Blame SOURCES/enforce-smartcard-at-unlock.patch

12ec7d
From 59b6d50061f3c8e5858230a881267014e8395594 Mon Sep 17 00:00:00 2001
12ec7d
From: Ray Strode <rstrode@redhat.com>
12ec7d
Date: Mon, 28 Sep 2015 10:57:02 -0400
12ec7d
Subject: [PATCH 1/3] smartcardManager: add way to detect if user logged using
12ec7d
 (any) token
12ec7d
12ec7d
If a user uses a token at login time, we need to make sure they continue
12ec7d
to use the token at unlock time.
12ec7d
12ec7d
As a prerequisite for addressing that problem we need to know up front
12ec7d
if a user logged in with a token at all.
12ec7d
12ec7d
This commit adds the necessary api to detect that case.
12ec7d
---
12ec7d
 js/misc/smartcardManager.js | 7 +++++++
12ec7d
 1 file changed, 7 insertions(+)
12ec7d
12ec7d
diff --git a/js/misc/smartcardManager.js b/js/misc/smartcardManager.js
12ec7d
index 4388f286d..75e9836e9 100644
12ec7d
--- a/js/misc/smartcardManager.js
12ec7d
+++ b/js/misc/smartcardManager.js
12ec7d
@@ -113,6 +113,13 @@ var SmartcardManager = new Lang.Class({
12ec7d
             return false;
12ec7d
 
12ec7d
         return true;
12ec7d
+    },
12ec7d
+
12ec7d
+    loggedInWithToken: function() {
12ec7d
+        if (this._loginToken)
12ec7d
+            return true;
12ec7d
+
12ec7d
+        return false;
12ec7d
     }
12ec7d
 
12ec7d
 });
12ec7d
-- 
12ec7d
2.14.2
12ec7d
12ec7d
12ec7d
From b25d32c8fef60dec567f05e6681214a6995656fc Mon Sep 17 00:00:00 2001
12ec7d
From: Ray Strode <rstrode@redhat.com>
12ec7d
Date: Mon, 28 Sep 2015 19:56:53 -0400
12ec7d
Subject: [PATCH 2/3] gdm: only unlock with smartcard, if smartcard used for
12ec7d
 login
12ec7d
12ec7d
If a smartcard is used for login, we need to make sure the smartcard
12ec7d
gets used for unlock, too.
12ec7d
---
12ec7d
 js/gdm/util.js | 7 +++++--
12ec7d
 1 file changed, 5 insertions(+), 2 deletions(-)
12ec7d
12ec7d
diff --git a/js/gdm/util.js b/js/gdm/util.js
12ec7d
index bae46bfe0..a44184c17 100644
12ec7d
--- a/js/gdm/util.js
12ec7d
+++ b/js/gdm/util.js
12ec7d
@@ -134,7 +134,6 @@ var ShellUserVerifier = new Lang.Class({
12ec7d
         this._settings = new Gio.Settings({ schema_id: LOGIN_SCREEN_SCHEMA });
12ec7d
         this._settings.connect('changed',
12ec7d
                                Lang.bind(this, this._updateDefaultService));
12ec7d
-        this._updateDefaultService();
12ec7d
 
12ec7d
         this._fprintManager = Fprint.FprintManager();
12ec7d
         this._smartcardManager = SmartcardManager.getSmartcardManager();
12ec7d
@@ -146,6 +145,8 @@ var ShellUserVerifier = new Lang.Class({
12ec7d
         this.smartcardDetected = false;
12ec7d
         this._checkForSmartcard();
12ec7d
 
12ec7d
+        this._updateDefaultService();
12ec7d
+
12ec7d
         this._smartcardInsertedId = this._smartcardManager.connect('smartcard-inserted',
12ec7d
                                                                    Lang.bind(this, this._checkForSmartcard));
12ec7d
         this._smartcardRemovedId = this._smartcardManager.connect('smartcard-removed',
12ec7d
@@ -413,7 +414,9 @@ var ShellUserVerifier = new Lang.Class({
12ec7d
     },
12ec7d
 
12ec7d
     _updateDefaultService: function() {
12ec7d
-        if (this._settings.get_boolean(PASSWORD_AUTHENTICATION_KEY))
12ec7d
+        if (this._smartcardManager.loggedInWithToken())
12ec7d
+            this._defaultService = SMARTCARD_SERVICE_NAME;
12ec7d
+        else if (this._settings.get_boolean(PASSWORD_AUTHENTICATION_KEY))
12ec7d
             this._defaultService = PASSWORD_SERVICE_NAME;
12ec7d
         else if (this._settings.get_boolean(SMARTCARD_AUTHENTICATION_KEY))
12ec7d
             this._defaultService = SMARTCARD_SERVICE_NAME;
12ec7d
-- 
12ec7d
2.14.2
12ec7d
12ec7d
12ec7d
From 3309c476c6815e03f17359155f565118a2ad57b2 Mon Sep 17 00:00:00 2001
12ec7d
From: Ray Strode <rstrode@redhat.com>
12ec7d
Date: Mon, 28 Sep 2015 19:57:36 -0400
12ec7d
Subject: [PATCH 3/3] gdm: update default service when smartcard inserted
12ec7d
12ec7d
Early on at start up we may not know if a smartcard is
12ec7d
available.  Make sure we reupdate the default service
12ec7d
after we get a smartcard insertion event.
12ec7d
---
12ec7d
 js/gdm/util.js | 2 ++
12ec7d
 1 file changed, 2 insertions(+)
12ec7d
12ec7d
diff --git a/js/gdm/util.js b/js/gdm/util.js
12ec7d
index a44184c17..83a12fb6c 100644
12ec7d
--- a/js/gdm/util.js
12ec7d
+++ b/js/gdm/util.js
12ec7d
@@ -336,6 +336,8 @@ var ShellUserVerifier = new Lang.Class({
12ec7d
             else if (this._preemptingService == SMARTCARD_SERVICE_NAME)
12ec7d
                 this._preemptingService = null;
12ec7d
 
12ec7d
+            this._updateDefaultService();
12ec7d
+
12ec7d
             this.emit('smartcard-status-changed');
12ec7d
         }
12ec7d
     },
12ec7d
-- 
12ec7d
2.14.2
12ec7d