xref: /openbmc/ipmitool/lib/ipmi_user.c (revision 3412d861)
1c18ec02fSPetter Reinholdtsen /*
2c18ec02fSPetter Reinholdtsen  * Copyright (c) 2003 Sun Microsystems, Inc.  All Rights Reserved.
3c18ec02fSPetter Reinholdtsen  *
4c18ec02fSPetter Reinholdtsen  * Redistribution and use in source and binary forms, with or without
5c18ec02fSPetter Reinholdtsen  * modification, are permitted provided that the following conditions
6c18ec02fSPetter Reinholdtsen  * are met:
7c18ec02fSPetter Reinholdtsen  *
8c18ec02fSPetter Reinholdtsen  * Redistribution of source code must retain the above copyright
9c18ec02fSPetter Reinholdtsen  * notice, this list of conditions and the following disclaimer.
10c18ec02fSPetter Reinholdtsen  *
11c18ec02fSPetter Reinholdtsen  * Redistribution in binary form must reproduce the above copyright
12c18ec02fSPetter Reinholdtsen  * notice, this list of conditions and the following disclaimer in the
13c18ec02fSPetter Reinholdtsen  * documentation and/or other materials provided with the distribution.
14c18ec02fSPetter Reinholdtsen  *
15c18ec02fSPetter Reinholdtsen  * Neither the name of Sun Microsystems, Inc. or the names of
16c18ec02fSPetter Reinholdtsen  * contributors may be used to endorse or promote products derived
17c18ec02fSPetter Reinholdtsen  * from this software without specific prior written permission.
18c18ec02fSPetter Reinholdtsen  *
19c18ec02fSPetter Reinholdtsen  * This software is provided "AS IS," without a warranty of any kind.
20c18ec02fSPetter Reinholdtsen  * ALL EXPRESS OR IMPLIED CONDITIONS, REPRESENTATIONS AND WARRANTIES,
21c18ec02fSPetter Reinholdtsen  * INCLUDING ANY IMPLIED WARRANTY OF MERCHANTABILITY, FITNESS FOR A
22c18ec02fSPetter Reinholdtsen  * PARTICULAR PURPOSE OR NON-INFRINGEMENT, ARE HEREBY EXCLUDED.
23c18ec02fSPetter Reinholdtsen  * SUN MICROSYSTEMS, INC. ("SUN") AND ITS LICENSORS SHALL NOT BE LIABLE
24c18ec02fSPetter Reinholdtsen  * FOR ANY DAMAGES SUFFERED BY LICENSEE AS A RESULT OF USING, MODIFYING
25c18ec02fSPetter Reinholdtsen  * OR DISTRIBUTING THIS SOFTWARE OR ITS DERIVATIVES.  IN NO EVENT WILL
26c18ec02fSPetter Reinholdtsen  * SUN OR ITS LICENSORS BE LIABLE FOR ANY LOST REVENUE, PROFIT OR DATA,
27c18ec02fSPetter Reinholdtsen  * OR FOR DIRECT, INDIRECT, SPECIAL, CONSEQUENTIAL, INCIDENTAL OR
28c18ec02fSPetter Reinholdtsen  * PUNITIVE DAMAGES, HOWEVER CAUSED AND REGARDLESS OF THE THEORY OF
29c18ec02fSPetter Reinholdtsen  * LIABILITY, ARISING OUT OF THE USE OF OR INABILITY TO USE THIS SOFTWARE,
30c18ec02fSPetter Reinholdtsen  * EVEN IF SUN HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
31c18ec02fSPetter Reinholdtsen  */
32c18ec02fSPetter Reinholdtsen 
33c18ec02fSPetter Reinholdtsen #include <stdlib.h>
34c18ec02fSPetter Reinholdtsen #include <string.h>
35c18ec02fSPetter Reinholdtsen #include <stdio.h>
36c18ec02fSPetter Reinholdtsen #include <sys/types.h>
37c18ec02fSPetter Reinholdtsen #include <sys/select.h>
38c18ec02fSPetter Reinholdtsen #include <sys/time.h>
39c18ec02fSPetter Reinholdtsen #include <signal.h>
40c18ec02fSPetter Reinholdtsen #include <unistd.h>
41c18ec02fSPetter Reinholdtsen 
42c18ec02fSPetter Reinholdtsen #include <ipmitool/helper.h>
43c18ec02fSPetter Reinholdtsen #include <ipmitool/log.h>
44c18ec02fSPetter Reinholdtsen #include <ipmitool/ipmi.h>
45c18ec02fSPetter Reinholdtsen #include <ipmitool/ipmi_intf.h>
46c18ec02fSPetter Reinholdtsen #include <ipmitool/ipmi_user.h>
47c18ec02fSPetter Reinholdtsen #include <ipmitool/ipmi_constants.h>
48c18ec02fSPetter Reinholdtsen #include <ipmitool/ipmi_strings.h>
49c18ec02fSPetter Reinholdtsen #include <ipmitool/bswap.h>
50c18ec02fSPetter Reinholdtsen 
51c18ec02fSPetter Reinholdtsen 
52c18ec02fSPetter Reinholdtsen extern int verbose;
53c18ec02fSPetter Reinholdtsen extern int csv_output;
54c18ec02fSPetter Reinholdtsen 
55c18ec02fSPetter Reinholdtsen 
5631f9d4c6SZdenek Styblik /* _ipmi_get_user_access - Get User Access for given channel. Results are stored
5731f9d4c6SZdenek Styblik  * into passed struct.
5831f9d4c6SZdenek Styblik  *
5931f9d4c6SZdenek Styblik  * @intf - IPMI interface
6031f9d4c6SZdenek Styblik  * @user_access_rsp - ptr to user_access_t with UID and Channel set
6131f9d4c6SZdenek Styblik  *
6231f9d4c6SZdenek Styblik  * returns - negative number means error, positive is a ccode
6331f9d4c6SZdenek Styblik  */
6431f9d4c6SZdenek Styblik int
_ipmi_get_user_access(struct ipmi_intf * intf,struct user_access_t * user_access_rsp)6531f9d4c6SZdenek Styblik _ipmi_get_user_access(struct ipmi_intf *intf,
6631f9d4c6SZdenek Styblik 		struct user_access_t *user_access_rsp)
6731f9d4c6SZdenek Styblik {
6831f9d4c6SZdenek Styblik 	struct ipmi_rq req = {0};
6931f9d4c6SZdenek Styblik 	struct ipmi_rs *rsp;
7031f9d4c6SZdenek Styblik 	uint8_t data[2];
7131f9d4c6SZdenek Styblik 	if (user_access_rsp == NULL) {
7231f9d4c6SZdenek Styblik 		return (-3);
7331f9d4c6SZdenek Styblik 	}
7431f9d4c6SZdenek Styblik 	data[0] = user_access_rsp->channel & 0x0F;
7531f9d4c6SZdenek Styblik 	data[1] = user_access_rsp->user_id & 0x3F;
7631f9d4c6SZdenek Styblik 	req.msg.netfn = IPMI_NETFN_APP;
7731f9d4c6SZdenek Styblik 	req.msg.cmd = IPMI_GET_USER_ACCESS;
7831f9d4c6SZdenek Styblik 	req.msg.data = data;
7931f9d4c6SZdenek Styblik 	req.msg.data_len = 2;
8031f9d4c6SZdenek Styblik 	rsp = intf->sendrecv(intf, &req);
8131f9d4c6SZdenek Styblik 	if (rsp == NULL) {
8231f9d4c6SZdenek Styblik 		return (-1);
8331f9d4c6SZdenek Styblik 	} else if (rsp->ccode != 0) {
8431f9d4c6SZdenek Styblik 		return rsp->ccode;
8531f9d4c6SZdenek Styblik 	} else if (rsp->data_len != 4) {
8631f9d4c6SZdenek Styblik 		return (-2);
8731f9d4c6SZdenek Styblik 	}
8831f9d4c6SZdenek Styblik 	user_access_rsp->max_user_ids = rsp->data[0] & 0x3F;
8931f9d4c6SZdenek Styblik 	user_access_rsp->enable_status = rsp->data[1] & 0xC0;
9031f9d4c6SZdenek Styblik 	user_access_rsp->enabled_user_ids = rsp->data[1] & 0x3F;
9131f9d4c6SZdenek Styblik 	user_access_rsp->fixed_user_ids = rsp->data[2] & 0x3F;
9231f9d4c6SZdenek Styblik 	user_access_rsp->callin_callback = rsp->data[3] & 0x40;
9331f9d4c6SZdenek Styblik 	user_access_rsp->link_auth = rsp->data[3] & 0x20;
9431f9d4c6SZdenek Styblik 	user_access_rsp->ipmi_messaging = rsp->data[3] & 0x10;
9531f9d4c6SZdenek Styblik 	user_access_rsp->privilege_limit = rsp->data[3] & 0x0F;
9631f9d4c6SZdenek Styblik 	return rsp->ccode;
9731f9d4c6SZdenek Styblik }
9831f9d4c6SZdenek Styblik 
996d1afbf3SZdenek Styblik /* _ipmi_get_user_name - Fetch User Name for given User ID. User Name is stored
1006d1afbf3SZdenek Styblik  * into passed structure.
1016d1afbf3SZdenek Styblik  *
1026d1afbf3SZdenek Styblik  * @intf - ipmi interface
1036d1afbf3SZdenek Styblik  * @user_name - user_name_t struct with UID set
1046d1afbf3SZdenek Styblik  *
1056d1afbf3SZdenek Styblik  * returns - negative number means error, positive is a ccode
1066d1afbf3SZdenek Styblik  */
1076d1afbf3SZdenek Styblik int
_ipmi_get_user_name(struct ipmi_intf * intf,struct user_name_t * user_name_ptr)1086d1afbf3SZdenek Styblik _ipmi_get_user_name(struct ipmi_intf *intf, struct user_name_t *user_name_ptr)
1096d1afbf3SZdenek Styblik {
1106d1afbf3SZdenek Styblik 	struct ipmi_rq req = {0};
1116d1afbf3SZdenek Styblik 	struct ipmi_rs *rsp;
1126d1afbf3SZdenek Styblik 	uint8_t data[1];
1136d1afbf3SZdenek Styblik 	if (user_name_ptr == NULL) {
1146d1afbf3SZdenek Styblik 		return (-3);
1156d1afbf3SZdenek Styblik 	}
1166d1afbf3SZdenek Styblik 	data[0] = user_name_ptr->user_id & 0x3F;
1176d1afbf3SZdenek Styblik 	req.msg.netfn = IPMI_NETFN_APP;
1186d1afbf3SZdenek Styblik 	req.msg.cmd = IPMI_GET_USER_NAME;
1196d1afbf3SZdenek Styblik 	req.msg.data = data;
1206d1afbf3SZdenek Styblik 	req.msg.data_len = 1;
1216d1afbf3SZdenek Styblik 	rsp = intf->sendrecv(intf, &req);
1226d1afbf3SZdenek Styblik 	if (rsp == NULL) {
1236d1afbf3SZdenek Styblik 		return (-1);
1246d1afbf3SZdenek Styblik 	} else if (rsp->ccode > 0) {
1256d1afbf3SZdenek Styblik 		return rsp->ccode;
126*3412d861SAlexander Rube 	} else if (rsp->data_len != 16) {
1276d1afbf3SZdenek Styblik 		return (-2);
1286d1afbf3SZdenek Styblik 	}
1296d1afbf3SZdenek Styblik 	memset(user_name_ptr->user_name, '\0', 17);
1306d1afbf3SZdenek Styblik 	memcpy(user_name_ptr->user_name, rsp->data, 16);
1316d1afbf3SZdenek Styblik 	return rsp->ccode;
1326d1afbf3SZdenek Styblik }
1336d1afbf3SZdenek Styblik 
13431f9d4c6SZdenek Styblik /* _ipmi_set_user_access - Set User Access for given channel.
13531f9d4c6SZdenek Styblik  *
13631f9d4c6SZdenek Styblik  * @intf - IPMI interface
13731f9d4c6SZdenek Styblik  * @user_access_req - ptr to user_access_t with desired User Access.
138708be8bcSZdenek Styblik  * @change_priv_limit_only - change User's privilege limit only
13931f9d4c6SZdenek Styblik  *
14031f9d4c6SZdenek Styblik  * returns - negative number means error, positive is a ccode
14131f9d4c6SZdenek Styblik  */
14231f9d4c6SZdenek Styblik int
_ipmi_set_user_access(struct ipmi_intf * intf,struct user_access_t * user_access_req,uint8_t change_priv_limit_only)14331f9d4c6SZdenek Styblik _ipmi_set_user_access(struct ipmi_intf *intf,
144708be8bcSZdenek Styblik 		struct user_access_t *user_access_req,
145708be8bcSZdenek Styblik 		uint8_t change_priv_limit_only)
14631f9d4c6SZdenek Styblik {
14731f9d4c6SZdenek Styblik 	uint8_t data[4];
14831f9d4c6SZdenek Styblik 	struct ipmi_rq req = {0};
14931f9d4c6SZdenek Styblik 	struct ipmi_rs *rsp;
15031f9d4c6SZdenek Styblik 	if (user_access_req == NULL) {
15131f9d4c6SZdenek Styblik 		return (-3);
15231f9d4c6SZdenek Styblik 	}
153708be8bcSZdenek Styblik 	data[0] = change_priv_limit_only ? 0x00 : 0x80;
15431f9d4c6SZdenek Styblik 	if (user_access_req->callin_callback) {
15531f9d4c6SZdenek Styblik 		data[0] |= 0x40;
15631f9d4c6SZdenek Styblik 	}
15731f9d4c6SZdenek Styblik 	if (user_access_req->link_auth) {
15831f9d4c6SZdenek Styblik 		data[0] |= 0x20;
15931f9d4c6SZdenek Styblik 	}
16031f9d4c6SZdenek Styblik 	if (user_access_req->ipmi_messaging) {
16131f9d4c6SZdenek Styblik 		data[0] |= 0x10;
16231f9d4c6SZdenek Styblik 	}
16331f9d4c6SZdenek Styblik 	data[0] |= (user_access_req->channel & 0x0F);
16431f9d4c6SZdenek Styblik 	data[1] = user_access_req->user_id & 0x3F;
16531f9d4c6SZdenek Styblik 	data[2] = user_access_req->privilege_limit & 0x0F;
16631f9d4c6SZdenek Styblik 	data[3] = user_access_req->session_limit & 0x0F;
16731f9d4c6SZdenek Styblik 	req.msg.netfn = IPMI_NETFN_APP;
16831f9d4c6SZdenek Styblik 	req.msg.cmd = IPMI_SET_USER_ACCESS;
169d099dca9SZdenek Styblik 	req.msg.data = data;
17031f9d4c6SZdenek Styblik 	req.msg.data_len = 4;
17131f9d4c6SZdenek Styblik 	rsp = intf->sendrecv(intf, &req);
17231f9d4c6SZdenek Styblik 	if (rsp == NULL) {
17331f9d4c6SZdenek Styblik 		return (-1);
17431f9d4c6SZdenek Styblik 	} else {
17531f9d4c6SZdenek Styblik 		return rsp->ccode;
17631f9d4c6SZdenek Styblik 	}
17731f9d4c6SZdenek Styblik }
17831f9d4c6SZdenek Styblik 
179a6d47cebSZdenek Styblik /* _ipmi_set_user_password - Set User Password command.
180a6d47cebSZdenek Styblik  *
18180814275SZdenek Styblik  * @intf - IPMI interface
182a6d47cebSZdenek Styblik  * @user_id - IPMI User ID
183a6d47cebSZdenek Styblik  * @operation - which operation to perform(en/disable user, set/test password)
184a6d47cebSZdenek Styblik  * @password - User Password
185a6d47cebSZdenek Styblik  * @is_twenty_byte - 0 = store as 16byte, otherwise store as 20byte password
186a6d47cebSZdenek Styblik  *
187a6d47cebSZdenek Styblik  * returns - negative number means error, positive is a ccode
188a6d47cebSZdenek Styblik  */
189a6d47cebSZdenek Styblik int
_ipmi_set_user_password(struct ipmi_intf * intf,uint8_t user_id,uint8_t operation,const char * password,uint8_t is_twenty_byte)190a6d47cebSZdenek Styblik _ipmi_set_user_password(struct ipmi_intf *intf, uint8_t user_id,
191a6d47cebSZdenek Styblik 		uint8_t operation, const char *password,
192a6d47cebSZdenek Styblik 		uint8_t is_twenty_byte)
193a6d47cebSZdenek Styblik {
194a6d47cebSZdenek Styblik 	struct ipmi_rq req = {0};
195a6d47cebSZdenek Styblik 	struct ipmi_rs *rsp;
196a6d47cebSZdenek Styblik 	uint8_t *data;
197a6d47cebSZdenek Styblik 	uint8_t data_len = (is_twenty_byte) ? 22 : 18;
198a6d47cebSZdenek Styblik 	data = malloc(sizeof(uint8_t) * data_len);
199a6d47cebSZdenek Styblik 	if (data == NULL) {
200a6d47cebSZdenek Styblik 		return (-4);
201a6d47cebSZdenek Styblik 	}
202a6d47cebSZdenek Styblik 	memset(data, 0, data_len);
203a6d47cebSZdenek Styblik 	data[0] = (is_twenty_byte) ? 0x80 : 0x00;
204a6d47cebSZdenek Styblik 	data[0] |= (0x0F & user_id);
205a6d47cebSZdenek Styblik 	data[1] = 0x03 & operation;
206a6d47cebSZdenek Styblik 	if (password != NULL) {
207a6d47cebSZdenek Styblik 		size_t copy_len = strlen(password);
208a6d47cebSZdenek Styblik 		if (copy_len > (data_len - 2)) {
209a6d47cebSZdenek Styblik 			copy_len = data_len - 2;
210a6d47cebSZdenek Styblik 		} else if (copy_len < 1) {
211a6d47cebSZdenek Styblik 			copy_len = 0;
212a6d47cebSZdenek Styblik 		}
213a6d47cebSZdenek Styblik 		strncpy((char *)(data + 2), password, copy_len);
214a6d47cebSZdenek Styblik 	}
215a6d47cebSZdenek Styblik 
216a6d47cebSZdenek Styblik 	req.msg.netfn = IPMI_NETFN_APP;
217a6d47cebSZdenek Styblik 	req.msg.cmd = IPMI_SET_USER_PASSWORD;
218a6d47cebSZdenek Styblik 	req.msg.data = data;
219a6d47cebSZdenek Styblik 	req.msg.data_len = data_len;
220a6d47cebSZdenek Styblik 	rsp = intf->sendrecv(intf, &req);
221a6d47cebSZdenek Styblik 	free(data);
222a6d47cebSZdenek Styblik 	data = NULL;
223a6d47cebSZdenek Styblik 	if (rsp == NULL) {
224a6d47cebSZdenek Styblik 		return (-1);
225a6d47cebSZdenek Styblik 	}
226a6d47cebSZdenek Styblik 	return rsp->ccode;
227a6d47cebSZdenek Styblik }
228a6d47cebSZdenek Styblik 
229c18ec02fSPetter Reinholdtsen static void
dump_user_access(const char * user_name,struct user_access_t * user_access)230d6deeb26SZdenek Styblik dump_user_access(const char *user_name,
231d6deeb26SZdenek Styblik 		struct user_access_t *user_access)
232c18ec02fSPetter Reinholdtsen {
233c18ec02fSPetter Reinholdtsen 	static int printed_header = 0;
234d6deeb26SZdenek Styblik 	if (!printed_header) {
235c18ec02fSPetter Reinholdtsen 		printf("ID  Name	     Callin  Link Auth	IPMI Msg   "
236c18ec02fSPetter Reinholdtsen 				"Channel Priv Limit\n");
237c18ec02fSPetter Reinholdtsen 		printed_header = 1;
238c18ec02fSPetter Reinholdtsen 	}
239c18ec02fSPetter Reinholdtsen 	printf("%-4d%-17s%-8s%-11s%-11s%-s\n",
240d6deeb26SZdenek Styblik 			user_access->user_id,
241c18ec02fSPetter Reinholdtsen 			user_name,
242d6deeb26SZdenek Styblik 			user_access->callin_callback? "false": "true ",
243d6deeb26SZdenek Styblik 			user_access->link_auth? "true ": "false",
244d6deeb26SZdenek Styblik 			user_access->ipmi_messaging? "true ": "false",
245d6deeb26SZdenek Styblik 			val2str(user_access->privilege_limit,
246c18ec02fSPetter Reinholdtsen 				ipmi_privlvl_vals));
247c18ec02fSPetter Reinholdtsen }
248c18ec02fSPetter Reinholdtsen 
249c18ec02fSPetter Reinholdtsen 
250c18ec02fSPetter Reinholdtsen 
251c18ec02fSPetter Reinholdtsen static void
dump_user_access_csv(const char * user_name,struct user_access_t * user_access)252d6deeb26SZdenek Styblik dump_user_access_csv(const char *user_name,
253d6deeb26SZdenek Styblik 		struct user_access_t *user_access)
254c18ec02fSPetter Reinholdtsen {
255c18ec02fSPetter Reinholdtsen 	printf("%d,%s,%s,%s,%s,%s\n",
256d6deeb26SZdenek Styblik 			user_access->user_id,
257c18ec02fSPetter Reinholdtsen 			user_name,
258d6deeb26SZdenek Styblik 			user_access->callin_callback? "false": "true",
259d6deeb26SZdenek Styblik 			user_access->link_auth? "true": "false",
260d6deeb26SZdenek Styblik 			user_access->ipmi_messaging? "true": "false",
261d6deeb26SZdenek Styblik 			val2str(user_access->privilege_limit,
262c18ec02fSPetter Reinholdtsen 				ipmi_privlvl_vals));
263c18ec02fSPetter Reinholdtsen }
264c18ec02fSPetter Reinholdtsen 
265d6deeb26SZdenek Styblik /* ipmi_print_user_list - List IPMI Users and their ACLs for given channel.
266d6deeb26SZdenek Styblik  *
267d6deeb26SZdenek Styblik  * @intf - IPMI interface
268d6deeb26SZdenek Styblik  * @channel_number - IPMI channel
269d6deeb26SZdenek Styblik  *
270d6deeb26SZdenek Styblik  * returns - 0 on success, (-1) on error
271d6deeb26SZdenek Styblik  */
272c18ec02fSPetter Reinholdtsen static int
ipmi_print_user_list(struct ipmi_intf * intf,uint8_t channel_number)273d6deeb26SZdenek Styblik ipmi_print_user_list(struct ipmi_intf *intf, uint8_t channel_number)
274c18ec02fSPetter Reinholdtsen {
275d6deeb26SZdenek Styblik 	struct user_access_t user_access = {0};
276d6deeb26SZdenek Styblik 	struct user_name_t user_name = {0};
277d6deeb26SZdenek Styblik 	int ccode = 0;
278c18ec02fSPetter Reinholdtsen 	uint8_t current_user_id = 1;
279d6deeb26SZdenek Styblik 	do {
280d6deeb26SZdenek Styblik 		memset(&user_access, 0, sizeof(user_access));
281d6deeb26SZdenek Styblik 		user_access.user_id = current_user_id;
282d6deeb26SZdenek Styblik 		user_access.channel = channel_number;
283d6deeb26SZdenek Styblik 		ccode = _ipmi_get_user_access(intf, &user_access);
284d6deeb26SZdenek Styblik 		if (eval_ccode(ccode) != 0) {
285d6deeb26SZdenek Styblik 			return (-1);
286d6deeb26SZdenek Styblik 		}
287d6deeb26SZdenek Styblik 		memset(&user_name, 0, sizeof(user_name));
288d6deeb26SZdenek Styblik 		user_name.user_id = current_user_id;
289d6deeb26SZdenek Styblik 		ccode = _ipmi_get_user_name(intf, &user_name);
290d6deeb26SZdenek Styblik 		if (eval_ccode(ccode) != 0) {
291d6deeb26SZdenek Styblik 			return (-1);
292d6deeb26SZdenek Styblik 		}
293d6deeb26SZdenek Styblik 		if ((current_user_id == 0)
294d6deeb26SZdenek Styblik 				|| user_access.link_auth
295d6deeb26SZdenek Styblik 				|| user_access.ipmi_messaging
296d6deeb26SZdenek Styblik 				|| strcmp("", (char *)user_name.user_name)) {
297d6deeb26SZdenek Styblik 			if (csv_output) {
298d6deeb26SZdenek Styblik 				dump_user_access_csv((char *)user_name.user_name,
299d6deeb26SZdenek Styblik 						&user_access);
300d6deeb26SZdenek Styblik 			} else {
301d6deeb26SZdenek Styblik 				dump_user_access((char *)user_name.user_name,
302c18ec02fSPetter Reinholdtsen 						&user_access);
303c18ec02fSPetter Reinholdtsen 			}
304d6deeb26SZdenek Styblik 		}
305c18ec02fSPetter Reinholdtsen 		++current_user_id;
306d6deeb26SZdenek Styblik 	} while ((current_user_id <= user_access.max_user_ids)
307d6deeb26SZdenek Styblik 			&& (current_user_id <= IPMI_UID_MAX));
308c18ec02fSPetter Reinholdtsen 	return 0;
309c18ec02fSPetter Reinholdtsen }
310c18ec02fSPetter Reinholdtsen 
311fb36c693SZdenek Styblik /* ipmi_print_user_summary - print User statistics for given channel
312fb36c693SZdenek Styblik  *
313fb36c693SZdenek Styblik  * @intf - IPMI interface
314fb36c693SZdenek Styblik  * @channel_number - channel number
315fb36c693SZdenek Styblik  *
316fb36c693SZdenek Styblik  * returns - 0 on success, (-1) on error
317fb36c693SZdenek Styblik  */
318c18ec02fSPetter Reinholdtsen static int
ipmi_print_user_summary(struct ipmi_intf * intf,uint8_t channel_number)319fb36c693SZdenek Styblik ipmi_print_user_summary(struct ipmi_intf *intf, uint8_t channel_number)
320c18ec02fSPetter Reinholdtsen {
321fb36c693SZdenek Styblik 	struct user_access_t user_access = {0};
322fb36c693SZdenek Styblik 	int ccode = 0;
323fb36c693SZdenek Styblik 	user_access.channel = channel_number;
324fb36c693SZdenek Styblik 	user_access.user_id = 1;
325fb36c693SZdenek Styblik 	ccode = _ipmi_get_user_access(intf, &user_access);
326fb36c693SZdenek Styblik 	if (eval_ccode(ccode) != 0) {
327fb36c693SZdenek Styblik 		return (-1);
328c18ec02fSPetter Reinholdtsen 	}
329fb36c693SZdenek Styblik 	if (csv_output) {
330fb36c693SZdenek Styblik 		printf("%" PRIu8 ",%" PRIu8 ",%" PRIu8 "\n",
331fb36c693SZdenek Styblik 				user_access.max_user_ids,
332fb36c693SZdenek Styblik 				user_access.enabled_user_ids,
333fb36c693SZdenek Styblik 				user_access.fixed_user_ids);
334fb36c693SZdenek Styblik 	} else {
335fb36c693SZdenek Styblik 		printf("Maximum IDs	    : %" PRIu8 "\n",
336fb36c693SZdenek Styblik 				user_access.max_user_ids);
337fb36c693SZdenek Styblik 		printf("Enabled User Count  : %" PRIu8 "\n",
338fb36c693SZdenek Styblik 				user_access.enabled_user_ids);
339fb36c693SZdenek Styblik 		printf("Fixed Name Count    : %" PRIu8 "\n",
340fb36c693SZdenek Styblik 				user_access.fixed_user_ids);
341c18ec02fSPetter Reinholdtsen 	}
342c18ec02fSPetter Reinholdtsen 	return 0;
343c18ec02fSPetter Reinholdtsen }
344c18ec02fSPetter Reinholdtsen 
345c18ec02fSPetter Reinholdtsen /*
346c18ec02fSPetter Reinholdtsen  * ipmi_user_set_username
347c18ec02fSPetter Reinholdtsen  */
348c18ec02fSPetter Reinholdtsen static int
ipmi_user_set_username(struct ipmi_intf * intf,uint8_t user_id,const char * name)349c18ec02fSPetter Reinholdtsen ipmi_user_set_username(
350c18ec02fSPetter Reinholdtsen 		       struct ipmi_intf *intf,
351c18ec02fSPetter Reinholdtsen 		       uint8_t user_id,
352c18ec02fSPetter Reinholdtsen 		       const char *name)
353c18ec02fSPetter Reinholdtsen {
354c18ec02fSPetter Reinholdtsen 	struct ipmi_rs	     * rsp;
355c18ec02fSPetter Reinholdtsen 	struct ipmi_rq	       req;
356c18ec02fSPetter Reinholdtsen 	uint8_t	       msg_data[17];
357c18ec02fSPetter Reinholdtsen 
358c18ec02fSPetter Reinholdtsen 	/*
359c18ec02fSPetter Reinholdtsen 	 * Ensure there is space for the name in the request message buffer
360c18ec02fSPetter Reinholdtsen 	 */
361c18ec02fSPetter Reinholdtsen 	if (strlen(name) >= sizeof(msg_data)) {
362c18ec02fSPetter Reinholdtsen 		return -1;
363c18ec02fSPetter Reinholdtsen 	}
364c18ec02fSPetter Reinholdtsen 
365c18ec02fSPetter Reinholdtsen 	memset(&req, 0, sizeof(req));
366c18ec02fSPetter Reinholdtsen 	req.msg.netfn    = IPMI_NETFN_APP;	     /* 0x06 */
367c18ec02fSPetter Reinholdtsen 	req.msg.cmd	     = IPMI_SET_USER_NAME;   /* 0x45 */
368c18ec02fSPetter Reinholdtsen 	req.msg.data     = msg_data;
369c18ec02fSPetter Reinholdtsen 	req.msg.data_len = sizeof(msg_data);
370c18ec02fSPetter Reinholdtsen 	memset(msg_data, 0, sizeof(msg_data));
371c18ec02fSPetter Reinholdtsen 
372c18ec02fSPetter Reinholdtsen 	/* The channel number will remain constant throughout this function */
373c18ec02fSPetter Reinholdtsen 	msg_data[0] = user_id;
374c18ec02fSPetter Reinholdtsen 	strncpy((char *)(msg_data + 1), name, strlen(name));
375c18ec02fSPetter Reinholdtsen 
376c18ec02fSPetter Reinholdtsen 	rsp = intf->sendrecv(intf, &req);
377c18ec02fSPetter Reinholdtsen 
378c18ec02fSPetter Reinholdtsen 	if (rsp == NULL) {
379c18ec02fSPetter Reinholdtsen 		lprintf(LOG_ERR, "Set User Name command failed (user %d, name %s)",
380c18ec02fSPetter Reinholdtsen 			user_id, name);
381c18ec02fSPetter Reinholdtsen 		return -1;
382c18ec02fSPetter Reinholdtsen 	}
383c18ec02fSPetter Reinholdtsen 	if (rsp->ccode > 0) {
384c18ec02fSPetter Reinholdtsen 		lprintf(LOG_ERR, "Set User Name command failed (user %d, name %s): %s",
385c18ec02fSPetter Reinholdtsen 			user_id, name, val2str(rsp->ccode, completion_code_vals));
386c18ec02fSPetter Reinholdtsen 		return -1;
387c18ec02fSPetter Reinholdtsen 	}
388c18ec02fSPetter Reinholdtsen 
389c18ec02fSPetter Reinholdtsen 	return 0;
390c18ec02fSPetter Reinholdtsen }
391c18ec02fSPetter Reinholdtsen 
39266eee40dSZdenek Styblik /* ipmi_user_test_password - Call _ipmi_set_user_password() with operation bit
39366eee40dSZdenek Styblik  * set to test password and interpret result.
394c18ec02fSPetter Reinholdtsen  */
395c18ec02fSPetter Reinholdtsen static int
ipmi_user_test_password(struct ipmi_intf * intf,uint8_t user_id,const char * password,uint8_t is_twenty_byte_password)39666eee40dSZdenek Styblik ipmi_user_test_password(struct ipmi_intf *intf, uint8_t user_id,
39766eee40dSZdenek Styblik 		const char *password, uint8_t is_twenty_byte_password)
398c18ec02fSPetter Reinholdtsen {
39966eee40dSZdenek Styblik 	int ret = 0;
40066eee40dSZdenek Styblik 	ret = _ipmi_set_user_password(intf, user_id,
40166eee40dSZdenek Styblik 			IPMI_PASSWORD_TEST_PASSWORD, password,
402c18ec02fSPetter Reinholdtsen 			is_twenty_byte_password);
403c18ec02fSPetter Reinholdtsen 
404c18ec02fSPetter Reinholdtsen 	switch (ret) {
405c18ec02fSPetter Reinholdtsen 	case 0:
406c18ec02fSPetter Reinholdtsen 		printf("Success\n");
407c18ec02fSPetter Reinholdtsen 		break;
408c18ec02fSPetter Reinholdtsen 	case 0x80:
409c18ec02fSPetter Reinholdtsen 		printf("Failure: password incorrect\n");
410c18ec02fSPetter Reinholdtsen 		break;
411c18ec02fSPetter Reinholdtsen 	case 0x81:
412c18ec02fSPetter Reinholdtsen 		printf("Failure: wrong password size\n");
413c18ec02fSPetter Reinholdtsen 		break;
414c18ec02fSPetter Reinholdtsen 	default:
415c18ec02fSPetter Reinholdtsen 		printf("Unknown error\n");
416c18ec02fSPetter Reinholdtsen 	}
417c18ec02fSPetter Reinholdtsen 
418c18ec02fSPetter Reinholdtsen 	return ((ret == 0) ? 0 : -1);
419c18ec02fSPetter Reinholdtsen }
420c18ec02fSPetter Reinholdtsen 
421c18ec02fSPetter Reinholdtsen 
422c18ec02fSPetter Reinholdtsen /*
423c18ec02fSPetter Reinholdtsen  * print_user_usage
424c18ec02fSPetter Reinholdtsen  */
425c18ec02fSPetter Reinholdtsen static void
print_user_usage(void)426c18ec02fSPetter Reinholdtsen print_user_usage(void)
427c18ec02fSPetter Reinholdtsen {
4281d1ce49bSZdenek Styblik 	lprintf(LOG_NOTICE,
4291d1ce49bSZdenek Styblik "User Commands:");
4301d1ce49bSZdenek Styblik 	lprintf(LOG_NOTICE,
4311d1ce49bSZdenek Styblik "               summary      [<channel number>]");
4321d1ce49bSZdenek Styblik 	lprintf(LOG_NOTICE,
4331d1ce49bSZdenek Styblik "               list         [<channel number>]");
4341d1ce49bSZdenek Styblik 	lprintf(LOG_NOTICE,
4351d1ce49bSZdenek Styblik "               set name     <user id> <username>");
4361d1ce49bSZdenek Styblik 	lprintf(LOG_NOTICE,
437ad77da20SZdenek Styblik "               set password <user id> [<password> <16|20>]");
4381d1ce49bSZdenek Styblik 	lprintf(LOG_NOTICE,
4391d1ce49bSZdenek Styblik "               disable      <user id>");
4401d1ce49bSZdenek Styblik 	lprintf(LOG_NOTICE,
4411d1ce49bSZdenek Styblik "               enable       <user id>");
442c18ec02fSPetter Reinholdtsen 	lprintf(LOG_NOTICE,
443c18ec02fSPetter Reinholdtsen "               priv         <user id> <privilege level> [<channel number>]");
4441d1ce49bSZdenek Styblik 	lprintf(LOG_NOTICE,
4451d1ce49bSZdenek Styblik "                     Privilege levels:");
4461d1ce49bSZdenek Styblik 	lprintf(LOG_NOTICE,
4471d1ce49bSZdenek Styblik "                      * 0x1 - Callback");
4481d1ce49bSZdenek Styblik 	lprintf(LOG_NOTICE,
4491d1ce49bSZdenek Styblik "                      * 0x2 - User");
4501d1ce49bSZdenek Styblik 	lprintf(LOG_NOTICE,
4511d1ce49bSZdenek Styblik "                      * 0x3 - Operator");
4521d1ce49bSZdenek Styblik 	lprintf(LOG_NOTICE,
4531d1ce49bSZdenek Styblik "                      * 0x4 - Administrator");
4541d1ce49bSZdenek Styblik 	lprintf(LOG_NOTICE,
4551d1ce49bSZdenek Styblik "                      * 0x5 - OEM Proprietary");
4561d1ce49bSZdenek Styblik 	lprintf(LOG_NOTICE,
4571d1ce49bSZdenek Styblik "                      * 0xF - No Access");
4581d1ce49bSZdenek Styblik 	lprintf(LOG_NOTICE, "");
4591d1ce49bSZdenek Styblik 	lprintf(LOG_NOTICE,
4601d1ce49bSZdenek Styblik "               test         <user id> <16|20> [<password]>");
4611d1ce49bSZdenek Styblik 	lprintf(LOG_NOTICE, "");
462c18ec02fSPetter Reinholdtsen }
463c18ec02fSPetter Reinholdtsen 
464c18ec02fSPetter Reinholdtsen 
465c18ec02fSPetter Reinholdtsen const char *
ipmi_user_build_password_prompt(uint8_t user_id)466c18ec02fSPetter Reinholdtsen ipmi_user_build_password_prompt(uint8_t user_id)
467c18ec02fSPetter Reinholdtsen {
468c18ec02fSPetter Reinholdtsen 	static char prompt[128];
469c18ec02fSPetter Reinholdtsen 	memset(prompt, 0, 128);
470c18ec02fSPetter Reinholdtsen 	snprintf(prompt, 128, "Password for user %d: ", user_id);
471c18ec02fSPetter Reinholdtsen 	return prompt;
472c18ec02fSPetter Reinholdtsen }
473c18ec02fSPetter Reinholdtsen 
474befb2149SZdenek Styblik /* ask_password - ask user for password
475befb2149SZdenek Styblik  *
476befb2149SZdenek Styblik  * @user_id: User ID which will be built-in into text
477befb2149SZdenek Styblik  *
478befb2149SZdenek Styblik  * @returns pointer to char with password
479befb2149SZdenek Styblik  */
480befb2149SZdenek Styblik char *
ask_password(uint8_t user_id)481befb2149SZdenek Styblik ask_password(uint8_t user_id)
482befb2149SZdenek Styblik {
483befb2149SZdenek Styblik 	const char *password_prompt =
484befb2149SZdenek Styblik 		ipmi_user_build_password_prompt(user_id);
485befb2149SZdenek Styblik # ifdef HAVE_GETPASSPHRASE
486befb2149SZdenek Styblik 	return getpassphrase(password_prompt);
487befb2149SZdenek Styblik # else
488befb2149SZdenek Styblik 	return (char*)getpass(password_prompt);
489befb2149SZdenek Styblik # endif
490befb2149SZdenek Styblik }
491befb2149SZdenek Styblik 
492c18ec02fSPetter Reinholdtsen int
ipmi_user_summary(struct ipmi_intf * intf,int argc,char ** argv)4934d3decc4SZdenek Styblik ipmi_user_summary(struct ipmi_intf *intf, int argc, char **argv)
494c18ec02fSPetter Reinholdtsen {
4953c34aa0eSZdenek Styblik 	/* Summary*/
496c18ec02fSPetter Reinholdtsen 	uint8_t channel;
4973c34aa0eSZdenek Styblik 	if (argc == 1) {
498c18ec02fSPetter Reinholdtsen 		channel = 0x0E; /* Ask about the current channel */
4992aa5d8c9SZdenek Styblik 	} else if (argc == 2) {
500140add9dSZdenek Styblik 		if (is_ipmi_channel_num(argv[1], &channel) != 0) {
501c18ec02fSPetter Reinholdtsen 			return (-1);
502c18ec02fSPetter Reinholdtsen 		}
5033c34aa0eSZdenek Styblik 	} else {
504c18ec02fSPetter Reinholdtsen 		print_user_usage();
505f8ce85eeSZdenek Styblik 		return (-1);
506c18ec02fSPetter Reinholdtsen 	}
5074d3decc4SZdenek Styblik 	return ipmi_print_user_summary(intf, channel);
5084d3decc4SZdenek Styblik }
5094d3decc4SZdenek Styblik 
5104d3decc4SZdenek Styblik int
ipmi_user_list(struct ipmi_intf * intf,int argc,char ** argv)5114d3decc4SZdenek Styblik ipmi_user_list(struct ipmi_intf *intf, int argc, char **argv)
5124d3decc4SZdenek Styblik {
5133c34aa0eSZdenek Styblik 	/* List */
514c18ec02fSPetter Reinholdtsen 	uint8_t channel;
5153c34aa0eSZdenek Styblik 	if (argc == 1) {
516c18ec02fSPetter Reinholdtsen 		channel = 0x0E; /* Ask about the current channel */
5173c34aa0eSZdenek Styblik 	} else if (argc == 2) {
518140add9dSZdenek Styblik 		if (is_ipmi_channel_num(argv[1], &channel) != 0) {
519c18ec02fSPetter Reinholdtsen 			return (-1);
520c18ec02fSPetter Reinholdtsen 		}
5213c34aa0eSZdenek Styblik 	} else {
522c18ec02fSPetter Reinholdtsen 		print_user_usage();
523f8ce85eeSZdenek Styblik 		return (-1);
524c18ec02fSPetter Reinholdtsen 	}
5254d3decc4SZdenek Styblik 	return ipmi_print_user_list(intf, channel);
5264d3decc4SZdenek Styblik }
5274d3decc4SZdenek Styblik 
5284d3decc4SZdenek Styblik int
ipmi_user_test(struct ipmi_intf * intf,int argc,char ** argv)5294d3decc4SZdenek Styblik ipmi_user_test(struct ipmi_intf *intf, int argc, char **argv)
5304d3decc4SZdenek Styblik {
5313c34aa0eSZdenek Styblik 	/* Test */
532c18ec02fSPetter Reinholdtsen 	char *password = NULL;
533c18ec02fSPetter Reinholdtsen 	int password_length = 0;
534c18ec02fSPetter Reinholdtsen 	uint8_t user_id = 0;
5352aa5d8c9SZdenek Styblik 	/* a little irritating, isn't it */
5362aa5d8c9SZdenek Styblik 	if (argc != 3 && argc != 4) {
5372aa5d8c9SZdenek Styblik 		print_user_usage();
538f8ce85eeSZdenek Styblik 		return (-1);
5392aa5d8c9SZdenek Styblik 	}
540c18ec02fSPetter Reinholdtsen 	if (is_ipmi_user_id(argv[1], &user_id)) {
541c18ec02fSPetter Reinholdtsen 		return (-1);
542c18ec02fSPetter Reinholdtsen 	}
543c18ec02fSPetter Reinholdtsen 	if (str2int(argv[2], &password_length) != 0
544c18ec02fSPetter Reinholdtsen 			|| (password_length != 16 && password_length != 20)) {
545c18ec02fSPetter Reinholdtsen 		lprintf(LOG_ERR,
546c18ec02fSPetter Reinholdtsen 				"Given password length '%s' is invalid.",
547c18ec02fSPetter Reinholdtsen 				argv[2]);
548c18ec02fSPetter Reinholdtsen 		lprintf(LOG_ERR, "Expected value is either 16 or 20.");
549c18ec02fSPetter Reinholdtsen 		return (-1);
550c18ec02fSPetter Reinholdtsen 	}
5513c34aa0eSZdenek Styblik 	if (argc == 3) {
552c18ec02fSPetter Reinholdtsen 		/* We need to prompt for a password */
553befb2149SZdenek Styblik 		password = ask_password(user_id);
554c18ec02fSPetter Reinholdtsen 		if (password == NULL) {
555c18ec02fSPetter Reinholdtsen 			lprintf(LOG_ERR, "ipmitool: malloc failure");
556f8ce85eeSZdenek Styblik 			return (-1);
557c18ec02fSPetter Reinholdtsen 		}
5583c34aa0eSZdenek Styblik 	} else {
559befb2149SZdenek Styblik 		password = argv[3];
560c18ec02fSPetter Reinholdtsen 	}
561befb2149SZdenek Styblik 	return ipmi_user_test_password(intf,
562c18ec02fSPetter Reinholdtsen 					 user_id,
563c18ec02fSPetter Reinholdtsen 					 password,
564c18ec02fSPetter Reinholdtsen 					 password_length == 20);
5654d3decc4SZdenek Styblik }
5664d3decc4SZdenek Styblik 
5674d3decc4SZdenek Styblik int
ipmi_user_priv(struct ipmi_intf * intf,int argc,char ** argv)5684d3decc4SZdenek Styblik ipmi_user_priv(struct ipmi_intf *intf, int argc, char **argv)
5694d3decc4SZdenek Styblik {
57012b85b3cSZdenek Styblik 	struct user_access_t user_access = {0};
571708be8bcSZdenek Styblik 	int ccode = 0;
5724d3decc4SZdenek Styblik 
5734d3decc4SZdenek Styblik 	if (argc != 3 && argc != 4) {
5744d3decc4SZdenek Styblik 		print_user_usage();
5754d3decc4SZdenek Styblik 		return (-1);
5764d3decc4SZdenek Styblik 	}
5774d3decc4SZdenek Styblik 	if (argc == 4) {
578708be8bcSZdenek Styblik 		if (is_ipmi_channel_num(argv[3], &user_access.channel) != 0) {
5794d3decc4SZdenek Styblik 			return (-1);
5804d3decc4SZdenek Styblik 		}
581708be8bcSZdenek Styblik 	} else {
582708be8bcSZdenek Styblik 		/* Use channel running on */
583708be8bcSZdenek Styblik 		user_access.channel = 0x0E;
5844d3decc4SZdenek Styblik 	}
585708be8bcSZdenek Styblik 	if (is_ipmi_user_priv_limit(argv[2], &user_access.privilege_limit) != 0
586708be8bcSZdenek Styblik 			|| is_ipmi_user_id(argv[1], &user_access.user_id) != 0) {
5874d3decc4SZdenek Styblik 		return (-1);
5884d3decc4SZdenek Styblik 	}
589708be8bcSZdenek Styblik 	ccode = _ipmi_set_user_access(intf, &user_access, 1);
590708be8bcSZdenek Styblik 	if (eval_ccode(ccode) != 0) {
591708be8bcSZdenek Styblik 		lprintf(LOG_ERR, "Set Privilege Level command failed (user %d)",
592708be8bcSZdenek Styblik 				user_access.user_id);
593708be8bcSZdenek Styblik 		return (-1);
594708be8bcSZdenek Styblik 	} else {
595708be8bcSZdenek Styblik 		printf("Set Privilege Level command successful (user %d)",
596708be8bcSZdenek Styblik 				user_access.user_id);
597708be8bcSZdenek Styblik 		return 0;
598708be8bcSZdenek Styblik 	}
5994d3decc4SZdenek Styblik }
6004d3decc4SZdenek Styblik 
6014d3decc4SZdenek Styblik int
ipmi_user_mod(struct ipmi_intf * intf,int argc,char ** argv)6024d3decc4SZdenek Styblik ipmi_user_mod(struct ipmi_intf *intf, int argc, char **argv)
6034d3decc4SZdenek Styblik {
6044d3decc4SZdenek Styblik 	/* Disable / Enable */
6054d3decc4SZdenek Styblik 	uint8_t user_id;
6064d3decc4SZdenek Styblik 	uint8_t operation;
6074d3decc4SZdenek Styblik 
6084d3decc4SZdenek Styblik 	if (argc != 2) {
6094d3decc4SZdenek Styblik 		print_user_usage();
6104d3decc4SZdenek Styblik 		return (-1);
6114d3decc4SZdenek Styblik 	}
6124d3decc4SZdenek Styblik 	if (is_ipmi_user_id(argv[1], &user_id)) {
6134d3decc4SZdenek Styblik 		return (-1);
6144d3decc4SZdenek Styblik 	}
6154d3decc4SZdenek Styblik 	operation = (strncmp(argv[0], "disable", 7) == 0) ?
6164d3decc4SZdenek Styblik 		IPMI_PASSWORD_DISABLE_USER : IPMI_PASSWORD_ENABLE_USER;
6174d3decc4SZdenek Styblik 
61866eee40dSZdenek Styblik 	return _ipmi_set_user_password(intf, user_id, operation,
61966eee40dSZdenek Styblik 			(char *)NULL, 0);
6204d3decc4SZdenek Styblik }
6214d3decc4SZdenek Styblik 
6224d3decc4SZdenek Styblik int
ipmi_user_password(struct ipmi_intf * intf,int argc,char ** argv)6234d3decc4SZdenek Styblik ipmi_user_password(struct ipmi_intf *intf, int argc, char **argv)
6244d3decc4SZdenek Styblik {
625c18ec02fSPetter Reinholdtsen 	char *password = NULL;
62666eee40dSZdenek Styblik 	int ccode = 0;
627ad77da20SZdenek Styblik 	uint8_t password_type = 16;
628c18ec02fSPetter Reinholdtsen 	uint8_t user_id = 0;
629c18ec02fSPetter Reinholdtsen 	if (is_ipmi_user_id(argv[2], &user_id)) {
630c18ec02fSPetter Reinholdtsen 		return (-1);
631c18ec02fSPetter Reinholdtsen 	}
632c18ec02fSPetter Reinholdtsen 
6333c34aa0eSZdenek Styblik 	if (argc == 3) {
634c18ec02fSPetter Reinholdtsen 		/* We need to prompt for a password */
635c18ec02fSPetter Reinholdtsen 		char *tmp;
636befb2149SZdenek Styblik 		password = ask_password(user_id);
637c18ec02fSPetter Reinholdtsen 		if (password == NULL) {
638c18ec02fSPetter Reinholdtsen 			lprintf(LOG_ERR, "ipmitool: malloc failure");
639f8ce85eeSZdenek Styblik 			return (-1);
640c18ec02fSPetter Reinholdtsen 		}
641befb2149SZdenek Styblik 		tmp = ask_password(user_id);
642c18ec02fSPetter Reinholdtsen 		if (tmp == NULL) {
643c18ec02fSPetter Reinholdtsen 			lprintf(LOG_ERR, "ipmitool: malloc failure");
644c18ec02fSPetter Reinholdtsen 			return (-1);
645c18ec02fSPetter Reinholdtsen 		}
646c18ec02fSPetter Reinholdtsen 		if (strlen(password) != strlen(tmp)
647c18ec02fSPetter Reinholdtsen 				|| strncmp(password, tmp, strlen(tmp))) {
648c18ec02fSPetter Reinholdtsen 			lprintf(LOG_ERR, "Passwords do not match.");
649f8ce85eeSZdenek Styblik 			return (-1);
650c18ec02fSPetter Reinholdtsen 		}
651c18ec02fSPetter Reinholdtsen 	} else {
652befb2149SZdenek Styblik 		password = argv[3];
653ad77da20SZdenek Styblik 		if (argc > 4) {
654ad77da20SZdenek Styblik 			if ((str2uchar(argv[4], &password_type) != 0)
655ad77da20SZdenek Styblik 					|| (password_type != 16 && password_type != 20)) {
656ad77da20SZdenek Styblik 				lprintf(LOG_ERR, "Invalid password length '%s'", argv[4]);
657ad77da20SZdenek Styblik 				return (-1);
658ad77da20SZdenek Styblik 			}
659ad77da20SZdenek Styblik 		} else {
660ad77da20SZdenek Styblik 			password_type = 16;
661ad77da20SZdenek Styblik 		}
662c18ec02fSPetter Reinholdtsen 	}
663c18ec02fSPetter Reinholdtsen 
664c18ec02fSPetter Reinholdtsen 	if (password == NULL) {
665c18ec02fSPetter Reinholdtsen 		lprintf(LOG_ERR, "Unable to parse password argument.");
666f8ce85eeSZdenek Styblik 		return (-1);
6673c34aa0eSZdenek Styblik 	} else if (strlen(password) > 20) {
668c18ec02fSPetter Reinholdtsen 		lprintf(LOG_ERR, "Password is too long (> 20 bytes)");
669f8ce85eeSZdenek Styblik 		return (-1);
670c18ec02fSPetter Reinholdtsen 	}
671c18ec02fSPetter Reinholdtsen 
67266eee40dSZdenek Styblik 	ccode = _ipmi_set_user_password(intf, user_id,
67366eee40dSZdenek Styblik 			IPMI_PASSWORD_SET_PASSWORD, password,
674ad77da20SZdenek Styblik 			password_type > 16);
67566eee40dSZdenek Styblik 	if (eval_ccode(ccode) != 0) {
67666eee40dSZdenek Styblik 		lprintf(LOG_ERR, "Set User Password command failed (user %d)",
67766eee40dSZdenek Styblik 			user_id);
67866eee40dSZdenek Styblik 		return (-1);
67966eee40dSZdenek Styblik 	} else {
68066eee40dSZdenek Styblik 		printf("Set User Password command successful (user %d)\n",
68166eee40dSZdenek Styblik 				user_id);
68266eee40dSZdenek Styblik 		return 0;
68366eee40dSZdenek Styblik 	}
6844d3decc4SZdenek Styblik }
6854d3decc4SZdenek Styblik 
6864d3decc4SZdenek Styblik int
ipmi_user_name(struct ipmi_intf * intf,int argc,char ** argv)6874d3decc4SZdenek Styblik ipmi_user_name(struct ipmi_intf *intf, int argc, char **argv)
6884d3decc4SZdenek Styblik {
6893c34aa0eSZdenek Styblik 	/* Set Name */
690c18ec02fSPetter Reinholdtsen 	uint8_t user_id = 0;
6913c34aa0eSZdenek Styblik 	if (argc != 4) {
692c18ec02fSPetter Reinholdtsen 		print_user_usage();
693f8ce85eeSZdenek Styblik 		return (-1);
694c18ec02fSPetter Reinholdtsen 	}
695c18ec02fSPetter Reinholdtsen 	if (is_ipmi_user_id(argv[2], &user_id)) {
696c18ec02fSPetter Reinholdtsen 		return (-1);
697c18ec02fSPetter Reinholdtsen 	}
6983c34aa0eSZdenek Styblik 	if (strlen(argv[3]) > 16) {
699c18ec02fSPetter Reinholdtsen 		lprintf(LOG_ERR, "Username is too long (> 16 bytes)");
700f8ce85eeSZdenek Styblik 		return (-1);
701c18ec02fSPetter Reinholdtsen 	}
702c18ec02fSPetter Reinholdtsen 
7034d3decc4SZdenek Styblik 	return ipmi_user_set_username(intf, user_id, argv[3]);
7044d3decc4SZdenek Styblik }
7054d3decc4SZdenek Styblik 
7064d3decc4SZdenek Styblik /*
7074d3decc4SZdenek Styblik  * ipmi_user_main
7084d3decc4SZdenek Styblik  *
7094d3decc4SZdenek Styblik  * Upon entry to this function argv should contain our arguments
7104d3decc4SZdenek Styblik  * specific to this subcommand
7114d3decc4SZdenek Styblik  */
7124d3decc4SZdenek Styblik int
ipmi_user_main(struct ipmi_intf * intf,int argc,char ** argv)7134d3decc4SZdenek Styblik ipmi_user_main(struct ipmi_intf *intf, int argc, char **argv)
7144d3decc4SZdenek Styblik {
7154d3decc4SZdenek Styblik 	if (argc == 0) {
7164d3decc4SZdenek Styblik 		lprintf(LOG_ERR, "Not enough parameters given.");
7174d3decc4SZdenek Styblik 		print_user_usage();
7184d3decc4SZdenek Styblik 		return (-1);
7194d3decc4SZdenek Styblik 	}
7204d3decc4SZdenek Styblik 	if (strncmp(argv[0], "help", 4) == 0) {
7214d3decc4SZdenek Styblik 		/* Help */
7224d3decc4SZdenek Styblik 		print_user_usage();
7234d3decc4SZdenek Styblik 		return 0;
7244d3decc4SZdenek Styblik 	} else if (strncmp(argv[0], "summary", 7) == 0) {
7254d3decc4SZdenek Styblik 		return ipmi_user_summary(intf, argc, argv);
7264d3decc4SZdenek Styblik 	} else if (strncmp(argv[0], "list", 4) == 0) {
7274d3decc4SZdenek Styblik 		return ipmi_user_list(intf, argc, argv);
7284d3decc4SZdenek Styblik 	} else if (strncmp(argv[0], "test", 4) == 0) {
7294d3decc4SZdenek Styblik 		return ipmi_user_test(intf, argc, argv);
7304d3decc4SZdenek Styblik 	} else if (strncmp(argv[0], "set", 3) == 0) {
7314d3decc4SZdenek Styblik 		/* Set */
7324d3decc4SZdenek Styblik 		if ((argc >= 3)
7334d3decc4SZdenek Styblik 				&& (strncmp("password", argv[1], 8) == 0)) {
7344d3decc4SZdenek Styblik 			return ipmi_user_password(intf, argc, argv);
7354d3decc4SZdenek Styblik 		} else if ((argc >= 2)
7364d3decc4SZdenek Styblik 				&& (strncmp("name", argv[1], 4) == 0)) {
7374d3decc4SZdenek Styblik 			return ipmi_user_name(intf, argc, argv);
7383c34aa0eSZdenek Styblik 		} else {
739c18ec02fSPetter Reinholdtsen 			print_user_usage();
740f8ce85eeSZdenek Styblik 			return (-1);
741c18ec02fSPetter Reinholdtsen 		}
7423c34aa0eSZdenek Styblik 	} else if (strncmp(argv[0], "priv", 4) == 0) {
7434d3decc4SZdenek Styblik 		return ipmi_user_priv(intf, argc, argv);
7443c34aa0eSZdenek Styblik 	} else if ((strncmp(argv[0], "disable", 7) == 0)
7453c34aa0eSZdenek Styblik 			|| (strncmp(argv[0], "enable",  6) == 0)) {
7464d3decc4SZdenek Styblik 		return ipmi_user_mod(intf, argc, argv);
7473c34aa0eSZdenek Styblik 	} else {
748c18ec02fSPetter Reinholdtsen 		lprintf(LOG_ERR, "Invalid user command: '%s'\n", argv[0]);
749c18ec02fSPetter Reinholdtsen 		print_user_usage();
7504d3decc4SZdenek Styblik 		return (-1);
751c18ec02fSPetter Reinholdtsen 	}
752c18ec02fSPetter Reinholdtsen }
753