AuthenticationTests.cs 18 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427
  1. using Renci.SshNet.Common;
  2. using Renci.SshNet.IntegrationTests.Common;
  3. namespace Renci.SshNet.IntegrationTests
  4. {
  5. [TestClass]
  6. public class AuthenticationTests : IntegrationTestBase
  7. {
  8. private AuthenticationMethodFactory _authenticationMethodFactory;
  9. private IConnectionInfoFactory _connectionInfoFactory;
  10. private IConnectionInfoFactory _adminConnectionInfoFactory;
  11. private RemoteSshdConfig _remoteSshdConfig;
  12. [TestInitialize]
  13. public void SetUp()
  14. {
  15. _authenticationMethodFactory = new AuthenticationMethodFactory();
  16. _connectionInfoFactory = new LinuxVMConnectionFactory(SshServerHostName, SshServerPort, _authenticationMethodFactory);
  17. _adminConnectionInfoFactory = new LinuxAdminConnectionFactory(SshServerHostName, SshServerPort);
  18. _remoteSshdConfig = new RemoteSshd(_adminConnectionInfoFactory).OpenConfig();
  19. }
  20. [TestCleanup]
  21. public void TearDown()
  22. {
  23. _remoteSshdConfig?.Reset();
  24. using (var client = new SshClient(_adminConnectionInfoFactory.Create()))
  25. {
  26. client.Connect();
  27. // Reset the password back to the "regular" password.
  28. using (var cmd = client.RunCommand($"echo \"{Users.Regular.Password}\n{Users.Regular.Password}\" | sudo passwd " + Users.Regular.UserName))
  29. {
  30. Assert.AreEqual(0, cmd.ExitStatus, cmd.Error);
  31. }
  32. // Remove password expiration
  33. using (var cmd = client.RunCommand($"sudo chage --expiredate -1 " + Users.Regular.UserName))
  34. {
  35. Assert.AreEqual(0, cmd.ExitStatus, cmd.Error);
  36. }
  37. }
  38. }
  39. [TestMethod]
  40. public void Multifactor_PublicKey()
  41. {
  42. _remoteSshdConfig.WithAuthenticationMethods(Users.Regular.UserName, "publickey")
  43. .Update()
  44. .Restart();
  45. var connectionInfo = _connectionInfoFactory.Create(_authenticationMethodFactory.CreateRegularUserPrivateKeyAuthenticationMethod());
  46. using (var client = new SftpClient(connectionInfo))
  47. {
  48. client.Connect();
  49. }
  50. }
  51. [TestMethod]
  52. [TestCategory("Authentication")]
  53. public void Multifactor_PublicKey_Connect_Then_Reconnect()
  54. {
  55. _remoteSshdConfig.WithAuthenticationMethods(Users.Regular.UserName, "publickey")
  56. .Update()
  57. .Restart();
  58. var connectionInfo = _connectionInfoFactory.Create(_authenticationMethodFactory.CreateRegularUserPrivateKeyAuthenticationMethod());
  59. using (var client = new SftpClient(connectionInfo))
  60. {
  61. client.Connect();
  62. client.Disconnect();
  63. client.Connect();
  64. client.Disconnect();
  65. }
  66. }
  67. [TestMethod]
  68. public void Multifactor_PublicKeyWithPassPhrase()
  69. {
  70. _remoteSshdConfig.WithAuthenticationMethods(Users.Regular.UserName, "publickey")
  71. .Update()
  72. .Restart();
  73. var connectionInfo = _connectionInfoFactory.Create(_authenticationMethodFactory.CreateRegularUserPrivateKeyWithPassPhraseAuthenticationMethod());
  74. using (var client = new SftpClient(connectionInfo))
  75. {
  76. client.Connect();
  77. }
  78. }
  79. [TestMethod]
  80. [ExpectedException(typeof(SshPassPhraseNullOrEmptyException))]
  81. public void Multifactor_PublicKeyWithEmptyPassPhrase()
  82. {
  83. _remoteSshdConfig.WithAuthenticationMethods(Users.Regular.UserName, "publickey")
  84. .Update()
  85. .Restart();
  86. var connectionInfo = _connectionInfoFactory.Create(_authenticationMethodFactory.CreateRegularUserPrivateKeyWithEmptyPassPhraseAuthenticationMethod());
  87. using (var client = new SftpClient(connectionInfo))
  88. {
  89. client.Connect();
  90. }
  91. }
  92. [TestMethod]
  93. public void Multifactor_PublicKey_MultiplePrivateKey()
  94. {
  95. _remoteSshdConfig.WithAuthenticationMethods(Users.Regular.UserName, "publickey")
  96. .Update()
  97. .Restart();
  98. var connectionInfo = _connectionInfoFactory.Create(_authenticationMethodFactory.CreateRegularUserMultiplePrivateKeyAuthenticationMethod());
  99. using (var client = new SftpClient(connectionInfo))
  100. {
  101. client.Connect();
  102. }
  103. }
  104. [TestMethod]
  105. public void Multifactor_PublicKey_MultipleAuthenticationMethod()
  106. {
  107. _remoteSshdConfig.WithAuthenticationMethods(Users.Regular.UserName, "publickey")
  108. .Update()
  109. .Restart();
  110. var connectionInfo = _connectionInfoFactory.Create(_authenticationMethodFactory.CreateRegularUserPrivateKeyAuthenticationMethod(),
  111. _authenticationMethodFactory.CreateRegularUserPrivateKeyAuthenticationMethod());
  112. using (var client = new SftpClient(connectionInfo))
  113. {
  114. client.Connect();
  115. }
  116. }
  117. [TestMethod]
  118. public void Multifactor_KeyboardInteractiveAndPublicKey()
  119. {
  120. _remoteSshdConfig.WithAuthenticationMethods(Users.Regular.UserName, "keyboard-interactive,publickey")
  121. .WithChallengeResponseAuthentication(true)
  122. .WithKeyboardInteractiveAuthentication(true)
  123. .WithUsePAM(true)
  124. .Update()
  125. .Restart();
  126. var connectionInfo = _connectionInfoFactory.Create(_authenticationMethodFactory.CreateRegularUserPasswordAuthenticationMethodWithBadPassword(),
  127. _authenticationMethodFactory.CreateRegularUserKeyboardInteractiveAuthenticationMethod(),
  128. _authenticationMethodFactory.CreateRegularUserPrivateKeyAuthenticationMethod());
  129. using (var client = new SftpClient(connectionInfo))
  130. {
  131. client.Connect();
  132. }
  133. }
  134. [TestMethod]
  135. public void Multifactor_Password_ExceedsPartialSuccessLimit()
  136. {
  137. // configure server to require more successfull authentications from a given method than our partial
  138. // success limit (5) allows
  139. _remoteSshdConfig.WithAuthenticationMethods(Users.Regular.UserName, "password,password,password,password,password,password")
  140. .Update()
  141. .Restart();
  142. var connectionInfo = _connectionInfoFactory.Create(_authenticationMethodFactory.CreateRegulatUserPasswordAuthenticationMethod());
  143. using (var client = new SftpClient(connectionInfo))
  144. {
  145. try
  146. {
  147. client.Connect();
  148. Assert.Fail();
  149. }
  150. catch (SshAuthenticationException ex)
  151. {
  152. Assert.IsNull(ex.InnerException);
  153. Assert.AreEqual("Reached authentication attempt limit for method (password).", ex.Message);
  154. }
  155. }
  156. }
  157. [TestMethod]
  158. public void Multifactor_Password_MatchPartialSuccessLimit()
  159. {
  160. // configure server to require a number of successfull authentications from a given method that exactly
  161. // matches our partial success limit (5)
  162. _remoteSshdConfig.WithAuthenticationMethods(Users.Regular.UserName, "password,password,password,password,password")
  163. .Update()
  164. .Restart();
  165. var connectionInfo = _connectionInfoFactory.Create(_authenticationMethodFactory.CreateRegulatUserPasswordAuthenticationMethod());
  166. using (var client = new SftpClient(connectionInfo))
  167. {
  168. client.Connect();
  169. }
  170. }
  171. [TestMethod]
  172. public void Multifactor_Password_Or_PublicKeyAndKeyboardInteractive()
  173. {
  174. _remoteSshdConfig.WithAuthenticationMethods(Users.Regular.UserName, "password publickey,keyboard-interactive")
  175. .WithChallengeResponseAuthentication(true)
  176. .WithKeyboardInteractiveAuthentication(true)
  177. .WithUsePAM(true)
  178. .Update()
  179. .Restart();
  180. var connectionInfo = _connectionInfoFactory.Create(_authenticationMethodFactory.CreateRegularUserPrivateKeyAuthenticationMethod(),
  181. _authenticationMethodFactory.CreateRegulatUserPasswordAuthenticationMethod());
  182. using (var client = new SftpClient(connectionInfo))
  183. {
  184. client.Connect();
  185. }
  186. }
  187. [TestMethod]
  188. public void Multifactor_Password_Or_PublicKeyAndPassword_BadPassword()
  189. {
  190. _remoteSshdConfig.WithAuthenticationMethods(Users.Regular.UserName, "password publickey,password")
  191. .Update()
  192. .Restart();
  193. var connectionInfo = _connectionInfoFactory.Create(_authenticationMethodFactory.CreateRegularUserPasswordAuthenticationMethodWithBadPassword(),
  194. _authenticationMethodFactory.CreateRegularUserPrivateKeyAuthenticationMethod());
  195. using (var client = new SftpClient(connectionInfo))
  196. {
  197. try
  198. {
  199. client.Connect();
  200. Assert.Fail();
  201. }
  202. catch (SshAuthenticationException ex)
  203. {
  204. Assert.IsNull(ex.InnerException);
  205. Assert.AreEqual("Permission denied (password).", ex.Message);
  206. }
  207. }
  208. }
  209. [TestMethod]
  210. public void Multifactor_PasswordAndPublicKey_Or_PasswordAndPassword()
  211. {
  212. _remoteSshdConfig.WithAuthenticationMethods(Users.Regular.UserName, "password,publickey password,password")
  213. .Update()
  214. .Restart();
  215. var connectionInfo = _connectionInfoFactory.Create(_authenticationMethodFactory.CreateRegulatUserPasswordAuthenticationMethod(),
  216. _authenticationMethodFactory.CreateRegularUserPrivateKeyAuthenticationMethodWithBadKey());
  217. using (var client = new SftpClient(connectionInfo))
  218. {
  219. client.Connect();
  220. }
  221. connectionInfo = _connectionInfoFactory.Create(_authenticationMethodFactory.CreateRegularUserPasswordAuthenticationMethodWithBadPassword(),
  222. _authenticationMethodFactory.CreateRegularUserPrivateKeyAuthenticationMethod());
  223. using (var client = new SftpClient(connectionInfo))
  224. {
  225. try
  226. {
  227. client.Connect();
  228. Assert.Fail();
  229. }
  230. catch (SshAuthenticationException ex)
  231. {
  232. Assert.IsNull(ex.InnerException);
  233. Assert.AreEqual("Permission denied (password).", ex.Message);
  234. }
  235. }
  236. }
  237. [TestMethod]
  238. public void Multifactor_PasswordAndPassword_Or_PublicKey()
  239. {
  240. _remoteSshdConfig.WithAuthenticationMethods(Users.Regular.UserName, "password,password publickey")
  241. .Update()
  242. .Restart();
  243. var connectionInfo = _connectionInfoFactory.Create(_authenticationMethodFactory.CreateRegulatUserPasswordAuthenticationMethod(),
  244. _authenticationMethodFactory.CreateRegularUserPrivateKeyAuthenticationMethodWithBadKey());
  245. using (var client = new SftpClient(connectionInfo))
  246. {
  247. client.Connect();
  248. }
  249. connectionInfo = _connectionInfoFactory.Create(_authenticationMethodFactory.CreateRegulatUserPasswordAuthenticationMethod());
  250. using (var client = new SftpClient(connectionInfo))
  251. {
  252. client.Connect();
  253. }
  254. }
  255. [TestMethod]
  256. public void Multifactor_Password_Or_Password()
  257. {
  258. _remoteSshdConfig.WithAuthenticationMethods(Users.Regular.UserName, "password password")
  259. .Update()
  260. .Restart();
  261. var connectionInfo = _connectionInfoFactory.Create(_authenticationMethodFactory.CreateRegulatUserPasswordAuthenticationMethod());
  262. using (var client = new SftpClient(connectionInfo))
  263. {
  264. client.Connect();
  265. }
  266. connectionInfo = _connectionInfoFactory.Create(_authenticationMethodFactory.CreateRegulatUserPasswordAuthenticationMethod(),
  267. _authenticationMethodFactory.CreateRegularUserPrivateKeyAuthenticationMethodWithBadKey());
  268. using (var client = new SftpClient(connectionInfo))
  269. {
  270. client.Connect();
  271. }
  272. }
  273. [TestMethod]
  274. public void KeyboardInteractive_PasswordExpired()
  275. {
  276. var temporaryPassword = new Random().Next().ToString();
  277. using (var client = new SshClient(_adminConnectionInfoFactory.Create()))
  278. {
  279. client.Connect();
  280. // Temporarity modify password so that when we expire this password, we change reset the password back to
  281. // the "regular" password.
  282. using (var cmd = client.RunCommand($"echo \"{temporaryPassword}\n{temporaryPassword}\" | sudo passwd " + Users.Regular.UserName))
  283. {
  284. Assert.AreEqual(0, cmd.ExitStatus, cmd.Error);
  285. }
  286. // Force the password to expire immediately
  287. using (var cmd = client.RunCommand($"sudo chage -d 0 " + Users.Regular.UserName))
  288. {
  289. Assert.AreEqual(0, cmd.ExitStatus, cmd.Error);
  290. }
  291. }
  292. _remoteSshdConfig.WithAuthenticationMethods(Users.Regular.UserName, "keyboard-interactive")
  293. .WithChallengeResponseAuthentication(true)
  294. .WithKeyboardInteractiveAuthentication(true)
  295. .WithUsePAM(true)
  296. .Update()
  297. .Restart();
  298. var keyboardInteractive = new KeyboardInteractiveAuthenticationMethod(Users.Regular.UserName);
  299. int authenticationPromptCount = 0;
  300. keyboardInteractive.AuthenticationPrompt += (sender, args) =>
  301. {
  302. Console.WriteLine(args.Instruction);
  303. foreach (var authenticationPrompt in args.Prompts)
  304. {
  305. Console.WriteLine(authenticationPrompt.Request);
  306. switch (authenticationPromptCount)
  307. {
  308. case 0:
  309. // Regular password prompt
  310. authenticationPrompt.Response = temporaryPassword;
  311. break;
  312. case 1:
  313. // Password expired, provide current password
  314. authenticationPrompt.Response = temporaryPassword;
  315. break;
  316. case 2:
  317. // Password expired, provide new password
  318. authenticationPrompt.Response = Users.Regular.Password;
  319. break;
  320. case 3:
  321. // Password expired, retype new password
  322. authenticationPrompt.Response = Users.Regular.Password;
  323. break;
  324. }
  325. authenticationPromptCount++;
  326. }
  327. };
  328. var connectionInfo = _connectionInfoFactory.Create(keyboardInteractive);
  329. using (var client = new SftpClient(connectionInfo))
  330. {
  331. client.Connect();
  332. Assert.AreEqual(4, authenticationPromptCount);
  333. }
  334. }
  335. [TestMethod]
  336. public void KeyboardInteractiveConnectionInfo()
  337. {
  338. _remoteSshdConfig.WithAuthenticationMethods(Users.Regular.UserName, "keyboard-interactive")
  339. .WithChallengeResponseAuthentication(true)
  340. .WithKeyboardInteractiveAuthentication(true)
  341. .WithUsePAM(true)
  342. .Update()
  343. .Restart();
  344. var host = SshServerHostName;
  345. var port = SshServerPort;
  346. var username = User.UserName;
  347. var password = User.Password;
  348. #region Example KeyboardInteractiveConnectionInfo AuthenticationPrompt
  349. var connectionInfo = new KeyboardInteractiveConnectionInfo(host, port, username);
  350. connectionInfo.AuthenticationPrompt += delegate (object sender, AuthenticationPromptEventArgs e)
  351. {
  352. Console.WriteLine(e.Instruction);
  353. foreach (var prompt in e.Prompts)
  354. {
  355. Console.WriteLine(prompt.Request);
  356. prompt.Response = password;
  357. }
  358. };
  359. using (var client = new SftpClient(connectionInfo))
  360. {
  361. client.Connect();
  362. // Do something here
  363. client.Disconnect();
  364. }
  365. #endregion
  366. Assert.AreEqual(connectionInfo.Host, SshServerHostName);
  367. Assert.AreEqual(connectionInfo.Username, User.UserName);
  368. }
  369. }
  370. }