Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Conditionally skip username check within certificate principals #21

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

ArmaanT
Copy link

@ArmaanT ArmaanT commented Aug 18, 2021

This PR removes the requirement that a username must appear within a certificate's list of principals so long as an explicit set of valid principals is defined. This change was made so that the call to c.CheckCert on line 166 will verify the certificate, but explicitly exclude checking principals because pam-ussh verifies principals later in the code.

This change is related to #15.

Skip checking if the username exists within the SSH certificiate
principals if a manual set of valid principals is defined
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant