X-Git-Url: https://jfr.im/git/irc/rqf/shadowircd.git/blobdiff_plain/e4c72f7919f8f467471f59166f5bbfee8a5429bb..7e6c9180dadba56c2d1d745b09b1cce65700cb52:/modules/m_challenge.c diff --git a/modules/m_challenge.c b/modules/m_challenge.c index 92f19d3..5b56cfe 100644 --- a/modules/m_challenge.c +++ b/modules/m_challenge.c @@ -237,6 +237,25 @@ m_challenge(struct Client *client_p, struct Client *source_p, int parc, const ch return 0; } + if (oper_p->certfp != NULL) + { + if (source_p->certfp == NULL || strcasecmp(source_p->certfp, oper_p->certfp)) + { + sendto_one_numeric(source_p, ERR_NOOPERHOST, form_str(ERR_NOOPERHOST)); + ilog(L_FOPER, "FAILED OPER (%s) by (%s!%s@%s) (%s) -- client certificate fingerprint mismatch", + parv[1], source_p->name, + source_p->username, source_p->host, source_p->sockhost); + + if(ConfigFileEntry.failed_oper_notice) + { + sendto_realops_snomask(SNO_GENERAL, L_ALL, + "Failed OPER attempt - client certificate fingerprint mismatch by %s (%s@%s)", + source_p->name, source_p->username, source_p->host); + } + return 0; + } + } + if(!generate_challenge(&challenge, &(source_p->localClient->challenge), oper_p->rsa_pubkey)) { char *chal = challenge;