#include <syslog.h>
#include <errno.h>
#include <fcntl.h>
+#include <time.h>
#include "openbsd.h"
#include "doas.h"
return rv;
}
+void
+authfail(int opt)
+{
+
+#ifdef DOAS_INSULTS
+ if (opt)
+ printf("%s\n", getinsult());
+#endif
+
+ errx(1, "Authentication failed");
+}
+
int
main(int argc, char **argv)
{
if (nflag)
errx(1, "Authentication required");
- shadowauth(mypw->pw_name, rule->options & PERSIST);
+ int ret = shadowauth(mypw->pw_name, rule->options & PERSIST);
+ if (ret == 5)
+ authfail(rule->options & INSULT);
}
#elif !defined(USE_PAM)
/* no authentication provider, only allow NOPASS rules */