HEX
Server: nginx/1.30.4
System: Linux d-twindigital-web-1.host-ed.eu 4.18.0-553.141.2.el8_10.x86_64 #1 SMP Wed Jul 8 10:28:18 EDT 2026 x86_64
User: u_twindigital_html (1009)
PHP: 8.3.30
Disabled: NONE
Upload Files
File: //usr/include/util.h
/*
 * SPDX-License-Identifier: GPL-2.0-with-classpath-exception
 *
 * util.h
 *
 * Copyright (c) 2023 Cisco Systems, Inc. and/or its affiliates
 * All rights reserved.
 */

#ifndef DUO_UTIL_H
#define DUO_UTIL_H

#define MAX_GROUPS 256
#define MAX_PROMPTS 3

#include <pwd.h>
#include <syslog.h>
#include <stdarg.h>

extern int duo_debug;

enum {
    DUO_FAIL_SAFE = 0,
    DUO_FAIL_SECURE
};

/*
 * Configured minimum TLS version floor. DUO_MIN_TLS_UNSET (0, the default
 * after duo_config_default()) leaves the library's negotiation behavior
 * unchanged for backwards compatibility. The library maps the remaining
 * values to OpenSSL protocol-version constants when initializing the
 * SSL context.
 */
enum {
    DUO_MIN_TLS_UNSET = 0,
    DUO_MIN_TLS_1_0,
    DUO_MIN_TLS_1_1,
    DUO_MIN_TLS_1_2,
    DUO_MIN_TLS_1_3
};

struct duo_config {
    char *ikey;
    char *skey;
    char *apihost;
    char *cafile;
    char *http_proxy;
    char *groups[MAX_GROUPS];
    char gecos_delim;
    int  groups_cnt;
    int  groups_mode;
    int  failmode;  /* Duo failure handling: DUO_FAIL_* */
    int  pushinfo;
    int  noverify;
    int  autopush;
    int  motd; /* login_duo only */
    int  prompts;
    int  accept_env;
    int  local_ip_fallback;
    int  https_timeout;
    int  send_gecos;
    int  gecos_username_pos;
    int  verified_push;
    int  min_tls;   /* Minimum TLS version floor: DUO_MIN_TLS_* */
};

void duo_config_default(struct duo_config *cfg);

int duo_set_boolean_option(const char *val);

int duo_common_ini_handler(
    struct duo_config *cfg,
    const char *section,
    const char *name,
    const char *val
);

/* Clean up config memory. */
void close_config(struct duo_config *cfg);

void cleanup_config_groups(struct duo_config *cfg);

int duo_check_groups(struct passwd *pw, char **groups, int groups_cnt);

/*
 * Return 1 if a groups filter is configured but every pattern is a
 * negation ('!'-prefixed), meaning the filter can never match any user
 * and Duo 2FA is effectively disabled host-wide. Returns 0 for an empty
 * filter or any config containing at least one non-negated pattern.
 */
int duo_groups_all_negated(const struct duo_config *cfg);

void duo_log(
    int priority,
    const char *msg,
    const char *user,
    const char *ip,
    const char *err
);

void duo_syslog(int priority, const char *fmt, ...);

const char *duo_resolve_name(const char *hostname);

const char *duo_local_ip();

char *duo_split_at(char *s, char delimiter, unsigned int position);

/* Replace non-printable characters (except \n and \t) with '?'. */
void duo_sanitize_str(char *s);

/* Free and zero out memory */
void duo_zero_free(void *ptr, size_t size);

#endif