mirror of
https://github.com/netbirdio/netbird.git
synced 2026-10-10 23:49:09 +02:00
Stop retrying a PKCS#11 PIN the token rejected
This commit is contained in:
@@ -0,0 +1,19 @@
|
||||
package pkcs11
|
||||
|
||||
import (
|
||||
"errors"
|
||||
"fmt"
|
||||
"testing"
|
||||
|
||||
"github.com/stretchr/testify/assert"
|
||||
)
|
||||
|
||||
func TestPINRejected(t *testing.T) {
|
||||
for _, code := range []uint{rvPINIncorrect, rvPINInvalid, rvPINLenRange, rvPINExpired, rvPINLocked} {
|
||||
err := fmt.Errorf("open session: %w", Error{Op: "C_Login", Code: code})
|
||||
assert.True(t, PINRejected(err), "CKR 0x%x refuses the PIN, also when wrapped", code)
|
||||
}
|
||||
assert.False(t, PINRejected(Error{Op: "C_Login", Code: 0x30}), "a device error says nothing about the PIN")
|
||||
assert.False(t, PINRejected(errors.New("CKR_PIN_INCORRECT")), "only a PKCS#11 return value counts")
|
||||
assert.False(t, PINRejected(nil))
|
||||
}
|
||||
@@ -44,6 +44,11 @@ const (
|
||||
MGF1SHA384 = 0x3
|
||||
|
||||
rvOK = 0x0
|
||||
rvPINIncorrect = 0xa0
|
||||
rvPINInvalid = 0xa1
|
||||
rvPINLenRange = 0xa2
|
||||
rvPINExpired = 0xa3
|
||||
rvPINLocked = 0xa4
|
||||
rvUserAlreadyLoggedIn = 0x100
|
||||
rvAlreadyInitialized = 0x191
|
||||
)
|
||||
@@ -63,6 +68,20 @@ func (e Error) Error() string {
|
||||
return fmt.Sprintf("%s: CKR 0x%x", e.Op, e.Code)
|
||||
}
|
||||
|
||||
// PINRejected reports whether err is the token refusing the user PIN. Retrying the same
|
||||
// PIN cannot succeed, and each attempt counts towards the token's lockout.
|
||||
func PINRejected(err error) bool {
|
||||
var e Error
|
||||
if !errors.As(err, &e) {
|
||||
return false
|
||||
}
|
||||
switch e.Code {
|
||||
case rvPINIncorrect, rvPINInvalid, rvPINLenRange, rvPINExpired, rvPINLocked:
|
||||
return true
|
||||
}
|
||||
return false
|
||||
}
|
||||
|
||||
var returnValueNames = map[uint]string{
|
||||
0x2: "CKR_HOST_MEMORY",
|
||||
0x3: "CKR_SLOT_ID_INVALID",
|
||||
@@ -77,6 +96,9 @@ var returnValueNames = map[uint]string{
|
||||
0x71: "CKR_MECHANISM_PARAM_INVALID",
|
||||
0x82: "CKR_OBJECT_HANDLE_INVALID",
|
||||
0xa0: "CKR_PIN_INCORRECT",
|
||||
0xa1: "CKR_PIN_INVALID",
|
||||
0xa2: "CKR_PIN_LEN_RANGE",
|
||||
0xa3: "CKR_PIN_EXPIRED",
|
||||
0xa4: "CKR_PIN_LOCKED",
|
||||
0xb3: "CKR_SESSION_HANDLE_INVALID",
|
||||
0xd0: "CKR_TEMPLATE_INCOMPLETE",
|
||||
|
||||
Reference in New Issue
Block a user