With the --daemon / SSL init reordering in da9b292733, we fail if we
daemonize first and then try to ask for a private key passphrase (or,
for that matter, username+password if --auth-nocache is set) - but
no meaningful error message was printed, instead depending on operating
system and library versions, either we looped around "ssl init failed"
or died with an unspecified "fatal error".
So: check if get_user_pass_cr() is called in a context that needs
"from_stdin", but both stdin and stderr are not connected to a tty
device (which getpass() needs). In that case, print a meaningful
error message pointing to --askpass, and die.
Trac #574 and #576
Signed-off-by: Gert Doering <gert@greenie.muc.de>
Acked-by: Steffan Karger <steffan.karger@fox-it.com>
Message-Id: <1436814607-16707-1-git-send-email-gert@greenie.muc.de>
URL: http://article.gmane.org/gmane.network.openvpn.devel/9916
(cherry picked from commit 079e5b9c13bf81d7afc6f932b5417d2f08f8e64b)
... | ... |
@@ -1088,6 +1088,10 @@ get_user_pass_cr (struct user_pass *up, |
1088 | 1088 |
*/ |
1089 | 1089 |
else if (from_stdin) |
1090 | 1090 |
{ |
1091 |
+ /* did we --daemon'ize before asking for passwords? */ |
|
1092 |
+ if ( !isatty(0) && !isatty(2) ) |
|
1093 |
+ { msg(M_FATAL, "neither stdin nor stderr are a tty device, can't ask for %s password. If you used --daemon, you need to use --askpass to make passphrase-protected keys work, and you can not use --auth-nocache.", prefix ); } |
|
1094 |
+ |
|
1091 | 1095 |
#ifdef ENABLE_CLIENT_CR |
1092 | 1096 |
if (auth_challenge && (flags & GET_USER_PASS_DYNAMIC_CHALLENGE)) |
1093 | 1097 |
{ |