
  312. break;
  313. }
  314. authenticationPromptCount++;
  315. }
  316. };
  317. var connectionInfo = _connectionInfoFactory.Create(keyboardInteractive);
  318. using (var client = new SftpClient(connectionInfo))
  319. {
  320. client.Connect();
  321. Assert.AreEqual(4, authenticationPromptCount);
  322. }
  323. }
  324. [TestMethod]
  325. public void KeyboardInteractiveConnectionInfo()
  326. {
  327. _remoteSshdConfig.WithAuthenticationMethods(Users.Regular.UserName, "keyboard-interactive")
  328. .WithChallengeResponseAuthentication(true)
  329. .WithKeyboardInteractiveAuthentication(true)
  330. .WithUsePAM(true)
  331. .Update()
  332. .Restart();
  333. var host = SshServerHostName;
  334. var port = SshServerPort;
  335. var username = User.UserName;
  336. var password = User.Password;
  337. #region Example KeyboardInteractiveConnectionInfo AuthenticationPrompt
  338. var connectionInfo = new KeyboardInteractiveConnectionInfo(host, port, username);
  339. connectionInfo.AuthenticationPrompt += delegate (object sender, AuthenticationPromptEventArgs e)
  340. {
  341. Console.WriteLine(e.Instruction);
  342. foreach (var prompt in e.Prompts)
  343. {
  344. Console.WriteLine(prompt.Request);
  345. prompt.Response = password;
  346. }
  347. };
  348. using (var client = new SftpClient(connectionInfo))
  349. {
  350. client.Connect();
  351. // Do something here
  352. client.Disconnect();
  353. }
  354. #endregion
  355. Assert.AreEqual(connectionInfo.Host, SshServerHostName);
  356. Assert.AreEqual(connectionInfo.Username, User.UserName);
  357. }
  358. [TestMethod]
  359. public void KeyboardInteractive_NoResponseSet_ThrowsSshAuthenticationException()
  360. {
  361. // ...instead of a cryptic ArgumentNullException
  362. // https://github.com/sshnet/SSH.NET/issues/382
  363. _remoteSshdConfig.WithAuthenticationMethods(Users.Regular.UserName, "keyboard-interactive")
  364. .WithChallengeResponseAuthentication(true)
  365. .WithKeyboardInteractiveAuthentication(true)
  366. .WithUsePAM(true)
  367. .Update()
  368. .Restart();
  369. var connectionInfo = _connectionInfoFactory.Create(new KeyboardInteractiveAuthenticationMethod(Users.Regular.UserName));
  370. using (var client = new SftpClient(connectionInfo))
  371. {
  372. try
  373. {
  374. client.Connect();
  375. Assert.Fail();
  376. }
  377. catch (SshAuthenticationException ex)
  378. {
  379. Assert.IsNull(ex.InnerException);
  380. Assert.IsTrue(ex.Message.StartsWith("AuthenticationPrompt.Response is null for prompt \"Password: \""), $"Message was \"{ex.Message}\"");
  381. }
  382. }
  383. }
  384. }
  385. }