|
|
c7fac9 |
From 483ac09afb6503432e48bc30a57194a490ec98c9 Mon Sep 17 00:00:00 2001
|
|
|
c7fac9 |
From: Ray Strode <rstrode@redhat.com>
|
|
|
c7fac9 |
Date: Mon, 28 Sep 2015 10:57:02 -0400
|
|
|
c7fac9 |
Subject: [PATCH 1/3] smartcardManager: add way to detect if user logged using
|
|
|
c7fac9 |
(any) token
|
|
|
c7fac9 |
|
|
|
c7fac9 |
If a user uses a token at login time, we need to make sure they continue
|
|
|
c7fac9 |
to use the token at unlock time.
|
|
|
c7fac9 |
|
|
|
c7fac9 |
As a prerequisite for addressing that problem we need to know up front
|
|
|
c7fac9 |
if a user logged in with a token at all.
|
|
|
c7fac9 |
|
|
|
c7fac9 |
This commit adds the necessary api to detect that case.
|
|
|
c7fac9 |
---
|
|
|
c7fac9 |
js/misc/smartcardManager.js | 7 +++++++
|
|
|
c7fac9 |
1 file changed, 7 insertions(+)
|
|
|
c7fac9 |
|
|
|
c7fac9 |
diff --git a/js/misc/smartcardManager.js b/js/misc/smartcardManager.js
|
|
|
c7fac9 |
index 60808b371..a9a748fb3 100644
|
|
|
c7fac9 |
--- a/js/misc/smartcardManager.js
|
|
|
c7fac9 |
+++ b/js/misc/smartcardManager.js
|
|
|
c7fac9 |
@@ -112,6 +112,13 @@ var SmartcardManager = new Lang.Class({
|
|
|
c7fac9 |
return false;
|
|
|
c7fac9 |
|
|
|
c7fac9 |
return true;
|
|
|
c7fac9 |
+ },
|
|
|
c7fac9 |
+
|
|
|
c7fac9 |
+ loggedInWithToken() {
|
|
|
c7fac9 |
+ if (this._loginToken)
|
|
|
c7fac9 |
+ return true;
|
|
|
c7fac9 |
+
|
|
|
c7fac9 |
+ return false;
|
|
|
c7fac9 |
}
|
|
|
c7fac9 |
|
|
|
c7fac9 |
});
|
|
|
c7fac9 |
--
|
|
|
c7fac9 |
2.20.1
|
|
|
c7fac9 |
|
|
|
c7fac9 |
|
|
|
c7fac9 |
From 5da6b6393ac89eaae91d2b250fb432c7e1cbe676 Mon Sep 17 00:00:00 2001
|
|
|
c7fac9 |
From: Ray Strode <rstrode@redhat.com>
|
|
|
c7fac9 |
Date: Mon, 28 Sep 2015 19:56:53 -0400
|
|
|
c7fac9 |
Subject: [PATCH 2/3] gdm: only unlock with smartcard, if smartcard used for
|
|
|
c7fac9 |
login
|
|
|
c7fac9 |
|
|
|
c7fac9 |
If a smartcard is used for login, we need to make sure the smartcard
|
|
|
c7fac9 |
gets used for unlock, too.
|
|
|
c7fac9 |
---
|
|
|
c7fac9 |
js/gdm/util.js | 7 +++++--
|
|
|
c7fac9 |
1 file changed, 5 insertions(+), 2 deletions(-)
|
|
|
c7fac9 |
|
|
|
c7fac9 |
diff --git a/js/gdm/util.js b/js/gdm/util.js
|
|
|
c7fac9 |
index 261e1e433..3d6d69c10 100644
|
|
|
c7fac9 |
--- a/js/gdm/util.js
|
|
|
c7fac9 |
+++ b/js/gdm/util.js
|
|
|
c7fac9 |
@@ -134,7 +134,6 @@ var ShellUserVerifier = new Lang.Class({
|
|
|
c7fac9 |
this._settings = new Gio.Settings({ schema_id: LOGIN_SCREEN_SCHEMA });
|
|
|
c7fac9 |
this._settings.connect('changed',
|
|
|
c7fac9 |
this._updateDefaultService.bind(this));
|
|
|
c7fac9 |
- this._updateDefaultService();
|
|
|
c7fac9 |
|
|
|
c7fac9 |
this._fprintManager = Fprint.FprintManager();
|
|
|
c7fac9 |
this._smartcardManager = SmartcardManager.getSmartcardManager();
|
|
|
c7fac9 |
@@ -146,6 +145,8 @@ var ShellUserVerifier = new Lang.Class({
|
|
|
c7fac9 |
this.smartcardDetected = false;
|
|
|
c7fac9 |
this._checkForSmartcard();
|
|
|
c7fac9 |
|
|
|
c7fac9 |
+ this._updateDefaultService();
|
|
|
c7fac9 |
+
|
|
|
c7fac9 |
this._smartcardInsertedId = this._smartcardManager.connect('smartcard-inserted',
|
|
|
c7fac9 |
this._checkForSmartcard.bind(this));
|
|
|
c7fac9 |
this._smartcardRemovedId = this._smartcardManager.connect('smartcard-removed',
|
|
|
c7fac9 |
@@ -412,7 +413,9 @@ var ShellUserVerifier = new Lang.Class({
|
|
|
c7fac9 |
},
|
|
|
c7fac9 |
|
|
|
c7fac9 |
_updateDefaultService() {
|
|
|
c7fac9 |
- if (this._settings.get_boolean(PASSWORD_AUTHENTICATION_KEY))
|
|
|
c7fac9 |
+ if (this._smartcardManager.loggedInWithToken())
|
|
|
c7fac9 |
+ this._defaultService = SMARTCARD_SERVICE_NAME;
|
|
|
c7fac9 |
+ else if (this._settings.get_boolean(PASSWORD_AUTHENTICATION_KEY))
|
|
|
c7fac9 |
this._defaultService = PASSWORD_SERVICE_NAME;
|
|
|
c7fac9 |
else if (this._settings.get_boolean(SMARTCARD_AUTHENTICATION_KEY))
|
|
|
c7fac9 |
this._defaultService = SMARTCARD_SERVICE_NAME;
|
|
|
c7fac9 |
--
|
|
|
c7fac9 |
2.20.1
|
|
|
c7fac9 |
|
|
|
c7fac9 |
|
|
|
c7fac9 |
From 1d6de184a8bfbd54b9472eea822380b89f70509a Mon Sep 17 00:00:00 2001
|
|
|
c7fac9 |
From: Ray Strode <rstrode@redhat.com>
|
|
|
c7fac9 |
Date: Mon, 28 Sep 2015 19:57:36 -0400
|
|
|
c7fac9 |
Subject: [PATCH 3/3] gdm: update default service when smartcard inserted
|
|
|
c7fac9 |
|
|
|
c7fac9 |
Early on at start up we may not know if a smartcard is
|
|
|
c7fac9 |
available. Make sure we reupdate the default service
|
|
|
c7fac9 |
after we get a smartcard insertion event.
|
|
|
c7fac9 |
---
|
|
|
c7fac9 |
js/gdm/util.js | 2 ++
|
|
|
c7fac9 |
1 file changed, 2 insertions(+)
|
|
|
c7fac9 |
|
|
|
c7fac9 |
diff --git a/js/gdm/util.js b/js/gdm/util.js
|
|
|
c7fac9 |
index 3d6d69c10..f5f9d5e5d 100644
|
|
|
c7fac9 |
--- a/js/gdm/util.js
|
|
|
c7fac9 |
+++ b/js/gdm/util.js
|
|
|
c7fac9 |
@@ -335,6 +335,8 @@ var ShellUserVerifier = new Lang.Class({
|
|
|
c7fac9 |
else if (this._preemptingService == SMARTCARD_SERVICE_NAME)
|
|
|
c7fac9 |
this._preemptingService = null;
|
|
|
c7fac9 |
|
|
|
c7fac9 |
+ this._updateDefaultService();
|
|
|
c7fac9 |
+
|
|
|
c7fac9 |
this.emit('smartcard-status-changed');
|
|
|
c7fac9 |
}
|
|
|
c7fac9 |
},
|
|
|
c7fac9 |
--
|
|
|
c7fac9 |
2.20.1
|
|
|
c7fac9 |
|