Compare commits
174 commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
c2ce5811ff | ||
|
|
fe6911cd3d | ||
|
|
53c3b9de3c | ||
|
|
fb94528750 | ||
|
|
a0a34794e3 | ||
|
|
5c0a004494 | ||
|
|
f2bc777d63 | ||
|
|
099df268ce | ||
|
|
9e0ac6c616 | ||
|
|
4c1f565dfa | ||
|
|
9767c1c24e | ||
|
|
d71494ca6c | ||
|
|
b45374269b | ||
|
|
5cc4a0d8bc | ||
|
|
87d784ddd7 | ||
|
|
1ed0e3a2d8 | ||
|
|
0fe5c327ec | ||
|
|
f5676fd233 | ||
|
|
ae2cf9bef3 | ||
|
|
a2c04215f0 | ||
|
|
0b340d0ef3 | ||
|
|
7058594eab | ||
|
|
ec957f5711 | ||
|
|
dca288bae2 | ||
|
|
4a4fd39d5e | ||
|
|
4eee9bbb50 | ||
|
|
f0b4f85e9e | ||
|
|
f29ff7186e | ||
|
|
ba968605e7 | ||
|
|
f003c0755c | ||
|
|
a206938c15 | ||
|
|
95288a2fb9 | ||
|
|
3668746b8f | ||
|
|
603ad7099e | ||
|
|
56cee506e7 | ||
|
|
c13bf943d8 | ||
|
|
0c2f5dcbe5 | ||
|
|
f5aa40a4a2 | ||
|
|
440331a1e4 | ||
|
|
3907ec760c | ||
|
|
e138eb8125 | ||
|
|
601b89387b | ||
|
|
e9188f0caa | ||
|
|
c25a51c969 | ||
|
|
04513849e3 | ||
|
|
fc958d4773 | ||
|
|
29a69aee06 | ||
|
|
0ceb166d96 | ||
|
|
2ef37ab30d | ||
|
|
970430cbff | ||
|
|
f858c7e550 | ||
|
|
b998554176 | ||
|
|
75355e197a | ||
|
|
ad88d4fd50 | ||
|
|
70255ea5b0 | ||
|
|
91c904e5df | ||
|
|
ca196a9d6b | ||
|
|
03e8c69837 | ||
|
|
c4016b4e4c | ||
|
|
2484569caa | ||
|
|
6a2eeb9666 | ||
|
|
af96dc0c6c | ||
|
|
c5044b0741 | ||
|
|
91bbbda93f | ||
|
|
4df0096f20 | ||
|
|
65a1e5607c | ||
|
|
72e80d67ef | ||
|
|
c4150c67d1 | ||
|
|
904d264a41 | ||
|
|
69e05d5e39 | ||
|
|
e9fb111a11 | ||
|
|
1c2362203e | ||
|
|
c183c8de7d | ||
|
|
7ef4909316 | ||
|
|
14c7d0b635 | ||
|
|
002bf4053e | ||
|
|
d67d35a3c6 | ||
|
|
cf3e70c97c | ||
|
|
1c03da79de | ||
|
|
d20ec5d3bc | ||
|
|
ab3f34f0e7 | ||
|
|
3faaf11da7 | ||
|
|
00a0ac8abc | ||
|
|
d3ac4cf9b0 | ||
|
|
35a4aa7b99 | ||
|
|
90bc2e25b3 | ||
|
|
d5839d0511 | ||
|
|
105082cb42 | ||
|
|
0dd40e4ff0 | ||
|
|
042ca4af99 | ||
|
|
54bf131a4a | ||
|
|
ef09340be0 | ||
|
|
327ebd0b26 | ||
|
|
b23f8f6215 | ||
|
|
9fb5239517 | ||
|
|
0da55d6175 | ||
|
|
58924baeb4 | ||
|
|
ed80b08062 | ||
|
|
b783a5421c | ||
|
|
ab7a2a35c2 | ||
|
|
dc8775d11d | ||
|
|
5facc9df4d | ||
|
|
015255764a | ||
|
|
ec1ab43ca2 | ||
|
|
d2da394f67 | ||
|
|
bfdc7c0b7b | ||
|
|
fced14e78a | ||
|
|
7c8b50fca5 | ||
|
|
da77b5dcf8 | ||
|
|
96c0dcc1c7 | ||
|
|
501e298072 | ||
|
|
c06ba2920a | ||
|
|
d7334ebf68 | ||
|
|
1003328588 | ||
|
|
cd0b1d6ba6 | ||
|
|
c59e4a1c67 | ||
|
|
2091f29399 | ||
|
|
4530bb6de9 | ||
|
|
8be5252136 | ||
|
|
d0cfa344c7 | ||
|
|
710f626f12 | ||
|
|
d314641a26 | ||
|
|
86ecb1b3d2 | ||
|
|
b1b925635d | ||
|
|
da1e8dbb3f | ||
|
|
f15271f04d | ||
|
|
80e06352b8 | ||
|
|
e326a52474 | ||
|
|
feaafc07b2 | ||
|
|
3c4e18f2f3 | ||
|
|
49849de329 | ||
|
|
883355750a | ||
|
|
331a9df349 | ||
|
|
dec02b8411 | ||
|
|
102adf5edf | ||
|
|
d370e2a431 | ||
|
|
0963a62bc3 | ||
|
|
a9ccd6fd57 | ||
|
|
19d5d2e504 | ||
|
|
46d8c677ae | ||
|
|
7fca7fd076 | ||
|
|
66ec722479 | ||
|
|
9f3201c4bc | ||
|
|
c262ec69f6 | ||
|
|
4e7e5fe69b | ||
|
|
dd7e9481aa | ||
|
|
5c9732a545 | ||
|
|
bea8330f52 | ||
|
|
bef2ba57a2 | ||
|
|
f6c62d5e63 | ||
|
|
812c07a94f | ||
|
|
0ecf7a0e65 | ||
|
|
3b6955d99e | ||
|
|
48a220a102 | ||
|
|
f287f939a9 | ||
|
|
dd3e136188 | ||
|
|
edfb00e001 | ||
|
|
8fb4697062 | ||
|
|
b3d5b8f719 | ||
|
|
7f642b1512 | ||
|
|
84aac1fa6d | ||
|
|
2496b50d00 | ||
|
|
fd463aed6a | ||
|
|
d6ef09022c | ||
|
|
9d642021d7 | ||
|
|
4aee4bdd71 | ||
|
|
02c0c74c74 | ||
|
|
76d9979dc3 | ||
|
|
4c128ec39a | ||
|
|
b9ea889e2a | ||
|
|
4b8056ef08 | ||
|
|
1404656ded | ||
|
|
cbf35c8b1f | ||
|
|
9ce53b906d |
146 changed files with 25914 additions and 32465 deletions
1
.fmf/version
Normal file
1
.fmf/version
Normal file
|
|
@ -0,0 +1 @@
|
|||
1
|
||||
125
.gitignore
vendored
125
.gitignore
vendored
|
|
@ -1,49 +1,50 @@
|
|||
krb5-1.3.4.tar.gz
|
||||
krb5-1.3.5.tar.gz
|
||||
krb5-1.3.5.tar.gz.asc
|
||||
krb5-1.3.6.tar.gz
|
||||
krb5-1.3.6.tar.gz.asc
|
||||
krb5-1.4.tar.gz
|
||||
krb5-1.4.tar.gz.asc
|
||||
krb5-1.4.1.tar.gz
|
||||
krb5-1.4.1.tar.gz.asc
|
||||
krb5-1.4.2.tar.gz
|
||||
krb5-1.4.2.tar.gz.asc
|
||||
krb5-1.4.3.tar.gz
|
||||
krb5-1.4.3.tar.gz.asc
|
||||
krb5-1.5.tar.gz
|
||||
krb5-1.5.tar.gz.asc
|
||||
krb5-1.6.tar.gz
|
||||
krb5-1.6.tar.gz.asc
|
||||
krb5-1.6-pdf.tar.gz
|
||||
krb5-1.6.1.tar.gz
|
||||
krb5-1.6.1.tar.gz.asc
|
||||
krb5-1.6.1-pdf.tar.gz
|
||||
krb5-1.6.2.tar.gz
|
||||
krb5-1.6.2.tar.gz.asc
|
||||
krb5-1.6.2-pdf.tar.gz
|
||||
krb5-1.6.3.tar.gz
|
||||
krb5-1.6.3.tar.gz.asc
|
||||
krb5-1.6.3-pdf.tar.gz
|
||||
krb5-1.7.tar.gz
|
||||
krb5-1.7.tar.gz.asc
|
||||
krb5-1.7-pdf.tar.gz
|
||||
krb5-1.7.1.tar.gz
|
||||
krb5-1.7.1.tar.gz.asc
|
||||
krb5-1.7.1-pdf.tar.gz
|
||||
krb5-1.8.tar.gz
|
||||
krb5-1.8.tar.gz.asc
|
||||
krb5-appl-1.0.tar.gz
|
||||
krb5-appl-1.0.tar.gz.asc
|
||||
krb5-1.8-pdf.tar.gz
|
||||
krb5-1.8.1.tar.gz
|
||||
krb5-1.8.1.tar.gz.asc
|
||||
krb5-1.8.1-pdf.tar.gz
|
||||
krb5-1.8.2.tar.gz.asc
|
||||
krb5-1.8.2-pdf.tar.gz
|
||||
krb5-1.8.3.tar.gz
|
||||
krb5-1.8.3.tar.gz.asc
|
||||
krb5-1.8.3-pdf.tar.gz
|
||||
/results_krb5
|
||||
/krb5-1.3.4.tar.gz
|
||||
/krb5-1.3.5.tar.gz
|
||||
/krb5-1.3.5.tar.gz.asc
|
||||
/krb5-1.3.6.tar.gz
|
||||
/krb5-1.3.6.tar.gz.asc
|
||||
/krb5-1.4.tar.gz
|
||||
/krb5-1.4.tar.gz.asc
|
||||
/krb5-1.4.1.tar.gz
|
||||
/krb5-1.4.1.tar.gz.asc
|
||||
/krb5-1.4.2.tar.gz
|
||||
/krb5-1.4.2.tar.gz.asc
|
||||
/krb5-1.4.3.tar.gz
|
||||
/krb5-1.4.3.tar.gz.asc
|
||||
/krb5-1.5.tar.gz
|
||||
/krb5-1.5.tar.gz.asc
|
||||
/krb5-1.6.tar.gz
|
||||
/krb5-1.6.tar.gz.asc
|
||||
/krb5-1.6-pdf.tar.gz
|
||||
/krb5-1.6.1.tar.gz
|
||||
/krb5-1.6.1.tar.gz.asc
|
||||
/krb5-1.6.1-pdf.tar.gz
|
||||
/krb5-1.6.2.tar.gz
|
||||
/krb5-1.6.2.tar.gz.asc
|
||||
/krb5-1.6.2-pdf.tar.gz
|
||||
/krb5-1.6.3.tar.gz
|
||||
/krb5-1.6.3.tar.gz.asc
|
||||
/krb5-1.6.3-pdf.tar.gz
|
||||
/krb5-1.7.tar.gz
|
||||
/krb5-1.7.tar.gz.asc
|
||||
/krb5-1.7-pdf.tar.gz
|
||||
/krb5-1.7.1.tar.gz
|
||||
/krb5-1.7.1.tar.gz.asc
|
||||
/krb5-1.7.1-pdf.tar.gz
|
||||
/krb5-1.8.tar.gz
|
||||
/krb5-1.8.tar.gz.asc
|
||||
/krb5-appl-1.0.tar.gz
|
||||
/krb5-appl-1.0.tar.gz.asc
|
||||
/krb5-1.8-pdf.tar.gz
|
||||
/krb5-1.8.1.tar.gz
|
||||
/krb5-1.8.1.tar.gz.asc
|
||||
/krb5-1.8.1-pdf.tar.gz
|
||||
/krb5-1.8.2.tar.gz.asc
|
||||
/krb5-1.8.2-pdf.tar.gz
|
||||
/krb5-1.8.3.tar.gz
|
||||
/krb5-1.8.3.tar.gz.asc
|
||||
/krb5-1.8.3-pdf.tar.gz
|
||||
/krb5-1.9-beta2.tar.gz
|
||||
/krb5-1.9-beta2.tar.gz.asc
|
||||
/krb5-1.9-beta2-pdf.tar.bz2
|
||||
|
|
@ -175,3 +176,35 @@ krb5-1.8.3-pdf.tar.gz
|
|||
/krb5-1.17-pdfs.tar
|
||||
/krb5-1.17.tar.gz
|
||||
/krb5-1.17.tar.gz.asc
|
||||
/krb5-1.17.1.tar.gz
|
||||
/krb5-1.17.1.tar.gz.asc
|
||||
/krb5-1.18-beta1.tar.gz
|
||||
/krb5-1.18-beta1.tar.gz.asc
|
||||
/krb5-1.18-beta2.tar.gz
|
||||
/krb5-1.18-beta2.tar.gz.asc
|
||||
/krb5-1.18.tar.gz
|
||||
/krb5-1.18.tar.gz.asc
|
||||
/krb5-1.18.1.tar.gz
|
||||
/krb5-1.18.1.tar.gz.asc
|
||||
/krb5-1.18.2.tar.gz
|
||||
/krb5-1.18.2.tar.gz.asc
|
||||
/krb5-1.18.3.tar.gz
|
||||
/krb5-1.18.3.tar.gz.asc
|
||||
/krb5-1.19-beta1.tar.gz
|
||||
/krb5-1.19-beta1.tar.gz.asc
|
||||
/krb5-1.19-beta2.tar.gz
|
||||
/krb5-1.19-beta2.tar.gz.asc
|
||||
/krb5-1.19.tar.gz
|
||||
/krb5-1.19.tar.gz.asc
|
||||
/krb5-1.19.1.tar.gz
|
||||
/krb5-1.19.1.tar.gz.asc
|
||||
/krb5-1.19.2.tar.gz
|
||||
/krb5-1.19.2.tar.gz.asc
|
||||
/krb5-1.20.1.tar.gz
|
||||
/krb5-1.20.1.tar.gz.asc
|
||||
/krb5-1.21.tar.gz
|
||||
/krb5-1.21.tar.gz.asc
|
||||
/krb5-1.21.2.tar.gz
|
||||
/krb5-1.21.2.tar.gz.asc
|
||||
/krb5-1.21.3.tar.gz
|
||||
/krb5-1.21.3.tar.gz.asc
|
||||
|
|
|
|||
310
0001-downstream-Revert-Don-t-issue-session-keys-with-depr.patch
Normal file
310
0001-downstream-Revert-Don-t-issue-session-keys-with-depr.patch
Normal file
|
|
@ -0,0 +1,310 @@
|
|||
From 6f7fd964539dfe4a885068f43a91db9738661870 Mon Sep 17 00:00:00 2001
|
||||
From: Julien Rische <jrische@redhat.com>
|
||||
Date: Tue, 9 Jul 2024 11:15:33 +0200
|
||||
Subject: [PATCH] [downstream] Revert "Don't issue session keys with
|
||||
deprecated enctypes"
|
||||
|
||||
This reverts commit 1b57a4d134bbd0e7c52d5885a92eccc815726463.
|
||||
---
|
||||
doc/admin/conf_files/krb5_conf.rst | 12 ------------
|
||||
doc/admin/enctypes.rst | 23 +++-------------------
|
||||
src/include/k5-int.h | 4 ----
|
||||
src/kdc/kdc_util.c | 10 ----------
|
||||
src/lib/krb5/krb/get_in_tkt.c | 31 +++++++++++-------------------
|
||||
src/lib/krb5/krb/init_ctx.c | 10 ----------
|
||||
src/tests/gssapi/t_enctypes.py | 3 +--
|
||||
src/tests/t_etype_info.py | 2 +-
|
||||
src/tests/t_sesskeynego.py | 28 ++-------------------------
|
||||
src/util/k5test.py | 4 ++--
|
||||
10 files changed, 20 insertions(+), 107 deletions(-)
|
||||
|
||||
diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst
|
||||
index ecdf917501..f22d5db11b 100644
|
||||
--- a/doc/admin/conf_files/krb5_conf.rst
|
||||
+++ b/doc/admin/conf_files/krb5_conf.rst
|
||||
@@ -95,18 +95,6 @@ Additionally, krb5.conf may include any of the relations described in
|
||||
|
||||
The libdefaults section may contain any of the following relations:
|
||||
|
||||
-**allow_des3**
|
||||
- Permit the KDC to issue tickets with des3-cbc-sha1 session keys.
|
||||
- In future releases, this flag will allow des3-cbc-sha1 to be used
|
||||
- at all. The default value for this tag is false. (Added in
|
||||
- release 1.21.)
|
||||
-
|
||||
-**allow_rc4**
|
||||
- Permit the KDC to issue tickets with arcfour-hmac session keys.
|
||||
- In future releases, this flag will allow arcfour-hmac to be used
|
||||
- at all. The default value for this tag is false. (Added in
|
||||
- release 1.21.)
|
||||
-
|
||||
**allow_weak_crypto**
|
||||
If this flag is set to false, then weak encryption types (as noted
|
||||
in :ref:`Encryption_types` in :ref:`kdc.conf(5)`) will be filtered
|
||||
diff --git a/doc/admin/enctypes.rst b/doc/admin/enctypes.rst
|
||||
index dce19ad43e..694922c0d9 100644
|
||||
--- a/doc/admin/enctypes.rst
|
||||
+++ b/doc/admin/enctypes.rst
|
||||
@@ -48,15 +48,12 @@ Session key selection
|
||||
The KDC chooses the session key enctype by taking the intersection of
|
||||
its **permitted_enctypes** list, the list of long-term keys for the
|
||||
most recent kvno of the service, and the client's requested list of
|
||||
-enctypes. Starting in krb5-1.21, all services are assumed to support
|
||||
-aes256-cts-hmac-sha1-96; also, des3-cbc-sha1 and arcfour-hmac session
|
||||
-keys will not be issued by default.
|
||||
+enctypes.
|
||||
|
||||
Starting in krb5-1.11, it is possible to set a string attribute on a
|
||||
service principal to control what session key enctypes the KDC may
|
||||
-issue for service tickets for that principal, overriding the service's
|
||||
-long-term keys and the assumption of aes256-cts-hmac-sha1-96 support.
|
||||
-See :ref:`set_string` in :ref:`kadmin(1)` for details.
|
||||
+issue for service tickets for that principal. See :ref:`set_string`
|
||||
+in :ref:`kadmin(1)` for details.
|
||||
|
||||
|
||||
Choosing enctypes for a service
|
||||
@@ -90,20 +87,6 @@ affect how enctypes are chosen.
|
||||
acceptable risk for your environment and the weak enctypes are
|
||||
required for backward compatibility.
|
||||
|
||||
-**allow_des3**
|
||||
- was added in release 1.21 and defaults to *false*. Unless this
|
||||
- flag is set to *true*, the KDC will not issue tickets with
|
||||
- des3-cbc-sha1 session keys. In a future release, this flag will
|
||||
- control whether des3-cbc-sha1 is permitted in similar fashion to
|
||||
- weak enctypes.
|
||||
-
|
||||
-**allow_rc4**
|
||||
- was added in release 1.21 and defaults to *false*. Unless this
|
||||
- flag is set to *true*, the KDC will not issue tickets with
|
||||
- arcfour-hmac session keys. In a future release, this flag will
|
||||
- control whether arcfour-hmac is permitted in similar fashion to
|
||||
- weak enctypes.
|
||||
-
|
||||
**permitted_enctypes**
|
||||
controls the set of enctypes that a service will permit for
|
||||
session keys and for ticket and authenticator encryption. The KDC
|
||||
diff --git a/src/include/k5-int.h b/src/include/k5-int.h
|
||||
index 2f7791b775..1d1c8293f4 100644
|
||||
--- a/src/include/k5-int.h
|
||||
+++ b/src/include/k5-int.h
|
||||
@@ -180,8 +180,6 @@ typedef unsigned char u_char;
|
||||
* matches the variable name. Keep these alphabetized. */
|
||||
#define KRB5_CONF_ACL_FILE "acl_file"
|
||||
#define KRB5_CONF_ADMIN_SERVER "admin_server"
|
||||
-#define KRB5_CONF_ALLOW_DES3 "allow_des3"
|
||||
-#define KRB5_CONF_ALLOW_RC4 "allow_rc4"
|
||||
#define KRB5_CONF_ALLOW_WEAK_CRYPTO "allow_weak_crypto"
|
||||
#define KRB5_CONF_AUTH_TO_LOCAL "auth_to_local"
|
||||
#define KRB5_CONF_AUTH_TO_LOCAL_NAMES "auth_to_local_names"
|
||||
@@ -1240,8 +1238,6 @@ struct _krb5_context {
|
||||
struct _kdb_log_context *kdblog_context;
|
||||
|
||||
krb5_boolean allow_weak_crypto;
|
||||
- krb5_boolean allow_des3;
|
||||
- krb5_boolean allow_rc4;
|
||||
krb5_boolean ignore_acceptor_hostname;
|
||||
krb5_boolean enforce_ok_as_delegate;
|
||||
enum dns_canonhost dns_canonicalize_hostname;
|
||||
diff --git a/src/kdc/kdc_util.c b/src/kdc/kdc_util.c
|
||||
index e54cc751f9..75e04b73db 100644
|
||||
--- a/src/kdc/kdc_util.c
|
||||
+++ b/src/kdc/kdc_util.c
|
||||
@@ -1088,16 +1088,6 @@ select_session_keytype(krb5_context context, krb5_db_entry *server,
|
||||
if (!krb5_is_permitted_enctype(context, ktype[i]))
|
||||
continue;
|
||||
|
||||
- /*
|
||||
- * Prevent these deprecated enctypes from being used as session keys
|
||||
- * unless they are explicitly allowed. In the future they will be more
|
||||
- * comprehensively disabled and eventually removed.
|
||||
- */
|
||||
- if (ktype[i] == ENCTYPE_DES3_CBC_SHA1 && !context->allow_des3)
|
||||
- continue;
|
||||
- if (ktype[i] == ENCTYPE_ARCFOUR_HMAC && !context->allow_rc4)
|
||||
- continue;
|
||||
-
|
||||
if (dbentry_supports_enctype(context, server, ktype[i]))
|
||||
return ktype[i];
|
||||
}
|
||||
diff --git a/src/lib/krb5/krb/get_in_tkt.c b/src/lib/krb5/krb/get_in_tkt.c
|
||||
index ea089f0fcc..1b420a3ac2 100644
|
||||
--- a/src/lib/krb5/krb/get_in_tkt.c
|
||||
+++ b/src/lib/krb5/krb/get_in_tkt.c
|
||||
@@ -1582,31 +1582,22 @@ warn_pw_expiry(krb5_context context, krb5_get_init_creds_opt *options,
|
||||
(*prompter)(context, data, 0, banner, 0, 0);
|
||||
}
|
||||
|
||||
-/* Display a warning via the prompter if a deprecated enctype was used for
|
||||
- * either the reply key or the session key. */
|
||||
+/* Display a warning via the prompter if des3-cbc-sha1 was used for either the
|
||||
+ * reply key or the session key. */
|
||||
static void
|
||||
-warn_deprecated(krb5_context context, krb5_init_creds_context ctx,
|
||||
- krb5_enctype as_key_enctype)
|
||||
+warn_des3(krb5_context context, krb5_init_creds_context ctx,
|
||||
+ krb5_enctype as_key_enctype)
|
||||
{
|
||||
- krb5_enctype etype;
|
||||
- char encbuf[128], banner[256];
|
||||
+ const char *banner;
|
||||
|
||||
- if (ctx->prompter == NULL)
|
||||
- return;
|
||||
-
|
||||
- if (krb5int_c_deprecated_enctype(as_key_enctype))
|
||||
- etype = as_key_enctype;
|
||||
- else if (krb5int_c_deprecated_enctype(ctx->cred.keyblock.enctype))
|
||||
- etype = ctx->cred.keyblock.enctype;
|
||||
- else
|
||||
+ if (as_key_enctype != ENCTYPE_DES3_CBC_SHA1 &&
|
||||
+ ctx->cred.keyblock.enctype != ENCTYPE_DES3_CBC_SHA1)
|
||||
return;
|
||||
-
|
||||
- if (krb5_enctype_to_name(etype, FALSE, encbuf, sizeof(encbuf)) != 0)
|
||||
+ if (ctx->prompter == NULL)
|
||||
return;
|
||||
- snprintf(banner, sizeof(banner),
|
||||
- _("Warning: encryption type %s used for authentication is "
|
||||
- "deprecated and will be disabled"), encbuf);
|
||||
|
||||
+ banner = _("Warning: encryption type des3-cbc-sha1 used for "
|
||||
+ "authentication is weak and will be disabled");
|
||||
/* PROMPTER_INVOCATION */
|
||||
(*ctx->prompter)(context, ctx->prompter_data, NULL, banner, 0, NULL);
|
||||
}
|
||||
@@ -1857,7 +1848,7 @@ init_creds_step_reply(krb5_context context,
|
||||
ctx->complete = TRUE;
|
||||
warn_pw_expiry(context, ctx->opt, ctx->prompter, ctx->prompter_data,
|
||||
ctx->in_tkt_service, ctx->reply);
|
||||
- warn_deprecated(context, ctx, encrypting_key.enctype);
|
||||
+ warn_des3(context, ctx, encrypting_key.enctype);
|
||||
|
||||
cleanup:
|
||||
krb5_free_pa_data(context, kdc_padata);
|
||||
diff --git a/src/lib/krb5/krb/init_ctx.c b/src/lib/krb5/krb/init_ctx.c
|
||||
index a6c2bbeb54..87b486c53f 100644
|
||||
--- a/src/lib/krb5/krb/init_ctx.c
|
||||
+++ b/src/lib/krb5/krb/init_ctx.c
|
||||
@@ -221,16 +221,6 @@ krb5_init_context_profile(profile_t profile, krb5_flags flags,
|
||||
goto cleanup;
|
||||
ctx->allow_weak_crypto = tmp;
|
||||
|
||||
- retval = get_boolean(ctx, KRB5_CONF_ALLOW_DES3, 0, &tmp);
|
||||
- if (retval)
|
||||
- goto cleanup;
|
||||
- ctx->allow_des3 = tmp;
|
||||
-
|
||||
- retval = get_boolean(ctx, KRB5_CONF_ALLOW_RC4, 0, &tmp);
|
||||
- if (retval)
|
||||
- goto cleanup;
|
||||
- ctx->allow_rc4 = tmp;
|
||||
-
|
||||
retval = get_boolean(ctx, KRB5_CONF_IGNORE_ACCEPTOR_HOSTNAME, 0, &tmp);
|
||||
if (retval)
|
||||
goto cleanup;
|
||||
diff --git a/src/tests/gssapi/t_enctypes.py b/src/tests/gssapi/t_enctypes.py
|
||||
index f5f11842e2..7494d7fcdb 100755
|
||||
--- a/src/tests/gssapi/t_enctypes.py
|
||||
+++ b/src/tests/gssapi/t_enctypes.py
|
||||
@@ -18,8 +18,7 @@ d_rc4 = 'DEPRECATED:arcfour-hmac'
|
||||
# These tests make assumptions about the default enctype lists, so set
|
||||
# them explicitly rather than relying on the library defaults.
|
||||
supp='aes256-cts:normal aes128-cts:normal des3-cbc-sha1:normal rc4-hmac:normal'
|
||||
-conf = {'libdefaults': {'permitted_enctypes': 'aes des3 rc4',
|
||||
- 'allow_des3': 'true', 'allow_rc4': 'true'},
|
||||
+conf = {'libdefaults': {'permitted_enctypes': 'aes des3 rc4'},
|
||||
'realms': {'$realm': {'supported_enctypes': supp}}}
|
||||
realm = K5Realm(krb5_conf=conf)
|
||||
shutil.copyfile(realm.ccache, os.path.join(realm.testdir, 'save'))
|
||||
diff --git a/src/tests/t_etype_info.py b/src/tests/t_etype_info.py
|
||||
index 38cf96ca8f..c982508d8b 100644
|
||||
--- a/src/tests/t_etype_info.py
|
||||
+++ b/src/tests/t_etype_info.py
|
||||
@@ -1,7 +1,7 @@
|
||||
from k5test import *
|
||||
|
||||
supported_enctypes = 'aes128-cts des3-cbc-sha1 rc4-hmac'
|
||||
-conf = {'libdefaults': {'allow_des3': 'true', 'allow_rc4': 'true'},
|
||||
+conf = {'libdefaults': {'allow_weak_crypto': 'true'},
|
||||
'realms': {'$realm': {'supported_enctypes': supported_enctypes}}}
|
||||
realm = K5Realm(create_host=False, get_creds=False, krb5_conf=conf)
|
||||
|
||||
diff --git a/src/tests/t_sesskeynego.py b/src/tests/t_sesskeynego.py
|
||||
index 5a213617b5..9024aee838 100755
|
||||
--- a/src/tests/t_sesskeynego.py
|
||||
+++ b/src/tests/t_sesskeynego.py
|
||||
@@ -25,8 +25,6 @@ conf3 = {'libdefaults': {
|
||||
'default_tkt_enctypes': 'aes128-cts',
|
||||
'default_tgs_enctypes': 'rc4-hmac,aes128-cts'}}
|
||||
conf4 = {'libdefaults': {'permitted_enctypes': 'aes256-cts'}}
|
||||
-conf5 = {'libdefaults': {'allow_rc4': 'true'}}
|
||||
-conf6 = {'libdefaults': {'allow_des3': 'true'}}
|
||||
# Test with client request and session_enctypes preferring aes128, but
|
||||
# aes256 long-term key.
|
||||
realm = K5Realm(krb5_conf=conf1, create_host=False, get_creds=False)
|
||||
@@ -56,12 +54,10 @@ realm.run([kadminl, 'setstr', 'server', 'session_enctypes',
|
||||
'aes128-cts,aes256-cts'])
|
||||
test_kvno(realm, 'aes128-cts-hmac-sha1-96', 'aes256-cts-hmac-sha1-96')
|
||||
|
||||
-# 3b: Skip RC4 (as the KDC does not allow it for session keys by
|
||||
-# default) and negotiate aes128-cts session key, with only an aes256
|
||||
-# long-term service key.
|
||||
+# 3b: Negotiate rc4-hmac session key when principal only has aes256 long-term.
|
||||
realm.run([kadminl, 'setstr', 'server', 'session_enctypes',
|
||||
'rc4-hmac,aes128-cts,aes256-cts'])
|
||||
-test_kvno(realm, 'aes128-cts-hmac-sha1-96', 'aes256-cts-hmac-sha1-96')
|
||||
+test_kvno(realm, 'DEPRECATED:arcfour-hmac', 'aes256-cts-hmac-sha1-96')
|
||||
realm.stop()
|
||||
|
||||
# 4: Check that permitted_enctypes is a default for session key enctypes.
|
||||
@@ -71,24 +67,4 @@ realm.run([kvno, 'user'],
|
||||
expected_trace=('etypes requested in TGS request: aes256-cts',))
|
||||
realm.stop()
|
||||
|
||||
-# 5: allow_rc4 permits negotiation of rc4-hmac session key.
|
||||
-realm = K5Realm(krb5_conf=conf5, create_host=False, get_creds=False)
|
||||
-realm.run([kadminl, 'addprinc', '-randkey', '-e', 'aes256-cts', 'server'])
|
||||
-realm.run([kadminl, 'setstr', 'server', 'session_enctypes', 'rc4-hmac'])
|
||||
-test_kvno(realm, 'DEPRECATED:arcfour-hmac', 'aes256-cts-hmac-sha1-96')
|
||||
-realm.stop()
|
||||
-
|
||||
-# 6: allow_des3 permits negotiation of des3-cbc-sha1 session key.
|
||||
-realm = K5Realm(krb5_conf=conf6, create_host=False, get_creds=False)
|
||||
-realm.run([kadminl, 'addprinc', '-randkey', '-e', 'aes256-cts', 'server'])
|
||||
-realm.run([kadminl, 'setstr', 'server', 'session_enctypes', 'des3-cbc-sha1'])
|
||||
-test_kvno(realm, 'DEPRECATED:des3-cbc-sha1', 'aes256-cts-hmac-sha1-96')
|
||||
-realm.stop()
|
||||
-
|
||||
-# 7: default config negotiates aes256-sha1 session key for RC4-only service.
|
||||
-realm = K5Realm(create_host=False, get_creds=False)
|
||||
-realm.run([kadminl, 'addprinc', '-randkey', '-e', 'rc4-hmac', 'server'])
|
||||
-test_kvno(realm, 'aes256-cts-hmac-sha1-96', 'DEPRECATED:arcfour-hmac')
|
||||
-realm.stop()
|
||||
-
|
||||
success('sesskeynego')
|
||||
diff --git a/src/util/k5test.py b/src/util/k5test.py
|
||||
index 8e5f5ba8e9..2a86c5cdfc 100644
|
||||
--- a/src/util/k5test.py
|
||||
+++ b/src/util/k5test.py
|
||||
@@ -1340,14 +1340,14 @@ _passes = [
|
||||
|
||||
# Exercise the DES3 enctype.
|
||||
('des3', None,
|
||||
- {'libdefaults': {'permitted_enctypes': 'des3 aes256-sha1'}},
|
||||
+ {'libdefaults': {'permitted_enctypes': 'des3'}},
|
||||
{'realms': {'$realm': {
|
||||
'supported_enctypes': 'des3-cbc-sha1:normal',
|
||||
'master_key_type': 'des3-cbc-sha1'}}}),
|
||||
|
||||
# Exercise the arcfour enctype.
|
||||
('arcfour', None,
|
||||
- {'libdefaults': {'permitted_enctypes': 'rc4 aes256-sha1'}},
|
||||
+ {'libdefaults': {'permitted_enctypes': 'rc4'}},
|
||||
{'realms': {'$realm': {
|
||||
'supported_enctypes': 'arcfour-hmac:normal',
|
||||
'master_key_type': 'arcfour-hmac'}}}),
|
||||
--
|
||||
2.45.1
|
||||
|
||||
|
|
@ -1,7 +1,7 @@
|
|||
From c8f2e321b2d8471feee69bbca3179e675228bd8a Mon Sep 17 00:00:00 2001
|
||||
From de4205c45e310ceaaa7cd7958af7293322fa43a6 Mon Sep 17 00:00:00 2001
|
||||
From: Robbie Harwood <rharwood@redhat.com>
|
||||
Date: Tue, 23 Aug 2016 16:29:58 -0400
|
||||
Subject: [PATCH] krb5-1.12.1-pam.patch
|
||||
Subject: [PATCH] [downstream] ksu pam integration
|
||||
|
||||
Modify ksu so that it performs account and session management on behalf of
|
||||
the target user account, mimicking the action of regular su. The default
|
||||
|
|
@ -16,25 +16,28 @@ When enabled, ksu gains a dependency on libpam.
|
|||
Originally RT#5939, though it's changed since then to perform the account
|
||||
and session management before dropping privileges, and to apply on top of
|
||||
changes we're proposing for how it handles cache collections.
|
||||
|
||||
Last-updated: krb5-1.18-beta1
|
||||
---
|
||||
src/aclocal.m4 | 67 +++++++
|
||||
src/aclocal.m4 | 69 +++++++
|
||||
src/clients/ksu/Makefile.in | 8 +-
|
||||
src/clients/ksu/main.c | 88 +++++++-
|
||||
src/clients/ksu/pam.c | 389 ++++++++++++++++++++++++++++++++++++
|
||||
src/clients/ksu/pam.h | 57 ++++++
|
||||
src/configure.in | 2 +
|
||||
6 files changed, 608 insertions(+), 3 deletions(-)
|
||||
src/configure.ac | 2 +
|
||||
6 files changed, 610 insertions(+), 3 deletions(-)
|
||||
create mode 100644 src/clients/ksu/pam.c
|
||||
create mode 100644 src/clients/ksu/pam.h
|
||||
|
||||
diff --git a/src/aclocal.m4 b/src/aclocal.m4
|
||||
index 3752d9bd5..340546d80 100644
|
||||
index 3d66a876b3..ce3c5a9bac 100644
|
||||
--- a/src/aclocal.m4
|
||||
+++ b/src/aclocal.m4
|
||||
@@ -1697,3 +1697,70 @@ AC_DEFUN(KRB5_AC_PERSISTENT_KEYRING,[
|
||||
]))
|
||||
@@ -1458,3 +1458,72 @@ if test "$with_ldap" = yes; then
|
||||
OPENLDAP_PLUGIN=yes
|
||||
fi
|
||||
])dnl
|
||||
dnl
|
||||
+dnl
|
||||
+dnl
|
||||
+dnl Use PAM instead of local crypt() compare for checking local passwords,
|
||||
+dnl and perform PAM account, session management, and password-changing where
|
||||
|
|
@ -102,12 +105,13 @@ index 3752d9bd5..340546d80 100644
|
|||
+AC_SUBST(PAM_MAN)
|
||||
+AC_SUBST(NON_PAM_MAN)
|
||||
+])dnl
|
||||
+
|
||||
diff --git a/src/clients/ksu/Makefile.in b/src/clients/ksu/Makefile.in
|
||||
index b2fcbf240..5755bb58a 100644
|
||||
index 8b4edce4d8..9d58f29b5d 100644
|
||||
--- a/src/clients/ksu/Makefile.in
|
||||
+++ b/src/clients/ksu/Makefile.in
|
||||
@@ -3,12 +3,14 @@ BUILDTOP=$(REL)..$(S)..
|
||||
DEFINES = -DGET_TGT_VIA_PASSWD -DPRINC_LOOK_AHEAD -DCMD_PATH='"/bin /local/bin"'
|
||||
DEFINES = -DGET_TGT_VIA_PASSWD -DPRINC_LOOK_AHEAD -DCMD_PATH='"/usr/local/sbin /usr/local/bin /sbin /bin /usr/sbin /usr/bin"'
|
||||
|
||||
KSU_LIBS=@KSU_LIBS@
|
||||
+PAM_LIBS=@PAM_LIBS@
|
||||
|
|
@ -141,11 +145,11 @@ index b2fcbf240..5755bb58a 100644
|
|||
clean:
|
||||
$(RM) ksu
|
||||
diff --git a/src/clients/ksu/main.c b/src/clients/ksu/main.c
|
||||
index d9596d948..ec06788bc 100644
|
||||
index af12861729..931f054041 100644
|
||||
--- a/src/clients/ksu/main.c
|
||||
+++ b/src/clients/ksu/main.c
|
||||
@@ -26,6 +26,7 @@
|
||||
* KSU was writen by: Ari Medvinsky, ari@isi.edu
|
||||
* KSU was written by: Ari Medvinsky, ari@isi.edu
|
||||
*/
|
||||
|
||||
+#include "autoconf.h"
|
||||
|
|
@ -171,7 +175,7 @@ index d9596d948..ec06788bc 100644
|
|||
/***********/
|
||||
|
||||
#define KS_TEMPORARY_CACHE "MEMORY:_ksu"
|
||||
@@ -528,6 +534,23 @@ main (argc, argv)
|
||||
@@ -536,6 +542,23 @@ main (argc, argv)
|
||||
prog_name,target_user,client_name,
|
||||
source_user,ontty());
|
||||
|
||||
|
|
@ -195,7 +199,7 @@ index d9596d948..ec06788bc 100644
|
|||
/* Run authorization as target.*/
|
||||
if (krb5_seteuid(target_uid)) {
|
||||
com_err(prog_name, errno, _("while switching to target for "
|
||||
@@ -588,6 +611,24 @@ main (argc, argv)
|
||||
@@ -596,6 +619,24 @@ main (argc, argv)
|
||||
|
||||
exit(1);
|
||||
}
|
||||
|
|
@ -220,7 +224,7 @@ index d9596d948..ec06788bc 100644
|
|||
}
|
||||
|
||||
if( some_rest_copy){
|
||||
@@ -645,6 +686,30 @@ main (argc, argv)
|
||||
@@ -653,6 +694,30 @@ main (argc, argv)
|
||||
exit(1);
|
||||
}
|
||||
|
||||
|
|
@ -251,7 +255,7 @@ index d9596d948..ec06788bc 100644
|
|||
/* set permissions */
|
||||
if (setgid(target_pwd->pw_gid) < 0) {
|
||||
perror("ksu: setgid");
|
||||
@@ -742,7 +807,7 @@ main (argc, argv)
|
||||
@@ -750,7 +815,7 @@ main (argc, argv)
|
||||
fprintf(stderr, "program to be execed %s\n",params[0]);
|
||||
}
|
||||
|
||||
|
|
@ -260,7 +264,7 @@ index d9596d948..ec06788bc 100644
|
|||
execv(params[0], params);
|
||||
com_err(prog_name, errno, _("while trying to execv %s"), params[0]);
|
||||
sweep_up(ksu_context, cc_target);
|
||||
@@ -772,16 +837,35 @@ main (argc, argv)
|
||||
@@ -780,16 +845,35 @@ main (argc, argv)
|
||||
if (ret_pid == -1) {
|
||||
com_err(prog_name, errno, _("while calling waitpid"));
|
||||
}
|
||||
|
|
@ -299,7 +303,7 @@ index d9596d948..ec06788bc 100644
|
|||
}
|
||||
diff --git a/src/clients/ksu/pam.c b/src/clients/ksu/pam.c
|
||||
new file mode 100644
|
||||
index 000000000..cbfe48704
|
||||
index 0000000000..cbfe487047
|
||||
--- /dev/null
|
||||
+++ b/src/clients/ksu/pam.c
|
||||
@@ -0,0 +1,389 @@
|
||||
|
|
@ -694,7 +698,7 @@ index 000000000..cbfe48704
|
|||
+#endif
|
||||
diff --git a/src/clients/ksu/pam.h b/src/clients/ksu/pam.h
|
||||
new file mode 100644
|
||||
index 000000000..0ab76569c
|
||||
index 0000000000..0ab76569cb
|
||||
--- /dev/null
|
||||
+++ b/src/clients/ksu/pam.h
|
||||
@@ -0,0 +1,57 @@
|
||||
|
|
@ -755,11 +759,11 @@ index 000000000..0ab76569c
|
|||
+int appl_pam_cred_init(void);
|
||||
+void appl_pam_cleanup(void);
|
||||
+#endif
|
||||
diff --git a/src/configure.in b/src/configure.in
|
||||
index 61ef738dc..e9a12ac16 100644
|
||||
--- a/src/configure.in
|
||||
+++ b/src/configure.in
|
||||
@@ -1352,6 +1352,8 @@ AC_SUBST([VERTO_VERSION])
|
||||
diff --git a/src/configure.ac b/src/configure.ac
|
||||
index 77be7a2025..587221936e 100644
|
||||
--- a/src/configure.ac
|
||||
+++ b/src/configure.ac
|
||||
@@ -1399,6 +1399,8 @@ AC_SUBST([VERTO_VERSION])
|
||||
|
||||
AC_PATH_PROG(GROFF, groff)
|
||||
|
||||
|
|
@ -768,3 +772,6 @@ index 61ef738dc..e9a12ac16 100644
|
|||
# Make localedir work in autoconf 2.5x.
|
||||
if test "${localedir+set}" != set; then
|
||||
localedir='$(datadir)/locale'
|
||||
--
|
||||
2.45.1
|
||||
|
||||
|
|
@ -1,7 +1,7 @@
|
|||
From e1c4f8894d22da9c157bfcf31e28f9ceaeebe39e Mon Sep 17 00:00:00 2001
|
||||
From 30ff501e4b519396f5aea25e24919be817863e7c Mon Sep 17 00:00:00 2001
|
||||
From: Robbie Harwood <rharwood@redhat.com>
|
||||
Date: Tue, 23 Aug 2016 16:30:53 -0400
|
||||
Subject: [PATCH] krb5-1.17-beta1-selinux-label.patch
|
||||
Subject: [PATCH] [downstream] SELinux integration
|
||||
|
||||
SELinux bases access to files on the domain of the requesting process,
|
||||
the operation being performed, and the context applied to the file.
|
||||
|
|
@ -35,11 +35,15 @@ stomp all over us.
|
|||
The selabel APIs for looking up the context should be thread-safe (per
|
||||
Red Hat #273081), so switching to using them instead of matchpathcon(),
|
||||
which we used earlier, is some improvement.
|
||||
|
||||
Last-updated: krb5-1.20.1
|
||||
[jrische@redhat.com: Replace deprecated security_context_t by char *:
|
||||
- src/util/support/selinux.c]
|
||||
---
|
||||
src/aclocal.m4 | 49 +++
|
||||
src/aclocal.m4 | 48 +++
|
||||
src/build-tools/krb5-config.in | 3 +-
|
||||
src/config/pre.in | 3 +-
|
||||
src/configure.in | 2 +
|
||||
src/configure.ac | 2 +
|
||||
src/include/k5-int.h | 1 +
|
||||
src/include/k5-label.h | 32 ++
|
||||
src/include/krb5/krb5.hin | 6 +
|
||||
|
|
@ -51,7 +55,6 @@ which we used earlier, is some improvement.
|
|||
src/lib/krb5/ccache/cc_dir.c | 26 +-
|
||||
src/lib/krb5/keytab/kt_file.c | 4 +-
|
||||
src/lib/krb5/os/trace.c | 2 +-
|
||||
src/lib/krb5/rcache/rc_dfl.c | 13 +
|
||||
src/plugins/kdb/db2/adb_openclose.c | 2 +-
|
||||
src/plugins/kdb/db2/kdb_db2.c | 4 +-
|
||||
src/plugins/kdb/db2/libdb2/btree/bt_open.c | 3 +-
|
||||
|
|
@ -60,16 +63,16 @@ which we used earlier, is some improvement.
|
|||
.../kdb/ldap/ldap_util/kdb5_ldap_services.c | 11 +-
|
||||
src/util/profile/prof_file.c | 3 +-
|
||||
src/util/support/Makefile.in | 3 +-
|
||||
src/util/support/selinux.c | 406 ++++++++++++++++++
|
||||
25 files changed, 587 insertions(+), 21 deletions(-)
|
||||
src/util/support/selinux.c | 405 ++++++++++++++++++
|
||||
24 files changed, 572 insertions(+), 21 deletions(-)
|
||||
create mode 100644 src/include/k5-label.h
|
||||
create mode 100644 src/util/support/selinux.c
|
||||
|
||||
diff --git a/src/aclocal.m4 b/src/aclocal.m4
|
||||
index 340546d80..a7afec09e 100644
|
||||
index ce3c5a9bac..3331970930 100644
|
||||
--- a/src/aclocal.m4
|
||||
+++ b/src/aclocal.m4
|
||||
@@ -89,6 +89,7 @@ AC_SUBST_FILE(libnodeps_frag)
|
||||
@@ -85,6 +85,7 @@ AC_SUBST_FILE(libnodeps_frag)
|
||||
dnl
|
||||
KRB5_AC_PRAGMA_WEAK_REF
|
||||
WITH_LDAP
|
||||
|
|
@ -77,7 +80,7 @@ index 340546d80..a7afec09e 100644
|
|||
KRB5_LIB_PARAMS
|
||||
KRB5_AC_INITFINI
|
||||
KRB5_AC_ENABLE_THREADS
|
||||
@@ -1764,3 +1765,51 @@ AC_SUBST(PAM_LIBS)
|
||||
@@ -1526,4 +1527,51 @@ AC_SUBST(PAM_LIBS)
|
||||
AC_SUBST(PAM_MAN)
|
||||
AC_SUBST(NON_PAM_MAN)
|
||||
])dnl
|
||||
|
|
@ -100,7 +103,7 @@ index 340546d80..a7afec09e 100644
|
|||
+ AC_MSG_ERROR([Unable to locate selinux/selinux.h.])
|
||||
+ fi
|
||||
+ fi
|
||||
+
|
||||
|
||||
+ LIBS=
|
||||
+ unset ac_cv_func_setfscreatecon
|
||||
+ AC_CHECK_FUNCS(setfscreatecon selabel_open)
|
||||
|
|
@ -130,10 +133,10 @@ index 340546d80..a7afec09e 100644
|
|||
+AC_SUBST(SELINUX_LIBS)
|
||||
+])dnl
|
||||
diff --git a/src/build-tools/krb5-config.in b/src/build-tools/krb5-config.in
|
||||
index f6184da3f..c17cb5eb5 100755
|
||||
index 8e6eb86601..7677f37359 100755
|
||||
--- a/src/build-tools/krb5-config.in
|
||||
+++ b/src/build-tools/krb5-config.in
|
||||
@@ -41,6 +41,7 @@ DL_LIB='@DL_LIB@'
|
||||
@@ -40,6 +40,7 @@ DL_LIB='@DL_LIB@'
|
||||
DEFCCNAME='@DEFCCNAME@'
|
||||
DEFKTNAME='@DEFKTNAME@'
|
||||
DEFCKTNAME='@DEFCKTNAME@'
|
||||
|
|
@ -141,7 +144,7 @@ index f6184da3f..c17cb5eb5 100755
|
|||
|
||||
LIBS='@LIBS@'
|
||||
GEN_LIB=@GEN_LIB@
|
||||
@@ -255,7 +256,7 @@ if test -n "$do_libs"; then
|
||||
@@ -253,7 +254,7 @@ if test -n "$do_libs"; then
|
||||
fi
|
||||
|
||||
# If we ever support a flag to generate output suitable for static
|
||||
|
|
@ -151,7 +154,7 @@ index f6184da3f..c17cb5eb5 100755
|
|||
|
||||
echo $lib_flags
|
||||
diff --git a/src/config/pre.in b/src/config/pre.in
|
||||
index ce87e21ca..917357df9 100644
|
||||
index a0c60c70b3..7eaa2f351c 100644
|
||||
--- a/src/config/pre.in
|
||||
+++ b/src/config/pre.in
|
||||
@@ -177,6 +177,7 @@ LD = $(PURE) @LD@
|
||||
|
|
@ -162,7 +165,7 @@ index ce87e21ca..917357df9 100644
|
|||
|
||||
INSTALL=@INSTALL@
|
||||
INSTALL_STRIP=
|
||||
@@ -402,7 +403,7 @@ SUPPORT_LIB = -l$(SUPPORT_LIBNAME)
|
||||
@@ -379,7 +380,7 @@ SUPPORT_LIB = -l$(SUPPORT_LIBNAME)
|
||||
# HESIOD_LIBS is -lhesiod...
|
||||
HESIOD_LIBS = @HESIOD_LIBS@
|
||||
|
||||
|
|
@ -171,11 +174,11 @@ index ce87e21ca..917357df9 100644
|
|||
KDB5_LIBS = $(KDB5_LIB) $(GSSRPC_LIBS)
|
||||
GSS_LIBS = $(GSS_KRB5_LIB)
|
||||
# needs fixing if ever used on macOS!
|
||||
diff --git a/src/configure.in b/src/configure.in
|
||||
index e9a12ac16..93aec682e 100644
|
||||
--- a/src/configure.in
|
||||
+++ b/src/configure.in
|
||||
@@ -1354,6 +1354,8 @@ AC_PATH_PROG(GROFF, groff)
|
||||
diff --git a/src/configure.ac b/src/configure.ac
|
||||
index 587221936e..69be9030f8 100644
|
||||
--- a/src/configure.ac
|
||||
+++ b/src/configure.ac
|
||||
@@ -1401,6 +1401,8 @@ AC_PATH_PROG(GROFF, groff)
|
||||
|
||||
KRB5_WITH_PAM
|
||||
|
||||
|
|
@ -185,7 +188,7 @@ index e9a12ac16..93aec682e 100644
|
|||
if test "${localedir+set}" != set; then
|
||||
localedir='$(datadir)/locale'
|
||||
diff --git a/src/include/k5-int.h b/src/include/k5-int.h
|
||||
index 652242207..8f9329c59 100644
|
||||
index 1d1c8293f4..768110e5ef 100644
|
||||
--- a/src/include/k5-int.h
|
||||
+++ b/src/include/k5-int.h
|
||||
@@ -128,6 +128,7 @@ typedef unsigned char u_char;
|
||||
|
|
@ -198,7 +201,7 @@ index 652242207..8f9329c59 100644
|
|||
#define KRB5_KDB_MAX_RLIFE (60*60*24*7) /* one week */
|
||||
diff --git a/src/include/k5-label.h b/src/include/k5-label.h
|
||||
new file mode 100644
|
||||
index 000000000..dfaaa847c
|
||||
index 0000000000..dfaaa847cb
|
||||
--- /dev/null
|
||||
+++ b/src/include/k5-label.h
|
||||
@@ -0,0 +1,32 @@
|
||||
|
|
@ -235,10 +238,10 @@ index 000000000..dfaaa847c
|
|||
+#endif
|
||||
+#endif
|
||||
diff --git a/src/include/krb5/krb5.hin b/src/include/krb5/krb5.hin
|
||||
index c40a6cca8..3ff86d7ff 100644
|
||||
index 4e09ed345d..09f800be52 100644
|
||||
--- a/src/include/krb5/krb5.hin
|
||||
+++ b/src/include/krb5/krb5.hin
|
||||
@@ -87,6 +87,12 @@
|
||||
@@ -83,6 +83,12 @@
|
||||
#define THREEPARAMOPEN(x,y,z) open(x,y,z)
|
||||
#endif
|
||||
|
||||
|
|
@ -252,7 +255,7 @@ index c40a6cca8..3ff86d7ff 100644
|
|||
|
||||
#include <stdlib.h>
|
||||
diff --git a/src/kadmin/dbutil/dump.c b/src/kadmin/dbutil/dump.c
|
||||
index c9574c6e1..8301a33d0 100644
|
||||
index a89b5144f6..4d6cc0bdf9 100644
|
||||
--- a/src/kadmin/dbutil/dump.c
|
||||
+++ b/src/kadmin/dbutil/dump.c
|
||||
@@ -148,12 +148,21 @@ create_ofile(char *ofile, char **tmpname)
|
||||
|
|
@ -287,10 +290,10 @@ index c9574c6e1..8301a33d0 100644
|
|||
com_err(progname, errno, _("while creating 'ok' file, '%s'"), file_ok);
|
||||
goto cleanup;
|
||||
diff --git a/src/kdc/main.c b/src/kdc/main.c
|
||||
index 408c723f5..663fd6303 100644
|
||||
index bfdfef5c48..b43fe9a082 100644
|
||||
--- a/src/kdc/main.c
|
||||
+++ b/src/kdc/main.c
|
||||
@@ -858,7 +858,7 @@ write_pid_file(const char *path)
|
||||
@@ -844,7 +844,7 @@ write_pid_file(const char *path)
|
||||
FILE *file;
|
||||
unsigned long pid;
|
||||
|
||||
|
|
@ -300,7 +303,7 @@ index 408c723f5..663fd6303 100644
|
|||
return errno;
|
||||
pid = (unsigned long) getpid();
|
||||
diff --git a/src/kprop/kpropd.c b/src/kprop/kpropd.c
|
||||
index 68323dd0f..4cc035dc6 100644
|
||||
index aa3c81ea30..cb9785aaeb 100644
|
||||
--- a/src/kprop/kpropd.c
|
||||
+++ b/src/kprop/kpropd.c
|
||||
@@ -488,6 +488,9 @@ doit(int fd)
|
||||
|
|
@ -330,10 +333,10 @@ index 68323dd0f..4cc035dc6 100644
|
|||
KRB5_LOCKMODE_EXCLUSIVE | KRB5_LOCKMODE_DONTBLOCK);
|
||||
if (retval) {
|
||||
diff --git a/src/lib/kadm5/logger.c b/src/lib/kadm5/logger.c
|
||||
index c6885edf2..9aec3c05e 100644
|
||||
index e14da53790..b879a4049b 100644
|
||||
--- a/src/lib/kadm5/logger.c
|
||||
+++ b/src/lib/kadm5/logger.c
|
||||
@@ -309,7 +309,7 @@ krb5_klog_init(krb5_context kcontext, char *ename, char *whoami, krb5_boolean do
|
||||
@@ -310,7 +310,7 @@ krb5_klog_init(krb5_context kcontext, char *ename, char *whoami, krb5_boolean do
|
||||
*/
|
||||
append = (cp[4] == ':') ? O_APPEND : 0;
|
||||
if (append || cp[4] == '=') {
|
||||
|
|
@ -342,7 +345,7 @@ index c6885edf2..9aec3c05e 100644
|
|||
S_IRUSR | S_IWUSR | S_IRGRP);
|
||||
if (fd != -1)
|
||||
f = fdopen(fd, append ? "a" : "w");
|
||||
@@ -776,7 +776,7 @@ krb5_klog_reopen(krb5_context kcontext)
|
||||
@@ -777,7 +777,7 @@ krb5_klog_reopen(krb5_context kcontext)
|
||||
* In case the old logfile did not get moved out of the
|
||||
* way, open for append to prevent squashing the old logs.
|
||||
*/
|
||||
|
|
@ -352,7 +355,7 @@ index c6885edf2..9aec3c05e 100644
|
|||
set_cloexec_file(f);
|
||||
log_control.log_entries[lindex].lfu_filep = f;
|
||||
diff --git a/src/lib/kdb/kdb_log.c b/src/lib/kdb/kdb_log.c
|
||||
index 2659a2501..e9b95fce5 100644
|
||||
index 2659a25018..e9b95fce59 100644
|
||||
--- a/src/lib/kdb/kdb_log.c
|
||||
+++ b/src/lib/kdb/kdb_log.c
|
||||
@@ -480,7 +480,7 @@ ulog_map(krb5_context context, const char *logname, uint32_t ulogentries)
|
||||
|
|
@ -365,7 +368,7 @@ index 2659a2501..e9b95fce5 100644
|
|||
retval = errno;
|
||||
goto cleanup;
|
||||
diff --git a/src/lib/krb5/ccache/cc_dir.c b/src/lib/krb5/ccache/cc_dir.c
|
||||
index bba64e516..73f0fe62d 100644
|
||||
index 1da40b51d0..f3ab7340a6 100644
|
||||
--- a/src/lib/krb5/ccache/cc_dir.c
|
||||
+++ b/src/lib/krb5/ccache/cc_dir.c
|
||||
@@ -183,10 +183,19 @@ write_primary_file(const char *primary_path, const char *contents)
|
||||
|
|
@ -415,10 +418,10 @@ index bba64e516..73f0fe62d 100644
|
|||
_("Credential cache directory %s does not exist"),
|
||||
dirname);
|
||||
diff --git a/src/lib/krb5/keytab/kt_file.c b/src/lib/krb5/keytab/kt_file.c
|
||||
index 89cb68680..21c80d419 100644
|
||||
index e510211fc5..f3ea28c8ec 100644
|
||||
--- a/src/lib/krb5/keytab/kt_file.c
|
||||
+++ b/src/lib/krb5/keytab/kt_file.c
|
||||
@@ -1024,14 +1024,14 @@ krb5_ktfileint_open(krb5_context context, krb5_keytab id, int mode)
|
||||
@@ -735,14 +735,14 @@ krb5_ktfileint_open(krb5_context context, krb5_keytab id, int mode)
|
||||
|
||||
KTCHECKLOCK(id);
|
||||
errno = 0;
|
||||
|
|
@ -436,10 +439,10 @@ index 89cb68680..21c80d419 100644
|
|||
goto report_errno;
|
||||
writevno = 1;
|
||||
diff --git a/src/lib/krb5/os/trace.c b/src/lib/krb5/os/trace.c
|
||||
index 4fff8f38c..40a9e7b10 100644
|
||||
index 4cbbbb270a..c4058ddc96 100644
|
||||
--- a/src/lib/krb5/os/trace.c
|
||||
+++ b/src/lib/krb5/os/trace.c
|
||||
@@ -458,7 +458,7 @@ krb5_set_trace_filename(krb5_context context, const char *filename)
|
||||
@@ -460,7 +460,7 @@ krb5_set_trace_filename(krb5_context context, const char *filename)
|
||||
fd = malloc(sizeof(*fd));
|
||||
if (fd == NULL)
|
||||
return ENOMEM;
|
||||
|
|
@ -448,40 +451,8 @@ index 4fff8f38c..40a9e7b10 100644
|
|||
if (*fd == -1) {
|
||||
free(fd);
|
||||
return errno;
|
||||
diff --git a/src/lib/krb5/rcache/rc_dfl.c b/src/lib/krb5/rcache/rc_dfl.c
|
||||
index 1e0cb22c9..f5e93b1ab 100644
|
||||
--- a/src/lib/krb5/rcache/rc_dfl.c
|
||||
+++ b/src/lib/krb5/rcache/rc_dfl.c
|
||||
@@ -793,6 +793,9 @@ krb5_rc_dfl_expunge_locked(krb5_context context, krb5_rcache id)
|
||||
krb5_error_code retval = 0;
|
||||
krb5_rcache tmp;
|
||||
krb5_deltat lifespan = t->lifespan; /* save original lifespan */
|
||||
+#ifdef USE_SELINUX
|
||||
+ void *selabel;
|
||||
+#endif
|
||||
|
||||
if (! t->recovering) {
|
||||
name = t->name;
|
||||
@@ -814,7 +817,17 @@ krb5_rc_dfl_expunge_locked(krb5_context context, krb5_rcache id)
|
||||
retval = krb5_rc_resolve(context, tmp, 0);
|
||||
if (retval)
|
||||
goto cleanup;
|
||||
+#ifdef USE_SELINUX
|
||||
+ if (t->d.fn != NULL)
|
||||
+ selabel = krb5int_push_fscreatecon_for(t->d.fn);
|
||||
+ else
|
||||
+ selabel = NULL;
|
||||
+#endif
|
||||
retval = krb5_rc_initialize(context, tmp, lifespan);
|
||||
+#ifdef USE_SELINUX
|
||||
+ if (selabel != NULL)
|
||||
+ krb5int_pop_fscreatecon(selabel);
|
||||
+#endif
|
||||
if (retval)
|
||||
goto cleanup;
|
||||
for (q = t->a; q; q = q->na) {
|
||||
diff --git a/src/plugins/kdb/db2/adb_openclose.c b/src/plugins/kdb/db2/adb_openclose.c
|
||||
index 7db30a33b..2b9d01921 100644
|
||||
index 9a506e9d44..f92ab47143 100644
|
||||
--- a/src/plugins/kdb/db2/adb_openclose.c
|
||||
+++ b/src/plugins/kdb/db2/adb_openclose.c
|
||||
@@ -152,7 +152,7 @@ osa_adb_init_db(osa_adb_db_t *dbp, char *filename, char *lockfilename,
|
||||
|
|
@ -494,7 +465,7 @@ index 7db30a33b..2b9d01921 100644
|
|||
* maybe someone took away write permission so we could only
|
||||
* get shared locks?
|
||||
diff --git a/src/plugins/kdb/db2/kdb_db2.c b/src/plugins/kdb/db2/kdb_db2.c
|
||||
index 5106a5c99..e481e8121 100644
|
||||
index 2c163d91cc..9a344a603e 100644
|
||||
--- a/src/plugins/kdb/db2/kdb_db2.c
|
||||
+++ b/src/plugins/kdb/db2/kdb_db2.c
|
||||
@@ -694,8 +694,8 @@ ctx_create_db(krb5_context context, krb5_db2_context *dbc)
|
||||
|
|
@ -509,7 +480,7 @@ index 5106a5c99..e481e8121 100644
|
|||
retval = errno;
|
||||
goto cleanup;
|
||||
diff --git a/src/plugins/kdb/db2/libdb2/btree/bt_open.c b/src/plugins/kdb/db2/libdb2/btree/bt_open.c
|
||||
index 2977b17f3..d5809a5a9 100644
|
||||
index 2977b17f3a..d5809a5a93 100644
|
||||
--- a/src/plugins/kdb/db2/libdb2/btree/bt_open.c
|
||||
+++ b/src/plugins/kdb/db2/libdb2/btree/bt_open.c
|
||||
@@ -60,6 +60,7 @@ static char sccsid[] = "@(#)bt_open.c 8.11 (Berkeley) 11/2/95";
|
||||
|
|
@ -530,7 +501,7 @@ index 2977b17f3..d5809a5a9 100644
|
|||
|
||||
} else {
|
||||
diff --git a/src/plugins/kdb/db2/libdb2/hash/hash.c b/src/plugins/kdb/db2/libdb2/hash/hash.c
|
||||
index 862dbb164..686a960c9 100644
|
||||
index 862dbb1640..686a960c96 100644
|
||||
--- a/src/plugins/kdb/db2/libdb2/hash/hash.c
|
||||
+++ b/src/plugins/kdb/db2/libdb2/hash/hash.c
|
||||
@@ -51,6 +51,7 @@ static char sccsid[] = "@(#)hash.c 8.12 (Berkeley) 11/7/95";
|
||||
|
|
@ -551,7 +522,7 @@ index 862dbb164..686a960c9 100644
|
|||
(void)fcntl(hashp->fp, F_SETFD, 1);
|
||||
}
|
||||
diff --git a/src/plugins/kdb/db2/libdb2/recno/rec_open.c b/src/plugins/kdb/db2/libdb2/recno/rec_open.c
|
||||
index d8b26e701..b0daa7c02 100644
|
||||
index d8b26e7011..b0daa7c021 100644
|
||||
--- a/src/plugins/kdb/db2/libdb2/recno/rec_open.c
|
||||
+++ b/src/plugins/kdb/db2/libdb2/recno/rec_open.c
|
||||
@@ -51,6 +51,7 @@ static char sccsid[] = "@(#)rec_open.c 8.12 (Berkeley) 11/18/94";
|
||||
|
|
@ -573,10 +544,10 @@ index d8b26e701..b0daa7c02 100644
|
|||
|
||||
if (fname != NULL && fcntl(rfd, F_SETFD, 1) == -1) {
|
||||
diff --git a/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c b/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c
|
||||
index 1ed72afe9..ce038fc3d 100644
|
||||
index e87688d666..30f7c00ab5 100644
|
||||
--- a/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c
|
||||
+++ b/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c
|
||||
@@ -194,7 +194,7 @@ kdb5_ldap_stash_service_password(int argc, char **argv)
|
||||
@@ -190,7 +190,7 @@ kdb5_ldap_stash_service_password(int argc, char **argv)
|
||||
|
||||
/* set password in the file */
|
||||
old_mode = umask(0177);
|
||||
|
|
@ -585,7 +556,7 @@ index 1ed72afe9..ce038fc3d 100644
|
|||
if (pfile == NULL) {
|
||||
com_err(me, errno, _("Failed to open file %s: %s"), file_name,
|
||||
strerror (errno));
|
||||
@@ -235,6 +235,9 @@ kdb5_ldap_stash_service_password(int argc, char **argv)
|
||||
@@ -231,6 +231,9 @@ kdb5_ldap_stash_service_password(int argc, char **argv)
|
||||
* Delete the existing entry and add the new entry
|
||||
*/
|
||||
FILE *newfile;
|
||||
|
|
@ -595,7 +566,7 @@ index 1ed72afe9..ce038fc3d 100644
|
|||
|
||||
mode_t omask;
|
||||
|
||||
@@ -246,7 +249,13 @@ kdb5_ldap_stash_service_password(int argc, char **argv)
|
||||
@@ -242,7 +245,13 @@ kdb5_ldap_stash_service_password(int argc, char **argv)
|
||||
}
|
||||
|
||||
omask = umask(077);
|
||||
|
|
@ -610,7 +581,7 @@ index 1ed72afe9..ce038fc3d 100644
|
|||
if (newfile == NULL) {
|
||||
com_err(me, errno, _("Error creating file %s"), tmp_file);
|
||||
diff --git a/src/util/profile/prof_file.c b/src/util/profile/prof_file.c
|
||||
index 24e41fb80..0dcb6b543 100644
|
||||
index aa951df05f..79f9500f69 100644
|
||||
--- a/src/util/profile/prof_file.c
|
||||
+++ b/src/util/profile/prof_file.c
|
||||
@@ -33,6 +33,7 @@
|
||||
|
|
@ -631,10 +602,10 @@ index 24e41fb80..0dcb6b543 100644
|
|||
retval = errno;
|
||||
if (retval == 0)
|
||||
diff --git a/src/util/support/Makefile.in b/src/util/support/Makefile.in
|
||||
index db7b030b8..321672bcb 100644
|
||||
index 86d5a950a6..1052d53a1e 100644
|
||||
--- a/src/util/support/Makefile.in
|
||||
+++ b/src/util/support/Makefile.in
|
||||
@@ -69,6 +69,7 @@ IPC_SYMS= \
|
||||
@@ -74,6 +74,7 @@ IPC_SYMS= \
|
||||
|
||||
STLIBOBJS= \
|
||||
threads.o \
|
||||
|
|
@ -642,7 +613,7 @@ index db7b030b8..321672bcb 100644
|
|||
init-addrinfo.o \
|
||||
plugins.o \
|
||||
errors.o \
|
||||
@@ -160,7 +161,7 @@ SRCS=\
|
||||
@@ -168,7 +169,7 @@ SRCS=\
|
||||
|
||||
SHLIB_EXPDEPS =
|
||||
# Add -lm if dumping thread stats, for sqrt.
|
||||
|
|
@ -653,10 +624,10 @@ index db7b030b8..321672bcb 100644
|
|||
|
||||
diff --git a/src/util/support/selinux.c b/src/util/support/selinux.c
|
||||
new file mode 100644
|
||||
index 000000000..6d41f3244
|
||||
index 0000000000..807d039da3
|
||||
--- /dev/null
|
||||
+++ b/src/util/support/selinux.c
|
||||
@@ -0,0 +1,406 @@
|
||||
@@ -0,0 +1,405 @@
|
||||
+/*
|
||||
+ * Copyright 2007,2008,2009,2011,2012,2013,2016 Red Hat, Inc. All Rights Reserved.
|
||||
+ *
|
||||
|
|
@ -755,17 +726,16 @@ index 000000000..6d41f3244
|
|||
+ }
|
||||
+}
|
||||
+
|
||||
+static security_context_t
|
||||
+static char *
|
||||
+push_fscreatecon(const char *pathname, mode_t mode)
|
||||
+{
|
||||
+ security_context_t previous, configuredsc, currentsc, derivedsc;
|
||||
+ char *previous, *configuredsc, *currentsc, *genpath;
|
||||
+ const char *derivedsc, *fullpath, *currentuser;
|
||||
+ context_t current, derived;
|
||||
+ const char *fullpath, *currentuser;
|
||||
+ char *genpath;
|
||||
+
|
||||
+ previous = configuredsc = currentsc = derivedsc = NULL;
|
||||
+ previous = configuredsc = currentsc = genpath = NULL;
|
||||
+ derivedsc = NULL;
|
||||
+ current = derived = NULL;
|
||||
+ genpath = NULL;
|
||||
+
|
||||
+ fullpath = pathname;
|
||||
+
|
||||
|
|
@ -893,7 +863,7 @@ index 000000000..6d41f3244
|
|||
+}
|
||||
+
|
||||
+static void
|
||||
+pop_fscreatecon(security_context_t previous)
|
||||
+pop_fscreatecon(char *previous)
|
||||
+{
|
||||
+ if (!is_selinux_enabled()) {
|
||||
+ return;
|
||||
|
|
@ -947,7 +917,7 @@ index 000000000..6d41f3244
|
|||
+{
|
||||
+ FILE *fp;
|
||||
+ int errno_save;
|
||||
+ security_context_t ctx;
|
||||
+ char *ctx;
|
||||
+
|
||||
+ if ((strcmp(mode, "r") == 0) ||
|
||||
+ (strcmp(mode, "rb") == 0)) {
|
||||
|
|
@ -973,7 +943,7 @@ index 000000000..6d41f3244
|
|||
+{
|
||||
+ int fd;
|
||||
+ int errno_save;
|
||||
+ security_context_t ctx;
|
||||
+ char *ctx;
|
||||
+
|
||||
+ k5_once(&labeled_once, label_mutex_init);
|
||||
+ k5_mutex_lock(&labeled_mutex);
|
||||
|
|
@ -994,7 +964,7 @@ index 000000000..6d41f3244
|
|||
+{
|
||||
+ int ret;
|
||||
+ int errno_save;
|
||||
+ security_context_t ctx;
|
||||
+ char *ctx;
|
||||
+
|
||||
+ k5_once(&labeled_once, label_mutex_init);
|
||||
+ k5_mutex_lock(&labeled_mutex);
|
||||
|
|
@ -1015,7 +985,7 @@ index 000000000..6d41f3244
|
|||
+{
|
||||
+ int ret;
|
||||
+ int errno_save;
|
||||
+ security_context_t ctx;
|
||||
+ char *ctx;
|
||||
+
|
||||
+ k5_once(&labeled_once, label_mutex_init);
|
||||
+ k5_mutex_lock(&labeled_mutex);
|
||||
|
|
@ -1036,7 +1006,7 @@ index 000000000..6d41f3244
|
|||
+{
|
||||
+ int fd;
|
||||
+ int errno_save;
|
||||
+ security_context_t ctx;
|
||||
+ char *ctx;
|
||||
+ mode_t mode;
|
||||
+ va_list ap;
|
||||
+
|
||||
|
|
@ -1063,3 +1033,6 @@ index 000000000..6d41f3244
|
|||
+}
|
||||
+
|
||||
+#endif /* USE_SELINUX */
|
||||
--
|
||||
2.45.1
|
||||
|
||||
|
|
@ -1,18 +1,20 @@
|
|||
From d205539d89b857f7bd2b09dfc875d5cdd79167b7 Mon Sep 17 00:00:00 2001
|
||||
From 393830d96000ed692aa9a99ef87187d6f2863931 Mon Sep 17 00:00:00 2001
|
||||
From: Robbie Harwood <rharwood@redhat.com>
|
||||
Date: Tue, 23 Aug 2016 16:49:25 -0400
|
||||
Subject: [PATCH] krb5-1.9-debuginfo.patch
|
||||
Subject: [PATCH] [downstream] fix debuginfo with y.tab.c
|
||||
|
||||
We want to keep these y.tab.c files around because the debuginfo points to
|
||||
them. It would be more elegant at the end to use symbolic links, but that
|
||||
could mess up people working in the tree on other things.
|
||||
|
||||
Last-updated: krb5-1.9
|
||||
---
|
||||
src/kadmin/cli/Makefile.in | 5 +++++
|
||||
src/plugins/kdb/ldap/ldap_util/Makefile.in | 2 +-
|
||||
2 files changed, 6 insertions(+), 1 deletion(-)
|
||||
|
||||
diff --git a/src/kadmin/cli/Makefile.in b/src/kadmin/cli/Makefile.in
|
||||
index adfea6e2b..d1327e400 100644
|
||||
index adfea6e2b5..d1327e400b 100644
|
||||
--- a/src/kadmin/cli/Makefile.in
|
||||
+++ b/src/kadmin/cli/Makefile.in
|
||||
@@ -37,3 +37,8 @@ clean-unix::
|
||||
|
|
@ -25,7 +27,7 @@ index adfea6e2b..d1327e400 100644
|
|||
+ $(YACC.y) $<
|
||||
+ $(CP) y.tab.c $@
|
||||
diff --git a/src/plugins/kdb/ldap/ldap_util/Makefile.in b/src/plugins/kdb/ldap/ldap_util/Makefile.in
|
||||
index 8669c2436..a22f23c02 100644
|
||||
index 8669c2436c..a22f23c02c 100644
|
||||
--- a/src/plugins/kdb/ldap/ldap_util/Makefile.in
|
||||
+++ b/src/plugins/kdb/ldap/ldap_util/Makefile.in
|
||||
@@ -20,7 +20,7 @@ $(PROG): $(OBJS) $(KADMSRV_DEPLIBS) $(KRB5_BASE_DEPLIB) $(GETDATE)
|
||||
|
|
@ -37,3 +39,6 @@ index 8669c2436..a22f23c02 100644
|
|||
|
||||
install:
|
||||
$(INSTALL_PROGRAM) $(PROG) ${DESTDIR}$(ADMIN_BINDIR)/$(PROG)
|
||||
--
|
||||
2.45.1
|
||||
|
||||
File diff suppressed because it is too large
Load diff
|
|
@ -1,7 +1,7 @@
|
|||
From ca3c0fc3fd80b3a9953da47f64beb8b24bd46f08 Mon Sep 17 00:00:00 2001
|
||||
From 7b6453903c248a761d3ceb538dfacebbf3d3a9ff Mon Sep 17 00:00:00 2001
|
||||
From: Robbie Harwood <rharwood@redhat.com>
|
||||
Date: Fri, 9 Nov 2018 15:12:21 -0500
|
||||
Subject: [PATCH] krb5-1.17post5 FIPS with PRNG and RADIUS without SPAKE
|
||||
Subject: [PATCH] [downstream] FIPS with PRNG and RADIUS and MD4
|
||||
|
||||
NB: Use openssl's PRNG in FIPS mode and taint within krad.
|
||||
|
||||
|
|
@ -15,41 +15,69 @@ This will slow down some calls slightly (FIPS_mode() takes multiple
|
|||
locks), but not for any ciphers we care about - which is to say that
|
||||
AES is fine. Shame about SPAKE though.
|
||||
|
||||
post5 removes SPAKE entirely.
|
||||
post6 restores MD4 (and therefore keygen-only RC4).
|
||||
|
||||
post7 restores MD5 and adds radius_md5_fips_override.
|
||||
|
||||
post8 silences a static analyzer warning.
|
||||
|
||||
Last-updated: krb5-1.20
|
||||
---
|
||||
src/lib/crypto/krb/prng.c | 11 ++++-
|
||||
doc/admin/conf_files/krb5_conf.rst | 6 +++
|
||||
src/lib/crypto/krb/prng.c | 15 +++++-
|
||||
.../crypto/openssl/enc_provider/camellia.c | 6 +++
|
||||
src/lib/crypto/openssl/enc_provider/rc4.c | 13 +++++-
|
||||
.../crypto/openssl/hash_provider/hash_evp.c | 4 ++
|
||||
.../crypto/openssl/hash_provider/hash_evp.c | 12 +++++
|
||||
src/lib/crypto/openssl/hmac.c | 6 ++-
|
||||
src/lib/krad/attr.c | 45 ++++++++++++++-----
|
||||
src/lib/krad/attrset.c | 5 ++-
|
||||
src/lib/krad/internal.h | 13 +++++-
|
||||
src/lib/krad/packet.c | 22 ++++-----
|
||||
src/lib/krad/remote.c | 10 ++++-
|
||||
src/lib/krad/attr.c | 46 ++++++++++++++-----
|
||||
src/lib/krad/attrset.c | 5 +-
|
||||
src/lib/krad/internal.h | 28 ++++++++++-
|
||||
src/lib/krad/packet.c | 22 +++++----
|
||||
src/lib/krad/remote.c | 10 +++-
|
||||
src/lib/krad/t_attr.c | 3 +-
|
||||
src/lib/krad/t_attrset.c | 4 +-
|
||||
src/plugins/preauth/spake/spake_client.c | 6 +++
|
||||
src/plugins/preauth/spake/spake_kdc.c | 6 +++
|
||||
14 files changed, 121 insertions(+), 33 deletions(-)
|
||||
15 files changed, 155 insertions(+), 33 deletions(-)
|
||||
|
||||
diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst
|
||||
index f22d5db11b..a33711d918 100644
|
||||
--- a/doc/admin/conf_files/krb5_conf.rst
|
||||
+++ b/doc/admin/conf_files/krb5_conf.rst
|
||||
@@ -330,6 +330,12 @@ The libdefaults section may contain any of the following relations:
|
||||
qualification of shortnames, set this relation to the empty string
|
||||
with ``qualify_shortname = ""``. (New in release 1.18.)
|
||||
|
||||
+**radius_md5_fips_override**
|
||||
+ Downstream-only option to enable use of MD5 in RADIUS
|
||||
+ communication (libkrad). This allows for local (or protected
|
||||
+ tunnel) communication with a RADIUS server that doesn't use krad
|
||||
+ (e.g., freeradius) while in FIPS mode.
|
||||
+
|
||||
**rdns**
|
||||
If this flag is true, reverse name lookup will be used in addition
|
||||
to forward name lookup to canonicalizing hostnames for use in
|
||||
diff --git a/src/lib/crypto/krb/prng.c b/src/lib/crypto/krb/prng.c
|
||||
index cb9ca9b98..f0e9984ca 100644
|
||||
index d6b79e2dea..9e80a03d21 100644
|
||||
--- a/src/lib/crypto/krb/prng.c
|
||||
+++ b/src/lib/crypto/krb/prng.c
|
||||
@@ -26,6 +26,8 @@
|
||||
@@ -26,6 +26,12 @@
|
||||
|
||||
#include "crypto_int.h"
|
||||
|
||||
+#include <openssl/rand.h>
|
||||
+
|
||||
+#if OPENSSL_VERSION_NUMBER < 0x30000000L
|
||||
+#include <openssl/crypto.h>
|
||||
+#endif
|
||||
+
|
||||
krb5_error_code KRB5_CALLCONV
|
||||
krb5_c_random_seed(krb5_context context, krb5_data *data)
|
||||
{
|
||||
@@ -99,9 +101,16 @@ krb5_boolean
|
||||
k5_get_os_entropy(unsigned char *buf, size_t len, int strong)
|
||||
@@ -96,9 +102,16 @@ cleanup:
|
||||
static krb5_boolean
|
||||
get_os_entropy(unsigned char *buf, size_t len)
|
||||
{
|
||||
const char *device;
|
||||
-#if defined(__linux__) && defined(SYS_getrandom)
|
||||
int r;
|
||||
|
||||
|
|
@ -65,10 +93,10 @@ index cb9ca9b98..f0e9984ca 100644
|
|||
/*
|
||||
* Pull from the /dev/urandom pool, but require it to have been seeded.
|
||||
diff --git a/src/lib/crypto/openssl/enc_provider/camellia.c b/src/lib/crypto/openssl/enc_provider/camellia.c
|
||||
index 2da691329..f79679a0b 100644
|
||||
index 01920e6ce1..d9f327add6 100644
|
||||
--- a/src/lib/crypto/openssl/enc_provider/camellia.c
|
||||
+++ b/src/lib/crypto/openssl/enc_provider/camellia.c
|
||||
@@ -304,6 +304,9 @@ krb5int_camellia_cbc_mac(krb5_key key, const krb5_crypto_iov *data,
|
||||
@@ -387,6 +387,9 @@ krb5int_camellia_cbc_mac(krb5_key key, const krb5_crypto_iov *data,
|
||||
unsigned char blockY[CAMELLIA_BLOCK_SIZE], blockB[CAMELLIA_BLOCK_SIZE];
|
||||
struct iov_cursor cursor;
|
||||
|
||||
|
|
@ -78,7 +106,7 @@ index 2da691329..f79679a0b 100644
|
|||
if (output->length < CAMELLIA_BLOCK_SIZE)
|
||||
return KRB5_BAD_MSIZE;
|
||||
|
||||
@@ -331,6 +334,9 @@ static krb5_error_code
|
||||
@@ -418,6 +421,9 @@ static krb5_error_code
|
||||
krb5int_camellia_init_state (const krb5_keyblock *key, krb5_keyusage usage,
|
||||
krb5_data *state)
|
||||
{
|
||||
|
|
@ -89,10 +117,10 @@ index 2da691329..f79679a0b 100644
|
|||
state->data = (void *) malloc(16);
|
||||
if (state->data == NULL)
|
||||
diff --git a/src/lib/crypto/openssl/enc_provider/rc4.c b/src/lib/crypto/openssl/enc_provider/rc4.c
|
||||
index a65d57b7a..6ccaca94a 100644
|
||||
index 448d563348..ce63cb5f1b 100644
|
||||
--- a/src/lib/crypto/openssl/enc_provider/rc4.c
|
||||
+++ b/src/lib/crypto/openssl/enc_provider/rc4.c
|
||||
@@ -66,6 +66,9 @@ k5_arcfour_docrypt(krb5_key key, const krb5_data *state, krb5_crypto_iov *data,
|
||||
@@ -69,6 +69,9 @@ k5_arcfour_docrypt(krb5_key key, const krb5_data *state, krb5_crypto_iov *data,
|
||||
EVP_CIPHER_CTX *ctx = NULL;
|
||||
struct arcfour_state *arcstate;
|
||||
|
||||
|
|
@ -102,7 +130,7 @@ index a65d57b7a..6ccaca94a 100644
|
|||
arcstate = (state != NULL) ? (void *)state->data : NULL;
|
||||
if (arcstate != NULL) {
|
||||
ctx = arcstate->ctx;
|
||||
@@ -113,7 +116,12 @@ k5_arcfour_docrypt(krb5_key key, const krb5_data *state, krb5_crypto_iov *data,
|
||||
@@ -116,7 +119,12 @@ k5_arcfour_docrypt(krb5_key key, const krb5_data *state, krb5_crypto_iov *data,
|
||||
static void
|
||||
k5_arcfour_free_state(krb5_data *state)
|
||||
{
|
||||
|
|
@ -116,7 +144,7 @@ index a65d57b7a..6ccaca94a 100644
|
|||
|
||||
EVP_CIPHER_CTX_free(arcstate->ctx);
|
||||
free(arcstate);
|
||||
@@ -125,6 +133,9 @@ k5_arcfour_init_state(const krb5_keyblock *key,
|
||||
@@ -128,6 +136,9 @@ k5_arcfour_init_state(const krb5_keyblock *key,
|
||||
{
|
||||
struct arcfour_state *arcstate;
|
||||
|
||||
|
|
@ -127,56 +155,64 @@ index a65d57b7a..6ccaca94a 100644
|
|||
* The cipher state here is a saved pointer to a struct arcfour_state
|
||||
* object, rather than a flat byte array as in most enc providers. The
|
||||
diff --git a/src/lib/crypto/openssl/hash_provider/hash_evp.c b/src/lib/crypto/openssl/hash_provider/hash_evp.c
|
||||
index 957ed8d9c..8c1fd7f59 100644
|
||||
index f2fbffdb29..11659908bb 100644
|
||||
--- a/src/lib/crypto/openssl/hash_provider/hash_evp.c
|
||||
+++ b/src/lib/crypto/openssl/hash_provider/hash_evp.c
|
||||
@@ -64,12 +64,16 @@ hash_evp(const EVP_MD *type, const krb5_crypto_iov *data, size_t num_data,
|
||||
@@ -60,6 +60,11 @@ hash_evp(const EVP_MD *type, const krb5_crypto_iov *data, size_t num_data,
|
||||
if (ctx == NULL)
|
||||
return ENOMEM;
|
||||
|
||||
+ if (type == EVP_md4() || type == EVP_md5()) {
|
||||
+ /* See comments below in hash_md4() and hash_md5(). */
|
||||
+ EVP_MD_CTX_set_flags(ctx, EVP_MD_CTX_FLAG_NON_FIPS_ALLOW);
|
||||
+ }
|
||||
+
|
||||
ok = EVP_DigestInit_ex(ctx, type, NULL);
|
||||
for (i = 0; i < num_data; i++) {
|
||||
if (!SIGN_IOV(&data[i]))
|
||||
@@ -78,6 +83,11 @@ hash_evp(const EVP_MD *type, const krb5_crypto_iov *data, size_t num_data,
|
||||
static krb5_error_code
|
||||
hash_md4(const krb5_crypto_iov *data, size_t num_data, krb5_data *output)
|
||||
{
|
||||
+ if (FIPS_mode())
|
||||
+ return KRB5_CRYPTO_INTERNAL;
|
||||
+ /*
|
||||
+ * MD4 is needed in FIPS mode to perform key generation for RC4 keys used
|
||||
+ * by IPA. These keys are only used along a (separately) secured channel
|
||||
+ * for legacy reasons when performing trusts to Active Directory.
|
||||
+ */
|
||||
return hash_evp(EVP_md4(), data, num_data, output);
|
||||
}
|
||||
|
||||
@@ -90,6 +100,8 @@ const struct krb5_hash_provider krb5int_hash_md4 = {
|
||||
static krb5_error_code
|
||||
hash_md5(const krb5_crypto_iov *data, size_t num_data, krb5_data *output)
|
||||
{
|
||||
+ if (FIPS_mode())
|
||||
+ return KRB5_CRYPTO_INTERNAL;
|
||||
+ /* MD5 is needed in FIPS mode for communication with RADIUS servers. This
|
||||
+ * is gated in libkrad by libdefaults->radius_md5_fips_override. */
|
||||
return hash_evp(EVP_md5(), data, num_data, output);
|
||||
}
|
||||
|
||||
diff --git a/src/lib/crypto/openssl/hmac.c b/src/lib/crypto/openssl/hmac.c
|
||||
index 7dc59dcc0..769a50c00 100644
|
||||
index bf12b8d6a0..f21e268f7f 100644
|
||||
--- a/src/lib/crypto/openssl/hmac.c
|
||||
+++ b/src/lib/crypto/openssl/hmac.c
|
||||
@@ -103,7 +103,11 @@ map_digest(const struct krb5_hash_provider *hash)
|
||||
@@ -111,7 +111,11 @@ map_digest(const struct krb5_hash_provider *hash)
|
||||
return EVP_sha256();
|
||||
else if (!strncmp(hash->hash_name, "SHA-384",7))
|
||||
else if (hash == &krb5int_hash_sha384)
|
||||
return EVP_sha384();
|
||||
- else if (!strncmp(hash->hash_name, "MD5", 3))
|
||||
- else if (hash == &krb5int_hash_md5)
|
||||
+
|
||||
+ if (FIPS_mode())
|
||||
+ return NULL;
|
||||
+
|
||||
+ if (!strncmp(hash->hash_name, "MD5", 3))
|
||||
+ if (hash == &krb5int_hash_md5)
|
||||
return EVP_md5();
|
||||
else if (!strncmp(hash->hash_name, "MD4", 3))
|
||||
else if (hash == &krb5int_hash_md4)
|
||||
return EVP_md4();
|
||||
diff --git a/src/lib/krad/attr.c b/src/lib/krad/attr.c
|
||||
index 9c13d9d75..275327e67 100644
|
||||
index 9c13d9d755..42d354a3b5 100644
|
||||
--- a/src/lib/krad/attr.c
|
||||
+++ b/src/lib/krad/attr.c
|
||||
@@ -30,6 +30,7 @@
|
||||
#include <k5-int.h>
|
||||
#include "internal.h"
|
||||
|
||||
+#include <openssl/crypto.h>
|
||||
#include <string.h>
|
||||
|
||||
/* RFC 2865 */
|
||||
@@ -38,7 +39,8 @@
|
||||
@@ -38,7 +38,8 @@
|
||||
typedef krb5_error_code
|
||||
(*attribute_transform_fn)(krb5_context ctx, const char *secret,
|
||||
const unsigned char *auth, const krb5_data *in,
|
||||
|
|
@ -186,7 +222,7 @@ index 9c13d9d75..275327e67 100644
|
|||
|
||||
typedef struct {
|
||||
const char *name;
|
||||
@@ -51,12 +53,14 @@ typedef struct {
|
||||
@@ -51,12 +52,14 @@ typedef struct {
|
||||
static krb5_error_code
|
||||
user_password_encode(krb5_context ctx, const char *secret,
|
||||
const unsigned char *auth, const krb5_data *in,
|
||||
|
|
@ -203,7 +239,7 @@ index 9c13d9d75..275327e67 100644
|
|||
|
||||
static const attribute_record attributes[UCHAR_MAX] = {
|
||||
{"User-Name", 1, MAX_ATTRSIZE, NULL, NULL},
|
||||
@@ -128,7 +132,8 @@ static const attribute_record attributes[UCHAR_MAX] = {
|
||||
@@ -128,7 +131,8 @@ static const attribute_record attributes[UCHAR_MAX] = {
|
||||
static krb5_error_code
|
||||
user_password_encode(krb5_context ctx, const char *secret,
|
||||
const unsigned char *auth, const krb5_data *in,
|
||||
|
|
@ -213,20 +249,21 @@ index 9c13d9d75..275327e67 100644
|
|||
{
|
||||
const unsigned char *indx;
|
||||
krb5_error_code retval;
|
||||
@@ -154,8 +159,14 @@ user_password_encode(krb5_context ctx, const char *secret,
|
||||
@@ -154,8 +158,15 @@ user_password_encode(krb5_context ctx, const char *secret,
|
||||
for (blck = 0, indx = auth; blck * BLOCKSIZE < len; blck++) {
|
||||
memcpy(tmp.data + seclen, indx, BLOCKSIZE);
|
||||
|
||||
- retval = krb5_c_make_checksum(ctx, CKSUMTYPE_RSA_MD5, NULL, 0, &tmp,
|
||||
- &sum);
|
||||
+ if (FIPS_mode()) {
|
||||
+ if (kr_use_fips(ctx)) {
|
||||
+ /* Skip encryption here. Taint so that we won't pass it out of
|
||||
+ * the machine by accident. */
|
||||
+ *is_fips = TRUE;
|
||||
+ sum.contents = calloc(1, BLOCKSIZE);
|
||||
+ } else
|
||||
+ } else {
|
||||
+ retval = krb5_c_make_checksum(ctx, CKSUMTYPE_RSA_MD5, NULL, 0, &tmp,
|
||||
+ &sum);
|
||||
+ }
|
||||
if (retval != 0) {
|
||||
zap(tmp.data, tmp.length);
|
||||
zap(outbuf, len);
|
||||
|
|
@ -240,24 +277,25 @@ index 9c13d9d75..275327e67 100644
|
|||
{
|
||||
const unsigned char *indx;
|
||||
krb5_error_code retval;
|
||||
@@ -204,8 +216,14 @@ user_password_decode(krb5_context ctx, const char *secret,
|
||||
@@ -204,8 +216,15 @@ user_password_decode(krb5_context ctx, const char *secret,
|
||||
for (blck = 0, indx = auth; blck * BLOCKSIZE < in->length; blck++) {
|
||||
memcpy(tmp.data + seclen, indx, BLOCKSIZE);
|
||||
|
||||
- retval = krb5_c_make_checksum(ctx, CKSUMTYPE_RSA_MD5, NULL, 0,
|
||||
- &tmp, &sum);
|
||||
+ if (FIPS_mode()) {
|
||||
+ if (kr_use_fips(ctx)) {
|
||||
+ /* Skip encryption here. Taint so that we won't pass it out of
|
||||
+ * the machine by accident. */
|
||||
+ *is_fips = TRUE;
|
||||
+ sum.contents = calloc(1, BLOCKSIZE);
|
||||
+ } else
|
||||
+ } else {
|
||||
+ retval = krb5_c_make_checksum(ctx, CKSUMTYPE_RSA_MD5, NULL, 0,
|
||||
+ &tmp, &sum);
|
||||
+ }
|
||||
if (retval != 0) {
|
||||
zap(tmp.data, tmp.length);
|
||||
zap(outbuf, in->length);
|
||||
@@ -248,7 +266,7 @@ krb5_error_code
|
||||
@@ -248,7 +267,7 @@ krb5_error_code
|
||||
kr_attr_encode(krb5_context ctx, const char *secret,
|
||||
const unsigned char *auth, krad_attr type,
|
||||
const krb5_data *in, unsigned char outbuf[MAX_ATTRSIZE],
|
||||
|
|
@ -266,7 +304,7 @@ index 9c13d9d75..275327e67 100644
|
|||
{
|
||||
krb5_error_code retval;
|
||||
|
||||
@@ -265,7 +283,8 @@ kr_attr_encode(krb5_context ctx, const char *secret,
|
||||
@@ -265,7 +284,8 @@ kr_attr_encode(krb5_context ctx, const char *secret,
|
||||
return 0;
|
||||
}
|
||||
|
||||
|
|
@ -276,7 +314,7 @@ index 9c13d9d75..275327e67 100644
|
|||
}
|
||||
|
||||
krb5_error_code
|
||||
@@ -274,6 +293,7 @@ kr_attr_decode(krb5_context ctx, const char *secret, const unsigned char *auth,
|
||||
@@ -274,6 +294,7 @@ kr_attr_decode(krb5_context ctx, const char *secret, const unsigned char *auth,
|
||||
unsigned char outbuf[MAX_ATTRSIZE], size_t *outlen)
|
||||
{
|
||||
krb5_error_code retval;
|
||||
|
|
@ -284,7 +322,7 @@ index 9c13d9d75..275327e67 100644
|
|||
|
||||
retval = kr_attr_valid(type, in);
|
||||
if (retval != 0)
|
||||
@@ -288,7 +308,8 @@ kr_attr_decode(krb5_context ctx, const char *secret, const unsigned char *auth,
|
||||
@@ -288,7 +309,8 @@ kr_attr_decode(krb5_context ctx, const char *secret, const unsigned char *auth,
|
||||
return 0;
|
||||
}
|
||||
|
||||
|
|
@ -295,7 +333,7 @@ index 9c13d9d75..275327e67 100644
|
|||
|
||||
krad_attr
|
||||
diff --git a/src/lib/krad/attrset.c b/src/lib/krad/attrset.c
|
||||
index 03c613716..d89982a13 100644
|
||||
index f309f1581c..6ec031e320 100644
|
||||
--- a/src/lib/krad/attrset.c
|
||||
+++ b/src/lib/krad/attrset.c
|
||||
@@ -167,7 +167,8 @@ krad_attrset_copy(const krad_attrset *set, krad_attrset **copy)
|
||||
|
|
@ -318,10 +356,19 @@ index 03c613716..d89982a13 100644
|
|||
return retval;
|
||||
|
||||
diff --git a/src/lib/krad/internal.h b/src/lib/krad/internal.h
|
||||
index 996a89372..a53ce31ce 100644
|
||||
index 7619563fc5..e123763954 100644
|
||||
--- a/src/lib/krad/internal.h
|
||||
+++ b/src/lib/krad/internal.h
|
||||
@@ -49,6 +49,13 @@
|
||||
@@ -39,6 +39,8 @@
|
||||
#include <sys/socket.h>
|
||||
#include <netdb.h>
|
||||
|
||||
+#include <openssl/crypto.h>
|
||||
+
|
||||
#ifndef UCHAR_MAX
|
||||
#define UCHAR_MAX 255
|
||||
#endif
|
||||
@@ -49,6 +51,13 @@
|
||||
|
||||
typedef struct krad_remote_st krad_remote;
|
||||
|
||||
|
|
@ -335,7 +382,7 @@ index 996a89372..a53ce31ce 100644
|
|||
/* Validate constraints of an attribute. */
|
||||
krb5_error_code
|
||||
kr_attr_valid(krad_attr type, const krb5_data *data);
|
||||
@@ -57,7 +64,8 @@ kr_attr_valid(krad_attr type, const krb5_data *data);
|
||||
@@ -57,7 +66,8 @@ kr_attr_valid(krad_attr type, const krb5_data *data);
|
||||
krb5_error_code
|
||||
kr_attr_encode(krb5_context ctx, const char *secret, const unsigned char *auth,
|
||||
krad_attr type, const krb5_data *in,
|
||||
|
|
@ -345,7 +392,7 @@ index 996a89372..a53ce31ce 100644
|
|||
|
||||
/* Decode an attribute. */
|
||||
krb5_error_code
|
||||
@@ -69,7 +77,8 @@ kr_attr_decode(krb5_context ctx, const char *secret, const unsigned char *auth,
|
||||
@@ -69,7 +79,8 @@ kr_attr_decode(krb5_context ctx, const char *secret, const unsigned char *auth,
|
||||
krb5_error_code
|
||||
kr_attrset_encode(const krad_attrset *set, const char *secret,
|
||||
const unsigned char *auth,
|
||||
|
|
@ -355,19 +402,29 @@ index 996a89372..a53ce31ce 100644
|
|||
|
||||
/* Decode attributes from a buffer. */
|
||||
krb5_error_code
|
||||
@@ -156,4 +167,17 @@ gai_error_code(int err)
|
||||
}
|
||||
}
|
||||
|
||||
+static inline krb5_boolean
|
||||
+kr_use_fips(krb5_context ctx)
|
||||
+{
|
||||
+ int val = 0;
|
||||
+
|
||||
+ if (!FIPS_mode())
|
||||
+ return 0;
|
||||
+
|
||||
+ (void)profile_get_boolean(ctx->profile, "libdefaults",
|
||||
+ "radius_md5_fips_override", NULL, 0, &val);
|
||||
+ return !val;
|
||||
+}
|
||||
+
|
||||
#endif /* INTERNAL_H_ */
|
||||
diff --git a/src/lib/krad/packet.c b/src/lib/krad/packet.c
|
||||
index c597174b6..794ac84c4 100644
|
||||
index c597174b65..fc2d248001 100644
|
||||
--- a/src/lib/krad/packet.c
|
||||
+++ b/src/lib/krad/packet.c
|
||||
@@ -32,6 +32,7 @@
|
||||
#include <string.h>
|
||||
|
||||
#include <arpa/inet.h>
|
||||
+#include <openssl/crypto.h>
|
||||
|
||||
typedef unsigned char uchar;
|
||||
|
||||
@@ -53,12 +54,6 @@ typedef unsigned char uchar;
|
||||
@@ -53,12 +53,6 @@ typedef unsigned char uchar;
|
||||
#define pkt_auth(p) ((uchar *)offset(&(p)->pkt, OFFSET_AUTH))
|
||||
#define pkt_attr(p) ((unsigned char *)offset(&(p)->pkt, OFFSET_ATTR))
|
||||
|
||||
|
|
@ -380,19 +437,20 @@ index c597174b6..794ac84c4 100644
|
|||
typedef struct {
|
||||
uchar x[(UCHAR_MAX + 1) / 8];
|
||||
} idmap;
|
||||
@@ -187,8 +182,13 @@ auth_generate_response(krb5_context ctx, const char *secret,
|
||||
@@ -187,8 +181,14 @@ auth_generate_response(krb5_context ctx, const char *secret,
|
||||
memcpy(data.data + response->pkt.length, secret, strlen(secret));
|
||||
|
||||
/* Hash it. */
|
||||
- retval = krb5_c_make_checksum(ctx, CKSUMTYPE_RSA_MD5, NULL, 0, &data,
|
||||
- &hash);
|
||||
+ if (FIPS_mode()) {
|
||||
+ if (kr_use_fips(ctx)) {
|
||||
+ /* This checksum does very little security-wise anyway, so don't
|
||||
+ * taint. */
|
||||
+ hash.contents = calloc(1, AUTH_FIELD_SIZE);
|
||||
+ } else
|
||||
+ } else {
|
||||
+ retval = krb5_c_make_checksum(ctx, CKSUMTYPE_RSA_MD5, NULL, 0, &data,
|
||||
+ &hash);
|
||||
+ }
|
||||
free(data.data);
|
||||
if (retval != 0)
|
||||
return retval;
|
||||
|
|
@ -424,7 +482,7 @@ index c597174b6..794ac84c4 100644
|
|||
}
|
||||
|
||||
diff --git a/src/lib/krad/remote.c b/src/lib/krad/remote.c
|
||||
index 437f7e91a..0f90443ce 100644
|
||||
index 06ae751bc8..929f1cef67 100644
|
||||
--- a/src/lib/krad/remote.c
|
||||
+++ b/src/lib/krad/remote.c
|
||||
@@ -263,7 +263,7 @@ on_io_write(krad_remote *rr)
|
||||
|
|
@ -445,7 +503,7 @@ index 437f7e91a..0f90443ce 100644
|
|||
request_finish(r, 0, rsp);
|
||||
break;
|
||||
}
|
||||
@@ -455,6 +455,12 @@ kr_remote_send(krad_remote *rr, krad_code code, krad_attrset *attrs,
|
||||
@@ -460,6 +460,12 @@ kr_remote_send(krad_remote *rr, krad_code code, krad_attrset *attrs,
|
||||
(krad_packet_iter_cb)iterator, &r, &tmp);
|
||||
if (retval != 0)
|
||||
goto error;
|
||||
|
|
@ -459,7 +517,7 @@ index 437f7e91a..0f90443ce 100644
|
|||
K5_TAILQ_FOREACH(r, &rr->list, list) {
|
||||
if (r->request == tmp) {
|
||||
diff --git a/src/lib/krad/t_attr.c b/src/lib/krad/t_attr.c
|
||||
index eb2a780c8..4d285ad9d 100644
|
||||
index eb2a780c89..4d285ad9de 100644
|
||||
--- a/src/lib/krad/t_attr.c
|
||||
+++ b/src/lib/krad/t_attr.c
|
||||
@@ -50,6 +50,7 @@ main()
|
||||
|
|
@ -480,7 +538,7 @@ index eb2a780c8..4d285ad9d 100644
|
|||
insist(len == sizeof(encoded));
|
||||
insist(memcmp(outbuf, encoded, len) == 0);
|
||||
diff --git a/src/lib/krad/t_attrset.c b/src/lib/krad/t_attrset.c
|
||||
index 7928335ca..0f9576253 100644
|
||||
index 7928335ca4..0f95762534 100644
|
||||
--- a/src/lib/krad/t_attrset.c
|
||||
+++ b/src/lib/krad/t_attrset.c
|
||||
@@ -49,6 +49,7 @@ main()
|
||||
|
|
@ -502,7 +560,7 @@ index 7928335ca..0f9576253 100644
|
|||
|
||||
/* Manually encode User-Name. */
|
||||
diff --git a/src/plugins/preauth/spake/spake_client.c b/src/plugins/preauth/spake/spake_client.c
|
||||
index 00734a13b..a3ce22b70 100644
|
||||
index 00734a13b5..a3ce22b70f 100644
|
||||
--- a/src/plugins/preauth/spake/spake_client.c
|
||||
+++ b/src/plugins/preauth/spake/spake_client.c
|
||||
@@ -38,6 +38,8 @@
|
||||
|
|
@ -526,7 +584,7 @@ index 00734a13b..a3ce22b70 100644
|
|||
vt->name = "spake";
|
||||
vt->pa_type_list = pa_types;
|
||||
diff --git a/src/plugins/preauth/spake/spake_kdc.c b/src/plugins/preauth/spake/spake_kdc.c
|
||||
index 59e88409e..1b3e569e9 100644
|
||||
index 1a772d450f..232e78bc05 100644
|
||||
--- a/src/plugins/preauth/spake/spake_kdc.c
|
||||
+++ b/src/plugins/preauth/spake/spake_kdc.c
|
||||
@@ -41,6 +41,8 @@
|
||||
|
|
@ -538,7 +596,7 @@ index 59e88409e..1b3e569e9 100644
|
|||
/*
|
||||
* The SPAKE kdcpreauth module uses a secure cookie containing the following
|
||||
* concatenated fields (all integer fields are big-endian):
|
||||
@@ -578,6 +580,10 @@ kdcpreauth_spake_initvt(krb5_context context, int maj_ver, int min_ver,
|
||||
@@ -551,6 +553,10 @@ kdcpreauth_spake_initvt(krb5_context context, int maj_ver, int min_ver,
|
||||
|
||||
if (maj_ver != 1)
|
||||
return KRB5_PLUGIN_VER_NOTSUPP;
|
||||
|
|
@ -549,3 +607,6 @@ index 59e88409e..1b3e569e9 100644
|
|||
vt = (krb5_kdcpreauth_vtable)vtable;
|
||||
vt->name = "spake";
|
||||
vt->pa_type_list = pa_types;
|
||||
--
|
||||
2.45.1
|
||||
|
||||
|
|
@ -0,0 +1,82 @@
|
|||
From 707fa7bd2be6327343dc8fc5c20dc77645524518 Mon Sep 17 00:00:00 2001
|
||||
From: Julien Rische <jrische@redhat.com>
|
||||
Date: Thu, 5 May 2022 17:15:12 +0200
|
||||
Subject: [PATCH] [downstream] Allow krad UDP/TCP localhost connection
|
||||
with FIPS
|
||||
|
||||
libkrad allows to establish connections only to UNIX socket in FIPS
|
||||
mode, because MD5 digest is not considered safe enough to be used for
|
||||
network communication. However, FreeRadius requires connection on TCP or
|
||||
UDP ports.
|
||||
|
||||
This commit allows TCP or UDP connections in FIPS mode if destination is
|
||||
localhost.
|
||||
|
||||
Resolves: rhbz#2082189
|
||||
---
|
||||
src/lib/krad/remote.c | 35 +++++++++++++++++++++++++++++++++--
|
||||
1 file changed, 33 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/src/lib/krad/remote.c b/src/lib/krad/remote.c
|
||||
index 929f1cef67..063f17a613 100644
|
||||
--- a/src/lib/krad/remote.c
|
||||
+++ b/src/lib/krad/remote.c
|
||||
@@ -33,6 +33,7 @@
|
||||
|
||||
#include <string.h>
|
||||
#include <unistd.h>
|
||||
+#include <stdbool.h>
|
||||
|
||||
#include <sys/un.h>
|
||||
|
||||
@@ -74,6 +75,35 @@ on_io(verto_ctx *ctx, verto_ev *ev);
|
||||
static void
|
||||
on_timeout(verto_ctx *ctx, verto_ev *ev);
|
||||
|
||||
+static in_addr_t get_in_addr(struct addrinfo *info)
|
||||
+{ return ((struct sockaddr_in *)(info->ai_addr))->sin_addr.s_addr; }
|
||||
+
|
||||
+static struct in6_addr *get_in6_addr(struct addrinfo *info)
|
||||
+{ return &(((struct sockaddr_in6 *)(info->ai_addr))->sin6_addr); }
|
||||
+
|
||||
+static bool is_inet_localhost(struct addrinfo *info)
|
||||
+{
|
||||
+ struct addrinfo *p;
|
||||
+
|
||||
+ for (p = info; p; p = p->ai_next) {
|
||||
+ switch (p->ai_family) {
|
||||
+ case AF_INET:
|
||||
+ if (IN_LOOPBACKNET != (get_in_addr(p) & IN_CLASSA_NET
|
||||
+ >> IN_CLASSA_NSHIFT))
|
||||
+ return false;
|
||||
+ break;
|
||||
+ case AF_INET6:
|
||||
+ if (!IN6_IS_ADDR_LOOPBACK(get_in6_addr(p)))
|
||||
+ return false;
|
||||
+ break;
|
||||
+ default:
|
||||
+ return false;
|
||||
+ }
|
||||
+ }
|
||||
+
|
||||
+ return true;
|
||||
+}
|
||||
+
|
||||
/* Iterate over the set of outstanding packets. */
|
||||
static const krad_packet *
|
||||
iterator(request **out)
|
||||
@@ -460,8 +490,9 @@ kr_remote_send(krad_remote *rr, krad_code code, krad_attrset *attrs,
|
||||
(krad_packet_iter_cb)iterator, &r, &tmp);
|
||||
if (retval != 0)
|
||||
goto error;
|
||||
- else if (tmp->is_fips && rr->info->ai_family != AF_LOCAL &&
|
||||
- rr->info->ai_family != AF_UNIX) {
|
||||
+ else if (tmp->is_fips && rr->info->ai_family != AF_LOCAL
|
||||
+ && rr->info->ai_family != AF_UNIX
|
||||
+ && !is_inet_localhost(rr->info)) {
|
||||
/* This would expose cleartext passwords, so abort. */
|
||||
retval = ESOCKTNOSUPPORT;
|
||||
goto error;
|
||||
--
|
||||
2.45.1
|
||||
|
||||
|
|
@ -0,0 +1,41 @@
|
|||
From 1da88bea558348be2974470774aa688f8be634c0 Mon Sep 17 00:00:00 2001
|
||||
From: Julien Rische <jrische@redhat.com>
|
||||
Date: Wed, 7 Dec 2022 13:22:42 +0100
|
||||
Subject: [PATCH] [downstream] Make tests compatible with
|
||||
sssd_krb5_locator_plugin.so
|
||||
|
||||
The sssd_krb5_locator_plugin.so plugin provided by sssd-client conflicts
|
||||
with the upstream test t_discover_uri.py. The test has to be modified in
|
||||
order to avoid false positive.
|
||||
---
|
||||
src/lib/krb5/os/t_discover_uri.py | 9 ++++++++-
|
||||
1 file changed, 8 insertions(+), 1 deletion(-)
|
||||
|
||||
diff --git a/src/lib/krb5/os/t_discover_uri.py b/src/lib/krb5/os/t_discover_uri.py
|
||||
index 87bac17929..26bc95a8dc 100644
|
||||
--- a/src/lib/krb5/os/t_discover_uri.py
|
||||
+++ b/src/lib/krb5/os/t_discover_uri.py
|
||||
@@ -1,3 +1,4 @@
|
||||
+from os.path import exists
|
||||
from k5test import *
|
||||
|
||||
entries = ('URI _kerberos.TEST krb5srv::kkdcp:https://kdc1 1 1\n',
|
||||
@@ -37,8 +38,14 @@ realm.env['RESOLV_WRAPPER_HOSTS'] = hosts_filename
|
||||
out = realm.run(['./t_locate_kdc', 'TEST'], env=realm.env)
|
||||
l = out.splitlines()
|
||||
|
||||
+if (exists('/usr/lib/krb5/plugins/libkrb5/sssd_krb5_locator_plugin.so')
|
||||
+ or exists('/usr/lib64/krb5/plugins/libkrb5/sssd_krb5_locator_plugin.so')):
|
||||
+ line_range = range(6, 14)
|
||||
+else:
|
||||
+ line_range = range(4, 12)
|
||||
+
|
||||
j = 0
|
||||
-for i in range(4, 12):
|
||||
+for i in line_range:
|
||||
if l[i].strip() != expected[j]:
|
||||
fail('URI answers do not match')
|
||||
j += 1
|
||||
--
|
||||
2.45.1
|
||||
|
||||
120
0009-downstream-Include-missing-OpenSSL-FIPS-header.patch
Normal file
120
0009-downstream-Include-missing-OpenSSL-FIPS-header.patch
Normal file
|
|
@ -0,0 +1,120 @@
|
|||
From 775ed8588cc21385fb16a4cec4a861f0d578ce04 Mon Sep 17 00:00:00 2001
|
||||
From: Julien Rische <jrische@redhat.com>
|
||||
Date: Thu, 5 Jan 2023 20:06:47 +0100
|
||||
Subject: [PATCH] [downstream] Include missing OpenSSL FIPS header
|
||||
|
||||
The inclusion of openssl/fips.h, which provides the declaration of
|
||||
FIPS_mode(), was removed from openssl/crypto.h. As a consequence, this
|
||||
header file has to be included explicitly in krb5 code.
|
||||
---
|
||||
src/lib/crypto/krb/prng.c | 4 +++-
|
||||
src/lib/crypto/openssl/enc_provider/camellia.c | 1 +
|
||||
src/lib/crypto/openssl/enc_provider/rc4.c | 4 ++++
|
||||
src/lib/crypto/openssl/hmac.c | 1 +
|
||||
src/lib/krad/internal.h | 4 ++++
|
||||
src/plugins/preauth/spake/spake_client.c | 4 ++++
|
||||
src/plugins/preauth/spake/spake_kdc.c | 4 ++++
|
||||
7 files changed, 21 insertions(+), 1 deletion(-)
|
||||
|
||||
diff --git a/src/lib/crypto/krb/prng.c b/src/lib/crypto/krb/prng.c
|
||||
index 9e80a03d21..ae37c77518 100644
|
||||
--- a/src/lib/crypto/krb/prng.c
|
||||
+++ b/src/lib/crypto/krb/prng.c
|
||||
@@ -28,7 +28,9 @@
|
||||
|
||||
#include <openssl/rand.h>
|
||||
|
||||
-#if OPENSSL_VERSION_NUMBER < 0x30000000L
|
||||
+#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||
+#include <openssl/fips.h>
|
||||
+#else
|
||||
#include <openssl/crypto.h>
|
||||
#endif
|
||||
|
||||
diff --git a/src/lib/crypto/openssl/enc_provider/camellia.c b/src/lib/crypto/openssl/enc_provider/camellia.c
|
||||
index d9f327add6..3dd3b0624f 100644
|
||||
--- a/src/lib/crypto/openssl/enc_provider/camellia.c
|
||||
+++ b/src/lib/crypto/openssl/enc_provider/camellia.c
|
||||
@@ -32,6 +32,7 @@
|
||||
#include <openssl/camellia.h>
|
||||
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||
#include <openssl/core_names.h>
|
||||
+#include <openssl/fips.h>
|
||||
#else
|
||||
#include <openssl/modes.h>
|
||||
#endif
|
||||
diff --git a/src/lib/crypto/openssl/enc_provider/rc4.c b/src/lib/crypto/openssl/enc_provider/rc4.c
|
||||
index ce63cb5f1b..6a83f10d27 100644
|
||||
--- a/src/lib/crypto/openssl/enc_provider/rc4.c
|
||||
+++ b/src/lib/crypto/openssl/enc_provider/rc4.c
|
||||
@@ -38,6 +38,10 @@
|
||||
|
||||
#include <openssl/evp.h>
|
||||
|
||||
+#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||
+#include <openssl/fips.h>
|
||||
+#endif
|
||||
+
|
||||
/*
|
||||
* The loopback field is a pointer to the structure. If the application copies
|
||||
* the state (not a valid operation, but one which happens to works with some
|
||||
diff --git a/src/lib/crypto/openssl/hmac.c b/src/lib/crypto/openssl/hmac.c
|
||||
index f21e268f7f..25a419d73a 100644
|
||||
--- a/src/lib/crypto/openssl/hmac.c
|
||||
+++ b/src/lib/crypto/openssl/hmac.c
|
||||
@@ -59,6 +59,7 @@
|
||||
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||
#include <openssl/params.h>
|
||||
#include <openssl/core_names.h>
|
||||
+#include <openssl/fips.h>
|
||||
#else
|
||||
#include <openssl/hmac.h>
|
||||
#endif
|
||||
diff --git a/src/lib/krad/internal.h b/src/lib/krad/internal.h
|
||||
index e123763954..a17b6f39b1 100644
|
||||
--- a/src/lib/krad/internal.h
|
||||
+++ b/src/lib/krad/internal.h
|
||||
@@ -41,6 +41,10 @@
|
||||
|
||||
#include <openssl/crypto.h>
|
||||
|
||||
+#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||
+#include <openssl/fips.h>
|
||||
+#endif
|
||||
+
|
||||
#ifndef UCHAR_MAX
|
||||
#define UCHAR_MAX 255
|
||||
#endif
|
||||
diff --git a/src/plugins/preauth/spake/spake_client.c b/src/plugins/preauth/spake/spake_client.c
|
||||
index a3ce22b70f..13c699071f 100644
|
||||
--- a/src/plugins/preauth/spake/spake_client.c
|
||||
+++ b/src/plugins/preauth/spake/spake_client.c
|
||||
@@ -40,6 +40,10 @@
|
||||
|
||||
#include <openssl/crypto.h>
|
||||
|
||||
+#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||
+#include <openssl/fips.h>
|
||||
+#endif
|
||||
+
|
||||
typedef struct reqstate_st {
|
||||
krb5_pa_spake *msg; /* set in prep_questions, used in process */
|
||||
krb5_keyblock *initial_key;
|
||||
diff --git a/src/plugins/preauth/spake/spake_kdc.c b/src/plugins/preauth/spake/spake_kdc.c
|
||||
index 232e78bc05..3394f8a58e 100644
|
||||
--- a/src/plugins/preauth/spake/spake_kdc.c
|
||||
+++ b/src/plugins/preauth/spake/spake_kdc.c
|
||||
@@ -43,6 +43,10 @@
|
||||
|
||||
#include <openssl/crypto.h>
|
||||
|
||||
+#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||
+#include <openssl/fips.h>
|
||||
+#endif
|
||||
+
|
||||
/*
|
||||
* The SPAKE kdcpreauth module uses a secure cookie containing the following
|
||||
* concatenated fields (all integer fields are big-endian):
|
||||
--
|
||||
2.45.1
|
||||
|
||||
31
0010-downstream-Do-not-set-root-as-ksu-file-owner.patch
Normal file
31
0010-downstream-Do-not-set-root-as-ksu-file-owner.patch
Normal file
|
|
@ -0,0 +1,31 @@
|
|||
From 4fd20741afcf76085ea62eb015cd589bb9392a7b Mon Sep 17 00:00:00 2001
|
||||
From: Julien Rische <jrische@redhat.com>
|
||||
Date: Mon, 9 Jan 2023 22:39:52 +0100
|
||||
Subject: [PATCH] [downstream] Do not set root as ksu file owner
|
||||
|
||||
Upstream Makefile uses the install command to set root as owner of the
|
||||
ksu executable file. However, this is no longer supported on latest
|
||||
versions of the Mock build environment.
|
||||
|
||||
In case of ksu, the owner, group, and mode are already set using %attr()
|
||||
in the specfile.
|
||||
---
|
||||
src/config/pre.in | 2 +-
|
||||
1 file changed, 1 insertion(+), 1 deletion(-)
|
||||
|
||||
diff --git a/src/config/pre.in b/src/config/pre.in
|
||||
index 7eaa2f351c..e9ae71471e 100644
|
||||
--- a/src/config/pre.in
|
||||
+++ b/src/config/pre.in
|
||||
@@ -185,7 +185,7 @@ INSTALL_PROGRAM=@INSTALL_PROGRAM@ $(INSTALL_STRIP)
|
||||
INSTALL_SCRIPT=@INSTALL_PROGRAM@
|
||||
INSTALL_DATA=@INSTALL_DATA@
|
||||
INSTALL_SHLIB=@INSTALL_SHLIB@
|
||||
-INSTALL_SETUID=$(INSTALL) $(INSTALL_STRIP) -m 4755 -o root
|
||||
+INSTALL_SETUID=$(INSTALL)
|
||||
## This is needed because autoconf will sometimes define @exec_prefix@ to be
|
||||
## ${prefix}.
|
||||
prefix=@prefix@
|
||||
--
|
||||
2.45.1
|
||||
|
||||
165
0011-downstream-Allow-KRB5KDF-MD5-and-MD4-in-FIPS-mode.patch
Normal file
165
0011-downstream-Allow-KRB5KDF-MD5-and-MD4-in-FIPS-mode.patch
Normal file
|
|
@ -0,0 +1,165 @@
|
|||
From 16f90c007036789d8d9343e8a0cbabfd21853b5a Mon Sep 17 00:00:00 2001
|
||||
From: Julien Rische <jrische@redhat.com>
|
||||
Date: Thu, 19 Jan 2023 19:22:27 +0100
|
||||
Subject: [PATCH] [downstream] Allow KRB5KDF, MD5, and MD4 in FIPS mode
|
||||
|
||||
OpenSSL's restrictions to use KRB5KDF, MD5, and MD4 in FIPS mode are
|
||||
bypassed in case AES SHA-1 HMAC or RC4 encryption types are allowed by
|
||||
the crypto policy.
|
||||
---
|
||||
.../crypto/openssl/hash_provider/hash_evp.c | 97 +++++++++++++++++--
|
||||
src/lib/crypto/openssl/kdf.c | 2 +-
|
||||
2 files changed, 89 insertions(+), 10 deletions(-)
|
||||
|
||||
diff --git a/src/lib/crypto/openssl/hash_provider/hash_evp.c b/src/lib/crypto/openssl/hash_provider/hash_evp.c
|
||||
index 11659908bb..eb2e693e9f 100644
|
||||
--- a/src/lib/crypto/openssl/hash_provider/hash_evp.c
|
||||
+++ b/src/lib/crypto/openssl/hash_provider/hash_evp.c
|
||||
@@ -44,6 +44,49 @@
|
||||
#define EVP_MD_CTX_free EVP_MD_CTX_destroy
|
||||
#endif
|
||||
|
||||
+#include <openssl/provider.h>
|
||||
+#include <openssl/fips.h>
|
||||
+#include <threads.h>
|
||||
+
|
||||
+typedef struct ossl_lib_md_context {
|
||||
+ OSSL_LIB_CTX *libctx;
|
||||
+ OSSL_PROVIDER *default_provider;
|
||||
+ OSSL_PROVIDER *legacy_provider;
|
||||
+} ossl_md_context_t;
|
||||
+
|
||||
+static thread_local ossl_md_context_t *ossl_md_ctx = NULL;
|
||||
+
|
||||
+static krb5_error_code
|
||||
+init_ossl_md_ctx(ossl_md_context_t *ctx, const char *algo)
|
||||
+{
|
||||
+ ctx->libctx = OSSL_LIB_CTX_new();
|
||||
+ if (!ctx->libctx)
|
||||
+ return KRB5_CRYPTO_INTERNAL;
|
||||
+
|
||||
+ /* Load both legacy and default provider as both may be needed. */
|
||||
+ ctx->default_provider = OSSL_PROVIDER_load(ctx->libctx, "default");
|
||||
+ ctx->legacy_provider = OSSL_PROVIDER_load(ctx->libctx, "legacy");
|
||||
+
|
||||
+ if (!(ctx->default_provider && ctx->legacy_provider))
|
||||
+ return KRB5_CRYPTO_INTERNAL;
|
||||
+
|
||||
+ return 0;
|
||||
+}
|
||||
+
|
||||
+static void
|
||||
+deinit_ossl_ctx(ossl_md_context_t *ctx)
|
||||
+{
|
||||
+ if (ctx->legacy_provider)
|
||||
+ OSSL_PROVIDER_unload(ctx->legacy_provider);
|
||||
+
|
||||
+ if (ctx->default_provider)
|
||||
+ OSSL_PROVIDER_unload(ctx->default_provider);
|
||||
+
|
||||
+ if (ctx->libctx)
|
||||
+ OSSL_LIB_CTX_free(ctx->libctx);
|
||||
+}
|
||||
+
|
||||
+
|
||||
static krb5_error_code
|
||||
hash_evp(const EVP_MD *type, const krb5_crypto_iov *data, size_t num_data,
|
||||
krb5_data *output)
|
||||
@@ -60,11 +103,6 @@ hash_evp(const EVP_MD *type, const krb5_crypto_iov *data, size_t num_data,
|
||||
if (ctx == NULL)
|
||||
return ENOMEM;
|
||||
|
||||
- if (type == EVP_md4() || type == EVP_md5()) {
|
||||
- /* See comments below in hash_md4() and hash_md5(). */
|
||||
- EVP_MD_CTX_set_flags(ctx, EVP_MD_CTX_FLAG_NON_FIPS_ALLOW);
|
||||
- }
|
||||
-
|
||||
ok = EVP_DigestInit_ex(ctx, type, NULL);
|
||||
for (i = 0; i < num_data; i++) {
|
||||
if (!SIGN_IOV(&data[i]))
|
||||
@@ -77,6 +115,43 @@ hash_evp(const EVP_MD *type, const krb5_crypto_iov *data, size_t num_data,
|
||||
return ok ? 0 : KRB5_CRYPTO_INTERNAL;
|
||||
}
|
||||
|
||||
+static krb5_error_code
|
||||
+hash_legacy_evp(const char *algo, const krb5_crypto_iov *data, size_t num_data,
|
||||
+ krb5_data *output)
|
||||
+{
|
||||
+ krb5_error_code err;
|
||||
+ EVP_MD *md = NULL;
|
||||
+
|
||||
+ if (!ossl_md_ctx) {
|
||||
+ ossl_md_ctx = malloc(sizeof(ossl_md_context_t));
|
||||
+ if (!ossl_md_ctx) {
|
||||
+ err = ENOMEM;
|
||||
+ goto end;
|
||||
+ }
|
||||
+
|
||||
+ err = init_ossl_md_ctx(ossl_md_ctx, algo);
|
||||
+ if (err) {
|
||||
+ deinit_ossl_ctx(ossl_md_ctx);
|
||||
+ free(ossl_md_ctx);
|
||||
+ ossl_md_ctx = NULL;
|
||||
+ goto end;
|
||||
+ }
|
||||
+ }
|
||||
+
|
||||
+ md = EVP_MD_fetch(ossl_md_ctx->libctx, algo, NULL);
|
||||
+ if (!md) {
|
||||
+ err = KRB5_CRYPTO_INTERNAL;
|
||||
+ goto end;
|
||||
+ }
|
||||
+
|
||||
+ err = hash_evp(md, data, num_data, output);
|
||||
+
|
||||
+end:
|
||||
+ if (md)
|
||||
+ EVP_MD_free(md);
|
||||
+
|
||||
+ return err;
|
||||
+}
|
||||
#endif
|
||||
|
||||
#ifdef K5_OPENSSL_MD4
|
||||
@@ -88,7 +163,8 @@ hash_md4(const krb5_crypto_iov *data, size_t num_data, krb5_data *output)
|
||||
* by IPA. These keys are only used along a (separately) secured channel
|
||||
* for legacy reasons when performing trusts to Active Directory.
|
||||
*/
|
||||
- return hash_evp(EVP_md4(), data, num_data, output);
|
||||
+ return FIPS_mode() ? hash_legacy_evp("MD4", data, num_data, output)
|
||||
+ : hash_evp(EVP_md4(), data, num_data, output);
|
||||
}
|
||||
|
||||
const struct krb5_hash_provider krb5int_hash_md4 = {
|
||||
@@ -100,9 +176,12 @@ const struct krb5_hash_provider krb5int_hash_md4 = {
|
||||
static krb5_error_code
|
||||
hash_md5(const krb5_crypto_iov *data, size_t num_data, krb5_data *output)
|
||||
{
|
||||
- /* MD5 is needed in FIPS mode for communication with RADIUS servers. This
|
||||
- * is gated in libkrad by libdefaults->radius_md5_fips_override. */
|
||||
- return hash_evp(EVP_md5(), data, num_data, output);
|
||||
+ /*
|
||||
+ * MD5 is needed in FIPS mode for communication with RADIUS servers. This
|
||||
+ * is gated in libkrad by libdefaults->radius_md5_fips_override.
|
||||
+ */
|
||||
+ return FIPS_mode() ? hash_legacy_evp("MD5", data, num_data, output)
|
||||
+ : hash_evp(EVP_md5(), data, num_data, output);
|
||||
}
|
||||
|
||||
const struct krb5_hash_provider krb5int_hash_md5 = {
|
||||
diff --git a/src/lib/crypto/openssl/kdf.c b/src/lib/crypto/openssl/kdf.c
|
||||
index 5a43c3d9eb..8528ddc4a9 100644
|
||||
--- a/src/lib/crypto/openssl/kdf.c
|
||||
+++ b/src/lib/crypto/openssl/kdf.c
|
||||
@@ -198,7 +198,7 @@ k5_derive_random_rfc3961(const struct krb5_enc_provider *enc, krb5_key key,
|
||||
goto done;
|
||||
}
|
||||
|
||||
- kdf = EVP_KDF_fetch(NULL, "KRB5KDF", NULL);
|
||||
+ kdf = EVP_KDF_fetch(NULL, "KRB5KDF", "-fips");
|
||||
if (kdf == NULL) {
|
||||
ret = KRB5_CRYPTO_INTERNAL;
|
||||
goto done;
|
||||
--
|
||||
2.45.1
|
||||
|
||||
280
0012-downstream-Allow-to-set-PAC-ticket-signature-as-opti.patch
Normal file
280
0012-downstream-Allow-to-set-PAC-ticket-signature-as-opti.patch
Normal file
|
|
@ -0,0 +1,280 @@
|
|||
From 23b58199db429603802e338db530677b61561335 Mon Sep 17 00:00:00 2001
|
||||
From: Julien Rische <jrische@redhat.com>
|
||||
Date: Wed, 15 Mar 2023 15:56:34 +0100
|
||||
Subject: [PATCH] [downstream] Allow to set PAC ticket signature as
|
||||
optional
|
||||
|
||||
MS-PAC states that "The ticket signature SHOULD be included in tickets
|
||||
that are not encrypted to the krbtgt account". However, the
|
||||
implementation of krb5_kdc_verify_ticket() will require the ticket
|
||||
signature to be present in case the target of the request is a service
|
||||
principal.
|
||||
|
||||
In gradual upgrade environments, it results in S4U2Proxy requests
|
||||
against a 1.20 KDC using a service ticket generated by an older version
|
||||
KDC to fail.
|
||||
|
||||
This commit adds a krb5_kdc_verify_ticket_ext() function with an extra
|
||||
switch parameter to tolerate the absence of ticket signature in this
|
||||
scenario. If the ticket signature is present, it has to be valid,
|
||||
regardless of this parameter.
|
||||
|
||||
This parameter is set based on the "optional_pac_tkt_chksum" string
|
||||
attribute of the TGT KDB entry.
|
||||
---
|
||||
doc/admin/admin_commands/kadmin_local.rst | 6 ++++
|
||||
doc/appdev/refs/api/index.rst | 1 +
|
||||
src/include/kdb.h | 1 +
|
||||
src/include/krb5/krb5.hin | 40 +++++++++++++++++++++++
|
||||
src/kdc/kdc_util.c | 32 ++++++++++++++----
|
||||
src/lib/krb5/krb/pac.c | 31 +++++++++++++++---
|
||||
src/lib/krb5/libkrb5.exports | 1 +
|
||||
src/man/kadmin.man | 6 ++++
|
||||
8 files changed, 108 insertions(+), 10 deletions(-)
|
||||
|
||||
diff --git a/doc/admin/admin_commands/kadmin_local.rst b/doc/admin/admin_commands/kadmin_local.rst
|
||||
index 2435b3c361..58ac79549f 100644
|
||||
--- a/doc/admin/admin_commands/kadmin_local.rst
|
||||
+++ b/doc/admin/admin_commands/kadmin_local.rst
|
||||
@@ -658,6 +658,12 @@ KDC:
|
||||
Directory realm when using aes-sha2 keys on the local krbtgt
|
||||
entry.
|
||||
|
||||
+**optional_pac_tkt_chksum**
|
||||
+ Boolean value defining the behavior of the KDC in case an expected
|
||||
+ ticket checksum signed with one of this principal keys is not
|
||||
+ present in the PAC. This is typically the case for TGS or
|
||||
+ cross-realm TGS principals when processing S4U2Proxy requests.
|
||||
+
|
||||
This command requires the **modify** privilege.
|
||||
|
||||
Alias: **setstr**
|
||||
diff --git a/doc/appdev/refs/api/index.rst b/doc/appdev/refs/api/index.rst
|
||||
index d12be47c3c..9b95ebd0f9 100644
|
||||
--- a/doc/appdev/refs/api/index.rst
|
||||
+++ b/doc/appdev/refs/api/index.rst
|
||||
@@ -225,6 +225,7 @@ Rarely used public interfaces
|
||||
krb5_is_referral_realm.rst
|
||||
krb5_kdc_sign_ticket.rst
|
||||
krb5_kdc_verify_ticket.rst
|
||||
+ krb5_kdc_verify_ticket_ext.rst
|
||||
krb5_kt_add_entry.rst
|
||||
krb5_kt_end_seq_get.rst
|
||||
krb5_kt_get_entry.rst
|
||||
diff --git a/src/include/kdb.h b/src/include/kdb.h
|
||||
index 745b24f351..6075349e5e 100644
|
||||
--- a/src/include/kdb.h
|
||||
+++ b/src/include/kdb.h
|
||||
@@ -136,6 +136,7 @@
|
||||
#define KRB5_KDB_SK_PAC_PRIVSVR_ENCTYPE "pac_privsvr_enctype"
|
||||
#define KRB5_KDB_SK_SESSION_ENCTYPES "session_enctypes"
|
||||
#define KRB5_KDB_SK_REQUIRE_AUTH "require_auth"
|
||||
+#define KRB5_KDB_SK_OPTIONAL_PAC_TKT_CHKSUM "optional_pac_tkt_chksum"
|
||||
|
||||
#if !defined(_WIN32)
|
||||
|
||||
diff --git a/src/include/krb5/krb5.hin b/src/include/krb5/krb5.hin
|
||||
index c5a625db8f..2d9b64dc85 100644
|
||||
--- a/src/include/krb5/krb5.hin
|
||||
+++ b/src/include/krb5/krb5.hin
|
||||
@@ -8329,6 +8329,46 @@ krb5_kdc_verify_ticket(krb5_context context, const krb5_enc_tkt_part *enc_tkt,
|
||||
const krb5_keyblock *server,
|
||||
const krb5_keyblock *privsvr, krb5_pac *pac_out);
|
||||
|
||||
+/**
|
||||
+ * Verify a PAC, possibly including ticket signature
|
||||
+ *
|
||||
+ * @param [in] context Library context
|
||||
+ * @param [in] enc_tkt Ticket enc-part, possibly containing a PAC
|
||||
+ * @param [in] server_princ Canonicalized name of ticket server
|
||||
+ * @param [in] server Key to validate server checksum (or NULL)
|
||||
+ * @param [in] privsvr Key to validate KDC checksum (or NULL)
|
||||
+ * @paran [in] optional_tkt_chksum Whether to require a ticket checksum
|
||||
+ * @param [out] pac_out Verified PAC (NULL if no PAC included)
|
||||
+ *
|
||||
+ * This function is an extension of krb5_kdc_verify_ticket(), adding the @a
|
||||
+ * optional_tkt_chksum parameter allowing to tolerate the absence of the PAC
|
||||
+ * ticket signature.
|
||||
+ *
|
||||
+ * If a PAC is present in @a enc_tkt, verify its signatures. If @a privsvr is
|
||||
+ * not NULL and @a server_princ is not a krbtgt or kadmin/changepw service and
|
||||
+ * @a optional_tkt_chksum is FALSE, require a ticket signature over @a enc_tkt
|
||||
+ * in addition to the KDC signature. Place the verified PAC in @a pac_out. If
|
||||
+ * an invalid PAC signature is found, return an error matching the Windows KDC
|
||||
+ * protocol code for that condition as closely as possible.
|
||||
+ *
|
||||
+ * If no PAC is present in @a enc_tkt, set @a pac_out to NULL and return
|
||||
+ * successfully.
|
||||
+ *
|
||||
+ * @note This function does not validate the PAC_CLIENT_INFO buffer. If a
|
||||
+ * specific value is expected, the caller can make a separate call to
|
||||
+ * krb5_pac_verify_ext() with a principal but no keys.
|
||||
+ *
|
||||
+ * @retval 0 Success; otherwise - Kerberos error codes
|
||||
+ */
|
||||
+krb5_error_code KRB5_CALLCONV
|
||||
+krb5_kdc_verify_ticket_ext(krb5_context context,
|
||||
+ const krb5_enc_tkt_part *enc_tkt,
|
||||
+ krb5_const_principal server_princ,
|
||||
+ const krb5_keyblock *server,
|
||||
+ const krb5_keyblock *privsvr,
|
||||
+ krb5_boolean optional_tkt_chksum,
|
||||
+ krb5_pac *pac_out);
|
||||
+
|
||||
/** @deprecated Use krb5_kdc_sign_ticket() instead. */
|
||||
krb5_error_code KRB5_CALLCONV
|
||||
krb5_pac_sign(krb5_context context, krb5_pac pac, krb5_timestamp authtime,
|
||||
diff --git a/src/kdc/kdc_util.c b/src/kdc/kdc_util.c
|
||||
index fe4e48209a..93415ba862 100644
|
||||
--- a/src/kdc/kdc_util.c
|
||||
+++ b/src/kdc/kdc_util.c
|
||||
@@ -560,16 +560,36 @@ cleanup:
|
||||
static krb5_error_code
|
||||
try_verify_pac(krb5_context context, const krb5_enc_tkt_part *enc_tkt,
|
||||
krb5_db_entry *server, krb5_keyblock *server_key,
|
||||
- const krb5_keyblock *tgt_key, krb5_pac *pac_out)
|
||||
+ krb5_db_entry *tgt, const krb5_keyblock *tgt_key,
|
||||
+ krb5_pac *pac_out)
|
||||
{
|
||||
krb5_error_code ret;
|
||||
+ krb5_boolean optional_tkt_chksum;
|
||||
+ char *str = NULL;
|
||||
krb5_keyblock *privsvr_key;
|
||||
|
||||
ret = pac_privsvr_key(context, server, tgt_key, &privsvr_key);
|
||||
if (ret)
|
||||
return ret;
|
||||
- ret = krb5_kdc_verify_ticket(context, enc_tkt, server->princ, server_key,
|
||||
- privsvr_key, pac_out);
|
||||
+
|
||||
+ /* Check if the absence of ticket signature is tolerated for this realm */
|
||||
+ ret = krb5_dbe_get_string(context, tgt,
|
||||
+ KRB5_KDB_SK_OPTIONAL_PAC_TKT_CHKSUM, &str);
|
||||
+ /* TODO: should be using _krb5_conf_boolean(), but os-proto.h is not
|
||||
+ * available here.
|
||||
+ */
|
||||
+ optional_tkt_chksum = !ret && str && (strncasecmp(str, "true", 4) == 0
|
||||
+ || strncasecmp(str, "t", 1) == 0
|
||||
+ || strncasecmp(str, "yes", 3) == 0
|
||||
+ || strncasecmp(str, "y", 1) == 0
|
||||
+ || strncasecmp(str, "1", 1) == 0
|
||||
+ || strncasecmp(str, "on", 2) == 0);
|
||||
+
|
||||
+ krb5_dbe_free_string(context, str);
|
||||
+
|
||||
+ ret = krb5_kdc_verify_ticket_ext(context, enc_tkt, server->princ,
|
||||
+ server_key, privsvr_key,
|
||||
+ optional_tkt_chksum, pac_out);
|
||||
krb5_free_keyblock(context, privsvr_key);
|
||||
return ret;
|
||||
}
|
||||
@@ -599,7 +619,7 @@ get_verified_pac(krb5_context context, const krb5_enc_tkt_part *enc_tkt,
|
||||
server_key, NULL, pac_out);
|
||||
}
|
||||
|
||||
- ret = try_verify_pac(context, enc_tkt, server, server_key, tgt_key,
|
||||
+ ret = try_verify_pac(context, enc_tkt, server, server_key, tgt, tgt_key,
|
||||
pac_out);
|
||||
if (ret != KRB5KRB_AP_ERR_MODIFIED && ret != KRB5_BAD_ENCTYPE)
|
||||
return ret;
|
||||
@@ -613,8 +633,8 @@ get_verified_pac(krb5_context context, const krb5_enc_tkt_part *enc_tkt,
|
||||
ret = krb5_dbe_decrypt_key_data(context, NULL, kd, &old_key, NULL);
|
||||
if (ret)
|
||||
return ret;
|
||||
- ret = try_verify_pac(context, enc_tkt, server, server_key, &old_key,
|
||||
- pac_out);
|
||||
+ ret = try_verify_pac(context, enc_tkt, server, server_key, tgt,
|
||||
+ &old_key, pac_out);
|
||||
krb5_free_keyblock_contents(context, &old_key);
|
||||
if (!ret)
|
||||
return 0;
|
||||
diff --git a/src/lib/krb5/krb/pac.c b/src/lib/krb5/krb/pac.c
|
||||
index 5d1fdf1ba0..0c0e2ada68 100644
|
||||
--- a/src/lib/krb5/krb/pac.c
|
||||
+++ b/src/lib/krb5/krb/pac.c
|
||||
@@ -594,6 +594,19 @@ krb5_kdc_verify_ticket(krb5_context context, const krb5_enc_tkt_part *enc_tkt,
|
||||
krb5_const_principal server_princ,
|
||||
const krb5_keyblock *server,
|
||||
const krb5_keyblock *privsvr, krb5_pac *pac_out)
|
||||
+{
|
||||
+ return krb5_kdc_verify_ticket_ext(context, enc_tkt, server_princ, server,
|
||||
+ privsvr, FALSE, pac_out);
|
||||
+}
|
||||
+
|
||||
+krb5_error_code KRB5_CALLCONV
|
||||
+krb5_kdc_verify_ticket_ext(krb5_context context,
|
||||
+ const krb5_enc_tkt_part *enc_tkt,
|
||||
+ krb5_const_principal server_princ,
|
||||
+ const krb5_keyblock *server,
|
||||
+ const krb5_keyblock *privsvr,
|
||||
+ krb5_boolean optional_tkt_chksum,
|
||||
+ krb5_pac *pac_out)
|
||||
{
|
||||
krb5_error_code ret;
|
||||
krb5_pac pac = NULL;
|
||||
@@ -602,7 +615,7 @@ krb5_kdc_verify_ticket(krb5_context context, const krb5_enc_tkt_part *enc_tkt,
|
||||
krb5_authdata *orig, **ifrel = NULL, **recoded_ifrel = NULL;
|
||||
uint8_t z = 0;
|
||||
krb5_authdata zpac = { KV5M_AUTHDATA, KRB5_AUTHDATA_WIN2K_PAC, 1, &z };
|
||||
- krb5_boolean is_service_tkt;
|
||||
+ krb5_boolean is_service_tkt, has_tkt_chksum = FALSE;
|
||||
size_t i, j;
|
||||
|
||||
*pac_out = NULL;
|
||||
@@ -667,11 +680,21 @@ krb5_kdc_verify_ticket(krb5_context context, const krb5_enc_tkt_part *enc_tkt,
|
||||
|
||||
ret = verify_checksum(context, pac, KRB5_PAC_TICKET_CHECKSUM, privsvr,
|
||||
KRB5_KEYUSAGE_APP_DATA_CKSUM, recoded_tkt);
|
||||
- if (ret)
|
||||
- goto cleanup;
|
||||
+ if (ret) {
|
||||
+ if (!optional_tkt_chksum)
|
||||
+ goto cleanup;
|
||||
+ else if (ret != ENOENT)
|
||||
+ goto cleanup;
|
||||
+ /* Otherwise ticket signature is absent but optional. Proceed... */
|
||||
+ } else {
|
||||
+ has_tkt_chksum = TRUE;
|
||||
+ }
|
||||
}
|
||||
+ /* Else, we make the assumption the ticket signature is absent in case this
|
||||
+ * is not a service ticket.
|
||||
+ */
|
||||
|
||||
- ret = verify_pac_checksums(context, pac, is_service_tkt, server, privsvr);
|
||||
+ ret = verify_pac_checksums(context, pac, has_tkt_chksum, server, privsvr);
|
||||
if (ret)
|
||||
goto cleanup;
|
||||
|
||||
diff --git a/src/lib/krb5/libkrb5.exports b/src/lib/krb5/libkrb5.exports
|
||||
index 4c50e935a2..d4b0455c8c 100644
|
||||
--- a/src/lib/krb5/libkrb5.exports
|
||||
+++ b/src/lib/krb5/libkrb5.exports
|
||||
@@ -463,6 +463,7 @@ krb5_is_thread_safe
|
||||
krb5_kdc_rep_decrypt_proc
|
||||
krb5_kdc_sign_ticket
|
||||
krb5_kdc_verify_ticket
|
||||
+krb5_kdc_verify_ticket_ext
|
||||
krb5_kt_add_entry
|
||||
krb5_kt_client_default
|
||||
krb5_kt_close
|
||||
diff --git a/src/man/kadmin.man b/src/man/kadmin.man
|
||||
index 8413e70ccd..f68eb0569d 100644
|
||||
--- a/src/man/kadmin.man
|
||||
+++ b/src/man/kadmin.man
|
||||
@@ -724,6 +724,12 @@ encryption type. It may be necessary to set this value to
|
||||
"aes256\-sha1" on the cross\-realm krbtgt entry for an Active
|
||||
Directory realm when using aes\-sha2 keys on the local krbtgt
|
||||
entry.
|
||||
+.TP
|
||||
+\fBoptional_pac_tkt_chksum\fP
|
||||
+Boolean value defining the behavior of the KDC in case an expected ticket
|
||||
+checksum signed with one of this principal keys is not present in the PAC. This
|
||||
+is typically the case for TGS or cross-realm TGS principals when processing
|
||||
+S4U2Proxy requests.
|
||||
.UNINDENT
|
||||
.sp
|
||||
This command requires the \fBmodify\fP privilege.
|
||||
--
|
||||
2.45.1
|
||||
|
||||
|
|
@ -0,0 +1,47 @@
|
|||
From 31b9debcf2cbd558f8f315fefb69fc8206b115b4 Mon Sep 17 00:00:00 2001
|
||||
From: Julien Rische <jrische@redhat.com>
|
||||
Date: Tue, 23 May 2023 12:19:54 +0200
|
||||
Subject: [PATCH] [downstream] Make PKINIT CMS SHA-1 signature
|
||||
verification available in FIPS mode
|
||||
|
||||
We recommend using the SHA1 crypto-module in order to allow the
|
||||
verification of SHA-1 signature for CMS messages. However, this module
|
||||
does not work in FIPS mode, because the SHA-1 algorithm is absent from
|
||||
the OpenSSL FIPS provider.
|
||||
|
||||
This commit enables the signature verification process to fetch the
|
||||
algorithm from a non-FIPS OpenSSL provider.
|
||||
|
||||
Support for SHA-1 CMS signature is still required, especially in order
|
||||
to interoperate with Active Directory. At least it is until elliptic
|
||||
curve cryptography is implemented for PKINIT in MIT krb5.
|
||||
---
|
||||
src/plugins/preauth/pkinit/pkinit_crypto_openssl.c | 11 ++++++++++-
|
||||
1 file changed, 10 insertions(+), 1 deletion(-)
|
||||
|
||||
diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c
|
||||
index cb9c79626c..17dd18e37d 100644
|
||||
--- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c
|
||||
+++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c
|
||||
@@ -1844,8 +1844,17 @@ cms_signeddata_verify(krb5_context context,
|
||||
if (oid == NULL)
|
||||
goto cleanup;
|
||||
|
||||
+#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||
+ /* Do not use FIPS provider (even in FIPS mode) because it keeps from
|
||||
+ * allowing SHA-1 signature verification using the SHA1 crypto-module
|
||||
+ */
|
||||
+ cms = CMS_ContentInfo_new_ex(NULL, "-fips");
|
||||
+ if (!cms)
|
||||
+ goto cleanup;
|
||||
+#endif
|
||||
+
|
||||
/* decode received CMS message */
|
||||
- if ((cms = d2i_CMS_ContentInfo(NULL, &p, (int)signed_data_len)) == NULL) {
|
||||
+ if (!d2i_CMS_ContentInfo(&cms, &p, (int)signed_data_len)) {
|
||||
retval = oerr(context, 0, _("Failed to decode CMS message"));
|
||||
goto cleanup;
|
||||
}
|
||||
--
|
||||
2.45.1
|
||||
|
||||
218
0014-Enable-PKINIT-if-at-least-one-group-is-available.patch
Normal file
218
0014-Enable-PKINIT-if-at-least-one-group-is-available.patch
Normal file
|
|
@ -0,0 +1,218 @@
|
|||
From c24c9faf859ddc04910a6bc591d8ddb2ada93e80 Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Tue, 30 May 2023 01:21:48 -0400
|
||||
Subject: [PATCH] Enable PKINIT if at least one group is available
|
||||
|
||||
OpenSSL may no longer allow decoding of non-well-known Diffie-Hellman
|
||||
group parameters as EVP_PKEY objects in FIPS mode. However, OpenSSL
|
||||
does not know about MODP group 2 (1024-bit), which is considered as a
|
||||
custom group. As a consequence, the PKINIT kdcpreauth module fails to
|
||||
load in FIPS mode.
|
||||
|
||||
Allow initialization of PKINIT plugin if at least one of the MODP
|
||||
well-known group parameters successfully decodes.
|
||||
|
||||
[ghudson@mit.edu: minor commit message and code edits]
|
||||
|
||||
ticket: 9096 (new)
|
||||
(cherry picked from commit 509d8db922e9ad6f108883838473b6178f89874a)
|
||||
---
|
||||
src/plugins/preauth/pkinit/pkinit_clnt.c | 2 +-
|
||||
src/plugins/preauth/pkinit/pkinit_crypto.h | 3 +-
|
||||
.../preauth/pkinit/pkinit_crypto_openssl.c | 76 +++++++++++--------
|
||||
src/plugins/preauth/pkinit/pkinit_srv.c | 2 +-
|
||||
src/plugins/preauth/pkinit/pkinit_trace.h | 3 +
|
||||
5 files changed, 51 insertions(+), 35 deletions(-)
|
||||
|
||||
diff --git a/src/plugins/preauth/pkinit/pkinit_clnt.c b/src/plugins/preauth/pkinit/pkinit_clnt.c
|
||||
index 725d5bc438..ea9ba454df 100644
|
||||
--- a/src/plugins/preauth/pkinit/pkinit_clnt.c
|
||||
+++ b/src/plugins/preauth/pkinit/pkinit_clnt.c
|
||||
@@ -1378,7 +1378,7 @@ pkinit_client_plugin_init(krb5_context context,
|
||||
if (retval)
|
||||
goto errout;
|
||||
|
||||
- retval = pkinit_init_plg_crypto(&ctx->cryptoctx);
|
||||
+ retval = pkinit_init_plg_crypto(context, &ctx->cryptoctx);
|
||||
if (retval)
|
||||
goto errout;
|
||||
|
||||
diff --git a/src/plugins/preauth/pkinit/pkinit_crypto.h b/src/plugins/preauth/pkinit/pkinit_crypto.h
|
||||
index 9fa315d7a0..8bdbea8e95 100644
|
||||
--- a/src/plugins/preauth/pkinit/pkinit_crypto.h
|
||||
+++ b/src/plugins/preauth/pkinit/pkinit_crypto.h
|
||||
@@ -103,7 +103,8 @@ typedef struct _pkinit_cert_matching_data {
|
||||
/*
|
||||
* Functions to initialize and cleanup crypto contexts
|
||||
*/
|
||||
-krb5_error_code pkinit_init_plg_crypto(pkinit_plg_crypto_context *);
|
||||
+krb5_error_code pkinit_init_plg_crypto(krb5_context,
|
||||
+ pkinit_plg_crypto_context *);
|
||||
void pkinit_fini_plg_crypto(pkinit_plg_crypto_context);
|
||||
|
||||
krb5_error_code pkinit_init_req_crypto(pkinit_req_crypto_context *);
|
||||
diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c
|
||||
index 17dd18e37d..8cdc40bfb4 100644
|
||||
--- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c
|
||||
+++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c
|
||||
@@ -47,7 +47,8 @@
|
||||
static krb5_error_code pkinit_init_pkinit_oids(pkinit_plg_crypto_context );
|
||||
static void pkinit_fini_pkinit_oids(pkinit_plg_crypto_context );
|
||||
|
||||
-static krb5_error_code pkinit_init_dh_params(pkinit_plg_crypto_context );
|
||||
+static krb5_error_code pkinit_init_dh_params(krb5_context,
|
||||
+ pkinit_plg_crypto_context);
|
||||
static void pkinit_fini_dh_params(pkinit_plg_crypto_context );
|
||||
|
||||
static krb5_error_code pkinit_init_certs(pkinit_identity_crypto_context ctx);
|
||||
@@ -951,7 +952,8 @@ oerr_cert(krb5_context context, krb5_error_code code, X509_STORE_CTX *certctx,
|
||||
}
|
||||
|
||||
krb5_error_code
|
||||
-pkinit_init_plg_crypto(pkinit_plg_crypto_context *cryptoctx)
|
||||
+pkinit_init_plg_crypto(krb5_context context,
|
||||
+ pkinit_plg_crypto_context *cryptoctx)
|
||||
{
|
||||
krb5_error_code retval = ENOMEM;
|
||||
pkinit_plg_crypto_context ctx = NULL;
|
||||
@@ -969,7 +971,7 @@ pkinit_init_plg_crypto(pkinit_plg_crypto_context *cryptoctx)
|
||||
if (retval)
|
||||
goto out;
|
||||
|
||||
- retval = pkinit_init_dh_params(ctx);
|
||||
+ retval = pkinit_init_dh_params(context, ctx);
|
||||
if (retval)
|
||||
goto out;
|
||||
|
||||
@@ -1278,30 +1280,36 @@ pkinit_fini_pkinit_oids(pkinit_plg_crypto_context ctx)
|
||||
ASN1_OBJECT_free(ctx->id_kp_serverAuth);
|
||||
}
|
||||
|
||||
-static krb5_error_code
|
||||
-pkinit_init_dh_params(pkinit_plg_crypto_context plgctx)
|
||||
+static int
|
||||
+try_import_group(krb5_context context, const krb5_data *params,
|
||||
+ const char *name, EVP_PKEY **pkey_out)
|
||||
{
|
||||
- krb5_error_code retval = ENOMEM;
|
||||
-
|
||||
- plgctx->dh_1024 = decode_dh_params(&oakley_1024);
|
||||
- if (plgctx->dh_1024 == NULL)
|
||||
- goto cleanup;
|
||||
-
|
||||
- plgctx->dh_2048 = decode_dh_params(&oakley_2048);
|
||||
- if (plgctx->dh_2048 == NULL)
|
||||
- goto cleanup;
|
||||
+ *pkey_out = decode_dh_params(params);
|
||||
+ if (*pkey_out == NULL)
|
||||
+ TRACE_PKINIT_DH_GROUP_UNAVAILABLE(context, name);
|
||||
+ return (*pkey_out != NULL) ? 1 : 0;
|
||||
+}
|
||||
|
||||
- plgctx->dh_4096 = decode_dh_params(&oakley_4096);
|
||||
- if (plgctx->dh_4096 == NULL)
|
||||
- goto cleanup;
|
||||
+static krb5_error_code
|
||||
+pkinit_init_dh_params(krb5_context context, pkinit_plg_crypto_context plgctx)
|
||||
+{
|
||||
+ int n = 0;
|
||||
|
||||
- retval = 0;
|
||||
+ n += try_import_group(context, &oakley_1024, "MODP 2 (1024-bit)",
|
||||
+ &plgctx->dh_1024);
|
||||
+ n += try_import_group(context, &oakley_2048, "MODP 14 (2048-bit)",
|
||||
+ &plgctx->dh_2048);
|
||||
+ n += try_import_group(context, &oakley_4096, "MODP 16 (4096-bit)",
|
||||
+ &plgctx->dh_4096);
|
||||
|
||||
-cleanup:
|
||||
- if (retval)
|
||||
+ if (n == 0) {
|
||||
pkinit_fini_dh_params(plgctx);
|
||||
+ k5_setmsg(context, ENOMEM,
|
||||
+ _("PKINIT cannot initialize any key exchange groups"));
|
||||
+ return ENOMEM;
|
||||
+ }
|
||||
|
||||
- return retval;
|
||||
+ return 0;
|
||||
}
|
||||
|
||||
static void
|
||||
@@ -2912,11 +2920,11 @@ client_create_dh(krb5_context context,
|
||||
|
||||
if (cryptoctx->received_params != NULL)
|
||||
params = cryptoctx->received_params;
|
||||
- else if (dh_size == 1024)
|
||||
+ else if (plg_cryptoctx->dh_1024 != NULL && dh_size == 1024)
|
||||
params = plg_cryptoctx->dh_1024;
|
||||
- else if (dh_size == 2048)
|
||||
+ else if (plg_cryptoctx->dh_2048 != NULL && dh_size == 2048)
|
||||
params = plg_cryptoctx->dh_2048;
|
||||
- else if (dh_size == 4096)
|
||||
+ else if (plg_cryptoctx->dh_4096 != NULL && dh_size == 4096)
|
||||
params = plg_cryptoctx->dh_4096;
|
||||
else
|
||||
goto cleanup;
|
||||
@@ -3212,19 +3220,23 @@ pkinit_create_td_dh_parameters(krb5_context context,
|
||||
krb5_algorithm_identifier alg_4096 = { dh_oid, oakley_4096 };
|
||||
krb5_algorithm_identifier *alglist[4];
|
||||
|
||||
- if (opts->dh_min_bits > 4096) {
|
||||
- ret = KRB5KRB_ERR_GENERIC;
|
||||
- goto cleanup;
|
||||
- }
|
||||
-
|
||||
i = 0;
|
||||
- if (opts->dh_min_bits <= 2048)
|
||||
+ if (plg_cryptoctx->dh_2048 != NULL && opts->dh_min_bits <= 2048)
|
||||
alglist[i++] = &alg_2048;
|
||||
- alglist[i++] = &alg_4096;
|
||||
- if (opts->dh_min_bits <= 1024)
|
||||
+ if (plg_cryptoctx->dh_4096 != NULL && opts->dh_min_bits <= 4096)
|
||||
+ alglist[i++] = &alg_4096;
|
||||
+ if (plg_cryptoctx->dh_1024 != NULL && opts->dh_min_bits <= 1024)
|
||||
alglist[i++] = &alg_1024;
|
||||
alglist[i] = NULL;
|
||||
|
||||
+ if (i == 0) {
|
||||
+ ret = KRB5KRB_ERR_GENERIC;
|
||||
+ k5_setmsg(context, ret,
|
||||
+ _("OpenSSL has no supported key exchange groups for "
|
||||
+ "pkinit_dh_min_bits=%d"), opts->dh_min_bits);
|
||||
+ goto cleanup;
|
||||
+ }
|
||||
+
|
||||
ret = k5int_encode_krb5_td_dh_parameters(alglist, &der_alglist);
|
||||
if (ret)
|
||||
goto cleanup;
|
||||
diff --git a/src/plugins/preauth/pkinit/pkinit_srv.c b/src/plugins/preauth/pkinit/pkinit_srv.c
|
||||
index 1b3bf6d4d0..768a4e559f 100644
|
||||
--- a/src/plugins/preauth/pkinit/pkinit_srv.c
|
||||
+++ b/src/plugins/preauth/pkinit/pkinit_srv.c
|
||||
@@ -1222,7 +1222,7 @@ pkinit_server_plugin_init_realm(krb5_context context, const char *realmname,
|
||||
goto errout;
|
||||
plgctx->realmname_len = strlen(plgctx->realmname);
|
||||
|
||||
- retval = pkinit_init_plg_crypto(&plgctx->cryptoctx);
|
||||
+ retval = pkinit_init_plg_crypto(context, &plgctx->cryptoctx);
|
||||
if (retval)
|
||||
goto errout;
|
||||
|
||||
diff --git a/src/plugins/preauth/pkinit/pkinit_trace.h b/src/plugins/preauth/pkinit/pkinit_trace.h
|
||||
index 259e95c6c2..5ee39c085c 100644
|
||||
--- a/src/plugins/preauth/pkinit/pkinit_trace.h
|
||||
+++ b/src/plugins/preauth/pkinit/pkinit_trace.h
|
||||
@@ -90,6 +90,9 @@
|
||||
#define TRACE_PKINIT_CLIENT_TRYAGAIN(c) \
|
||||
TRACE(c, "PKINIT client trying again with KDC-provided parameters")
|
||||
|
||||
+#define TRACE_PKINIT_DH_GROUP_UNAVAILABLE(c, name) \
|
||||
+ TRACE(c, "PKINIT key exchange group {str} unsupported", name)
|
||||
+
|
||||
#define TRACE_PKINIT_OPENSSL_ERROR(c, msg) \
|
||||
TRACE(c, "PKINIT OpenSSL error: {str}", msg)
|
||||
|
||||
--
|
||||
2.45.1
|
||||
|
||||
64
0015-Replace-ssl.wrap_socket-for-tests.patch
Normal file
64
0015-Replace-ssl.wrap_socket-for-tests.patch
Normal file
|
|
@ -0,0 +1,64 @@
|
|||
From e92365b510a2407eaceaec90836f5c713403d75f Mon Sep 17 00:00:00 2001
|
||||
From: Julien Rische <jrische@redhat.com>
|
||||
Date: Wed, 19 Jul 2023 13:43:17 +0200
|
||||
Subject: [PATCH] Replace ssl.wrap_socket() for tests
|
||||
|
||||
The ssl.wrap_socket() function was deprecated in Python 3.7 and is
|
||||
removed in Python 3.12. The ssl.SSLContext.wrap_socket() method
|
||||
replaces it.
|
||||
|
||||
Bump the required Python version for tests to 3.4 for
|
||||
ssl.create_default_context().
|
||||
|
||||
[ghudson@mit.edu: changed minimum Python version]
|
||||
|
||||
(cherry picked from commit 0ceab6c363e65fb21d3312a663f2b9b569ecc415)
|
||||
---
|
||||
src/configure.ac | 9 ++++-----
|
||||
src/util/wsgiref-kdcproxy.py | 4 +++-
|
||||
2 files changed, 7 insertions(+), 6 deletions(-)
|
||||
|
||||
diff --git a/src/configure.ac b/src/configure.ac
|
||||
index 2561e917a2..487f393146 100644
|
||||
--- a/src/configure.ac
|
||||
+++ b/src/configure.ac
|
||||
@@ -1157,10 +1157,9 @@ AC_SUBST(PKINIT)
|
||||
# for lib/apputils
|
||||
AC_REPLACE_FUNCS(daemon)
|
||||
|
||||
-# For Python tests. Python version 3.2.4 is required as prior
|
||||
-# versions do not accept string input to subprocess.Popen.communicate
|
||||
-# when universal_newlines is set.
|
||||
-PYTHON_MINVERSION=3.2.4
|
||||
+# For Python tests. Python version 3.4 is required for
|
||||
+# ssl.create_default_context().
|
||||
+PYTHON_MINVERSION=3.4
|
||||
AC_SUBST(PYTHON_MINVERSION)
|
||||
AC_CHECK_PROG(PYTHON,python3,python3)
|
||||
if test x"$PYTHON" = x; then
|
||||
@@ -1168,7 +1167,7 @@ if test x"$PYTHON" = x; then
|
||||
fi
|
||||
HAVE_PYTHON=no
|
||||
if test x"$PYTHON" != x; then
|
||||
- wantver="(sys.hexversion >= 0x30204F0)"
|
||||
+ wantver="(sys.hexversion >= 0x30400F0)"
|
||||
if "$PYTHON" -c "import sys; sys.exit(not $wantver and 1 or 0)"; then
|
||||
HAVE_PYTHON=yes
|
||||
fi
|
||||
diff --git a/src/util/wsgiref-kdcproxy.py b/src/util/wsgiref-kdcproxy.py
|
||||
index 58759696b6..d1d10d733c 100755
|
||||
--- a/src/util/wsgiref-kdcproxy.py
|
||||
+++ b/src/util/wsgiref-kdcproxy.py
|
||||
@@ -14,6 +14,8 @@ else:
|
||||
pem = '*'
|
||||
|
||||
server = make_server('localhost', port, kdcproxy.Application())
|
||||
-server.socket = ssl.wrap_socket(server.socket, certfile=pem, server_side=True)
|
||||
+sslctx = ssl.create_default_context(purpose=ssl.Purpose.CLIENT_AUTH)
|
||||
+sslctx.load_cert_chain(certfile=pem)
|
||||
+server.socket = sslctx.wrap_socket(server.socket, server_side=True)
|
||||
os.write(sys.stdout.fileno(), b'proxy server ready\n')
|
||||
server.serve_forever()
|
||||
--
|
||||
2.45.1
|
||||
|
||||
10685
0016-Eliminate-old-style-function-declarations.patch
Normal file
10685
0016-Eliminate-old-style-function-declarations.patch
Normal file
File diff suppressed because it is too large
Load diff
206
0017-Fix-two-unlikely-memory-leaks.patch
Normal file
206
0017-Fix-two-unlikely-memory-leaks.patch
Normal file
|
|
@ -0,0 +1,206 @@
|
|||
From ee66c1feedb57ce06ce51aaa823f9a61f564c58e Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Tue, 5 Mar 2024 19:53:07 -0500
|
||||
Subject: [PATCH] Fix two unlikely memory leaks
|
||||
|
||||
In gss_krb5int_make_seal_token_v3(), one of the bounds checks (which
|
||||
could probably never be triggered) leaks plain.data. Fix this leak
|
||||
and use current practices for cleanup throughout the function.
|
||||
|
||||
In xmt_rmtcallres() (unused within the tree and likely elsewhere),
|
||||
store port_ptr into crp->port_ptr as soon as it is allocated;
|
||||
otherwise it could leak if the subsequent xdr_u_int32() operation
|
||||
fails.
|
||||
|
||||
(cherry picked from commit c5f9c816107f70139de11b38aa02db2f1774ee0d)
|
||||
---
|
||||
src/lib/gssapi/krb5/k5sealv3.c | 56 +++++++++++++++-------------------
|
||||
src/lib/rpc/pmap_rmt.c | 10 +++---
|
||||
2 files changed, 29 insertions(+), 37 deletions(-)
|
||||
|
||||
diff --git a/src/lib/gssapi/krb5/k5sealv3.c b/src/lib/gssapi/krb5/k5sealv3.c
|
||||
index 1fcbdfbb87..d3210c1107 100644
|
||||
--- a/src/lib/gssapi/krb5/k5sealv3.c
|
||||
+++ b/src/lib/gssapi/krb5/k5sealv3.c
|
||||
@@ -65,7 +65,7 @@ gss_krb5int_make_seal_token_v3 (krb5_context context,
|
||||
int conf_req_flag, int toktype)
|
||||
{
|
||||
size_t bufsize = 16;
|
||||
- unsigned char *outbuf = 0;
|
||||
+ unsigned char *outbuf = NULL;
|
||||
krb5_error_code err;
|
||||
int key_usage;
|
||||
unsigned char acceptor_flag;
|
||||
@@ -75,9 +75,13 @@ gss_krb5int_make_seal_token_v3 (krb5_context context,
|
||||
#endif
|
||||
size_t ec;
|
||||
unsigned short tok_id;
|
||||
- krb5_checksum sum;
|
||||
+ krb5_checksum sum = { 0 };
|
||||
krb5_key key;
|
||||
krb5_cksumtype cksumtype;
|
||||
+ krb5_data plain = empty_data();
|
||||
+
|
||||
+ token->value = NULL;
|
||||
+ token->length = 0;
|
||||
|
||||
acceptor_flag = ctx->initiate ? 0 : FLAG_SENDER_IS_ACCEPTOR;
|
||||
key_usage = (toktype == KG_TOK_WRAP_MSG
|
||||
@@ -107,14 +111,15 @@ gss_krb5int_make_seal_token_v3 (krb5_context context,
|
||||
#endif
|
||||
|
||||
if (toktype == KG_TOK_WRAP_MSG && conf_req_flag) {
|
||||
- krb5_data plain;
|
||||
krb5_enc_data cipher;
|
||||
size_t ec_max;
|
||||
size_t encrypt_size;
|
||||
|
||||
/* 300: Adds some slop. */
|
||||
- if (SIZE_MAX - 300 < message->length)
|
||||
- return ENOMEM;
|
||||
+ if (SIZE_MAX - 300 < message->length) {
|
||||
+ err = ENOMEM;
|
||||
+ goto cleanup;
|
||||
+ }
|
||||
ec_max = SIZE_MAX - message->length - 300;
|
||||
if (ec_max > 0xffff)
|
||||
ec_max = 0xffff;
|
||||
@@ -126,20 +131,20 @@ gss_krb5int_make_seal_token_v3 (krb5_context context,
|
||||
#endif
|
||||
err = alloc_data(&plain, message->length + 16 + ec);
|
||||
if (err)
|
||||
- return err;
|
||||
+ goto cleanup;
|
||||
|
||||
/* Get size of ciphertext. */
|
||||
encrypt_size = krb5_encrypt_size(plain.length, key->keyblock.enctype);
|
||||
if (encrypt_size > SIZE_MAX / 2) {
|
||||
err = ENOMEM;
|
||||
- goto error;
|
||||
+ goto cleanup;
|
||||
}
|
||||
bufsize = 16 + encrypt_size;
|
||||
/* Allocate space for header plus encrypted data. */
|
||||
outbuf = gssalloc_malloc(bufsize);
|
||||
if (outbuf == NULL) {
|
||||
- free(plain.data);
|
||||
- return ENOMEM;
|
||||
+ err = ENOMEM;
|
||||
+ goto cleanup;
|
||||
}
|
||||
|
||||
/* TOK_ID */
|
||||
@@ -164,11 +169,8 @@ gss_krb5int_make_seal_token_v3 (krb5_context context,
|
||||
cipher.ciphertext.length = bufsize - 16;
|
||||
cipher.enctype = key->keyblock.enctype;
|
||||
err = krb5_k_encrypt(context, key, key_usage, 0, &plain, &cipher);
|
||||
- zap(plain.data, plain.length);
|
||||
- free(plain.data);
|
||||
- plain.data = 0;
|
||||
if (err)
|
||||
- goto error;
|
||||
+ goto cleanup;
|
||||
|
||||
/* Now that we know we're returning a valid token.... */
|
||||
ctx->seq_send++;
|
||||
@@ -181,7 +183,6 @@ gss_krb5int_make_seal_token_v3 (krb5_context context,
|
||||
/* If the rotate fails, don't worry about it. */
|
||||
#endif
|
||||
} else if (toktype == KG_TOK_WRAP_MSG && !conf_req_flag) {
|
||||
- krb5_data plain;
|
||||
size_t cksumsize;
|
||||
|
||||
/* Here, message is the application-supplied data; message2 is
|
||||
@@ -193,21 +194,19 @@ gss_krb5int_make_seal_token_v3 (krb5_context context,
|
||||
wrap_with_checksum:
|
||||
err = alloc_data(&plain, message->length + 16);
|
||||
if (err)
|
||||
- return err;
|
||||
+ goto cleanup;
|
||||
|
||||
err = krb5_c_checksum_length(context, cksumtype, &cksumsize);
|
||||
if (err)
|
||||
- goto error;
|
||||
+ goto cleanup;
|
||||
|
||||
assert(cksumsize <= 0xffff);
|
||||
|
||||
bufsize = 16 + message2->length + cksumsize;
|
||||
outbuf = gssalloc_malloc(bufsize);
|
||||
if (outbuf == NULL) {
|
||||
- free(plain.data);
|
||||
- plain.data = 0;
|
||||
err = ENOMEM;
|
||||
- goto error;
|
||||
+ goto cleanup;
|
||||
}
|
||||
|
||||
/* TOK_ID */
|
||||
@@ -239,23 +238,15 @@ gss_krb5int_make_seal_token_v3 (krb5_context context,
|
||||
if (message2->length)
|
||||
memcpy(outbuf + 16, message2->value, message2->length);
|
||||
|
||||
- sum.contents = outbuf + 16 + message2->length;
|
||||
- sum.length = cksumsize;
|
||||
-
|
||||
err = krb5_k_make_checksum(context, cksumtype, key,
|
||||
key_usage, &plain, &sum);
|
||||
- zap(plain.data, plain.length);
|
||||
- free(plain.data);
|
||||
- plain.data = 0;
|
||||
if (err) {
|
||||
zap(outbuf,bufsize);
|
||||
- goto error;
|
||||
+ goto cleanup;
|
||||
}
|
||||
if (sum.length != cksumsize)
|
||||
abort();
|
||||
memcpy(outbuf + 16 + message2->length, sum.contents, cksumsize);
|
||||
- krb5_free_checksum_contents(context, &sum);
|
||||
- sum.contents = 0;
|
||||
/* Now that we know we're actually generating the token... */
|
||||
ctx->seq_send++;
|
||||
|
||||
@@ -285,12 +276,13 @@ gss_krb5int_make_seal_token_v3 (krb5_context context,
|
||||
|
||||
token->value = outbuf;
|
||||
token->length = bufsize;
|
||||
- return 0;
|
||||
+ outbuf = NULL;
|
||||
+ err = 0;
|
||||
|
||||
-error:
|
||||
+cleanup:
|
||||
+ krb5_free_checksum_contents(context, &sum);
|
||||
+ zapfree(plain.data, plain.length);
|
||||
gssalloc_free(outbuf);
|
||||
- token->value = NULL;
|
||||
- token->length = 0;
|
||||
return err;
|
||||
}
|
||||
|
||||
diff --git a/src/lib/rpc/pmap_rmt.c b/src/lib/rpc/pmap_rmt.c
|
||||
index 434e4eea65..f55ca46c60 100644
|
||||
--- a/src/lib/rpc/pmap_rmt.c
|
||||
+++ b/src/lib/rpc/pmap_rmt.c
|
||||
@@ -161,12 +161,12 @@ xdr_rmtcallres(
|
||||
caddr_t port_ptr;
|
||||
|
||||
port_ptr = (caddr_t)(void *)crp->port_ptr;
|
||||
- if (xdr_reference(xdrs, &port_ptr, sizeof (uint32_t),
|
||||
- (xdrproc_t)xdr_u_int32) &&
|
||||
- xdr_u_int32(xdrs, &crp->resultslen)) {
|
||||
- crp->port_ptr = (uint32_t *)(void *)port_ptr;
|
||||
+ if (!xdr_reference(xdrs, &port_ptr, sizeof (uint32_t),
|
||||
+ (xdrproc_t)xdr_u_int32))
|
||||
+ return (FALSE);
|
||||
+ crp->port_ptr = (uint32_t *)(void *)port_ptr;
|
||||
+ if (xdr_u_int32(xdrs, &crp->resultslen))
|
||||
return ((*(crp->xdr_results))(xdrs, crp->results_ptr));
|
||||
- }
|
||||
return (FALSE);
|
||||
}
|
||||
|
||||
--
|
||||
2.45.1
|
||||
|
||||
2316
0018-Fix-unimportant-memory-leaks.patch
Normal file
2316
0018-Fix-unimportant-memory-leaks.patch
Normal file
File diff suppressed because it is too large
Load diff
71
0019-Remove-klist-s-defname-global-variable.patch
Normal file
71
0019-Remove-klist-s-defname-global-variable.patch
Normal file
|
|
@ -0,0 +1,71 @@
|
|||
From 05bb6d9c729a3c6a4ba35270368bc0f6e1875ad0 Mon Sep 17 00:00:00 2001
|
||||
From: Julien Rische <jrische@redhat.com>
|
||||
Date: Mon, 8 Jan 2024 16:52:27 +0100
|
||||
Subject: [PATCH] Remove klist's defname global variable
|
||||
|
||||
Addition of a "cleanup" section in kinit's show_ccache() function as
|
||||
part of commit 6c5471176f5266564fbc8a7e02f03b4b042202f8 introduced a
|
||||
double-free bug, because defname is a global variable. After the
|
||||
first call, successive calls may take place with a dangling pointer in
|
||||
defname, which will be freed if krb5_cc_get_principal() fails.
|
||||
|
||||
Convert "defname" to a local variable initialized at the beginning of
|
||||
show_ccache().
|
||||
|
||||
[ghudson@mit.edu: edited commit message]
|
||||
|
||||
(cherry picked from commit 5b00197227231943bd2305328c8260dd0b0dbcf0)
|
||||
---
|
||||
src/clients/klist/klist.c | 8 ++++----
|
||||
1 file changed, 4 insertions(+), 4 deletions(-)
|
||||
|
||||
diff --git a/src/clients/klist/klist.c b/src/clients/klist/klist.c
|
||||
index b5ae96a843..b5808e5c93 100644
|
||||
--- a/src/clients/klist/klist.c
|
||||
+++ b/src/clients/klist/klist.c
|
||||
@@ -53,7 +53,6 @@ int show_flags = 0, show_time = 0, status_only = 0, show_keys = 0;
|
||||
int show_etype = 0, show_addresses = 0, no_resolve = 0, print_version = 0;
|
||||
int show_adtype = 0, show_all = 0, list_all = 0, use_client_keytab = 0;
|
||||
int show_config = 0;
|
||||
-char *defname;
|
||||
char *progname;
|
||||
krb5_timestamp now;
|
||||
unsigned int timestamp_width;
|
||||
@@ -62,7 +61,7 @@ krb5_context context;
|
||||
|
||||
static krb5_boolean is_local_tgt(krb5_principal princ, krb5_data *realm);
|
||||
static char *etype_string(krb5_enctype );
|
||||
-static void show_credential(krb5_creds *);
|
||||
+static void show_credential(krb5_creds *, const char *);
|
||||
|
||||
static void list_all_ccaches(void);
|
||||
static int list_ccache(krb5_ccache);
|
||||
@@ -473,6 +472,7 @@ show_ccache(krb5_ccache cache)
|
||||
krb5_creds creds;
|
||||
krb5_principal princ = NULL;
|
||||
krb5_error_code ret;
|
||||
+ char *defname = NULL;
|
||||
int status = 1;
|
||||
|
||||
ret = krb5_cc_get_principal(context, cache, &princ);
|
||||
@@ -503,7 +503,7 @@ show_ccache(krb5_ccache cache)
|
||||
}
|
||||
while ((ret = krb5_cc_next_cred(context, cache, &cur, &creds)) == 0) {
|
||||
if (show_config || !krb5_is_config_principal(context, creds.server))
|
||||
- show_credential(&creds);
|
||||
+ show_credential(&creds, defname);
|
||||
krb5_free_cred_contents(context, &creds);
|
||||
}
|
||||
if (ret == KRB5_CC_END) {
|
||||
@@ -676,7 +676,7 @@ print_config_data(int col, krb5_data *data)
|
||||
}
|
||||
|
||||
static void
|
||||
-show_credential(krb5_creds *cred)
|
||||
+show_credential(krb5_creds *cred, const char *defname)
|
||||
{
|
||||
krb5_error_code ret;
|
||||
krb5_ticket *tkt = NULL;
|
||||
--
|
||||
2.45.1
|
||||
|
||||
34
0020-End-connection-on-KDC_ERR_SVC_UNAVAILABLE.patch
Normal file
34
0020-End-connection-on-KDC_ERR_SVC_UNAVAILABLE.patch
Normal file
|
|
@ -0,0 +1,34 @@
|
|||
From d7bcca2a215de880f4419afc450a96a747d48560 Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Fri, 27 Oct 2023 00:44:53 -0400
|
||||
Subject: [PATCH] End connection on KDC_ERR_SVC_UNAVAILABLE
|
||||
|
||||
In sendto_kdc.c:service_fds(), if a message handler indicates that a
|
||||
message should be discarded, kill the connection so we don't continue
|
||||
waiting on it for more data.
|
||||
|
||||
ticket: 7899
|
||||
(cherry picked from commit ca80f64c786341d5871ae1de18142e62af64f7b9)
|
||||
---
|
||||
src/lib/krb5/os/sendto_kdc.c | 5 ++++-
|
||||
1 file changed, 4 insertions(+), 1 deletion(-)
|
||||
|
||||
diff --git a/src/lib/krb5/os/sendto_kdc.c b/src/lib/krb5/os/sendto_kdc.c
|
||||
index 0f4bf23a95..262edf09b4 100644
|
||||
--- a/src/lib/krb5/os/sendto_kdc.c
|
||||
+++ b/src/lib/krb5/os/sendto_kdc.c
|
||||
@@ -1440,7 +1440,10 @@ service_fds(krb5_context context, struct select_state *selstate,
|
||||
if (msg_handler != NULL) {
|
||||
krb5_data reply = make_data(state->in.buf, state->in.pos);
|
||||
|
||||
- stop = (msg_handler(context, &reply, msg_handler_data) != 0);
|
||||
+ if (!msg_handler(context, &reply, msg_handler_data)) {
|
||||
+ kill_conn(context, state, selstate);
|
||||
+ stop = 0;
|
||||
+ }
|
||||
}
|
||||
|
||||
if (stop) {
|
||||
--
|
||||
2.46.0
|
||||
|
||||
226
0021-Add-request_timeout-configuration-parameter.patch
Normal file
226
0021-Add-request_timeout-configuration-parameter.patch
Normal file
|
|
@ -0,0 +1,226 @@
|
|||
From a07b3ae29fd972c40e30b95f6bcc8fb3ed4d9991 Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Thu, 26 Oct 2023 14:20:34 -0400
|
||||
Subject: [PATCH] Add request_timeout configuration parameter
|
||||
|
||||
Add a parameter to limit the total amount of time taken for a KDC or
|
||||
password change request.
|
||||
|
||||
ticket: 9106 (new)
|
||||
(cherry picked from commit 802318cda963456b3ed7856c836e89da891483be)
|
||||
---
|
||||
doc/admin/conf_files/krb5_conf.rst | 9 ++++++
|
||||
src/include/k5-int.h | 2 ++
|
||||
src/lib/krb5/krb/init_ctx.c | 14 +++++++-
|
||||
src/lib/krb5/os/sendto_kdc.c | 51 ++++++++++++++++++++----------
|
||||
4 files changed, 58 insertions(+), 18 deletions(-)
|
||||
|
||||
diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst
|
||||
index a33711d918..65fb592d98 100644
|
||||
--- a/doc/admin/conf_files/krb5_conf.rst
|
||||
+++ b/doc/admin/conf_files/krb5_conf.rst
|
||||
@@ -356,6 +356,15 @@ The libdefaults section may contain any of the following relations:
|
||||
(:ref:`duration` string.) Sets the default renewable lifetime
|
||||
for initial ticket requests. The default value is 0.
|
||||
|
||||
+**request_timeout**
|
||||
+ (:ref:`duration` string.) Sets the maximum total time for KDC or
|
||||
+ password change requests. This timeout does not affect the
|
||||
+ intervals between requests, so setting a low timeout may result in
|
||||
+ fewer requests being attempted and/or some servers not being
|
||||
+ contacted. A value of 0 indicates no specific maximum, in which
|
||||
+ case requests will time out if no server responds after several
|
||||
+ tries. The default value is 0. (New in release 1.22.)
|
||||
+
|
||||
**spake_preauth_groups**
|
||||
A whitespace or comma-separated list of words which specifies the
|
||||
groups allowed for SPAKE preauthentication. The possible values
|
||||
diff --git a/src/include/k5-int.h b/src/include/k5-int.h
|
||||
index b3e07945c1..69d6a6f569 100644
|
||||
--- a/src/include/k5-int.h
|
||||
+++ b/src/include/k5-int.h
|
||||
@@ -296,6 +296,7 @@ typedef unsigned char u_char;
|
||||
#define KRB5_CONF_SPAKE_PREAUTH_INDICATOR "spake_preauth_indicator"
|
||||
#define KRB5_CONF_SPAKE_PREAUTH_KDC_CHALLENGE "spake_preauth_kdc_challenge"
|
||||
#define KRB5_CONF_SPAKE_PREAUTH_GROUPS "spake_preauth_groups"
|
||||
+#define KRB5_CONF_REQUEST_TIMEOUT "request_timeout"
|
||||
#define KRB5_CONF_TICKET_LIFETIME "ticket_lifetime"
|
||||
#define KRB5_CONF_UDP_PREFERENCE_LIMIT "udp_preference_limit"
|
||||
#define KRB5_CONF_UNLOCKITER "unlockiter"
|
||||
@@ -1200,6 +1201,7 @@ struct _krb5_context {
|
||||
kdb5_dal_handle *dal_handle;
|
||||
/* allowable clock skew */
|
||||
krb5_deltat clockskew;
|
||||
+ krb5_deltat req_timeout;
|
||||
krb5_flags kdc_default_options;
|
||||
krb5_flags library_options;
|
||||
krb5_boolean profile_secure;
|
||||
diff --git a/src/lib/krb5/krb/init_ctx.c b/src/lib/krb5/krb/init_ctx.c
|
||||
index 2b5abcd817..582a2945ff 100644
|
||||
--- a/src/lib/krb5/krb/init_ctx.c
|
||||
+++ b/src/lib/krb5/krb/init_ctx.c
|
||||
@@ -157,7 +157,7 @@ krb5_init_context_profile(profile_t profile, krb5_flags flags,
|
||||
krb5_context ctx = 0;
|
||||
krb5_error_code retval;
|
||||
int tmp;
|
||||
- char *plugin_dir = NULL;
|
||||
+ char *plugin_dir = NULL, *timeout_str = NULL;
|
||||
|
||||
/* Verify some assumptions. If the assumptions hold and the
|
||||
compiler is optimizing, this should result in no code being
|
||||
@@ -240,6 +240,17 @@ krb5_init_context_profile(profile_t profile, krb5_flags flags,
|
||||
get_integer(ctx, KRB5_CONF_CLOCKSKEW, DEFAULT_CLOCKSKEW, &tmp);
|
||||
ctx->clockskew = tmp;
|
||||
|
||||
+ retval = profile_get_string(ctx->profile, KRB5_CONF_LIBDEFAULTS,
|
||||
+ KRB5_CONF_REQUEST_TIMEOUT, NULL, NULL,
|
||||
+ &timeout_str);
|
||||
+ if (retval)
|
||||
+ goto cleanup;
|
||||
+ if (timeout_str != NULL) {
|
||||
+ retval = krb5_string_to_deltat(timeout_str, &ctx->req_timeout);
|
||||
+ if (retval)
|
||||
+ goto cleanup;
|
||||
+ }
|
||||
+
|
||||
get_integer(ctx, KRB5_CONF_KDC_DEFAULT_OPTIONS, KDC_OPT_RENEWABLE_OK,
|
||||
&tmp);
|
||||
ctx->kdc_default_options = tmp;
|
||||
@@ -281,6 +292,7 @@ krb5_init_context_profile(profile_t profile, krb5_flags flags,
|
||||
|
||||
cleanup:
|
||||
profile_release_string(plugin_dir);
|
||||
+ profile_release_string(timeout_str);
|
||||
krb5_free_context(ctx);
|
||||
return retval;
|
||||
}
|
||||
diff --git a/src/lib/krb5/os/sendto_kdc.c b/src/lib/krb5/os/sendto_kdc.c
|
||||
index 262edf09b4..98247a1089 100644
|
||||
--- a/src/lib/krb5/os/sendto_kdc.c
|
||||
+++ b/src/lib/krb5/os/sendto_kdc.c
|
||||
@@ -1395,34 +1395,41 @@ get_endtime(time_ms endtime, struct conn_state *conns)
|
||||
|
||||
static krb5_boolean
|
||||
service_fds(krb5_context context, struct select_state *selstate,
|
||||
- time_ms interval, struct conn_state *conns,
|
||||
+ time_ms interval, time_ms timeout, struct conn_state *conns,
|
||||
struct select_state *seltemp, const krb5_data *realm,
|
||||
int (*msg_handler)(krb5_context, const krb5_data *, void *),
|
||||
void *msg_handler_data, struct conn_state **winner_out)
|
||||
{
|
||||
int e, selret = 0;
|
||||
- time_ms endtime;
|
||||
+ time_ms curtime, interval_end, endtime;
|
||||
struct conn_state *state;
|
||||
|
||||
*winner_out = NULL;
|
||||
|
||||
- e = get_curtime_ms(&endtime);
|
||||
+ e = get_curtime_ms(&curtime);
|
||||
if (e)
|
||||
return TRUE;
|
||||
- endtime += interval;
|
||||
+ interval_end = curtime + interval;
|
||||
|
||||
e = 0;
|
||||
while (selstate->nfds > 0) {
|
||||
- e = cm_select_or_poll(selstate, get_endtime(endtime, conns),
|
||||
- seltemp, &selret);
|
||||
+ endtime = get_endtime(interval_end, conns);
|
||||
+ /* Don't wait longer than the whole request should last. */
|
||||
+ if (timeout && endtime > timeout)
|
||||
+ endtime = timeout;
|
||||
+ e = cm_select_or_poll(selstate, endtime, seltemp, &selret);
|
||||
if (e == EINTR)
|
||||
continue;
|
||||
if (e != 0)
|
||||
break;
|
||||
|
||||
- if (selret == 0)
|
||||
- /* Timeout, return to caller. */
|
||||
+ if (selret == 0) {
|
||||
+ /* We timed out. Stop if we hit the overall request timeout. */
|
||||
+ if (timeout && (get_curtime_ms(&curtime) || curtime >= timeout))
|
||||
+ return TRUE;
|
||||
+ /* Otherwise return to the caller to send the next request. */
|
||||
return FALSE;
|
||||
+ }
|
||||
|
||||
/* Got something on a socket, process it. */
|
||||
for (state = conns; state != NULL; state = state->next) {
|
||||
@@ -1495,7 +1502,7 @@ k5_sendto(krb5_context context, const krb5_data *message,
|
||||
void *msg_handler_data)
|
||||
{
|
||||
int pass;
|
||||
- time_ms delay;
|
||||
+ time_ms delay, timeout = 0;
|
||||
krb5_error_code retval;
|
||||
struct conn_state *conns = NULL, *state, **tailptr, *next, *winner;
|
||||
size_t s;
|
||||
@@ -1505,6 +1512,13 @@ k5_sendto(krb5_context context, const krb5_data *message,
|
||||
|
||||
*reply = empty_data();
|
||||
|
||||
+ if (context->req_timeout) {
|
||||
+ retval = get_curtime_ms(&timeout);
|
||||
+ if (retval)
|
||||
+ return retval;
|
||||
+ timeout += 1000 * context->req_timeout;
|
||||
+ }
|
||||
+
|
||||
/* One for use here, listing all our fds in use, and one for
|
||||
* temporary use in service_fds, for the fds of interest. */
|
||||
sel_state = malloc(2 * sizeof(*sel_state));
|
||||
@@ -1532,8 +1546,9 @@ k5_sendto(krb5_context context, const krb5_data *message,
|
||||
if (maybe_send(context, state, message, sel_state, realm,
|
||||
callback_info))
|
||||
continue;
|
||||
- done = service_fds(context, sel_state, 1000, conns, seltemp,
|
||||
- realm, msg_handler, msg_handler_data, &winner);
|
||||
+ done = service_fds(context, sel_state, 1000, timeout, conns,
|
||||
+ seltemp, realm, msg_handler, msg_handler_data,
|
||||
+ &winner);
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1545,13 +1560,13 @@ k5_sendto(krb5_context context, const krb5_data *message,
|
||||
if (maybe_send(context, state, message, sel_state, realm,
|
||||
callback_info))
|
||||
continue;
|
||||
- done = service_fds(context, sel_state, 1000, conns, seltemp,
|
||||
+ done = service_fds(context, sel_state, 1000, timeout, conns, seltemp,
|
||||
realm, msg_handler, msg_handler_data, &winner);
|
||||
}
|
||||
|
||||
/* Wait for two seconds at the end of the first pass. */
|
||||
if (!done) {
|
||||
- done = service_fds(context, sel_state, 2000, conns, seltemp,
|
||||
+ done = service_fds(context, sel_state, 2000, timeout, conns, seltemp,
|
||||
realm, msg_handler, msg_handler_data, &winner);
|
||||
}
|
||||
|
||||
@@ -1562,15 +1577,17 @@ k5_sendto(krb5_context context, const krb5_data *message,
|
||||
if (maybe_send(context, state, message, sel_state, realm,
|
||||
callback_info))
|
||||
continue;
|
||||
- done = service_fds(context, sel_state, 1000, conns, seltemp,
|
||||
- realm, msg_handler, msg_handler_data, &winner);
|
||||
+ done = service_fds(context, sel_state, 1000, timeout, conns,
|
||||
+ seltemp, realm, msg_handler, msg_handler_data,
|
||||
+ &winner);
|
||||
if (sel_state->nfds == 0)
|
||||
break;
|
||||
}
|
||||
/* Wait for the delay backoff at the end of this pass. */
|
||||
if (!done) {
|
||||
- done = service_fds(context, sel_state, delay, conns, seltemp,
|
||||
- realm, msg_handler, msg_handler_data, &winner);
|
||||
+ done = service_fds(context, sel_state, delay, timeout, conns,
|
||||
+ seltemp, realm, msg_handler, msg_handler_data,
|
||||
+ &winner);
|
||||
}
|
||||
if (sel_state->nfds == 0)
|
||||
break;
|
||||
--
|
||||
2.46.0
|
||||
|
||||
138
0022-Wait-indefinitely-on-KDC-TCP-connections.patch
Normal file
138
0022-Wait-indefinitely-on-KDC-TCP-connections.patch
Normal file
|
|
@ -0,0 +1,138 @@
|
|||
From 1da153d97d7fb30a44fca35f9b71b8f4ed5385b9 Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Thu, 26 Oct 2023 16:26:42 -0400
|
||||
Subject: [PATCH] Wait indefinitely on KDC TCP connections
|
||||
|
||||
When making a KDC or password change request, wait indefinitely
|
||||
(limited only by request_timeout if set) once a KDC has accepted a TCP
|
||||
connection.
|
||||
|
||||
ticket: 9105 (new)
|
||||
(cherry picked from commit 6436a3808061da787a43c6810f5f0370cdfb6e36)
|
||||
---
|
||||
doc/admin/conf_files/krb5_conf.rst | 2 +-
|
||||
src/lib/krb5/os/sendto_kdc.c | 50 ++++++++++++++++--------------
|
||||
2 files changed, 27 insertions(+), 25 deletions(-)
|
||||
|
||||
diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst
|
||||
index 65fb592d98..b7284c47df 100644
|
||||
--- a/doc/admin/conf_files/krb5_conf.rst
|
||||
+++ b/doc/admin/conf_files/krb5_conf.rst
|
||||
@@ -357,7 +357,7 @@ The libdefaults section may contain any of the following relations:
|
||||
for initial ticket requests. The default value is 0.
|
||||
|
||||
**request_timeout**
|
||||
- (:ref:`duration` string.) Sets the maximum total time for KDC or
|
||||
+ (:ref:`duration` string.) Sets the maximum total time for KDC and
|
||||
password change requests. This timeout does not affect the
|
||||
intervals between requests, so setting a low timeout may result in
|
||||
fewer requests being attempted and/or some servers not being
|
||||
diff --git a/src/lib/krb5/os/sendto_kdc.c b/src/lib/krb5/os/sendto_kdc.c
|
||||
index 98247a1089..924f5b2d26 100644
|
||||
--- a/src/lib/krb5/os/sendto_kdc.c
|
||||
+++ b/src/lib/krb5/os/sendto_kdc.c
|
||||
@@ -134,7 +134,6 @@ struct conn_state {
|
||||
krb5_data callback_buffer;
|
||||
size_t server_index;
|
||||
struct conn_state *next;
|
||||
- time_ms endtime;
|
||||
krb5_boolean defer;
|
||||
struct {
|
||||
const char *uri_path;
|
||||
@@ -344,15 +343,19 @@ cm_select_or_poll(const struct select_state *in, time_ms endtime,
|
||||
struct select_state *out, int *sret)
|
||||
{
|
||||
#ifndef USE_POLL
|
||||
- struct timeval tv;
|
||||
+ struct timeval tv, *tvp;
|
||||
#endif
|
||||
krb5_error_code retval;
|
||||
time_ms curtime, interval;
|
||||
|
||||
- retval = get_curtime_ms(&curtime);
|
||||
- if (retval != 0)
|
||||
- return retval;
|
||||
- interval = (curtime < endtime) ? endtime - curtime : 0;
|
||||
+ if (endtime != 0) {
|
||||
+ retval = get_curtime_ms(&curtime);
|
||||
+ if (retval != 0)
|
||||
+ return retval;
|
||||
+ interval = (curtime < endtime) ? endtime - curtime : 0;
|
||||
+ } else {
|
||||
+ interval = -1;
|
||||
+ }
|
||||
|
||||
/* We don't need a separate copy of the selstate for poll, but use one for
|
||||
* consistency with how we use select. */
|
||||
@@ -361,9 +364,14 @@ cm_select_or_poll(const struct select_state *in, time_ms endtime,
|
||||
#ifdef USE_POLL
|
||||
*sret = poll(out->fds, out->nfds, interval);
|
||||
#else
|
||||
- tv.tv_sec = interval / 1000;
|
||||
- tv.tv_usec = interval % 1000 * 1000;
|
||||
- *sret = select(out->max, &out->rfds, &out->wfds, &out->xfds, &tv);
|
||||
+ if (interval != -1) {
|
||||
+ tv.tv_sec = interval / 1000;
|
||||
+ tv.tv_usec = interval % 1000 * 1000;
|
||||
+ tvp = &tv;
|
||||
+ } else {
|
||||
+ tvp = NULL;
|
||||
+ }
|
||||
+ *sret = select(out->max, &out->rfds, &out->wfds, &out->xfds, tvp);
|
||||
#endif
|
||||
|
||||
return (*sret < 0) ? SOCKET_ERRNO : 0;
|
||||
@@ -1099,11 +1107,6 @@ service_tcp_connect(krb5_context context, const krb5_data *realm,
|
||||
}
|
||||
|
||||
conn->state = WRITING;
|
||||
-
|
||||
- /* Record this connection's timeout for service_fds. */
|
||||
- if (get_curtime_ms(&conn->endtime) == 0)
|
||||
- conn->endtime += 10000;
|
||||
-
|
||||
return conn->service_write(context, realm, conn, selstate);
|
||||
}
|
||||
|
||||
@@ -1378,19 +1381,18 @@ kill_conn:
|
||||
return FALSE;
|
||||
}
|
||||
|
||||
-/* Return the maximum of endtime and the endtime fields of all currently active
|
||||
- * TCP connections. */
|
||||
-static time_ms
|
||||
-get_endtime(time_ms endtime, struct conn_state *conns)
|
||||
+/* Return true if conns contains any states with connected TCP sockets. */
|
||||
+static krb5_boolean
|
||||
+any_tcp_connections(struct conn_state *conns)
|
||||
{
|
||||
struct conn_state *state;
|
||||
|
||||
for (state = conns; state != NULL; state = state->next) {
|
||||
- if ((state->state == READING || state->state == WRITING) &&
|
||||
- state->endtime > endtime)
|
||||
- endtime = state->endtime;
|
||||
+ if (state->addr.transport != UDP &&
|
||||
+ (state->state == READING || state->state == WRITING))
|
||||
+ return TRUE;
|
||||
}
|
||||
- return endtime;
|
||||
+ return FALSE;
|
||||
}
|
||||
|
||||
static krb5_boolean
|
||||
@@ -1413,9 +1415,9 @@ service_fds(krb5_context context, struct select_state *selstate,
|
||||
|
||||
e = 0;
|
||||
while (selstate->nfds > 0) {
|
||||
- endtime = get_endtime(interval_end, conns);
|
||||
+ endtime = any_tcp_connections(conns) ? 0 : interval_end;
|
||||
/* Don't wait longer than the whole request should last. */
|
||||
- if (timeout && endtime > timeout)
|
||||
+ if (timeout && (!endtime || endtime > timeout))
|
||||
endtime = timeout;
|
||||
e = cm_select_or_poll(selstate, endtime, seltemp, &selret);
|
||||
if (e == EINTR)
|
||||
--
|
||||
2.46.0
|
||||
|
||||
1297
0023-Remove-PKINIT-RSA-support.patch
Normal file
1297
0023-Remove-PKINIT-RSA-support.patch
Normal file
File diff suppressed because it is too large
Load diff
265
0024-Fix-various-issues-detected-by-static-analysis.patch
Normal file
265
0024-Fix-various-issues-detected-by-static-analysis.patch
Normal file
|
|
@ -0,0 +1,265 @@
|
|||
From 3999883b9745bfd7065d41ff05b19e56bcb2e791 Mon Sep 17 00:00:00 2001
|
||||
From: Julien Rische <jrische@redhat.com>
|
||||
Date: Fri, 6 Sep 2024 17:18:11 +0200
|
||||
Subject: [PATCH] Fix various issues detected by static analysis
|
||||
|
||||
In klists's show_credential(), ensure that the column counter doesn't
|
||||
decrease if printf() fails.
|
||||
|
||||
In process_k5beta7_princ(), bounds-check the e_length field.
|
||||
|
||||
In ndr_enc_delegation_info(), initialize b so it is always valid for
|
||||
the cleanup handler.
|
||||
|
||||
In krb5_dbe_def_decrypt_key_data(), change the flow control so ret is
|
||||
always set by the end of the function. Return KRB5_KDB_INVALIDKEYSIZE
|
||||
if there isn't enough data in the first key_data_contents field or if
|
||||
the serialized key length is invalid.
|
||||
|
||||
In svcauth_gss_validate(), expand rpchdr to accomodate the header plus
|
||||
MAX_AUTH_BYTES.
|
||||
|
||||
In svcudp_reply(), change slen to unsigned to match the return type of
|
||||
XDR_GETPOS() and eliminate an unnecessary check for slen >= 0.
|
||||
|
||||
In krb5int_pthread_loaded()(), remove pthread_equal() from the weak
|
||||
symbol checks. It is implemented as an inline function in some glibc
|
||||
versions, which makes the comparison "&pthread_equal == 0" always
|
||||
false.
|
||||
|
||||
[ghudson@mit.edu: further modified krb5_dbe_def_decrypt_key_data() for
|
||||
clarity; added detail to commit message]
|
||||
|
||||
(cherry picked from commit a96541981ee34c8642ddeb6101b98e883e41c6e5)
|
||||
---
|
||||
src/clients/klist/klist.c | 12 ++++-----
|
||||
src/kadmin/dbutil/dump.c | 5 ++++
|
||||
src/kdc/ndr.c | 2 +-
|
||||
src/lib/kdb/decrypt_key.c | 54 ++++++++++++++++++++------------------
|
||||
src/lib/rpc/svc_auth_gss.c | 5 +++-
|
||||
src/lib/rpc/svc_udp.c | 13 ++++-----
|
||||
src/util/support/threads.c | 2 --
|
||||
7 files changed, 51 insertions(+), 42 deletions(-)
|
||||
|
||||
diff --git a/src/clients/klist/klist.c b/src/clients/klist/klist.c
|
||||
index b5808e5c93..ba9539fd23 100644
|
||||
--- a/src/clients/klist/klist.c
|
||||
+++ b/src/clients/klist/klist.c
|
||||
@@ -681,7 +681,7 @@ show_credential(krb5_creds *cred, const char *defname)
|
||||
krb5_error_code ret;
|
||||
krb5_ticket *tkt = NULL;
|
||||
char *name = NULL, *sname = NULL, *tktsname, *flags;
|
||||
- int extra_field = 0, ccol = 0, i;
|
||||
+ int extra_field = 0, ccol = 0, i, r;
|
||||
krb5_boolean is_config = krb5_is_config_principal(context, cred->server);
|
||||
|
||||
ret = krb5_unparse_name(context, cred->client, &name);
|
||||
@@ -711,11 +711,11 @@ show_credential(krb5_creds *cred, const char *defname)
|
||||
fputs("config: ", stdout);
|
||||
ccol = 8;
|
||||
for (i = 1; i < cred->server->length; i++) {
|
||||
- ccol += printf("%s%.*s%s",
|
||||
- i > 1 ? "(" : "",
|
||||
- (int)cred->server->data[i].length,
|
||||
- cred->server->data[i].data,
|
||||
- i > 1 ? ")" : "");
|
||||
+ r = printf("%s%.*s%s", i > 1 ? "(" : "",
|
||||
+ (int)cred->server->data[i].length,
|
||||
+ cred->server->data[i].data, i > 1 ? ")" : "");
|
||||
+ if (r >= 0)
|
||||
+ ccol += r;
|
||||
}
|
||||
fputs(" = ", stdout);
|
||||
ccol += 3;
|
||||
diff --git a/src/kadmin/dbutil/dump.c b/src/kadmin/dbutil/dump.c
|
||||
index 4d6cc0bdf9..feb053d834 100644
|
||||
--- a/src/kadmin/dbutil/dump.c
|
||||
+++ b/src/kadmin/dbutil/dump.c
|
||||
@@ -704,6 +704,11 @@ process_k5beta7_princ(krb5_context context, const char *fname, FILE *filep,
|
||||
|
||||
dbentry->len = u1;
|
||||
dbentry->n_key_data = u4;
|
||||
+
|
||||
+ if (u5 > UINT16_MAX) {
|
||||
+ load_err(fname, *linenop, _("invalid principal extra data size"));
|
||||
+ goto fail;
|
||||
+ }
|
||||
dbentry->e_length = u5;
|
||||
|
||||
if (kp != NULL) {
|
||||
diff --git a/src/kdc/ndr.c b/src/kdc/ndr.c
|
||||
index d438408ee2..38be9fe42a 100644
|
||||
--- a/src/kdc/ndr.c
|
||||
+++ b/src/kdc/ndr.c
|
||||
@@ -242,7 +242,7 @@ ndr_enc_delegation_info(struct pac_s4u_delegation_info *in, krb5_data *out)
|
||||
{
|
||||
krb5_error_code ret;
|
||||
size_t i;
|
||||
- struct k5buf b;
|
||||
+ struct k5buf b = EMPTY_K5BUF;
|
||||
struct encoded_wchars pt_encoded = { 0 }, *tss_encoded = NULL;
|
||||
uint32_t pointer = 0;
|
||||
|
||||
diff --git a/src/lib/kdb/decrypt_key.c b/src/lib/kdb/decrypt_key.c
|
||||
index 82bbed6312..21aa3742b1 100644
|
||||
--- a/src/lib/kdb/decrypt_key.c
|
||||
+++ b/src/lib/kdb/decrypt_key.c
|
||||
@@ -60,7 +60,7 @@ krb5_dbe_def_decrypt_key_data(krb5_context context, const krb5_keyblock *mkey,
|
||||
krb5_keyblock *dbkey_out,
|
||||
krb5_keysalt *keysalt_out)
|
||||
{
|
||||
- krb5_error_code ret;
|
||||
+ krb5_error_code ret = KRB5_CRYPTO_INTERNAL;
|
||||
int16_t keylen;
|
||||
krb5_enc_data cipher;
|
||||
krb5_data plain = empty_data();
|
||||
@@ -74,36 +74,38 @@ krb5_dbe_def_decrypt_key_data(krb5_context context, const krb5_keyblock *mkey,
|
||||
if (mkey == NULL)
|
||||
return KRB5_KDB_BADSTORED_MKEY;
|
||||
|
||||
- if (kd->key_data_contents[0] != NULL && kd->key_data_length[0] >= 2) {
|
||||
- keylen = load_16_le(kd->key_data_contents[0]);
|
||||
- if (keylen < 0)
|
||||
- return EINVAL;
|
||||
- cipher.enctype = ENCTYPE_UNKNOWN;
|
||||
- cipher.ciphertext = make_data(kd->key_data_contents[0] + 2,
|
||||
- kd->key_data_length[0] - 2);
|
||||
- ret = alloc_data(&plain, kd->key_data_length[0] - 2);
|
||||
- if (ret)
|
||||
- goto cleanup;
|
||||
+ if (kd->key_data_contents[0] == NULL || kd->key_data_length[0] < 2)
|
||||
+ return KRB5_KDB_INVALIDKEYSIZE;
|
||||
|
||||
- ret = krb5_c_decrypt(context, mkey, 0, 0, &cipher, &plain);
|
||||
- if (ret)
|
||||
- goto cleanup;
|
||||
+ keylen = load_16_le(kd->key_data_contents[0]);
|
||||
+ if (keylen < 0)
|
||||
+ return KRB5_KDB_INVALIDKEYSIZE;
|
||||
|
||||
- /* Make sure the plaintext has at least as many bytes as the true ke
|
||||
- * length (it may have more due to padding). */
|
||||
- if ((unsigned int)keylen > plain.length) {
|
||||
- ret = KRB5_CRYPTO_INTERNAL;
|
||||
- if (ret)
|
||||
- goto cleanup;
|
||||
- }
|
||||
+ cipher.enctype = ENCTYPE_UNKNOWN;
|
||||
+ cipher.ciphertext = make_data(kd->key_data_contents[0] + 2,
|
||||
+ kd->key_data_length[0] - 2);
|
||||
+ ret = alloc_data(&plain, kd->key_data_length[0] - 2);
|
||||
+ if (ret)
|
||||
+ goto cleanup;
|
||||
|
||||
- kb.magic = KV5M_KEYBLOCK;
|
||||
- kb.enctype = kd->key_data_type[0];
|
||||
- kb.length = keylen;
|
||||
- kb.contents = (uint8_t *)plain.data;
|
||||
- plain = empty_data();
|
||||
+ ret = krb5_c_decrypt(context, mkey, 0, 0, &cipher, &plain);
|
||||
+ if (ret)
|
||||
+ goto cleanup;
|
||||
+
|
||||
+ /* Make sure the plaintext has at least as many bytes as the true key
|
||||
+ * length (it may have more due to padding). */
|
||||
+ if ((unsigned int)keylen > plain.length) {
|
||||
+ ret = KRB5_CRYPTO_INTERNAL;
|
||||
+ if (ret)
|
||||
+ goto cleanup;
|
||||
}
|
||||
|
||||
+ kb.magic = KV5M_KEYBLOCK;
|
||||
+ kb.enctype = kd->key_data_type[0];
|
||||
+ kb.length = keylen;
|
||||
+ kb.contents = (uint8_t *)plain.data;
|
||||
+ plain = empty_data();
|
||||
+
|
||||
/* Decode salt data. */
|
||||
if (keysalt_out != NULL) {
|
||||
if (kd->key_data_ver == 2) {
|
||||
diff --git a/src/lib/rpc/svc_auth_gss.c b/src/lib/rpc/svc_auth_gss.c
|
||||
index 98d601c8ab..4f1d2911b0 100644
|
||||
--- a/src/lib/rpc/svc_auth_gss.c
|
||||
+++ b/src/lib/rpc/svc_auth_gss.c
|
||||
@@ -297,7 +297,7 @@ svcauth_gss_validate(struct svc_req *rqst, struct svc_rpc_gss_data *gd, struct r
|
||||
struct opaque_auth *oa;
|
||||
gss_buffer_desc rpcbuf, checksum;
|
||||
OM_uint32 maj_stat, min_stat, qop_state;
|
||||
- u_char rpchdr[128];
|
||||
+ u_char rpchdr[32 + MAX_AUTH_BYTES];
|
||||
int32_t *buf;
|
||||
|
||||
log_debug("in svcauth_gss_validate()");
|
||||
@@ -315,6 +315,8 @@ svcauth_gss_validate(struct svc_req *rqst, struct svc_rpc_gss_data *gd, struct r
|
||||
return (FALSE);
|
||||
|
||||
buf = (int32_t *)(void *)rpchdr;
|
||||
+
|
||||
+ /* Write the 32 first bytes of the header. */
|
||||
IXDR_PUT_LONG(buf, msg->rm_xid);
|
||||
IXDR_PUT_ENUM(buf, msg->rm_direction);
|
||||
IXDR_PUT_LONG(buf, msg->rm_call.cb_rpcvers);
|
||||
@@ -323,6 +325,7 @@ svcauth_gss_validate(struct svc_req *rqst, struct svc_rpc_gss_data *gd, struct r
|
||||
IXDR_PUT_LONG(buf, msg->rm_call.cb_proc);
|
||||
IXDR_PUT_ENUM(buf, oa->oa_flavor);
|
||||
IXDR_PUT_LONG(buf, oa->oa_length);
|
||||
+
|
||||
if (oa->oa_length) {
|
||||
memcpy((caddr_t)buf, oa->oa_base, oa->oa_length);
|
||||
buf += RNDUP(oa->oa_length) / sizeof(int32_t);
|
||||
diff --git a/src/lib/rpc/svc_udp.c b/src/lib/rpc/svc_udp.c
|
||||
index 8ecbdf2b33..3aff277eb7 100644
|
||||
--- a/src/lib/rpc/svc_udp.c
|
||||
+++ b/src/lib/rpc/svc_udp.c
|
||||
@@ -248,8 +248,9 @@ static bool_t svcudp_reply(
|
||||
{
|
||||
struct svcudp_data *su = su_data(xprt);
|
||||
XDR *xdrs = &su->su_xdrs;
|
||||
- int slen;
|
||||
+ u_int slen;
|
||||
bool_t stat = FALSE;
|
||||
+ ssize_t r;
|
||||
|
||||
xdrproc_t xdr_results = NULL;
|
||||
caddr_t xdr_location = 0;
|
||||
@@ -272,12 +273,12 @@ static bool_t svcudp_reply(
|
||||
if (xdr_replymsg(xdrs, msg) &&
|
||||
(!has_args ||
|
||||
(SVCAUTH_WRAP(xprt->xp_auth, xdrs, xdr_results, xdr_location)))) {
|
||||
- slen = (int)XDR_GETPOS(xdrs);
|
||||
- if (sendto(xprt->xp_sock, rpc_buffer(xprt), slen, 0,
|
||||
- (struct sockaddr *)&(xprt->xp_raddr), xprt->xp_addrlen)
|
||||
- == slen) {
|
||||
+ slen = XDR_GETPOS(xdrs);
|
||||
+ r = sendto(xprt->xp_sock, rpc_buffer(xprt), slen, 0,
|
||||
+ (struct sockaddr *)&(xprt->xp_raddr), xprt->xp_addrlen);
|
||||
+ if (r >= 0 && (u_int)r == slen) {
|
||||
stat = TRUE;
|
||||
- if (su->su_cache && slen >= 0) {
|
||||
+ if (su->su_cache) {
|
||||
cache_set(xprt, (uint32_t) slen);
|
||||
}
|
||||
}
|
||||
diff --git a/src/util/support/threads.c b/src/util/support/threads.c
|
||||
index be7e4c2e3f..4ded805b79 100644
|
||||
--- a/src/util/support/threads.c
|
||||
+++ b/src/util/support/threads.c
|
||||
@@ -118,7 +118,6 @@ struct tsd_block {
|
||||
# pragma weak pthread_mutex_destroy
|
||||
# pragma weak pthread_mutex_init
|
||||
# pragma weak pthread_self
|
||||
-# pragma weak pthread_equal
|
||||
# pragma weak pthread_getspecific
|
||||
# pragma weak pthread_setspecific
|
||||
# pragma weak pthread_key_create
|
||||
@@ -151,7 +150,6 @@ int krb5int_pthread_loaded (void)
|
||||
|| &pthread_mutex_destroy == 0
|
||||
|| &pthread_mutex_init == 0
|
||||
|| &pthread_self == 0
|
||||
- || &pthread_equal == 0
|
||||
/* Any program that's really multithreaded will have to be
|
||||
able to create threads. */
|
||||
|| &pthread_create == 0
|
||||
--
|
||||
2.46.0
|
||||
|
||||
629
0025-Generate-and-verify-message-MACs-in-libkrad.patch
Normal file
629
0025-Generate-and-verify-message-MACs-in-libkrad.patch
Normal file
|
|
@ -0,0 +1,629 @@
|
|||
From ea02fd7bb79861b8e36517c7c95af821a16657c4 Mon Sep 17 00:00:00 2001
|
||||
From: Julien Rische <jrische@redhat.com>
|
||||
Date: Thu, 22 Aug 2024 17:15:50 +0200
|
||||
Subject: [PATCH] Generate and verify message MACs in libkrad
|
||||
|
||||
Implement some of the measures specified in
|
||||
draft-ietf-radext-deprecating-radius-03 for mitigating the BlastRADIUS
|
||||
attack (CVE-2024-3596):
|
||||
|
||||
* Include a Message-Authenticator MAC as the first attribute when
|
||||
generating a packet of type Access-Request, Access-Reject,
|
||||
Access-Accept, or Access-Challenge (sections 5.2.1 and 5.2.4), if
|
||||
the secret is non-empty. (An empty secret indicates the use of Unix
|
||||
domain socket transport.)
|
||||
|
||||
* Validate the Message-Authenticator MAC in received packets, if
|
||||
present.
|
||||
|
||||
FreeRADIUS enforces Message-Authenticator as of versions 3.2.5 and
|
||||
3.0.27. libkrad must generate Message-Authenticator attributes in
|
||||
order to remain compatible with these implementations.
|
||||
|
||||
[ghudson@mit.edu: adjusted style and naming; simplified some
|
||||
functions; edited commit message]
|
||||
|
||||
ticket: 9142 (new)
|
||||
tags: pullup
|
||||
target_version: 1.21-next
|
||||
|
||||
(cherry picked from commit 871125fea8ce0370a972bf65f7d1de63f619b06c)
|
||||
---
|
||||
src/include/k5-int.h | 5 +
|
||||
src/lib/crypto/krb/checksum_hmac_md5.c | 28 ++++
|
||||
src/lib/crypto/libk5crypto.exports | 1 +
|
||||
src/lib/krad/attr.c | 17 ++
|
||||
src/lib/krad/attrset.c | 59 +++++--
|
||||
src/lib/krad/internal.h | 7 +-
|
||||
src/lib/krad/packet.c | 206 +++++++++++++++++++++++--
|
||||
src/lib/krad/t_attrset.c | 2 +-
|
||||
src/lib/krad/t_daemon.py | 3 +-
|
||||
src/lib/krad/t_packet.c | 11 ++
|
||||
src/tests/t_otp.py | 3 +
|
||||
11 files changed, 311 insertions(+), 31 deletions(-)
|
||||
|
||||
diff --git a/src/include/k5-int.h b/src/include/k5-int.h
|
||||
index 69d6a6f569..b7789a2dd8 100644
|
||||
--- a/src/include/k5-int.h
|
||||
+++ b/src/include/k5-int.h
|
||||
@@ -2403,4 +2403,9 @@ krb5_boolean
|
||||
k5_sname_compare(krb5_context context, krb5_const_principal sname,
|
||||
krb5_const_principal princ);
|
||||
|
||||
+/* Generate an HMAC-MD5 keyed checksum as specified by RFC 2104. */
|
||||
+krb5_error_code
|
||||
+k5_hmac_md5(const krb5_data *key, const krb5_crypto_iov *data, size_t num_data,
|
||||
+ krb5_data *output);
|
||||
+
|
||||
#endif /* _KRB5_INT_H */
|
||||
diff --git a/src/lib/crypto/krb/checksum_hmac_md5.c b/src/lib/crypto/krb/checksum_hmac_md5.c
|
||||
index ec024f3966..a809388549 100644
|
||||
--- a/src/lib/crypto/krb/checksum_hmac_md5.c
|
||||
+++ b/src/lib/crypto/krb/checksum_hmac_md5.c
|
||||
@@ -92,3 +92,31 @@ cleanup:
|
||||
free(hash_iov);
|
||||
return ret;
|
||||
}
|
||||
+
|
||||
+krb5_error_code
|
||||
+k5_hmac_md5(const krb5_data *key, const krb5_crypto_iov *data, size_t num_data,
|
||||
+ krb5_data *output)
|
||||
+{
|
||||
+ krb5_error_code ret;
|
||||
+ const struct krb5_hash_provider *hash = &krb5int_hash_md5;
|
||||
+ krb5_keyblock keyblock = { 0 };
|
||||
+ krb5_data hashed_key;
|
||||
+ uint8_t hkeybuf[16];
|
||||
+ krb5_crypto_iov iov;
|
||||
+
|
||||
+ /* Hash the key if it is longer than the block size. */
|
||||
+ if (key->length > hash->blocksize) {
|
||||
+ hashed_key = make_data(hkeybuf, sizeof(hkeybuf));
|
||||
+ iov.flags = KRB5_CRYPTO_TYPE_DATA;
|
||||
+ iov.data = *key;
|
||||
+ ret = hash->hash(&iov, 1, &hashed_key);
|
||||
+ if (ret)
|
||||
+ return ret;
|
||||
+ key = &hashed_key;
|
||||
+ }
|
||||
+
|
||||
+ keyblock.magic = KV5M_KEYBLOCK;
|
||||
+ keyblock.length = key->length;
|
||||
+ keyblock.contents = (uint8_t *)key->data;
|
||||
+ return krb5int_hmac_keyblock(hash, &keyblock, data, num_data, output);
|
||||
+}
|
||||
diff --git a/src/lib/crypto/libk5crypto.exports b/src/lib/crypto/libk5crypto.exports
|
||||
index d8ffa63304..00e0ce1812 100644
|
||||
--- a/src/lib/crypto/libk5crypto.exports
|
||||
+++ b/src/lib/crypto/libk5crypto.exports
|
||||
@@ -102,3 +102,4 @@ krb5_c_prfplus
|
||||
krb5_c_derive_prfplus
|
||||
k5_enctype_to_ssf
|
||||
krb5int_c_deprecated_enctype
|
||||
+k5_hmac_md5
|
||||
diff --git a/src/lib/krad/attr.c b/src/lib/krad/attr.c
|
||||
index 42d354a3b5..65ed1d35e7 100644
|
||||
--- a/src/lib/krad/attr.c
|
||||
+++ b/src/lib/krad/attr.c
|
||||
@@ -125,6 +125,23 @@ static const attribute_record attributes[UCHAR_MAX] = {
|
||||
{"NAS-Port-Type", 4, 4, NULL, NULL},
|
||||
{"Port-Limit", 4, 4, NULL, NULL},
|
||||
{"Login-LAT-Port", 1, MAX_ATTRSIZE, NULL, NULL},
|
||||
+ {NULL, 0, 0, NULL, NULL}, /* Reserved for tunnelling */
|
||||
+ {NULL, 0, 0, NULL, NULL}, /* Reserved for tunnelling */
|
||||
+ {NULL, 0, 0, NULL, NULL}, /* Reserved for tunnelling */
|
||||
+ {NULL, 0, 0, NULL, NULL}, /* Reserved for tunnelling */
|
||||
+ {NULL, 0, 0, NULL, NULL}, /* Reserved for tunnelling */
|
||||
+ {NULL, 0, 0, NULL, NULL}, /* Reserved for tunnelling */
|
||||
+ {NULL, 0, 0, NULL, NULL}, /* Reserved for Apple Remote Access Protocol */
|
||||
+ {NULL, 0, 0, NULL, NULL}, /* Reserved for Apple Remote Access Protocol */
|
||||
+ {NULL, 0, 0, NULL, NULL}, /* Reserved for Apple Remote Access Protocol */
|
||||
+ {NULL, 0, 0, NULL, NULL}, /* Reserved for Apple Remote Access Protocol */
|
||||
+ {NULL, 0, 0, NULL, NULL}, /* Reserved for Apple Remote Access Protocol */
|
||||
+ {NULL, 0, 0, NULL, NULL}, /* Password-Retry */
|
||||
+ {NULL, 0, 0, NULL, NULL}, /* Prompt */
|
||||
+ {NULL, 0, 0, NULL, NULL}, /* Connect-Info */
|
||||
+ {NULL, 0, 0, NULL, NULL}, /* Configuration-Token */
|
||||
+ {NULL, 0, 0, NULL, NULL}, /* EAP-Message */
|
||||
+ {"Message-Authenticator", MD5_DIGEST_SIZE, MD5_DIGEST_SIZE, NULL, NULL},
|
||||
};
|
||||
|
||||
/* Encode User-Password attribute. */
|
||||
diff --git a/src/lib/krad/attrset.c b/src/lib/krad/attrset.c
|
||||
index 6ec031e320..e5457ebfd7 100644
|
||||
--- a/src/lib/krad/attrset.c
|
||||
+++ b/src/lib/krad/attrset.c
|
||||
@@ -164,15 +164,44 @@ krad_attrset_copy(const krad_attrset *set, krad_attrset **copy)
|
||||
return 0;
|
||||
}
|
||||
|
||||
+/* Place an encoded attributes into outbuf at position *i. Increment *i by the
|
||||
+ * length of the encoding. */
|
||||
+static krb5_error_code
|
||||
+append_attr(krb5_context ctx, const char *secret,
|
||||
+ const uint8_t *auth, krad_attr type, const krb5_data *data,
|
||||
+ uint8_t outbuf[MAX_ATTRSETSIZE], size_t *i, krb5_boolean *is_fips)
|
||||
+{
|
||||
+ uint8_t buffer[MAX_ATTRSIZE];
|
||||
+ size_t attrlen;
|
||||
+ krb5_error_code retval;
|
||||
+
|
||||
+ retval = kr_attr_encode(ctx, secret, auth, type, data, buffer, &attrlen,
|
||||
+ is_fips);
|
||||
+ if (retval)
|
||||
+ return retval;
|
||||
+
|
||||
+ if (attrlen > MAX_ATTRSETSIZE - *i - 2)
|
||||
+ return EMSGSIZE;
|
||||
+
|
||||
+ outbuf[(*i)++] = type;
|
||||
+ outbuf[(*i)++] = attrlen + 2;
|
||||
+ memcpy(outbuf + *i, buffer, attrlen);
|
||||
+ *i += attrlen;
|
||||
+
|
||||
+ return 0;
|
||||
+}
|
||||
+
|
||||
krb5_error_code
|
||||
kr_attrset_encode(const krad_attrset *set, const char *secret,
|
||||
- const unsigned char *auth,
|
||||
+ const uint8_t *auth, krb5_boolean add_msgauth,
|
||||
unsigned char outbuf[MAX_ATTRSETSIZE], size_t *outlen,
|
||||
krb5_boolean *is_fips)
|
||||
{
|
||||
- unsigned char buffer[MAX_ATTRSIZE];
|
||||
krb5_error_code retval;
|
||||
- size_t i = 0, attrlen;
|
||||
+ krad_attr msgauth_type = krad_attr_name2num("Message-Authenticator");
|
||||
+ const uint8_t zeroes[MD5_DIGEST_SIZE] = { 0 };
|
||||
+ krb5_data zerodata;
|
||||
+ size_t i = 0;
|
||||
attr *a;
|
||||
|
||||
if (set == NULL) {
|
||||
@@ -180,19 +209,21 @@ kr_attrset_encode(const krad_attrset *set, const char *secret,
|
||||
return 0;
|
||||
}
|
||||
|
||||
- K5_TAILQ_FOREACH(a, &set->list, list) {
|
||||
- retval = kr_attr_encode(set->ctx, secret, auth, a->type, &a->attr,
|
||||
- buffer, &attrlen, is_fips);
|
||||
- if (retval != 0)
|
||||
+ if (add_msgauth) {
|
||||
+ /* Encode Message-Authenticator as the first attribute, per
|
||||
+ * draft-ietf-radext-deprecating-radius-03 section 5.2. */
|
||||
+ zerodata = make_data((uint8_t *)zeroes, MD5_DIGEST_SIZE);
|
||||
+ retval = append_attr(set->ctx, secret, auth, msgauth_type, &zerodata,
|
||||
+ outbuf, &i, is_fips);
|
||||
+ if (retval)
|
||||
return retval;
|
||||
+ }
|
||||
|
||||
- if (i + attrlen + 2 > MAX_ATTRSETSIZE)
|
||||
- return EMSGSIZE;
|
||||
-
|
||||
- outbuf[i++] = a->type;
|
||||
- outbuf[i++] = attrlen + 2;
|
||||
- memcpy(&outbuf[i], buffer, attrlen);
|
||||
- i += attrlen;
|
||||
+ K5_TAILQ_FOREACH(a, &set->list, list) {
|
||||
+ retval = append_attr(set->ctx, secret, auth, a->type, &a->attr,
|
||||
+ outbuf, &i, is_fips);
|
||||
+ if (retval)
|
||||
+ return retval;
|
||||
}
|
||||
|
||||
*outlen = i;
|
||||
diff --git a/src/lib/krad/internal.h b/src/lib/krad/internal.h
|
||||
index a17b6f39b1..ca66f3ec68 100644
|
||||
--- a/src/lib/krad/internal.h
|
||||
+++ b/src/lib/krad/internal.h
|
||||
@@ -49,6 +49,8 @@
|
||||
#define UCHAR_MAX 255
|
||||
#endif
|
||||
|
||||
+#define MD5_DIGEST_SIZE 16
|
||||
+
|
||||
/* RFC 2865 */
|
||||
#define MAX_ATTRSIZE (UCHAR_MAX - 2)
|
||||
#define MAX_ATTRSETSIZE (KRAD_PACKET_SIZE_MAX - 20)
|
||||
@@ -79,10 +81,11 @@ kr_attr_decode(krb5_context ctx, const char *secret, const unsigned char *auth,
|
||||
krad_attr type, const krb5_data *in,
|
||||
unsigned char outbuf[MAX_ATTRSIZE], size_t *outlen);
|
||||
|
||||
-/* Encode the attributes into the buffer. */
|
||||
+/* Encode set into outbuf. If add_msgauth is true, include a zeroed
|
||||
+ * Message-Authenticator as the first attribute. */
|
||||
krb5_error_code
|
||||
kr_attrset_encode(const krad_attrset *set, const char *secret,
|
||||
- const unsigned char *auth,
|
||||
+ const uint8_t *auth, krb5_boolean add_msgauth,
|
||||
unsigned char outbuf[MAX_ATTRSETSIZE], size_t *outlen,
|
||||
krb5_boolean *is_fips);
|
||||
|
||||
diff --git a/src/lib/krad/packet.c b/src/lib/krad/packet.c
|
||||
index c5446b890c..3c1a4d507e 100644
|
||||
--- a/src/lib/krad/packet.c
|
||||
+++ b/src/lib/krad/packet.c
|
||||
@@ -36,6 +36,7 @@
|
||||
typedef unsigned char uchar;
|
||||
|
||||
/* RFC 2865 */
|
||||
+#define MSGAUTH_SIZE (2 + MD5_DIGEST_SIZE)
|
||||
#define OFFSET_CODE 0
|
||||
#define OFFSET_ID 1
|
||||
#define OFFSET_LENGTH 2
|
||||
@@ -222,6 +223,106 @@ packet_set_attrset(krb5_context ctx, const char *secret, krad_packet *pkt)
|
||||
return kr_attrset_decode(ctx, &tmp, secret, pkt_auth(pkt), &pkt->attrset);
|
||||
}
|
||||
|
||||
+/* Determine if a packet requires a Message-Authenticator attribute. */
|
||||
+static inline krb5_boolean
|
||||
+requires_msgauth(const char *secret, krad_code code)
|
||||
+{
|
||||
+ /* If no secret is provided, assume that the transport is a UNIX socket.
|
||||
+ * Message-Authenticator is required only on UDP and TCP connections. */
|
||||
+ if (*secret == '\0')
|
||||
+ return FALSE;
|
||||
+
|
||||
+ /*
|
||||
+ * Per draft-ietf-radext-deprecating-radius-03 sections 5.2.1 and 5.2.4,
|
||||
+ * Message-Authenticator is required in Access-Request packets and all
|
||||
+ * potential responses when UDP or TCP transport is used.
|
||||
+ */
|
||||
+ return code == krad_code_name2num("Access-Request") ||
|
||||
+ code == krad_code_name2num("Access-Reject") ||
|
||||
+ code == krad_code_name2num("Access-Accept") ||
|
||||
+ code == krad_code_name2num("Access-Challenge");
|
||||
+}
|
||||
+
|
||||
+/* Check if the packet has a Message-Authenticator attribute. */
|
||||
+static inline krb5_boolean
|
||||
+has_pkt_msgauth(const krad_packet *pkt)
|
||||
+{
|
||||
+ krad_attr msgauth_type = krad_attr_name2num("Message-Authenticator");
|
||||
+
|
||||
+ return krad_attrset_get(pkt->attrset, msgauth_type, 0) != NULL;
|
||||
+}
|
||||
+
|
||||
+/* Return the beginning of the Message-Authenticator attribute in pkt, or NULL
|
||||
+ * if no such attribute is present. */
|
||||
+static const uint8_t *
|
||||
+lookup_msgauth_addr(const krad_packet *pkt)
|
||||
+{
|
||||
+ krad_attr msgauth_type = krad_attr_name2num("Message-Authenticator");
|
||||
+ size_t i;
|
||||
+ uint8_t *p;
|
||||
+
|
||||
+ i = OFFSET_ATTR;
|
||||
+ while (i + 2 < pkt->pkt.length) {
|
||||
+ p = (uint8_t *)offset(&pkt->pkt, i);
|
||||
+ if (msgauth_type == *p)
|
||||
+ return p;
|
||||
+ i += p[1];
|
||||
+ }
|
||||
+
|
||||
+ return NULL;
|
||||
+}
|
||||
+
|
||||
+/*
|
||||
+ * Calculate the message authenticator MAC for pkt as specified in RFC 2869
|
||||
+ * section 5.14, placing the result in mac_out. Use the provided authenticator
|
||||
+ * auth, which may be from pkt or from a corresponding request.
|
||||
+ */
|
||||
+static krb5_error_code
|
||||
+calculate_mac(const char *secret, const krad_packet *pkt,
|
||||
+ const uint8_t auth[AUTH_FIELD_SIZE],
|
||||
+ uint8_t mac_out[MD5_DIGEST_SIZE])
|
||||
+{
|
||||
+ uint8_t zeroed_msgauth[MSGAUTH_SIZE];
|
||||
+ krad_attr msgauth_type = krad_attr_name2num("Message-Authenticator");
|
||||
+ const uint8_t *msgauth_attr, *msgauth_end, *pkt_end;
|
||||
+ krb5_crypto_iov input[5];
|
||||
+ krb5_data ksecr, mac;
|
||||
+
|
||||
+ msgauth_attr = lookup_msgauth_addr(pkt);
|
||||
+ if (msgauth_attr == NULL)
|
||||
+ return EINVAL;
|
||||
+ msgauth_end = msgauth_attr + MSGAUTH_SIZE;
|
||||
+ pkt_end = (const uint8_t *)pkt->pkt.data + pkt->pkt.length;
|
||||
+
|
||||
+ /* Read code, id, and length from the packet. */
|
||||
+ input[0].flags = KRB5_CRYPTO_TYPE_DATA;
|
||||
+ input[0].data = make_data(pkt->pkt.data, OFFSET_AUTH);
|
||||
+
|
||||
+ /* Read the provided authenticator. */
|
||||
+ input[1].flags = KRB5_CRYPTO_TYPE_DATA;
|
||||
+ input[1].data = make_data((uint8_t *)auth, AUTH_FIELD_SIZE);
|
||||
+
|
||||
+ /* Read any attributes before Message-Authenticator. */
|
||||
+ input[2].flags = KRB5_CRYPTO_TYPE_DATA;
|
||||
+ input[2].data = make_data(pkt_attr(pkt), msgauth_attr - pkt_attr(pkt));
|
||||
+
|
||||
+ /* Read Message-Authenticator with the data bytes all set to zero, per RFC
|
||||
+ * 2869 section 5.14. */
|
||||
+ zeroed_msgauth[0] = msgauth_type;
|
||||
+ zeroed_msgauth[1] = MSGAUTH_SIZE;
|
||||
+ memset(zeroed_msgauth + 2, 0, MD5_DIGEST_SIZE);
|
||||
+ input[3].flags = KRB5_CRYPTO_TYPE_DATA;
|
||||
+ input[3].data = make_data(zeroed_msgauth, MSGAUTH_SIZE);
|
||||
+
|
||||
+ /* Read any attributes after Message-Authenticator. */
|
||||
+ input[4].flags = KRB5_CRYPTO_TYPE_DATA;
|
||||
+ input[4].data = make_data((uint8_t *)msgauth_end, pkt_end - msgauth_end);
|
||||
+
|
||||
+ mac = make_data(mac_out, MD5_DIGEST_SIZE);
|
||||
+ ksecr = string2data((char *)secret);
|
||||
+ return k5_hmac_md5(&ksecr, input, 5, &mac);
|
||||
+}
|
||||
+
|
||||
ssize_t
|
||||
krad_packet_bytes_needed(const krb5_data *buffer)
|
||||
{
|
||||
@@ -255,6 +356,7 @@ krad_packet_new_request(krb5_context ctx, const char *secret, krad_code code,
|
||||
krad_packet *pkt;
|
||||
uchar id;
|
||||
size_t attrset_len;
|
||||
+ krb5_boolean msgauth_required;
|
||||
|
||||
pkt = packet_new();
|
||||
if (pkt == NULL) {
|
||||
@@ -274,9 +376,13 @@ krad_packet_new_request(krb5_context ctx, const char *secret, krad_code code,
|
||||
if (retval != 0)
|
||||
goto error;
|
||||
|
||||
+ /* Determine if Message-Authenticator is required. */
|
||||
+ msgauth_required = (*secret != '\0' &&
|
||||
+ code == krad_code_name2num("Access-Request"));
|
||||
+
|
||||
/* Encode the attributes. */
|
||||
- retval = kr_attrset_encode(set, secret, pkt_auth(pkt), pkt_attr(pkt),
|
||||
- &attrset_len, &pkt->is_fips);
|
||||
+ retval = kr_attrset_encode(set, secret, pkt_auth(pkt), msgauth_required,
|
||||
+ pkt_attr(pkt), &attrset_len, &pkt->is_fips);
|
||||
if (retval != 0)
|
||||
goto error;
|
||||
|
||||
@@ -285,6 +391,13 @@ krad_packet_new_request(krb5_context ctx, const char *secret, krad_code code,
|
||||
pkt_code_set(pkt, code);
|
||||
pkt_len_set(pkt, pkt->pkt.length);
|
||||
|
||||
+ if (msgauth_required) {
|
||||
+ /* Calculate and set the Message-Authenticator MAC. */
|
||||
+ retval = calculate_mac(secret, pkt, pkt_auth(pkt), pkt_attr(pkt) + 2);
|
||||
+ if (retval != 0)
|
||||
+ goto error;
|
||||
+ }
|
||||
+
|
||||
/* Copy the attrset for future use. */
|
||||
retval = packet_set_attrset(ctx, secret, pkt);
|
||||
if (retval != 0)
|
||||
@@ -307,14 +420,19 @@ krad_packet_new_response(krb5_context ctx, const char *secret, krad_code code,
|
||||
krb5_error_code retval;
|
||||
krad_packet *pkt;
|
||||
size_t attrset_len;
|
||||
+ krb5_boolean msgauth_required;
|
||||
|
||||
pkt = packet_new();
|
||||
if (pkt == NULL)
|
||||
return ENOMEM;
|
||||
|
||||
+ /* Determine if Message-Authenticator is required. */
|
||||
+ msgauth_required = requires_msgauth(secret, code);
|
||||
+
|
||||
/* Encode the attributes. */
|
||||
- retval = kr_attrset_encode(set, secret, pkt_auth(request), pkt_attr(pkt),
|
||||
- &attrset_len, &pkt->is_fips);
|
||||
+ retval = kr_attrset_encode(set, secret, pkt_auth(request),
|
||||
+ msgauth_required, pkt_attr(pkt), &attrset_len,
|
||||
+ &pkt->is_fips);
|
||||
if (retval != 0)
|
||||
goto error;
|
||||
|
||||
@@ -330,6 +448,18 @@ krad_packet_new_response(krb5_context ctx, const char *secret, krad_code code,
|
||||
if (retval != 0)
|
||||
goto error;
|
||||
|
||||
+ if (msgauth_required) {
|
||||
+ /*
|
||||
+ * Calculate and replace the Message-Authenticator MAC. Per RFC 2869
|
||||
+ * section 5.14, use the authenticator from the request, not from the
|
||||
+ * response.
|
||||
+ */
|
||||
+ retval = calculate_mac(secret, pkt, pkt_auth(request),
|
||||
+ pkt_attr(pkt) + 2);
|
||||
+ if (retval != 0)
|
||||
+ goto error;
|
||||
+ }
|
||||
+
|
||||
/* Copy the attrset for future use. */
|
||||
retval = packet_set_attrset(ctx, secret, pkt);
|
||||
if (retval != 0)
|
||||
@@ -343,6 +473,34 @@ error:
|
||||
return retval;
|
||||
}
|
||||
|
||||
+/* Verify the Message-Authenticator value in pkt, using the provided
|
||||
+ * authenticator (which may be from pkt or from a corresponding request). */
|
||||
+static krb5_error_code
|
||||
+verify_msgauth(const char *secret, const krad_packet *pkt,
|
||||
+ const uint8_t auth[AUTH_FIELD_SIZE])
|
||||
+{
|
||||
+ uint8_t mac[MD5_DIGEST_SIZE];
|
||||
+ krad_attr msgauth_type = krad_attr_name2num("Message-Authenticator");
|
||||
+ const krb5_data *msgauth;
|
||||
+ krb5_error_code retval;
|
||||
+
|
||||
+ msgauth = krad_packet_get_attr(pkt, msgauth_type, 0);
|
||||
+ if (msgauth == NULL)
|
||||
+ return ENODATA;
|
||||
+
|
||||
+ retval = calculate_mac(secret, pkt, auth, mac);
|
||||
+ if (retval)
|
||||
+ return retval;
|
||||
+
|
||||
+ if (msgauth->length != MD5_DIGEST_SIZE)
|
||||
+ return EMSGSIZE;
|
||||
+
|
||||
+ if (k5_bcmp(mac, msgauth->data, MD5_DIGEST_SIZE) != 0)
|
||||
+ return EBADMSG;
|
||||
+
|
||||
+ return 0;
|
||||
+}
|
||||
+
|
||||
/* Decode a packet. */
|
||||
static krb5_error_code
|
||||
decode_packet(krb5_context ctx, const char *secret, const krb5_data *buffer,
|
||||
@@ -394,21 +552,35 @@ krad_packet_decode_request(krb5_context ctx, const char *secret,
|
||||
krad_packet **reqpkt)
|
||||
{
|
||||
const krad_packet *tmp = NULL;
|
||||
+ krad_packet *req;
|
||||
krb5_error_code retval;
|
||||
|
||||
- retval = decode_packet(ctx, secret, buffer, reqpkt);
|
||||
- if (cb != NULL && retval == 0) {
|
||||
+ retval = decode_packet(ctx, secret, buffer, &req);
|
||||
+ if (retval)
|
||||
+ return retval;
|
||||
+
|
||||
+ /* Verify Message-Authenticator if present. */
|
||||
+ if (has_pkt_msgauth(req)) {
|
||||
+ retval = verify_msgauth(secret, req, pkt_auth(req));
|
||||
+ if (retval) {
|
||||
+ krad_packet_free(req);
|
||||
+ return retval;
|
||||
+ }
|
||||
+ }
|
||||
+
|
||||
+ if (cb != NULL) {
|
||||
for (tmp = (*cb)(data, FALSE); tmp != NULL; tmp = (*cb)(data, FALSE)) {
|
||||
if (pkt_id_get(*reqpkt) == pkt_id_get(tmp))
|
||||
break;
|
||||
}
|
||||
- }
|
||||
|
||||
- if (cb != NULL && (retval != 0 || tmp != NULL))
|
||||
- (*cb)(data, TRUE);
|
||||
+ if (tmp != NULL)
|
||||
+ (*cb)(data, TRUE);
|
||||
+ }
|
||||
|
||||
+ *reqpkt = req;
|
||||
*duppkt = tmp;
|
||||
- return retval;
|
||||
+ return 0;
|
||||
}
|
||||
|
||||
krb5_error_code
|
||||
@@ -435,9 +607,17 @@ krad_packet_decode_response(krb5_context ctx, const char *secret,
|
||||
break;
|
||||
}
|
||||
|
||||
- /* If the authenticator matches, then the response is valid. */
|
||||
- if (memcmp(pkt_auth(*rsppkt), auth, sizeof(auth)) == 0)
|
||||
- break;
|
||||
+ /* Verify the response authenticator. */
|
||||
+ if (k5_bcmp(pkt_auth(*rsppkt), auth, sizeof(auth)) != 0)
|
||||
+ continue;
|
||||
+
|
||||
+ /* Verify Message-Authenticator if present. */
|
||||
+ if (has_pkt_msgauth(*rsppkt)) {
|
||||
+ if (verify_msgauth(secret, *rsppkt, pkt_auth(tmp)) != 0)
|
||||
+ continue;
|
||||
+ }
|
||||
+
|
||||
+ break;
|
||||
}
|
||||
}
|
||||
|
||||
diff --git a/src/lib/krad/t_attrset.c b/src/lib/krad/t_attrset.c
|
||||
index 4cdb8b7d8e..f9c66509bd 100644
|
||||
--- a/src/lib/krad/t_attrset.c
|
||||
+++ b/src/lib/krad/t_attrset.c
|
||||
@@ -63,7 +63,7 @@ main(void)
|
||||
noerror(krad_attrset_add(set, krad_attr_name2num("User-Password"), &tmp));
|
||||
|
||||
/* Encode attrset. */
|
||||
- noerror(kr_attrset_encode(set, "foo", auth, buffer, &encode_len,
|
||||
+ noerror(kr_attrset_encode(set, "foo", auth, FALSE, buffer, &encode_len,
|
||||
&is_fips));
|
||||
krad_attrset_free(set);
|
||||
|
||||
diff --git a/src/lib/krad/t_daemon.py b/src/lib/krad/t_daemon.py
|
||||
index 4a3de079c7..647d4894eb 100755
|
||||
--- a/src/lib/krad/t_daemon.py
|
||||
+++ b/src/lib/krad/t_daemon.py
|
||||
@@ -40,6 +40,7 @@ DICTIONARY = """
|
||||
ATTRIBUTE\tUser-Name\t1\tstring
|
||||
ATTRIBUTE\tUser-Password\t2\toctets
|
||||
ATTRIBUTE\tNAS-Identifier\t32\tstring
|
||||
+ATTRIBUTE\tMessage-Authenticator\t80\toctets
|
||||
"""
|
||||
|
||||
class TestServer(server.Server):
|
||||
@@ -52,7 +53,7 @@ class TestServer(server.Server):
|
||||
if key == "User-Password":
|
||||
passwd = [pkt.PwDecrypt(x) for x in pkt[key]]
|
||||
|
||||
- reply = self.CreateReplyPacket(pkt)
|
||||
+ reply = self.CreateReplyPacket(pkt, message_authenticator=True)
|
||||
if passwd == ['accept']:
|
||||
reply.code = packet.AccessAccept
|
||||
else:
|
||||
diff --git a/src/lib/krad/t_packet.c b/src/lib/krad/t_packet.c
|
||||
index c22489144f..104b6507a2 100644
|
||||
--- a/src/lib/krad/t_packet.c
|
||||
+++ b/src/lib/krad/t_packet.c
|
||||
@@ -172,6 +172,9 @@ main(int argc, const char **argv)
|
||||
krb5_data username, password;
|
||||
krb5_boolean auth = FALSE;
|
||||
krb5_context ctx;
|
||||
+ const krad_packet *dupreq;
|
||||
+ const krb5_data *encpkt;
|
||||
+ krad_packet *decreq;
|
||||
|
||||
username = string2data("testUser");
|
||||
|
||||
@@ -184,9 +187,17 @@ main(int argc, const char **argv)
|
||||
|
||||
password = string2data("accept");
|
||||
noerror(make_packet(ctx, &username, &password, &packets[ACCEPT_PACKET]));
|
||||
+ encpkt = krad_packet_encode(packets[ACCEPT_PACKET]);
|
||||
+ noerror(krad_packet_decode_request(ctx, "foo", encpkt, NULL, NULL,
|
||||
+ &dupreq, &decreq));
|
||||
+ krad_packet_free(decreq);
|
||||
|
||||
password = string2data("reject");
|
||||
noerror(make_packet(ctx, &username, &password, &packets[REJECT_PACKET]));
|
||||
+ encpkt = krad_packet_encode(packets[REJECT_PACKET]);
|
||||
+ noerror(krad_packet_decode_request(ctx, "foo", encpkt, NULL, NULL,
|
||||
+ &dupreq, &decreq));
|
||||
+ krad_packet_free(decreq);
|
||||
|
||||
memset(&hints, 0, sizeof(hints));
|
||||
hints.ai_family = AF_INET;
|
||||
diff --git a/src/tests/t_otp.py b/src/tests/t_otp.py
|
||||
index c3b820a411..dd5cdc5c26 100755
|
||||
--- a/src/tests/t_otp.py
|
||||
+++ b/src/tests/t_otp.py
|
||||
@@ -49,6 +49,7 @@ ATTRIBUTE User-Name 1 string
|
||||
ATTRIBUTE User-Password 2 octets
|
||||
ATTRIBUTE Service-Type 6 integer
|
||||
ATTRIBUTE NAS-Identifier 32 string
|
||||
+ATTRIBUTE Message-Authenticator 80 octets
|
||||
'''
|
||||
|
||||
class RadiusDaemon(Process):
|
||||
@@ -97,6 +98,8 @@ class RadiusDaemon(Process):
|
||||
reply.code = packet.AccessReject
|
||||
replyq['reply'] = False
|
||||
|
||||
+ reply.add_message_authenticator()
|
||||
+
|
||||
outq.put(replyq)
|
||||
if addr is None:
|
||||
sock.send(reply.ReplyPacket())
|
||||
--
|
||||
2.46.0
|
||||
|
||||
1027
0026-PKINIT-ECDH-support.patch
Normal file
1027
0026-PKINIT-ECDH-support.patch
Normal file
File diff suppressed because it is too large
Load diff
78
0027-Add-ecdsa-with-sha512-256-to-supportedCMSTypes.patch
Normal file
78
0027-Add-ecdsa-with-sha512-256-to-supportedCMSTypes.patch
Normal file
|
|
@ -0,0 +1,78 @@
|
|||
From 43d10f1580c033fe706470e7588c720ac7854918 Mon Sep 17 00:00:00 2001
|
||||
From: Julien Rische <jrische@redhat.com>
|
||||
Date: Wed, 21 Jun 2023 18:27:11 +0200
|
||||
Subject: [PATCH] Add ecdsa-with-sha512/256 to supportedCMSTypes
|
||||
|
||||
Elliptic curve certificates are already supported for PKINIT
|
||||
pre-authentication, but their associated signature types aren't
|
||||
advertized. Add ecdsa-with-sha512 and ecdsa-with-sha256 OIDs to the
|
||||
supportedCMSTypes list sent by the client.
|
||||
|
||||
[ghudson@mit.edu: edited commit message]
|
||||
|
||||
ticket: 9100 (new)
|
||||
(cherry picked from commit 9913e5c92c4e5cb76d6ae58386f744766d2e6454)
|
||||
---
|
||||
src/plugins/preauth/pkinit/pkinit_constants.c | 38 +++++++++++++++++++
|
||||
1 file changed, 38 insertions(+)
|
||||
|
||||
diff --git a/src/plugins/preauth/pkinit/pkinit_constants.c b/src/plugins/preauth/pkinit/pkinit_constants.c
|
||||
index 10f8688ec2..905e90d29c 100644
|
||||
--- a/src/plugins/preauth/pkinit/pkinit_constants.c
|
||||
+++ b/src/plugins/preauth/pkinit/pkinit_constants.c
|
||||
@@ -64,14 +64,52 @@ static char sha512WithRSAEncr_oid[9] = {
|
||||
0x2a, 0x86, 0x48, 0x86, 0xf7, 0x0d, 0x01, 0x01, 0x0d
|
||||
};
|
||||
|
||||
+/* RFC 3279 ecdsa-with-SHA1: iso(1) member-body(2) us(840) ansi-X9-62(10045)
|
||||
+ * signatures(4) 1 */
|
||||
+static char ecdsaWithSha1_oid[] = {
|
||||
+ 0x2a, 0x86, 0x48, 0xce, 0x3d, 0x04, 0x01
|
||||
+};
|
||||
+
|
||||
+/* RFC 5758 ecdsa-with-SHA256: iso(1) member-body(2) us(840) ansi-X9-62(10045)
|
||||
+ * signatures(4) ecdsa-with-SHA2(3) 2 */
|
||||
+static char ecdsaWithSha256_oid[] = {
|
||||
+ 0x2a, 0x86, 0x48, 0xce, 0x3d, 0x04, 0x03, 0x02
|
||||
+};
|
||||
+
|
||||
+/* RFC 5758 ecdsa-with-SHA384: iso(1) member-body(2) us(840) ansi-X9-62(10045)
|
||||
+ * signatures(4) ecdsa-with-SHA2(3) 3 */
|
||||
+static char ecdsaWithSha384_oid[] = {
|
||||
+ 0x2a, 0x86, 0x48, 0xce, 0x3d, 0x04, 0x03, 0x03
|
||||
+};
|
||||
+
|
||||
+/* RFC 5758 ecdsa-with-SHA512: iso(1) member-body(2) us(840) ansi-X9-62(10045)
|
||||
+ * signatures(4) ecdsa-with-SHA2(3) 4 */
|
||||
+static char ecdsaWithSha512_oid[] = {
|
||||
+ 0x2a, 0x86, 0x48, 0xce, 0x3d, 0x04, 0x03, 0x04
|
||||
+};
|
||||
+
|
||||
const krb5_data sha256WithRSAEncr_id = {
|
||||
KV5M_DATA, sizeof(sha256WithRSAEncr_oid), sha256WithRSAEncr_oid
|
||||
};
|
||||
const krb5_data sha512WithRSAEncr_id = {
|
||||
KV5M_DATA, sizeof(sha512WithRSAEncr_oid), sha512WithRSAEncr_oid
|
||||
};
|
||||
+const krb5_data ecdsaWithSha1_id = {
|
||||
+ KV5M_DATA, sizeof(ecdsaWithSha1_oid), ecdsaWithSha1_oid
|
||||
+};
|
||||
+const krb5_data ecdsaWithSha256_id = {
|
||||
+ KV5M_DATA, sizeof(ecdsaWithSha256_oid), ecdsaWithSha256_oid
|
||||
+};
|
||||
+const krb5_data ecdsaWithSha384_id = {
|
||||
+ KV5M_DATA, sizeof(ecdsaWithSha384_oid), ecdsaWithSha384_oid
|
||||
+};
|
||||
+const krb5_data ecdsaWithSha512_id = {
|
||||
+ KV5M_DATA, sizeof(ecdsaWithSha512_oid), ecdsaWithSha512_oid
|
||||
+};
|
||||
|
||||
krb5_data const * const supported_cms_algs[] = {
|
||||
+ &ecdsaWithSha512_id,
|
||||
+ &ecdsaWithSha256_id,
|
||||
&sha512WithRSAEncr_id,
|
||||
&sha256WithRSAEncr_id,
|
||||
NULL
|
||||
--
|
||||
2.47.1
|
||||
|
||||
264
0028-Get-rid-of-pkinit_crypto_openssl.h.patch
Normal file
264
0028-Get-rid-of-pkinit_crypto_openssl.h.patch
Normal file
|
|
@ -0,0 +1,264 @@
|
|||
From fba4cbf0bc50569b8ea6d1e1c3303eaab84935e1 Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Sun, 30 Jul 2023 01:07:38 -0400
|
||||
Subject: [PATCH] Get rid of pkinit_crypto_openssl.h
|
||||
|
||||
Fold pkinit_crypto_openssl.h into the one source file where it was
|
||||
used. Also clean up the include of <arpa/inet.h>, as htonl() is no
|
||||
longer used after commit 1c87ce6c44a9de0824580a2d72a8a202237e01f4.
|
||||
|
||||
(cherry picked from commit b3352945fb8836f8b4095e0b8aad04b54aca3152)
|
||||
---
|
||||
src/plugins/preauth/pkinit/deps | 2 +-
|
||||
.../preauth/pkinit/pkinit_crypto_openssl.c | 85 +++++++++++-
|
||||
.../preauth/pkinit/pkinit_crypto_openssl.h | 121 ------------------
|
||||
3 files changed, 83 insertions(+), 125 deletions(-)
|
||||
delete mode 100644 src/plugins/preauth/pkinit/pkinit_crypto_openssl.h
|
||||
|
||||
diff --git a/src/plugins/preauth/pkinit/deps b/src/plugins/preauth/pkinit/deps
|
||||
index 58320aa801..b6f4476fe8 100644
|
||||
--- a/src/plugins/preauth/pkinit/deps
|
||||
+++ b/src/plugins/preauth/pkinit/deps
|
||||
@@ -112,4 +112,4 @@ pkinit_crypto_openssl.so pkinit_crypto_openssl.po $(OUTPRE)pkinit_crypto_openssl
|
||||
$(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/krb5/preauth_plugin.h \
|
||||
$(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \
|
||||
pkcs11.h pkinit.h pkinit_accessor.h pkinit_crypto.h \
|
||||
- pkinit_crypto_openssl.c pkinit_crypto_openssl.h pkinit_trace.h
|
||||
+ pkinit_crypto_openssl.c pkinit_trace.h
|
||||
diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c
|
||||
index f6d494bd11..ae8599d5a2 100644
|
||||
--- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c
|
||||
+++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c
|
||||
@@ -30,20 +30,99 @@
|
||||
*/
|
||||
|
||||
#include "k5-int.h"
|
||||
-#include "pkinit_crypto_openssl.h"
|
||||
#include "k5-buf.h"
|
||||
#include "k5-err.h"
|
||||
#include "k5-hex.h"
|
||||
-#include <unistd.h>
|
||||
+#include "pkinit.h"
|
||||
#include <dirent.h>
|
||||
-#include <arpa/inet.h>
|
||||
|
||||
+#include <openssl/bn.h>
|
||||
+#include <openssl/dh.h>
|
||||
+#include <openssl/x509.h>
|
||||
+#include <openssl/pkcs7.h>
|
||||
+#include <openssl/pkcs12.h>
|
||||
+#include <openssl/obj_mac.h>
|
||||
+#include <openssl/x509v3.h>
|
||||
+#include <openssl/err.h>
|
||||
+#include <openssl/evp.h>
|
||||
+#include <openssl/sha.h>
|
||||
+#include <openssl/asn1.h>
|
||||
+#include <openssl/pem.h>
|
||||
+#include <openssl/asn1t.h>
|
||||
+#include <openssl/cms.h>
|
||||
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||
#include <openssl/core_names.h>
|
||||
#include <openssl/kdf.h>
|
||||
+#include <openssl/decoder.h>
|
||||
#include <openssl/params.h>
|
||||
#endif
|
||||
|
||||
+#define DN_BUF_LEN 256
|
||||
+#define MAX_CREDS_ALLOWED 20
|
||||
+
|
||||
+struct _pkinit_cred_info {
|
||||
+ char *name;
|
||||
+ X509 *cert;
|
||||
+ EVP_PKEY *key;
|
||||
+#ifndef WITHOUT_PKCS11
|
||||
+ CK_BYTE_PTR cert_id;
|
||||
+ int cert_id_len;
|
||||
+#endif
|
||||
+};
|
||||
+typedef struct _pkinit_cred_info *pkinit_cred_info;
|
||||
+
|
||||
+struct _pkinit_identity_crypto_context {
|
||||
+ pkinit_cred_info creds[MAX_CREDS_ALLOWED+1];
|
||||
+ STACK_OF(X509) *my_certs; /* available user certs */
|
||||
+ char *identity; /* identity name for user cert */
|
||||
+ int cert_index; /* cert to use out of available certs*/
|
||||
+ EVP_PKEY *my_key; /* available user keys if in filesystem */
|
||||
+ STACK_OF(X509) *trustedCAs; /* available trusted ca certs */
|
||||
+ STACK_OF(X509) *intermediateCAs; /* available intermediate ca certs */
|
||||
+ STACK_OF(X509_CRL) *revoked; /* available crls */
|
||||
+ int pkcs11_method;
|
||||
+ krb5_prompter_fct prompter;
|
||||
+ void *prompter_data;
|
||||
+#ifndef WITHOUT_PKCS11
|
||||
+ char *p11_module_name;
|
||||
+ CK_SLOT_ID slotid;
|
||||
+ char *token_label;
|
||||
+ char *cert_label;
|
||||
+ /* These are crypto-specific. */
|
||||
+ struct plugin_file_handle *p11_module;
|
||||
+ CK_SESSION_HANDLE session;
|
||||
+ CK_FUNCTION_LIST_PTR p11;
|
||||
+ uint8_t *cert_id;
|
||||
+ size_t cert_id_len;
|
||||
+ CK_MECHANISM_TYPE mech;
|
||||
+#endif
|
||||
+ krb5_boolean defer_id_prompt;
|
||||
+ pkinit_deferred_id *deferred_ids;
|
||||
+};
|
||||
+
|
||||
+struct _pkinit_plg_crypto_context {
|
||||
+ EVP_PKEY *dh_1024;
|
||||
+ EVP_PKEY *dh_2048;
|
||||
+ EVP_PKEY *dh_4096;
|
||||
+ EVP_PKEY *ec_p256;
|
||||
+ EVP_PKEY *ec_p384;
|
||||
+ EVP_PKEY *ec_p521;
|
||||
+ ASN1_OBJECT *id_pkinit_authData;
|
||||
+ ASN1_OBJECT *id_pkinit_DHKeyData;
|
||||
+ ASN1_OBJECT *id_pkinit_rkeyData;
|
||||
+ ASN1_OBJECT *id_pkinit_san;
|
||||
+ ASN1_OBJECT *id_ms_san_upn;
|
||||
+ ASN1_OBJECT *id_pkinit_KPClientAuth;
|
||||
+ ASN1_OBJECT *id_pkinit_KPKdc;
|
||||
+ ASN1_OBJECT *id_ms_kp_sc_logon;
|
||||
+ ASN1_OBJECT *id_kp_serverAuth;
|
||||
+};
|
||||
+
|
||||
+struct _pkinit_req_crypto_context {
|
||||
+ X509 *received_cert;
|
||||
+ EVP_PKEY *client_pkey;
|
||||
+};
|
||||
+
|
||||
static krb5_error_code pkinit_init_pkinit_oids(pkinit_plg_crypto_context );
|
||||
static void pkinit_fini_pkinit_oids(pkinit_plg_crypto_context );
|
||||
|
||||
diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.h b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.h
|
||||
deleted file mode 100644
|
||||
index b7a3358800..0000000000
|
||||
--- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.h
|
||||
+++ /dev/null
|
||||
@@ -1,121 +0,0 @@
|
||||
-/*
|
||||
- * COPYRIGHT (C) 2006,2007
|
||||
- * THE REGENTS OF THE UNIVERSITY OF MICHIGAN
|
||||
- * ALL RIGHTS RESERVED
|
||||
- *
|
||||
- * Permission is granted to use, copy, create derivative works
|
||||
- * and redistribute this software and such derivative works
|
||||
- * for any purpose, so long as the name of The University of
|
||||
- * Michigan is not used in any advertising or publicity
|
||||
- * pertaining to the use of distribution of this software
|
||||
- * without specific, written prior authorization. If the
|
||||
- * above copyright notice or any other identification of the
|
||||
- * University of Michigan is included in any copy of any
|
||||
- * portion of this software, then the disclaimer below must
|
||||
- * also be included.
|
||||
- *
|
||||
- * THIS SOFTWARE IS PROVIDED AS IS, WITHOUT REPRESENTATION
|
||||
- * FROM THE UNIVERSITY OF MICHIGAN AS TO ITS FITNESS FOR ANY
|
||||
- * PURPOSE, AND WITHOUT WARRANTY BY THE UNIVERSITY OF
|
||||
- * MICHIGAN OF ANY KIND, EITHER EXPRESS OR IMPLIED, INCLUDING
|
||||
- * WITHOUT LIMITATION THE IMPLIED WARRANTIES OF
|
||||
- * MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. THE
|
||||
- * REGENTS OF THE UNIVERSITY OF MICHIGAN SHALL NOT BE LIABLE
|
||||
- * FOR ANY DAMAGES, INCLUDING SPECIAL, INDIRECT, INCIDENTAL, OR
|
||||
- * CONSEQUENTIAL DAMAGES, WITH RESPECT TO ANY CLAIM ARISING
|
||||
- * OUT OF OR IN CONNECTION WITH THE USE OF THE SOFTWARE, EVEN
|
||||
- * IF IT HAS BEEN OR IS HEREAFTER ADVISED OF THE POSSIBILITY OF
|
||||
- * SUCH DAMAGES.
|
||||
- */
|
||||
-
|
||||
-#ifndef _PKINIT_CRYPTO_OPENSSL_H
|
||||
-#define _PKINIT_CRYPTO_OPENSSL_H
|
||||
-
|
||||
-#include "pkinit.h"
|
||||
-
|
||||
-#include <openssl/bn.h>
|
||||
-#include <openssl/dh.h>
|
||||
-#include <openssl/x509.h>
|
||||
-#include <openssl/pkcs7.h>
|
||||
-#include <openssl/pkcs12.h>
|
||||
-#include <openssl/obj_mac.h>
|
||||
-#include <openssl/x509v3.h>
|
||||
-#include <openssl/err.h>
|
||||
-#include <openssl/evp.h>
|
||||
-#include <openssl/sha.h>
|
||||
-#include <openssl/asn1.h>
|
||||
-#include <openssl/pem.h>
|
||||
-#include <openssl/asn1t.h>
|
||||
-#include <openssl/cms.h>
|
||||
-#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||
-#include <openssl/core_names.h>
|
||||
-#include <openssl/decoder.h>
|
||||
-#endif
|
||||
-
|
||||
-#define DN_BUF_LEN 256
|
||||
-#define MAX_CREDS_ALLOWED 20
|
||||
-
|
||||
-struct _pkinit_cred_info {
|
||||
- char *name;
|
||||
- X509 *cert;
|
||||
- EVP_PKEY *key;
|
||||
-#ifndef WITHOUT_PKCS11
|
||||
- CK_BYTE_PTR cert_id;
|
||||
- int cert_id_len;
|
||||
-#endif
|
||||
-};
|
||||
-typedef struct _pkinit_cred_info * pkinit_cred_info;
|
||||
-
|
||||
-struct _pkinit_identity_crypto_context {
|
||||
- pkinit_cred_info creds[MAX_CREDS_ALLOWED+1];
|
||||
- STACK_OF(X509) *my_certs; /* available user certs */
|
||||
- char *identity; /* identity name for user cert */
|
||||
- int cert_index; /* cert to use out of available certs*/
|
||||
- EVP_PKEY *my_key; /* available user keys if in filesystem */
|
||||
- STACK_OF(X509) *trustedCAs; /* available trusted ca certs */
|
||||
- STACK_OF(X509) *intermediateCAs; /* available intermediate ca certs */
|
||||
- STACK_OF(X509_CRL) *revoked; /* available crls */
|
||||
- int pkcs11_method;
|
||||
- krb5_prompter_fct prompter;
|
||||
- void *prompter_data;
|
||||
-#ifndef WITHOUT_PKCS11
|
||||
- char *p11_module_name;
|
||||
- CK_SLOT_ID slotid;
|
||||
- char *token_label;
|
||||
- char *cert_label;
|
||||
- /* These are crypto-specific */
|
||||
- struct plugin_file_handle *p11_module;
|
||||
- CK_SESSION_HANDLE session;
|
||||
- CK_FUNCTION_LIST_PTR p11;
|
||||
- uint8_t *cert_id;
|
||||
- size_t cert_id_len;
|
||||
- CK_MECHANISM_TYPE mech;
|
||||
-#endif
|
||||
- krb5_boolean defer_id_prompt;
|
||||
- pkinit_deferred_id *deferred_ids;
|
||||
-};
|
||||
-
|
||||
-struct _pkinit_plg_crypto_context {
|
||||
- EVP_PKEY *dh_1024;
|
||||
- EVP_PKEY *dh_2048;
|
||||
- EVP_PKEY *dh_4096;
|
||||
- EVP_PKEY *ec_p256;
|
||||
- EVP_PKEY *ec_p384;
|
||||
- EVP_PKEY *ec_p521;
|
||||
- ASN1_OBJECT *id_pkinit_authData;
|
||||
- ASN1_OBJECT *id_pkinit_DHKeyData;
|
||||
- ASN1_OBJECT *id_pkinit_rkeyData;
|
||||
- ASN1_OBJECT *id_pkinit_san;
|
||||
- ASN1_OBJECT *id_ms_san_upn;
|
||||
- ASN1_OBJECT *id_pkinit_KPClientAuth;
|
||||
- ASN1_OBJECT *id_pkinit_KPKdc;
|
||||
- ASN1_OBJECT *id_ms_kp_sc_logon;
|
||||
- ASN1_OBJECT *id_kp_serverAuth;
|
||||
-};
|
||||
-
|
||||
-struct _pkinit_req_crypto_context {
|
||||
- X509 *received_cert;
|
||||
- EVP_PKEY *client_pkey;
|
||||
-};
|
||||
-
|
||||
-#endif /* _PKINIT_CRYPTO_OPENSSL_H */
|
||||
--
|
||||
2.47.1
|
||||
|
||||
157
0029-Use-SoftHSMv2-for-PKCS11-PKINIT-tests.patch
Normal file
157
0029-Use-SoftHSMv2-for-PKCS11-PKINIT-tests.patch
Normal file
|
|
@ -0,0 +1,157 @@
|
|||
From 1b01057df4c2223fbf92be44f1e764207208ef03 Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Mon, 26 Feb 2024 19:03:38 -0500
|
||||
Subject: [PATCH] Use SoftHSMv2 for PKCS11 PKINIT tests
|
||||
|
||||
Instead of softpkcs11, use SoftHSMv2 to mock the PKCS11 token for
|
||||
PKINIT tests. Use pkcs11-tool from OpenSC to initialize the token and
|
||||
import a certificate and key. SoftHSM does not support PIN-less
|
||||
tokens (see https://github.com/opendnssec/SoftHSMv2/issues/480) so
|
||||
remove that test for now.
|
||||
|
||||
(cherry picked from commit 8ab61608236883fdc5c2d43f4bd1ff2094401d19)
|
||||
---
|
||||
.github/workflows/build.yml | 2 +-
|
||||
src/tests/t_pkinit.py | 82 ++++++++++++++++++++-----------------
|
||||
2 files changed, 45 insertions(+), 39 deletions(-)
|
||||
|
||||
diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml
|
||||
index 68a4788adb..d7ae86b150 100644
|
||||
--- a/.github/workflows/build.yml
|
||||
+++ b/.github/workflows/build.yml
|
||||
@@ -33,7 +33,7 @@ jobs:
|
||||
if: startsWith(matrix.os, 'ubuntu')
|
||||
run: |
|
||||
sudo apt-get update -qq
|
||||
- sudo apt-get install -y bison gettext keyutils ldap-utils libcmocka-dev libldap2-dev libkeyutils-dev libsasl2-dev libssl-dev python3-kdcproxy python3-pip slapd tcsh
|
||||
+ sudo apt-get install -y bison gettext keyutils ldap-utils libcmocka-dev libldap2-dev libkeyutils-dev libsasl2-dev libssl-dev python3-kdcproxy python3-pip slapd tcsh softhsm2 opensc
|
||||
pip3 install pyrad
|
||||
- name: Build
|
||||
env:
|
||||
diff --git a/src/tests/t_pkinit.py b/src/tests/t_pkinit.py
|
||||
index f8f2debc1b..4435746429 100755
|
||||
--- a/src/tests/t_pkinit.py
|
||||
+++ b/src/tests/t_pkinit.py
|
||||
@@ -1,11 +1,10 @@
|
||||
from k5test import *
|
||||
+import re
|
||||
|
||||
# Skip this test if pkinit wasn't built.
|
||||
if not pkinit_enabled:
|
||||
skip_rest('PKINIT tests', 'PKINIT module not built')
|
||||
|
||||
-soft_pkcs11 = os.path.join(buildtop, 'tests', 'softpkcs11', 'softpkcs11.so')
|
||||
-
|
||||
# Construct a krb5.conf fragment configuring pkinit.
|
||||
user_pem = os.path.join(pkinit_certs, 'user.pem')
|
||||
privkey_pem = os.path.join(pkinit_certs, 'privkey.pem')
|
||||
@@ -55,9 +54,6 @@ p12_upn2_identity = 'PKCS12:%s' % user_upn2_p12
|
||||
p12_upn3_identity = 'PKCS12:%s' % user_upn3_p12
|
||||
p12_generic_identity = 'PKCS12:%s' % generic_p12
|
||||
p12_enc_identity = 'PKCS12:%s' % user_enc_p12
|
||||
-p11_identity = 'PKCS11:' + soft_pkcs11
|
||||
-p11_token_identity = ('PKCS11:module_name=' + soft_pkcs11 +
|
||||
- ':slotid=1:token=SoftToken (token)')
|
||||
|
||||
# Start a realm with the test kdb module for the following UPN SAN tests.
|
||||
realm = K5Realm(kdc_conf=alias_kdc_conf, create_kdb=False, pkinit=True)
|
||||
@@ -389,53 +385,63 @@ realm.klist(realm.user_princ)
|
||||
realm.kinit(realm.user_princ, flags=['-X', 'X509_user_identity=,'],
|
||||
expected_code=1, expected_msg='Preauthentication failed while')
|
||||
|
||||
-softpkcs11rc = os.path.join(os.getcwd(), 'testdir', 'soft-pkcs11.rc')
|
||||
-realm.env['SOFTPKCS11RC'] = softpkcs11rc
|
||||
+softhsm2 = '/usr/lib/softhsm/libsofthsm2.so'
|
||||
+if not os.path.exists(softhsm2):
|
||||
+ skip_rest('PKCS11 tests', 'SoftHSMv2 required')
|
||||
+pkcs11_tool = which('pkcs11-tool')
|
||||
+if not pkcs11_tool:
|
||||
+ skip_rest('PKCS11 tests', 'pkcs11-tool from OpenSC required')
|
||||
+tool_cmd = [pkcs11_tool, '--module', softhsm2]
|
||||
+
|
||||
+# Prepare a SoftHSM token.
|
||||
+softhsm2_conf = os.path.join(realm.testdir, 'softhsm2.conf')
|
||||
+softhsm2_tokens = os.path.join(realm.testdir, 'tokens')
|
||||
+os.mkdir(softhsm2_tokens)
|
||||
+realm.env['SOFTHSM2_CONF'] = softhsm2_conf
|
||||
+with open(softhsm2_conf, 'w') as f:
|
||||
+ f.write('directories.tokendir = %s\n' % softhsm2_tokens)
|
||||
+realm.run(tool_cmd + ['--init-token', '--label', 'user',
|
||||
+ '--so-pin', 'sopin', '--init-pin', '--pin', 'userpin'])
|
||||
+realm.run(tool_cmd + ['-w', user_pem, '-y', 'cert'])
|
||||
+realm.run(tool_cmd + ['-w', privkey_pem, '-y', 'privkey',
|
||||
+ '-l', '--pin', 'userpin'])
|
||||
+
|
||||
+# Extract the slot ID generated by SoftHSM.
|
||||
+out = realm.run(tool_cmd + ['-L'])
|
||||
+m = re.search(r'slot ID 0x([0-9a-f]+)\n', out)
|
||||
+if not m:
|
||||
+ fail('could not extract slot ID from SoftHSM token')
|
||||
+slot_id = int(m.group(1), 16)
|
||||
+
|
||||
+p11_attr = 'X509_user_identity=PKCS11:' + softhsm2
|
||||
+p11_token_identity = ('PKCS11:module_name=%s:slotid=%d:token=user' %
|
||||
+ (softhsm2, slot_id))
|
||||
|
||||
-# PKINIT with PKCS11: identity, with no need for a PIN.
|
||||
-mark('PKCS11 identity, no PIN')
|
||||
-conf = open(softpkcs11rc, 'w')
|
||||
-conf.write("%s\t%s\t%s\t%s\n" % ('user', 'user token', user_pem, privkey_pem))
|
||||
-conf.close()
|
||||
-# Expect to succeed without having to supply any more information.
|
||||
-realm.kinit(realm.user_princ,
|
||||
- flags=['-X', 'X509_user_identity=%s' % p11_identity])
|
||||
+mark('PKCS11 identity, with PIN (prompter)')
|
||||
+realm.kinit(realm.user_princ, flags=['-X', p11_attr], password='userpin')
|
||||
realm.klist(realm.user_princ)
|
||||
realm.run([kvno, realm.host_princ])
|
||||
|
||||
-# PKINIT with PKCS11: identity, with a PIN supplied by the prompter.
|
||||
-mark('PKCS11 identity, with PIN (prompter)')
|
||||
-os.remove(softpkcs11rc)
|
||||
-conf = open(softpkcs11rc, 'w')
|
||||
-conf.write("%s\t%s\t%s\t%s\n" % ('user', 'user token', user_pem,
|
||||
- privkey_enc_pem))
|
||||
-conf.close()
|
||||
-# Expect failure if the responder does nothing, and there's no prompter
|
||||
+mark('PKCS11 identity, unavailable PIN')
|
||||
realm.run(['./responder', '-x', 'pkinit={"%s": 0}' % p11_token_identity,
|
||||
- '-X', 'X509_user_identity=%s' % p11_identity, realm.user_princ],
|
||||
- expected_code=2)
|
||||
-realm.kinit(realm.user_princ,
|
||||
- flags=['-X', 'X509_user_identity=%s' % p11_identity],
|
||||
- password='encrypted')
|
||||
-realm.klist(realm.user_princ)
|
||||
-realm.run([kvno, realm.host_princ])
|
||||
+ '-X', p11_attr, realm.user_princ], expected_code=2)
|
||||
|
||||
-# Supply the wrong PIN.
|
||||
mark('PKCS11 identity, wrong PIN')
|
||||
expected_trace = ('PKINIT client has no configured identity; giving up',)
|
||||
realm.kinit(realm.user_princ,
|
||||
- flags=['-X', 'X509_user_identity=%s' % p11_identity],
|
||||
+ flags=['-X', p11_attr],
|
||||
password='wrong', expected_code=1, expected_trace=expected_trace)
|
||||
|
||||
# PKINIT with PKCS11: identity, with a PIN supplied by the responder.
|
||||
-# Supply the response in raw form.
|
||||
+# Supply the response in raw form. Expect the PIN_COUNT_LOW flag (1)
|
||||
+# to be set due to the previous test.
|
||||
mark('PKCS11 identity, with PIN (responder)')
|
||||
-realm.run(['./responder', '-x', 'pkinit={"%s": 0}' % p11_token_identity,
|
||||
- '-r', 'pkinit={"%s": "encrypted"}' % p11_token_identity,
|
||||
- '-X', 'X509_user_identity=%s' % p11_identity, realm.user_princ])
|
||||
+realm.run(['./responder', '-x', 'pkinit={"%s": 1}' % p11_token_identity,
|
||||
+ '-r', 'pkinit={"%s": "userpin"}' % p11_token_identity,
|
||||
+ '-X', p11_attr, realm.user_princ])
|
||||
# Supply the response through the convenience API.
|
||||
-realm.run(['./responder', '-X', 'X509_user_identity=%s' % p11_identity,
|
||||
- '-p', '%s=%s' % (p11_token_identity, 'encrypted'),
|
||||
+realm.run(['./responder', '-X', p11_attr,
|
||||
+ '-p', '%s=%s' % (p11_token_identity, 'userpin'),
|
||||
realm.user_princ])
|
||||
realm.klist(realm.user_princ)
|
||||
realm.run([kvno, realm.host_princ])
|
||||
--
|
||||
2.47.1
|
||||
|
||||
202
0030-Simplify-PKINIT-cert-representation.patch
Normal file
202
0030-Simplify-PKINIT-cert-representation.patch
Normal file
|
|
@ -0,0 +1,202 @@
|
|||
From b0315d30f066c4241fcecc33dd9e4d1c7c28b9d8 Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Fri, 9 Feb 2024 17:32:40 -0500
|
||||
Subject: [PATCH] Simplify PKINIT cert representation
|
||||
|
||||
In the _pkinit_identity_crypto_context structure, the my_certs field
|
||||
is a stack which only ever contains one cert and is only ever used to
|
||||
retrieve that one cert. The cert_index field is always 0. Replace
|
||||
these fields with a my_cert field pointing directly to the X509
|
||||
certificate.
|
||||
|
||||
Simplify crypto_cert_select_default() by making it call
|
||||
crypto_cert_select() with index 0 after verifying the certificate
|
||||
count.
|
||||
|
||||
(cherry picked from commit f95dfb7908456f9563cee66706216a21df8d791f)
|
||||
---
|
||||
.../preauth/pkinit/pkinit_crypto_openssl.c | 74 +++++--------------
|
||||
1 file changed, 20 insertions(+), 54 deletions(-)
|
||||
|
||||
diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c
|
||||
index ae8599d5a2..da59cb1e02 100644
|
||||
--- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c
|
||||
+++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c
|
||||
@@ -73,10 +73,9 @@ typedef struct _pkinit_cred_info *pkinit_cred_info;
|
||||
|
||||
struct _pkinit_identity_crypto_context {
|
||||
pkinit_cred_info creds[MAX_CREDS_ALLOWED+1];
|
||||
- STACK_OF(X509) *my_certs; /* available user certs */
|
||||
+ X509 *my_cert; /* selected user or KDC cert */
|
||||
char *identity; /* identity name for user cert */
|
||||
- int cert_index; /* cert to use out of available certs*/
|
||||
- EVP_PKEY *my_key; /* available user keys if in filesystem */
|
||||
+ EVP_PKEY *my_key; /* selected cert key if in filesystem */
|
||||
STACK_OF(X509) *trustedCAs; /* available trusted ca certs */
|
||||
STACK_OF(X509) *intermediateCAs; /* available intermediate ca certs */
|
||||
STACK_OF(X509_CRL) *revoked; /* available crls */
|
||||
@@ -1489,8 +1488,7 @@ pkinit_init_certs(pkinit_identity_crypto_context ctx)
|
||||
|
||||
for (i = 0; i < MAX_CREDS_ALLOWED; i++)
|
||||
ctx->creds[i] = NULL;
|
||||
- ctx->my_certs = NULL;
|
||||
- ctx->cert_index = 0;
|
||||
+ ctx->my_cert = NULL;
|
||||
ctx->my_key = NULL;
|
||||
ctx->trustedCAs = NULL;
|
||||
ctx->intermediateCAs = NULL;
|
||||
@@ -1506,8 +1504,8 @@ pkinit_fini_certs(pkinit_identity_crypto_context ctx)
|
||||
if (ctx == NULL)
|
||||
return;
|
||||
|
||||
- if (ctx->my_certs != NULL)
|
||||
- sk_X509_pop_free(ctx->my_certs, X509_free);
|
||||
+ if (ctx->my_cert != NULL)
|
||||
+ X509_free(ctx->my_cert);
|
||||
|
||||
if (ctx->my_key != NULL)
|
||||
EVP_PKEY_free(ctx->my_key);
|
||||
@@ -1696,7 +1694,6 @@ cms_signeddata_create(krb5_context context,
|
||||
ASN1_OCTET_STRING *digest = NULL;
|
||||
unsigned int alg_len = 0, digest_len = 0;
|
||||
unsigned char *y = NULL;
|
||||
- X509 *cert = NULL;
|
||||
ASN1_OBJECT *oid = NULL, *oid_copy;
|
||||
|
||||
/* Start creating PKCS7 data. */
|
||||
@@ -1715,7 +1712,7 @@ cms_signeddata_create(krb5_context context,
|
||||
if (oid == NULL)
|
||||
goto cleanup;
|
||||
|
||||
- if (id_cryptoctx->my_certs != NULL) {
|
||||
+ if (id_cryptoctx->my_cert != NULL) {
|
||||
X509_STORE *certstore = NULL;
|
||||
X509_STORE_CTX *certctx;
|
||||
STACK_OF(X509) *certstack = NULL;
|
||||
@@ -1726,8 +1723,6 @@ cms_signeddata_create(krb5_context context,
|
||||
if ((cert_stack = sk_X509_new_null()) == NULL)
|
||||
goto cleanup;
|
||||
|
||||
- cert = sk_X509_value(id_cryptoctx->my_certs, id_cryptoctx->cert_index);
|
||||
-
|
||||
certstore = X509_STORE_new();
|
||||
if (certstore == NULL)
|
||||
goto cleanup;
|
||||
@@ -1736,7 +1731,7 @@ cms_signeddata_create(krb5_context context,
|
||||
certctx = X509_STORE_CTX_new();
|
||||
if (certctx == NULL)
|
||||
goto cleanup;
|
||||
- X509_STORE_CTX_init(certctx, certstore, cert,
|
||||
+ X509_STORE_CTX_init(certctx, certstore, id_cryptoctx->my_cert,
|
||||
id_cryptoctx->intermediateCAs);
|
||||
X509_STORE_CTX_trusted_stack(certctx, id_cryptoctx->trustedCAs);
|
||||
if (!X509_verify_cert(certctx)) {
|
||||
@@ -1764,13 +1759,13 @@ cms_signeddata_create(krb5_context context,
|
||||
if (!ASN1_INTEGER_set(p7si->version, 1))
|
||||
goto cleanup;
|
||||
if (!X509_NAME_set(&p7si->issuer_and_serial->issuer,
|
||||
- X509_get_issuer_name(cert)))
|
||||
+ X509_get_issuer_name(id_cryptoctx->my_cert)))
|
||||
goto cleanup;
|
||||
/* because ASN1_INTEGER_set is used to set a 'long' we will do
|
||||
* things the ugly way. */
|
||||
ASN1_INTEGER_free(p7si->issuer_and_serial->serial);
|
||||
if (!(p7si->issuer_and_serial->serial =
|
||||
- ASN1_INTEGER_dup(X509_get_serialNumber(cert))))
|
||||
+ ASN1_INTEGER_dup(X509_get_serialNumber(id_cryptoctx->my_cert))))
|
||||
goto cleanup;
|
||||
|
||||
/* will not fill-out EVP_PKEY because it's on the smartcard */
|
||||
@@ -3311,7 +3306,7 @@ pkinit_check_kdc_pkid(krb5_context context,
|
||||
PKCS7_ISSUER_AND_SERIAL *is = NULL;
|
||||
const unsigned char *p = pdid_buf;
|
||||
int status = 1;
|
||||
- X509 *kdc_cert = sk_X509_value(id_cryptoctx->my_certs, id_cryptoctx->cert_index);
|
||||
+ X509 *kdc_cert = id_cryptoctx->my_cert;
|
||||
|
||||
*valid_kdcPkId = 0;
|
||||
pkiDebug("found kdcPkId in AS REQ\n");
|
||||
@@ -4783,7 +4778,8 @@ cleanup:
|
||||
}
|
||||
|
||||
/*
|
||||
- * Set the certificate in idctx->creds[cred_index] as the selected certificate.
|
||||
+ * Set the certificate in idctx->creds[cred_index] as the selected certificate,
|
||||
+ * stealing pointers from it.
|
||||
*/
|
||||
krb5_error_code
|
||||
crypto_cert_select(krb5_context context, pkinit_identity_crypto_context idctx,
|
||||
@@ -4795,20 +4791,17 @@ crypto_cert_select(krb5_context context, pkinit_identity_crypto_context idctx,
|
||||
return ENOENT;
|
||||
|
||||
ci = idctx->creds[cred_index];
|
||||
- /* copy the selected cert into our id_cryptoctx */
|
||||
- if (idctx->my_certs != NULL)
|
||||
- sk_X509_pop_free(idctx->my_certs, X509_free);
|
||||
- idctx->my_certs = sk_X509_new_null();
|
||||
- sk_X509_push(idctx->my_certs, ci->cert);
|
||||
- free(idctx->identity);
|
||||
+
|
||||
+ idctx->my_cert = ci->cert;
|
||||
+ ci->cert = NULL;
|
||||
+
|
||||
/* hang on to the selected credential name */
|
||||
+ free(idctx->identity);
|
||||
if (ci->name != NULL)
|
||||
idctx->identity = strdup(ci->name);
|
||||
else
|
||||
idctx->identity = NULL;
|
||||
|
||||
- ci->cert = NULL; /* Don't free it twice */
|
||||
- idctx->cert_index = 0;
|
||||
if (idctx->pkcs11_method != 1) {
|
||||
idctx->my_key = ci->key;
|
||||
ci->key = NULL; /* Don't free it twice */
|
||||
@@ -4837,41 +4830,14 @@ crypto_cert_select_default(krb5_context context,
|
||||
|
||||
retval = crypto_cert_get_count(id_cryptoctx, &cert_count);
|
||||
if (retval)
|
||||
- goto errout;
|
||||
+ return retval;
|
||||
|
||||
if (cert_count != 1) {
|
||||
TRACE_PKINIT_NO_DEFAULT_CERT(context, cert_count);
|
||||
- retval = EINVAL;
|
||||
- goto errout;
|
||||
- }
|
||||
- /* copy the selected cert into our id_cryptoctx */
|
||||
- if (id_cryptoctx->my_certs != NULL) {
|
||||
- sk_X509_pop_free(id_cryptoctx->my_certs, X509_free);
|
||||
+ return EINVAL;
|
||||
}
|
||||
- id_cryptoctx->my_certs = sk_X509_new_null();
|
||||
- sk_X509_push(id_cryptoctx->my_certs, id_cryptoctx->creds[0]->cert);
|
||||
- id_cryptoctx->creds[0]->cert = NULL; /* Don't free it twice */
|
||||
- id_cryptoctx->cert_index = 0;
|
||||
- /* hang on to the selected credential name */
|
||||
- if (id_cryptoctx->creds[0]->name != NULL)
|
||||
- id_cryptoctx->identity = strdup(id_cryptoctx->creds[0]->name);
|
||||
- else
|
||||
- id_cryptoctx->identity = NULL;
|
||||
|
||||
- if (id_cryptoctx->pkcs11_method != 1) {
|
||||
- id_cryptoctx->my_key = id_cryptoctx->creds[0]->key;
|
||||
- id_cryptoctx->creds[0]->key = NULL; /* Don't free it twice */
|
||||
- }
|
||||
-#ifndef WITHOUT_PKCS11
|
||||
- else {
|
||||
- id_cryptoctx->cert_id = id_cryptoctx->creds[0]->cert_id;
|
||||
- id_cryptoctx->creds[0]->cert_id = NULL; /* Don't free it twice */
|
||||
- id_cryptoctx->cert_id_len = id_cryptoctx->creds[0]->cert_id_len;
|
||||
- }
|
||||
-#endif
|
||||
- retval = 0;
|
||||
-errout:
|
||||
- return retval;
|
||||
+ return crypto_cert_select(context, id_cryptoctx, 0);
|
||||
}
|
||||
|
||||
|
||||
--
|
||||
2.47.1
|
||||
|
||||
1768
0031-Support-PKCS11-EC-client-certs-in-PKINIT.patch
Normal file
1768
0031-Support-PKCS11-EC-client-certs-in-PKINIT.patch
Normal file
File diff suppressed because it is too large
Load diff
599
0032-Improve-PKCS11-error-reporting-in-PKINIT.patch
Normal file
599
0032-Improve-PKCS11-error-reporting-in-PKINIT.patch
Normal file
|
|
@ -0,0 +1,599 @@
|
|||
From e43c05e7b0b93401dd68fc3ec3186c3a455b04ea Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Fri, 23 Feb 2024 13:51:26 -0500
|
||||
Subject: [PATCH] Improve PKCS11 error reporting in PKINIT
|
||||
|
||||
Create a helper p11err() to set extended error message for failed
|
||||
PKCS11 operations, and use it instead of pkiDebug() and pkcs11error().
|
||||
|
||||
ticket: 9113 (new)
|
||||
(cherry picked from commit 98afb314d13939cbee19c69885dcb655db8460da)
|
||||
---
|
||||
.../preauth/pkinit/pkinit_crypto_openssl.c | 262 ++++++++++--------
|
||||
src/plugins/preauth/pkinit/pkinit_trace.h | 9 -
|
||||
2 files changed, 142 insertions(+), 129 deletions(-)
|
||||
|
||||
diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c
|
||||
index 4accfc2664..402bf1b9b3 100644
|
||||
--- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c
|
||||
+++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c
|
||||
@@ -161,9 +161,11 @@ static krb5_error_code pkinit_create_sequence_of_principal_identifiers
|
||||
int type, krb5_pa_data ***e_data_out);
|
||||
|
||||
#ifndef WITHOUT_PKCS11
|
||||
-static krb5_error_code pkinit_find_private_key
|
||||
-(pkinit_identity_crypto_context, CK_ATTRIBUTE_TYPE usage,
|
||||
- CK_OBJECT_HANDLE *objp);
|
||||
+static krb5_error_code
|
||||
+pkinit_find_private_key(krb5_context context,
|
||||
+ pkinit_identity_crypto_context id_cryptoctx,
|
||||
+ CK_ATTRIBUTE_TYPE usage,
|
||||
+ CK_OBJECT_HANDLE *objp);
|
||||
static krb5_error_code pkinit_login
|
||||
(krb5_context context, pkinit_identity_crypto_context id_cryptoctx,
|
||||
CK_TOKEN_INFO *tip, const char *password);
|
||||
@@ -180,6 +182,8 @@ static krb5_error_code pkinit_sign_data_pkcs11
|
||||
(krb5_context context, pkinit_identity_crypto_context id_cryptoctx,
|
||||
unsigned char *data, unsigned int data_len,
|
||||
unsigned char **sig, unsigned int *sig_len);
|
||||
+
|
||||
+static krb5_error_code p11err(krb5_context context, CK_RV rv, const char *op);
|
||||
#endif /* WITHOUT_PKCS11 */
|
||||
|
||||
static krb5_error_code pkinit_sign_data_fs
|
||||
@@ -197,9 +201,6 @@ create_krb5_invalidCertificates(krb5_context context,
|
||||
static krb5_error_code
|
||||
create_identifiers_from_stack(STACK_OF(X509) *sk,
|
||||
krb5_external_principal_identifier *** ids);
|
||||
-static const char *
|
||||
-pkcs11err(int err);
|
||||
-
|
||||
|
||||
#if OPENSSL_VERSION_NUMBER < 0x10100000L
|
||||
|
||||
@@ -944,8 +945,9 @@ cleanup:
|
||||
|
||||
#endif /* OPENSSL_VERSION_NUMBER < 0x30000000L */
|
||||
|
||||
+#ifndef WITHOUT_PKC11
|
||||
static struct pkcs11_errstrings {
|
||||
- short code;
|
||||
+ CK_RV code;
|
||||
char *text;
|
||||
} pkcs11_errstrings[] = {
|
||||
{ 0x0, "ok" },
|
||||
@@ -1035,6 +1037,7 @@ static struct pkcs11_errstrings {
|
||||
{ 0x200, "function rejected" },
|
||||
{ -1, NULL }
|
||||
};
|
||||
+#endif
|
||||
|
||||
MAKE_INIT_FUNCTION(pkinit_openssl_init);
|
||||
|
||||
@@ -1563,6 +1566,8 @@ pkinit_fini_pkcs11(pkinit_identity_crypto_context ctx)
|
||||
free(ctx->token_label);
|
||||
free(ctx->cert_id);
|
||||
free(ctx->cert_label);
|
||||
+ ctx->p11_module_name = ctx->token_label = ctx->cert_label = NULL;
|
||||
+ ctx->cert_id = NULL;
|
||||
#endif
|
||||
}
|
||||
|
||||
@@ -3344,48 +3349,53 @@ pkinit_pkcs7type2oid(pkinit_plg_crypto_context cryptoctx, int pkcs7_type)
|
||||
}
|
||||
|
||||
#ifndef WITHOUT_PKCS11
|
||||
-static struct plugin_file_handle *
|
||||
+static krb5_error_code
|
||||
load_pkcs11_module(krb5_context context, const char *modname,
|
||||
- CK_FUNCTION_LIST_PTR_PTR p11p)
|
||||
+ struct plugin_file_handle **handle_out,
|
||||
+ CK_FUNCTION_LIST_PTR_PTR p11_out)
|
||||
{
|
||||
struct plugin_file_handle *handle = NULL;
|
||||
- CK_RV (*getflist)(CK_FUNCTION_LIST_PTR_PTR);
|
||||
+ CK_RV rv, (*getflist)(CK_FUNCTION_LIST_PTR_PTR);
|
||||
struct errinfo einfo = EMPTY_ERRINFO;
|
||||
- const char *errmsg = NULL;
|
||||
+ const char *errmsg = NULL, *failure;
|
||||
void (*sym)(void);
|
||||
long err;
|
||||
- CK_RV rv;
|
||||
|
||||
TRACE_PKINIT_PKCS11_OPEN(context, modname);
|
||||
err = krb5int_open_plugin(modname, &handle, &einfo);
|
||||
if (err) {
|
||||
- errmsg = k5_get_error(&einfo, err);
|
||||
- TRACE_PKINIT_PKCS11_OPEN_FAILED(context, errmsg);
|
||||
+ failure = _("Cannot load PKCS11 module");
|
||||
goto error;
|
||||
}
|
||||
|
||||
err = krb5int_get_plugin_func(handle, "C_GetFunctionList", &sym, &einfo);
|
||||
if (err) {
|
||||
- errmsg = k5_get_error(&einfo, err);
|
||||
- TRACE_PKINIT_PKCS11_GETSYM_FAILED(context, errmsg);
|
||||
+ failure = _("Cannot find C_GetFunctionList in PKCS11 module");
|
||||
goto error;
|
||||
}
|
||||
|
||||
getflist = (CK_RV (*)(CK_FUNCTION_LIST_PTR_PTR))sym;
|
||||
- rv = (*getflist)(p11p);
|
||||
+ rv = (*getflist)(p11_out);
|
||||
if (rv != CKR_OK) {
|
||||
- TRACE_PKINIT_PKCS11_GETFLIST_FAILED(context, pkcs11err(rv));
|
||||
+ failure = _("Cannot retrieve function list in PKCS11 module");
|
||||
goto error;
|
||||
}
|
||||
|
||||
- return handle;
|
||||
+ *handle_out = handle;
|
||||
+ return 0;
|
||||
|
||||
error:
|
||||
- k5_free_error(&einfo, errmsg);
|
||||
+ if (err) {
|
||||
+ errmsg = k5_get_error(&einfo, err);
|
||||
+ k5_setmsg(context, err, _("%s: %s"), failure, errmsg);
|
||||
+ } else {
|
||||
+ err = KRB5KDC_ERR_PREAUTH_FAILED;
|
||||
+ k5_setmsg(context, err, "%s", failure);
|
||||
+ }
|
||||
k5_clear_error(&einfo);
|
||||
if (handle != NULL)
|
||||
krb5int_close_plugin(handle);
|
||||
- return NULL;
|
||||
+ return err;
|
||||
}
|
||||
|
||||
static krb5_error_code
|
||||
@@ -3393,12 +3403,13 @@ pkinit_login(krb5_context context,
|
||||
pkinit_identity_crypto_context id_cryptoctx,
|
||||
CK_TOKEN_INFO *tip, const char *password)
|
||||
{
|
||||
+ krb5_error_code ret = 0;
|
||||
+ CK_RV rv;
|
||||
krb5_data rdat;
|
||||
char *prompt;
|
||||
const char *warning;
|
||||
krb5_prompt kprompt;
|
||||
krb5_prompt_type prompt_type;
|
||||
- int r = 0;
|
||||
|
||||
if (tip->flags & CKF_PROTECTED_AUTHENTICATION_PATH) {
|
||||
rdat.data = NULL;
|
||||
@@ -3407,7 +3418,7 @@ pkinit_login(krb5_context context,
|
||||
rdat.data = strdup(password);
|
||||
rdat.length = strlen(password);
|
||||
} else if (id_cryptoctx->prompter == NULL) {
|
||||
- r = KRB5_LIBOS_CANTREADPWD;
|
||||
+ ret = KRB5_LIBOS_CANTREADPWD;
|
||||
rdat.data = NULL;
|
||||
} else {
|
||||
if (tip->flags & CKF_USER_PIN_LOCKED)
|
||||
@@ -3431,31 +3442,28 @@ pkinit_login(krb5_context context,
|
||||
|
||||
/* PROMPTER_INVOCATION */
|
||||
k5int_set_prompt_types(context, &prompt_type);
|
||||
- r = (*id_cryptoctx->prompter)(context, id_cryptoctx->prompter_data,
|
||||
- NULL, NULL, 1, &kprompt);
|
||||
+ ret = (*id_cryptoctx->prompter)(context, id_cryptoctx->prompter_data,
|
||||
+ NULL, NULL, 1, &kprompt);
|
||||
k5int_set_prompt_types(context, 0);
|
||||
free(prompt);
|
||||
}
|
||||
|
||||
- if (r == 0) {
|
||||
- r = id_cryptoctx->p11->C_Login(id_cryptoctx->session, CKU_USER,
|
||||
- (u_char *) rdat.data, rdat.length);
|
||||
-
|
||||
- if (r != CKR_OK) {
|
||||
- TRACE_PKINIT_PKCS11_LOGIN_FAILED(context, pkcs11err(r));
|
||||
- r = KRB5KDC_ERR_PREAUTH_FAILED;
|
||||
- }
|
||||
+ if (!ret) {
|
||||
+ rv = id_cryptoctx->p11->C_Login(id_cryptoctx->session, CKU_USER,
|
||||
+ (uint8_t *)rdat.data, rdat.length);
|
||||
+ if (rv != CKR_OK)
|
||||
+ ret = p11err(context, rv, "C_Login");
|
||||
}
|
||||
free(rdat.data);
|
||||
|
||||
- return r;
|
||||
+ return ret;
|
||||
}
|
||||
|
||||
static krb5_error_code
|
||||
pkinit_open_session(krb5_context context,
|
||||
pkinit_identity_crypto_context cctx)
|
||||
{
|
||||
- CK_ULONG i, pret;
|
||||
+ CK_ULONG i, rv;
|
||||
unsigned char *cp;
|
||||
size_t label_len;
|
||||
CK_ULONG count = 0;
|
||||
@@ -3469,30 +3477,35 @@ pkinit_open_session(krb5_context context,
|
||||
return 0; /* session already open */
|
||||
|
||||
/* Load module */
|
||||
- cctx->p11_module = load_pkcs11_module(context, cctx->p11_module_name,
|
||||
- &cctx->p11);
|
||||
- if (cctx->p11_module == NULL)
|
||||
- return KRB5KDC_ERR_PREAUTH_FAILED;
|
||||
+ ret = load_pkcs11_module(context, cctx->p11_module_name, &cctx->p11_module,
|
||||
+ &cctx->p11);
|
||||
+ if (ret)
|
||||
+ goto cleanup;
|
||||
|
||||
/* Init */
|
||||
- pret = cctx->p11->C_Initialize(NULL);
|
||||
- if (pret != CKR_OK) {
|
||||
- pkiDebug("C_Initialize: %s\n", pkcs11err(pret));
|
||||
- return KRB5KDC_ERR_PREAUTH_FAILED;
|
||||
+ rv = cctx->p11->C_Initialize(NULL);
|
||||
+ if (rv != CKR_OK) {
|
||||
+ ret = p11err(context, rv, "C_Initialize");
|
||||
+ goto cleanup;
|
||||
}
|
||||
|
||||
/* Get the list of available slots */
|
||||
- if (cctx->p11->C_GetSlotList(TRUE, NULL, &count) != CKR_OK)
|
||||
- return KRB5KDC_ERR_PREAUTH_FAILED;
|
||||
+ rv = cctx->p11->C_GetSlotList(TRUE, NULL, &count);
|
||||
+ if (rv != CKR_OK) {
|
||||
+ ret = p11err(context, rv, "C_GetSlotList");
|
||||
+ goto cleanup;
|
||||
+ }
|
||||
if (count == 0) {
|
||||
TRACE_PKINIT_PKCS11_NO_TOKEN(context);
|
||||
- return KRB5KDC_ERR_PREAUTH_FAILED;
|
||||
+ ret = KRB5KDC_ERR_PREAUTH_FAILED;
|
||||
+ goto cleanup;
|
||||
}
|
||||
- slotlist = calloc(count, sizeof(CK_SLOT_ID));
|
||||
+ slotlist = k5calloc(count, sizeof(CK_SLOT_ID), &ret);
|
||||
if (slotlist == NULL)
|
||||
- return ENOMEM;
|
||||
- if (cctx->p11->C_GetSlotList(TRUE, slotlist, &count) != CKR_OK) {
|
||||
- ret = KRB5KDC_ERR_PREAUTH_FAILED;
|
||||
+ goto cleanup;
|
||||
+ rv = cctx->p11->C_GetSlotList(TRUE, slotlist, &count);
|
||||
+ if (rv != CKR_OK) {
|
||||
+ ret = p11err(context, rv, "C_GetSlotList");
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
@@ -3503,19 +3516,17 @@ pkinit_open_session(krb5_context context,
|
||||
continue;
|
||||
|
||||
/* Open session */
|
||||
- pret = cctx->p11->C_OpenSession(slotlist[i], CKF_SERIAL_SESSION,
|
||||
- NULL, NULL, &cctx->session);
|
||||
- if (pret != CKR_OK) {
|
||||
- pkiDebug("C_OpenSession: %s\n", pkcs11err(pret));
|
||||
- ret = KRB5KDC_ERR_PREAUTH_FAILED;
|
||||
+ rv = cctx->p11->C_OpenSession(slotlist[i], CKF_SERIAL_SESSION,
|
||||
+ NULL, NULL, &cctx->session);
|
||||
+ if (rv != CKR_OK) {
|
||||
+ ret = p11err(context, rv, "C_OpenSession");
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
/* Get token info */
|
||||
- pret = cctx->p11->C_GetTokenInfo(slotlist[i], &tinfo);
|
||||
- if (pret != CKR_OK) {
|
||||
- pkiDebug("C_GetTokenInfo: %s\n", pkcs11err(pret));
|
||||
- ret = KRB5KDC_ERR_PREAUTH_FAILED;
|
||||
+ rv = cctx->p11->C_GetTokenInfo(slotlist[i], &tinfo);
|
||||
+ if (rv != CKR_OK) {
|
||||
+ ret = p11err(context, rv, "C_GetTokenInfo");
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
@@ -3577,6 +3588,10 @@ pkinit_open_session(krb5_context context,
|
||||
|
||||
ret = 0;
|
||||
cleanup:
|
||||
+ /* On error, finalize the PKCS11 fields to ensure that we don't mistakenly
|
||||
+ * short-circuit with success on the next call. */
|
||||
+ if (ret)
|
||||
+ pkinit_fini_pkcs11(cctx);
|
||||
free(slotlist);
|
||||
free(p11name);
|
||||
return ret;
|
||||
@@ -3598,16 +3613,17 @@ cleanup:
|
||||
* If there are more than one, we just take the first one.
|
||||
*/
|
||||
|
||||
-krb5_error_code
|
||||
-pkinit_find_private_key(pkinit_identity_crypto_context id_cryptoctx,
|
||||
+static krb5_error_code
|
||||
+pkinit_find_private_key(krb5_context context,
|
||||
+ pkinit_identity_crypto_context id_cryptoctx,
|
||||
CK_ATTRIBUTE_TYPE usage,
|
||||
CK_OBJECT_HANDLE *objp)
|
||||
{
|
||||
CK_OBJECT_CLASS cls;
|
||||
CK_ATTRIBUTE attrs[4];
|
||||
CK_ULONG count;
|
||||
+ CK_RV rv;
|
||||
unsigned int nattrs = 0;
|
||||
- int r;
|
||||
#ifdef PKINIT_USE_KEY_USAGE
|
||||
CK_BBOOL true_false;
|
||||
#endif
|
||||
@@ -3637,18 +3653,21 @@ pkinit_find_private_key(pkinit_identity_crypto_context id_cryptoctx,
|
||||
attrs[nattrs].ulValueLen = id_cryptoctx->cert_id_len;
|
||||
nattrs++;
|
||||
|
||||
- r = id_cryptoctx->p11->C_FindObjectsInit(id_cryptoctx->session, attrs, nattrs);
|
||||
- if (r != CKR_OK) {
|
||||
- pkiDebug("krb5_pkinit_sign_data: C_FindObjectsInit: %s\n",
|
||||
- pkcs11err(r));
|
||||
- return KRB5KDC_ERR_PREAUTH_FAILED;
|
||||
- }
|
||||
+ rv = id_cryptoctx->p11->C_FindObjectsInit(id_cryptoctx->session, attrs,
|
||||
+ nattrs);
|
||||
+ if (rv != CKR_OK)
|
||||
+ return p11err(context, rv, _("C_FindObjectsInit"));
|
||||
|
||||
- r = id_cryptoctx->p11->C_FindObjects(id_cryptoctx->session, objp, 1, &count);
|
||||
+ rv = id_cryptoctx->p11->C_FindObjects(id_cryptoctx->session, objp, 1,
|
||||
+ &count);
|
||||
id_cryptoctx->p11->C_FindObjectsFinal(id_cryptoctx->session);
|
||||
- pkiDebug("found %d private keys (%s)\n", (int)count, pkcs11err(r));
|
||||
- if (r != CKR_OK || count < 1)
|
||||
+ if (rv != CKR_OK)
|
||||
+ return p11err(context, rv, _("C_FindObjects"));
|
||||
+ if (count < 1) {
|
||||
+ k5_setmsg(context, KRB5KDC_ERR_PREAUTH_FAILED,
|
||||
+ _("Found no private keys in PKCS11 token"));
|
||||
return KRB5KDC_ERR_PREAUTH_FAILED;
|
||||
+ }
|
||||
return 0;
|
||||
}
|
||||
#endif
|
||||
@@ -3796,34 +3815,32 @@ pkinit_sign_data_pkcs11(krb5_context context,
|
||||
CK_FUNCTION_LIST_PTR p11;
|
||||
CK_ATTRIBUTE attr;
|
||||
CK_KEY_TYPE keytype;
|
||||
+ CK_RV rv;
|
||||
EVP_MD_CTX *ctx;
|
||||
const EVP_MD *md = EVP_sha256();
|
||||
unsigned int mdlen;
|
||||
uint8_t mdbuf[EVP_MAX_MD_SIZE], *dinfo = NULL, *sigbuf = NULL, *input;
|
||||
size_t dinfo_len, input_len;
|
||||
- int r;
|
||||
|
||||
*sig = NULL;
|
||||
*sig_len = 0;
|
||||
|
||||
- if (pkinit_open_session(context, id_cryptoctx)) {
|
||||
- pkiDebug("can't open pkcs11 session\n");
|
||||
- return KRB5KDC_ERR_PREAUTH_FAILED;
|
||||
- }
|
||||
+ ret = pkinit_open_session(context, id_cryptoctx);
|
||||
+ if (ret)
|
||||
+ return ret;
|
||||
p11 = id_cryptoctx->p11;
|
||||
session = id_cryptoctx->session;
|
||||
|
||||
- ret = pkinit_find_private_key(id_cryptoctx, CKA_SIGN, &obj);
|
||||
+ ret = pkinit_find_private_key(context, id_cryptoctx, CKA_SIGN, &obj);
|
||||
if (ret)
|
||||
return ret;
|
||||
|
||||
attr.type = CKA_KEY_TYPE;
|
||||
attr.pValue = &keytype;
|
||||
attr.ulValueLen = sizeof(keytype);
|
||||
- r = p11->C_GetAttributeValue(session, obj, &attr, 1);
|
||||
- if (r) {
|
||||
- pkiDebug("C_GetAttributeValue: %s\n", pkcs11err(r));
|
||||
- ret = KRB5KDC_ERR_PREAUTH_FAILED;
|
||||
+ rv = p11->C_GetAttributeValue(session, obj, &attr, 1);
|
||||
+ if (rv != CKR_OK) {
|
||||
+ ret = p11err(context, rv, "C_GetAttributeValue");
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
@@ -3865,10 +3882,9 @@ pkinit_sign_data_pkcs11(krb5_context context,
|
||||
mech.pParameter = NULL;
|
||||
mech.ulParameterLen = 0;
|
||||
|
||||
- r = p11->C_SignInit(session, &mech, obj);
|
||||
- if (r != CKR_OK) {
|
||||
- pkiDebug("C_SignInit: %s\n", pkcs11err(r));
|
||||
- ret = KRB5KDC_ERR_PREAUTH_FAILED;
|
||||
+ rv = p11->C_SignInit(session, &mech, obj);
|
||||
+ if (rv != CKR_OK) {
|
||||
+ ret = p11err(context, rv, "C_SignInit");
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
@@ -3881,18 +3897,17 @@ pkinit_sign_data_pkcs11(krb5_context context,
|
||||
if (sigbuf == NULL)
|
||||
goto cleanup;
|
||||
|
||||
- r = p11->C_Sign(session, input, input_len, sigbuf, &len);
|
||||
- if (r == CKR_BUFFER_TOO_SMALL || (r == CKR_OK && len >= PK_SIGLEN_GUESS)) {
|
||||
+ rv = p11->C_Sign(session, input, input_len, sigbuf, &len);
|
||||
+ if (rv == CKR_BUFFER_TOO_SMALL ||
|
||||
+ (rv == CKR_OK && len >= PK_SIGLEN_GUESS)) {
|
||||
free(sigbuf);
|
||||
- pkiDebug("C_Sign realloc %d\n", (int) len);
|
||||
sigbuf = k5alloc(len, &ret);
|
||||
if (sigbuf == NULL)
|
||||
goto cleanup;
|
||||
- r = p11->C_Sign(session, input, input_len, sigbuf, &len);
|
||||
+ rv = p11->C_Sign(session, input, input_len, sigbuf, &len);
|
||||
}
|
||||
- if (r != CKR_OK) {
|
||||
- pkiDebug("C_Sign: %s\n", pkcs11err(r));
|
||||
- ret = KRB5KDC_ERR_PREAUTH_FAILED;
|
||||
+ if (rv != CKR_OK) {
|
||||
+ ret = p11err(context, rv, "C_Sign");
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
@@ -4348,13 +4363,14 @@ reassemble_pkcs11_name(pkinit_identity_opts *idopts)
|
||||
}
|
||||
|
||||
static krb5_error_code
|
||||
-load_one_cert(CK_FUNCTION_LIST_PTR p11, CK_SESSION_HANDLE session,
|
||||
- pkinit_identity_opts *idopts, pkinit_cred_info *cred_out)
|
||||
+load_one_cert(krb5_context context, CK_FUNCTION_LIST_PTR p11,
|
||||
+ CK_SESSION_HANDLE session, pkinit_identity_opts *idopts,
|
||||
+ pkinit_cred_info *cred_out)
|
||||
{
|
||||
krb5_error_code ret;
|
||||
CK_ATTRIBUTE attrs[2];
|
||||
CK_BYTE_PTR cert = NULL, cert_id = NULL;
|
||||
- CK_RV pret;
|
||||
+ CK_RV rv;
|
||||
const unsigned char *cp;
|
||||
CK_OBJECT_HANDLE obj;
|
||||
CK_ULONG count;
|
||||
@@ -4364,8 +4380,8 @@ load_one_cert(CK_FUNCTION_LIST_PTR p11, CK_SESSION_HANDLE session,
|
||||
*cred_out = NULL;
|
||||
|
||||
/* Look for X.509 cert. */
|
||||
- pret = p11->C_FindObjects(session, &obj, 1, &count);
|
||||
- if (pret != CKR_OK || count <= 0)
|
||||
+ rv = p11->C_FindObjects(session, &obj, 1, &count);
|
||||
+ if (rv != CKR_OK || count <= 0)
|
||||
return 0;
|
||||
|
||||
/* Get cert and id len. */
|
||||
@@ -4375,10 +4391,9 @@ load_one_cert(CK_FUNCTION_LIST_PTR p11, CK_SESSION_HANDLE session,
|
||||
attrs[1].type = CKA_ID;
|
||||
attrs[1].pValue = NULL;
|
||||
attrs[1].ulValueLen = 0;
|
||||
- pret = p11->C_GetAttributeValue(session, obj, attrs, 2);
|
||||
- if (pret != CKR_OK && pret != CKR_BUFFER_TOO_SMALL) {
|
||||
- pkiDebug("C_GetAttributeValue: %s\n", pkcs11err(pret));
|
||||
- ret = KRB5KDC_ERR_PREAUTH_FAILED;
|
||||
+ rv = p11->C_GetAttributeValue(session, obj, attrs, 2);
|
||||
+ if (rv != CKR_OK && rv != CKR_BUFFER_TOO_SMALL) {
|
||||
+ ret = p11err(context, rv, "C_GetAttributeValue");
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
@@ -4393,10 +4408,9 @@ load_one_cert(CK_FUNCTION_LIST_PTR p11, CK_SESSION_HANDLE session,
|
||||
attrs[0].pValue = cert;
|
||||
attrs[1].type = CKA_ID;
|
||||
attrs[1].pValue = cert_id;
|
||||
- pret = p11->C_GetAttributeValue(session, obj, attrs, 2);
|
||||
- if (pret != CKR_OK) {
|
||||
- pkiDebug("C_GetAttributeValue: %s\n", pkcs11err(pret));
|
||||
- ret = KRB5KDC_ERR_PREAUTH_FAILED;
|
||||
+ rv = p11->C_GetAttributeValue(session, obj, attrs, 2);
|
||||
+ if (rv != CKR_OK) {
|
||||
+ ret = p11err(context, rv, "C_GetAttributeValue");
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
@@ -4406,7 +4420,8 @@ load_one_cert(CK_FUNCTION_LIST_PTR p11, CK_SESSION_HANDLE session,
|
||||
cp = (unsigned char *)cert;
|
||||
x = d2i_X509(NULL, &cp, (int)attrs[0].ulValueLen);
|
||||
if (x == NULL) {
|
||||
- ret = KRB5KDC_ERR_PREAUTH_FAILED;
|
||||
+ ret = oerr(context, 0,
|
||||
+ _("Failed to decode X509 certificate from PKCS11 token"));
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
@@ -4444,7 +4459,7 @@ pkinit_get_certs_pkcs11(krb5_context context,
|
||||
int i;
|
||||
unsigned int nattrs;
|
||||
krb5_error_code ret;
|
||||
- CK_RV pret;
|
||||
+ CK_RV rv;
|
||||
|
||||
/* Copy stuff from idopts -> id_cryptoctx */
|
||||
if (idopts->p11_module_name != NULL) {
|
||||
@@ -4516,16 +4531,16 @@ pkinit_get_certs_pkcs11(krb5_context context,
|
||||
nattrs++;
|
||||
}
|
||||
|
||||
- pret = id_cryptoctx->p11->C_FindObjectsInit(id_cryptoctx->session, attrs,
|
||||
- nattrs);
|
||||
- if (pret != CKR_OK) {
|
||||
- pkiDebug("C_FindObjectsInit: %s\n", pkcs11err(pret));
|
||||
+ rv = id_cryptoctx->p11->C_FindObjectsInit(id_cryptoctx->session, attrs,
|
||||
+ nattrs);
|
||||
+ if (rv != CKR_OK) {
|
||||
+ ret = p11err(context, rv, "C_FindObjectsInit");
|
||||
return KRB5KDC_ERR_PREAUTH_FAILED;
|
||||
}
|
||||
|
||||
for (i = 0; i < MAX_CREDS_ALLOWED; i++) {
|
||||
- ret = load_one_cert(id_cryptoctx->p11, id_cryptoctx->session, idopts,
|
||||
- &id_cryptoctx->creds[i]);
|
||||
+ ret = load_one_cert(context, id_cryptoctx->p11, id_cryptoctx->session,
|
||||
+ idopts, &id_cryptoctx->creds[i]);
|
||||
if (ret)
|
||||
return ret;
|
||||
if (id_cryptoctx->creds[i] == NULL)
|
||||
@@ -5510,19 +5525,26 @@ print_pubkey(BIGNUM * key, char *msg)
|
||||
}
|
||||
#endif
|
||||
|
||||
-static const char *
|
||||
-pkcs11err(int err)
|
||||
+#ifndef WITHOUT_PKCS11
|
||||
+static krb5_error_code
|
||||
+p11err(krb5_context context, CK_RV rv, const char *op)
|
||||
{
|
||||
+ krb5_error_code code = KRB5KDC_ERR_PREAUTH_FAILED;
|
||||
int i;
|
||||
+ const char *msg;
|
||||
|
||||
- for (i = 0; pkcs11_errstrings[i].text != NULL; i++)
|
||||
- if (pkcs11_errstrings[i].code == err)
|
||||
+ for (i = 0; pkcs11_errstrings[i].text != NULL; i++) {
|
||||
+ if (pkcs11_errstrings[i].code == rv)
|
||||
break;
|
||||
- if (pkcs11_errstrings[i].text != NULL)
|
||||
- return (pkcs11_errstrings[i].text);
|
||||
+ }
|
||||
+ msg = pkcs11_errstrings[i].text;
|
||||
+ if (msg == NULL)
|
||||
+ msg = "unknown PKCS11 error";
|
||||
|
||||
- return "unknown PKCS11 error";
|
||||
+ krb5_set_error_message(context, code, _("PKCS11 error (%s): %s"), op, msg);
|
||||
+ return code;
|
||||
}
|
||||
+#endif
|
||||
|
||||
/*
|
||||
* Add an item to the pkinit_identity_crypto_context's list of deferred
|
||||
diff --git a/src/plugins/preauth/pkinit/pkinit_trace.h b/src/plugins/preauth/pkinit/pkinit_trace.h
|
||||
index 1c1ceb5a41..1faa6816d7 100644
|
||||
--- a/src/plugins/preauth/pkinit/pkinit_trace.h
|
||||
+++ b/src/plugins/preauth/pkinit/pkinit_trace.h
|
||||
@@ -98,21 +98,12 @@
|
||||
#define TRACE_PKINIT_OPENSSL_ERROR(c, msg) \
|
||||
TRACE(c, "PKINIT OpenSSL error: {str}", msg)
|
||||
|
||||
-#define TRACE_PKINIT_PKCS11_GETFLIST_FAILED(c, errstr) \
|
||||
- TRACE(c, "PKINIT PKCS11 C_GetFunctionList failed: {str}", errstr)
|
||||
-#define TRACE_PKINIT_PKCS11_GETSYM_FAILED(c, errstr) \
|
||||
- TRACE(c, "PKINIT unable to find PKCS11 plugin symbol " \
|
||||
- "C_GetFunctionList: {str}", errstr)
|
||||
-#define TRACE_PKINIT_PKCS11_LOGIN_FAILED(c, errstr) \
|
||||
- TRACE(c, "PKINIT PKCS11 C_Login failed: {str}", errstr)
|
||||
#define TRACE_PKINIT_PKCS11_NO_MATCH_TOKEN(c) \
|
||||
TRACE(c, "PKINIT PKCS#11 module has no matching tokens")
|
||||
#define TRACE_PKINIT_PKCS11_NO_TOKEN(c) \
|
||||
TRACE(c, "PKINIT PKCS#11 module shows no slots with tokens")
|
||||
#define TRACE_PKINIT_PKCS11_OPEN(c, name) \
|
||||
TRACE(c, "PKINIT opening PKCS#11 module \"{str}\"", name)
|
||||
-#define TRACE_PKINIT_PKCS11_OPEN_FAILED(c, errstr) \
|
||||
- TRACE(c, "PKINIT PKCS#11 module open failed: {str}", errstr)
|
||||
#define TRACE_PKINIT_PKCS11_SLOT(c, slot, len, label) \
|
||||
TRACE(c, "PKINIT PKCS#11 slotid {int} token {lenstr}", \
|
||||
slot, len, label)
|
||||
--
|
||||
2.47.1
|
||||
|
||||
61
0033-Set-missing-mask-flags-for-kdb5_util-operations.patch
Normal file
61
0033-Set-missing-mask-flags-for-kdb5_util-operations.patch
Normal file
|
|
@ -0,0 +1,61 @@
|
|||
From 946f7dba8cea3d2ed0e68c5e7594cbd7e1364609 Mon Sep 17 00:00:00 2001
|
||||
From: Julien Rische <jrische@redhat.com>
|
||||
Date: Thu, 1 Aug 2024 10:56:07 +0200
|
||||
Subject: [PATCH] Set missing mask flags for kdb5_util operations
|
||||
|
||||
Set KADM5_TL_DATA for the use_mkey and update_princ_encryption
|
||||
commands. (Commit c877f13c8985d820583b0d7ac1bb4c5dc36e677e did this
|
||||
for the add_new_mkey and purge_mkeys commands.) Set appropriate flags
|
||||
for the add_random_key command.
|
||||
|
||||
[ghudson@mit.edu: combined two commits; pruned out proposed mask flag
|
||||
additions for values represented within key data or tl-data (like
|
||||
KADM5_MKVNO), as those flags are currently only used in the kadm5
|
||||
protocol, not to communicate with the KDB module]
|
||||
|
||||
ticket: 9158 (new)
|
||||
(cherry picked from commit 4ed7da378940198cf4415f86d4eb013de6ac6455)
|
||||
---
|
||||
src/kadmin/dbutil/kdb5_mkey.c | 4 +++-
|
||||
src/kadmin/dbutil/kdb5_util.c | 3 +++
|
||||
2 files changed, 6 insertions(+), 1 deletion(-)
|
||||
|
||||
diff --git a/src/kadmin/dbutil/kdb5_mkey.c b/src/kadmin/dbutil/kdb5_mkey.c
|
||||
index aceb0a9b80..ac5c51d05e 100644
|
||||
--- a/src/kadmin/dbutil/kdb5_mkey.c
|
||||
+++ b/src/kadmin/dbutil/kdb5_mkey.c
|
||||
@@ -525,6 +525,8 @@ kdb5_use_mkey(int argc, char *argv[])
|
||||
goto cleanup_return;
|
||||
}
|
||||
|
||||
+ master_entry->mask |= KADM5_TL_DATA;
|
||||
+
|
||||
if ((retval = krb5_db_put_principal(util_context, master_entry))) {
|
||||
com_err(progname, retval,
|
||||
_("while adding master key entry to the database"));
|
||||
@@ -814,7 +816,7 @@ update_princ_encryption_1(void *cb, krb5_db_entry *ent)
|
||||
goto fail;
|
||||
}
|
||||
|
||||
- ent->mask |= KADM5_KEY_DATA;
|
||||
+ ent->mask |= KADM5_KEY_DATA | KADM5_TL_DATA;
|
||||
|
||||
if ((retval = krb5_db_put_principal(util_context, ent))) {
|
||||
com_err(progname, retval, _("while updating principal '%s' key data "
|
||||
diff --git a/src/kadmin/dbutil/kdb5_util.c b/src/kadmin/dbutil/kdb5_util.c
|
||||
index 55d529fa4c..afc817891b 100644
|
||||
--- a/src/kadmin/dbutil/kdb5_util.c
|
||||
+++ b/src/kadmin/dbutil/kdb5_util.c
|
||||
@@ -600,6 +600,9 @@ add_random_key(int argc, char **argv)
|
||||
exit_status++;
|
||||
return;
|
||||
}
|
||||
+
|
||||
+ dbent->mask |= KADM5_ATTRIBUTES | KADM5_KEY_DATA | KADM5_TL_DATA;
|
||||
+
|
||||
ret = krb5_db_put_principal(util_context, dbent);
|
||||
krb5_db_free_principal(util_context, dbent);
|
||||
if (ret) {
|
||||
--
|
||||
2.47.1
|
||||
|
||||
64
0034-Prevent-overflow-when-calculating-ulog-block-size.patch
Normal file
64
0034-Prevent-overflow-when-calculating-ulog-block-size.patch
Normal file
|
|
@ -0,0 +1,64 @@
|
|||
From 9b669dd42b28e7900f5ccac2816204e7d04ea23c Mon Sep 17 00:00:00 2001
|
||||
From: Zoltan Borbely <Zoltan.Borbely@morganstanley.com>
|
||||
Date: Tue, 28 Jan 2025 16:39:25 -0500
|
||||
Subject: [PATCH] Prevent overflow when calculating ulog block size
|
||||
|
||||
In kdb_log.c:resize(), log an error and fail if the update size is
|
||||
larger than the largest possible block size (2^16-1).
|
||||
|
||||
CVE-2025-24528:
|
||||
|
||||
In MIT krb5 release 1.7 and later with incremental propagation
|
||||
enabled, an authenticated attacker can cause kadmind to write beyond
|
||||
the end of the mapped region for the iprop log file, likely causing a
|
||||
process crash.
|
||||
|
||||
[ghudson@mit.edu: edited commit message and added CVE description]
|
||||
|
||||
ticket: 9159 (new)
|
||||
tags: pullup
|
||||
target_version: 1.21-next
|
||||
|
||||
(cherry picked from commit 78ceba024b64d49612375be4a12d1c066b0bfbd0)
|
||||
---
|
||||
src/lib/kdb/kdb_log.c | 10 ++++++++--
|
||||
1 file changed, 8 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/src/lib/kdb/kdb_log.c b/src/lib/kdb/kdb_log.c
|
||||
index e9b95fce59..c805ebd988 100644
|
||||
--- a/src/lib/kdb/kdb_log.c
|
||||
+++ b/src/lib/kdb/kdb_log.c
|
||||
@@ -183,7 +183,7 @@ extend_file_to(int fd, unsigned int new_size)
|
||||
*/
|
||||
static krb5_error_code
|
||||
resize(kdb_hlog_t *ulog, uint32_t ulogentries, int ulogfd,
|
||||
- unsigned int recsize)
|
||||
+ unsigned int recsize, const kdb_incr_update_t *upd)
|
||||
{
|
||||
unsigned int new_block, new_size;
|
||||
|
||||
@@ -195,6 +195,12 @@ resize(kdb_hlog_t *ulog, uint32_t ulogentries, int ulogfd,
|
||||
new_block *= ULOG_BLOCK;
|
||||
new_size += ulogentries * new_block;
|
||||
|
||||
+ if (new_block > UINT16_MAX) {
|
||||
+ syslog(LOG_ERR, _("ulog overflow caused by principal %.*s"),
|
||||
+ upd->kdb_princ_name.utf8str_t_len,
|
||||
+ upd->kdb_princ_name.utf8str_t_val);
|
||||
+ return KRB5_LOG_ERROR;
|
||||
+ }
|
||||
if (new_size > MAXLOGLEN)
|
||||
return KRB5_LOG_ERROR;
|
||||
|
||||
@@ -291,7 +297,7 @@ store_update(kdb_log_context *log_ctx, kdb_incr_update_t *upd)
|
||||
recsize = sizeof(kdb_ent_header_t) + upd_size;
|
||||
|
||||
if (recsize > ulog->kdb_block) {
|
||||
- retval = resize(ulog, ulogentries, log_ctx->ulogfd, recsize);
|
||||
+ retval = resize(ulog, ulogentries, log_ctx->ulogfd, recsize, upd);
|
||||
if (retval)
|
||||
return retval;
|
||||
}
|
||||
--
|
||||
2.48.1
|
||||
|
||||
327
0035-Don-t-issue-session-keys-with-deprecated-enctypes.patch
Normal file
327
0035-Don-t-issue-session-keys-with-deprecated-enctypes.patch
Normal file
|
|
@ -0,0 +1,327 @@
|
|||
From c617915958a5cb05463713adcf03b6a0e0512ac3 Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Fri, 16 Dec 2022 18:31:07 -0500
|
||||
Subject: [PATCH] Don't issue session keys with deprecated enctypes
|
||||
|
||||
A paper by Tom Tervoort noted that rc4-hmac pre-hashes the input for
|
||||
its checksum and GSS operations before applying HMAC, and is therefore
|
||||
potentially vulnerable to hash collision attacks if a protocol
|
||||
contains a restricted signing oracle.
|
||||
|
||||
In light of these potential attacks, begin the functional deprecation
|
||||
of DES3 and RC4 by disallowing their use as session key enctypes by
|
||||
default. Add the variables allow_des3 and allow_rc4 in case
|
||||
negotiability of these enctypes for session keys needs to be turned
|
||||
back on, with the expectation that in future releases the enctypes
|
||||
will be more comprehensively deprecated.
|
||||
|
||||
ticket: 9081
|
||||
(cherry picked from commit 1b57a4d134bbd0e7c52d5885a92eccc815726463)
|
||||
---
|
||||
doc/admin/conf_files/krb5_conf.rst | 12 ++++++++++++
|
||||
doc/admin/enctypes.rst | 23 +++++++++++++++++++---
|
||||
src/include/k5-int.h | 4 ++++
|
||||
src/kdc/kdc_util.c | 10 ++++++++++
|
||||
src/lib/krb5/krb/get_in_tkt.c | 31 +++++++++++++++++++-----------
|
||||
src/lib/krb5/krb/init_ctx.c | 10 ++++++++++
|
||||
src/tests/gssapi/t_enctypes.py | 5 +++--
|
||||
src/tests/t_etype_info.py | 5 +++--
|
||||
src/tests/t_sesskeynego.py | 28 +++++++++++++++++++++++++--
|
||||
src/util/k5test.py | 9 ++++++++-
|
||||
10 files changed, 116 insertions(+), 21 deletions(-)
|
||||
|
||||
diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst
|
||||
index dca52e1426..d51fd3ce7e 100644
|
||||
--- a/doc/admin/conf_files/krb5_conf.rst
|
||||
+++ b/doc/admin/conf_files/krb5_conf.rst
|
||||
@@ -95,6 +95,18 @@ Additionally, krb5.conf may include any of the relations described in
|
||||
|
||||
The libdefaults section may contain any of the following relations:
|
||||
|
||||
+**allow_des3**
|
||||
+ Permit the KDC to issue tickets with des3-cbc-sha1 session keys.
|
||||
+ In future releases, this flag will allow des3-cbc-sha1 to be used
|
||||
+ at all. The default value for this tag is false. (Added in
|
||||
+ release 1.21.)
|
||||
+
|
||||
+**allow_rc4**
|
||||
+ Permit the KDC to issue tickets with arcfour-hmac session keys.
|
||||
+ In future releases, this flag will allow arcfour-hmac to be used
|
||||
+ at all. The default value for this tag is false. (Added in
|
||||
+ release 1.21.)
|
||||
+
|
||||
**allow_weak_crypto**
|
||||
If this flag is set to false, then weak encryption types (as noted
|
||||
in :ref:`Encryption_types` in :ref:`kdc.conf(5)`) will be filtered
|
||||
diff --git a/doc/admin/enctypes.rst b/doc/admin/enctypes.rst
|
||||
index c4d5499d3b..2b4ed7da0b 100644
|
||||
--- a/doc/admin/enctypes.rst
|
||||
+++ b/doc/admin/enctypes.rst
|
||||
@@ -48,12 +48,15 @@ Session key selection
|
||||
The KDC chooses the session key enctype by taking the intersection of
|
||||
its **permitted_enctypes** list, the list of long-term keys for the
|
||||
most recent kvno of the service, and the client's requested list of
|
||||
-enctypes.
|
||||
+enctypes. Starting in krb5-1.21, all services are assumed to support
|
||||
+aes256-cts-hmac-sha1-96; also, des3-cbc-sha1 and arcfour-hmac session
|
||||
+keys will not be issued by default.
|
||||
|
||||
Starting in krb5-1.11, it is possible to set a string attribute on a
|
||||
service principal to control what session key enctypes the KDC may
|
||||
-issue for service tickets for that principal. See :ref:`set_string`
|
||||
-in :ref:`kadmin(1)` for details.
|
||||
+issue for service tickets for that principal, overriding the service's
|
||||
+long-term keys and the assumption of aes256-cts-hmac-sha1-96 support.
|
||||
+See :ref:`set_string` in :ref:`kadmin(1)` for details.
|
||||
|
||||
|
||||
Choosing enctypes for a service
|
||||
@@ -87,6 +90,20 @@ affect how enctypes are chosen.
|
||||
acceptable risk for your environment and the weak enctypes are
|
||||
required for backward compatibility.
|
||||
|
||||
+**allow_des3**
|
||||
+ was added in release 1.21 and defaults to *false*. Unless this
|
||||
+ flag is set to *true*, the KDC will not issue tickets with
|
||||
+ des3-cbc-sha1 session keys. In a future release, this flag will
|
||||
+ control whether des3-cbc-sha1 is permitted in similar fashion to
|
||||
+ weak enctypes.
|
||||
+
|
||||
+**allow_rc4**
|
||||
+ was added in release 1.21 and defaults to *false*. Unless this
|
||||
+ flag is set to *true*, the KDC will not issue tickets with
|
||||
+ arcfour-hmac session keys. In a future release, this flag will
|
||||
+ control whether arcfour-hmac is permitted in similar fashion to
|
||||
+ weak enctypes.
|
||||
+
|
||||
**permitted_enctypes**
|
||||
controls the set of enctypes that a service will permit for
|
||||
session keys and for ticket and authenticator encryption. The KDC
|
||||
diff --git a/src/include/k5-int.h b/src/include/k5-int.h
|
||||
index b7789a2dd8..d0a263aa7d 100644
|
||||
--- a/src/include/k5-int.h
|
||||
+++ b/src/include/k5-int.h
|
||||
@@ -181,6 +181,8 @@ typedef unsigned char u_char;
|
||||
* matches the variable name. Keep these alphabetized. */
|
||||
#define KRB5_CONF_ACL_FILE "acl_file"
|
||||
#define KRB5_CONF_ADMIN_SERVER "admin_server"
|
||||
+#define KRB5_CONF_ALLOW_DES3 "allow_des3"
|
||||
+#define KRB5_CONF_ALLOW_RC4 "allow_rc4"
|
||||
#define KRB5_CONF_ALLOW_WEAK_CRYPTO "allow_weak_crypto"
|
||||
#define KRB5_CONF_AUTH_TO_LOCAL "auth_to_local"
|
||||
#define KRB5_CONF_AUTH_TO_LOCAL_NAMES "auth_to_local_names"
|
||||
@@ -1241,6 +1243,8 @@ struct _krb5_context {
|
||||
struct _kdb_log_context *kdblog_context;
|
||||
|
||||
krb5_boolean allow_weak_crypto;
|
||||
+ krb5_boolean allow_des3;
|
||||
+ krb5_boolean allow_rc4;
|
||||
krb5_boolean ignore_acceptor_hostname;
|
||||
krb5_boolean enforce_ok_as_delegate;
|
||||
enum dns_canonhost dns_canonicalize_hostname;
|
||||
diff --git a/src/kdc/kdc_util.c b/src/kdc/kdc_util.c
|
||||
index 93415ba862..c7b6e4090d 100644
|
||||
--- a/src/kdc/kdc_util.c
|
||||
+++ b/src/kdc/kdc_util.c
|
||||
@@ -1108,6 +1108,16 @@ select_session_keytype(krb5_context context, krb5_db_entry *server,
|
||||
if (!krb5_is_permitted_enctype(context, ktype[i]))
|
||||
continue;
|
||||
|
||||
+ /*
|
||||
+ * Prevent these deprecated enctypes from being used as session keys
|
||||
+ * unless they are explicitly allowed. In the future they will be more
|
||||
+ * comprehensively disabled and eventually removed.
|
||||
+ */
|
||||
+ if (ktype[i] == ENCTYPE_DES3_CBC_SHA1 && !context->allow_des3)
|
||||
+ continue;
|
||||
+ if (ktype[i] == ENCTYPE_ARCFOUR_HMAC && !context->allow_rc4)
|
||||
+ continue;
|
||||
+
|
||||
if (dbentry_supports_enctype(context, server, ktype[i]))
|
||||
return ktype[i];
|
||||
}
|
||||
diff --git a/src/lib/krb5/krb/get_in_tkt.c b/src/lib/krb5/krb/get_in_tkt.c
|
||||
index 1b420a3ac2..ea089f0fcc 100644
|
||||
--- a/src/lib/krb5/krb/get_in_tkt.c
|
||||
+++ b/src/lib/krb5/krb/get_in_tkt.c
|
||||
@@ -1582,22 +1582,31 @@ warn_pw_expiry(krb5_context context, krb5_get_init_creds_opt *options,
|
||||
(*prompter)(context, data, 0, banner, 0, 0);
|
||||
}
|
||||
|
||||
-/* Display a warning via the prompter if des3-cbc-sha1 was used for either the
|
||||
- * reply key or the session key. */
|
||||
+/* Display a warning via the prompter if a deprecated enctype was used for
|
||||
+ * either the reply key or the session key. */
|
||||
static void
|
||||
-warn_des3(krb5_context context, krb5_init_creds_context ctx,
|
||||
- krb5_enctype as_key_enctype)
|
||||
+warn_deprecated(krb5_context context, krb5_init_creds_context ctx,
|
||||
+ krb5_enctype as_key_enctype)
|
||||
{
|
||||
- const char *banner;
|
||||
+ krb5_enctype etype;
|
||||
+ char encbuf[128], banner[256];
|
||||
|
||||
- if (as_key_enctype != ENCTYPE_DES3_CBC_SHA1 &&
|
||||
- ctx->cred.keyblock.enctype != ENCTYPE_DES3_CBC_SHA1)
|
||||
- return;
|
||||
if (ctx->prompter == NULL)
|
||||
return;
|
||||
|
||||
- banner = _("Warning: encryption type des3-cbc-sha1 used for "
|
||||
- "authentication is weak and will be disabled");
|
||||
+ if (krb5int_c_deprecated_enctype(as_key_enctype))
|
||||
+ etype = as_key_enctype;
|
||||
+ else if (krb5int_c_deprecated_enctype(ctx->cred.keyblock.enctype))
|
||||
+ etype = ctx->cred.keyblock.enctype;
|
||||
+ else
|
||||
+ return;
|
||||
+
|
||||
+ if (krb5_enctype_to_name(etype, FALSE, encbuf, sizeof(encbuf)) != 0)
|
||||
+ return;
|
||||
+ snprintf(banner, sizeof(banner),
|
||||
+ _("Warning: encryption type %s used for authentication is "
|
||||
+ "deprecated and will be disabled"), encbuf);
|
||||
+
|
||||
/* PROMPTER_INVOCATION */
|
||||
(*ctx->prompter)(context, ctx->prompter_data, NULL, banner, 0, NULL);
|
||||
}
|
||||
@@ -1848,7 +1857,7 @@ init_creds_step_reply(krb5_context context,
|
||||
ctx->complete = TRUE;
|
||||
warn_pw_expiry(context, ctx->opt, ctx->prompter, ctx->prompter_data,
|
||||
ctx->in_tkt_service, ctx->reply);
|
||||
- warn_des3(context, ctx, encrypting_key.enctype);
|
||||
+ warn_deprecated(context, ctx, encrypting_key.enctype);
|
||||
|
||||
cleanup:
|
||||
krb5_free_pa_data(context, kdc_padata);
|
||||
diff --git a/src/lib/krb5/krb/init_ctx.c b/src/lib/krb5/krb/init_ctx.c
|
||||
index 582a2945ff..a32f8dbf03 100644
|
||||
--- a/src/lib/krb5/krb/init_ctx.c
|
||||
+++ b/src/lib/krb5/krb/init_ctx.c
|
||||
@@ -220,6 +220,16 @@ krb5_init_context_profile(profile_t profile, krb5_flags flags,
|
||||
goto cleanup;
|
||||
ctx->allow_weak_crypto = tmp;
|
||||
|
||||
+ retval = get_boolean(ctx, KRB5_CONF_ALLOW_DES3, 0, &tmp);
|
||||
+ if (retval)
|
||||
+ goto cleanup;
|
||||
+ ctx->allow_des3 = tmp;
|
||||
+
|
||||
+ retval = get_boolean(ctx, KRB5_CONF_ALLOW_RC4, 0, &tmp);
|
||||
+ if (retval)
|
||||
+ goto cleanup;
|
||||
+ ctx->allow_rc4 = tmp;
|
||||
+
|
||||
retval = get_boolean(ctx, KRB5_CONF_IGNORE_ACCEPTOR_HOSTNAME, 0, &tmp);
|
||||
if (retval)
|
||||
goto cleanup;
|
||||
diff --git a/src/tests/gssapi/t_enctypes.py b/src/tests/gssapi/t_enctypes.py
|
||||
index 2f95d89967..e6bde47afc 100755
|
||||
--- a/src/tests/gssapi/t_enctypes.py
|
||||
+++ b/src/tests/gssapi/t_enctypes.py
|
||||
@@ -10,8 +10,9 @@ d_rc4 = 'DEPRECATED:arcfour-hmac'
|
||||
|
||||
# These tests make assumptions about the default enctype lists, so set
|
||||
# them explicitly rather than relying on the library defaults.
|
||||
-supp='aes256-cts:normal aes128-cts:normal rc4-hmac:normal'
|
||||
-conf = {'libdefaults': {'permitted_enctypes': 'aes rc4'},
|
||||
+supp='aes256-cts:normal aes128-cts:normal des3-cbc-sha1:normal rc4-hmac:normal'
|
||||
+conf = {'libdefaults': {'permitted_enctypes': 'aes des3 rc4',
|
||||
+ 'allow_des3': 'true', 'allow_rc4': 'true'},
|
||||
'realms': {'$realm': {'supported_enctypes': supp}}}
|
||||
realm = K5Realm(krb5_conf=conf)
|
||||
shutil.copyfile(realm.ccache, os.path.join(realm.testdir, 'save'))
|
||||
diff --git a/src/tests/t_etype_info.py b/src/tests/t_etype_info.py
|
||||
index a6f538b66d..75d9621dd6 100644
|
||||
--- a/src/tests/t_etype_info.py
|
||||
+++ b/src/tests/t_etype_info.py
|
||||
@@ -1,7 +1,8 @@
|
||||
from k5test import *
|
||||
|
||||
-supported_enctypes = 'aes128-cts rc4-hmac'
|
||||
-conf = {'realms': {'$realm': {'supported_enctypes': supported_enctypes}}}
|
||||
+supported_enctypes = 'aes128-cts des3-cbc-sha1 rc4-hmac'
|
||||
+conf = {'libdefaults': {'allow_des3': 'true', 'allow_rc4': 'true'},
|
||||
+ 'realms': {'$realm': {'supported_enctypes': supported_enctypes}}}
|
||||
realm = K5Realm(create_host=False, get_creds=False, krb5_conf=conf)
|
||||
|
||||
realm.run([kadminl, 'addprinc', '-pw', 'pw', '+requires_preauth',
|
||||
diff --git a/src/tests/t_sesskeynego.py b/src/tests/t_sesskeynego.py
|
||||
index 9024aee838..5a213617b5 100755
|
||||
--- a/src/tests/t_sesskeynego.py
|
||||
+++ b/src/tests/t_sesskeynego.py
|
||||
@@ -25,6 +25,8 @@ conf3 = {'libdefaults': {
|
||||
'default_tkt_enctypes': 'aes128-cts',
|
||||
'default_tgs_enctypes': 'rc4-hmac,aes128-cts'}}
|
||||
conf4 = {'libdefaults': {'permitted_enctypes': 'aes256-cts'}}
|
||||
+conf5 = {'libdefaults': {'allow_rc4': 'true'}}
|
||||
+conf6 = {'libdefaults': {'allow_des3': 'true'}}
|
||||
# Test with client request and session_enctypes preferring aes128, but
|
||||
# aes256 long-term key.
|
||||
realm = K5Realm(krb5_conf=conf1, create_host=False, get_creds=False)
|
||||
@@ -54,10 +56,12 @@ realm.run([kadminl, 'setstr', 'server', 'session_enctypes',
|
||||
'aes128-cts,aes256-cts'])
|
||||
test_kvno(realm, 'aes128-cts-hmac-sha1-96', 'aes256-cts-hmac-sha1-96')
|
||||
|
||||
-# 3b: Negotiate rc4-hmac session key when principal only has aes256 long-term.
|
||||
+# 3b: Skip RC4 (as the KDC does not allow it for session keys by
|
||||
+# default) and negotiate aes128-cts session key, with only an aes256
|
||||
+# long-term service key.
|
||||
realm.run([kadminl, 'setstr', 'server', 'session_enctypes',
|
||||
'rc4-hmac,aes128-cts,aes256-cts'])
|
||||
-test_kvno(realm, 'DEPRECATED:arcfour-hmac', 'aes256-cts-hmac-sha1-96')
|
||||
+test_kvno(realm, 'aes128-cts-hmac-sha1-96', 'aes256-cts-hmac-sha1-96')
|
||||
realm.stop()
|
||||
|
||||
# 4: Check that permitted_enctypes is a default for session key enctypes.
|
||||
@@ -67,4 +71,24 @@ realm.run([kvno, 'user'],
|
||||
expected_trace=('etypes requested in TGS request: aes256-cts',))
|
||||
realm.stop()
|
||||
|
||||
+# 5: allow_rc4 permits negotiation of rc4-hmac session key.
|
||||
+realm = K5Realm(krb5_conf=conf5, create_host=False, get_creds=False)
|
||||
+realm.run([kadminl, 'addprinc', '-randkey', '-e', 'aes256-cts', 'server'])
|
||||
+realm.run([kadminl, 'setstr', 'server', 'session_enctypes', 'rc4-hmac'])
|
||||
+test_kvno(realm, 'DEPRECATED:arcfour-hmac', 'aes256-cts-hmac-sha1-96')
|
||||
+realm.stop()
|
||||
+
|
||||
+# 6: allow_des3 permits negotiation of des3-cbc-sha1 session key.
|
||||
+realm = K5Realm(krb5_conf=conf6, create_host=False, get_creds=False)
|
||||
+realm.run([kadminl, 'addprinc', '-randkey', '-e', 'aes256-cts', 'server'])
|
||||
+realm.run([kadminl, 'setstr', 'server', 'session_enctypes', 'des3-cbc-sha1'])
|
||||
+test_kvno(realm, 'DEPRECATED:des3-cbc-sha1', 'aes256-cts-hmac-sha1-96')
|
||||
+realm.stop()
|
||||
+
|
||||
+# 7: default config negotiates aes256-sha1 session key for RC4-only service.
|
||||
+realm = K5Realm(create_host=False, get_creds=False)
|
||||
+realm.run([kadminl, 'addprinc', '-randkey', '-e', 'rc4-hmac', 'server'])
|
||||
+test_kvno(realm, 'aes256-cts-hmac-sha1-96', 'DEPRECATED:arcfour-hmac')
|
||||
+realm.stop()
|
||||
+
|
||||
success('sesskeynego')
|
||||
diff --git a/src/util/k5test.py b/src/util/k5test.py
|
||||
index d823653aa0..8e5f5ba8e9 100644
|
||||
--- a/src/util/k5test.py
|
||||
+++ b/src/util/k5test.py
|
||||
@@ -1338,9 +1338,16 @@ _passes = [
|
||||
# No special settings; exercises AES256.
|
||||
('default', None, None, None),
|
||||
|
||||
+ # Exercise the DES3 enctype.
|
||||
+ ('des3', None,
|
||||
+ {'libdefaults': {'permitted_enctypes': 'des3 aes256-sha1'}},
|
||||
+ {'realms': {'$realm': {
|
||||
+ 'supported_enctypes': 'des3-cbc-sha1:normal',
|
||||
+ 'master_key_type': 'des3-cbc-sha1'}}}),
|
||||
+
|
||||
# Exercise the arcfour enctype.
|
||||
('arcfour', None,
|
||||
- {'libdefaults': {'permitted_enctypes': 'rc4'}},
|
||||
+ {'libdefaults': {'permitted_enctypes': 'rc4 aes256-sha1'}},
|
||||
{'realms': {'$realm': {
|
||||
'supported_enctypes': 'arcfour-hmac:normal',
|
||||
'master_key_type': 'arcfour-hmac'}}}),
|
||||
--
|
||||
2.49.0
|
||||
|
||||
260
0036-downstream-Remove-3des-support-cumulative-1.patch
Normal file
260
0036-downstream-Remove-3des-support-cumulative-1.patch
Normal file
|
|
@ -0,0 +1,260 @@
|
|||
From b0993b57dbe584f9308cc7773b930efe76e19ba3 Mon Sep 17 00:00:00 2001
|
||||
From: Julien Rische <jrische@redhat.com>
|
||||
Date: Fri, 4 Apr 2025 15:08:36 +0200
|
||||
Subject: [PATCH] [downstream] Remove 3des support (cumulative 1)
|
||||
|
||||
Remove mentions for the triple-DES encryption type which were added
|
||||
since the previous downstream patch.
|
||||
---
|
||||
README | 15 +++++++--------
|
||||
doc/admin/conf_files/krb5_conf.rst | 6 ------
|
||||
doc/admin/enctypes.rst | 11 ++---------
|
||||
doc/mitK5features.rst | 5 ++---
|
||||
src/include/k5-int.h | 2 --
|
||||
src/kdc/kdc_util.c | 2 --
|
||||
src/lib/krb5/krb/init_ctx.c | 5 -----
|
||||
src/man/krb5.conf.man | 6 ------
|
||||
src/tests/gssapi/t_enctypes.py | 5 ++---
|
||||
src/tests/t_etype_info.py | 4 ++--
|
||||
src/tests/t_sesskeynego.py | 8 --------
|
||||
src/util/k5test.py | 7 -------
|
||||
12 files changed, 15 insertions(+), 61 deletions(-)
|
||||
|
||||
diff --git a/README b/README
|
||||
index 6d6f7f16e3..9341bd3dd8 100644
|
||||
--- a/README
|
||||
+++ b/README
|
||||
@@ -81,11 +81,11 @@ Triple-DES and RC4 transitions
|
||||
------------------------------
|
||||
|
||||
Beginning with the krb5-1.21 release, the KDC will not issue tickets
|
||||
-with triple-DES or RC4 session keys unless explicitly configured using
|
||||
-the new allow_des3 and allow_rc4 variables in [libdefaults]. To
|
||||
-facilitate the negotiation of session keys, the KDC will assume that
|
||||
-all services can handle aes256-sha1 session keys unless the service
|
||||
-principal has a session_enctypes string attribute.
|
||||
+with RC4 session keys unless explicitly configured using the new
|
||||
+allow_rc4 variable in [libdefaults]. To facilitate the negotiation of
|
||||
+session keys, the KDC will assume that all services can handle
|
||||
+aes256-sha1 session keys unless the service principal has a
|
||||
+session_enctypes string attribute.
|
||||
|
||||
Beginning with the krb5-1.19 release, a warning will be issued if
|
||||
initial credentials are acquired using the des3-cbc-sha1 encryption
|
||||
@@ -164,9 +164,8 @@ Developer experience:
|
||||
|
||||
Protocol evolution:
|
||||
|
||||
-* The KDC will no longer issue tickets with RC4 or triple-DES session
|
||||
- keys unless explicitly configured with the new allow_rc4 or
|
||||
- allow_des3 variables respectively.
|
||||
+* The KDC will no longer issue tickets with RC4 session keys unless
|
||||
+ explicitly configured with the new allow_rc4 variable.
|
||||
|
||||
* The KDC will assume that all services can handle aes256-sha1 session
|
||||
keys unless the service principal has a session_enctypes string
|
||||
diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst
|
||||
index d51fd3ce7e..d20dcf18e3 100644
|
||||
--- a/doc/admin/conf_files/krb5_conf.rst
|
||||
+++ b/doc/admin/conf_files/krb5_conf.rst
|
||||
@@ -95,12 +95,6 @@ Additionally, krb5.conf may include any of the relations described in
|
||||
|
||||
The libdefaults section may contain any of the following relations:
|
||||
|
||||
-**allow_des3**
|
||||
- Permit the KDC to issue tickets with des3-cbc-sha1 session keys.
|
||||
- In future releases, this flag will allow des3-cbc-sha1 to be used
|
||||
- at all. The default value for this tag is false. (Added in
|
||||
- release 1.21.)
|
||||
-
|
||||
**allow_rc4**
|
||||
Permit the KDC to issue tickets with arcfour-hmac session keys.
|
||||
In future releases, this flag will allow arcfour-hmac to be used
|
||||
diff --git a/doc/admin/enctypes.rst b/doc/admin/enctypes.rst
|
||||
index 2b4ed7da0b..6ce4638d5e 100644
|
||||
--- a/doc/admin/enctypes.rst
|
||||
+++ b/doc/admin/enctypes.rst
|
||||
@@ -49,8 +49,8 @@ The KDC chooses the session key enctype by taking the intersection of
|
||||
its **permitted_enctypes** list, the list of long-term keys for the
|
||||
most recent kvno of the service, and the client's requested list of
|
||||
enctypes. Starting in krb5-1.21, all services are assumed to support
|
||||
-aes256-cts-hmac-sha1-96; also, des3-cbc-sha1 and arcfour-hmac session
|
||||
-keys will not be issued by default.
|
||||
+aes256-cts-hmac-sha1-96; also, arcfour-hmac session keys will not be
|
||||
+issued by default.
|
||||
|
||||
Starting in krb5-1.11, it is possible to set a string attribute on a
|
||||
service principal to control what session key enctypes the KDC may
|
||||
@@ -90,13 +90,6 @@ affect how enctypes are chosen.
|
||||
acceptable risk for your environment and the weak enctypes are
|
||||
required for backward compatibility.
|
||||
|
||||
-**allow_des3**
|
||||
- was added in release 1.21 and defaults to *false*. Unless this
|
||||
- flag is set to *true*, the KDC will not issue tickets with
|
||||
- des3-cbc-sha1 session keys. In a future release, this flag will
|
||||
- control whether des3-cbc-sha1 is permitted in similar fashion to
|
||||
- weak enctypes.
|
||||
-
|
||||
**allow_rc4**
|
||||
was added in release 1.21 and defaults to *false*. Unless this
|
||||
flag is set to *true*, the KDC will not issue tickets with
|
||||
diff --git a/doc/mitK5features.rst b/doc/mitK5features.rst
|
||||
index cad0855724..64d746b0af 100644
|
||||
--- a/doc/mitK5features.rst
|
||||
+++ b/doc/mitK5features.rst
|
||||
@@ -659,9 +659,8 @@ Release 1.21
|
||||
|
||||
* Protocol evolution:
|
||||
|
||||
- - The KDC will no longer issue tickets with RC4 or triple-DES
|
||||
- session keys unless explicitly configured with the new allow_rc4
|
||||
- or allow_des3 variables respectively.
|
||||
+ - The KDC will no longer issue tickets with RC4 session keys unless
|
||||
+ explicitly configured with the new allow_rc4 variable.
|
||||
|
||||
- The KDC will assume that all services can handle aes256-sha1
|
||||
session keys unless the service principal has a session_enctypes
|
||||
diff --git a/src/include/k5-int.h b/src/include/k5-int.h
|
||||
index d0a263aa7d..82a763298d 100644
|
||||
--- a/src/include/k5-int.h
|
||||
+++ b/src/include/k5-int.h
|
||||
@@ -181,7 +181,6 @@ typedef unsigned char u_char;
|
||||
* matches the variable name. Keep these alphabetized. */
|
||||
#define KRB5_CONF_ACL_FILE "acl_file"
|
||||
#define KRB5_CONF_ADMIN_SERVER "admin_server"
|
||||
-#define KRB5_CONF_ALLOW_DES3 "allow_des3"
|
||||
#define KRB5_CONF_ALLOW_RC4 "allow_rc4"
|
||||
#define KRB5_CONF_ALLOW_WEAK_CRYPTO "allow_weak_crypto"
|
||||
#define KRB5_CONF_AUTH_TO_LOCAL "auth_to_local"
|
||||
@@ -1243,7 +1242,6 @@ struct _krb5_context {
|
||||
struct _kdb_log_context *kdblog_context;
|
||||
|
||||
krb5_boolean allow_weak_crypto;
|
||||
- krb5_boolean allow_des3;
|
||||
krb5_boolean allow_rc4;
|
||||
krb5_boolean ignore_acceptor_hostname;
|
||||
krb5_boolean enforce_ok_as_delegate;
|
||||
diff --git a/src/kdc/kdc_util.c b/src/kdc/kdc_util.c
|
||||
index c7b6e4090d..bafcf5f728 100644
|
||||
--- a/src/kdc/kdc_util.c
|
||||
+++ b/src/kdc/kdc_util.c
|
||||
@@ -1113,8 +1113,6 @@ select_session_keytype(krb5_context context, krb5_db_entry *server,
|
||||
* unless they are explicitly allowed. In the future they will be more
|
||||
* comprehensively disabled and eventually removed.
|
||||
*/
|
||||
- if (ktype[i] == ENCTYPE_DES3_CBC_SHA1 && !context->allow_des3)
|
||||
- continue;
|
||||
if (ktype[i] == ENCTYPE_ARCFOUR_HMAC && !context->allow_rc4)
|
||||
continue;
|
||||
|
||||
diff --git a/src/lib/krb5/krb/init_ctx.c b/src/lib/krb5/krb/init_ctx.c
|
||||
index a32f8dbf03..82aba64c5e 100644
|
||||
--- a/src/lib/krb5/krb/init_ctx.c
|
||||
+++ b/src/lib/krb5/krb/init_ctx.c
|
||||
@@ -220,11 +220,6 @@ krb5_init_context_profile(profile_t profile, krb5_flags flags,
|
||||
goto cleanup;
|
||||
ctx->allow_weak_crypto = tmp;
|
||||
|
||||
- retval = get_boolean(ctx, KRB5_CONF_ALLOW_DES3, 0, &tmp);
|
||||
- if (retval)
|
||||
- goto cleanup;
|
||||
- ctx->allow_des3 = tmp;
|
||||
-
|
||||
retval = get_boolean(ctx, KRB5_CONF_ALLOW_RC4, 0, &tmp);
|
||||
if (retval)
|
||||
goto cleanup;
|
||||
diff --git a/src/man/krb5.conf.man b/src/man/krb5.conf.man
|
||||
index 6c0e9aff8c..4b53988712 100644
|
||||
--- a/src/man/krb5.conf.man
|
||||
+++ b/src/man/krb5.conf.man
|
||||
@@ -178,12 +178,6 @@ kdc.conf(5), but it is not a recommended practice.
|
||||
The libdefaults section may contain any of the following relations:
|
||||
.INDENT 0.0
|
||||
.TP
|
||||
-\fBallow_des3\fP
|
||||
-Permit the KDC to issue tickets with des3\-cbc\-sha1 session keys.
|
||||
-In future releases, this flag will allow des3\-cbc\-sha1 to be used
|
||||
-at all. The default value for this tag is false. (Added in
|
||||
-release 1.21.)
|
||||
-.TP
|
||||
\fBallow_rc4\fP
|
||||
Permit the KDC to issue tickets with arcfour\-hmac session keys.
|
||||
In future releases, this flag will allow arcfour\-hmac to be used
|
||||
diff --git a/src/tests/gssapi/t_enctypes.py b/src/tests/gssapi/t_enctypes.py
|
||||
index e6bde47afc..1bb8c40b6b 100755
|
||||
--- a/src/tests/gssapi/t_enctypes.py
|
||||
+++ b/src/tests/gssapi/t_enctypes.py
|
||||
@@ -10,9 +10,8 @@ d_rc4 = 'DEPRECATED:arcfour-hmac'
|
||||
|
||||
# These tests make assumptions about the default enctype lists, so set
|
||||
# them explicitly rather than relying on the library defaults.
|
||||
-supp='aes256-cts:normal aes128-cts:normal des3-cbc-sha1:normal rc4-hmac:normal'
|
||||
-conf = {'libdefaults': {'permitted_enctypes': 'aes des3 rc4',
|
||||
- 'allow_des3': 'true', 'allow_rc4': 'true'},
|
||||
+supp='aes256-cts:normal aes128-cts:normal rc4-hmac:normal'
|
||||
+conf = {'libdefaults': {'permitted_enctypes': 'aes rc4', 'allow_rc4': 'true'},
|
||||
'realms': {'$realm': {'supported_enctypes': supp}}}
|
||||
realm = K5Realm(krb5_conf=conf)
|
||||
shutil.copyfile(realm.ccache, os.path.join(realm.testdir, 'save'))
|
||||
diff --git a/src/tests/t_etype_info.py b/src/tests/t_etype_info.py
|
||||
index 75d9621dd6..e82ff7ff07 100644
|
||||
--- a/src/tests/t_etype_info.py
|
||||
+++ b/src/tests/t_etype_info.py
|
||||
@@ -1,7 +1,7 @@
|
||||
from k5test import *
|
||||
|
||||
-supported_enctypes = 'aes128-cts des3-cbc-sha1 rc4-hmac'
|
||||
-conf = {'libdefaults': {'allow_des3': 'true', 'allow_rc4': 'true'},
|
||||
+supported_enctypes = 'aes128-cts rc4-hmac'
|
||||
+conf = {'libdefaults': {'allow_rc4': 'true'},
|
||||
'realms': {'$realm': {'supported_enctypes': supported_enctypes}}}
|
||||
realm = K5Realm(create_host=False, get_creds=False, krb5_conf=conf)
|
||||
|
||||
diff --git a/src/tests/t_sesskeynego.py b/src/tests/t_sesskeynego.py
|
||||
index 5a213617b5..c7dba0ff5b 100755
|
||||
--- a/src/tests/t_sesskeynego.py
|
||||
+++ b/src/tests/t_sesskeynego.py
|
||||
@@ -26,7 +26,6 @@ conf3 = {'libdefaults': {
|
||||
'default_tgs_enctypes': 'rc4-hmac,aes128-cts'}}
|
||||
conf4 = {'libdefaults': {'permitted_enctypes': 'aes256-cts'}}
|
||||
conf5 = {'libdefaults': {'allow_rc4': 'true'}}
|
||||
-conf6 = {'libdefaults': {'allow_des3': 'true'}}
|
||||
# Test with client request and session_enctypes preferring aes128, but
|
||||
# aes256 long-term key.
|
||||
realm = K5Realm(krb5_conf=conf1, create_host=False, get_creds=False)
|
||||
@@ -78,13 +77,6 @@ realm.run([kadminl, 'setstr', 'server', 'session_enctypes', 'rc4-hmac'])
|
||||
test_kvno(realm, 'DEPRECATED:arcfour-hmac', 'aes256-cts-hmac-sha1-96')
|
||||
realm.stop()
|
||||
|
||||
-# 6: allow_des3 permits negotiation of des3-cbc-sha1 session key.
|
||||
-realm = K5Realm(krb5_conf=conf6, create_host=False, get_creds=False)
|
||||
-realm.run([kadminl, 'addprinc', '-randkey', '-e', 'aes256-cts', 'server'])
|
||||
-realm.run([kadminl, 'setstr', 'server', 'session_enctypes', 'des3-cbc-sha1'])
|
||||
-test_kvno(realm, 'DEPRECATED:des3-cbc-sha1', 'aes256-cts-hmac-sha1-96')
|
||||
-realm.stop()
|
||||
-
|
||||
# 7: default config negotiates aes256-sha1 session key for RC4-only service.
|
||||
realm = K5Realm(create_host=False, get_creds=False)
|
||||
realm.run([kadminl, 'addprinc', '-randkey', '-e', 'rc4-hmac', 'server'])
|
||||
diff --git a/src/util/k5test.py b/src/util/k5test.py
|
||||
index 8e5f5ba8e9..b953827018 100644
|
||||
--- a/src/util/k5test.py
|
||||
+++ b/src/util/k5test.py
|
||||
@@ -1338,13 +1338,6 @@ _passes = [
|
||||
# No special settings; exercises AES256.
|
||||
('default', None, None, None),
|
||||
|
||||
- # Exercise the DES3 enctype.
|
||||
- ('des3', None,
|
||||
- {'libdefaults': {'permitted_enctypes': 'des3 aes256-sha1'}},
|
||||
- {'realms': {'$realm': {
|
||||
- 'supported_enctypes': 'des3-cbc-sha1:normal',
|
||||
- 'master_key_type': 'des3-cbc-sha1'}}}),
|
||||
-
|
||||
# Exercise the arcfour enctype.
|
||||
('arcfour', None,
|
||||
{'libdefaults': {'permitted_enctypes': 'rc4 aes256-sha1'}},
|
||||
--
|
||||
2.49.0
|
||||
|
||||
692
0037-Add-PKINIT-paChecksum2-from-MS-PKCA-v20230920.patch
Normal file
692
0037-Add-PKINIT-paChecksum2-from-MS-PKCA-v20230920.patch
Normal file
|
|
@ -0,0 +1,692 @@
|
|||
From 9d03713af124c2096d071ba36893018da8d71655 Mon Sep 17 00:00:00 2001
|
||||
From: Julien Rische <jrische@redhat.com>
|
||||
Date: Tue, 14 Jan 2025 13:31:11 +0100
|
||||
Subject: [PATCH] Add PKINIT paChecksum2 from MS-PKCA v20230920
|
||||
|
||||
In 2023, Microsoft updated MS-PKCA to add the optional paChecksum2
|
||||
element in the PKAuthenticator sequence. This checksum accepts SHA-1,
|
||||
SHA-256, SHA-384, and SHA-512 digests.
|
||||
|
||||
In Windows Server 2025, this checksum becomes mandatory when using
|
||||
PKINIT with FFDH (but strangely not with ECDH if SHA-1 is configured as
|
||||
allowed).
|
||||
|
||||
[ghudson@mit.edu: refactored crypto interfaces to reduce complexity of
|
||||
calling code]
|
||||
|
||||
ticket: 9166 (new)
|
||||
(cherry picked from commit 310793ba63782af5ffa3a95d20e41f8f03ca7e00)
|
||||
---
|
||||
src/include/k5-int-pkinit.h | 25 ++--
|
||||
src/lib/krb5/asn.1/asn1_k_encode.c | 18 ++-
|
||||
src/plugins/preauth/pkinit/pkinit.h | 1 +
|
||||
src/plugins/preauth/pkinit/pkinit_clnt.c | 41 +++----
|
||||
src/plugins/preauth/pkinit/pkinit_constants.c | 42 +++++--
|
||||
src/plugins/preauth/pkinit/pkinit_crypto.h | 24 +++-
|
||||
.../preauth/pkinit/pkinit_crypto_openssl.c | 116 +++++++++++++++++-
|
||||
src/plugins/preauth/pkinit/pkinit_kdf_test.c | 4 +-
|
||||
src/plugins/preauth/pkinit/pkinit_lib.c | 16 ++-
|
||||
src/plugins/preauth/pkinit/pkinit_srv.c | 38 ++----
|
||||
src/plugins/preauth/pkinit/pkinit_trace.h | 5 +-
|
||||
src/tests/asn.1/krb5_decode_test.c | 2 +-
|
||||
src/tests/asn.1/ktest.c | 7 +-
|
||||
src/tests/asn.1/ktest_equal.c | 2 +-
|
||||
src/tests/asn.1/pkinit_encode.out | 2 +-
|
||||
src/tests/asn.1/pkinit_trval.out | 2 +-
|
||||
16 files changed, 250 insertions(+), 95 deletions(-)
|
||||
|
||||
diff --git a/src/include/k5-int-pkinit.h b/src/include/k5-int-pkinit.h
|
||||
index 915904e518..cf6b1f99c5 100644
|
||||
--- a/src/include/k5-int-pkinit.h
|
||||
+++ b/src/include/k5-int-pkinit.h
|
||||
@@ -36,21 +36,28 @@
|
||||
* pkinit structures
|
||||
*/
|
||||
|
||||
-/* PKAuthenticator */
|
||||
-typedef struct _krb5_pk_authenticator {
|
||||
- krb5_int32 cusec; /* (0..999999) */
|
||||
- krb5_timestamp ctime;
|
||||
- krb5_int32 nonce; /* (0..4294967295) */
|
||||
- krb5_checksum paChecksum;
|
||||
- krb5_data *freshnessToken;
|
||||
-} krb5_pk_authenticator;
|
||||
-
|
||||
/* AlgorithmIdentifier */
|
||||
typedef struct _krb5_algorithm_identifier {
|
||||
krb5_data algorithm; /* OID */
|
||||
krb5_data parameters; /* Optional */
|
||||
} krb5_algorithm_identifier;
|
||||
|
||||
+/* PAChecksum2 */
|
||||
+typedef struct _krb5_pachecksum2 {
|
||||
+ krb5_data checksum;
|
||||
+ krb5_algorithm_identifier algorithmIdentifier;
|
||||
+} krb5_pachecksum2;
|
||||
+
|
||||
+/* PKAuthenticator */
|
||||
+typedef struct _krb5_pk_authenticator {
|
||||
+ krb5_int32 cusec; /* (0..999999) */
|
||||
+ krb5_timestamp ctime;
|
||||
+ krb5_int32 nonce; /* (0..4294967295) */
|
||||
+ krb5_data paChecksum;
|
||||
+ krb5_data *freshnessToken; /* Optional */
|
||||
+ krb5_pachecksum2 *paChecksum2; /* Optional */
|
||||
+} krb5_pk_authenticator;
|
||||
+
|
||||
/** AuthPack from RFC 4556*/
|
||||
typedef struct _krb5_auth_pack {
|
||||
krb5_pk_authenticator pkAuthenticator;
|
||||
diff --git a/src/lib/krb5/asn.1/asn1_k_encode.c b/src/lib/krb5/asn.1/asn1_k_encode.c
|
||||
index 5378b5c23b..cf7b500837 100644
|
||||
--- a/src/lib/krb5/asn.1/asn1_k_encode.c
|
||||
+++ b/src/lib/krb5/asn.1/asn1_k_encode.c
|
||||
@@ -1394,20 +1394,30 @@ DEFSEQTYPE(pkinit_supp_pub_info, krb5_pkinit_supp_pub_info,
|
||||
MAKE_ENCODER(encode_krb5_pkinit_supp_pub_info, pkinit_supp_pub_info);
|
||||
MAKE_ENCODER(encode_krb5_sp80056a_other_info, sp80056a_other_info);
|
||||
|
||||
-/* A krb5_checksum encoded as an OCTET STRING, for PKAuthenticator. */
|
||||
-DEFCOUNTEDTYPE(ostring_checksum, krb5_checksum, contents, length, octetstring);
|
||||
+DEFFIELD(pachecksum2_0, krb5_pachecksum2, checksum, 0, ostring_data);
|
||||
+DEFFIELD(pachecksum2_1, krb5_pachecksum2, algorithmIdentifier, 1,
|
||||
+ algorithm_identifier);
|
||||
+static const struct atype_info *pachecksum2_fields[] = {
|
||||
+ &k5_atype_pachecksum2_0, &k5_atype_pachecksum2_1
|
||||
+};
|
||||
+DEFSEQTYPE(pachecksum2, krb5_pachecksum2, pachecksum2_fields);
|
||||
+
|
||||
+DEFPTRTYPE(pachecksum2_ptr, pachecksum2);
|
||||
+DEFOPTIONALZEROTYPE(opt_pachecksum2_ptr, pachecksum2_ptr);
|
||||
|
||||
DEFFIELD(pk_authenticator_0, krb5_pk_authenticator, cusec, 0, int32);
|
||||
DEFFIELD(pk_authenticator_1, krb5_pk_authenticator, ctime, 1, kerberos_time);
|
||||
DEFFIELD(pk_authenticator_2, krb5_pk_authenticator, nonce, 2, int32);
|
||||
DEFFIELD(pk_authenticator_3, krb5_pk_authenticator, paChecksum, 3,
|
||||
- ostring_checksum);
|
||||
+ ostring_data);
|
||||
DEFFIELD(pk_authenticator_4, krb5_pk_authenticator, freshnessToken, 4,
|
||||
opt_ostring_data_ptr);
|
||||
+DEFFIELD(pk_authenticator_5, krb5_pk_authenticator, paChecksum2, 5,
|
||||
+ opt_pachecksum2_ptr);
|
||||
static const struct atype_info *pk_authenticator_fields[] = {
|
||||
&k5_atype_pk_authenticator_0, &k5_atype_pk_authenticator_1,
|
||||
&k5_atype_pk_authenticator_2, &k5_atype_pk_authenticator_3,
|
||||
- &k5_atype_pk_authenticator_4
|
||||
+ &k5_atype_pk_authenticator_4, &k5_atype_pk_authenticator_5
|
||||
};
|
||||
DEFSEQTYPE(pk_authenticator, krb5_pk_authenticator, pk_authenticator_fields);
|
||||
|
||||
diff --git a/src/plugins/preauth/pkinit/pkinit.h b/src/plugins/preauth/pkinit/pkinit.h
|
||||
index 7ba7155bb4..a1564b6df2 100644
|
||||
--- a/src/plugins/preauth/pkinit/pkinit.h
|
||||
+++ b/src/plugins/preauth/pkinit/pkinit.h
|
||||
@@ -338,6 +338,7 @@ void free_krb5_external_principal_identifier(krb5_external_principal_identifier
|
||||
void free_krb5_algorithm_identifiers(krb5_algorithm_identifier ***in);
|
||||
void free_krb5_algorithm_identifier(krb5_algorithm_identifier *in);
|
||||
void free_krb5_kdc_dh_key_info(krb5_kdc_dh_key_info **in);
|
||||
+void free_pachecksum2(krb5_context context, krb5_pachecksum2 **in);
|
||||
krb5_error_code pkinit_copy_krb5_data(krb5_data *dst, const krb5_data *src);
|
||||
|
||||
|
||||
diff --git a/src/plugins/preauth/pkinit/pkinit_clnt.c b/src/plugins/preauth/pkinit/pkinit_clnt.c
|
||||
index b08022a214..433f477538 100644
|
||||
--- a/src/plugins/preauth/pkinit/pkinit_clnt.c
|
||||
+++ b/src/plugins/preauth/pkinit/pkinit_clnt.c
|
||||
@@ -56,10 +56,9 @@ use_content_info(krb5_context context, pkinit_req_context req,
|
||||
static krb5_error_code
|
||||
pkinit_as_req_create(krb5_context context, pkinit_context plgctx,
|
||||
pkinit_req_context reqctx, krb5_timestamp ctsec,
|
||||
- krb5_int32 cusec, krb5_ui_4 nonce,
|
||||
- const krb5_checksum *cksum,
|
||||
- krb5_principal client, krb5_principal server,
|
||||
- krb5_data **as_req);
|
||||
+ krb5_int32 cusec, krb5_ui_4 nonce, const krb5_data *cksum,
|
||||
+ const krb5_pachecksum2 *cksum2, krb5_principal client,
|
||||
+ krb5_principal server, krb5_data **as_req);
|
||||
|
||||
static krb5_error_code
|
||||
pkinit_as_rep_parse(krb5_context context, pkinit_context plgctx,
|
||||
@@ -89,7 +88,8 @@ pa_pkinit_gen_req(krb5_context context,
|
||||
krb5_timestamp ctsec = 0;
|
||||
krb5_int32 cusec = 0;
|
||||
krb5_ui_4 nonce = 0;
|
||||
- krb5_checksum cksum;
|
||||
+ krb5_data cksum = empty_data();
|
||||
+ krb5_pachecksum2 *cksum2 = NULL;
|
||||
krb5_data *der_req = NULL;
|
||||
krb5_pa_data **return_pa_data = NULL;
|
||||
|
||||
@@ -118,15 +118,10 @@ pa_pkinit_gen_req(krb5_context context,
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
- retval = krb5_c_make_checksum(context, CKSUMTYPE_SHA1, NULL, 0, der_req,
|
||||
- &cksum);
|
||||
+ retval = crypto_generate_checksums(context, der_req, &cksum, &cksum2);
|
||||
if (retval)
|
||||
goto cleanup;
|
||||
- TRACE_PKINIT_CLIENT_REQ_CHECKSUM(context, &cksum);
|
||||
-#ifdef DEBUG_CKSUM
|
||||
- pkiDebug("calculating checksum on buf size (%d)\n", der_req->length);
|
||||
- print_buffer(der_req->data, der_req->length);
|
||||
-#endif
|
||||
+ TRACE_PKINIT_CLIENT_REQ_CHECKSUMS(context, &cksum, cksum2);
|
||||
|
||||
retval = cb->get_preauth_time(context, rock, TRUE, &ctsec, &cusec);
|
||||
if (retval)
|
||||
@@ -140,7 +135,8 @@ pa_pkinit_gen_req(krb5_context context,
|
||||
nonce = request->nonce;
|
||||
|
||||
retval = pkinit_as_req_create(context, plgctx, reqctx, ctsec, cusec,
|
||||
- nonce, &cksum, request->client, request->server, &out_data);
|
||||
+ nonce, &cksum, cksum2, request->client,
|
||||
+ request->server, &out_data);
|
||||
if (retval) {
|
||||
pkiDebug("error %d on pkinit_as_req_create; aborting PKINIT\n",
|
||||
(int) retval);
|
||||
@@ -168,23 +164,19 @@ pa_pkinit_gen_req(krb5_context context,
|
||||
|
||||
cleanup:
|
||||
krb5_free_data(context, der_req);
|
||||
- krb5_free_checksum_contents(context, &cksum);
|
||||
+ krb5_free_data_contents(context, &cksum);
|
||||
+ free_pachecksum2(context, &cksum2);
|
||||
krb5_free_data(context, out_data);
|
||||
krb5_free_pa_data(context, return_pa_data);
|
||||
return retval;
|
||||
}
|
||||
|
||||
static krb5_error_code
|
||||
-pkinit_as_req_create(krb5_context context,
|
||||
- pkinit_context plgctx,
|
||||
- pkinit_req_context reqctx,
|
||||
- krb5_timestamp ctsec,
|
||||
- krb5_int32 cusec,
|
||||
- krb5_ui_4 nonce,
|
||||
- const krb5_checksum * cksum,
|
||||
- krb5_principal client,
|
||||
- krb5_principal server,
|
||||
- krb5_data ** as_req)
|
||||
+pkinit_as_req_create(krb5_context context, pkinit_context plgctx,
|
||||
+ pkinit_req_context reqctx, krb5_timestamp ctsec,
|
||||
+ krb5_int32 cusec, krb5_ui_4 nonce, const krb5_data *cksum,
|
||||
+ const krb5_pachecksum2 *cksum2, krb5_principal client,
|
||||
+ krb5_principal server, krb5_data **as_req)
|
||||
{
|
||||
krb5_error_code retval = ENOMEM;
|
||||
krb5_data spki = empty_data(), *coded_auth_pack = NULL;
|
||||
@@ -202,6 +194,7 @@ pkinit_as_req_create(krb5_context context,
|
||||
auth_pack.pkAuthenticator.paChecksum = *cksum;
|
||||
if (!reqctx->opts->disable_freshness)
|
||||
auth_pack.pkAuthenticator.freshnessToken = reqctx->freshness_token;
|
||||
+ auth_pack.pkAuthenticator.paChecksum2 = (krb5_pachecksum2 *)cksum2;
|
||||
auth_pack.clientDHNonce.length = 0;
|
||||
auth_pack.supportedKDFs = (krb5_data **)supported_kdf_alg_ids;
|
||||
|
||||
diff --git a/src/plugins/preauth/pkinit/pkinit_constants.c b/src/plugins/preauth/pkinit/pkinit_constants.c
|
||||
index 905e90d29c..a32b373c32 100644
|
||||
--- a/src/plugins/preauth/pkinit/pkinit_constants.c
|
||||
+++ b/src/plugins/preauth/pkinit/pkinit_constants.c
|
||||
@@ -34,25 +34,49 @@
|
||||
|
||||
/* RFC 8636 id-pkinit-kdf-ah-sha1: iso(1) identified-organization(3) dod(6)
|
||||
* internet(1) security(5) kerberosv5(2) pkinit(3) kdf(6) sha1(1) */
|
||||
-static char sha1_oid[8] = { 0x2B, 0x06, 0x01, 0x05, 0x02, 0x03, 0x06, 0x01 };
|
||||
+static char kdf_sha1[8] = { 0x2B, 0x06, 0x01, 0x05, 0x02, 0x03, 0x06, 0x01 };
|
||||
/* RFC 8636 id-pkinit-kdf-ah-sha256: iso(1) identified-organization(3) dod(6)
|
||||
* internet(1) security(5) kerberosv5(2) pkinit(3) kdf(6) sha256(2) */
|
||||
-static char sha256_oid[8] = { 0x2B, 0x06, 0x01, 0x05, 0x02, 0x03, 0x06, 0x02 };
|
||||
+static char kdf_sha256[8] = { 0x2B, 0x06, 0x01, 0x05, 0x02, 0x03, 0x06, 0x02 };
|
||||
/* RFC 8636 id-pkinit-kdf-ah-sha512: iso(1) identified-organization(3) dod(6)
|
||||
* internet(1) security(5) kerberosv5(2) pkinit(3) kdf(6) sha512(3) */
|
||||
-static char sha512_oid[8] = { 0x2B, 0x06, 0x01, 0x05, 0x02, 0x03, 0x06, 0x03 };
|
||||
+static char kdf_sha512[8] = { 0x2B, 0x06, 0x01, 0x05, 0x02, 0x03, 0x06, 0x03 };
|
||||
|
||||
-const krb5_data sha1_id = { KV5M_DATA, sizeof(sha1_oid), sha1_oid };
|
||||
-const krb5_data sha256_id = { KV5M_DATA, sizeof(sha256_oid), sha256_oid };
|
||||
-const krb5_data sha512_id = { KV5M_DATA, sizeof(sha512_oid), sha512_oid };
|
||||
+const krb5_data kdf_sha1_id = { KV5M_DATA, sizeof(kdf_sha1), kdf_sha1 };
|
||||
+const krb5_data kdf_sha256_id = { KV5M_DATA, sizeof(kdf_sha256), kdf_sha256 };
|
||||
+const krb5_data kdf_sha512_id = { KV5M_DATA, sizeof(kdf_sha512), kdf_sha512 };
|
||||
|
||||
krb5_data const * const supported_kdf_alg_ids[] = {
|
||||
- &sha256_id,
|
||||
- &sha1_id,
|
||||
- &sha512_id,
|
||||
+ &kdf_sha256_id,
|
||||
+ &kdf_sha1_id,
|
||||
+ &kdf_sha512_id,
|
||||
NULL
|
||||
};
|
||||
|
||||
+/* RFC 3370 sha-1: iso(1) identified-organization(3) oiw(14) secsig(3)
|
||||
+ * algorithm(2) 26 */
|
||||
+static char cms_sha1[] = { 0x2b, 0x0e, 0x03, 0x02, 0x1a };
|
||||
+/* RFC 5754 id-sha256: joint-iso-itu-t(2) country(16) us(840) organization(1)
|
||||
+ * gov(101) csor(3) nistalgorithm(4) hashalgs(2) 1 */
|
||||
+static char cms_sha256[] = {
|
||||
+ 0x60, 0x86, 0x48, 0x01, 0x65, 0x03, 0x04, 0x02, 0x01
|
||||
+};
|
||||
+/* RFC 5754 id-sha384: joint-iso-itu-t(2) country(16) us(840) organization(1)
|
||||
+ * gov(101) csor(3) nistalgorithm(4) hashalgs(2) 2 */
|
||||
+static char cms_sha384[] = {
|
||||
+ 0x60, 0x86, 0x48, 0x01, 0x65, 0x03, 0x04, 0x02, 0x02
|
||||
+};
|
||||
+/* RFC 5754 id-sha512: joint-iso-itu-t(2) country(16) us(840) organization(1)
|
||||
+ * gov(101) csor(3) nistalgorithm(4) hashalgs(2) 3 */
|
||||
+static char cms_sha512[] = {
|
||||
+ 0x60, 0x86, 0x48, 0x01, 0x65, 0x03, 0x04, 0x02, 0x03
|
||||
+};
|
||||
+
|
||||
+const krb5_data cms_sha1_id = { KV5M_DATA, sizeof(cms_sha1), cms_sha1 };
|
||||
+const krb5_data cms_sha256_id = { KV5M_DATA, sizeof(cms_sha256), cms_sha256 };
|
||||
+const krb5_data cms_sha384_id = { KV5M_DATA, sizeof(cms_sha384), cms_sha384 };
|
||||
+const krb5_data cms_sha512_id = { KV5M_DATA, sizeof(cms_sha512), cms_sha512 };
|
||||
+
|
||||
/* RFC 4055 sha256WithRSAEncryption: iso(1) member-body(2) us(840)
|
||||
* rsadsi(113549) pkcs(1) 1 11 */
|
||||
static char sha256WithRSAEncr_oid[9] = {
|
||||
diff --git a/src/plugins/preauth/pkinit/pkinit_crypto.h b/src/plugins/preauth/pkinit/pkinit_crypto.h
|
||||
index fd876e4850..3b12e904b1 100644
|
||||
--- a/src/plugins/preauth/pkinit/pkinit_crypto.h
|
||||
+++ b/src/plugins/preauth/pkinit/pkinit_crypto.h
|
||||
@@ -562,9 +562,13 @@ pkinit_alg_agility_kdf(krb5_context context,
|
||||
krb5_data *pk_as_rep,
|
||||
krb5_keyblock *key_block);
|
||||
|
||||
-extern const krb5_data sha1_id;
|
||||
-extern const krb5_data sha256_id;
|
||||
-extern const krb5_data sha512_id;
|
||||
+extern const krb5_data kdf_sha1_id;
|
||||
+extern const krb5_data kdf_sha256_id;
|
||||
+extern const krb5_data kdf_sha512_id;
|
||||
+extern const krb5_data cms_sha1_id;
|
||||
+extern const krb5_data cms_sha256_id;
|
||||
+extern const krb5_data cms_sha384_id;
|
||||
+extern const krb5_data cms_sha512_id;
|
||||
extern const krb5_data oakley_1024;
|
||||
extern const krb5_data oakley_2048;
|
||||
extern const krb5_data oakley_4096;
|
||||
@@ -597,4 +601,18 @@ crypto_req_cert_matching_data(krb5_context context,
|
||||
|
||||
int parse_dh_min_bits(krb5_context context, const char *str);
|
||||
|
||||
+/* Generate a SHA-1 checksum over body in *cksum1_out and a SHA-256 checksum
|
||||
+ * over body in *cksum2_out with appropriate metadata. */
|
||||
+krb5_error_code
|
||||
+crypto_generate_checksums(krb5_context context, const krb5_data *body,
|
||||
+ krb5_data *cksum1_out,
|
||||
+ krb5_pachecksum2 **cksum2_out);
|
||||
+
|
||||
+/* Verify the SHA-1 checksum in cksum1 and the tagged checksum in cksum2.
|
||||
+ * cksum2 may be NULL, in which case only cksum1 is verified. */
|
||||
+krb5_error_code
|
||||
+crypto_verify_checksums(krb5_context context, krb5_data *body,
|
||||
+ const krb5_data *cksum1,
|
||||
+ const krb5_pachecksum2 *cksum2);
|
||||
+
|
||||
#endif /* _PKINIT_CRYPTO_H */
|
||||
diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c
|
||||
index 402bf1b9b3..429b7d202c 100644
|
||||
--- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c
|
||||
+++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c
|
||||
@@ -2616,11 +2616,11 @@ cleanup:
|
||||
static const EVP_MD *
|
||||
algid_to_md(const krb5_data *alg_id)
|
||||
{
|
||||
- if (data_eq(*alg_id, sha1_id))
|
||||
+ if (data_eq(*alg_id, kdf_sha1_id))
|
||||
return EVP_sha1();
|
||||
- if (data_eq(*alg_id, sha256_id))
|
||||
+ if (data_eq(*alg_id, kdf_sha256_id))
|
||||
return EVP_sha256();
|
||||
- if (data_eq(*alg_id, sha512_id))
|
||||
+ if (data_eq(*alg_id, kdf_sha512_id))
|
||||
return EVP_sha512();
|
||||
return NULL;
|
||||
}
|
||||
@@ -5663,3 +5663,113 @@ parse_dh_min_bits(krb5_context context, const char *str)
|
||||
TRACE_PKINIT_DH_INVALID_MIN_BITS(context, str);
|
||||
return PKINIT_DEFAULT_DH_MIN_BITS;
|
||||
}
|
||||
+
|
||||
+/* Return the OpenSSL message digest type matching the given CMS OID, or NULL
|
||||
+ * if it doesn't match any of the CMS OIDs we know about. */
|
||||
+static const EVP_MD *
|
||||
+md_from_cms_oid(const krb5_data *alg_id)
|
||||
+{
|
||||
+ if (data_eq(*alg_id, cms_sha1_id))
|
||||
+ return EVP_sha1();
|
||||
+ if (data_eq(*alg_id, cms_sha256_id))
|
||||
+ return EVP_sha256();
|
||||
+ if (data_eq(*alg_id, cms_sha384_id))
|
||||
+ return EVP_sha384();
|
||||
+ if (data_eq(*alg_id, cms_sha512_id))
|
||||
+ return EVP_sha512();
|
||||
+ return NULL;
|
||||
+}
|
||||
+
|
||||
+/* Compute a message digest of the given type over body, placing the result in
|
||||
+ * *digest_out in allocated storage. Return true on success. */
|
||||
+static krb5_boolean
|
||||
+make_digest(const krb5_data *body, const EVP_MD *md, krb5_data *digest_out)
|
||||
+{
|
||||
+ krb5_error_code ret;
|
||||
+ krb5_data d;
|
||||
+
|
||||
+ if (md == NULL)
|
||||
+ return FALSE;
|
||||
+ ret = alloc_data(&d, EVP_MD_size(md));
|
||||
+ if (ret)
|
||||
+ return FALSE;
|
||||
+ if (!EVP_Digest(body->data, body->length, (uint8_t *)d.data, &d.length, md,
|
||||
+ NULL)) {
|
||||
+ free(d.data);
|
||||
+ return FALSE;
|
||||
+ }
|
||||
+ *digest_out = d;
|
||||
+ return TRUE;
|
||||
+}
|
||||
+
|
||||
+/* Return true if digest verifies for the given body and message digest
|
||||
+ * type. */
|
||||
+static krb5_boolean
|
||||
+check_digest(const krb5_data *body, const EVP_MD *md, const krb5_data *digest)
|
||||
+{
|
||||
+ unsigned int digest_len;
|
||||
+ uint8_t buf[EVP_MAX_MD_SIZE];
|
||||
+
|
||||
+ if (md == NULL)
|
||||
+ return FALSE;
|
||||
+ if (!EVP_Digest(body->data, body->length, buf, &digest_len, md, NULL))
|
||||
+ return FALSE;
|
||||
+ return (digest->length == digest_len &&
|
||||
+ CRYPTO_memcmp(digest->data, buf, digest_len) == 0);
|
||||
+}
|
||||
+
|
||||
+krb5_error_code
|
||||
+crypto_generate_checksums(krb5_context context, const krb5_data *body,
|
||||
+ krb5_data *cksum1_out, krb5_pachecksum2 **cksum2_out)
|
||||
+{
|
||||
+ krb5_data cksum1 = empty_data();
|
||||
+ krb5_pachecksum2 *cksum2 = NULL;
|
||||
+ krb5_error_code ret;
|
||||
+
|
||||
+ if (!make_digest(body, EVP_sha1(), &cksum1))
|
||||
+ goto fail;
|
||||
+
|
||||
+ cksum2 = k5alloc(sizeof(*cksum2), &ret);
|
||||
+ if (cksum2 == NULL)
|
||||
+ goto fail;
|
||||
+
|
||||
+ if (!make_digest(body, EVP_sha256(), &cksum2->checksum))
|
||||
+ goto fail;
|
||||
+
|
||||
+ if (krb5int_copy_data_contents(context, &cms_sha256_id,
|
||||
+ &cksum2->algorithmIdentifier.algorithm))
|
||||
+ goto fail;
|
||||
+
|
||||
+ cksum2->algorithmIdentifier.parameters = empty_data();
|
||||
+
|
||||
+ *cksum1_out = cksum1;
|
||||
+ *cksum2_out = cksum2;
|
||||
+ return 0;
|
||||
+
|
||||
+fail:
|
||||
+ krb5_free_data_contents(context, &cksum1);
|
||||
+ free_pachecksum2(context, &cksum2);
|
||||
+ return KRB5_CRYPTO_INTERNAL;
|
||||
+}
|
||||
+
|
||||
+krb5_error_code
|
||||
+crypto_verify_checksums(krb5_context context, krb5_data *body,
|
||||
+ const krb5_data *cksum1,
|
||||
+ const krb5_pachecksum2 *cksum2)
|
||||
+{
|
||||
+ const EVP_MD *md;
|
||||
+
|
||||
+ /* RFC 4556 doesn't say what error to return if the checksum doesn't match.
|
||||
+ * Windows returns this one. */
|
||||
+ if (!check_digest(body, EVP_sha1(), cksum1))
|
||||
+ return KRB5KRB_AP_ERR_MODIFIED;
|
||||
+
|
||||
+ if (cksum2 == NULL)
|
||||
+ return 0;
|
||||
+
|
||||
+ md = md_from_cms_oid(&cksum2->algorithmIdentifier.algorithm);
|
||||
+ if (!check_digest(body, md, &cksum2->checksum))
|
||||
+ return KRB5KRB_AP_ERR_MODIFIED;
|
||||
+
|
||||
+ return 0;
|
||||
+}
|
||||
diff --git a/src/plugins/preauth/pkinit/pkinit_kdf_test.c b/src/plugins/preauth/pkinit/pkinit_kdf_test.c
|
||||
index 99c93ac128..dd6e8d7503 100644
|
||||
--- a/src/plugins/preauth/pkinit/pkinit_kdf_test.c
|
||||
+++ b/src/plugins/preauth/pkinit/pkinit_kdf_test.c
|
||||
@@ -126,7 +126,7 @@ main(int argc, char **argv)
|
||||
|
||||
/* TEST 1: SHA-1/AES */
|
||||
/* set up algorithm id */
|
||||
- alg_id.algorithm = sha1_id;
|
||||
+ alg_id.algorithm = kdf_sha1_id;
|
||||
|
||||
enctype = enctype_aes;
|
||||
|
||||
@@ -157,7 +157,7 @@ main(int argc, char **argv)
|
||||
|
||||
/* TEST 2: SHA-256/AES */
|
||||
/* set up algorithm id */
|
||||
- alg_id.algorithm = sha256_id;
|
||||
+ alg_id.algorithm = kdf_sha256_id;
|
||||
|
||||
enctype = enctype_aes;
|
||||
|
||||
diff --git a/src/plugins/preauth/pkinit/pkinit_lib.c b/src/plugins/preauth/pkinit/pkinit_lib.c
|
||||
index 25965eb5d2..891f47fd26 100644
|
||||
--- a/src/plugins/preauth/pkinit/pkinit_lib.c
|
||||
+++ b/src/plugins/preauth/pkinit/pkinit_lib.c
|
||||
@@ -29,6 +29,7 @@
|
||||
* SUCH DAMAGES.
|
||||
*/
|
||||
|
||||
+#include "k5-int.h"
|
||||
#include "pkinit.h"
|
||||
|
||||
#define FAKECERT
|
||||
@@ -119,8 +120,9 @@ free_krb5_auth_pack(krb5_auth_pack **in)
|
||||
{
|
||||
if ((*in) == NULL) return;
|
||||
krb5_free_data_contents(NULL, &(*in)->clientPublicValue);
|
||||
- free((*in)->pkAuthenticator.paChecksum.contents);
|
||||
+ free((*in)->pkAuthenticator.paChecksum.data);
|
||||
krb5_free_data(NULL, (*in)->pkAuthenticator.freshnessToken);
|
||||
+ free_pachecksum2(NULL, &(*in)->pkAuthenticator.paChecksum2);
|
||||
if ((*in)->supportedCMSTypes != NULL)
|
||||
free_krb5_algorithm_identifiers(&((*in)->supportedCMSTypes));
|
||||
if ((*in)->supportedKDFs) {
|
||||
@@ -196,6 +198,18 @@ free_krb5_kdc_dh_key_info(krb5_kdc_dh_key_info **in)
|
||||
free(*in);
|
||||
}
|
||||
|
||||
+void
|
||||
+free_pachecksum2(krb5_context context, krb5_pachecksum2 **in)
|
||||
+{
|
||||
+ if (*in == NULL)
|
||||
+ return;
|
||||
+ krb5_free_data_contents(context, &(*in)->checksum);
|
||||
+ krb5_free_data_contents(context, &(*in)->algorithmIdentifier.algorithm);
|
||||
+ krb5_free_data_contents(context, &(*in)->algorithmIdentifier.parameters);
|
||||
+ free(*in);
|
||||
+ *in = NULL;
|
||||
+}
|
||||
+
|
||||
void
|
||||
init_krb5_pa_pk_as_req(krb5_pa_pk_as_req **in)
|
||||
{
|
||||
diff --git a/src/plugins/preauth/pkinit/pkinit_srv.c b/src/plugins/preauth/pkinit/pkinit_srv.c
|
||||
index e22bcb195b..f558308483 100644
|
||||
--- a/src/plugins/preauth/pkinit/pkinit_srv.c
|
||||
+++ b/src/plugins/preauth/pkinit/pkinit_srv.c
|
||||
@@ -428,11 +428,12 @@ pkinit_server_verify_padata(krb5_context context,
|
||||
krb5_data authp_data = {0, 0, NULL}, krb5_authz = {0, 0, NULL};
|
||||
krb5_pa_pk_as_req *reqp = NULL;
|
||||
krb5_auth_pack *auth_pack = NULL;
|
||||
+ krb5_pk_authenticator *pka;
|
||||
pkinit_kdc_context plgctx = NULL;
|
||||
pkinit_kdc_req_context reqctx = NULL;
|
||||
krb5_checksum cksum = {0, 0, 0, NULL};
|
||||
krb5_data *der_req = NULL;
|
||||
- krb5_data k5data, *ftoken;
|
||||
+ krb5_data k5data;
|
||||
int is_signed = 1;
|
||||
krb5_pa_data **e_data = NULL;
|
||||
krb5_kdcpreauth_modreq modreq = NULL;
|
||||
@@ -524,8 +525,9 @@ pkinit_server_verify_padata(krb5_context context,
|
||||
pkiDebug("failed to decode krb5_auth_pack\n");
|
||||
goto cleanup;
|
||||
}
|
||||
+ pka = &auth_pack->pkAuthenticator;
|
||||
|
||||
- retval = krb5_check_clockskew(context, auth_pack->pkAuthenticator.ctime);
|
||||
+ retval = krb5_check_clockskew(context, pka->ctime);
|
||||
if (retval)
|
||||
goto cleanup;
|
||||
|
||||
@@ -548,36 +550,14 @@ pkinit_server_verify_padata(krb5_context context,
|
||||
goto cleanup;
|
||||
}
|
||||
der_req = cb->request_body(context, rock);
|
||||
- retval = krb5_c_make_checksum(context, CKSUMTYPE_SHA1, NULL, 0, der_req,
|
||||
- &cksum);
|
||||
- if (retval) {
|
||||
- pkiDebug("unable to calculate AS REQ checksum\n");
|
||||
- goto cleanup;
|
||||
- }
|
||||
- if (cksum.length != auth_pack->pkAuthenticator.paChecksum.length ||
|
||||
- k5_bcmp(cksum.contents, auth_pack->pkAuthenticator.paChecksum.contents,
|
||||
- cksum.length) != 0) {
|
||||
- pkiDebug("failed to match the checksum\n");
|
||||
-#ifdef DEBUG_CKSUM
|
||||
- pkiDebug("calculating checksum on buf size (%d)\n", req_pkt->length);
|
||||
- print_buffer(req_pkt->data, req_pkt->length);
|
||||
- pkiDebug("received checksum type=%d size=%d ",
|
||||
- auth_pack->pkAuthenticator.paChecksum.checksum_type,
|
||||
- auth_pack->pkAuthenticator.paChecksum.length);
|
||||
- print_buffer(auth_pack->pkAuthenticator.paChecksum.contents,
|
||||
- auth_pack->pkAuthenticator.paChecksum.length);
|
||||
- pkiDebug("expected checksum type=%d size=%d ",
|
||||
- cksum.checksum_type, cksum.length);
|
||||
- print_buffer(cksum.contents, cksum.length);
|
||||
-#endif
|
||||
|
||||
- retval = KRB5KDC_ERR_PA_CHECKSUM_MUST_BE_INCLUDED;
|
||||
+ retval = crypto_verify_checksums(context, der_req, &pka->paChecksum,
|
||||
+ pka->paChecksum2);
|
||||
+ if (retval)
|
||||
goto cleanup;
|
||||
- }
|
||||
|
||||
- ftoken = auth_pack->pkAuthenticator.freshnessToken;
|
||||
- if (ftoken != NULL) {
|
||||
- retval = cb->check_freshness_token(context, rock, ftoken);
|
||||
+ if (pka->freshnessToken != NULL) {
|
||||
+ retval = cb->check_freshness_token(context, rock, pka->freshnessToken);
|
||||
if (retval)
|
||||
goto cleanup;
|
||||
valid_freshness_token = TRUE;
|
||||
diff --git a/src/plugins/preauth/pkinit/pkinit_trace.h b/src/plugins/preauth/pkinit/pkinit_trace.h
|
||||
index 1faa6816d7..7b68d4b3b1 100644
|
||||
--- a/src/plugins/preauth/pkinit/pkinit_trace.h
|
||||
+++ b/src/plugins/preauth/pkinit/pkinit_trace.h
|
||||
@@ -58,8 +58,9 @@
|
||||
TRACE(c, "PKINIT client verified DH reply")
|
||||
#define TRACE_PKINIT_CLIENT_REP_DH_FAIL(c) \
|
||||
TRACE(c, "PKINIT client could not verify DH reply")
|
||||
-#define TRACE_PKINIT_CLIENT_REQ_CHECKSUM(c, cksum) \
|
||||
- TRACE(c, "PKINIT client computed kdc-req-body checksum {cksum}", cksum)
|
||||
+#define TRACE_PKINIT_CLIENT_REQ_CHECKSUMS(c, ck1, ck2) \
|
||||
+ TRACE(c, "PKINIT client computed checksums: {hexdata} {hexdata}", \
|
||||
+ ck1, &(ck2)->checksum)
|
||||
#define TRACE_PKINIT_CLIENT_REQ_DH(c) \
|
||||
TRACE(c, "PKINIT client making DH request")
|
||||
#define TRACE_PKINIT_CLIENT_SAN_CONFIG_DNSNAME(c, host) \
|
||||
diff --git a/src/tests/asn.1/krb5_decode_test.c b/src/tests/asn.1/krb5_decode_test.c
|
||||
index 2fa6dce8eb..f47849abad 100644
|
||||
--- a/src/tests/asn.1/krb5_decode_test.c
|
||||
+++ b/src/tests/asn.1/krb5_decode_test.c
|
||||
@@ -1174,7 +1174,7 @@ main(int argc, char **argv)
|
||||
/* decode_krb5_auth_pack */
|
||||
{
|
||||
setup(krb5_auth_pack,ktest_make_sample_auth_pack);
|
||||
- decode_run("krb5_auth_pack","","30 81 85 A0 35 30 33 A0 05 02 03 01 E2 40 A1 11 18 0F 31 39 39 34 30 36 31 30 30 36 30 33 31 37 5A A2 03 02 01 2A A3 06 04 04 31 32 33 34 A4 0A 04 08 6B 72 62 35 64 61 74 61 A1 08 04 06 70 76 61 6C 75 65 A2 24 30 22 30 13 06 09 2A 86 48 86 F7 12 01 02 02 04 06 70 61 72 61 6D 73 30 0B 06 09 2A 86 48 86 F7 12 01 02 02 A3 0A 04 08 6B 72 62 35 64 61 74 61 A4 10 30 0E 30 0C A0 0A 06 08 6B 72 62 35 64 61 74 61",
|
||||
+ decode_run("krb5_auth_pack","","30 81 89 A0 39 30 37 A0 05 02 03 01 E2 40 A1 11 18 0F 31 39 39 34 30 36 31 30 30 36 30 33 31 37 5A A2 03 02 01 2A A3 0A 04 08 6B 72 62 35 64 61 74 61 A4 0A 04 08 6B 72 62 35 64 61 74 61 A1 08 04 06 70 76 61 6C 75 65 A2 24 30 22 30 13 06 09 2A 86 48 86 F7 12 01 02 02 04 06 70 61 72 61 6D 73 30 0B 06 09 2A 86 48 86 F7 12 01 02 02 A3 0A 04 08 6B 72 62 35 64 61 74 61 A4 10 30 0E 30 0C A0 0A 06 08 6B 72 62 35 64 61 74 61",
|
||||
acc.decode_krb5_auth_pack,
|
||||
ktest_equal_auth_pack,ktest_free_auth_pack);
|
||||
ktest_empty_auth_pack(&ref);
|
||||
diff --git a/src/tests/asn.1/ktest.c b/src/tests/asn.1/ktest.c
|
||||
index d37e4fa7e6..7f54aa3184 100644
|
||||
--- a/src/tests/asn.1/ktest.c
|
||||
+++ b/src/tests/asn.1/ktest.c
|
||||
@@ -700,9 +700,7 @@ ktest_make_sample_pk_authenticator(krb5_pk_authenticator *p)
|
||||
p->cusec = SAMPLE_USEC;
|
||||
p->ctime = SAMPLE_TIME;
|
||||
p->nonce = SAMPLE_NONCE;
|
||||
- ktest_make_sample_checksum(&p->paChecksum);
|
||||
- /* We don't encode the checksum type, only the contents. */
|
||||
- p->paChecksum.checksum_type = 0;
|
||||
+ ktest_make_sample_data(&p->paChecksum);
|
||||
p->freshnessToken = ealloc(sizeof(krb5_data));
|
||||
ktest_make_sample_data(p->freshnessToken);
|
||||
}
|
||||
@@ -1604,8 +1602,7 @@ ktest_empty_pa_otp_req(krb5_pa_otp_req *p)
|
||||
static void
|
||||
ktest_empty_pk_authenticator(krb5_pk_authenticator *p)
|
||||
{
|
||||
- ktest_empty_checksum(&p->paChecksum);
|
||||
- p->paChecksum.contents = NULL;
|
||||
+ ktest_empty_data(&p->paChecksum);
|
||||
krb5_free_data(NULL, p->freshnessToken);
|
||||
p->freshnessToken = NULL;
|
||||
}
|
||||
diff --git a/src/tests/asn.1/ktest_equal.c b/src/tests/asn.1/ktest_equal.c
|
||||
index b48a0285d2..13786dd1e5 100644
|
||||
--- a/src/tests/asn.1/ktest_equal.c
|
||||
+++ b/src/tests/asn.1/ktest_equal.c
|
||||
@@ -844,7 +844,7 @@ ktest_equal_pk_authenticator(krb5_pk_authenticator *ref,
|
||||
p = p && scalar_equal(cusec);
|
||||
p = p && scalar_equal(ctime);
|
||||
p = p && scalar_equal(nonce);
|
||||
- p = p && struct_equal(paChecksum, ktest_equal_checksum);
|
||||
+ p = p && data_eq(ref->paChecksum, var->paChecksum);
|
||||
return p;
|
||||
}
|
||||
|
||||
diff --git a/src/tests/asn.1/pkinit_encode.out b/src/tests/asn.1/pkinit_encode.out
|
||||
index 6ec7aaa36a..a764182e15 100644
|
||||
--- a/src/tests/asn.1/pkinit_encode.out
|
||||
+++ b/src/tests/asn.1/pkinit_encode.out
|
||||
@@ -1,7 +1,7 @@
|
||||
encode_krb5_pa_pk_as_req: 30 38 80 08 6B 72 62 35 64 61 74 61 A1 22 30 20 30 1E 80 08 6B 72 62 35 64 61 74 61 81 08 6B 72 62 35 64 61 74 61 82 08 6B 72 62 35 64 61 74 61 82 08 6B 72 62 35 64 61 74 61
|
||||
encode_krb5_pa_pk_as_rep(dhInfo): A0 28 30 26 80 08 6B 72 62 35 64 61 74 61 A1 0A 04 08 6B 72 62 35 64 61 74 61 A2 0E 30 0C A0 0A 06 08 6B 72 62 35 64 61 74 61
|
||||
encode_krb5_pa_pk_as_rep(encKeyPack): 81 08 6B 72 62 35 64 61 74 61
|
||||
-encode_krb5_auth_pack: 30 81 85 A0 35 30 33 A0 05 02 03 01 E2 40 A1 11 18 0F 31 39 39 34 30 36 31 30 30 36 30 33 31 37 5A A2 03 02 01 2A A3 06 04 04 31 32 33 34 A4 0A 04 08 6B 72 62 35 64 61 74 61 A1 08 04 06 70 76 61 6C 75 65 A2 24 30 22 30 13 06 09 2A 86 48 86 F7 12 01 02 02 04 06 70 61 72 61 6D 73 30 0B 06 09 2A 86 48 86 F7 12 01 02 02 A3 0A 04 08 6B 72 62 35 64 61 74 61 A4 10 30 0E 30 0C A0 0A 06 08 6B 72 62 35 64 61 74 61
|
||||
+encode_krb5_auth_pack: 30 81 89 A0 39 30 37 A0 05 02 03 01 E2 40 A1 11 18 0F 31 39 39 34 30 36 31 30 30 36 30 33 31 37 5A A2 03 02 01 2A A3 0A 04 08 6B 72 62 35 64 61 74 61 A4 0A 04 08 6B 72 62 35 64 61 74 61 A1 08 04 06 70 76 61 6C 75 65 A2 24 30 22 30 13 06 09 2A 86 48 86 F7 12 01 02 02 04 06 70 61 72 61 6D 73 30 0B 06 09 2A 86 48 86 F7 12 01 02 02 A3 0A 04 08 6B 72 62 35 64 61 74 61 A4 10 30 0E 30 0C A0 0A 06 08 6B 72 62 35 64 61 74 61
|
||||
encode_krb5_kdc_dh_key_info: 30 25 A0 0B 03 09 00 6B 72 62 35 64 61 74 61 A1 03 02 01 2A A2 11 18 0F 31 39 39 34 30 36 31 30 30 36 30 33 31 37 5A
|
||||
encode_krb5_reply_key_pack: 30 26 A0 13 30 11 A0 03 02 01 01 A1 0A 04 08 31 32 33 34 35 36 37 38 A1 0F 30 0D A0 03 02 01 01 A1 06 04 04 31 32 33 34
|
||||
encode_krb5_sp80056a_other_info: 30 81 81 30 0B 06 09 2A 86 48 86 F7 12 01 02 02 A0 32 04 30 30 2E A0 10 1B 0E 41 54 48 45 4E 41 2E 4D 49 54 2E 45 44 55 A1 1A 30 18 A0 03 02 01 01 A1 11 30 0F 1B 06 68 66 74 73 61 69 1B 05 65 78 74 72 61 A1 32 04 30 30 2E A0 10 1B 0E 41 54 48 45 4E 41 2E 4D 49 54 2E 45 44 55 A1 1A 30 18 A0 03 02 01 01 A1 11 30 0F 1B 06 68 66 74 73 61 69 1B 05 65 78 74 72 61 A2 0A 04 08 6B 72 62 35 64 61 74 61
|
||||
diff --git a/src/tests/asn.1/pkinit_trval.out b/src/tests/asn.1/pkinit_trval.out
|
||||
index 46f4a34108..c47bd71f67 100644
|
||||
--- a/src/tests/asn.1/pkinit_trval.out
|
||||
+++ b/src/tests/asn.1/pkinit_trval.out
|
||||
@@ -38,7 +38,7 @@ encode_krb5_auth_pack:
|
||||
. . [0] [Integer] 123456
|
||||
. . [1] [Generalized Time] "19940610060317Z"
|
||||
. . [2] [Integer] 42
|
||||
-. . [3] [Octet String] "1234"
|
||||
+. . [3] [Octet String] "krb5data"
|
||||
. . [4] [Octet String] "krb5data"
|
||||
. [1] [Octet String] "pvalue"
|
||||
. [2] [Sequence/Sequence Of]
|
||||
--
|
||||
2.49.0
|
||||
|
||||
381
0038-downstream-Do-not-block-HMAC-MD4-5-in-FIPS-mode.patch
Normal file
381
0038-downstream-Do-not-block-HMAC-MD4-5-in-FIPS-mode.patch
Normal file
|
|
@ -0,0 +1,381 @@
|
|||
From 33afd2a6cfdf87d153170b41fbabfb92be49c422 Mon Sep 17 00:00:00 2001
|
||||
From: Julien Rische <jrische@redhat.com>
|
||||
Date: Thu, 10 Apr 2025 10:04:22 +0200
|
||||
Subject: [PATCH] [downstream] Do not block HMAC-MD4/5 in FIPS mode
|
||||
|
||||
To ensure RC4 HMAC-MD5 was not used in FIPS mode, access to HMAC-MD4/5
|
||||
was not allowed in this mode. However, since we provide the
|
||||
"radius_md5_fips_override" configuration parameter to allow using RADIUS
|
||||
regardless to the FIPS restrictions, we should allow HMAC-MD5 to be used
|
||||
too in this case, because it is required for the newly supported
|
||||
Message-Authenticator attribute.
|
||||
|
||||
A FIPS mode check is added in calculate_mac() which will fail if
|
||||
"radius_md5_fips_override" is not true. It will not affect interactions
|
||||
between krb5kdc and ipa-otpd, because the Message-Authenticator
|
||||
attribute is not generated in this case.
|
||||
---
|
||||
src/lib/crypto/krb/crypto_int.h | 9 +++
|
||||
src/lib/crypto/openssl/Makefile.in | 9 ++-
|
||||
src/lib/crypto/openssl/common.c | 80 +++++++++++++++++++
|
||||
.../crypto/openssl/hash_provider/hash_evp.c | 62 ++------------
|
||||
src/lib/crypto/openssl/hmac.c | 15 ++--
|
||||
src/lib/krad/packet.c | 19 +++--
|
||||
6 files changed, 120 insertions(+), 74 deletions(-)
|
||||
create mode 100644 src/lib/crypto/openssl/common.c
|
||||
|
||||
diff --git a/src/lib/crypto/krb/crypto_int.h b/src/lib/crypto/krb/crypto_int.h
|
||||
index 1ee4b30e02..ff67b6bd35 100644
|
||||
--- a/src/lib/crypto/krb/crypto_int.h
|
||||
+++ b/src/lib/crypto/krb/crypto_int.h
|
||||
@@ -36,6 +36,9 @@
|
||||
|
||||
#include <openssl/opensslv.h>
|
||||
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||
+
|
||||
+#include <openssl/provider.h>
|
||||
+
|
||||
/*
|
||||
* OpenSSL 3.0 relegates MD4 and RC4 to the legacy provider, which must be
|
||||
* explicitly loaded into a library context. Performing this loading within a
|
||||
@@ -660,4 +663,10 @@ iov_cursor_advance(struct iov_cursor *c, size_t nblocks)
|
||||
c->out_pos += nblocks * c->block_size;
|
||||
}
|
||||
|
||||
+#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||
+
|
||||
+krb5_error_code k5_get_ossl_legacy_libctx(OSSL_LIB_CTX **libctx);
|
||||
+
|
||||
+#endif /* OPENSSL_VERSION_NUMBER >= 0x30000000L */
|
||||
+
|
||||
#endif /* CRYPTO_INT_H */
|
||||
diff --git a/src/lib/crypto/openssl/Makefile.in b/src/lib/crypto/openssl/Makefile.in
|
||||
index 8e4cdb8bbf..cc131000bd 100644
|
||||
--- a/src/lib/crypto/openssl/Makefile.in
|
||||
+++ b/src/lib/crypto/openssl/Makefile.in
|
||||
@@ -8,21 +8,24 @@ STLIBOBJS=\
|
||||
hmac.o \
|
||||
kdf.o \
|
||||
pbkdf2.o \
|
||||
- sha256.o
|
||||
+ sha256.o \
|
||||
+ common.o
|
||||
|
||||
OBJS=\
|
||||
$(OUTPRE)cmac.$(OBJEXT) \
|
||||
$(OUTPRE)hmac.$(OBJEXT) \
|
||||
$(OUTPRE)kdf.$(OBJEXT) \
|
||||
$(OUTPRE)pbkdf2.$(OBJEXT) \
|
||||
- $(OUTPRE)sha256.$(OBJEXT)
|
||||
+ $(OUTPRE)sha256.$(OBJEXT) \
|
||||
+ $(OUTPRE)common.$(OBJEXT)
|
||||
|
||||
SRCS=\
|
||||
$(srcdir)/cmac.c \
|
||||
$(srcdir)/hmac.c \
|
||||
$(srcdir)/kdf.c \
|
||||
$(srcdir)/pbkdf2.c \
|
||||
- $(srcdir)/sha256.c
|
||||
+ $(srcdir)/sha256.c \
|
||||
+ $(srcdir)/common.c
|
||||
|
||||
SUBDIROBJLISTS= md4/OBJS.ST \
|
||||
md5/OBJS.ST sha1/OBJS.ST sha2/OBJS.ST \
|
||||
diff --git a/src/lib/crypto/openssl/common.c b/src/lib/crypto/openssl/common.c
|
||||
new file mode 100644
|
||||
index 0000000000..ced43fd54c
|
||||
--- /dev/null
|
||||
+++ b/src/lib/crypto/openssl/common.c
|
||||
@@ -0,0 +1,80 @@
|
||||
+#include "crypto_int.h"
|
||||
+
|
||||
+#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||
+
|
||||
+#include <openssl/provider.h>
|
||||
+#include <openssl/fips.h>
|
||||
+#include <threads.h>
|
||||
+#include <stdbool.h>
|
||||
+
|
||||
+typedef struct ossl_legacy_context {
|
||||
+ bool initialized;
|
||||
+ OSSL_LIB_CTX *libctx;
|
||||
+ OSSL_PROVIDER *default_provider;
|
||||
+ OSSL_PROVIDER *legacy_provider;
|
||||
+} ossl_legacy_context_t;
|
||||
+
|
||||
+static thread_local ossl_legacy_context_t g_ossl_legacy_ctx;
|
||||
+
|
||||
+static krb5_error_code
|
||||
+init_ossl_legacy_ctx(ossl_legacy_context_t *ctx)
|
||||
+{
|
||||
+ ctx->libctx = OSSL_LIB_CTX_new();
|
||||
+ if (!ctx->libctx)
|
||||
+ return KRB5_CRYPTO_INTERNAL;
|
||||
+
|
||||
+ /* Load both legacy and default provider as both may be needed. */
|
||||
+ ctx->default_provider = OSSL_PROVIDER_load(ctx->libctx, "default");
|
||||
+ ctx->legacy_provider = OSSL_PROVIDER_load(ctx->libctx, "legacy");
|
||||
+
|
||||
+ if (!(ctx->default_provider && ctx->legacy_provider))
|
||||
+ return KRB5_CRYPTO_INTERNAL;
|
||||
+
|
||||
+ ctx->initialized = true;
|
||||
+ return 0;
|
||||
+}
|
||||
+
|
||||
+static void
|
||||
+deinit_ossl_legacy_ctx(ossl_legacy_context_t *ctx)
|
||||
+{
|
||||
+ if (ctx->legacy_provider)
|
||||
+ OSSL_PROVIDER_unload(ctx->legacy_provider);
|
||||
+
|
||||
+ if (ctx->default_provider)
|
||||
+ OSSL_PROVIDER_unload(ctx->default_provider);
|
||||
+
|
||||
+ if (ctx->libctx)
|
||||
+ OSSL_LIB_CTX_free(ctx->libctx);
|
||||
+
|
||||
+ ctx->initialized = false;
|
||||
+}
|
||||
+
|
||||
+krb5_error_code
|
||||
+k5_get_ossl_legacy_libctx(OSSL_LIB_CTX **libctx)
|
||||
+{
|
||||
+ krb5_error_code err;
|
||||
+
|
||||
+ if (!FIPS_mode()) {
|
||||
+ if (libctx)
|
||||
+ *libctx = NULL;
|
||||
+ err = 0;
|
||||
+ goto end;
|
||||
+ }
|
||||
+
|
||||
+ if (!g_ossl_legacy_ctx.initialized) {
|
||||
+ err = init_ossl_legacy_ctx(&g_ossl_legacy_ctx);
|
||||
+ if (err) {
|
||||
+ deinit_ossl_legacy_ctx(&g_ossl_legacy_ctx);
|
||||
+ goto end;
|
||||
+ }
|
||||
+ }
|
||||
+
|
||||
+ if (libctx)
|
||||
+ *libctx = g_ossl_legacy_ctx.libctx;
|
||||
+ err = 0;
|
||||
+
|
||||
+end:
|
||||
+ return err;
|
||||
+}
|
||||
+
|
||||
+#endif /* OPENSSL_VERSION_NUMBER >= 0x30000000L */
|
||||
diff --git a/src/lib/crypto/openssl/hash_provider/hash_evp.c b/src/lib/crypto/openssl/hash_provider/hash_evp.c
|
||||
index eb2e693e9f..2fd5d383d6 100644
|
||||
--- a/src/lib/crypto/openssl/hash_provider/hash_evp.c
|
||||
+++ b/src/lib/crypto/openssl/hash_provider/hash_evp.c
|
||||
@@ -44,48 +44,7 @@
|
||||
#define EVP_MD_CTX_free EVP_MD_CTX_destroy
|
||||
#endif
|
||||
|
||||
-#include <openssl/provider.h>
|
||||
#include <openssl/fips.h>
|
||||
-#include <threads.h>
|
||||
-
|
||||
-typedef struct ossl_lib_md_context {
|
||||
- OSSL_LIB_CTX *libctx;
|
||||
- OSSL_PROVIDER *default_provider;
|
||||
- OSSL_PROVIDER *legacy_provider;
|
||||
-} ossl_md_context_t;
|
||||
-
|
||||
-static thread_local ossl_md_context_t *ossl_md_ctx = NULL;
|
||||
-
|
||||
-static krb5_error_code
|
||||
-init_ossl_md_ctx(ossl_md_context_t *ctx, const char *algo)
|
||||
-{
|
||||
- ctx->libctx = OSSL_LIB_CTX_new();
|
||||
- if (!ctx->libctx)
|
||||
- return KRB5_CRYPTO_INTERNAL;
|
||||
-
|
||||
- /* Load both legacy and default provider as both may be needed. */
|
||||
- ctx->default_provider = OSSL_PROVIDER_load(ctx->libctx, "default");
|
||||
- ctx->legacy_provider = OSSL_PROVIDER_load(ctx->libctx, "legacy");
|
||||
-
|
||||
- if (!(ctx->default_provider && ctx->legacy_provider))
|
||||
- return KRB5_CRYPTO_INTERNAL;
|
||||
-
|
||||
- return 0;
|
||||
-}
|
||||
-
|
||||
-static void
|
||||
-deinit_ossl_ctx(ossl_md_context_t *ctx)
|
||||
-{
|
||||
- if (ctx->legacy_provider)
|
||||
- OSSL_PROVIDER_unload(ctx->legacy_provider);
|
||||
-
|
||||
- if (ctx->default_provider)
|
||||
- OSSL_PROVIDER_unload(ctx->default_provider);
|
||||
-
|
||||
- if (ctx->libctx)
|
||||
- OSSL_LIB_CTX_free(ctx->libctx);
|
||||
-}
|
||||
-
|
||||
|
||||
static krb5_error_code
|
||||
hash_evp(const EVP_MD *type, const krb5_crypto_iov *data, size_t num_data,
|
||||
@@ -120,25 +79,14 @@ hash_legacy_evp(const char *algo, const krb5_crypto_iov *data, size_t num_data,
|
||||
krb5_data *output)
|
||||
{
|
||||
krb5_error_code err;
|
||||
+ OSSL_LIB_CTX *ossl_libctx;
|
||||
EVP_MD *md = NULL;
|
||||
|
||||
- if (!ossl_md_ctx) {
|
||||
- ossl_md_ctx = malloc(sizeof(ossl_md_context_t));
|
||||
- if (!ossl_md_ctx) {
|
||||
- err = ENOMEM;
|
||||
- goto end;
|
||||
- }
|
||||
-
|
||||
- err = init_ossl_md_ctx(ossl_md_ctx, algo);
|
||||
- if (err) {
|
||||
- deinit_ossl_ctx(ossl_md_ctx);
|
||||
- free(ossl_md_ctx);
|
||||
- ossl_md_ctx = NULL;
|
||||
- goto end;
|
||||
- }
|
||||
- }
|
||||
+ err = k5_get_ossl_legacy_libctx(&ossl_libctx);
|
||||
+ if (err)
|
||||
+ goto end;
|
||||
|
||||
- md = EVP_MD_fetch(ossl_md_ctx->libctx, algo, NULL);
|
||||
+ md = EVP_MD_fetch(ossl_libctx, algo, NULL);
|
||||
if (!md) {
|
||||
err = KRB5_CRYPTO_INTERNAL;
|
||||
goto end;
|
||||
diff --git a/src/lib/crypto/openssl/hmac.c b/src/lib/crypto/openssl/hmac.c
|
||||
index 25a419d73a..8f9e88fec9 100644
|
||||
--- a/src/lib/crypto/openssl/hmac.c
|
||||
+++ b/src/lib/crypto/openssl/hmac.c
|
||||
@@ -59,7 +59,6 @@
|
||||
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||
#include <openssl/params.h>
|
||||
#include <openssl/core_names.h>
|
||||
-#include <openssl/fips.h>
|
||||
#else
|
||||
#include <openssl/hmac.h>
|
||||
#endif
|
||||
@@ -112,11 +111,7 @@ map_digest(const struct krb5_hash_provider *hash)
|
||||
return EVP_sha256();
|
||||
else if (hash == &krb5int_hash_sha384)
|
||||
return EVP_sha384();
|
||||
-
|
||||
- if (FIPS_mode())
|
||||
- return NULL;
|
||||
-
|
||||
- if (hash == &krb5int_hash_md5)
|
||||
+ else if (hash == &krb5int_hash_md5)
|
||||
return EVP_md5();
|
||||
else if (hash == &krb5int_hash_md4)
|
||||
return EVP_md4();
|
||||
@@ -138,13 +133,19 @@ krb5int_hmac_keyblock(const struct krb5_hash_provider *hash,
|
||||
EVP_MAC_CTX *ctx = NULL;
|
||||
OSSL_PARAM params[2], *p = params;
|
||||
size_t i = 0, md_len;
|
||||
+ OSSL_LIB_CTX *ossl_libctx;
|
||||
+ krb5_error_code err;
|
||||
|
||||
if (md == NULL || keyblock->length > hash->blocksize)
|
||||
return KRB5_CRYPTO_INTERNAL;
|
||||
if (output->length < hash->hashsize)
|
||||
return KRB5_BAD_MSIZE;
|
||||
|
||||
- mac = EVP_MAC_fetch(NULL, "HMAC", NULL);
|
||||
+ err = k5_get_ossl_legacy_libctx(&ossl_libctx);
|
||||
+ if (err)
|
||||
+ return err;
|
||||
+
|
||||
+ mac = EVP_MAC_fetch(ossl_libctx, "HMAC", NULL);
|
||||
if (mac == NULL)
|
||||
return KRB5_CRYPTO_INTERNAL;
|
||||
|
||||
diff --git a/src/lib/krad/packet.c b/src/lib/krad/packet.c
|
||||
index 3c1a4d507e..b95c99df65 100644
|
||||
--- a/src/lib/krad/packet.c
|
||||
+++ b/src/lib/krad/packet.c
|
||||
@@ -278,7 +278,7 @@ lookup_msgauth_addr(const krad_packet *pkt)
|
||||
* auth, which may be from pkt or from a corresponding request.
|
||||
*/
|
||||
static krb5_error_code
|
||||
-calculate_mac(const char *secret, const krad_packet *pkt,
|
||||
+calculate_mac(krb5_context ctx, const char *secret, const krad_packet *pkt,
|
||||
const uint8_t auth[AUTH_FIELD_SIZE],
|
||||
uint8_t mac_out[MD5_DIGEST_SIZE])
|
||||
{
|
||||
@@ -288,6 +288,10 @@ calculate_mac(const char *secret, const krad_packet *pkt,
|
||||
krb5_crypto_iov input[5];
|
||||
krb5_data ksecr, mac;
|
||||
|
||||
+ /* Do not use HMAC-MD5 if not explicitly allowed */
|
||||
+ if (kr_use_fips(ctx))
|
||||
+ return KRB5_CRYPTO_INTERNAL;
|
||||
+
|
||||
msgauth_attr = lookup_msgauth_addr(pkt);
|
||||
if (msgauth_attr == NULL)
|
||||
return EINVAL;
|
||||
@@ -393,7 +397,8 @@ krad_packet_new_request(krb5_context ctx, const char *secret, krad_code code,
|
||||
|
||||
if (msgauth_required) {
|
||||
/* Calculate and set the Message-Authenticator MAC. */
|
||||
- retval = calculate_mac(secret, pkt, pkt_auth(pkt), pkt_attr(pkt) + 2);
|
||||
+ retval = calculate_mac(ctx, secret, pkt, pkt_auth(pkt),
|
||||
+ pkt_attr(pkt) + 2);
|
||||
if (retval != 0)
|
||||
goto error;
|
||||
}
|
||||
@@ -454,7 +459,7 @@ krad_packet_new_response(krb5_context ctx, const char *secret, krad_code code,
|
||||
* section 5.14, use the authenticator from the request, not from the
|
||||
* response.
|
||||
*/
|
||||
- retval = calculate_mac(secret, pkt, pkt_auth(request),
|
||||
+ retval = calculate_mac(ctx, secret, pkt, pkt_auth(request),
|
||||
pkt_attr(pkt) + 2);
|
||||
if (retval != 0)
|
||||
goto error;
|
||||
@@ -476,7 +481,7 @@ error:
|
||||
/* Verify the Message-Authenticator value in pkt, using the provided
|
||||
* authenticator (which may be from pkt or from a corresponding request). */
|
||||
static krb5_error_code
|
||||
-verify_msgauth(const char *secret, const krad_packet *pkt,
|
||||
+verify_msgauth(krb5_context ctx, const char *secret, const krad_packet *pkt,
|
||||
const uint8_t auth[AUTH_FIELD_SIZE])
|
||||
{
|
||||
uint8_t mac[MD5_DIGEST_SIZE];
|
||||
@@ -488,7 +493,7 @@ verify_msgauth(const char *secret, const krad_packet *pkt,
|
||||
if (msgauth == NULL)
|
||||
return ENODATA;
|
||||
|
||||
- retval = calculate_mac(secret, pkt, auth, mac);
|
||||
+ retval = calculate_mac(ctx, secret, pkt, auth, mac);
|
||||
if (retval)
|
||||
return retval;
|
||||
|
||||
@@ -561,7 +566,7 @@ krad_packet_decode_request(krb5_context ctx, const char *secret,
|
||||
|
||||
/* Verify Message-Authenticator if present. */
|
||||
if (has_pkt_msgauth(req)) {
|
||||
- retval = verify_msgauth(secret, req, pkt_auth(req));
|
||||
+ retval = verify_msgauth(ctx, secret, req, pkt_auth(req));
|
||||
if (retval) {
|
||||
krad_packet_free(req);
|
||||
return retval;
|
||||
@@ -613,7 +618,7 @@ krad_packet_decode_response(krb5_context ctx, const char *secret,
|
||||
|
||||
/* Verify Message-Authenticator if present. */
|
||||
if (has_pkt_msgauth(*rsppkt)) {
|
||||
- if (verify_msgauth(secret, *rsppkt, pkt_auth(tmp)) != 0)
|
||||
+ if (verify_msgauth(ctx, secret, *rsppkt, pkt_auth(tmp)) != 0)
|
||||
continue;
|
||||
}
|
||||
|
||||
--
|
||||
2.49.0
|
||||
|
||||
189
0039-Fix-strchr-conformance-to-C23.patch
Normal file
189
0039-Fix-strchr-conformance-to-C23.patch
Normal file
|
|
@ -0,0 +1,189 @@
|
|||
From 1761e06398e4f043e4f540f57131c37fcc53a1b9 Mon Sep 17 00:00:00 2001
|
||||
From: Alexander Bokovoy <abokovoy@redhat.com>
|
||||
Date: Wed, 10 Dec 2025 10:42:02 +0200
|
||||
Subject: [PATCH] Fix strchr() conformance to C23
|
||||
|
||||
C23 7.28.5.1 specifies search functions such as strchr() as generic,
|
||||
returning const char * if the first argument is of type const char *.
|
||||
Fix uses of strchr() to conform to this change.
|
||||
|
||||
[jrische@redhat.com: altered changes to avoid casts; fixed an
|
||||
additional case]
|
||||
[ghudson@mit.edu: condensed some declarations; rewrote commit message]
|
||||
|
||||
ticket: 9191 (new)
|
||||
(cherry picked from commit 6cd8580d823585d50ee4f30efd9f7e855823a369)
|
||||
---
|
||||
src/lib/krb5/ccache/ccbase.c | 4 ++--
|
||||
src/lib/krb5/os/expand_path.c | 3 ++-
|
||||
src/lib/krb5/os/locate_kdc.c | 15 +++++++--------
|
||||
src/plugins/preauth/pkinit/pkinit_crypto.h | 2 +-
|
||||
.../preauth/pkinit/pkinit_crypto_openssl.c | 6 +++---
|
||||
src/plugins/preauth/pkinit/pkinit_identity.c | 2 +-
|
||||
src/plugins/preauth/pkinit/pkinit_matching.c | 2 +-
|
||||
src/tests/responder.c | 3 +--
|
||||
8 files changed, 18 insertions(+), 19 deletions(-)
|
||||
|
||||
diff --git a/src/lib/krb5/ccache/ccbase.c b/src/lib/krb5/ccache/ccbase.c
|
||||
index 5a01320832..1aada91b5e 100644
|
||||
--- a/src/lib/krb5/ccache/ccbase.c
|
||||
+++ b/src/lib/krb5/ccache/ccbase.c
|
||||
@@ -201,8 +201,8 @@ krb5_cc_register(krb5_context context, const krb5_cc_ops *ops,
|
||||
krb5_error_code KRB5_CALLCONV
|
||||
krb5_cc_resolve (krb5_context context, const char *name, krb5_ccache *cache)
|
||||
{
|
||||
- char *pfx, *cp;
|
||||
- const char *resid;
|
||||
+ char *pfx;
|
||||
+ const char *cp, *resid;
|
||||
unsigned int pfxlen;
|
||||
krb5_error_code err;
|
||||
const krb5_cc_ops *ops;
|
||||
diff --git a/src/lib/krb5/os/expand_path.c b/src/lib/krb5/os/expand_path.c
|
||||
index 5cbccf08c8..6569b8820b 100644
|
||||
--- a/src/lib/krb5/os/expand_path.c
|
||||
+++ b/src/lib/krb5/os/expand_path.c
|
||||
@@ -454,7 +454,8 @@ k5_expand_path_tokens_extra(krb5_context context, const char *path_in,
|
||||
{
|
||||
krb5_error_code ret;
|
||||
struct k5buf buf;
|
||||
- char *tok_begin, *tok_end, *tok_val, **extra_tokens = NULL, *path;
|
||||
+ const char *tok_begin, *tok_end;
|
||||
+ char *tok_val, **extra_tokens = NULL, *path;
|
||||
const char *path_left;
|
||||
size_t nargs = 0, i;
|
||||
va_list ap;
|
||||
diff --git a/src/lib/krb5/os/locate_kdc.c b/src/lib/krb5/os/locate_kdc.c
|
||||
index edca5ac7eb..47e15c849f 100644
|
||||
--- a/src/lib/krb5/os/locate_kdc.c
|
||||
+++ b/src/lib/krb5/os/locate_kdc.c
|
||||
@@ -188,8 +188,8 @@ oom:
|
||||
}
|
||||
|
||||
static void
|
||||
-parse_uri_if_https(const char *host_or_uri, k5_transport *transport,
|
||||
- const char **host, const char **uri_path)
|
||||
+parse_uri_if_https(char *host_or_uri, k5_transport *transport,
|
||||
+ char **host, const char **uri_path)
|
||||
{
|
||||
char *cp;
|
||||
|
||||
@@ -229,8 +229,7 @@ locate_srv_conf_1(krb5_context context, const krb5_data *realm,
|
||||
k5_transport transport, int udpport)
|
||||
{
|
||||
const char *realm_srv_names[4];
|
||||
- char **hostlist = NULL, *realmstr = NULL, *host = NULL;
|
||||
- const char *hostspec;
|
||||
+ char **hostlist = NULL, *realmstr = NULL, *host = NULL, *hostspec;
|
||||
krb5_error_code code;
|
||||
int i, default_port;
|
||||
|
||||
@@ -535,8 +534,8 @@ prof_locate_server(krb5_context context, const krb5_data *realm,
|
||||
* Return a NULL *host_out if there are any problems parsing the URI.
|
||||
*/
|
||||
static void
|
||||
-parse_uri_fields(const char *uri, k5_transport *transport_out,
|
||||
- const char **host_out, int *primary_out)
|
||||
+parse_uri_fields(char *uri, k5_transport *transport_out,
|
||||
+ char **host_out, int *primary_out)
|
||||
|
||||
{
|
||||
k5_transport transport;
|
||||
@@ -604,8 +603,8 @@ locate_uri(krb5_context context, const krb5_data *realm,
|
||||
krb5_error_code ret;
|
||||
k5_transport transport, host_trans;
|
||||
struct srv_dns_entry *answers, *entry;
|
||||
- char *host;
|
||||
- const char *host_field, *path;
|
||||
+ char *host, *host_field;
|
||||
+ const char *path;
|
||||
int port, def_port, primary;
|
||||
|
||||
ret = k5_make_uri_query(context, realm, req_service, &answers);
|
||||
diff --git a/src/plugins/preauth/pkinit/pkinit_crypto.h b/src/plugins/preauth/pkinit/pkinit_crypto.h
|
||||
index 3b12e904b1..99e2394040 100644
|
||||
--- a/src/plugins/preauth/pkinit/pkinit_crypto.h
|
||||
+++ b/src/plugins/preauth/pkinit/pkinit_crypto.h
|
||||
@@ -456,7 +456,7 @@ krb5_error_code crypto_load_cas_and_crls
|
||||
defines the storage type (file, directory, etc) */
|
||||
int catype, /* IN
|
||||
defines the ca type (anchor, intermediate, crls) */
|
||||
- char *id); /* IN
|
||||
+ const char *id); /* IN
|
||||
defines the location (filename, directory name, etc) */
|
||||
|
||||
/*
|
||||
diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c
|
||||
index 429b7d202c..6013080afc 100644
|
||||
--- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c
|
||||
+++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c
|
||||
@@ -4956,7 +4956,7 @@ load_cas_and_crls(krb5_context context,
|
||||
pkinit_req_crypto_context req_cryptoctx,
|
||||
pkinit_identity_crypto_context id_cryptoctx,
|
||||
int catype,
|
||||
- char *filename)
|
||||
+ const char *filename)
|
||||
{
|
||||
STACK_OF(X509_INFO) *sk = NULL;
|
||||
STACK_OF(X509) *ca_certs = NULL;
|
||||
@@ -5114,7 +5114,7 @@ load_cas_and_crls_dir(krb5_context context,
|
||||
pkinit_req_crypto_context req_cryptoctx,
|
||||
pkinit_identity_crypto_context id_cryptoctx,
|
||||
int catype,
|
||||
- char *dirname)
|
||||
+ const char *dirname)
|
||||
{
|
||||
krb5_error_code retval = EINVAL;
|
||||
DIR *d = NULL;
|
||||
@@ -5166,7 +5166,7 @@ crypto_load_cas_and_crls(krb5_context context,
|
||||
pkinit_identity_crypto_context id_cryptoctx,
|
||||
int idtype,
|
||||
int catype,
|
||||
- char *id)
|
||||
+ const char *id)
|
||||
{
|
||||
switch (idtype) {
|
||||
case IDTYPE_FILE:
|
||||
diff --git a/src/plugins/preauth/pkinit/pkinit_identity.c b/src/plugins/preauth/pkinit/pkinit_identity.c
|
||||
index a5a979f279..b06d519c66 100644
|
||||
--- a/src/plugins/preauth/pkinit/pkinit_identity.c
|
||||
+++ b/src/plugins/preauth/pkinit/pkinit_identity.c
|
||||
@@ -474,7 +474,7 @@ process_option_ca_crl(krb5_context context,
|
||||
const char *value,
|
||||
int catype)
|
||||
{
|
||||
- char *residual;
|
||||
+ const char *residual;
|
||||
unsigned int typelen;
|
||||
int idtype;
|
||||
|
||||
diff --git a/src/plugins/preauth/pkinit/pkinit_matching.c b/src/plugins/preauth/pkinit/pkinit_matching.c
|
||||
index b42485a50a..5a7f2ba3fa 100644
|
||||
--- a/src/plugins/preauth/pkinit/pkinit_matching.c
|
||||
+++ b/src/plugins/preauth/pkinit/pkinit_matching.c
|
||||
@@ -263,7 +263,7 @@ parse_rule_component(krb5_context context,
|
||||
char err_buf[128];
|
||||
int ret;
|
||||
struct keyword_desc *kw, *nextkw;
|
||||
- char *nk;
|
||||
+ const char *nk;
|
||||
int found_next_kw = 0;
|
||||
char *value = NULL;
|
||||
size_t len;
|
||||
diff --git a/src/tests/responder.c b/src/tests/responder.c
|
||||
index 82f870ea5d..4221a20283 100644
|
||||
--- a/src/tests/responder.c
|
||||
+++ b/src/tests/responder.c
|
||||
@@ -282,8 +282,7 @@ responder(krb5_context ctx, void *rawdata, krb5_responder_context rctx)
|
||||
/* Provide a particular response for an OTP challenge. */
|
||||
if (data->otp_answer != NULL) {
|
||||
if (krb5_responder_otp_get_challenge(ctx, rctx, &ochl) == 0) {
|
||||
- key = strchr(data->otp_answer, '=');
|
||||
- if (key != NULL) {
|
||||
+ if (strchr(data->otp_answer, '=') != NULL) {
|
||||
/* Make a copy of the answer that we can chop up. */
|
||||
key = strdup(data->otp_answer);
|
||||
if (key == NULL)
|
||||
--
|
||||
2.51.1
|
||||
|
||||
226
0040-automated-fast.patch
Normal file
226
0040-automated-fast.patch
Normal file
|
|
@ -0,0 +1,226 @@
|
|||
From 3baf9b93dc1dfe38585722c71d7268304cb4a01a Mon Sep 17 00:00:00 2001
|
||||
From: Alexander Bokovoy <abokovoy@redhat.com>
|
||||
Date: Sun, 21 Sep 2025 11:14:51 +0300
|
||||
Subject: libkrb5: in case PKINIT is configured, attempt Anonymous
|
||||
PKINIT for FAST
|
||||
|
||||
If auto_fast_armor is configured for the realm or globally, optimistically
|
||||
assume that Anonymous PKINIT is supported as well and try to obtain it for
|
||||
FAST use in case no pre-made FAST channel was established by the caller.
|
||||
|
||||
This behavior will automatically enable use of passwordless pre-authentication
|
||||
methods which rely on FAST channel presence in deployments such as FreeIPA.
|
||||
|
||||
Notably, Microsoft Active Directory KDCs do not support Anonymous PKINIT. For
|
||||
these deployments only a machine account (host keytab) can be used to build a
|
||||
FAST channel. However, libkrb5 does not have access to /etc/krb5.keytab in a
|
||||
general case.
|
||||
|
||||
Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
|
||||
---
|
||||
src/lib/krb5/krb/fast.c | 118 ++++++++++++++++++++++++++++++++++++++++
|
||||
src/lib/krb5/krb/fast.h | 2 +
|
||||
src/man/krb5.conf.man | 13 +++++
|
||||
3 files changed, 133 insertions(+)
|
||||
|
||||
diff --git a/src/lib/krb5/krb/fast.c b/src/lib/krb5/krb/fast.c
|
||||
index 62c9f0841..ee2e08189 100644
|
||||
--- a/src/lib/krb5/krb/fast.c
|
||||
+++ b/src/lib/krb5/krb/fast.c
|
||||
@@ -168,6 +168,109 @@ krb5int_fast_prep_req_body(krb5_context context,
|
||||
return retval;
|
||||
}
|
||||
|
||||
+static krb5_boolean
|
||||
+fast_is_pkinit_allowed(krb5_context context, krb5_data *realm)
|
||||
+{
|
||||
+ int value;
|
||||
+ krb5_error_code retval = EINVAL;
|
||||
+ char realmstr[1024];
|
||||
+ const char *option = "auto_fast_armor";
|
||||
+ const int def_value = FALSE;
|
||||
+
|
||||
+ if (realm != NULL && realm->length > sizeof(realmstr)-1)
|
||||
+ return FALSE;
|
||||
+
|
||||
+ if (realm != NULL) {
|
||||
+ strncpy(realmstr, realm->data, realm->length);
|
||||
+ realmstr[realm->length] = '\0';
|
||||
+
|
||||
+ retval = profile_get_boolean(context->profile,
|
||||
+ KRB5_CONF_REALMS, realmstr,
|
||||
+ option, def_value, &value);
|
||||
+ }
|
||||
+
|
||||
+ return retval ? FALSE : value;
|
||||
+
|
||||
+}
|
||||
+
|
||||
+static krb5_error_code
|
||||
+fast_acquire_pkinit_armor(krb5_context context,
|
||||
+ struct krb5int_fast_request_state *state,
|
||||
+ krb5_get_init_creds_opt *opt, krb5_kdc_req *request)
|
||||
+{
|
||||
+ krb5_context ctx;
|
||||
+ krb5_get_init_creds_opt *options = NULL;
|
||||
+ krb5_error_code retval = 0;
|
||||
+ krb5_data *target_realm = &request->server->realm;
|
||||
+ krb5_creds creds;
|
||||
+ krb5_principal anon_princ = NULL;
|
||||
+ krb5_ccache out_cc;
|
||||
+
|
||||
+ /* short circuit, we are asked to perform Anonymous PKINIT already */
|
||||
+ if (opt->flags & KRB5_GET_INIT_CREDS_OPT_ANONYMOUS) {
|
||||
+ return EINVAL;
|
||||
+ }
|
||||
+
|
||||
+ /* skip realms which do not allow use of automated FAST armor */
|
||||
+ if (!fast_is_pkinit_allowed(context, target_realm)) {
|
||||
+ return EINVAL;
|
||||
+ }
|
||||
+
|
||||
+ retval = krb5_init_context(&ctx);
|
||||
+ if (retval != 0) {
|
||||
+ return retval;
|
||||
+ }
|
||||
+ retval = krb5_get_init_creds_opt_alloc(ctx, &options);
|
||||
+ if (retval != 0) {
|
||||
+ goto cleanup;
|
||||
+ }
|
||||
+ krb5_get_init_creds_opt_set_anonymous(options, 1);
|
||||
+ retval = krb5_cc_new_unique(ctx, "MEMORY", NULL, &out_cc);
|
||||
+ if (retval != 0) {
|
||||
+ goto cleanup;
|
||||
+ }
|
||||
+
|
||||
+ retval = krb5_get_init_creds_opt_set_out_ccache(ctx, options, out_cc);
|
||||
+ if (retval != 0) {
|
||||
+ goto cleanup;
|
||||
+ }
|
||||
+
|
||||
+ retval = krb5_build_principal_ext(ctx, &anon_princ,
|
||||
+ target_realm->length, target_realm->data,
|
||||
+ strlen(KRB5_WELLKNOWN_NAMESTR),
|
||||
+ KRB5_WELLKNOWN_NAMESTR,
|
||||
+ strlen(KRB5_ANONYMOUS_PRINCSTR),
|
||||
+ KRB5_ANONYMOUS_PRINCSTR, 0);
|
||||
+ if (retval != 0) {
|
||||
+ goto cleanup;
|
||||
+ }
|
||||
+
|
||||
+ retval = krb5_get_init_creds_password(ctx, &creds, anon_princ, 0,
|
||||
+ NULL /* no prompter */, NULL,
|
||||
+ 0, NULL /* service name */,
|
||||
+ options);
|
||||
+ if (retval == 0) {
|
||||
+ state->fast_state_flags |= KRB5INT_FAST_OWN_ARMOR;
|
||||
+ state->armor_ccache = out_cc;
|
||||
+ }
|
||||
+cleanup:
|
||||
+ if (retval != 0 && out_cc != NULL) {
|
||||
+ (void) krb5_cc_destroy(ctx, out_cc);
|
||||
+ }
|
||||
+ if (retval == 0) {
|
||||
+ krb5_free_cred_contents(ctx, &creds);
|
||||
+ }
|
||||
+ if (options != NULL) {
|
||||
+ krb5_get_init_creds_opt_free(ctx, options);
|
||||
+ }
|
||||
+ if (anon_princ != NULL) {
|
||||
+ krb5_free_principal(ctx, anon_princ);
|
||||
+ }
|
||||
+ krb5_free_context(ctx);
|
||||
+
|
||||
+ return retval;
|
||||
+}
|
||||
+
|
||||
krb5_error_code
|
||||
krb5int_fast_as_armor(krb5_context context,
|
||||
struct krb5int_fast_request_state *state,
|
||||
@@ -178,10 +281,20 @@ krb5int_fast_as_armor(krb5_context context,
|
||||
krb5_principal target_principal = NULL;
|
||||
krb5_data *target_realm;
|
||||
const char *ccname = k5_gic_opt_get_fast_ccache_name(opt);
|
||||
+ char *fast_ccname = NULL;
|
||||
krb5_flags fast_flags;
|
||||
|
||||
krb5_clear_error_message(context);
|
||||
target_realm = &request->server->realm;
|
||||
+ if (ccname == NULL) {
|
||||
+ retval = fast_acquire_pkinit_armor(context, state, opt, request);
|
||||
+ if (retval == 0) {
|
||||
+ retval = krb5_cc_get_full_name(context, state->armor_ccache, &fast_ccname);
|
||||
+ if (retval == 0 && fast_ccname != NULL)
|
||||
+ ccname = fast_ccname;
|
||||
+ }
|
||||
+ retval = 0;
|
||||
+ }
|
||||
if (ccname != NULL) {
|
||||
TRACE_FAST_ARMOR_CCACHE(context, ccname);
|
||||
state->fast_state_flags |= KRB5INT_FAST_ARMOR_AVAIL;
|
||||
@@ -220,6 +333,8 @@ krb5int_fast_as_armor(krb5_context context,
|
||||
krb5_cc_close(context, ccache);
|
||||
if (target_principal)
|
||||
krb5_free_principal(context, target_principal);
|
||||
+ if (fast_ccname)
|
||||
+ free(fast_ccname);
|
||||
return retval;
|
||||
}
|
||||
|
||||
@@ -615,6 +730,9 @@ krb5int_fast_free_state(krb5_context context,
|
||||
/*We are responsible for none of the store in the fast_outer_req*/
|
||||
krb5_free_keyblock(context, state->armor_key);
|
||||
krb5_free_fast_armor(context, state->armor);
|
||||
+ if (state->fast_state_flags & KRB5INT_FAST_OWN_ARMOR) {
|
||||
+ krb5_cc_destroy(context, state->armor_ccache);
|
||||
+ }
|
||||
free(state);
|
||||
}
|
||||
|
||||
diff --git a/src/lib/krb5/krb/fast.h b/src/lib/krb5/krb/fast.h
|
||||
index 7156ea203..e5fe8bd54 100644
|
||||
--- a/src/lib/krb5/krb/fast.h
|
||||
+++ b/src/lib/krb5/krb/fast.h
|
||||
@@ -34,6 +34,7 @@ struct krb5int_fast_request_state {
|
||||
krb5_kdc_req fast_outer_request;
|
||||
krb5_keyblock *armor_key; /*non-null means fast is in use*/
|
||||
krb5_fast_armor *armor;
|
||||
+ krb5_ccache armor_ccache;
|
||||
krb5_ui_4 fast_state_flags;
|
||||
krb5_ui_4 fast_options;
|
||||
krb5_int32 nonce;
|
||||
@@ -41,6 +42,7 @@ struct krb5int_fast_request_state {
|
||||
|
||||
#define KRB5INT_FAST_DO_FAST (1l<<0) /* Perform FAST */
|
||||
#define KRB5INT_FAST_ARMOR_AVAIL (1l<<1)
|
||||
+#define KRB5INT_FAST_OWN_ARMOR (1l<<2)
|
||||
|
||||
krb5_error_code
|
||||
krb5int_fast_prep_req_body(krb5_context context,
|
||||
diff --git a/src/man/krb5.conf.man b/src/man/krb5.conf.man
|
||||
index d4caa2bd3..ac7649647 100644
|
||||
--- a/src/man/krb5.conf.man
|
||||
+++ b/src/man/krb5.conf.man
|
||||
@@ -650,6 +650,19 @@ primary KDC, in case the user\(aqs password has just been changed, and
|
||||
the updated database has not been propagated to the replica
|
||||
servers yet. New in release 1.19.
|
||||
.TP
|
||||
+\fBauto_fast_armor\fP
|
||||
+If this flag is true, then initial ticket request will use Anonymous
|
||||
+PKINIT to protect the communication as a FAST channel in case an application
|
||||
+did not provide its own FAST channel. This is useful for deployments where
|
||||
+pre-authentication methods require use of the FAST channel, such as
|
||||
+passwordless methods provided by FreeIPA. Microsoft Active Directory
|
||||
+implementation of PKINIT does not support Anonymous PKINIT feature.
|
||||
+As a result, \fIauto_fast_armor\fP defaults to false.
|
||||
+.sp
|
||||
+Use of \fIauto_fast_armor = true\fP requires properly configured PKINIT and
|
||||
+WELLKNOWN/ANONYMOUS principal defined on the KDC side. Consult KDC documentation
|
||||
+for details.
|
||||
+.TP
|
||||
\fBv4_instance_convert\fP
|
||||
This subsection allows the administrator to configure exceptions
|
||||
to the \fBdefault_domain\fP mapping rule. It contains V4 instances
|
||||
--
|
||||
2.51.0
|
||||
|
||||
40
0041-bail-if-prompter-is-not-specified-but-required.patch
Normal file
40
0041-bail-if-prompter-is-not-specified-but-required.patch
Normal file
|
|
@ -0,0 +1,40 @@
|
|||
From ff580d9cf86202d45454a6b6f53accc22cb40b62 Mon Sep 17 00:00:00 2001
|
||||
From: Alexander Bokovoy <abokovoy@redhat.com>
|
||||
Date: Sun, 19 Oct 2025 18:14:29 +0300
|
||||
Subject: [PATCH] bail if prompter is not specified but required
|
||||
|
||||
GSSAPI gss_init_sec_context() may trigger credential re-initialization
|
||||
if the cred in ccache is expired. If automatic FAST armor is in use,
|
||||
we'd request Anonymous PKINIT and use it as an armor and this will
|
||||
enable seeing pre-authentication methods which require armor presence.
|
||||
|
||||
OTP is one of such methods and its use requires prompter to be set,
|
||||
but GSSAPI cannot specify a prompter and thus we should fail any
|
||||
pre-auth where a prompter wasn't passed.
|
||||
|
||||
PKINIT PKCS11 and SAM-2 preauth methods use KRB5_LIBOS_CANTREADPWD while PKINIT
|
||||
and gic_pwd.c use EIO. Use EIO here because we technically attempt to read a
|
||||
PIN rather than a password.
|
||||
|
||||
Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
|
||||
---
|
||||
src/lib/krb5/krb/preauth_otp.c | 3 +++
|
||||
1 file changed, 3 insertions(+)
|
||||
|
||||
diff --git a/src/lib/krb5/krb/preauth_otp.c b/src/lib/krb5/krb/preauth_otp.c
|
||||
index 07ffc15c2..48003da62 100644
|
||||
--- a/src/lib/krb5/krb/preauth_otp.c
|
||||
+++ b/src/lib/krb5/krb/preauth_otp.c
|
||||
@@ -479,6 +479,9 @@ doprompt(krb5_context context, krb5_prompter_fct prompter, void *prompter_data,
|
||||
krb5_error_code retval;
|
||||
krb5_prompt_type prompt_type = KRB5_PROMPT_TYPE_PREAUTH;
|
||||
|
||||
+ if (prompter == NULL)
|
||||
+ return EIO;
|
||||
+
|
||||
if (prompttxt == NULL || out == NULL)
|
||||
return EINVAL;
|
||||
|
||||
--
|
||||
2.51.0
|
||||
|
||||
|
|
@ -1,409 +0,0 @@
|
|||
From 1723d5cf07693d8fb249956ee73ca9f4436f95da Mon Sep 17 00:00:00 2001
|
||||
From: Simo Sorce <simo@redhat.com>
|
||||
Date: Tue, 4 Dec 2018 15:22:55 -0500
|
||||
Subject: [PATCH] Add dns_canonicalize_hostname=fallback support
|
||||
|
||||
Turn dns_canonicalize_hostname into a tristate variable, allowing the
|
||||
value "fallback" as well as the true/false booleans. If it is set to
|
||||
fallback, delay DNS canonicalization and attempt it only in
|
||||
krb5_get_credentials() if the KDC responds that the requested server
|
||||
principal name is unknown.
|
||||
|
||||
[ghudson@mit.edu: added TGS tests; refactored code; edited commit
|
||||
message and documentation]
|
||||
|
||||
ticket: 8765 (new)
|
||||
(cherry picked from commit 6c20cb1c89acaa03db897182a3b28d5f8f284907)
|
||||
---
|
||||
doc/admin/conf_files/krb5_conf.rst | 4 ++
|
||||
src/include/k5-int.h | 8 ++-
|
||||
src/include/k5-trace.h | 3 ++
|
||||
src/lib/krb5/krb/get_creds.c | 79 ++++++++++++++++++++++++++----
|
||||
src/lib/krb5/krb/init_ctx.c | 27 +++++++++-
|
||||
src/lib/krb5/krb/t_copy_context.c | 2 +-
|
||||
src/lib/krb5/os/os-proto.h | 4 ++
|
||||
src/lib/krb5/os/sn2princ.c | 19 +++++--
|
||||
src/tests/gcred.c | 5 +-
|
||||
src/tests/t_sn2princ.py | 34 ++++++++++++-
|
||||
10 files changed, 167 insertions(+), 18 deletions(-)
|
||||
|
||||
diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst
|
||||
index 7b4389f6b..e9f7e8c59 100644
|
||||
--- a/doc/admin/conf_files/krb5_conf.rst
|
||||
+++ b/doc/admin/conf_files/krb5_conf.rst
|
||||
@@ -201,6 +201,10 @@ The libdefaults section may contain any of the following relations:
|
||||
means that short hostnames will not be canonicalized to
|
||||
fully-qualified hostnames. The default value is true.
|
||||
|
||||
+ If this option is set to ``fallback`` (new in release 1.18), DNS
|
||||
+ canonicalization will only be performed the server hostname is not
|
||||
+ found with the original name when requesting credentials.
|
||||
+
|
||||
**dns_lookup_kdc**
|
||||
Indicate whether DNS SRV records should be used to locate the KDCs
|
||||
and other servers for a realm, if they are not listed in the
|
||||
diff --git a/src/include/k5-int.h b/src/include/k5-int.h
|
||||
index 255cee822..1e6a739e9 100644
|
||||
--- a/src/include/k5-int.h
|
||||
+++ b/src/include/k5-int.h
|
||||
@@ -1159,6 +1159,12 @@ k5_plugin_register_dyn(krb5_context context, int interface_id,
|
||||
void
|
||||
k5_plugin_free_context(krb5_context context);
|
||||
|
||||
+enum dns_canonhost {
|
||||
+ CANONHOST_FALSE = 0,
|
||||
+ CANONHOST_TRUE = 1,
|
||||
+ CANONHOST_FALLBACK = 2
|
||||
+};
|
||||
+
|
||||
struct _kdb5_dal_handle; /* private, in kdb5.h */
|
||||
typedef struct _kdb5_dal_handle kdb5_dal_handle;
|
||||
struct _kdb_log_context;
|
||||
@@ -1222,7 +1228,7 @@ struct _krb5_context {
|
||||
|
||||
krb5_boolean allow_weak_crypto;
|
||||
krb5_boolean ignore_acceptor_hostname;
|
||||
- krb5_boolean dns_canonicalize_hostname;
|
||||
+ enum dns_canonhost dns_canonicalize_hostname;
|
||||
|
||||
krb5_trace_callback trace_callback;
|
||||
void *trace_callback_data;
|
||||
diff --git a/src/include/k5-trace.h b/src/include/k5-trace.h
|
||||
index 2aa379b76..f3ed6a45d 100644
|
||||
--- a/src/include/k5-trace.h
|
||||
+++ b/src/include/k5-trace.h
|
||||
@@ -191,6 +191,9 @@ void krb5int_trace(krb5_context context, const char *fmt, ...);
|
||||
#define TRACE_FAST_REQUIRED(c) \
|
||||
TRACE(c, "Using FAST due to KRB5_FAST_REQUIRED flag")
|
||||
|
||||
+#define TRACE_GET_CREDS_FALLBACK(c, hostname) \
|
||||
+ TRACE(c, "Falling back to canonicalized server hostname {str}", hostname)
|
||||
+
|
||||
#define TRACE_GIC_PWD_CHANGED(c) \
|
||||
TRACE(c, "Getting initial TGT with changed password")
|
||||
#define TRACE_GIC_PWD_CHANGEPW(c, tries) \
|
||||
diff --git a/src/lib/krb5/krb/get_creds.c b/src/lib/krb5/krb/get_creds.c
|
||||
index 69900adfa..0a04d68b9 100644
|
||||
--- a/src/lib/krb5/krb/get_creds.c
|
||||
+++ b/src/lib/krb5/krb/get_creds.c
|
||||
@@ -39,6 +39,7 @@
|
||||
|
||||
#include "k5-int.h"
|
||||
#include "int-proto.h"
|
||||
+#include "os-proto.h"
|
||||
#include "fast.h"
|
||||
|
||||
/*
|
||||
@@ -1249,6 +1250,26 @@ krb5_tkt_creds_step(krb5_context context, krb5_tkt_creds_context ctx,
|
||||
return EINVAL;
|
||||
}
|
||||
|
||||
+static krb5_error_code
|
||||
+try_get_creds(krb5_context context, krb5_flags options, krb5_ccache ccache,
|
||||
+ krb5_creds *in_creds, krb5_creds *creds_out)
|
||||
+{
|
||||
+ krb5_error_code code;
|
||||
+ krb5_tkt_creds_context ctx = NULL;
|
||||
+
|
||||
+ code = krb5_tkt_creds_init(context, ccache, in_creds, options, &ctx);
|
||||
+ if (code)
|
||||
+ goto cleanup;
|
||||
+ code = krb5_tkt_creds_get(context, ctx);
|
||||
+ if (code)
|
||||
+ goto cleanup;
|
||||
+ code = krb5_tkt_creds_get_creds(context, ctx, creds_out);
|
||||
+
|
||||
+cleanup:
|
||||
+ krb5_tkt_creds_free(context, ctx);
|
||||
+ return code;
|
||||
+}
|
||||
+
|
||||
krb5_error_code KRB5_CALLCONV
|
||||
krb5_get_credentials(krb5_context context, krb5_flags options,
|
||||
krb5_ccache ccache, krb5_creds *in_creds,
|
||||
@@ -1256,7 +1277,10 @@ krb5_get_credentials(krb5_context context, krb5_flags options,
|
||||
{
|
||||
krb5_error_code code;
|
||||
krb5_creds *ncreds = NULL;
|
||||
- krb5_tkt_creds_context ctx = NULL;
|
||||
+ krb5_creds canon_creds, store_creds;
|
||||
+ krb5_principal_data canon_server;
|
||||
+ krb5_data canon_components[2];
|
||||
+ char *hostname = NULL, *canon_hostname = NULL;
|
||||
|
||||
*out_creds = NULL;
|
||||
|
||||
@@ -1265,22 +1289,59 @@ krb5_get_credentials(krb5_context context, krb5_flags options,
|
||||
if (ncreds == NULL)
|
||||
goto cleanup;
|
||||
|
||||
- /* Make and execute a krb5_tkt_creds context to get the credential. */
|
||||
- code = krb5_tkt_creds_init(context, ccache, in_creds, options, &ctx);
|
||||
- if (code != 0)
|
||||
+ code = try_get_creds(context, options, ccache, in_creds, ncreds);
|
||||
+ if (!code) {
|
||||
+ *out_creds = ncreds;
|
||||
+ return 0;
|
||||
+ }
|
||||
+
|
||||
+ /* Possibly try again with the canonicalized hostname, if the server is
|
||||
+ * host-based and we are configured for fallback canonicalization. */
|
||||
+ if (code != KRB5KDC_ERR_S_PRINCIPAL_UNKNOWN)
|
||||
goto cleanup;
|
||||
- code = krb5_tkt_creds_get(context, ctx);
|
||||
- if (code != 0)
|
||||
+ if (context->dns_canonicalize_hostname != CANONHOST_FALLBACK)
|
||||
goto cleanup;
|
||||
- code = krb5_tkt_creds_get_creds(context, ctx, ncreds);
|
||||
- if (code != 0)
|
||||
+ if (in_creds->server->type != KRB5_NT_SRV_HST ||
|
||||
+ in_creds->server->length != 2)
|
||||
goto cleanup;
|
||||
|
||||
+ hostname = k5memdup0(in_creds->server->data[1].data,
|
||||
+ in_creds->server->data[1].length, &code);
|
||||
+ if (hostname == NULL)
|
||||
+ goto cleanup;
|
||||
+ code = k5_expand_hostname(context, hostname, TRUE, &canon_hostname);
|
||||
+ if (code)
|
||||
+ goto cleanup;
|
||||
+
|
||||
+ TRACE_GET_CREDS_FALLBACK(context, canon_hostname);
|
||||
+
|
||||
+ /* Make shallow copies of in_creds and its server to alter the hostname. */
|
||||
+ canon_components[0] = in_creds->server->data[0];
|
||||
+ canon_components[1] = string2data(canon_hostname);
|
||||
+ canon_server = *in_creds->server;
|
||||
+ canon_server.data = canon_components;
|
||||
+ canon_creds = *in_creds;
|
||||
+ canon_creds.server = &canon_server;
|
||||
+
|
||||
+ code = try_get_creds(context, options | KRB5_GC_NO_STORE, ccache,
|
||||
+ &canon_creds, ncreds);
|
||||
+ if (code)
|
||||
+ goto cleanup;
|
||||
+
|
||||
+ if (!(options & KRB5_GC_NO_STORE)) {
|
||||
+ /* Store the creds under the originally requested server name. The
|
||||
+ * ccache layer will also store them under the ticket server name. */
|
||||
+ store_creds = *ncreds;
|
||||
+ store_creds.server = in_creds->server;
|
||||
+ (void)krb5_cc_store_cred(context, ccache, &store_creds);
|
||||
+ }
|
||||
+
|
||||
*out_creds = ncreds;
|
||||
ncreds = NULL;
|
||||
|
||||
cleanup:
|
||||
+ free(hostname);
|
||||
+ free(canon_hostname);
|
||||
krb5_free_creds(context, ncreds);
|
||||
- krb5_tkt_creds_free(context, ctx);
|
||||
return code;
|
||||
}
|
||||
diff --git a/src/lib/krb5/krb/init_ctx.c b/src/lib/krb5/krb/init_ctx.c
|
||||
index 947e50400..d263d5cc5 100644
|
||||
--- a/src/lib/krb5/krb/init_ctx.c
|
||||
+++ b/src/lib/krb5/krb/init_ctx.c
|
||||
@@ -101,6 +101,30 @@ get_boolean(krb5_context ctx, const char *name, int def_val, int *boolean_out)
|
||||
return retval;
|
||||
}
|
||||
|
||||
+static krb5_error_code
|
||||
+get_tristate(krb5_context ctx, const char *name, const char *third_option,
|
||||
+ int third_option_val, int def_val, int *val_out)
|
||||
+{
|
||||
+ krb5_error_code retval;
|
||||
+ char *str;
|
||||
+ int match;
|
||||
+
|
||||
+ retval = profile_get_boolean(ctx->profile, KRB5_CONF_LIBDEFAULTS, name,
|
||||
+ NULL, def_val, val_out);
|
||||
+ if (retval != PROF_BAD_BOOLEAN)
|
||||
+ return retval;
|
||||
+ retval = profile_get_string(ctx->profile, KRB5_CONF_LIBDEFAULTS, name,
|
||||
+ NULL, NULL, &str);
|
||||
+ if (retval)
|
||||
+ return retval;
|
||||
+ match = (strcasecmp(third_option, str) == 0);
|
||||
+ free(str);
|
||||
+ if (!match)
|
||||
+ return EINVAL;
|
||||
+ *val_out = third_option_val;
|
||||
+ return 0;
|
||||
+}
|
||||
+
|
||||
krb5_error_code KRB5_CALLCONV
|
||||
krb5_init_context(krb5_context *context)
|
||||
{
|
||||
@@ -213,7 +237,8 @@ krb5_init_context_profile(profile_t profile, krb5_flags flags,
|
||||
goto cleanup;
|
||||
ctx->ignore_acceptor_hostname = tmp;
|
||||
|
||||
- retval = get_boolean(ctx, KRB5_CONF_DNS_CANONICALIZE_HOSTNAME, 1, &tmp);
|
||||
+ retval = get_tristate(ctx, KRB5_CONF_DNS_CANONICALIZE_HOSTNAME, "fallback",
|
||||
+ CANONHOST_FALLBACK, 1, &tmp);
|
||||
if (retval)
|
||||
goto cleanup;
|
||||
ctx->dns_canonicalize_hostname = tmp;
|
||||
diff --git a/src/lib/krb5/krb/t_copy_context.c b/src/lib/krb5/krb/t_copy_context.c
|
||||
index fa810be8a..a6e48cd25 100644
|
||||
--- a/src/lib/krb5/krb/t_copy_context.c
|
||||
+++ b/src/lib/krb5/krb/t_copy_context.c
|
||||
@@ -145,7 +145,7 @@ main(int argc, char **argv)
|
||||
ctx->udp_pref_limit = 2345;
|
||||
ctx->use_conf_ktypes = TRUE;
|
||||
ctx->ignore_acceptor_hostname = TRUE;
|
||||
- ctx->dns_canonicalize_hostname = FALSE;
|
||||
+ ctx->dns_canonicalize_hostname = CANONHOST_FALSE;
|
||||
free(ctx->plugin_base_dir);
|
||||
check((ctx->plugin_base_dir = strdup("/a/b/c/d")) != NULL);
|
||||
|
||||
diff --git a/src/lib/krb5/os/os-proto.h b/src/lib/krb5/os/os-proto.h
|
||||
index 634e82d70..066d30221 100644
|
||||
--- a/src/lib/krb5/os/os-proto.h
|
||||
+++ b/src/lib/krb5/os/os-proto.h
|
||||
@@ -83,6 +83,10 @@ struct sendto_callback_info {
|
||||
void *data;
|
||||
};
|
||||
|
||||
+krb5_error_code k5_expand_hostname(krb5_context context, const char *host,
|
||||
+ krb5_boolean is_fallback,
|
||||
+ char **canonhost_out);
|
||||
+
|
||||
krb5_error_code k5_locate_server(krb5_context, const krb5_data *realm,
|
||||
struct serverlist *serverlist,
|
||||
enum locate_service_type svc,
|
||||
diff --git a/src/lib/krb5/os/sn2princ.c b/src/lib/krb5/os/sn2princ.c
|
||||
index 5932fd9b3..98d2600aa 100644
|
||||
--- a/src/lib/krb5/os/sn2princ.c
|
||||
+++ b/src/lib/krb5/os/sn2princ.c
|
||||
@@ -53,19 +53,23 @@ use_reverse_dns(krb5_context context)
|
||||
return value;
|
||||
}
|
||||
|
||||
-krb5_error_code KRB5_CALLCONV
|
||||
-krb5_expand_hostname(krb5_context context, const char *host,
|
||||
- char **canonhost_out)
|
||||
+krb5_error_code
|
||||
+k5_expand_hostname(krb5_context context, const char *host,
|
||||
+ krb5_boolean is_fallback, char **canonhost_out)
|
||||
{
|
||||
struct addrinfo *ai = NULL, hint;
|
||||
char namebuf[NI_MAXHOST], *copy, *p;
|
||||
int err;
|
||||
const char *canonhost;
|
||||
+ krb5_boolean use_dns;
|
||||
|
||||
*canonhost_out = NULL;
|
||||
|
||||
canonhost = host;
|
||||
- if (context->dns_canonicalize_hostname) {
|
||||
+ use_dns = (context->dns_canonicalize_hostname == CANONHOST_TRUE ||
|
||||
+ (is_fallback &&
|
||||
+ context->dns_canonicalize_hostname == CANONHOST_FALLBACK));
|
||||
+ if (use_dns) {
|
||||
/* Try a forward lookup of the hostname. */
|
||||
memset(&hint, 0, sizeof(hint));
|
||||
hint.ai_flags = AI_CANONNAME;
|
||||
@@ -112,6 +116,13 @@ cleanup:
|
||||
return (*canonhost_out == NULL) ? ENOMEM : 0;
|
||||
}
|
||||
|
||||
+krb5_error_code KRB5_CALLCONV
|
||||
+krb5_expand_hostname(krb5_context context, const char *host,
|
||||
+ char **canonhost_out)
|
||||
+{
|
||||
+ return k5_expand_hostname(context, host, FALSE, canonhost_out);
|
||||
+}
|
||||
+
|
||||
/* If hostname appears to have a :port or :instance trailer (used in MSSQLSvc
|
||||
* principals), return a pointer to the separator. Otherwise return NULL. */
|
||||
static const char *
|
||||
diff --git a/src/tests/gcred.c b/src/tests/gcred.c
|
||||
index b14e4fc9a..cac524c51 100644
|
||||
--- a/src/tests/gcred.c
|
||||
+++ b/src/tests/gcred.c
|
||||
@@ -66,6 +66,7 @@ main(int argc, char **argv)
|
||||
krb5_principal client, server;
|
||||
krb5_ccache ccache;
|
||||
krb5_creds in_creds, *creds;
|
||||
+ krb5_ticket *ticket;
|
||||
krb5_flags options = 0;
|
||||
char *name;
|
||||
int c;
|
||||
@@ -102,9 +103,11 @@ main(int argc, char **argv)
|
||||
in_creds.client = client;
|
||||
in_creds.server = server;
|
||||
check(krb5_get_credentials(ctx, options, ccache, &in_creds, &creds));
|
||||
- check(krb5_unparse_name(ctx, creds->server, &name));
|
||||
+ check(krb5_decode_ticket(&creds->ticket, &ticket));
|
||||
+ check(krb5_unparse_name(ctx, ticket->server, &name));
|
||||
printf("%s\n", name);
|
||||
|
||||
+ krb5_free_ticket(ctx, ticket);
|
||||
krb5_free_unparsed_name(ctx, name);
|
||||
krb5_free_creds(ctx, creds);
|
||||
krb5_free_principal(ctx, client);
|
||||
diff --git a/src/tests/t_sn2princ.py b/src/tests/t_sn2princ.py
|
||||
index 1ffda51f4..fe435a2d5 100755
|
||||
--- a/src/tests/t_sn2princ.py
|
||||
+++ b/src/tests/t_sn2princ.py
|
||||
@@ -7,10 +7,15 @@ conf = {'domain_realm': {'kerberos.org': 'R1',
|
||||
'mit.edu': 'R3'}}
|
||||
no_rdns_conf = {'libdefaults': {'rdns': 'false'}}
|
||||
no_canon_conf = {'libdefaults': {'dns_canonicalize_hostname': 'false'}}
|
||||
+fallback_canon_conf = {'libdefaults':
|
||||
+ {'rdns': 'false',
|
||||
+ 'dns_canonicalize_hostname': 'fallback'}}
|
||||
|
||||
-realm = K5Realm(create_kdb=False, krb5_conf=conf)
|
||||
+realm = K5Realm(realm='R1', create_host=False, krb5_conf=conf)
|
||||
no_rdns = realm.special_env('no_rdns', False, krb5_conf=no_rdns_conf)
|
||||
no_canon = realm.special_env('no_canon', False, krb5_conf=no_canon_conf)
|
||||
+fallback_canon = realm.special_env('fallback_canon', False,
|
||||
+ krb5_conf=fallback_canon_conf)
|
||||
|
||||
def testbase(host, nametype, princhost, princrealm, env=None):
|
||||
# Run the sn2princ harness with a specified host and name type and
|
||||
@@ -37,6 +42,10 @@ def testu(host, princhost, princrealm):
|
||||
# Test with the unknown name type.
|
||||
testbase(host, 'unknown', princhost, princrealm)
|
||||
|
||||
+def testfc(host, princhost, princrealm):
|
||||
+ # Test with the host-based name type with canonicalization fallback.
|
||||
+ testbase(host, 'srv-hst', princhost, princrealm, env=fallback_canon)
|
||||
+
|
||||
# With the unknown principal type, we do not canonicalize or downcase,
|
||||
# but we do remove a trailing period and look up the realm.
|
||||
mark('unknown type')
|
||||
@@ -71,6 +80,29 @@ if offline:
|
||||
oname = 'ptr-mismatch.kerberos.org'
|
||||
fname = 'www.kerberos.org'
|
||||
|
||||
+# Test fallback canonicalization krb5_sname_to_principal() results
|
||||
+# (same as dns_canonicalize_hostname=false).
|
||||
+mark('dns_canonicalize_host=fallback')
|
||||
+testfc(oname, oname, 'R1')
|
||||
+
|
||||
+# Test fallback canonicalization in krb5_get_credentials().
|
||||
+oprinc = 'host/' + oname
|
||||
+fprinc = 'host/' + fname
|
||||
+shutil.copy(realm.ccache, realm.ccache + '.save')
|
||||
+realm.addprinc(fprinc)
|
||||
+# oprinc doesn't exist, so we get the canonicalized fprinc as a fallback.
|
||||
+msgs = ('Falling back to canonicalized server hostname ' + fname,)
|
||||
+realm.run(['./gcred', 'srv-hst', oprinc], env=fallback_canon,
|
||||
+ expected_msg=fprinc, expected_trace=msgs)
|
||||
+realm.addprinc(oprinc)
|
||||
+# oprinc now exists, but we still get the fprinc ticket from the cache.
|
||||
+realm.run(['./gcred', 'srv-hst', oprinc], env=fallback_canon,
|
||||
+ expected_msg=fprinc)
|
||||
+# Without the cached result, we sould get oprinc in preference to fprinc.
|
||||
+os.rename(realm.ccache + '.save', realm.ccache)
|
||||
+realm.run(['./gcred', 'srv-hst', oprinc], env=fallback_canon,
|
||||
+ expected_msg=oprinc)
|
||||
+
|
||||
# Verify forward resolution before testing for it.
|
||||
try:
|
||||
ai = socket.getaddrinfo(oname, None, 0, 0, 0, socket.AI_CANONNAME)
|
||||
|
|
@ -1,183 +0,0 @@
|
|||
From 5817cf4b254ab7f266d74ba30ca2a0ffa26e803e Mon Sep 17 00:00:00 2001
|
||||
From: Robbie Harwood <rharwood@redhat.com>
|
||||
Date: Tue, 15 Jan 2019 16:16:57 -0500
|
||||
Subject: [PATCH] Add function and enctype flag for deprecations
|
||||
|
||||
krb5int_c_deprecated_enctype() checks for the ETYPE_DEPRECATED flag on
|
||||
enctypes. All ENCTYPE_WEAK enctypes are currently deprecated; not all
|
||||
deprecated enctypes are considered weak. Deprecations follow RFC 6649
|
||||
and RFC 8429.
|
||||
|
||||
(cherry picked from commit 484a6e7712f9b66e782b2520f07b0883889e116f)
|
||||
---
|
||||
src/include/k5-int.h | 1 +
|
||||
src/lib/crypto/krb/crypto_int.h | 9 ++++++++-
|
||||
src/lib/crypto/krb/enctype_util.c | 7 +++++++
|
||||
src/lib/crypto/krb/etypes.c | 19 ++++++++++---------
|
||||
src/lib/crypto/libk5crypto.exports | 1 +
|
||||
src/lib/krb5_32.def | 3 +++
|
||||
6 files changed, 30 insertions(+), 10 deletions(-)
|
||||
|
||||
diff --git a/src/include/k5-int.h b/src/include/k5-int.h
|
||||
index 8f9329c59..255cee822 100644
|
||||
--- a/src/include/k5-int.h
|
||||
+++ b/src/include/k5-int.h
|
||||
@@ -2077,6 +2077,7 @@ krb5_get_tgs_ktypes(krb5_context, krb5_const_principal, krb5_enctype **);
|
||||
krb5_boolean krb5_is_permitted_enctype(krb5_context, krb5_enctype);
|
||||
|
||||
krb5_boolean KRB5_CALLCONV krb5int_c_weak_enctype(krb5_enctype);
|
||||
+krb5_boolean KRB5_CALLCONV krb5int_c_deprecated_enctype(krb5_enctype);
|
||||
krb5_error_code k5_enctype_to_ssf(krb5_enctype enctype, unsigned int *ssf_out);
|
||||
|
||||
krb5_error_code krb5_kdc_rep_decrypt_proc(krb5_context, const krb5_keyblock *,
|
||||
diff --git a/src/lib/crypto/krb/crypto_int.h b/src/lib/crypto/krb/crypto_int.h
|
||||
index e5099291e..6c1c77cac 100644
|
||||
--- a/src/lib/crypto/krb/crypto_int.h
|
||||
+++ b/src/lib/crypto/krb/crypto_int.h
|
||||
@@ -114,7 +114,14 @@ struct krb5_keytypes {
|
||||
unsigned int ssf;
|
||||
};
|
||||
|
||||
-#define ETYPE_WEAK 1
|
||||
+/*
|
||||
+ * "Weak" means the enctype is believed to be vulnerable to practical attacks,
|
||||
+ * and will be disabled unless allow_weak_crypto is set to true. "Deprecated"
|
||||
+ * means the enctype has been deprecated by the IETF, and affects display and
|
||||
+ * logging.
|
||||
+ */
|
||||
+#define ETYPE_WEAK (1 << 0)
|
||||
+#define ETYPE_DEPRECATED (1 << 1)
|
||||
|
||||
extern const struct krb5_keytypes krb5int_enctypes_list[];
|
||||
extern const int krb5int_enctypes_length;
|
||||
diff --git a/src/lib/crypto/krb/enctype_util.c b/src/lib/crypto/krb/enctype_util.c
|
||||
index b1b40e7ec..e394f4e19 100644
|
||||
--- a/src/lib/crypto/krb/enctype_util.c
|
||||
+++ b/src/lib/crypto/krb/enctype_util.c
|
||||
@@ -51,6 +51,13 @@ krb5int_c_weak_enctype(krb5_enctype etype)
|
||||
return (ktp != NULL && (ktp->flags & ETYPE_WEAK) != 0);
|
||||
}
|
||||
|
||||
+krb5_boolean KRB5_CALLCONV
|
||||
+krb5int_c_deprecated_enctype(krb5_enctype etype)
|
||||
+{
|
||||
+ const struct krb5_keytypes *ktp = find_enctype(etype);
|
||||
+ return ktp != NULL && (ktp->flags & ETYPE_DEPRECATED) != 0;
|
||||
+}
|
||||
+
|
||||
krb5_error_code KRB5_CALLCONV
|
||||
krb5_c_enctype_compare(krb5_context context, krb5_enctype e1, krb5_enctype e2,
|
||||
krb5_boolean *similar)
|
||||
diff --git a/src/lib/crypto/krb/etypes.c b/src/lib/crypto/krb/etypes.c
|
||||
index 53d4a5c79..8f44c37e7 100644
|
||||
--- a/src/lib/crypto/krb/etypes.c
|
||||
+++ b/src/lib/crypto/krb/etypes.c
|
||||
@@ -33,6 +33,7 @@
|
||||
that the keytypes are all near each other. I'd rather not make
|
||||
that assumption. */
|
||||
|
||||
+/* Deprecations come from RFC 6649 and RFC 8249. */
|
||||
const struct krb5_keytypes krb5int_enctypes_list[] = {
|
||||
{ ENCTYPE_DES_CBC_CRC,
|
||||
"des-cbc-crc", { 0 }, "DES cbc mode with CRC-32",
|
||||
@@ -42,7 +43,7 @@ const struct krb5_keytypes krb5int_enctypes_list[] = {
|
||||
krb5int_des_string_to_key, k5_rand2key_des,
|
||||
krb5int_des_prf,
|
||||
CKSUMTYPE_RSA_MD5_DES,
|
||||
- ETYPE_WEAK, 56 },
|
||||
+ ETYPE_WEAK | ETYPE_DEPRECATED, 56 },
|
||||
{ ENCTYPE_DES_CBC_MD4,
|
||||
"des-cbc-md4", { 0 }, "DES cbc mode with RSA-MD4",
|
||||
&krb5int_enc_des, &krb5int_hash_md4,
|
||||
@@ -51,7 +52,7 @@ const struct krb5_keytypes krb5int_enctypes_list[] = {
|
||||
krb5int_des_string_to_key, k5_rand2key_des,
|
||||
krb5int_des_prf,
|
||||
CKSUMTYPE_RSA_MD4_DES,
|
||||
- ETYPE_WEAK, 56 },
|
||||
+ ETYPE_WEAK | ETYPE_DEPRECATED, 56 },
|
||||
{ ENCTYPE_DES_CBC_MD5,
|
||||
"des-cbc-md5", { "des" }, "DES cbc mode with RSA-MD5",
|
||||
&krb5int_enc_des, &krb5int_hash_md5,
|
||||
@@ -60,7 +61,7 @@ const struct krb5_keytypes krb5int_enctypes_list[] = {
|
||||
krb5int_des_string_to_key, k5_rand2key_des,
|
||||
krb5int_des_prf,
|
||||
CKSUMTYPE_RSA_MD5_DES,
|
||||
- ETYPE_WEAK, 56 },
|
||||
+ ETYPE_WEAK | ETYPE_DEPRECATED, 56 },
|
||||
{ ENCTYPE_DES_CBC_RAW,
|
||||
"des-cbc-raw", { 0 }, "DES cbc mode raw",
|
||||
&krb5int_enc_des, NULL,
|
||||
@@ -69,7 +70,7 @@ const struct krb5_keytypes krb5int_enctypes_list[] = {
|
||||
krb5int_des_string_to_key, k5_rand2key_des,
|
||||
krb5int_des_prf,
|
||||
0,
|
||||
- ETYPE_WEAK, 56 },
|
||||
+ ETYPE_WEAK | ETYPE_DEPRECATED, 56 },
|
||||
{ ENCTYPE_DES3_CBC_RAW,
|
||||
"des3-cbc-raw", { 0 }, "Triple DES cbc mode raw",
|
||||
&krb5int_enc_des3, NULL,
|
||||
@@ -78,7 +79,7 @@ const struct krb5_keytypes krb5int_enctypes_list[] = {
|
||||
krb5int_dk_string_to_key, k5_rand2key_des3,
|
||||
NULL, /*PRF*/
|
||||
0,
|
||||
- ETYPE_WEAK, 112 },
|
||||
+ ETYPE_WEAK | ETYPE_DEPRECATED, 112 },
|
||||
|
||||
{ ENCTYPE_DES3_CBC_SHA1,
|
||||
"des3-cbc-sha1", { "des3-hmac-sha1", "des3-cbc-sha1-kd" },
|
||||
@@ -89,7 +90,7 @@ const struct krb5_keytypes krb5int_enctypes_list[] = {
|
||||
krb5int_dk_string_to_key, k5_rand2key_des3,
|
||||
krb5int_dk_prf,
|
||||
CKSUMTYPE_HMAC_SHA1_DES3,
|
||||
- 0 /*flags*/, 112 },
|
||||
+ ETYPE_DEPRECATED, 112 },
|
||||
|
||||
{ ENCTYPE_DES_HMAC_SHA1,
|
||||
"des-hmac-sha1", { 0 }, "DES with HMAC/sha1",
|
||||
@@ -99,7 +100,7 @@ const struct krb5_keytypes krb5int_enctypes_list[] = {
|
||||
krb5int_dk_string_to_key, k5_rand2key_des,
|
||||
NULL, /*PRF*/
|
||||
0,
|
||||
- ETYPE_WEAK, 56 },
|
||||
+ ETYPE_WEAK | ETYPE_DEPRECATED, 56 },
|
||||
|
||||
/* rc4-hmac uses a 128-bit key, but due to weaknesses in the RC4 cipher, we
|
||||
* consider its strength degraded and assign it an SSF value of 64. */
|
||||
@@ -113,7 +114,7 @@ const struct krb5_keytypes krb5int_enctypes_list[] = {
|
||||
krb5int_arcfour_decrypt, krb5int_arcfour_string_to_key,
|
||||
k5_rand2key_direct, krb5int_arcfour_prf,
|
||||
CKSUMTYPE_HMAC_MD5_ARCFOUR,
|
||||
- 0 /*flags*/, 64 },
|
||||
+ ETYPE_DEPRECATED, 64 },
|
||||
{ ENCTYPE_ARCFOUR_HMAC_EXP,
|
||||
"arcfour-hmac-exp", { "rc4-hmac-exp", "arcfour-hmac-md5-exp" },
|
||||
"Exportable ArcFour with HMAC/md5",
|
||||
@@ -124,7 +125,7 @@ const struct krb5_keytypes krb5int_enctypes_list[] = {
|
||||
krb5int_arcfour_decrypt, krb5int_arcfour_string_to_key,
|
||||
k5_rand2key_direct, krb5int_arcfour_prf,
|
||||
CKSUMTYPE_HMAC_MD5_ARCFOUR,
|
||||
- ETYPE_WEAK, 40
|
||||
+ ETYPE_WEAK | ETYPE_DEPRECATED, 40
|
||||
},
|
||||
|
||||
{ ENCTYPE_AES128_CTS_HMAC_SHA1_96,
|
||||
diff --git a/src/lib/crypto/libk5crypto.exports b/src/lib/crypto/libk5crypto.exports
|
||||
index 82eb5f30c..90afdf5f7 100644
|
||||
--- a/src/lib/crypto/libk5crypto.exports
|
||||
+++ b/src/lib/crypto/libk5crypto.exports
|
||||
@@ -109,3 +109,4 @@ k5_allow_weak_pbkdf2iter
|
||||
krb5_c_prfplus
|
||||
krb5_c_derive_prfplus
|
||||
k5_enctype_to_ssf
|
||||
+krb5int_c_deprecated_enctype
|
||||
diff --git a/src/lib/krb5_32.def b/src/lib/krb5_32.def
|
||||
index c35022931..e6a487593 100644
|
||||
--- a/src/lib/krb5_32.def
|
||||
+++ b/src/lib/krb5_32.def
|
||||
@@ -487,3 +487,6 @@ EXPORTS
|
||||
encode_krb5_pa_spake @444 ; PRIVATE
|
||||
decode_krb5_pa_spake @445 ; PRIVATE
|
||||
k5_free_pa_spake @446 ; PRIVATE
|
||||
+
|
||||
+; new in 1.18
|
||||
+ krb5int_c_deprecated_enctype @450 ; PRIVATE
|
||||
|
|
@ -1,37 +0,0 @@
|
|||
From 4928699bdfd051bf0d69afee0b15574c15f40a48 Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Tue, 21 May 2019 12:52:26 -0400
|
||||
Subject: [PATCH] Add missing newlines to deprecation warnings
|
||||
|
||||
Commit 8d8e68283b599e680f9fe45eff8af397e827bd6c omitted newlines in
|
||||
two warning messages sent to stderr. Add them now.
|
||||
|
||||
ticket: 8773
|
||||
(cherry picked from commit 274fee295d1429668b31c6ed898fc5d11a7e3589)
|
||||
---
|
||||
src/kdc/main.c | 5 +++--
|
||||
1 file changed, 3 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/src/kdc/main.c b/src/kdc/main.c
|
||||
index 04393772f..1596c1c5b 100644
|
||||
--- a/src/kdc/main.c
|
||||
+++ b/src/kdc/main.c
|
||||
@@ -223,7 +223,8 @@ init_realm(kdc_realm_t * rdp, krb5_pointer aprof, char *realm,
|
||||
if (krb5_enctype_to_name(def_enctype, FALSE, ename, sizeof(ename)))
|
||||
ename[0] = '\0';
|
||||
fprintf(stderr,
|
||||
- _("Requested master password enctype %s in %s is DEPRECATED!"),
|
||||
+ _("Requested master password enctype %s in %s is "
|
||||
+ "DEPRECATED!\n"),
|
||||
ename, realm);
|
||||
}
|
||||
|
||||
@@ -385,7 +386,7 @@ init_realm(kdc_realm_t * rdp, krb5_pointer aprof, char *realm,
|
||||
if (krb5_enctype_to_name(rdp->realm_mkey.enctype, FALSE, ename,
|
||||
sizeof(ename)))
|
||||
ename[0] = '\0';
|
||||
- fprintf(stderr, _("Stash file %s uses DEPRECATED enctype %s!"),
|
||||
+ fprintf(stderr, _("Stash file %s uses DEPRECATED enctype %s!\n"),
|
||||
rdp->realm_stash, ename);
|
||||
}
|
||||
|
||||
File diff suppressed because it is too large
Load diff
|
|
@ -1,294 +0,0 @@
|
|||
From ae2475679b7b0e9381eac5d134c06cfc559d7d1b Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Thu, 22 Nov 2018 00:27:35 -0500
|
||||
Subject: [PATCH] Add tests for KCM ccache type
|
||||
|
||||
Using a trivial Python implementation of a KCM server, run the
|
||||
t_ccache.py tests against the KCM ccache type.
|
||||
|
||||
(cherry picked from commit f0bcb86131e385b2603ccf0f3c7d65aa3891b220)
|
||||
---
|
||||
src/tests/kcmserver.py | 246 +++++++++++++++++++++++++++++++++++++++++
|
||||
src/tests/t_ccache.py | 9 +-
|
||||
2 files changed, 254 insertions(+), 1 deletion(-)
|
||||
create mode 100644 src/tests/kcmserver.py
|
||||
|
||||
diff --git a/src/tests/kcmserver.py b/src/tests/kcmserver.py
|
||||
new file mode 100644
|
||||
index 000000000..57432e5a7
|
||||
--- /dev/null
|
||||
+++ b/src/tests/kcmserver.py
|
||||
@@ -0,0 +1,246 @@
|
||||
+# This is a simple KCM test server, used to exercise the KCM ccache
|
||||
+# client code. It will generally throw an uncaught exception if the
|
||||
+# client sends anything unexpected, so is unsuitable for production.
|
||||
+# (It also imposes no namespace or access constraints, and blocks
|
||||
+# while reading requests and writing responses.)
|
||||
+
|
||||
+# This code knows nothing about how to marshal and unmarshal principal
|
||||
+# names and credentials as is required in the KCM protocol; instead,
|
||||
+# it just remembers the marshalled forms and replays them to the
|
||||
+# client when asked. This works because marshalled creds and
|
||||
+# principal names are always the last part of marshalled request
|
||||
+# arguments, and because we don't need to implement remove_cred (which
|
||||
+# would need to know how to match a cred tag against previously stored
|
||||
+# credentials).
|
||||
+
|
||||
+# The following code is useful for debugging if anything appears to be
|
||||
+# going wrong in the server, since daemon output is generally not
|
||||
+# visible in Python test scripts.
|
||||
+#
|
||||
+# import sys, traceback
|
||||
+# def ehook(etype, value, tb):
|
||||
+# with open('/tmp/exception', 'w') as f:
|
||||
+# traceback.print_exception(etype, value, tb, file=f)
|
||||
+# sys.excepthook = ehook
|
||||
+
|
||||
+import select
|
||||
+import socket
|
||||
+import struct
|
||||
+import sys
|
||||
+
|
||||
+caches = {}
|
||||
+cache_uuidmap = {}
|
||||
+defname = b'default'
|
||||
+next_unique = 1
|
||||
+next_uuid = 1
|
||||
+
|
||||
+class KCMOpcodes(object):
|
||||
+ GEN_NEW = 3
|
||||
+ INITIALIZE = 4
|
||||
+ DESTROY = 5
|
||||
+ STORE = 6
|
||||
+ GET_PRINCIPAL = 8
|
||||
+ GET_CRED_UUID_LIST = 9
|
||||
+ GET_CRED_BY_UUID = 10
|
||||
+ REMOVE_CRED = 11
|
||||
+ GET_CACHE_UUID_LIST = 18
|
||||
+ GET_CACHE_BY_UUID = 19
|
||||
+ GET_DEFAULT_CACHE = 20
|
||||
+ SET_DEFAULT_CACHE = 21
|
||||
+ GET_KDC_OFFSET = 22
|
||||
+ SET_KDC_OFFSET = 23
|
||||
+
|
||||
+
|
||||
+class KRB5Errors(object):
|
||||
+ KRB5_CC_END = -1765328242
|
||||
+ KRB5_CC_NOSUPP = -1765328137
|
||||
+ KRB5_FCC_NOFILE = -1765328189
|
||||
+
|
||||
+
|
||||
+def make_uuid():
|
||||
+ global next_uuid
|
||||
+ uuid = bytes(12) + struct.pack('>L', next_uuid)
|
||||
+ next_uuid = next_uuid + 1
|
||||
+ return uuid
|
||||
+
|
||||
+
|
||||
+class Cache(object):
|
||||
+ def __init__(self, name):
|
||||
+ self.name = name
|
||||
+ self.princ = None
|
||||
+ self.uuid = make_uuid()
|
||||
+ self.cred_uuids = []
|
||||
+ self.creds = {}
|
||||
+ self.time_offset = 0
|
||||
+
|
||||
+
|
||||
+def get_cache(name):
|
||||
+ if name in caches:
|
||||
+ return caches[name]
|
||||
+ cache = Cache(name)
|
||||
+ caches[name] = cache
|
||||
+ cache_uuidmap[cache.uuid] = cache
|
||||
+ return cache
|
||||
+
|
||||
+
|
||||
+def unmarshal_name(argbytes):
|
||||
+ offset = argbytes.find(b'\0')
|
||||
+ return argbytes[0:offset], argbytes[offset+1:]
|
||||
+
|
||||
+
|
||||
+def op_gen_new(argbytes):
|
||||
+ # Does not actually check for uniqueness.
|
||||
+ global next_unique
|
||||
+ name = b'unique' + str(next_unique).encode('ascii')
|
||||
+ next_unique += 1
|
||||
+ return 0, name + b'\0'
|
||||
+
|
||||
+
|
||||
+def op_initialize(argbytes):
|
||||
+ name, princ = unmarshal_name(argbytes)
|
||||
+ cache = get_cache(name)
|
||||
+ cache.princ = princ
|
||||
+ cache.cred_uuids = []
|
||||
+ cache.creds = {}
|
||||
+ cache.time_offset = 0
|
||||
+ return 0, b''
|
||||
+
|
||||
+
|
||||
+def op_destroy(argbytes):
|
||||
+ name, rest = unmarshal_name(argbytes)
|
||||
+ cache = get_cache(name)
|
||||
+ del cache_uuidmap[cache.uuid]
|
||||
+ del caches[name]
|
||||
+ return 0, b''
|
||||
+
|
||||
+
|
||||
+def op_store(argbytes):
|
||||
+ name, cred = unmarshal_name(argbytes)
|
||||
+ cache = get_cache(name)
|
||||
+ uuid = make_uuid()
|
||||
+ cache.creds[uuid] = cred
|
||||
+ cache.cred_uuids.append(uuid)
|
||||
+ return 0, b''
|
||||
+
|
||||
+
|
||||
+def op_get_principal(argbytes):
|
||||
+ name, rest = unmarshal_name(argbytes)
|
||||
+ cache = get_cache(name)
|
||||
+ if cache.princ is None:
|
||||
+ return KRB5Errors.KRB5_FCC_NOFILE, b''
|
||||
+ return 0, cache.princ + b'\0'
|
||||
+
|
||||
+
|
||||
+def op_get_cred_uuid_list(argbytes):
|
||||
+ name, rest = unmarshal_name(argbytes)
|
||||
+ cache = get_cache(name)
|
||||
+ return 0, b''.join(cache.cred_uuids)
|
||||
+
|
||||
+
|
||||
+def op_get_cred_by_uuid(argbytes):
|
||||
+ name, uuid = unmarshal_name(argbytes)
|
||||
+ cache = get_cache(name)
|
||||
+ if uuid not in cache.creds:
|
||||
+ return KRB5Errors.KRB5_CC_END, b''
|
||||
+ return 0, cache.creds[uuid]
|
||||
+
|
||||
+
|
||||
+def op_remove_cred(argbytes):
|
||||
+ return KRB5Errors.KRB5_CC_NOSUPP, b''
|
||||
+
|
||||
+
|
||||
+def op_get_cache_uuid_list(argbytes):
|
||||
+ return 0, b''.join(cache_uuidmap.keys())
|
||||
+
|
||||
+
|
||||
+def op_get_cache_by_uuid(argbytes):
|
||||
+ uuid = argbytes
|
||||
+ if uuid not in cache_uuidmap:
|
||||
+ return KRB5Errors.KRB5_CC_END, b''
|
||||
+ return 0, cache_uuidmap[uuid].name + b'\0'
|
||||
+
|
||||
+
|
||||
+def op_get_default_cache(argbytes):
|
||||
+ return 0, defname + b'\0'
|
||||
+
|
||||
+
|
||||
+def op_set_default_cache(argbytes):
|
||||
+ global defname
|
||||
+ defname, rest = unmarshal_name(argbytes)
|
||||
+ return 0, b''
|
||||
+
|
||||
+
|
||||
+def op_get_kdc_offset(argbytes):
|
||||
+ name, rest = unmarshal_name(argbytes)
|
||||
+ cache = get_cache(name)
|
||||
+ return 0, struct.pack('>l', cache.time_offset)
|
||||
+
|
||||
+
|
||||
+def op_set_kdc_offset(argbytes):
|
||||
+ name, obytes = unmarshal_name(argbytes)
|
||||
+ cache = get_cache(name)
|
||||
+ cache.time_offset, = struct.unpack('>l', obytes)
|
||||
+ return 0, b''
|
||||
+
|
||||
+
|
||||
+ophandlers = {
|
||||
+ KCMOpcodes.GEN_NEW : op_gen_new,
|
||||
+ KCMOpcodes.INITIALIZE : op_initialize,
|
||||
+ KCMOpcodes.DESTROY : op_destroy,
|
||||
+ KCMOpcodes.STORE : op_store,
|
||||
+ KCMOpcodes.GET_PRINCIPAL : op_get_principal,
|
||||
+ KCMOpcodes.GET_CRED_UUID_LIST : op_get_cred_uuid_list,
|
||||
+ KCMOpcodes.GET_CRED_BY_UUID : op_get_cred_by_uuid,
|
||||
+ KCMOpcodes.REMOVE_CRED : op_remove_cred,
|
||||
+ KCMOpcodes.GET_CACHE_UUID_LIST : op_get_cache_uuid_list,
|
||||
+ KCMOpcodes.GET_CACHE_BY_UUID : op_get_cache_by_uuid,
|
||||
+ KCMOpcodes.GET_DEFAULT_CACHE : op_get_default_cache,
|
||||
+ KCMOpcodes.SET_DEFAULT_CACHE : op_set_default_cache,
|
||||
+ KCMOpcodes.GET_KDC_OFFSET : op_get_kdc_offset,
|
||||
+ KCMOpcodes.SET_KDC_OFFSET : op_set_kdc_offset
|
||||
+}
|
||||
+
|
||||
+# Read and respond to a request from the socket s.
|
||||
+def service_request(s):
|
||||
+ lenbytes = b''
|
||||
+ while len(lenbytes) < 4:
|
||||
+ lenbytes += s.recv(4 - len(lenbytes))
|
||||
+ if lenbytes == b'':
|
||||
+ return False
|
||||
+
|
||||
+ reqlen, = struct.unpack('>L', lenbytes)
|
||||
+ req = b''
|
||||
+ while len(req) < reqlen:
|
||||
+ req += s.recv(reqlen - len(req))
|
||||
+
|
||||
+ majver, minver, op = struct.unpack('>BBH', req[:4])
|
||||
+ argbytes = req[4:]
|
||||
+ code, payload = ophandlers[op](argbytes)
|
||||
+
|
||||
+ # The KCM response is the code (4 bytes) and the response payload.
|
||||
+ # The Heimdal IPC response is the length of the KCM response (4
|
||||
+ # bytes), a status code which is essentially always 0 (4 bytes),
|
||||
+ # and the KCM response.
|
||||
+ kcm_response = struct.pack('>l', code) + payload
|
||||
+ hipc_response = struct.pack('>LL', len(kcm_response), 0) + kcm_response
|
||||
+ s.sendall(hipc_response)
|
||||
+ return True
|
||||
+
|
||||
+
|
||||
+server = socket.socket(socket.AF_UNIX, socket.SOCK_STREAM)
|
||||
+server.bind(sys.argv[1])
|
||||
+server.listen(5)
|
||||
+select_input = [server,]
|
||||
+sys.stderr.write('starting...\n')
|
||||
+sys.stderr.flush()
|
||||
+
|
||||
+while True:
|
||||
+ iready, oready, xready = select.select(select_input, [], [])
|
||||
+ for s in iready:
|
||||
+ if s == server:
|
||||
+ client, addr = server.accept()
|
||||
+ select_input.append(client)
|
||||
+ else:
|
||||
+ if not service_request(s):
|
||||
+ select_input.remove(s)
|
||||
+ s.close()
|
||||
diff --git a/src/tests/t_ccache.py b/src/tests/t_ccache.py
|
||||
index fcf1a611e..66804afa5 100755
|
||||
--- a/src/tests/t_ccache.py
|
||||
+++ b/src/tests/t_ccache.py
|
||||
@@ -22,7 +22,10 @@
|
||||
|
||||
from k5test import *
|
||||
|
||||
-realm = K5Realm(create_host=False)
|
||||
+kcm_socket_path = os.path.join(os.getcwd(), 'testdir', 'kcm')
|
||||
+conf = {'libdefaults': {'kcm_socket': kcm_socket_path,
|
||||
+ 'kcm_mach_service': '-'}}
|
||||
+realm = K5Realm(create_host=False, krb5_conf=conf)
|
||||
|
||||
keyctl = which('keyctl')
|
||||
out = realm.run([klist, '-c', 'KEYRING:process:abcd'], expected_code=1)
|
||||
@@ -122,6 +125,10 @@ def collection_test(realm, ccname):
|
||||
|
||||
|
||||
collection_test(realm, 'DIR:' + os.path.join(realm.testdir, 'cc'))
|
||||
+kcmserver_path = os.path.join(srctop, 'tests', 'kcmserver.py')
|
||||
+realm.start_server([sys.executable, kcmserver_path, kcm_socket_path],
|
||||
+ 'starting...')
|
||||
+collection_test(realm, 'KCM:')
|
||||
if test_keyring:
|
||||
def cleanup_keyring(anchor, name):
|
||||
out = realm.run(['keyctl', 'list', anchor])
|
||||
|
|
@ -1,31 +0,0 @@
|
|||
From 7fb0b432d9192360ec3439a7f5c33ad8366064f1 Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Thu, 14 Mar 2019 11:26:44 -0400
|
||||
Subject: [PATCH] Add zapfreedata() convenience function
|
||||
|
||||
(cherry picked from commit abd974cf867db5a398aa87ba9b9aaa34346e12a4)
|
||||
---
|
||||
src/include/k5-int.h | 10 ++++++++++
|
||||
1 file changed, 10 insertions(+)
|
||||
|
||||
diff --git a/src/include/k5-int.h b/src/include/k5-int.h
|
||||
index e0c557554..2bc59e636 100644
|
||||
--- a/src/include/k5-int.h
|
||||
+++ b/src/include/k5-int.h
|
||||
@@ -663,6 +663,16 @@ zapfreestr(void *str)
|
||||
}
|
||||
}
|
||||
|
||||
+/* Convenience function: zap and free krb5_data pointer if it is non-NULL. */
|
||||
+static inline void
|
||||
+zapfreedata(krb5_data *data)
|
||||
+{
|
||||
+ if (data != NULL) {
|
||||
+ zapfree(data->data, data->length);
|
||||
+ free(data);
|
||||
+ }
|
||||
+}
|
||||
+
|
||||
/*
|
||||
* Combine two keys (normally used by the hardware preauth mechanism)
|
||||
*/
|
||||
|
|
@ -1,94 +0,0 @@
|
|||
From b54bce8e7b54c8700467fefcc74623fa50234046 Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Sun, 30 Dec 2018 16:40:28 -0500
|
||||
Subject: [PATCH] Address some optimized-out memset() calls
|
||||
|
||||
Ilja Van Sprundel reported a list of memset() calls which gcc
|
||||
optimizes out. In krb_auth_su.c, use zap() to clear the password, and
|
||||
remove two memset() calls when there is no password to clear. In
|
||||
iakerb.c, remove an unnecessary memset() before setting the only two
|
||||
fields of the IAKERB header structure. In svr_principal.c, use
|
||||
krb5_free_key_keyblock_contents() instead of hand-freeing key data.
|
||||
In asn1_k_encode.c, remove an unnecessary memset() of the kdc_req_hack
|
||||
shell before returning.
|
||||
|
||||
(cherry picked from commit 1057b0befec1f1c0e9d4da5521a58496e2dc0997)
|
||||
---
|
||||
src/clients/ksu/krb_auth_su.c | 4 +---
|
||||
src/lib/gssapi/krb5/iakerb.c | 1 -
|
||||
src/lib/kadm5/srv/svr_principal.c | 10 ++--------
|
||||
src/lib/krb5/asn.1/asn1_k_encode.c | 1 -
|
||||
4 files changed, 3 insertions(+), 13 deletions(-)
|
||||
|
||||
diff --git a/src/clients/ksu/krb_auth_su.c b/src/clients/ksu/krb_auth_su.c
|
||||
index 7af48195c..e39685fff 100644
|
||||
--- a/src/clients/ksu/krb_auth_su.c
|
||||
+++ b/src/clients/ksu/krb_auth_su.c
|
||||
@@ -183,21 +183,19 @@ krb5_boolean ksu_get_tgt_via_passwd(context, client, options, zero_password,
|
||||
if (code ) {
|
||||
com_err(prog_name, code, _("while reading password for '%s'\n"),
|
||||
client_name);
|
||||
- memset(password, 0, sizeof(password));
|
||||
return (FALSE);
|
||||
}
|
||||
|
||||
if ( pwsize == 0) {
|
||||
fprintf(stderr, _("No password given\n"));
|
||||
*zero_password = TRUE;
|
||||
- memset(password, 0, sizeof(password));
|
||||
return (FALSE);
|
||||
}
|
||||
|
||||
code = krb5_get_init_creds_password(context, &creds, client, password,
|
||||
krb5_prompter_posix, NULL, 0, NULL,
|
||||
options);
|
||||
- memset(password, 0, sizeof(password));
|
||||
+ zap(password, sizeof(password));
|
||||
|
||||
|
||||
if (code) {
|
||||
diff --git a/src/lib/gssapi/krb5/iakerb.c b/src/lib/gssapi/krb5/iakerb.c
|
||||
index bb1072fe4..47c161ec9 100644
|
||||
--- a/src/lib/gssapi/krb5/iakerb.c
|
||||
+++ b/src/lib/gssapi/krb5/iakerb.c
|
||||
@@ -262,7 +262,6 @@ iakerb_make_token(iakerb_ctx_id_t ctx,
|
||||
/*
|
||||
* Assemble the IAKERB-HEADER from the realm and cookie
|
||||
*/
|
||||
- memset(&iah, 0, sizeof(iah));
|
||||
iah.target_realm = *realm;
|
||||
iah.cookie = cookie;
|
||||
|
||||
diff --git a/src/lib/kadm5/srv/svr_principal.c b/src/lib/kadm5/srv/svr_principal.c
|
||||
index 21c53ece1..9ab2c5a74 100644
|
||||
--- a/src/lib/kadm5/srv/svr_principal.c
|
||||
+++ b/src/lib/kadm5/srv/svr_principal.c
|
||||
@@ -2093,14 +2093,8 @@ static int decrypt_key_data(krb5_context context,
|
||||
ret = krb5_dbe_decrypt_key_data(context, NULL, &key_data[i], &keys[i],
|
||||
NULL);
|
||||
if (ret) {
|
||||
- for (; i >= 0; i--) {
|
||||
- if (keys[i].contents) {
|
||||
- memset (keys[i].contents, 0, keys[i].length);
|
||||
- free( keys[i].contents );
|
||||
- }
|
||||
- }
|
||||
-
|
||||
- memset(keys, 0, n_key_data*sizeof(krb5_keyblock));
|
||||
+ for (; i >= 0; i--)
|
||||
+ krb5_free_keyblock_contents(context, &keys[i]);
|
||||
free(keys);
|
||||
return ret;
|
||||
}
|
||||
diff --git a/src/lib/krb5/asn.1/asn1_k_encode.c b/src/lib/krb5/asn.1/asn1_k_encode.c
|
||||
index 65c84be2f..81a34bac9 100644
|
||||
--- a/src/lib/krb5/asn.1/asn1_k_encode.c
|
||||
+++ b/src/lib/krb5/asn.1/asn1_k_encode.c
|
||||
@@ -528,7 +528,6 @@ decode_kdc_req_body(const taginfo *t, const uint8_t *asn1, size_t len,
|
||||
if (ret) {
|
||||
free_kdc_req_body(b);
|
||||
free(h.server_realm.data);
|
||||
- memset(&h, 0, sizeof(h));
|
||||
return ret;
|
||||
}
|
||||
b->server->realm = h.server_realm;
|
||||
|
|
@ -1,63 +0,0 @@
|
|||
From c39a5710d0e4039a4f2bbd53ec284eb89d3b83c4 Mon Sep 17 00:00:00 2001
|
||||
From: Robbie Harwood <rharwood@redhat.com>
|
||||
Date: Mon, 6 May 2019 15:14:49 -0400
|
||||
Subject: [PATCH] Avoid alignment warnings in openssl rc4.c
|
||||
|
||||
Add a comment to k5_arcfour_init_state() explaining how we stretch the
|
||||
krb5_data cipher state contract. Use void * casts when interpreting
|
||||
the data pointer to avoid alignment warnings.
|
||||
|
||||
[ghudson@mit.edu: moved and expanded comment; rewrote commit message]
|
||||
|
||||
(cherry picked from commit 1cd41d76c12fc1cea0a8bf0d6a40f34623c60d6d)
|
||||
---
|
||||
src/lib/crypto/openssl/enc_provider/rc4.c | 15 ++++++++++++---
|
||||
1 file changed, 12 insertions(+), 3 deletions(-)
|
||||
|
||||
diff --git a/src/lib/crypto/openssl/enc_provider/rc4.c b/src/lib/crypto/openssl/enc_provider/rc4.c
|
||||
index 7f3c086ed..a65d57b7a 100644
|
||||
--- a/src/lib/crypto/openssl/enc_provider/rc4.c
|
||||
+++ b/src/lib/crypto/openssl/enc_provider/rc4.c
|
||||
@@ -57,7 +57,7 @@ struct arcfour_state {
|
||||
|
||||
/* In-place IOV crypto */
|
||||
static krb5_error_code
|
||||
-k5_arcfour_docrypt(krb5_key key,const krb5_data *state, krb5_crypto_iov *data,
|
||||
+k5_arcfour_docrypt(krb5_key key, const krb5_data *state, krb5_crypto_iov *data,
|
||||
size_t num_data)
|
||||
{
|
||||
size_t i;
|
||||
@@ -66,7 +66,7 @@ k5_arcfour_docrypt(krb5_key key,const krb5_data *state, krb5_crypto_iov *data,
|
||||
EVP_CIPHER_CTX *ctx = NULL;
|
||||
struct arcfour_state *arcstate;
|
||||
|
||||
- arcstate = (state != NULL) ? (struct arcfour_state *) state->data : NULL;
|
||||
+ arcstate = (state != NULL) ? (void *)state->data : NULL;
|
||||
if (arcstate != NULL) {
|
||||
ctx = arcstate->ctx;
|
||||
if (arcstate->loopback != arcstate)
|
||||
@@ -113,7 +113,7 @@ k5_arcfour_docrypt(krb5_key key,const krb5_data *state, krb5_crypto_iov *data,
|
||||
static void
|
||||
k5_arcfour_free_state(krb5_data *state)
|
||||
{
|
||||
- struct arcfour_state *arcstate = (struct arcfour_state *) state->data;
|
||||
+ struct arcfour_state *arcstate = (void *)state->data;
|
||||
|
||||
EVP_CIPHER_CTX_free(arcstate->ctx);
|
||||
free(arcstate);
|
||||
@@ -125,6 +125,15 @@ k5_arcfour_init_state(const krb5_keyblock *key,
|
||||
{
|
||||
struct arcfour_state *arcstate;
|
||||
|
||||
+ /*
|
||||
+ * The cipher state here is a saved pointer to a struct arcfour_state
|
||||
+ * object, rather than a flat byte array as in most enc providers. The
|
||||
+ * object includes a loopback pointer to detect if if the caller made a
|
||||
+ * copy of the krb5_data value or otherwise assumed it was a simple byte
|
||||
+ * array. When we cast the data pointer back, we need to go through void *
|
||||
+ * to avoid increased alignment warnings.
|
||||
+ */
|
||||
+
|
||||
/* Create a state structure with an uninitialized context. */
|
||||
arcstate = calloc(1, sizeof(*arcstate));
|
||||
if (arcstate == NULL)
|
||||
|
|
@ -1,55 +0,0 @@
|
|||
From 7491d9ed5c358960c6344c2581db9cafaf308f06 Mon Sep 17 00:00:00 2001
|
||||
From: Andreas Schneider <asn@samba.org>
|
||||
Date: Thu, 3 Jan 2019 17:19:32 +0100
|
||||
Subject: [PATCH] Avoid allocating a register in zap() assembly
|
||||
|
||||
See https://bugs.llvm.org/show_bug.cgi?id=15495
|
||||
|
||||
Also add explicit_bzero() (glibc, FreeBSD) and explicit_memset()
|
||||
(NetBSD) as alternatives.
|
||||
|
||||
[ghudson@mit.edu: added explicit_bzero() and explicit_memset()]
|
||||
|
||||
(cherry picked from commit 7391e8b541061d0f584193b4a53365b64364b0e8)
|
||||
---
|
||||
src/configure.in | 2 +-
|
||||
src/include/k5-platform.h | 6 +++++-
|
||||
2 files changed, 6 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/src/configure.in b/src/configure.in
|
||||
index 93aec682e..7c309a26b 100644
|
||||
--- a/src/configure.in
|
||||
+++ b/src/configure.in
|
||||
@@ -421,7 +421,7 @@ AC_PROG_LEX
|
||||
AC_C_CONST
|
||||
AC_HEADER_DIRENT
|
||||
AC_FUNC_STRERROR_R
|
||||
-AC_CHECK_FUNCS(strdup setvbuf seteuid setresuid setreuid setegid setresgid setregid setsid flock fchmod chmod strptime geteuid setenv unsetenv getenv gmtime_r localtime_r bswap16 bswap64 mkstemp getusershell access getcwd srand48 srand srandom stat strchr strerror timegm)
|
||||
+AC_CHECK_FUNCS(strdup setvbuf seteuid setresuid setreuid setegid setresgid setregid setsid flock fchmod chmod strptime geteuid setenv unsetenv getenv gmtime_r localtime_r bswap16 bswap64 mkstemp getusershell access getcwd srand48 srand srandom stat strchr strerror timegm explicit_bzero explicit_memset)
|
||||
|
||||
AC_CHECK_FUNC(mkstemp,
|
||||
[MKSTEMP_ST_OBJ=
|
||||
diff --git a/src/include/k5-platform.h b/src/include/k5-platform.h
|
||||
index 997b655e1..1fcd68e8c 100644
|
||||
--- a/src/include/k5-platform.h
|
||||
+++ b/src/include/k5-platform.h
|
||||
@@ -1023,6 +1023,10 @@ static inline void zap(void *ptr, size_t len)
|
||||
if (len > 0)
|
||||
memset_s(ptr, len, 0, len);
|
||||
}
|
||||
+#elif defined(HAVE_EXPLICIT_BZERO)
|
||||
+# define zap(ptr, len) explicit_bzero(ptr, len)
|
||||
+#elif defined(HAVE_EXPLICIT_MEMSET)
|
||||
+# define zap(ptr, len) explicit_memset(ptr, 0, len)
|
||||
#elif defined(__GNUC__) || defined(__clang__)
|
||||
/*
|
||||
* Use an asm statement which declares a memory clobber to force the memset to
|
||||
@@ -1032,7 +1036,7 @@ static inline void zap(void *ptr, size_t len)
|
||||
{
|
||||
if (len > 0)
|
||||
memset(ptr, 0, len);
|
||||
- __asm__ __volatile__("" : : "r" (ptr) : "memory");
|
||||
+ __asm__ __volatile__("" : : "g" (ptr) : "memory");
|
||||
}
|
||||
#else
|
||||
/*
|
||||
|
|
@ -1,88 +0,0 @@
|
|||
From 842524798c7f69edcef3f01cae7a9a6f126ed1dc Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Mon, 22 Apr 2019 14:26:42 -0400
|
||||
Subject: [PATCH] Check more errors in OpenSSL crypto backend
|
||||
|
||||
In krb5int_hmac_keyblock() and krb5int_pbkdf2_hmac(), check for errors
|
||||
from previously unchecked OpenSSL function calls and return
|
||||
KRB5_CRYPTO_INTERNAL if they fail.
|
||||
|
||||
HMAC_Init() is deprecated in OpenSSL 1.0 and later; as we are
|
||||
modifying the call to check for errors, call HMAC_Init_ex() instead.
|
||||
|
||||
ticket: 8799 (new)
|
||||
(cherry picked from commit 2298e5c2ff1122bcaff715129f5b746e77c3f42a)
|
||||
---
|
||||
src/lib/crypto/openssl/hmac.c | 18 +++++++++---------
|
||||
src/lib/crypto/openssl/pbkdf2.c | 9 +++++----
|
||||
2 files changed, 14 insertions(+), 13 deletions(-)
|
||||
|
||||
diff --git a/src/lib/crypto/openssl/hmac.c b/src/lib/crypto/openssl/hmac.c
|
||||
index b2db6ec02..7dc59dcc0 100644
|
||||
--- a/src/lib/crypto/openssl/hmac.c
|
||||
+++ b/src/lib/crypto/openssl/hmac.c
|
||||
@@ -117,7 +117,7 @@ krb5int_hmac_keyblock(const struct krb5_hash_provider *hash,
|
||||
const krb5_crypto_iov *data, size_t num_data,
|
||||
krb5_data *output)
|
||||
{
|
||||
- unsigned int i = 0, md_len = 0;
|
||||
+ unsigned int i = 0, md_len = 0, ok;
|
||||
unsigned char md[EVP_MAX_MD_SIZE];
|
||||
HMAC_CTX *ctx;
|
||||
size_t hashsize, blocksize;
|
||||
@@ -137,22 +137,22 @@ krb5int_hmac_keyblock(const struct krb5_hash_provider *hash,
|
||||
if (ctx == NULL)
|
||||
return ENOMEM;
|
||||
|
||||
- HMAC_Init(ctx, keyblock->contents, keyblock->length, map_digest(hash));
|
||||
- for (i = 0; i < num_data; i++) {
|
||||
+ ok = HMAC_Init_ex(ctx, keyblock->contents, keyblock->length,
|
||||
+ map_digest(hash), NULL);
|
||||
+ for (i = 0; ok && i < num_data; i++) {
|
||||
const krb5_crypto_iov *iov = &data[i];
|
||||
|
||||
if (SIGN_IOV(iov))
|
||||
- HMAC_Update(ctx, (uint8_t *)iov->data.data, iov->data.length);
|
||||
+ ok = HMAC_Update(ctx, (uint8_t *)iov->data.data, iov->data.length);
|
||||
}
|
||||
- HMAC_Final(ctx, md, &md_len);
|
||||
- if ( md_len <= output->length) {
|
||||
+ if (ok)
|
||||
+ ok = HMAC_Final(ctx, md, &md_len);
|
||||
+ if (ok && md_len <= output->length) {
|
||||
output->length = md_len;
|
||||
memcpy(output->data, md, output->length);
|
||||
}
|
||||
HMAC_CTX_free(ctx);
|
||||
- return 0;
|
||||
-
|
||||
-
|
||||
+ return ok ? 0 : KRB5_CRYPTO_INTERNAL;
|
||||
}
|
||||
|
||||
krb5_error_code
|
||||
diff --git a/src/lib/crypto/openssl/pbkdf2.c b/src/lib/crypto/openssl/pbkdf2.c
|
||||
index 00c2116fc..732ec6405 100644
|
||||
--- a/src/lib/crypto/openssl/pbkdf2.c
|
||||
+++ b/src/lib/crypto/openssl/pbkdf2.c
|
||||
@@ -35,6 +35,7 @@ krb5int_pbkdf2_hmac(const struct krb5_hash_provider *hash,
|
||||
const krb5_data *pass, const krb5_data *salt)
|
||||
{
|
||||
const EVP_MD *md = NULL;
|
||||
+ int ok;
|
||||
|
||||
/* Get the message digest handle corresponding to the hash. */
|
||||
if (hash == &krb5int_hash_sha1)
|
||||
@@ -46,8 +47,8 @@ krb5int_pbkdf2_hmac(const struct krb5_hash_provider *hash,
|
||||
if (md == NULL)
|
||||
return KRB5_CRYPTO_INTERNAL;
|
||||
|
||||
- PKCS5_PBKDF2_HMAC(pass->data, pass->length, (unsigned char *)salt->data,
|
||||
- salt->length, count, md, out->length,
|
||||
- (unsigned char *)out->data);
|
||||
- return 0;
|
||||
+ ok = PKCS5_PBKDF2_HMAC(pass->data, pass->length,
|
||||
+ (unsigned char *)salt->data, salt->length, count,
|
||||
+ md, out->length, (unsigned char *)out->data);
|
||||
+ return ok ? 0 : KRB5_CRYPTO_INTERNAL;
|
||||
}
|
||||
|
|
@ -1,31 +0,0 @@
|
|||
From 2f50c282127bf8d4c570986c212fbc1e910fb8c5 Mon Sep 17 00:00:00 2001
|
||||
From: Robbie Harwood <rharwood@redhat.com>
|
||||
Date: Tue, 2 Apr 2019 14:18:57 -0400
|
||||
Subject: [PATCH] Clarify header comment for krb5_cc_start_seq_get()
|
||||
|
||||
Previously this comment seemed to suggest that applications needed to
|
||||
block all other access to the ccache (including by other processes)
|
||||
during iteration.
|
||||
|
||||
(cherry picked from commit f4f51a25dd38601357e2f64b17b51eb23f45a53e)
|
||||
---
|
||||
src/include/krb5/krb5.hin | 6 ++++--
|
||||
1 file changed, 4 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/src/include/krb5/krb5.hin b/src/include/krb5/krb5.hin
|
||||
index 3ff86d7ff..346e796a5 100644
|
||||
--- a/src/include/krb5/krb5.hin
|
||||
+++ b/src/include/krb5/krb5.hin
|
||||
@@ -2491,8 +2491,10 @@ krb5_cc_get_principal(krb5_context context, krb5_ccache cache,
|
||||
*
|
||||
* krb5_cc_end_seq_get() must be called to complete the retrieve operation.
|
||||
*
|
||||
- * @note If @a cache is modified between the time of the call to this function
|
||||
- * and the time of the final krb5_cc_end_seq_get(), the results are undefined.
|
||||
+ * @note If the cache represented by @a cache is modified between the time of
|
||||
+ * the call to this function and the time of the final krb5_cc_end_seq_get(),
|
||||
+ * these changes may not be reflected in the results of krb5_cc_next_cred()
|
||||
+ * calls.
|
||||
*
|
||||
* @retval 0 Success; otherwise - Kerberos error codes
|
||||
*/
|
||||
|
|
@ -1,485 +0,0 @@
|
|||
From 6bd9bc03f2ad2aa5415d738c28180def7e17874f Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Thu, 15 Nov 2018 13:40:43 -0500
|
||||
Subject: [PATCH] Clear forwardable flag instead of denying request
|
||||
|
||||
If the client requests a forwardable or proxiable ticket and the
|
||||
option cannot be honored by policy, issue a non-forwardable or
|
||||
non-proxiable ticket rather than denying the request.
|
||||
|
||||
Add a test script for testing KDC request options and populate it with
|
||||
tests for the forwardable and proxiable flags.
|
||||
|
||||
ticket: 7871
|
||||
(cherry picked from commit 08e948cce2c79a3604066fcf7a64fc527456f83d)
|
||||
---
|
||||
src/kdc/do_as_req.c | 19 ++------
|
||||
src/kdc/do_tgs_req.c | 58 +++++-----------------
|
||||
src/kdc/kdc_util.c | 82 ++++++++++++++++++-------------
|
||||
src/kdc/kdc_util.h | 9 ++--
|
||||
src/kdc/tgs_policy.c | 8 +--
|
||||
src/tests/Makefile.in | 1 +
|
||||
src/tests/gcred.c | 28 ++++++++---
|
||||
src/tests/t_kdcoptions.py | 100 ++++++++++++++++++++++++++++++++++++++
|
||||
8 files changed, 190 insertions(+), 115 deletions(-)
|
||||
create mode 100644 src/tests/t_kdcoptions.py
|
||||
|
||||
diff --git a/src/kdc/do_as_req.c b/src/kdc/do_as_req.c
|
||||
index 588c1375a..8a96c12a9 100644
|
||||
--- a/src/kdc/do_as_req.c
|
||||
+++ b/src/kdc/do_as_req.c
|
||||
@@ -192,13 +192,6 @@ finish_process_as_req(struct as_req_state *state, krb5_error_code errcode)
|
||||
|
||||
au_state->stage = ENCR_REP;
|
||||
|
||||
- if ((errcode = validate_forwardable(state->request, *state->client,
|
||||
- *state->server, state->kdc_time,
|
||||
- &state->status))) {
|
||||
- errcode += ERROR_TABLE_BASE_krb5;
|
||||
- goto egress;
|
||||
- }
|
||||
-
|
||||
errcode = check_indicators(kdc_context, state->server,
|
||||
state->auth_indicators);
|
||||
if (errcode) {
|
||||
@@ -708,12 +701,11 @@ process_as_req(krb5_kdc_req *request, krb5_data *req_pkt,
|
||||
}
|
||||
|
||||
/* Copy options that request the corresponding ticket flags. */
|
||||
- state->enc_tkt_reply.flags = OPTS2FLAGS(state->request->kdc_options);
|
||||
+ state->enc_tkt_reply.flags = get_ticket_flags(state->request->kdc_options,
|
||||
+ state->client, state->server,
|
||||
+ NULL);
|
||||
state->enc_tkt_reply.times.authtime = state->authtime;
|
||||
|
||||
- setflag(state->enc_tkt_reply.flags, TKT_FLG_INITIAL);
|
||||
- setflag(state->enc_tkt_reply.flags, TKT_FLG_ENC_PA_REP);
|
||||
-
|
||||
/*
|
||||
* It should be noted that local policy may affect the
|
||||
* processing of any of these flags. For example, some
|
||||
@@ -732,10 +724,9 @@ process_as_req(krb5_kdc_req *request, krb5_data *req_pkt,
|
||||
state->enc_tkt_reply.transited.tr_type = KRB5_DOMAIN_X500_COMPRESS;
|
||||
state->enc_tkt_reply.transited.tr_contents = empty_string;
|
||||
|
||||
- if (isflagset(state->request->kdc_options, KDC_OPT_POSTDATED)) {
|
||||
- setflag(state->enc_tkt_reply.flags, TKT_FLG_INVALID);
|
||||
+ if (isflagset(state->request->kdc_options, KDC_OPT_POSTDATED))
|
||||
state->enc_tkt_reply.times.starttime = state->request->from;
|
||||
- } else
|
||||
+ else
|
||||
state->enc_tkt_reply.times.starttime = state->kdc_time;
|
||||
|
||||
kdc_get_ticket_endtime(kdc_active_realm,
|
||||
diff --git a/src/kdc/do_tgs_req.c b/src/kdc/do_tgs_req.c
|
||||
index 587342a6c..1da099318 100644
|
||||
--- a/src/kdc/do_tgs_req.c
|
||||
+++ b/src/kdc/do_tgs_req.c
|
||||
@@ -378,15 +378,16 @@ process_tgs_req(krb5_kdc_req *request, krb5_data *pkt,
|
||||
else
|
||||
ticket_reply.server = request->server; /* XXX careful for realm... */
|
||||
|
||||
- enc_tkt_reply.flags = OPTS2FLAGS(request->kdc_options);
|
||||
- enc_tkt_reply.flags |= COPY_TKT_FLAGS(header_enc_tkt->flags);
|
||||
+ enc_tkt_reply.flags = get_ticket_flags(request->kdc_options, client,
|
||||
+ server, header_enc_tkt);
|
||||
enc_tkt_reply.times.starttime = 0;
|
||||
|
||||
- if (isflagset(server->attributes, KRB5_KDB_OK_AS_DELEGATE))
|
||||
- setflag(enc_tkt_reply.flags, TKT_FLG_OK_AS_DELEGATE);
|
||||
-
|
||||
- /* Indicate support for encrypted padata (RFC 6806). */
|
||||
- setflag(enc_tkt_reply.flags, TKT_FLG_ENC_PA_REP);
|
||||
+ /* OK_TO_AUTH_AS_DELEGATE must be set on the service requesting S4U2Self
|
||||
+ * for forwardable tickets to be issued. */
|
||||
+ if (isflagset(c_flags, KRB5_KDB_FLAG_PROTOCOL_TRANSITION) &&
|
||||
+ !is_referral &&
|
||||
+ !isflagset(server->attributes, KRB5_KDB_OK_TO_AUTH_AS_DELEGATE))
|
||||
+ clear(enc_tkt_reply.flags, TKT_FLG_FORWARDABLE);
|
||||
|
||||
/* don't use new addresses unless forwarded, see below */
|
||||
|
||||
@@ -401,37 +402,6 @@ process_tgs_req(krb5_kdc_req *request, krb5_data *pkt,
|
||||
* realms may refuse to issue renewable tickets
|
||||
*/
|
||||
|
||||
- if (isflagset(request->kdc_options, KDC_OPT_FORWARDABLE)) {
|
||||
-
|
||||
- if (isflagset(c_flags, KRB5_KDB_FLAG_PROTOCOL_TRANSITION)) {
|
||||
- /*
|
||||
- * If S4U2Self principal is not forwardable, then mark ticket as
|
||||
- * unforwardable. This behaviour matches Windows, but it is
|
||||
- * different to the MIT AS-REQ path, which returns an error
|
||||
- * (KDC_ERR_POLICY) if forwardable tickets cannot be issued.
|
||||
- *
|
||||
- * Consider this block the S4U2Self equivalent to
|
||||
- * validate_forwardable().
|
||||
- */
|
||||
- if (client != NULL &&
|
||||
- isflagset(client->attributes, KRB5_KDB_DISALLOW_FORWARDABLE))
|
||||
- clear(enc_tkt_reply.flags, TKT_FLG_FORWARDABLE);
|
||||
- /*
|
||||
- * Forwardable flag is propagated along referral path.
|
||||
- */
|
||||
- else if (!isflagset(header_enc_tkt->flags, TKT_FLG_FORWARDABLE))
|
||||
- clear(enc_tkt_reply.flags, TKT_FLG_FORWARDABLE);
|
||||
- /*
|
||||
- * OK_TO_AUTH_AS_DELEGATE must be set on the service requesting
|
||||
- * S4U2Self in order for forwardable tickets to be returned.
|
||||
- */
|
||||
- else if (!is_referral &&
|
||||
- !isflagset(server->attributes,
|
||||
- KRB5_KDB_OK_TO_AUTH_AS_DELEGATE))
|
||||
- clear(enc_tkt_reply.flags, TKT_FLG_FORWARDABLE);
|
||||
- }
|
||||
- }
|
||||
-
|
||||
if (isflagset(request->kdc_options, KDC_OPT_FORWARDED) ||
|
||||
isflagset(request->kdc_options, KDC_OPT_PROXY)) {
|
||||
|
||||
@@ -440,16 +410,10 @@ process_tgs_req(krb5_kdc_req *request, krb5_data *pkt,
|
||||
enc_tkt_reply.caddrs = request->addresses;
|
||||
reply_encpart.caddrs = request->addresses;
|
||||
}
|
||||
- /* We don't currently handle issuing anonymous tickets based on
|
||||
- * non-anonymous ones, so just ignore the option. */
|
||||
- if (isflagset(request->kdc_options, KDC_OPT_REQUEST_ANONYMOUS) &&
|
||||
- !isflagset(header_enc_tkt->flags, TKT_FLG_ANONYMOUS))
|
||||
- clear(enc_tkt_reply.flags, TKT_FLG_ANONYMOUS);
|
||||
-
|
||||
- if (isflagset(request->kdc_options, KDC_OPT_POSTDATED)) {
|
||||
- setflag(enc_tkt_reply.flags, TKT_FLG_INVALID);
|
||||
+
|
||||
+ if (isflagset(request->kdc_options, KDC_OPT_POSTDATED))
|
||||
enc_tkt_reply.times.starttime = request->from;
|
||||
- } else
|
||||
+ else
|
||||
enc_tkt_reply.times.starttime = kdc_time;
|
||||
|
||||
if (isflagset(request->kdc_options, KDC_OPT_VALIDATE)) {
|
||||
diff --git a/src/kdc/kdc_util.c b/src/kdc/kdc_util.c
|
||||
index 96c88edc1..f2741090e 100644
|
||||
--- a/src/kdc/kdc_util.c
|
||||
+++ b/src/kdc/kdc_util.c
|
||||
@@ -697,29 +697,6 @@ validate_as_request(kdc_realm_t *kdc_active_realm,
|
||||
return(KDC_ERR_CANNOT_POSTDATE);
|
||||
}
|
||||
|
||||
- /*
|
||||
- * A Windows KDC will return KDC_ERR_PREAUTH_REQUIRED instead of
|
||||
- * KDC_ERR_POLICY in the following case:
|
||||
- *
|
||||
- * - KDC_OPT_FORWARDABLE is set in KDCOptions but local
|
||||
- * policy has KRB5_KDB_DISALLOW_FORWARDABLE set for the
|
||||
- * client, and;
|
||||
- * - KRB5_KDB_REQUIRES_PRE_AUTH is set for the client but
|
||||
- * preauthentication data is absent in the request.
|
||||
- *
|
||||
- * Hence, this check most be done after the check for preauth
|
||||
- * data, and is now performed by validate_forwardable() (the
|
||||
- * contents of which were previously below).
|
||||
- */
|
||||
-
|
||||
- /* Client and server must allow proxiable tickets */
|
||||
- if (isflagset(request->kdc_options, KDC_OPT_PROXIABLE) &&
|
||||
- (isflagset(client.attributes, KRB5_KDB_DISALLOW_PROXIABLE) ||
|
||||
- isflagset(server.attributes, KRB5_KDB_DISALLOW_PROXIABLE))) {
|
||||
- *status = "PROXIABLE NOT ALLOWED";
|
||||
- return(KDC_ERR_POLICY);
|
||||
- }
|
||||
-
|
||||
/* Check to see if client is locked out */
|
||||
if (isflagset(client.attributes, KRB5_KDB_DISALLOW_ALL_TIX)) {
|
||||
*status = "CLIENT LOCKED OUT";
|
||||
@@ -752,19 +729,54 @@ validate_as_request(kdc_realm_t *kdc_active_realm,
|
||||
return 0;
|
||||
}
|
||||
|
||||
-int
|
||||
-validate_forwardable(krb5_kdc_req *request, krb5_db_entry client,
|
||||
- krb5_db_entry server, krb5_timestamp kdc_time,
|
||||
- const char **status)
|
||||
+/*
|
||||
+ * Compute ticket flags based on the request, the client and server DB entry
|
||||
+ * (which may prohibit forwardable or proxiable tickets), and the header
|
||||
+ * ticket. client may be NULL for a TGS request (although it may be set, such
|
||||
+ * as for an S4U2Self request). header_enc may be NULL for an AS request.
|
||||
+ */
|
||||
+krb5_flags
|
||||
+get_ticket_flags(krb5_flags reqflags, krb5_db_entry *client,
|
||||
+ krb5_db_entry *server, krb5_enc_tkt_part *header_enc)
|
||||
{
|
||||
- *status = NULL;
|
||||
- if (isflagset(request->kdc_options, KDC_OPT_FORWARDABLE) &&
|
||||
- (isflagset(client.attributes, KRB5_KDB_DISALLOW_FORWARDABLE) ||
|
||||
- isflagset(server.attributes, KRB5_KDB_DISALLOW_FORWARDABLE))) {
|
||||
- *status = "FORWARDABLE NOT ALLOWED";
|
||||
- return(KDC_ERR_POLICY);
|
||||
- } else
|
||||
- return 0;
|
||||
+ krb5_flags flags;
|
||||
+
|
||||
+ /* Indicate support for encrypted padata (RFC 6806), and set flags based on
|
||||
+ * request options and the header ticket. */
|
||||
+ flags = OPTS2FLAGS(reqflags) | TKT_FLG_ENC_PA_REP;
|
||||
+ if (reqflags & KDC_OPT_POSTDATED)
|
||||
+ flags |= TKT_FLG_INVALID;
|
||||
+ if (header_enc != NULL)
|
||||
+ flags |= COPY_TKT_FLAGS(header_enc->flags);
|
||||
+ if (header_enc == NULL)
|
||||
+ flags |= TKT_FLG_INITIAL;
|
||||
+
|
||||
+ /* For TGS requests, indicate if the service is marked ok-as-delegate. */
|
||||
+ if (header_enc != NULL && (server->attributes & KRB5_KDB_OK_AS_DELEGATE))
|
||||
+ flags |= TKT_FLG_OK_AS_DELEGATE;
|
||||
+
|
||||
+ /* Unset PROXIABLE if it is disallowed. */
|
||||
+ if (client != NULL && (client->attributes & KRB5_KDB_DISALLOW_PROXIABLE))
|
||||
+ flags &= ~TKT_FLG_PROXIABLE;
|
||||
+ if (server->attributes & KRB5_KDB_DISALLOW_PROXIABLE)
|
||||
+ flags &= ~TKT_FLG_PROXIABLE;
|
||||
+ if (header_enc != NULL && !(header_enc->flags & TKT_FLG_PROXIABLE))
|
||||
+ flags &= ~TKT_FLG_PROXIABLE;
|
||||
+
|
||||
+ /* Unset FORWARDABLE if it is disallowed. */
|
||||
+ if (client != NULL && (client->attributes & KRB5_KDB_DISALLOW_FORWARDABLE))
|
||||
+ flags &= ~TKT_FLG_FORWARDABLE;
|
||||
+ if (server->attributes & KRB5_KDB_DISALLOW_FORWARDABLE)
|
||||
+ flags &= ~TKT_FLG_FORWARDABLE;
|
||||
+ if (header_enc != NULL && !(header_enc->flags & TKT_FLG_FORWARDABLE))
|
||||
+ flags &= ~TKT_FLG_FORWARDABLE;
|
||||
+
|
||||
+ /* We don't currently handle issuing anonymous tickets based on
|
||||
+ * non-anonymous ones. */
|
||||
+ if (header_enc != NULL && !(header_enc->flags & TKT_FLG_ANONYMOUS))
|
||||
+ flags &= ~TKT_FLG_ANONYMOUS;
|
||||
+
|
||||
+ return flags;
|
||||
}
|
||||
|
||||
/* Return KRB5KDC_ERR_POLICY if indicators does not contain the required auth
|
||||
diff --git a/src/kdc/kdc_util.h b/src/kdc/kdc_util.h
|
||||
index 25077cbf5..1314bdd58 100644
|
||||
--- a/src/kdc/kdc_util.h
|
||||
+++ b/src/kdc/kdc_util.h
|
||||
@@ -85,16 +85,15 @@ validate_as_request (kdc_realm_t *, krb5_kdc_req *, krb5_db_entry,
|
||||
krb5_db_entry, krb5_timestamp,
|
||||
const char **, krb5_pa_data ***);
|
||||
|
||||
-int
|
||||
-validate_forwardable(krb5_kdc_req *, krb5_db_entry,
|
||||
- krb5_db_entry, krb5_timestamp,
|
||||
- const char **);
|
||||
-
|
||||
int
|
||||
validate_tgs_request (kdc_realm_t *, krb5_kdc_req *, krb5_db_entry,
|
||||
krb5_ticket *, krb5_timestamp,
|
||||
const char **, krb5_pa_data ***);
|
||||
|
||||
+krb5_flags
|
||||
+get_ticket_flags(krb5_flags reqflags, krb5_db_entry *client,
|
||||
+ krb5_db_entry *server, krb5_enc_tkt_part *header_enc);
|
||||
+
|
||||
krb5_error_code
|
||||
check_indicators(krb5_context context, krb5_db_entry *server,
|
||||
krb5_data *const *indicators);
|
||||
diff --git a/src/kdc/tgs_policy.c b/src/kdc/tgs_policy.c
|
||||
index 907fcd330..554345ba5 100644
|
||||
--- a/src/kdc/tgs_policy.c
|
||||
+++ b/src/kdc/tgs_policy.c
|
||||
@@ -63,9 +63,9 @@ static check_tgs_svc_pol_fn * const svc_pol_fns[] = {
|
||||
};
|
||||
|
||||
static const struct tgsflagrule tgsflagrules[] = {
|
||||
- { (KDC_OPT_FORWARDED | KDC_OPT_FORWARDABLE), TKT_FLG_FORWARDABLE,
|
||||
+ { KDC_OPT_FORWARDED, TKT_FLG_FORWARDABLE,
|
||||
"TGT NOT FORWARDABLE", KDC_ERR_BADOPTION },
|
||||
- { (KDC_OPT_PROXY | KDC_OPT_PROXIABLE), TKT_FLG_PROXIABLE,
|
||||
+ { KDC_OPT_PROXY, TKT_FLG_PROXIABLE,
|
||||
"TGT NOT PROXIABLE", KDC_ERR_BADOPTION },
|
||||
{ (KDC_OPT_ALLOW_POSTDATE | KDC_OPT_POSTDATED), TKT_FLG_MAY_POSTDATE,
|
||||
"TGT NOT POSTDATABLE", KDC_ERR_BADOPTION },
|
||||
@@ -98,12 +98,8 @@ check_tgs_opts(krb5_kdc_req *req, krb5_ticket *tkt, const char **status)
|
||||
}
|
||||
|
||||
static const struct tgsflagrule svcdenyrules[] = {
|
||||
- { KDC_OPT_FORWARDABLE, KRB5_KDB_DISALLOW_FORWARDABLE,
|
||||
- "NON-FORWARDABLE TICKET", KDC_ERR_POLICY },
|
||||
{ KDC_OPT_RENEWABLE, KRB5_KDB_DISALLOW_RENEWABLE,
|
||||
"NON-RENEWABLE TICKET", KDC_ERR_POLICY },
|
||||
- { KDC_OPT_PROXIABLE, KRB5_KDB_DISALLOW_PROXIABLE,
|
||||
- "NON-PROXIABLE TICKET", KDC_ERR_POLICY },
|
||||
{ KDC_OPT_ALLOW_POSTDATE, KRB5_KDB_DISALLOW_POSTDATED,
|
||||
"NON-POSTDATABLE TICKET", KDC_ERR_CANNOT_POSTDATE },
|
||||
{ KDC_OPT_ENC_TKT_IN_SKEY, KRB5_KDB_DISALLOW_DUP_SKEY,
|
||||
diff --git a/src/tests/Makefile.in b/src/tests/Makefile.in
|
||||
index c96c5d6b7..d2a37c616 100644
|
||||
--- a/src/tests/Makefile.in
|
||||
+++ b/src/tests/Makefile.in
|
||||
@@ -171,6 +171,7 @@ check-pytests: unlockiter
|
||||
$(RUNPYTEST) $(srcdir)/t_y2038.py $(PYTESTFLAGS)
|
||||
$(RUNPYTEST) $(srcdir)/t_kdcpolicy.py $(PYTESTFLAGS)
|
||||
$(RUNPYTEST) $(srcdir)/t_u2u.py $(PYTESTFLAGS)
|
||||
+ $(RUNPYTEST) $(srcdir)/t_kdcoptions.py $(PYTESTFLAGS)
|
||||
|
||||
clean:
|
||||
$(RM) adata etinfo forward gcred hist hooks hrealm icinterleave icred
|
||||
diff --git a/src/tests/gcred.c b/src/tests/gcred.c
|
||||
index cb0ae6af5..b14e4fc9a 100644
|
||||
--- a/src/tests/gcred.c
|
||||
+++ b/src/tests/gcred.c
|
||||
@@ -66,20 +66,32 @@ main(int argc, char **argv)
|
||||
krb5_principal client, server;
|
||||
krb5_ccache ccache;
|
||||
krb5_creds in_creds, *creds;
|
||||
+ krb5_flags options = 0;
|
||||
char *name;
|
||||
+ int c;
|
||||
|
||||
check(krb5_init_context(&ctx));
|
||||
|
||||
- /* Parse arguments. */
|
||||
- assert(argc == 3);
|
||||
- check(krb5_parse_name(ctx, argv[2], &server));
|
||||
- if (strcmp(argv[1], "unknown") == 0)
|
||||
+ while ((c = getopt(argc, argv, "f")) != -1) {
|
||||
+ switch (c) {
|
||||
+ case 'f':
|
||||
+ options |= KRB5_GC_FORWARDABLE;
|
||||
+ break;
|
||||
+ default:
|
||||
+ abort();
|
||||
+ }
|
||||
+ }
|
||||
+ argc -= optind;
|
||||
+ argv += optind;
|
||||
+ assert(argc == 2);
|
||||
+ check(krb5_parse_name(ctx, argv[1], &server));
|
||||
+ if (strcmp(argv[0], "unknown") == 0)
|
||||
server->type = KRB5_NT_UNKNOWN;
|
||||
- else if (strcmp(argv[1], "principal") == 0)
|
||||
+ else if (strcmp(argv[0], "principal") == 0)
|
||||
server->type = KRB5_NT_PRINCIPAL;
|
||||
- else if (strcmp(argv[1], "srv-inst") == 0)
|
||||
+ else if (strcmp(argv[0], "srv-inst") == 0)
|
||||
server->type = KRB5_NT_SRV_INST;
|
||||
- else if (strcmp(argv[1], "srv-hst") == 0)
|
||||
+ else if (strcmp(argv[0], "srv-hst") == 0)
|
||||
server->type = KRB5_NT_SRV_HST;
|
||||
else
|
||||
abort();
|
||||
@@ -89,7 +101,7 @@ main(int argc, char **argv)
|
||||
memset(&in_creds, 0, sizeof(in_creds));
|
||||
in_creds.client = client;
|
||||
in_creds.server = server;
|
||||
- check(krb5_get_credentials(ctx, 0, ccache, &in_creds, &creds));
|
||||
+ check(krb5_get_credentials(ctx, options, ccache, &in_creds, &creds));
|
||||
check(krb5_unparse_name(ctx, creds->server, &name));
|
||||
printf("%s\n", name);
|
||||
|
||||
diff --git a/src/tests/t_kdcoptions.py b/src/tests/t_kdcoptions.py
|
||||
new file mode 100644
|
||||
index 000000000..7ec57508c
|
||||
--- /dev/null
|
||||
+++ b/src/tests/t_kdcoptions.py
|
||||
@@ -0,0 +1,100 @@
|
||||
+from k5test import *
|
||||
+import re
|
||||
+
|
||||
+# KDC option test coverage notes:
|
||||
+#
|
||||
+# FORWARDABLE here
|
||||
+# FORWARDED no test
|
||||
+# PROXIABLE here
|
||||
+# PROXY no test
|
||||
+# ALLOW_POSTDATE no test
|
||||
+# POSTDATED no test
|
||||
+# RENEWABLE t_renew.py
|
||||
+# CNAME_IN_ADDL_TKT gssapi/t_s4u.py
|
||||
+# CANONICALIZE t_kdb.py and various other tests
|
||||
+# REQUEST_ANONYMOUS t_pkinit.py
|
||||
+# DISABLE_TRANSITED_CHECK no test
|
||||
+# RENEWABLE_OK t_renew.py
|
||||
+# ENC_TKT_IN_SKEY t_u2u.py
|
||||
+# RENEW t_renew.py
|
||||
+# VALIDATE no test
|
||||
+
|
||||
+# Run klist -f and return the flags on the ticket for svcprinc.
|
||||
+def get_flags(realm, svcprinc):
|
||||
+ grab_flags = False
|
||||
+ for line in realm.run([klist, '-f']).splitlines():
|
||||
+ if grab_flags:
|
||||
+ return re.findall(r'Flags: ([a-zA-Z]*)', line)[0]
|
||||
+ grab_flags = line.endswith(svcprinc)
|
||||
+
|
||||
+
|
||||
+# Get the flags on the ticket for svcprinc, and check for an expected
|
||||
+# element and an expected-absent element, either of which can be None.
|
||||
+def check_flags(realm, svcprinc, expected_flag, expected_noflag):
|
||||
+ flags = get_flags(realm, svcprinc)
|
||||
+ if expected_flag is not None and not expected_flag in flags:
|
||||
+ fail('expected flag ' + expected_flag)
|
||||
+ if expected_noflag is not None and expected_noflag in flags:
|
||||
+ fail('did not expect flag ' + expected_noflag)
|
||||
+
|
||||
+
|
||||
+# Run kinit with the given flags, and check the flags on the resulting
|
||||
+# TGT.
|
||||
+def kinit_check_flags(realm, flags, expected_flag, expected_noflag):
|
||||
+ realm.kinit(realm.user_princ, password('user'), flags)
|
||||
+ check_flags(realm, realm.krbtgt_princ, expected_flag, expected_noflag)
|
||||
+
|
||||
+
|
||||
+# Run kinit with kflags. Then get credentials for the host principal
|
||||
+# with gflags, and check the flags on the resulting ticket.
|
||||
+def gcred_check_flags(realm, kflags, gflags, expected_flag, expected_noflag):
|
||||
+ realm.kinit(realm.user_princ, password('user'), kflags)
|
||||
+ realm.run(['./gcred'] + gflags + ['unknown', realm.host_princ])
|
||||
+ check_flags(realm, realm.host_princ, expected_flag, expected_noflag)
|
||||
+
|
||||
+
|
||||
+realm = K5Realm()
|
||||
+
|
||||
+mark('proxiable (AS)')
|
||||
+kinit_check_flags(realm, [], None, 'P')
|
||||
+kinit_check_flags(realm, ['-p'], 'P', None)
|
||||
+realm.run([kadminl, 'modprinc', '-allow_proxiable', realm.user_princ])
|
||||
+kinit_check_flags(realm, ['-p'], None, 'P')
|
||||
+realm.run([kadminl, 'modprinc', '+allow_proxiable', realm.user_princ])
|
||||
+realm.run([kadminl, 'modprinc', '-allow_proxiable', realm.krbtgt_princ])
|
||||
+kinit_check_flags(realm, ['-p'], None, 'P')
|
||||
+realm.run([kadminl, 'modprinc', '+allow_proxiable', realm.krbtgt_princ])
|
||||
+
|
||||
+mark('proxiable (TGS)')
|
||||
+gcred_check_flags(realm, [], [], None, 'P')
|
||||
+gcred_check_flags(realm, ['-p'], [], 'P', None)
|
||||
+
|
||||
+# Not tested: PROXIABLE option set with a non-proxiable TGT (because
|
||||
+# there is no krb5_get_credentials() flag to request this; would
|
||||
+# expect a non-proxiable ticket).
|
||||
+
|
||||
+# Not tested: proxiable TGT but PROXIABLE flag not set (because we
|
||||
+# internally set the PROXIABLE option when using a proxiable TGT;
|
||||
+# would expect a non-proxiable ticket).
|
||||
+
|
||||
+mark('forwardable (AS)')
|
||||
+kinit_check_flags(realm, [], None, 'F')
|
||||
+kinit_check_flags(realm, ['-f'], 'F', None)
|
||||
+realm.run([kadminl, 'modprinc', '-allow_forwardable', realm.user_princ])
|
||||
+kinit_check_flags(realm, ['-f'], None, 'F')
|
||||
+realm.run([kadminl, 'modprinc', '+allow_forwardable', realm.user_princ])
|
||||
+realm.run([kadminl, 'modprinc', '-allow_forwardable', realm.krbtgt_princ])
|
||||
+kinit_check_flags(realm, ['-f'], None, 'F')
|
||||
+realm.run([kadminl, 'modprinc', '+allow_forwardable', realm.krbtgt_princ])
|
||||
+
|
||||
+mark('forwardable (TGS)')
|
||||
+realm.kinit(realm.user_princ, password('user'))
|
||||
+gcred_check_flags(realm, [], [], None, 'F')
|
||||
+gcred_check_flags(realm, [], ['-f'], None, 'F')
|
||||
+gcred_check_flags(realm, ['-f'], [], 'F', None)
|
||||
+
|
||||
+# Not tested: forwardable TGT but FORWARDABLE flag not set (because we
|
||||
+# internally set the FORWARDABLE option when using a forwardable TGT;
|
||||
+# would expect a non-proxiable ticket).
|
||||
+
|
||||
+success('KDC option tests')
|
||||
|
|
@ -1,79 +0,0 @@
|
|||
From 144eea330aba65a140c0e0bf66ad3cfe06f28899 Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Tue, 21 May 2019 13:34:39 -0400
|
||||
Subject: [PATCH] Display unsupported enctype names
|
||||
|
||||
Add a table of unsupported enctype numbers to enctype_util.c and
|
||||
consult it in krb5_enctype_to_name(). Treat unsupported enctype
|
||||
numbers as deprecated in krb5int_c_deprecated_enctype(). In kadmin,
|
||||
display "UNSUPPORTED:" before invalid enctype names.
|
||||
|
||||
ticket: 8808
|
||||
(cherry picked from commit ebbc6e8e99ee9d5d757411200a6a3173171774df)
|
||||
---
|
||||
src/kadmin/cli/kadmin.c | 4 +++-
|
||||
src/lib/crypto/krb/enctype_util.c | 22 +++++++++++++++++++++-
|
||||
2 files changed, 24 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/src/kadmin/cli/kadmin.c b/src/kadmin/cli/kadmin.c
|
||||
index fe4cb493c..b4d1aad93 100644
|
||||
--- a/src/kadmin/cli/kadmin.c
|
||||
+++ b/src/kadmin/cli/kadmin.c
|
||||
@@ -1461,7 +1461,9 @@ kadmin_getprinc(int argc, char *argv[])
|
||||
enctype, sizeof(enctype)))
|
||||
snprintf(enctype, sizeof(enctype), _("<Encryption type 0x%x>"),
|
||||
key_data->key_data_type[0]);
|
||||
- if (krb5int_c_deprecated_enctype(key_data->key_data_type[0]))
|
||||
+ if (!krb5_c_valid_enctype(key_data->key_data_type[0]))
|
||||
+ deprecated = "UNSUPPORTED:";
|
||||
+ else if (krb5int_c_deprecated_enctype(key_data->key_data_type[0]))
|
||||
deprecated = "DEPRECATED:";
|
||||
printf("Key: vno %d, %s%s", key_data->key_data_kvno, deprecated,
|
||||
enctype);
|
||||
diff --git a/src/lib/crypto/krb/enctype_util.c b/src/lib/crypto/krb/enctype_util.c
|
||||
index e394f4e19..1542d4062 100644
|
||||
--- a/src/lib/crypto/krb/enctype_util.c
|
||||
+++ b/src/lib/crypto/krb/enctype_util.c
|
||||
@@ -36,6 +36,18 @@
|
||||
|
||||
#include "crypto_int.h"
|
||||
|
||||
+struct {
|
||||
+ krb5_enctype etype;
|
||||
+ const char *name;
|
||||
+} unsupported_etypes[] = {
|
||||
+ { ENCTYPE_DES_CBC_CRC, "des-cbc-crc" },
|
||||
+ { ENCTYPE_DES_CBC_MD4, "des-cbc-md4" },
|
||||
+ { ENCTYPE_DES_CBC_MD5, "des-cbc-md5" },
|
||||
+ { ENCTYPE_DES_CBC_RAW, "des-cbc-raw" },
|
||||
+ { ENCTYPE_DES_HMAC_SHA1, "des-hmac-sha1" },
|
||||
+ { ENCTYPE_NULL, NULL }
|
||||
+};
|
||||
+
|
||||
krb5_boolean KRB5_CALLCONV
|
||||
krb5_c_valid_enctype(krb5_enctype etype)
|
||||
{
|
||||
@@ -55,7 +67,7 @@ krb5_boolean KRB5_CALLCONV
|
||||
krb5int_c_deprecated_enctype(krb5_enctype etype)
|
||||
{
|
||||
const struct krb5_keytypes *ktp = find_enctype(etype);
|
||||
- return ktp != NULL && (ktp->flags & ETYPE_DEPRECATED) != 0;
|
||||
+ return ktp == NULL || (ktp->flags & ETYPE_DEPRECATED) != 0;
|
||||
}
|
||||
|
||||
krb5_error_code KRB5_CALLCONV
|
||||
@@ -122,6 +134,14 @@ krb5_enctype_to_name(krb5_enctype enctype, krb5_boolean shortest,
|
||||
const char *name;
|
||||
int i;
|
||||
|
||||
+ for (i = 0; unsupported_etypes[i].etype != ENCTYPE_NULL; i++) {
|
||||
+ if (enctype == unsupported_etypes[i].etype) {
|
||||
+ if (strlcpy(buffer, unsupported_etypes[i].name, buflen) >= buflen)
|
||||
+ return ENOMEM;
|
||||
+ return 0;
|
||||
+ }
|
||||
+ }
|
||||
+
|
||||
ktp = find_enctype(enctype);
|
||||
if (ktp == NULL)
|
||||
return EINVAL;
|
||||
|
|
@ -1,67 +0,0 @@
|
|||
From 84bb2b804c69830ff2dc405b1a2bd7893291d8e6 Mon Sep 17 00:00:00 2001
|
||||
From: Robbie Harwood <rharwood@redhat.com>
|
||||
Date: Wed, 10 Jul 2019 17:10:16 -0400
|
||||
Subject: [PATCH] Don't error on invalid enctypes in keytab
|
||||
|
||||
krb5_ktfile_get_entry() used krb5_c_enctype_compare() to compare
|
||||
enctypes, in order to share keys between single-DES enctypes. As
|
||||
key-sharing between enctypes is no longer done and single-DES support
|
||||
has been removed, use a simple equality test to match the enctype.
|
||||
This fixes a bug where krb5_kt_get_entry() would error out if the
|
||||
keytab contained any entries with invalid enctypes (include single-DES
|
||||
entries, after commit fb2dada5eb89c4cd4e39dedd6dbb7dbd5e94f8b8) even
|
||||
if a matching entry is found.
|
||||
|
||||
[ghudson@mit.edu: rewrote commit message]
|
||||
|
||||
ticket: 8808
|
||||
(cherry picked from commit 38be1a0a31a6104cdf8c8d72828905775f6d6636)
|
||||
---
|
||||
src/lib/krb5/keytab/kt_file.c | 27 +++++----------------------
|
||||
1 file changed, 5 insertions(+), 22 deletions(-)
|
||||
|
||||
diff --git a/src/lib/krb5/keytab/kt_file.c b/src/lib/krb5/keytab/kt_file.c
|
||||
index 21c80d419..df2530a45 100644
|
||||
--- a/src/lib/krb5/keytab/kt_file.c
|
||||
+++ b/src/lib/krb5/keytab/kt_file.c
|
||||
@@ -289,7 +289,6 @@ krb5_ktfile_get_entry(krb5_context context, krb5_keytab id,
|
||||
krb5_keytab_entry cur_entry, new_entry;
|
||||
krb5_error_code kerror = 0;
|
||||
int found_wrong_kvno = 0;
|
||||
- krb5_boolean similar;
|
||||
int was_open;
|
||||
char *princname;
|
||||
|
||||
@@ -336,27 +335,11 @@ krb5_ktfile_get_entry(krb5_context context, krb5_keytab id,
|
||||
continue;
|
||||
}
|
||||
|
||||
- /* if the enctype is not ignored and doesn't match, free new_entry
|
||||
- and continue to the next */
|
||||
-
|
||||
- if (enctype != IGNORE_ENCTYPE) {
|
||||
- if ((kerror = krb5_c_enctype_compare(context, enctype,
|
||||
- new_entry.key.enctype,
|
||||
- &similar))) {
|
||||
- krb5_kt_free_entry(context, &new_entry);
|
||||
- break;
|
||||
- }
|
||||
-
|
||||
- if (!similar) {
|
||||
- krb5_kt_free_entry(context, &new_entry);
|
||||
- continue;
|
||||
- }
|
||||
- /*
|
||||
- * Coerce the enctype of the output keyblock in case we
|
||||
- * got an inexact match on the enctype.
|
||||
- */
|
||||
- new_entry.key.enctype = enctype;
|
||||
-
|
||||
+ /* If the enctype is not ignored and doesn't match, free new_entry and
|
||||
+ continue to the next. */
|
||||
+ if (enctype != IGNORE_ENCTYPE && enctype != new_entry.key.enctype) {
|
||||
+ krb5_kt_free_entry(context, &new_entry);
|
||||
+ continue;
|
||||
}
|
||||
|
||||
if (kvno == IGNORE_VNO || new_entry.vno == IGNORE_VNO) {
|
||||
|
|
@ -1,70 +0,0 @@
|
|||
From aa3b2bb07bf48375b2391b31e68d0abf7ba5e4ea Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Tue, 16 Jul 2019 00:15:42 -0400
|
||||
Subject: [PATCH] Filter enctypes in gss_set_allowable_enctypes()
|
||||
|
||||
Instead of erroring out when any invalid enctypes are present in the
|
||||
caller's list, filter out the invalid ones and only error if no
|
||||
enctypes remain.
|
||||
|
||||
ticket: 8819
|
||||
(cherry picked from commit 37ab7ea128a4c2aa2dad65ab9006baded5335bc7)
|
||||
---
|
||||
src/lib/gssapi/krb5/set_allowable_enctypes.c | 29 ++++++++++----------
|
||||
1 file changed, 14 insertions(+), 15 deletions(-)
|
||||
|
||||
diff --git a/src/lib/gssapi/krb5/set_allowable_enctypes.c b/src/lib/gssapi/krb5/set_allowable_enctypes.c
|
||||
index d9fd279ed..a74b161cb 100644
|
||||
--- a/src/lib/gssapi/krb5/set_allowable_enctypes.c
|
||||
+++ b/src/lib/gssapi/krb5/set_allowable_enctypes.c
|
||||
@@ -66,7 +66,7 @@ gss_krb5int_set_allowable_enctypes(OM_uint32 *minor_status,
|
||||
const gss_OID desired_oid,
|
||||
const gss_buffer_t value)
|
||||
{
|
||||
- unsigned int i;
|
||||
+ unsigned int i, j;
|
||||
krb5_enctype * new_ktypes;
|
||||
OM_uint32 major_status;
|
||||
krb5_gss_cred_id_t cred;
|
||||
@@ -83,14 +83,7 @@ gss_krb5int_set_allowable_enctypes(OM_uint32 *minor_status,
|
||||
/* verify and valildate cred handle */
|
||||
cred = (krb5_gss_cred_id_t) *cred_handle;
|
||||
|
||||
- if (req->ktypes) {
|
||||
- for (i = 0; i < req->num_ktypes && req->ktypes[i]; i++) {
|
||||
- if (!krb5_c_valid_enctype(req->ktypes[i])) {
|
||||
- kerr = KRB5_PROG_ETYPE_NOSUPP;
|
||||
- goto error_out;
|
||||
- }
|
||||
- }
|
||||
- } else {
|
||||
+ if (req->ktypes == NULL) {
|
||||
k5_mutex_lock(&cred->lock);
|
||||
if (cred->req_enctypes)
|
||||
free(cred->req_enctypes);
|
||||
@@ -99,13 +92,19 @@ gss_krb5int_set_allowable_enctypes(OM_uint32 *minor_status,
|
||||
return GSS_S_COMPLETE;
|
||||
}
|
||||
|
||||
- /* Copy the requested ktypes into the cred structure */
|
||||
- if ((new_ktypes = (krb5_enctype *)malloc(sizeof(krb5_enctype) * (i + 1)))) {
|
||||
- memcpy(new_ktypes, req->ktypes, sizeof(krb5_enctype) * i);
|
||||
- new_ktypes[i] = 0; /* "null-terminate" the list */
|
||||
+ /* Copy the requested enctypes into the cred structure. Filter out the
|
||||
+ * ones we don't consider valid. Error out if no enctypes are valid. */
|
||||
+ new_ktypes = k5calloc(req->num_ktypes + 1, sizeof(*new_ktypes), &kerr);
|
||||
+ if (new_ktypes == NULL)
|
||||
+ goto error_out;
|
||||
+ for (i = 0, j = 0; i < req->num_ktypes && req->ktypes[i]; i++) {
|
||||
+ if (krb5_c_valid_enctype(req->ktypes[i]))
|
||||
+ new_ktypes[j++] = req->ktypes[i];
|
||||
}
|
||||
- else {
|
||||
- kerr = ENOMEM;
|
||||
+ new_ktypes[j] = 0;
|
||||
+ if (j == 0) {
|
||||
+ free(new_ktypes);
|
||||
+ kerr = KRB5_PROG_ETYPE_NOSUPP;
|
||||
goto error_out;
|
||||
}
|
||||
k5_mutex_lock(&cred->lock);
|
||||
|
|
@ -1,206 +0,0 @@
|
|||
From 28db01445d2807d51b5045c0a04d5e49905de504 Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Sat, 20 Jul 2019 00:51:52 -0400
|
||||
Subject: [PATCH] Fix Coverity defects in soft-pkcs11 test code
|
||||
|
||||
Nothing in the code removes objects from soft_token.object.obs, so
|
||||
simplify add_st_object() not to search for an empty slot. Avoid using
|
||||
random() by using a counter for session handles and just the array
|
||||
slot number for object handles. Add a helper get_rcfilename() to
|
||||
facilitate checking the result of asprintf(). Properly initialize ap
|
||||
in sprintf_fill(). Close the file handle in read_conf_file().
|
||||
|
||||
(cherry picked from commit b4831515b2f3b6fd7d7fd4bff4558c10c710891d)
|
||||
---
|
||||
src/tests/softpkcs11/main.c | 102 +++++++++++++++++++-----------------
|
||||
1 file changed, 53 insertions(+), 49 deletions(-)
|
||||
|
||||
diff --git a/src/tests/softpkcs11/main.c b/src/tests/softpkcs11/main.c
|
||||
index 5255323d3..2d1448ca2 100644
|
||||
--- a/src/tests/softpkcs11/main.c
|
||||
+++ b/src/tests/softpkcs11/main.c
|
||||
@@ -78,6 +78,7 @@ compat_rsa_get0_key(const RSA *rsa, const BIGNUM **n, const BIGNUM **e,
|
||||
(BL) = i2d_##T((S), &p); \
|
||||
if ((BL) <= 0) { \
|
||||
free((B)); \
|
||||
+ (B) = NULL; \
|
||||
(R) = EINVAL; \
|
||||
} \
|
||||
} \
|
||||
@@ -149,6 +150,7 @@ static struct soft_token {
|
||||
} state[10];
|
||||
#define MAX_NUM_SESSION (sizeof(soft_token.state)/sizeof(soft_token.state[0]))
|
||||
FILE *logfile;
|
||||
+ CK_SESSION_HANDLE next_session_handle;
|
||||
} soft_token;
|
||||
|
||||
static void
|
||||
@@ -179,6 +181,7 @@ snprintf_fill(char *str, int size, char fillchar, const char *fmt, ...)
|
||||
{
|
||||
int len;
|
||||
va_list ap;
|
||||
+ va_start(ap, fmt);
|
||||
len = vsnprintf(str, size, fmt, ap);
|
||||
va_end(ap);
|
||||
if (len < 0 || len > size)
|
||||
@@ -344,7 +347,13 @@ static struct st_object *
|
||||
add_st_object(void)
|
||||
{
|
||||
struct st_object *o, **objs;
|
||||
- int i;
|
||||
+
|
||||
+ objs = realloc(soft_token.object.objs,
|
||||
+ (soft_token.object.num_objs + 1) *
|
||||
+ sizeof(soft_token.object.objs[0]));
|
||||
+ if (objs == NULL)
|
||||
+ return NULL;
|
||||
+ soft_token.object.objs = objs;
|
||||
|
||||
o = malloc(sizeof(*o));
|
||||
if (o == NULL)
|
||||
@@ -352,26 +361,9 @@ add_st_object(void)
|
||||
memset(o, 0, sizeof(*o));
|
||||
o->attrs = NULL;
|
||||
o->num_attributes = 0;
|
||||
+ o->object_handle = soft_token.object.num_objs;
|
||||
|
||||
- for (i = 0; i < soft_token.object.num_objs; i++) {
|
||||
- if (soft_token.object.objs == NULL) {
|
||||
- soft_token.object.objs[i] = o;
|
||||
- break;
|
||||
- }
|
||||
- }
|
||||
- if (i == soft_token.object.num_objs) {
|
||||
- objs = realloc(soft_token.object.objs,
|
||||
- (soft_token.object.num_objs + 1) * sizeof(soft_token.object.objs[0]));
|
||||
- if (objs == NULL) {
|
||||
- free(o);
|
||||
- return NULL;
|
||||
- }
|
||||
- soft_token.object.objs = objs;
|
||||
- soft_token.object.objs[soft_token.object.num_objs++] = o;
|
||||
- }
|
||||
- soft_token.object.objs[i]->object_handle =
|
||||
- (random() & (~OBJECT_ID_MASK)) | i;
|
||||
-
|
||||
+ soft_token.object.objs[soft_token.object.num_objs++] = o;
|
||||
return o;
|
||||
}
|
||||
|
||||
@@ -797,6 +789,8 @@ read_conf_file(const char *fn)
|
||||
|
||||
add_certificate(label, cert, key, id, anchor);
|
||||
}
|
||||
+
|
||||
+ fclose(f);
|
||||
}
|
||||
|
||||
static CK_RV
|
||||
@@ -806,19 +800,47 @@ func_not_supported(void)
|
||||
return CKR_FUNCTION_NOT_SUPPORTED;
|
||||
}
|
||||
|
||||
+static char *
|
||||
+get_rcfilename()
|
||||
+{
|
||||
+ struct passwd *pw;
|
||||
+ const char *home = NULL;
|
||||
+ char *fn;
|
||||
+
|
||||
+ if (getuid() == geteuid()) {
|
||||
+ fn = getenv("SOFTPKCS11RC");
|
||||
+ if (fn != NULL)
|
||||
+ return strdup(fn);
|
||||
+
|
||||
+ home = getenv("HOME");
|
||||
+ }
|
||||
+
|
||||
+ if (home == NULL) {
|
||||
+ pw = getpwuid(getuid());
|
||||
+ if (pw != NULL)
|
||||
+ home = pw->pw_dir;
|
||||
+ }
|
||||
+
|
||||
+ if (home == NULL)
|
||||
+ return strdup("/etc/soft-token.rc");
|
||||
+
|
||||
+ if (asprintf(&fn, "%s/.soft-token.rc", home) < 0)
|
||||
+ return NULL;
|
||||
+ return fn;
|
||||
+}
|
||||
+
|
||||
CK_RV
|
||||
C_Initialize(CK_VOID_PTR a)
|
||||
{
|
||||
CK_C_INITIALIZE_ARGS_PTR args = a;
|
||||
size_t i;
|
||||
+ char *fn;
|
||||
|
||||
st_logf("Initialize\n");
|
||||
|
||||
OpenSSL_add_all_algorithms();
|
||||
ERR_load_crypto_strings();
|
||||
|
||||
- srandom(getpid() ^ time(NULL));
|
||||
-
|
||||
for (i = 0; i < MAX_NUM_SESSION; i++) {
|
||||
soft_token.state[i].session_handle = CK_INVALID_HANDLE;
|
||||
soft_token.state[i].find.attributes = NULL;
|
||||
@@ -850,31 +872,13 @@ C_Initialize(CK_VOID_PTR a)
|
||||
st_logf("\tFlags\t%04x\n", (unsigned int)args->flags);
|
||||
}
|
||||
|
||||
- {
|
||||
- char *fn = NULL, *home = NULL;
|
||||
-
|
||||
- if (getuid() == geteuid()) {
|
||||
- fn = getenv("SOFTPKCS11RC");
|
||||
- if (fn)
|
||||
- fn = strdup(fn);
|
||||
- home = getenv("HOME");
|
||||
- }
|
||||
- if (fn == NULL && home == NULL) {
|
||||
- struct passwd *pw = getpwuid(getuid());
|
||||
- if(pw != NULL)
|
||||
- home = pw->pw_dir;
|
||||
- }
|
||||
- if (fn == NULL) {
|
||||
- if (home)
|
||||
- asprintf(&fn, "%s/.soft-token.rc", home);
|
||||
- else
|
||||
- fn = strdup("/etc/soft-token.rc");
|
||||
- }
|
||||
-
|
||||
- read_conf_file(fn);
|
||||
- free(fn);
|
||||
- }
|
||||
+ soft_token.next_session_handle = 0;
|
||||
|
||||
+ fn = get_rcfilename();
|
||||
+ if (fn == NULL)
|
||||
+ return CKR_DEVICE_MEMORY;
|
||||
+ read_conf_file(fn);
|
||||
+ free(fn);
|
||||
return CKR_OK;
|
||||
}
|
||||
|
||||
@@ -1082,8 +1086,7 @@ C_OpenSession(CK_SLOT_ID slotID,
|
||||
|
||||
soft_token.open_sessions++;
|
||||
|
||||
- soft_token.state[i].session_handle =
|
||||
- (CK_SESSION_HANDLE)(random() & 0xfffff);
|
||||
+ soft_token.state[i].session_handle = soft_token.next_session_handle++;
|
||||
*phSession = soft_token.state[i].session_handle;
|
||||
|
||||
return CKR_OK;
|
||||
@@ -1152,7 +1155,8 @@ C_Login(CK_SESSION_HANDLE hSession,
|
||||
VERIFY_SESSION_HANDLE(hSession, NULL);
|
||||
|
||||
if (pPin != NULL_PTR) {
|
||||
- asprintf(&pin, "%.*s", (int)ulPinLen, pPin);
|
||||
+ if (asprintf(&pin, "%.*s", (int)ulPinLen, pPin) < 0)
|
||||
+ return CKR_DEVICE_MEMORY;
|
||||
st_logf("type: %d password: %s\n", (int)userType, pin);
|
||||
}
|
||||
|
||||
|
|
@ -1,32 +0,0 @@
|
|||
From 7e81b8077cf2cf186dadb96b064573f7c221fbf3 Mon Sep 17 00:00:00 2001
|
||||
From: Robbie Harwood <rharwood@redhat.com>
|
||||
Date: Wed, 14 Aug 2019 13:52:27 -0400
|
||||
Subject: [PATCH] Fix KCM client time offset propagation
|
||||
|
||||
An inverted status check in get_kdc_offset() would cause querying the
|
||||
offset time from the ccache to always fail (silently) on KCM. Fix the
|
||||
status check so that KCM can properly handle desync.
|
||||
|
||||
ticket: 8826 (new)
|
||||
tags: pullup
|
||||
target_version: 1.17-next
|
||||
target_verison: 1.16-next
|
||||
|
||||
(cherry picked from commit 323abb6d1ebe5469d6c2167c29aa5d696d099b90)
|
||||
---
|
||||
src/lib/krb5/ccache/cc_kcm.c | 2 +-
|
||||
1 file changed, 1 insertion(+), 1 deletion(-)
|
||||
|
||||
diff --git a/src/lib/krb5/ccache/cc_kcm.c b/src/lib/krb5/ccache/cc_kcm.c
|
||||
index 092ab7daf..fe93ca3dc 100644
|
||||
--- a/src/lib/krb5/ccache/cc_kcm.c
|
||||
+++ b/src/lib/krb5/ccache/cc_kcm.c
|
||||
@@ -583,7 +583,7 @@ get_kdc_offset(krb5_context context, krb5_ccache cache)
|
||||
if (cache_call(context, cache, &req, FALSE) != 0)
|
||||
goto cleanup;
|
||||
time_offset = k5_input_get_uint32_be(&req.reply);
|
||||
- if (!req.reply.status)
|
||||
+ if (req.reply.status)
|
||||
goto cleanup;
|
||||
context->os_context.time_offset = time_offset;
|
||||
context->os_context.usec_offset = 0;
|
||||
|
|
@ -1,31 +0,0 @@
|
|||
From 55353df13814c6d711a1d947dd6690b334269122 Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Wed, 25 Sep 2019 12:57:56 -0400
|
||||
Subject: [PATCH] Fix KDC crash when logging PKINIT enctypes
|
||||
|
||||
Commit a649279727490687d54becad91fde8cf7429d951 introduced a KDC crash
|
||||
bug due to transposed strlcpy() arguments. Fix the argument order.
|
||||
|
||||
This bug does not affect any MIT krb5 release, but affects the Fedora
|
||||
krb5 packages due to backports. CVE-2019-14844 has been issued as a
|
||||
result.
|
||||
|
||||
ticket: 8772
|
||||
(cherry picked from commit 275c9a1aad36a1a7b56042f1a2c21c33e7d16eaf)
|
||||
---
|
||||
src/kdc/kdc_util.c | 2 +-
|
||||
1 file changed, 1 insertion(+), 1 deletion(-)
|
||||
|
||||
diff --git a/src/kdc/kdc_util.c b/src/kdc/kdc_util.c
|
||||
index 23ad6c584..698f18c1c 100644
|
||||
--- a/src/kdc/kdc_util.c
|
||||
+++ b/src/kdc/kdc_util.c
|
||||
@@ -1080,7 +1080,7 @@ enctype_name(krb5_enctype ktype, char *buf, size_t buflen)
|
||||
else
|
||||
return krb5_enctype_to_name(ktype, FALSE, buf, buflen);
|
||||
|
||||
- if (strlcpy(name, buf, buflen) >= buflen)
|
||||
+ if (strlcpy(buf, name, buflen) >= buflen)
|
||||
return ENOMEM;
|
||||
return 0;
|
||||
}
|
||||
|
|
@ -1,29 +0,0 @@
|
|||
From 7ed0d71eb3eef640e57f3c55f8aeac636cce3110 Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Tue, 16 Apr 2019 10:47:35 -0400
|
||||
Subject: [PATCH] Fix config realm change logic in FILE remove_cred
|
||||
|
||||
Use data_eq_string() to check the server realm, and do not check if
|
||||
cred->server is NULL since it is not expected to be (and
|
||||
k5_marshal_cred() would have already crashed if it were).
|
||||
|
||||
ticket: 8792
|
||||
(cherry picked from commit e5367fcddd53dc4db0c1fd2279e91eda3791960a)
|
||||
---
|
||||
src/lib/krb5/ccache/cc_file.c | 3 +--
|
||||
1 file changed, 1 insertion(+), 2 deletions(-)
|
||||
|
||||
diff --git a/src/lib/krb5/ccache/cc_file.c b/src/lib/krb5/ccache/cc_file.c
|
||||
index 09da38fa9..a3f67766e 100644
|
||||
--- a/src/lib/krb5/ccache/cc_file.c
|
||||
+++ b/src/lib/krb5/ccache/cc_file.c
|
||||
@@ -1058,8 +1058,7 @@ delete_cred(krb5_context context, krb5_ccache cache, krb5_cc_cursor *cursor,
|
||||
|
||||
/* For config entries, also change the realm so that other implementations
|
||||
* won't match them. */
|
||||
- if (cred->server != NULL && cred->server->realm.length > 0 &&
|
||||
- strcmp(cred->server->realm.data, "X-CACHECONF:") == 0)
|
||||
+ if (data_eq_string(cred->server->realm, "X-CACHECONF:"))
|
||||
memcpy(cred->server->realm.data, "X-RMED-CONF:", 12);
|
||||
|
||||
k5_marshal_cred(&overwrite, fcursor->version, cred);
|
||||
|
|
@ -1,33 +0,0 @@
|
|||
From e215c213a068d96599a3069339bfb3e4024ef61b Mon Sep 17 00:00:00 2001
|
||||
From: Corene Casper <C.Casper@Dell.com>
|
||||
Date: Sat, 16 Feb 2019 00:49:26 -0500
|
||||
Subject: [PATCH] Fix memory leak in 'none' replay cache type
|
||||
|
||||
Commit 0f06098e2ab419d02e89a1ca6bc9f2828f6bdb1e fixed part of a memory
|
||||
leak in the 'none' replay cache type by freeing the outer container,
|
||||
but we also need to free the mutex.
|
||||
|
||||
[ghudson@mit.edu: wrote commit message]
|
||||
|
||||
ticket: 8783
|
||||
tags: pullup
|
||||
target_version: 1.17-next
|
||||
target_version: 1.16-next
|
||||
|
||||
(cherry picked from commit af2a3115cb8feb5174151b4b40223ae45aa9db17)
|
||||
---
|
||||
src/lib/krb5/rcache/rc_none.c | 1 +
|
||||
1 file changed, 1 insertion(+)
|
||||
|
||||
diff --git a/src/lib/krb5/rcache/rc_none.c b/src/lib/krb5/rcache/rc_none.c
|
||||
index e30aed09f..0b2274df7 100644
|
||||
--- a/src/lib/krb5/rcache/rc_none.c
|
||||
+++ b/src/lib/krb5/rcache/rc_none.c
|
||||
@@ -50,6 +50,7 @@ krb5_rc_none_noargs(krb5_context ctx, krb5_rcache rc)
|
||||
static krb5_error_code KRB5_CALLCONV
|
||||
krb5_rc_none_close(krb5_context ctx, krb5_rcache rc)
|
||||
{
|
||||
+ k5_mutex_destroy(&rc->lock);
|
||||
free (rc);
|
||||
return 0;
|
||||
}
|
||||
|
|
@ -1,122 +0,0 @@
|
|||
From 5cc80472e7a8b0fb3002f229ffb104dccf8bd120 Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Mon, 5 Aug 2019 01:53:51 -0400
|
||||
Subject: [PATCH] Fix memory leaks in soft-pkcs11 code
|
||||
|
||||
Fix leaks detected by asan in t_pkinit.py. Add a helper to free a
|
||||
struct st_object and free objects in C_Finalize(). Duplicate the X509
|
||||
cert in add_certificate() instead of creating aliases so it can be
|
||||
properly freed. Start the session handle counter at 1 so that
|
||||
C_Finalize() won't confuse the first session handle with
|
||||
CK_INVALID_HANDLE (defined to 0 in pkinit.h) and will properly clean
|
||||
the session object.
|
||||
|
||||
(cherry picked from commit 15bcaf8bcb4af25ff89820ad3bf23ad5a324e863)
|
||||
---
|
||||
src/tests/softpkcs11/main.c | 44 +++++++++++++++++++++++++++++++++----
|
||||
1 file changed, 40 insertions(+), 4 deletions(-)
|
||||
|
||||
diff --git a/src/tests/softpkcs11/main.c b/src/tests/softpkcs11/main.c
|
||||
index 2d1448ca2..a4c3ae78e 100644
|
||||
--- a/src/tests/softpkcs11/main.c
|
||||
+++ b/src/tests/softpkcs11/main.c
|
||||
@@ -109,7 +109,7 @@ struct st_object {
|
||||
X509 *cert;
|
||||
EVP_PKEY *public_key;
|
||||
struct {
|
||||
- const char *file;
|
||||
+ char *file;
|
||||
EVP_PKEY *key;
|
||||
X509 *cert;
|
||||
} private_key;
|
||||
@@ -343,6 +343,26 @@ print_attributes(const CK_ATTRIBUTE *attributes,
|
||||
}
|
||||
}
|
||||
|
||||
+static void
|
||||
+free_st_object(struct st_object *o)
|
||||
+{
|
||||
+ int i;
|
||||
+
|
||||
+ for (i = 0; i < o->num_attributes; i++)
|
||||
+ free(o->attrs[i].attribute.pValue);
|
||||
+ free(o->attrs);
|
||||
+ if (o->type == STO_T_CERTIFICATE) {
|
||||
+ X509_free(o->u.cert);
|
||||
+ } else if (o->type == STO_T_PRIVATE_KEY) {
|
||||
+ free(o->u.private_key.file);
|
||||
+ EVP_PKEY_free(o->u.private_key.key);
|
||||
+ X509_free(o->u.private_key.cert);
|
||||
+ } else if (o->type == STO_T_PUBLIC_KEY) {
|
||||
+ EVP_PKEY_free(o->u.public_key);
|
||||
+ }
|
||||
+ free(o);
|
||||
+}
|
||||
+
|
||||
static struct st_object *
|
||||
add_st_object(void)
|
||||
{
|
||||
@@ -518,7 +538,11 @@ add_certificate(char *label,
|
||||
goto out;
|
||||
}
|
||||
o->type = STO_T_CERTIFICATE;
|
||||
- o->u.cert = cert;
|
||||
+ o->u.cert = X509_dup(cert);
|
||||
+ if (o->u.cert == NULL) {
|
||||
+ ret = CKR_DEVICE_MEMORY;
|
||||
+ goto out;
|
||||
+ }
|
||||
public_key = X509_get_pubkey(o->u.cert);
|
||||
|
||||
switch (EVP_PKEY_base_id(public_key)) {
|
||||
@@ -602,7 +626,11 @@ add_certificate(char *label,
|
||||
o->u.private_key.file = strdup(private_key_file);
|
||||
o->u.private_key.key = NULL;
|
||||
|
||||
- o->u.private_key.cert = cert;
|
||||
+ o->u.private_key.cert = X509_dup(cert);
|
||||
+ if (o->u.private_key.cert == NULL) {
|
||||
+ ret = CKR_DEVICE_MEMORY;
|
||||
+ goto out;
|
||||
+ }
|
||||
|
||||
c = CKO_PRIVATE_KEY;
|
||||
add_object_attribute(o, 0, CKA_CLASS, &c, sizeof(c));
|
||||
@@ -676,6 +704,7 @@ add_certificate(char *label,
|
||||
free(serial_data);
|
||||
free(issuer_data);
|
||||
free(subject_data);
|
||||
+ X509_free(cert);
|
||||
|
||||
return ret;
|
||||
}
|
||||
@@ -872,7 +901,7 @@ C_Initialize(CK_VOID_PTR a)
|
||||
st_logf("\tFlags\t%04x\n", (unsigned int)args->flags);
|
||||
}
|
||||
|
||||
- soft_token.next_session_handle = 0;
|
||||
+ soft_token.next_session_handle = 1;
|
||||
|
||||
fn = get_rcfilename();
|
||||
if (fn == NULL)
|
||||
@@ -886,6 +915,7 @@ CK_RV
|
||||
C_Finalize(CK_VOID_PTR args)
|
||||
{
|
||||
size_t i;
|
||||
+ int j;
|
||||
|
||||
st_logf("Finalize\n");
|
||||
|
||||
@@ -897,6 +927,12 @@ C_Finalize(CK_VOID_PTR args)
|
||||
}
|
||||
}
|
||||
|
||||
+ for (j = 0; j < soft_token.object.num_objs; j++)
|
||||
+ free_st_object(soft_token.object.objs[j]);
|
||||
+ free(soft_token.object.objs);
|
||||
+ soft_token.object.objs = NULL;
|
||||
+ soft_token.object.num_objs = 0;
|
||||
+
|
||||
return CKR_OK;
|
||||
}
|
||||
|
||||
|
|
@ -1,30 +0,0 @@
|
|||
From 013037d7c4f6073d28ea2b0bd53eca04bae170ea Mon Sep 17 00:00:00 2001
|
||||
From: Robbie Harwood <rharwood@redhat.com>
|
||||
Date: Thu, 18 Apr 2019 13:39:37 -0400
|
||||
Subject: [PATCH] Fix potential close(-1) in cc_file.c
|
||||
|
||||
As part of error handling in d3b39a8bac6206b5ea78b0bf6a2958c1df0b0dd5,
|
||||
an error path in delete_cred() may result in close(-1). While this
|
||||
shouldn't be a prolblem in practice (just returning EBADF), it does
|
||||
upset Coverity.
|
||||
|
||||
ticket: 8792
|
||||
(cherry picked from commit 5ccfbaf2f0c8871d2f0ea87ad4b21cc33392ca2c)
|
||||
---
|
||||
src/lib/krb5/ccache/cc_file.c | 3 ++-
|
||||
1 file changed, 2 insertions(+), 1 deletion(-)
|
||||
|
||||
diff --git a/src/lib/krb5/ccache/cc_file.c b/src/lib/krb5/ccache/cc_file.c
|
||||
index a3f67766e..bf58c1d45 100644
|
||||
--- a/src/lib/krb5/ccache/cc_file.c
|
||||
+++ b/src/lib/krb5/ccache/cc_file.c
|
||||
@@ -1122,7 +1122,8 @@ delete_cred(krb5_context context, krb5_ccache cache, krb5_cc_cursor *cursor,
|
||||
}
|
||||
|
||||
cleanup:
|
||||
- close(fd);
|
||||
+ if (fd >= 0)
|
||||
+ close(fd);
|
||||
zapfree(on_disk, expected.len);
|
||||
k5_buf_free(&expected);
|
||||
k5_buf_free(&overwrite);
|
||||
|
|
@ -1,103 +0,0 @@
|
|||
From 6f0b53aea2dfcccf1efe0c1c6142eeeaf998f2bb Mon Sep 17 00:00:00 2001
|
||||
From: Robbie Harwood <rharwood@redhat.com>
|
||||
Date: Thu, 2 May 2019 14:05:38 -0400
|
||||
Subject: [PATCH] Fix some return code handling bugs
|
||||
|
||||
Fix five cases where return codes could be set (in unlikely cases) but
|
||||
did not result in error exits.
|
||||
|
||||
[ghudson@mit.edu: squashed commits and rewrote commit message]
|
||||
|
||||
ticket: 8801 (new)
|
||||
tags: pullup
|
||||
target_version: 1.17-next
|
||||
target_version: 1.16-next
|
||||
|
||||
(cherry picked from commit 7c26740f9df3c79c3f01c3a4dda4d9dabba5298d)
|
||||
---
|
||||
src/kdc/fast_util.c | 16 ++++++++--------
|
||||
src/lib/gssapi/krb5/k5unsealiov.c | 1 +
|
||||
src/lib/kadm5/clnt/client_init.c | 3 +++
|
||||
src/tests/gssapi/t_pcontok.c | 1 +
|
||||
4 files changed, 13 insertions(+), 8 deletions(-)
|
||||
|
||||
diff --git a/src/kdc/fast_util.c b/src/kdc/fast_util.c
|
||||
index 6a3fc11b9..c9ba83e5e 100644
|
||||
--- a/src/kdc/fast_util.c
|
||||
+++ b/src/kdc/fast_util.c
|
||||
@@ -47,9 +47,10 @@ static krb5_error_code armor_ap_request
|
||||
if (retval == 0)
|
||||
retval = krb5_auth_con_setflags(kdc_context,
|
||||
authcontext, 0); /*disable replay cache*/
|
||||
- retval = krb5_rd_req(kdc_context, &authcontext,
|
||||
- &armor->armor_value, NULL /*server*/,
|
||||
- kdc_active_realm->realm_keytab, NULL, &ticket);
|
||||
+ if (retval == 0)
|
||||
+ retval = krb5_rd_req(kdc_context, &authcontext, &armor->armor_value,
|
||||
+ NULL /*server*/, kdc_active_realm->realm_keytab,
|
||||
+ NULL, &ticket);
|
||||
if (retval != 0) {
|
||||
const char * errmsg = krb5_get_error_message(kdc_context, retval);
|
||||
k5_setmsg(kdc_context, retval, _("%s while handling ap-request armor"),
|
||||
@@ -132,7 +133,7 @@ kdc_find_fast(krb5_kdc_req **requestptr,
|
||||
{
|
||||
krb5_error_code retval = 0;
|
||||
krb5_pa_data *fast_padata;
|
||||
- krb5_data scratch, *inner_body = NULL;
|
||||
+ krb5_data scratch, plaintext, *inner_body = NULL;
|
||||
krb5_fast_req * fast_req = NULL;
|
||||
krb5_kdc_req *request = *requestptr;
|
||||
krb5_fast_armored_req *fast_armored_req = NULL;
|
||||
@@ -183,11 +184,10 @@ kdc_find_fast(krb5_kdc_req **requestptr,
|
||||
}
|
||||
}
|
||||
if (retval == 0) {
|
||||
- krb5_data plaintext;
|
||||
plaintext.length = fast_armored_req->enc_part.ciphertext.length;
|
||||
- plaintext.data = malloc(plaintext.length);
|
||||
- if (plaintext.data == NULL)
|
||||
- retval = ENOMEM;
|
||||
+ plaintext.data = k5alloc(plaintext.length, &retval);
|
||||
+ }
|
||||
+ if (retval == 0) {
|
||||
retval = krb5_c_decrypt(kdc_context,
|
||||
state->armor_key,
|
||||
KRB5_KEYUSAGE_FAST_ENC, NULL,
|
||||
diff --git a/src/lib/gssapi/krb5/k5unsealiov.c b/src/lib/gssapi/krb5/k5unsealiov.c
|
||||
index 8b6704274..f15d2db69 100644
|
||||
--- a/src/lib/gssapi/krb5/k5unsealiov.c
|
||||
+++ b/src/lib/gssapi/krb5/k5unsealiov.c
|
||||
@@ -281,6 +281,7 @@ kg_unseal_v1_iov(krb5_context context,
|
||||
(!ctx->initiate && direction != 0)) {
|
||||
*minor_status = (OM_uint32)G_BAD_DIRECTION;
|
||||
retval = GSS_S_BAD_SIG;
|
||||
+ goto cleanup;
|
||||
}
|
||||
|
||||
code = 0;
|
||||
diff --git a/src/lib/kadm5/clnt/client_init.c b/src/lib/kadm5/clnt/client_init.c
|
||||
index 6f10db018..aa08918e2 100644
|
||||
--- a/src/lib/kadm5/clnt/client_init.c
|
||||
+++ b/src/lib/kadm5/clnt/client_init.c
|
||||
@@ -465,6 +465,9 @@ gic_iter(kadm5_server_handle_t handle, enum init_type init_type,
|
||||
/* Credentials for kadmin don't need to be forwardable or proxiable. */
|
||||
if (init_type != INIT_CREDS) {
|
||||
code = krb5_get_init_creds_opt_alloc(ctx, &opt);
|
||||
+ if (code)
|
||||
+ goto error;
|
||||
+
|
||||
krb5_get_init_creds_opt_set_forwardable(opt, 0);
|
||||
krb5_get_init_creds_opt_set_proxiable(opt, 0);
|
||||
krb5_get_init_creds_opt_set_out_ccache(ctx, opt, ccache);
|
||||
diff --git a/src/tests/gssapi/t_pcontok.c b/src/tests/gssapi/t_pcontok.c
|
||||
index b966f8129..c40ea434c 100644
|
||||
--- a/src/tests/gssapi/t_pcontok.c
|
||||
+++ b/src/tests/gssapi/t_pcontok.c
|
||||
@@ -126,6 +126,7 @@ make_delete_token(gss_krb5_lucid_context_v1_t *lctx, gss_buffer_desc *out)
|
||||
iov.flags = KRB5_CRYPTO_TYPE_DATA;
|
||||
iov.data = make_data(cksum.contents, 16);
|
||||
ret = krb5_k_encrypt_iov(context, seq, 0, NULL, &iov, 1);
|
||||
+ check_k5err(context, "krb5_k_encrypt_iov", ret);
|
||||
memcpy(ptr + 8, cksum.contents + 8, 8);
|
||||
} else {
|
||||
memcpy(ptr + 8, cksum.contents, cksize);
|
||||
|
|
@ -1,599 +0,0 @@
|
|||
From ebc913ea73bfc439f293831f19db83ec83622d51 Mon Sep 17 00:00:00 2001
|
||||
From: Robbie Harwood <rharwood@redhat.com>
|
||||
Date: Mon, 1 Apr 2019 14:28:48 -0400
|
||||
Subject: [PATCH] Implement krb5_cc_remove_cred for remaining types
|
||||
|
||||
Previously, only KCM and MSLA implemented credential removal. Add
|
||||
support for FILE (and therefore DIR), MEMORY, and KEYRING.
|
||||
|
||||
The FILE logic is similar Heimdal's implementation, with additional
|
||||
logic for skipping removed creds during iteration. In addition to
|
||||
setting endtime to 0 and changing the realm for config entries as
|
||||
Heimdal does, we set authtime to -1 to make deleted entries
|
||||
distinguishable from gssproxy encrypted creds and config entries.
|
||||
|
||||
For MEMORY, leave behind empty list elements when removing a cred will
|
||||
leave behind an empty list element, in case an iterator holds a
|
||||
pointer to that element.
|
||||
|
||||
[ghudson@mit.edu: edited commit message; made minor style and comment
|
||||
changes; fixed memory leaks detected by asan]
|
||||
|
||||
ticket: 8792 (new)
|
||||
(cherry picked from commit d3b39a8bac6206b5ea78b0bf6a2958c1df0b0dd5)
|
||||
---
|
||||
src/lib/krb5/ccache/cc_file.c | 177 ++++++++++++++++++++++++++++---
|
||||
src/lib/krb5/ccache/cc_keyring.c | 89 +++++++++++-----
|
||||
src/lib/krb5/ccache/cc_memory.c | 36 +++++--
|
||||
src/lib/krb5/ccache/t_cc.c | 129 +++++++++++++++++++++-
|
||||
4 files changed, 381 insertions(+), 50 deletions(-)
|
||||
|
||||
diff --git a/src/lib/krb5/ccache/cc_file.c b/src/lib/krb5/ccache/cc_file.c
|
||||
index 9263a0054..09da38fa9 100644
|
||||
--- a/src/lib/krb5/ccache/cc_file.c
|
||||
+++ b/src/lib/krb5/ccache/cc_file.c
|
||||
@@ -744,6 +744,14 @@ cleanup:
|
||||
return set_errmsg_filename(context, ret, data->filename);
|
||||
}
|
||||
|
||||
+/* Return true if cred is a removed entry (assuming that no legitimate cred
|
||||
+ * entries will have authtime=-1 and endtime=0). */
|
||||
+static inline krb5_boolean
|
||||
+cred_removed(krb5_creds *c)
|
||||
+{
|
||||
+ return c->times.endtime == 0 && c->times.authtime == -1;
|
||||
+}
|
||||
+
|
||||
/* Get the next credential from the cache file. */
|
||||
static krb5_error_code KRB5_CALLCONV
|
||||
fcc_next_cred(krb5_context context, krb5_ccache id, krb5_cc_cursor *cursor,
|
||||
@@ -765,19 +773,30 @@ fcc_next_cred(krb5_context context, krb5_ccache id, krb5_cc_cursor *cursor,
|
||||
goto cleanup;
|
||||
file_locked = TRUE;
|
||||
|
||||
- /* Load a marshalled cred into memory. */
|
||||
- ret = get_size(context, fcursor->fp, &maxsize);
|
||||
- if (ret)
|
||||
- goto cleanup;
|
||||
- ret = load_cred(context, fcursor->fp, fcursor->version, maxsize, &buf);
|
||||
- if (ret)
|
||||
- goto cleanup;
|
||||
- ret = k5_buf_status(&buf);
|
||||
- if (ret)
|
||||
- goto cleanup;
|
||||
+ for (;;) {
|
||||
+ /* Load a marshalled cred into memory. */
|
||||
+ ret = get_size(context, fcursor->fp, &maxsize);
|
||||
+ if (ret)
|
||||
+ goto cleanup;
|
||||
+ ret = load_cred(context, fcursor->fp, fcursor->version, maxsize, &buf);
|
||||
+ if (ret)
|
||||
+ goto cleanup;
|
||||
+ ret = k5_buf_status(&buf);
|
||||
+ if (ret)
|
||||
+ goto cleanup;
|
||||
|
||||
- /* Unmarshal it from buf into creds. */
|
||||
- ret = k5_unmarshal_cred(buf.data, buf.len, fcursor->version, creds);
|
||||
+ /* Unmarshal it from buf into creds. */
|
||||
+ ret = k5_unmarshal_cred(buf.data, buf.len, fcursor->version, creds);
|
||||
+ if (ret)
|
||||
+ goto cleanup;
|
||||
+
|
||||
+ /* Keep going if this entry has been removed; otherwise stop. */
|
||||
+ if (!cred_removed(creds))
|
||||
+ break;
|
||||
+
|
||||
+ k5_buf_truncate(&buf, 0);
|
||||
+ krb5_free_cred_contents(context, creds);
|
||||
+ }
|
||||
|
||||
cleanup:
|
||||
if (file_locked)
|
||||
@@ -1002,12 +1021,142 @@ cleanup:
|
||||
return set_errmsg_filename(context, ret ? ret : ret2, data->filename);
|
||||
}
|
||||
|
||||
-/* Non-functional stub for removing a cred from the cache file. */
|
||||
+/*
|
||||
+ * Overwrite cred in the ccache file with an entry that should not match any
|
||||
+ * reasonable search. Deletion is not guaranteed. This method is originally
|
||||
+ * from Heimdal, with the addition of setting authtime to -1.
|
||||
+ */
|
||||
+static krb5_error_code
|
||||
+delete_cred(krb5_context context, krb5_ccache cache, krb5_cc_cursor *cursor,
|
||||
+ krb5_creds *cred)
|
||||
+{
|
||||
+ krb5_error_code ret;
|
||||
+ krb5_fcc_cursor *fcursor = *cursor;
|
||||
+ fcc_data *data = cache->data;
|
||||
+ struct k5buf expected = EMPTY_K5BUF, overwrite = EMPTY_K5BUF;
|
||||
+ int fd = -1;
|
||||
+ uint8_t *on_disk = NULL;
|
||||
+ ssize_t rwret;
|
||||
+ off_t start_offset;
|
||||
+
|
||||
+ k5_buf_init_dynamic_zap(&expected);
|
||||
+ k5_buf_init_dynamic_zap(&overwrite);
|
||||
+
|
||||
+ /* Re-marshal cred to get its byte representation in the file. */
|
||||
+ k5_marshal_cred(&expected, fcursor->version, cred);
|
||||
+ ret = k5_buf_status(&expected);
|
||||
+ if (ret)
|
||||
+ goto cleanup;
|
||||
+
|
||||
+ /*
|
||||
+ * Mark the cred expired so that it will be skipped over by any future
|
||||
+ * match checks. Heimdal only sets endtime, but we also set authtime to
|
||||
+ * distinguish from gssproxy's creds.
|
||||
+ */
|
||||
+ cred->times.endtime = 0;
|
||||
+ cred->times.authtime = -1;
|
||||
+
|
||||
+ /* For config entries, also change the realm so that other implementations
|
||||
+ * won't match them. */
|
||||
+ if (cred->server != NULL && cred->server->realm.length > 0 &&
|
||||
+ strcmp(cred->server->realm.data, "X-CACHECONF:") == 0)
|
||||
+ memcpy(cred->server->realm.data, "X-RMED-CONF:", 12);
|
||||
+
|
||||
+ k5_marshal_cred(&overwrite, fcursor->version, cred);
|
||||
+ ret = k5_buf_status(&overwrite);
|
||||
+ if (ret)
|
||||
+ goto cleanup;
|
||||
+
|
||||
+ if (expected.len != overwrite.len) {
|
||||
+ ret = KRB5_CC_FORMAT;
|
||||
+ goto cleanup;
|
||||
+ }
|
||||
+
|
||||
+ /* Get a non-O_APPEND handle to the raw file. */
|
||||
+ fd = open(data->filename, O_RDWR | O_BINARY | O_CLOEXEC);
|
||||
+ if (fd == -1) {
|
||||
+ ret = interpret_errno(context, errno);
|
||||
+ goto cleanup;
|
||||
+ }
|
||||
+
|
||||
+ start_offset = ftell(fcursor->fp);
|
||||
+ if (start_offset == -1) {
|
||||
+ ret = interpret_errno(context, errno);
|
||||
+ goto cleanup;
|
||||
+ }
|
||||
+ start_offset -= expected.len;
|
||||
+
|
||||
+ /* Read the bytes at the entry to be overwritten. */
|
||||
+ if (lseek(fd, start_offset, SEEK_SET) == -1) {
|
||||
+ ret = interpret_errno(context, errno);
|
||||
+ goto cleanup;
|
||||
+ }
|
||||
+ on_disk = k5alloc(expected.len, &ret);
|
||||
+ if (ret != 0)
|
||||
+ goto cleanup;
|
||||
+ rwret = read(fd, on_disk, expected.len);
|
||||
+ if (rwret < 0) {
|
||||
+ ret = interpret_errno(context, errno);
|
||||
+ goto cleanup;
|
||||
+ } else if ((size_t)rwret != expected.len) {
|
||||
+ ret = KRB5_CC_FORMAT;
|
||||
+ goto cleanup;
|
||||
+ }
|
||||
+
|
||||
+ /*
|
||||
+ * If the bytes have changed, either someone else removed the same cred or
|
||||
+ * the cache was reinitialized. Either way the cred is no longer present,
|
||||
+ * so return successfully.
|
||||
+ */
|
||||
+ if (memcmp(on_disk, expected.data, expected.len) != 0)
|
||||
+ goto cleanup;
|
||||
+
|
||||
+ /* Write out the altered entry. */
|
||||
+ if (lseek(fd, start_offset, SEEK_SET) == -1) {
|
||||
+ ret = interpret_errno(context, errno);
|
||||
+ goto cleanup;
|
||||
+ }
|
||||
+ rwret = write(fd, overwrite.data, overwrite.len);
|
||||
+ if (rwret < 0) {
|
||||
+ ret = interpret_errno(context, errno);
|
||||
+ goto cleanup;
|
||||
+ }
|
||||
+
|
||||
+cleanup:
|
||||
+ close(fd);
|
||||
+ zapfree(on_disk, expected.len);
|
||||
+ k5_buf_free(&expected);
|
||||
+ k5_buf_free(&overwrite);
|
||||
+ return ret;
|
||||
+}
|
||||
+
|
||||
+/* Remove the given creds from the ccache file. */
|
||||
static krb5_error_code KRB5_CALLCONV
|
||||
fcc_remove_cred(krb5_context context, krb5_ccache cache, krb5_flags flags,
|
||||
krb5_creds *creds)
|
||||
{
|
||||
- return KRB5_CC_NOSUPP;
|
||||
+ krb5_error_code ret;
|
||||
+ krb5_cc_cursor cursor;
|
||||
+ krb5_creds cur;
|
||||
+
|
||||
+ ret = krb5_cc_start_seq_get(context, cache, &cursor);
|
||||
+ if (ret)
|
||||
+ return ret;
|
||||
+
|
||||
+ for (;;) {
|
||||
+ ret = krb5_cc_next_cred(context, cache, &cursor, &cur);
|
||||
+ if (ret)
|
||||
+ break;
|
||||
+
|
||||
+ if (krb5int_cc_creds_match_request(context, flags, creds, &cur))
|
||||
+ ret = delete_cred(context, cache, &cursor, &cur);
|
||||
+ krb5_free_cred_contents(context, &cur);
|
||||
+ if (ret)
|
||||
+ break;
|
||||
+ }
|
||||
+
|
||||
+ krb5_cc_end_seq_get(context, cache, &cursor);
|
||||
+ return (ret == KRB5_CC_END) ? 0 : ret;
|
||||
}
|
||||
|
||||
static krb5_error_code KRB5_CALLCONV
|
||||
diff --git a/src/lib/krb5/ccache/cc_keyring.c b/src/lib/krb5/ccache/cc_keyring.c
|
||||
index 8419f6ebf..98723fe2e 100644
|
||||
--- a/src/lib/krb5/ccache/cc_keyring.c
|
||||
+++ b/src/lib/krb5/ccache/cc_keyring.c
|
||||
@@ -1032,40 +1032,44 @@ krcc_next_cred(krb5_context context, krb5_ccache id, krb5_cc_cursor *cursor,
|
||||
|
||||
memset(creds, 0, sizeof(krb5_creds));
|
||||
|
||||
- /* The cursor has the entire list of keys. (Note that we don't support
|
||||
- * remove_cred.) */
|
||||
+ /* The cursor has the entire list of keys. */
|
||||
krcursor = *cursor;
|
||||
if (krcursor == NULL)
|
||||
return KRB5_CC_END;
|
||||
|
||||
- /* If we're pointing past the end of the keys array, there are no more. */
|
||||
- if (krcursor->currkey >= krcursor->numkeys)
|
||||
- return KRB5_CC_END;
|
||||
+ while (krcursor->currkey < krcursor->numkeys) {
|
||||
+ /* If we're pointing at the entry with the principal, or at the key
|
||||
+ * with the time offsets, skip it. */
|
||||
+ if (krcursor->keys[krcursor->currkey] == krcursor->princ_id ||
|
||||
+ krcursor->keys[krcursor->currkey] == krcursor->offsets_id) {
|
||||
+ krcursor->currkey++;
|
||||
+ continue;
|
||||
+ }
|
||||
|
||||
- /* If we're pointing at the entry with the principal, or at the key
|
||||
- * with the time offsets, skip it. */
|
||||
- while (krcursor->keys[krcursor->currkey] == krcursor->princ_id ||
|
||||
- krcursor->keys[krcursor->currkey] == krcursor->offsets_id) {
|
||||
- krcursor->currkey++;
|
||||
- /* Check if we have now reached the end */
|
||||
- if (krcursor->currkey >= krcursor->numkeys)
|
||||
- return KRB5_CC_END;
|
||||
- }
|
||||
+ /* Read the key; the right size buffer will be allocated and
|
||||
+ * returned. */
|
||||
+ psize = keyctl_read_alloc(krcursor->keys[krcursor->currkey],
|
||||
+ &payload);
|
||||
+ if (psize != -1) {
|
||||
+ krcursor->currkey++;
|
||||
|
||||
- /* Read the key; the right size buffer will be allocated and returned. */
|
||||
- psize = keyctl_read_alloc(krcursor->keys[krcursor->currkey], &payload);
|
||||
- if (psize == -1) {
|
||||
- DEBUG_PRINT(("Error reading key %d: %s\n",
|
||||
- krcursor->keys[krcursor->currkey],
|
||||
- strerror(errno)));
|
||||
- return KRB5_FCC_NOFILE;
|
||||
+ /* Unmarshal the cred using the file ccache version 4 format. */
|
||||
+ ret = k5_unmarshal_cred(payload, psize, 4, creds);
|
||||
+ free(payload);
|
||||
+ return ret;
|
||||
+ } else if (errno != ENOKEY && errno != EACCES) {
|
||||
+ DEBUG_PRINT(("Error reading key %d: %s\n",
|
||||
+ krcursor->keys[krcursor->currkey], strerror(errno)));
|
||||
+ return KRB5_FCC_NOFILE;
|
||||
+ }
|
||||
+
|
||||
+ /* The current key was unlinked, probably by a remove_cred call; move
|
||||
+ * on to the next one. */
|
||||
+ krcursor->currkey++;
|
||||
}
|
||||
- krcursor->currkey++;
|
||||
|
||||
- /* Unmarshal the credential using the file ccache version 4 format. */
|
||||
- ret = k5_unmarshal_cred(payload, psize, 4, creds);
|
||||
- free(payload);
|
||||
- return ret;
|
||||
+ /* No more keys in keyring. */
|
||||
+ return KRB5_CC_END;
|
||||
}
|
||||
|
||||
/* Release an iteration cursor. */
|
||||
@@ -1248,12 +1252,41 @@ krcc_retrieve(krb5_context context, krb5_ccache id,
|
||||
creds);
|
||||
}
|
||||
|
||||
-/* Non-functional stub for removing a cred from the cache keyring. */
|
||||
+/* Remove a credential from the cache keyring. */
|
||||
static krb5_error_code KRB5_CALLCONV
|
||||
krcc_remove_cred(krb5_context context, krb5_ccache cache,
|
||||
krb5_flags flags, krb5_creds *creds)
|
||||
{
|
||||
- return KRB5_CC_NOSUPP;
|
||||
+ krb5_error_code ret;
|
||||
+ krcc_data *data = cache->data;
|
||||
+ krb5_cc_cursor cursor;
|
||||
+ krb5_creds c;
|
||||
+ krcc_cursor krcursor;
|
||||
+ key_serial_t key;
|
||||
+ krb5_boolean match;
|
||||
+
|
||||
+ ret = krcc_start_seq_get(context, cache, &cursor);
|
||||
+ if (ret)
|
||||
+ return ret;
|
||||
+
|
||||
+ for (;;) {
|
||||
+ ret = krcc_next_cred(context, cache, &cursor, &c);
|
||||
+ if (ret)
|
||||
+ break;
|
||||
+ match = krb5int_cc_creds_match_request(context, flags, creds, &c);
|
||||
+ krb5_free_cred_contents(context, &c);
|
||||
+ if (match) {
|
||||
+ krcursor = cursor;
|
||||
+ key = krcursor->keys[krcursor->currkey - 1];
|
||||
+ if (keyctl_unlink(key, data->cache_id) == -1) {
|
||||
+ ret = errno;
|
||||
+ break;
|
||||
+ }
|
||||
+ }
|
||||
+ }
|
||||
+
|
||||
+ krcc_end_seq_get(context, cache, &cursor);
|
||||
+ return (ret == KRB5_CC_END) ? 0 : ret;
|
||||
}
|
||||
|
||||
/* Set flags on the cache. (We don't care about any flags.) */
|
||||
diff --git a/src/lib/krb5/ccache/cc_memory.c b/src/lib/krb5/ccache/cc_memory.c
|
||||
index 114ef6913..edf6fcc26 100644
|
||||
--- a/src/lib/krb5/ccache/cc_memory.c
|
||||
+++ b/src/lib/krb5/ccache/cc_memory.c
|
||||
@@ -405,14 +405,23 @@ krb5_mcc_next_cred(krb5_context context, krb5_ccache id,
|
||||
*/
|
||||
k5_cc_mutex_lock(context, &d->lock);
|
||||
if (mcursor->generation != d->generation) {
|
||||
- k5_cc_mutex_unlock(context, &d->lock);
|
||||
- return KRB5_CC_END;
|
||||
+ retval = KRB5_CC_END;
|
||||
+ goto done;
|
||||
+ }
|
||||
+
|
||||
+ /* Skip over removed creds. */
|
||||
+ while (mcursor->next_link != NULL && mcursor->next_link->creds == NULL)
|
||||
+ mcursor->next_link = mcursor->next_link->next;
|
||||
+ if (mcursor->next_link == NULL) {
|
||||
+ retval = KRB5_CC_END;
|
||||
+ goto done;
|
||||
}
|
||||
|
||||
retval = k5_copy_creds_contents(context, mcursor->next_link->creds, creds);
|
||||
if (retval == 0)
|
||||
mcursor->next_link = mcursor->next_link->next;
|
||||
|
||||
+done:
|
||||
k5_cc_mutex_unlock(context, &d->lock);
|
||||
return retval;
|
||||
}
|
||||
@@ -592,16 +601,31 @@ krb5_mcc_retrieve(krb5_context context, krb5_ccache id, krb5_flags whichfields,
|
||||
}
|
||||
|
||||
/*
|
||||
- * Non-functional stub implementation for krb5_mcc_remove
|
||||
+ * Modifies:
|
||||
+ * the memory cache
|
||||
*
|
||||
- * Errors:
|
||||
- * KRB5_CC_NOSUPP - not implemented
|
||||
+ * Effects:
|
||||
+ * Remove the given creds from the ccache.
|
||||
*/
|
||||
static krb5_error_code KRB5_CALLCONV
|
||||
krb5_mcc_remove_cred(krb5_context context, krb5_ccache cache, krb5_flags flags,
|
||||
krb5_creds *creds)
|
||||
{
|
||||
- return KRB5_CC_NOSUPP;
|
||||
+ krb5_mcc_data *data = (krb5_mcc_data *)cache->data;
|
||||
+ krb5_mcc_link *l;
|
||||
+
|
||||
+ k5_cc_mutex_lock(context, &data->lock);
|
||||
+
|
||||
+ for (l = data->link; l != NULL; l = l->next) {
|
||||
+ if (l->creds != NULL &&
|
||||
+ krb5int_cc_creds_match_request(context, flags, creds, l->creds)) {
|
||||
+ krb5_free_creds(context, l->creds);
|
||||
+ l->creds = NULL;
|
||||
+ }
|
||||
+ }
|
||||
+
|
||||
+ k5_cc_mutex_unlock(context, &data->lock);
|
||||
+ return 0;
|
||||
}
|
||||
|
||||
|
||||
diff --git a/src/lib/krb5/ccache/t_cc.c b/src/lib/krb5/ccache/t_cc.c
|
||||
index cd4569c4c..954f2f465 100644
|
||||
--- a/src/lib/krb5/ccache/t_cc.c
|
||||
+++ b/src/lib/krb5/ccache/t_cc.c
|
||||
@@ -36,7 +36,7 @@
|
||||
|
||||
#define KRB5_OK 0
|
||||
|
||||
-krb5_creds test_creds;
|
||||
+krb5_creds test_creds, test_creds2;
|
||||
|
||||
int debug=0;
|
||||
|
||||
@@ -144,6 +144,10 @@ init_test_cred(krb5_context context)
|
||||
a->length = 2;
|
||||
test_creds.authdata[1] = a;
|
||||
|
||||
+ memcpy(&test_creds2, &test_creds, sizeof(test_creds));
|
||||
+ kret = krb5_build_principal(context, &test_creds2.server, sizeof(REALM),
|
||||
+ REALM, "server-comp1", "server-comp3", NULL);
|
||||
+
|
||||
cleanup:
|
||||
if(kret) {
|
||||
if (test_creds.client) {
|
||||
@@ -170,6 +174,7 @@ free_test_cred(krb5_context context)
|
||||
krb5_free_principal(context, test_creds.client);
|
||||
|
||||
krb5_free_principal(context, test_creds.server);
|
||||
+ krb5_free_principal(context, test_creds2.server);
|
||||
|
||||
if(test_creds.authdata) {
|
||||
krb5_free_authdata(context, test_creds.authdata);
|
||||
@@ -199,6 +204,44 @@ free_test_cred(krb5_context context)
|
||||
#define CHECK_FAIL(experr, kret, msg) \
|
||||
if (experr != kret) { CHECK(kret, msg);}
|
||||
|
||||
+static void
|
||||
+check_num_entries(krb5_context context, krb5_ccache cache, int expected,
|
||||
+ unsigned linenum)
|
||||
+{
|
||||
+ krb5_error_code ret;
|
||||
+ krb5_cc_cursor cursor;
|
||||
+ krb5_creds creds;
|
||||
+ int count = 0;
|
||||
+
|
||||
+ ret = krb5_cc_start_seq_get(context, cache, &cursor);
|
||||
+ if (ret != 0) {
|
||||
+ com_err("", ret, "(on line %d) - krb5_cc_start_seq_get", linenum);
|
||||
+ fflush(stderr);
|
||||
+ exit(1);
|
||||
+ }
|
||||
+
|
||||
+ while (1) {
|
||||
+ ret = krb5_cc_next_cred(context, cache, &cursor, &creds);
|
||||
+ if (ret)
|
||||
+ break;
|
||||
+
|
||||
+ count++;
|
||||
+ krb5_free_cred_contents(context, &creds);
|
||||
+ }
|
||||
+ krb5_cc_end_seq_get(context, cache, &cursor);
|
||||
+ if (ret != KRB5_CC_END) {
|
||||
+ CHECK(ret, "counting entries in ccache");
|
||||
+ }
|
||||
+
|
||||
+ if (count != expected) {
|
||||
+ com_err("", KRB5_FCC_INTERNAL,
|
||||
+ "(on line %d) - count didn't match (expected %d, got %d)",
|
||||
+ linenum, expected, count);
|
||||
+ fflush(stderr);
|
||||
+ exit(1);
|
||||
+ }
|
||||
+}
|
||||
+
|
||||
static void
|
||||
cc_test(krb5_context context, const char *name, krb5_flags flags)
|
||||
{
|
||||
@@ -207,6 +250,7 @@ cc_test(krb5_context context, const char *name, krb5_flags flags)
|
||||
krb5_error_code kret;
|
||||
krb5_cc_cursor cursor;
|
||||
krb5_principal tmp;
|
||||
+ krb5_flags matchflags = KRB5_TC_MATCH_IS_SKEY;
|
||||
|
||||
const char *c_name;
|
||||
char newcache[300];
|
||||
@@ -311,9 +355,90 @@ cc_test(krb5_context context, const char *name, krb5_flags flags)
|
||||
kret = krb5_cc_destroy(context, id2);
|
||||
CHECK(kret, "destroy id2");
|
||||
|
||||
+ /* ----------------------------------------------------- */
|
||||
+ /* Test credential removal */
|
||||
+ kret = krb5_cc_resolve(context, name, &id);
|
||||
+ CHECK(kret, "resolving for remove");
|
||||
+
|
||||
+ kret = krb5_cc_initialize(context, id, test_creds.client);
|
||||
+ CHECK(kret, "initialize for remove");
|
||||
+ check_num_entries(context, id, 0, __LINE__);
|
||||
+
|
||||
+ kret = krb5_cc_store_cred(context, id, &test_creds);
|
||||
+ CHECK(kret, "store for remove (first pass)");
|
||||
+ check_num_entries(context, id, 1, __LINE__); /* 1 */
|
||||
+
|
||||
+ kret = krb5_cc_remove_cred(context, id, matchflags, &test_creds);
|
||||
+ CHECK(kret, "removing credential (first pass)");
|
||||
+ check_num_entries(context, id, 0, __LINE__); /* empty */
|
||||
+
|
||||
+ kret = krb5_cc_store_cred(context, id, &test_creds);
|
||||
+ CHECK(kret, "first store for remove (second pass)");
|
||||
+ check_num_entries(context, id, 1, __LINE__); /* 1 */
|
||||
+
|
||||
+ kret = krb5_cc_store_cred(context, id, &test_creds2);
|
||||
+ CHECK(kret, "second store for remove (second pass)");
|
||||
+ check_num_entries(context, id, 2, __LINE__); /* 1, 2 */
|
||||
+
|
||||
+ kret = krb5_cc_remove_cred(context, id, matchflags, &test_creds2);
|
||||
+ CHECK(kret, "first remove (second pass)");
|
||||
+ check_num_entries(context, id, 1, __LINE__); /* 1 */
|
||||
+
|
||||
+ kret = krb5_cc_store_cred(context, id, &test_creds2);
|
||||
+ CHECK(kret, "third store for remove (second pass)");
|
||||
+ check_num_entries(context, id, 2, __LINE__); /* 1, 2 */
|
||||
+
|
||||
+ kret = krb5_cc_remove_cred(context, id, matchflags, &test_creds);
|
||||
+ CHECK(kret, "second remove (second pass)");
|
||||
+ check_num_entries(context, id, 1, __LINE__); /* 2 */
|
||||
+
|
||||
+ kret = krb5_cc_remove_cred(context, id, matchflags, &test_creds2);
|
||||
+ CHECK(kret, "third remove (second pass)");
|
||||
+ check_num_entries(context, id, 0, __LINE__); /* empty */
|
||||
+
|
||||
+ kret = krb5_cc_destroy(context, id);
|
||||
+ CHECK(kret, "destruction for remove");
|
||||
+
|
||||
+ /* Test removal with iteration. */
|
||||
+ kret = krb5_cc_resolve(context, name, &id);
|
||||
+ CHECK(kret, "resolving for remove-iter");
|
||||
+
|
||||
+ kret = krb5_cc_initialize(context, id, test_creds.client);
|
||||
+ CHECK(kret, "initialize for remove-iter");
|
||||
+
|
||||
+ kret = krb5_cc_store_cred(context, id, &test_creds);
|
||||
+ CHECK(kret, "first store for remove-iter");
|
||||
+
|
||||
+ kret = krb5_cc_store_cred(context, id, &test_creds2);
|
||||
+ CHECK(kret, "second store for remove-iter");
|
||||
+
|
||||
+ kret = krb5_cc_start_seq_get(context, id, &cursor);
|
||||
+ CHECK(kret, "start_seq_get for remove-iter");
|
||||
+
|
||||
+ kret = krb5_cc_remove_cred(context, id, matchflags, &test_creds);
|
||||
+ CHECK(kret, "remove for remove-iter");
|
||||
+
|
||||
+ while (1) {
|
||||
+ /* The removed credential may or may not be present in the cache -
|
||||
+ * either behavior is technically correct. */
|
||||
+ kret = krb5_cc_next_cred(context, id, &cursor, &creds);
|
||||
+ if (kret == KRB5_CC_END)
|
||||
+ break;
|
||||
+ CHECK(kret, "next_cred for remove-iter: %s");
|
||||
+
|
||||
+ CHECK(creds.times.endtime == 0, "no-lifetime cred");
|
||||
+
|
||||
+ krb5_free_cred_contents(context, &creds);
|
||||
+ }
|
||||
+
|
||||
+ kret = krb5_cc_end_seq_get(context, id, &cursor);
|
||||
+ CHECK(kret, "end_seq_get for remove-iter");
|
||||
+
|
||||
+ kret = krb5_cc_destroy(context, id);
|
||||
+ CHECK(kret, "destruction for remove-iter");
|
||||
+
|
||||
free(save_type);
|
||||
free_test_cred(context);
|
||||
-
|
||||
}
|
||||
|
||||
/*
|
||||
|
|
@ -1,55 +0,0 @@
|
|||
From f9123277a5b4e27d5fea3dbae0889dcb527115fc Mon Sep 17 00:00:00 2001
|
||||
From: Robbie Harwood <rharwood@redhat.com>
|
||||
Date: Mon, 6 May 2019 13:13:16 -0400
|
||||
Subject: [PATCH] Improve error messages from kadmin change_password
|
||||
|
||||
The checks for missing option arguments were dead code, because the
|
||||
loop condition requires at least two remaining arguments. Instead
|
||||
check for at least one argument with a leading "-", and check for too
|
||||
many or too few arguments after the loop. Add an initial message for
|
||||
unrecognized options.
|
||||
|
||||
[ghudson@mit.edu: adjusted logic to improve mesages in more cases]
|
||||
|
||||
(cherry picked from commit 13ba54002d362ebb09be464b4e7ec75050d1348f)
|
||||
---
|
||||
src/kadmin/cli/kadmin.c | 12 ++++++++----
|
||||
1 file changed, 8 insertions(+), 4 deletions(-)
|
||||
|
||||
diff --git a/src/kadmin/cli/kadmin.c b/src/kadmin/cli/kadmin.c
|
||||
index cc74921bf..fe4cb493c 100644
|
||||
--- a/src/kadmin/cli/kadmin.c
|
||||
+++ b/src/kadmin/cli/kadmin.c
|
||||
@@ -797,11 +797,11 @@ kadmin_cpw(int argc, char *argv[])
|
||||
char **db_args = NULL;
|
||||
int db_args_size = 0;
|
||||
|
||||
- if (argc < 2) {
|
||||
+ if (argc < 1) {
|
||||
cpw_usage(NULL);
|
||||
return;
|
||||
}
|
||||
- for (argv++, argc--; argc > 1; argc--, argv++) {
|
||||
+ for (argv++, argc--; argc > 0 && **argv == '-'; argc--, argv++) {
|
||||
if (!strcmp("-x", *argv)) {
|
||||
argc--;
|
||||
if (argc < 1) {
|
||||
@@ -841,12 +841,16 @@ kadmin_cpw(int argc, char *argv[])
|
||||
goto cleanup;
|
||||
}
|
||||
} else {
|
||||
+ com_err("change_password", 0, _("unrecognized option %s"), *argv);
|
||||
cpw_usage(NULL);
|
||||
goto cleanup;
|
||||
}
|
||||
}
|
||||
- if (*argv == NULL) {
|
||||
- com_err("change_password", 0, _("missing principal name"));
|
||||
+ if (argc != 1) {
|
||||
+ if (argc < 1)
|
||||
+ com_err("change_password", 0, _("missing principal name"));
|
||||
+ else
|
||||
+ com_err("change_password", 0, _("too many arguments"));
|
||||
cpw_usage(NULL);
|
||||
goto cleanup;
|
||||
}
|
||||
|
|
@ -1,28 +0,0 @@
|
|||
From 0e1c9fa82ea2a5f32a6ce937ffe9b1aef21e133e Mon Sep 17 00:00:00 2001
|
||||
From: Robbie Harwood <rharwood@redhat.com>
|
||||
Date: Tue, 15 Jan 2019 13:41:16 -0500
|
||||
Subject: [PATCH] In kpropd, debug-log proper ticket enctype names
|
||||
|
||||
This change replaces the last call of krb5_enctype_to_string() in our
|
||||
sources with krb5_enctype_to_name(), ensuring that we log consistently
|
||||
to users using readily discoverable strings.
|
||||
|
||||
(cherry picked from commit 30e12a2ecdf7e2a034a91626a03b5c9909e4c68d)
|
||||
---
|
||||
src/kprop/kpropd.c | 3 ++-
|
||||
1 file changed, 2 insertions(+), 1 deletion(-)
|
||||
|
||||
diff --git a/src/kprop/kpropd.c b/src/kprop/kpropd.c
|
||||
index 4cc035dc6..0c7bffa24 100644
|
||||
--- a/src/kprop/kpropd.c
|
||||
+++ b/src/kprop/kpropd.c
|
||||
@@ -1279,7 +1279,8 @@ kerberos_authenticate(krb5_context context, int fd, krb5_principal *clientp,
|
||||
exit(1);
|
||||
}
|
||||
|
||||
- retval = krb5_enctype_to_string(*etype, etypebuf, sizeof(etypebuf));
|
||||
+ retval = krb5_enctype_to_name(*etype, FALSE, etypebuf,
|
||||
+ sizeof(etypebuf));
|
||||
if (retval) {
|
||||
com_err(progname, retval, _("while unparsing ticket etype"));
|
||||
exit(1);
|
||||
|
|
@ -1,54 +0,0 @@
|
|||
From 92e46dabccaf7dfecfcb85bb87b773b734724ccb Mon Sep 17 00:00:00 2001
|
||||
From: Robbie Harwood <rharwood@redhat.com>
|
||||
Date: Mon, 14 Jan 2019 17:14:42 -0500
|
||||
Subject: [PATCH] In rd_req_dec, always log non-permitted enctypes
|
||||
|
||||
The buffer specified in negotiate_etype() is too small for use with
|
||||
the AES enctypes when used with krb5_enctype_to_string(), so switch to
|
||||
using krb5_enctype_to_name().
|
||||
|
||||
(cherry picked from commit bf75ebf583a51bf00005a96d17924818d19377be)
|
||||
---
|
||||
src/lib/krb5/krb/rd_req_dec.c | 5 ++---
|
||||
src/tests/gssapi/t_enctypes.py | 5 +++--
|
||||
2 files changed, 5 insertions(+), 5 deletions(-)
|
||||
|
||||
diff --git a/src/lib/krb5/krb/rd_req_dec.c b/src/lib/krb5/krb/rd_req_dec.c
|
||||
index 4cd429a11..e75192fee 100644
|
||||
--- a/src/lib/krb5/krb/rd_req_dec.c
|
||||
+++ b/src/lib/krb5/krb/rd_req_dec.c
|
||||
@@ -864,9 +864,8 @@ negotiate_etype(krb5_context context,
|
||||
if (permitted == FALSE) {
|
||||
char enctype_name[30];
|
||||
|
||||
- if (krb5_enctype_to_string(desired_etypes[i],
|
||||
- enctype_name,
|
||||
- sizeof(enctype_name)) == 0)
|
||||
+ if (krb5_enctype_to_name(desired_etypes[i], FALSE, enctype_name,
|
||||
+ sizeof(enctype_name)) == 0)
|
||||
k5_setmsg(context, KRB5_NOPERM_ETYPE,
|
||||
_("Encryption type %s not permitted"), enctype_name);
|
||||
return KRB5_NOPERM_ETYPE;
|
||||
diff --git a/src/tests/gssapi/t_enctypes.py b/src/tests/gssapi/t_enctypes.py
|
||||
index ee43ff028..5d9f80e04 100755
|
||||
--- a/src/tests/gssapi/t_enctypes.py
|
||||
+++ b/src/tests/gssapi/t_enctypes.py
|
||||
@@ -85,7 +85,8 @@ test('both aes128', 'aes128-cts', 'aes128-cts',
|
||||
# If only the acceptor constrains the permitted session enctypes to
|
||||
# aes128, subkey negotiation fails because the acceptor considers the
|
||||
# aes256 session key to be non-permitted.
|
||||
-test_err('acc aes128', None, 'aes128-cts', 'Encryption type not permitted')
|
||||
+test_err('acc aes128', None, 'aes128-cts',
|
||||
+ 'Encryption type aes256-cts-hmac-sha1-96 not permitted')
|
||||
|
||||
# If the initiator constrains the permitted session enctypes to des3,
|
||||
# no acceptor subkey will be generated because we can't upgrade to a
|
||||
@@ -128,7 +129,7 @@ test('upgrade init des3+rc4', 'des3 rc4', None,
|
||||
# is only for the sake of the kernel, since we could upgrade to an
|
||||
# aes128 subkey, but it's the current semantics.)
|
||||
test_err('upgrade acc aes128', None, 'aes128-cts',
|
||||
- 'Encryption type ArcFour with HMAC/md5 not permitted')
|
||||
+ 'Encryption type arcfour-hmac not permitted')
|
||||
|
||||
# If the acceptor permits rc4 but prefers aes128, it will negotiate an
|
||||
# upgrade to aes128.
|
||||
|
|
@ -1,41 +0,0 @@
|
|||
From b448801a1ab19d89cc069e63f5ce5acbc9f3cd8d Mon Sep 17 00:00:00 2001
|
||||
From: Robbie Harwood <rharwood@redhat.com>
|
||||
Date: Fri, 9 Aug 2019 14:07:22 -0400
|
||||
Subject: [PATCH] Initialize life/rlife in kdcpolicy interface
|
||||
|
||||
A value of 0 indicates that the plugin doesn't wish to modify lifetimes.
|
||||
Make this the default, rather than requiring all plugins to set these
|
||||
values themselves.
|
||||
|
||||
ticket: 8824 (new)
|
||||
tags: pullup
|
||||
target_version: 1.17-next
|
||||
target_version: 1.16-next
|
||||
|
||||
(cherry picked from commit d81c5870013240c04642c8e0cb994b4c49e40ddf)
|
||||
---
|
||||
src/kdc/policy.c | 4 ++--
|
||||
1 file changed, 2 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/src/kdc/policy.c b/src/kdc/policy.c
|
||||
index 26c16f97c..a3ff556c5 100644
|
||||
--- a/src/kdc/policy.c
|
||||
+++ b/src/kdc/policy.c
|
||||
@@ -106,7 +106,7 @@ check_kdcpolicy_as(krb5_context context, const krb5_kdc_req *request,
|
||||
krb5_data *const *auth_indicators, krb5_timestamp kdc_time,
|
||||
krb5_ticket_times *times, const char **status)
|
||||
{
|
||||
- krb5_deltat life, rlife;
|
||||
+ krb5_deltat life = 0, rlife = 0;
|
||||
krb5_error_code ret;
|
||||
kdcpolicy_handle *hp, h;
|
||||
char **ais = NULL;
|
||||
@@ -146,7 +146,7 @@ check_kdcpolicy_tgs(krb5_context context, const krb5_kdc_req *request,
|
||||
krb5_data *const *auth_indicators, krb5_timestamp kdc_time,
|
||||
krb5_ticket_times *times, const char **status)
|
||||
{
|
||||
- krb5_deltat life, rlife;
|
||||
+ krb5_deltat life = 0, rlife = 0;
|
||||
krb5_error_code ret;
|
||||
kdcpolicy_handle *hp, h;
|
||||
char **ais = NULL;
|
||||
|
|
@ -1,55 +0,0 @@
|
|||
From 0f05d25ddecba6d8dd5de5c1b2e31f45942b9a85 Mon Sep 17 00:00:00 2001
|
||||
From: Robbie Harwood <rharwood@redhat.com>
|
||||
Date: Thu, 2 May 2019 13:36:38 -0400
|
||||
Subject: [PATCH] Initialize some data structure magic fields
|
||||
|
||||
Static analyzers may complain if they see a data structure copied with
|
||||
an uninitialized field, even if the copy target won't use the field.
|
||||
Add magic field initializers in three such places.
|
||||
|
||||
[ghudson@mit.edu: rewrote commit message]
|
||||
|
||||
(cherry picked from commit 551e88e76e537e45f6c80eadaefeb790994f83f9)
|
||||
---
|
||||
src/lib/gssapi/krb5/util_cksum.c | 1 +
|
||||
src/lib/krb5/krb/authdata.c | 8 ++------
|
||||
2 files changed, 3 insertions(+), 6 deletions(-)
|
||||
|
||||
diff --git a/src/lib/gssapi/krb5/util_cksum.c b/src/lib/gssapi/krb5/util_cksum.c
|
||||
index cfd585ec7..a1770774e 100644
|
||||
--- a/src/lib/gssapi/krb5/util_cksum.c
|
||||
+++ b/src/lib/gssapi/krb5/util_cksum.c
|
||||
@@ -48,6 +48,7 @@ kg_checksum_channel_bindings(context, cb, cksum)
|
||||
|
||||
cksum->checksum_type = CKSUMTYPE_RSA_MD5;
|
||||
cksum->length = sumlen;
|
||||
+ cksum->magic = KV5M_CHECKSUM;
|
||||
|
||||
/* generate a buffer full of zeros if no cb specified */
|
||||
|
||||
diff --git a/src/lib/krb5/krb/authdata.c b/src/lib/krb5/krb/authdata.c
|
||||
index 7fbcfab68..3e7dfbe49 100644
|
||||
--- a/src/lib/krb5/krb/authdata.c
|
||||
+++ b/src/lib/krb5/krb/authdata.c
|
||||
@@ -976,9 +976,7 @@ krb5_authdata_export_internal(krb5_context kcontext,
|
||||
|
||||
*ptr = NULL;
|
||||
|
||||
- name.length = strlen(module_name);
|
||||
- name.data = (char *)module_name;
|
||||
-
|
||||
+ name = make_data((char *)module_name, strlen(module_name));
|
||||
module = k5_ad_find_module(kcontext, context, AD_USAGE_MASK, &name);
|
||||
if (module == NULL)
|
||||
return ENOENT;
|
||||
@@ -1005,9 +1003,7 @@ krb5_authdata_free_internal(krb5_context kcontext,
|
||||
krb5_data name;
|
||||
struct _krb5_authdata_context_module *module;
|
||||
|
||||
- name.length = strlen(module_name);
|
||||
- name.data = (char *)module_name;
|
||||
-
|
||||
+ name = make_data((char *)module_name, strlen(module_name));
|
||||
module = k5_ad_find_module(kcontext, context, AD_USAGE_MASK, &name);
|
||||
if (module == NULL)
|
||||
return ENOENT;
|
||||
|
|
@ -1,293 +0,0 @@
|
|||
From c955111643b4ef9a005a083d8f2aa39ec4af81ec Mon Sep 17 00:00:00 2001
|
||||
From: Robbie Harwood <rharwood@redhat.com>
|
||||
Date: Tue, 8 Jan 2019 17:42:35 -0500
|
||||
Subject: [PATCH] Make etype names in KDC logs human-readable
|
||||
|
||||
Introduce enctype_name() as a wrapper over krb5_enctype_to_name for
|
||||
converting between registered constants and names. Adjust signatures
|
||||
and rewrite ktypes2str() and rep_etypes2str() to operate on dynamic
|
||||
buffers.
|
||||
|
||||
ticket: 8772 (new)
|
||||
(cherry picked from commit a649279727490687d54becad91fde8cf7429d951)
|
||||
---
|
||||
src/kdc/kdc_log.c | 42 +++++++--------
|
||||
src/kdc/kdc_util.c | 125 +++++++++++++++++++++++----------------------
|
||||
src/kdc/kdc_util.h | 6 +--
|
||||
3 files changed, 87 insertions(+), 86 deletions(-)
|
||||
|
||||
diff --git a/src/kdc/kdc_log.c b/src/kdc/kdc_log.c
|
||||
index 4eec50373..b160ba21a 100644
|
||||
--- a/src/kdc/kdc_log.c
|
||||
+++ b/src/kdc/kdc_log.c
|
||||
@@ -65,7 +65,7 @@ log_as_req(krb5_context context,
|
||||
{
|
||||
const char *fromstring = 0;
|
||||
char fromstringbuf[70];
|
||||
- char ktypestr[128];
|
||||
+ char *ktypestr = NULL;
|
||||
const char *cname2 = cname ? cname : "<unknown client>";
|
||||
const char *sname2 = sname ? sname : "<unknown server>";
|
||||
|
||||
@@ -74,26 +74,29 @@ log_as_req(krb5_context context,
|
||||
fromstringbuf, sizeof(fromstringbuf));
|
||||
if (!fromstring)
|
||||
fromstring = "<unknown>";
|
||||
- ktypes2str(ktypestr, sizeof(ktypestr),
|
||||
- request->nktypes, request->ktype);
|
||||
+
|
||||
+ ktypestr = ktypes2str(request->ktype, request->nktypes);
|
||||
|
||||
if (status == NULL) {
|
||||
/* success */
|
||||
- char rep_etypestr[128];
|
||||
- rep_etypes2str(rep_etypestr, sizeof(rep_etypestr), reply);
|
||||
+ char *rep_etypestr = rep_etypes2str(reply);
|
||||
krb5_klog_syslog(LOG_INFO, _("AS_REQ (%s) %s: ISSUE: authtime %u, %s, "
|
||||
"%s for %s"),
|
||||
- ktypestr, fromstring, (unsigned int)authtime,
|
||||
- rep_etypestr, cname2, sname2);
|
||||
+ ktypestr ? ktypestr : "", fromstring,
|
||||
+ (unsigned int)authtime,
|
||||
+ rep_etypestr ? rep_etypestr : "", cname2, sname2);
|
||||
+ free(rep_etypestr);
|
||||
} else {
|
||||
/* fail */
|
||||
krb5_klog_syslog(LOG_INFO, _("AS_REQ (%s) %s: %s: %s for %s%s%s"),
|
||||
- ktypestr, fromstring, status,
|
||||
- cname2, sname2, emsg ? ", " : "", emsg ? emsg : "");
|
||||
+ ktypestr ? ktypestr : "", fromstring, status, cname2,
|
||||
+ sname2, emsg ? ", " : "", emsg ? emsg : "");
|
||||
}
|
||||
krb5_db_audit_as_req(context, request,
|
||||
local_addr->address, remote_addr->address,
|
||||
client, server, authtime, errcode);
|
||||
+
|
||||
+ free(ktypestr);
|
||||
}
|
||||
|
||||
/*
|
||||
@@ -122,10 +125,9 @@ log_tgs_req(krb5_context ctx, const krb5_fulladdr *from,
|
||||
unsigned int c_flags,
|
||||
const char *status, krb5_error_code errcode, const char *emsg)
|
||||
{
|
||||
- char ktypestr[128];
|
||||
+ char *ktypestr = NULL, *rep_etypestr = NULL;
|
||||
const char *fromstring = 0;
|
||||
char fromstringbuf[70];
|
||||
- char rep_etypestr[128];
|
||||
char *cname = NULL, *sname = NULL, *altcname = NULL;
|
||||
char *logcname = NULL, *logsname = NULL, *logaltcname = NULL;
|
||||
|
||||
@@ -134,11 +136,6 @@ log_tgs_req(krb5_context ctx, const krb5_fulladdr *from,
|
||||
fromstringbuf, sizeof(fromstringbuf));
|
||||
if (!fromstring)
|
||||
fromstring = "<unknown>";
|
||||
- ktypes2str(ktypestr, sizeof(ktypestr), request->nktypes, request->ktype);
|
||||
- if (!errcode)
|
||||
- rep_etypes2str(rep_etypestr, sizeof(rep_etypestr), reply);
|
||||
- else
|
||||
- rep_etypestr[0] = 0;
|
||||
|
||||
unparse_and_limit(ctx, cprinc, &cname);
|
||||
logcname = (cname != NULL) ? cname : "<unknown client>";
|
||||
@@ -151,10 +148,14 @@ log_tgs_req(krb5_context ctx, const krb5_fulladdr *from,
|
||||
name (useful), and doesn't log ktypestr (probably not
|
||||
important). */
|
||||
if (errcode != KRB5KDC_ERR_SERVER_NOMATCH) {
|
||||
+ ktypestr = ktypes2str(request->ktype, request->nktypes);
|
||||
+ rep_etypestr = rep_etypes2str(reply);
|
||||
krb5_klog_syslog(LOG_INFO, _("TGS_REQ (%s) %s: %s: authtime %u, %s%s "
|
||||
"%s for %s%s%s"),
|
||||
- ktypestr, fromstring, status, (unsigned int)authtime,
|
||||
- rep_etypestr, !errcode ? "," : "", logcname, logsname,
|
||||
+ ktypestr ? ktypestr : "", fromstring, status,
|
||||
+ (unsigned int)authtime,
|
||||
+ rep_etypestr ? rep_etypestr : "",
|
||||
+ !errcode ? "," : "", logcname, logsname,
|
||||
errcode ? ", " : "", errcode ? emsg : "");
|
||||
if (isflagset(c_flags, KRB5_KDB_FLAG_PROTOCOL_TRANSITION))
|
||||
krb5_klog_syslog(LOG_INFO,
|
||||
@@ -171,9 +172,8 @@ log_tgs_req(krb5_context ctx, const krb5_fulladdr *from,
|
||||
fromstring, status, (unsigned int)authtime,
|
||||
logcname, logsname, logaltcname);
|
||||
|
||||
- /* OpenSolaris: audit_krb5kdc_tgs_req(...) or
|
||||
- audit_krb5kdc_tgs_req_2ndtktmm(...) */
|
||||
-
|
||||
+ free(rep_etypestr);
|
||||
+ free(ktypestr);
|
||||
krb5_free_unparsed_name(ctx, cname);
|
||||
krb5_free_unparsed_name(ctx, sname);
|
||||
krb5_free_unparsed_name(ctx, altcname);
|
||||
diff --git a/src/kdc/kdc_util.c b/src/kdc/kdc_util.c
|
||||
index 0155c28c6..f5c581c82 100644
|
||||
--- a/src/kdc/kdc_util.c
|
||||
+++ b/src/kdc/kdc_util.c
|
||||
@@ -1043,84 +1043,87 @@ void limit_string(char *name)
|
||||
return;
|
||||
}
|
||||
|
||||
-/*
|
||||
- * L10_2 = log10(2**x), rounded up; log10(2) ~= 0.301.
|
||||
- */
|
||||
-#define L10_2(x) ((int)(((x * 301) + 999) / 1000))
|
||||
+/* Wrapper of krb5_enctype_to_name() to include the PKINIT types. */
|
||||
+static krb5_error_code
|
||||
+enctype_name(krb5_enctype ktype, char *buf, size_t buflen)
|
||||
+{
|
||||
+ char *name;
|
||||
+
|
||||
+ if (buflen == 0)
|
||||
+ return EINVAL;
|
||||
+ *buf = '\0'; /* ensure these are always valid C-strings */
|
||||
+
|
||||
+ /* rfc4556 recommends that clients wishing to indicate support for these
|
||||
+ * pkinit algorithms include them in the etype field of the AS-REQ. */
|
||||
+ if (ktype == ENCTYPE_DSA_SHA1_CMS)
|
||||
+ name = "id-dsa-with-sha1-CmsOID";
|
||||
+ else if (ktype == ENCTYPE_MD5_RSA_CMS)
|
||||
+ name = "md5WithRSAEncryption-CmsOID";
|
||||
+ else if (ktype == ENCTYPE_SHA1_RSA_CMS)
|
||||
+ name = "sha-1WithRSAEncryption-CmsOID";
|
||||
+ else if (ktype == ENCTYPE_RC2_CBC_ENV)
|
||||
+ name = "rc2-cbc-EnvOID";
|
||||
+ else if (ktype == ENCTYPE_RSA_ENV)
|
||||
+ name = "rsaEncryption-EnvOID";
|
||||
+ else if (ktype == ENCTYPE_RSA_ES_OAEP_ENV)
|
||||
+ name = "id-RSAES-OAEP-EnvOID";
|
||||
+ else if (ktype == ENCTYPE_DES3_CBC_ENV)
|
||||
+ name = "des-ede3-cbc-EnvOID";
|
||||
+ else
|
||||
+ return krb5_enctype_to_name(ktype, FALSE, buf, buflen);
|
||||
|
||||
-/*
|
||||
- * Max length of sprintf("%ld") for an int of type T; includes leading
|
||||
- * minus sign and terminating NUL.
|
||||
- */
|
||||
-#define D_LEN(t) (L10_2(sizeof(t) * CHAR_BIT) + 2)
|
||||
+ if (strlcpy(name, buf, buflen) >= buflen)
|
||||
+ return ENOMEM;
|
||||
+ return 0;
|
||||
+}
|
||||
|
||||
-void
|
||||
-ktypes2str(char *s, size_t len, int nktypes, krb5_enctype *ktype)
|
||||
+char *
|
||||
+ktypes2str(krb5_enctype *ktype, int nktypes)
|
||||
{
|
||||
+ struct k5buf buf;
|
||||
int i;
|
||||
- char stmp[D_LEN(krb5_enctype) + 1];
|
||||
- char *p;
|
||||
+ char name[64];
|
||||
|
||||
- if (nktypes < 0
|
||||
- || len < (sizeof(" etypes {...}") + D_LEN(int))) {
|
||||
- *s = '\0';
|
||||
- return;
|
||||
- }
|
||||
+ if (nktypes < 0)
|
||||
+ return NULL;
|
||||
|
||||
- snprintf(s, len, "%d etypes {", nktypes);
|
||||
+ k5_buf_init_dynamic(&buf);
|
||||
+ k5_buf_add_fmt(&buf, "%d etypes {", nktypes);
|
||||
for (i = 0; i < nktypes; i++) {
|
||||
- snprintf(stmp, sizeof(stmp), "%s%ld", i ? " " : "", (long)ktype[i]);
|
||||
- if (strlen(s) + strlen(stmp) + sizeof("}") > len)
|
||||
- break;
|
||||
- strlcat(s, stmp, len);
|
||||
+ enctype_name(ktype[i], name, sizeof(name));
|
||||
+ k5_buf_add_fmt(&buf, "%s%s(%ld)", i ? ", " : "", name, (long)ktype[i]);
|
||||
}
|
||||
- if (i < nktypes) {
|
||||
- /*
|
||||
- * We broke out of the loop. Try to truncate the list.
|
||||
- */
|
||||
- p = s + strlen(s);
|
||||
- while (p - s + sizeof("...}") > len) {
|
||||
- while (p > s && *p != ' ' && *p != '{')
|
||||
- *p-- = '\0';
|
||||
- if (p > s && *p == ' ') {
|
||||
- *p-- = '\0';
|
||||
- continue;
|
||||
- }
|
||||
- }
|
||||
- strlcat(s, "...", len);
|
||||
- }
|
||||
- strlcat(s, "}", len);
|
||||
- return;
|
||||
+ k5_buf_add(&buf, "}");
|
||||
+ return buf.data;
|
||||
}
|
||||
|
||||
-void
|
||||
-rep_etypes2str(char *s, size_t len, krb5_kdc_rep *rep)
|
||||
+char *
|
||||
+rep_etypes2str(krb5_kdc_rep *rep)
|
||||
{
|
||||
- char stmp[sizeof("ses=") + D_LEN(krb5_enctype)];
|
||||
-
|
||||
- if (len < (3 * D_LEN(krb5_enctype)
|
||||
- + sizeof("etypes {rep= tkt= ses=}"))) {
|
||||
- *s = '\0';
|
||||
- return;
|
||||
- }
|
||||
+ struct k5buf buf;
|
||||
+ char name[64];
|
||||
+ krb5_enctype etype;
|
||||
|
||||
- snprintf(s, len, "etypes {rep=%ld", (long)rep->enc_part.enctype);
|
||||
+ k5_buf_init_dynamic(&buf);
|
||||
+ k5_buf_add(&buf, "etypes {rep=");
|
||||
+ enctype_name(rep->enc_part.enctype, name, sizeof(name));
|
||||
+ k5_buf_add_fmt(&buf, "%s(%ld)", name, (long)rep->enc_part.enctype);
|
||||
|
||||
if (rep->ticket != NULL) {
|
||||
- snprintf(stmp, sizeof(stmp),
|
||||
- " tkt=%ld", (long)rep->ticket->enc_part.enctype);
|
||||
- strlcat(s, stmp, len);
|
||||
+ etype = rep->ticket->enc_part.enctype;
|
||||
+ enctype_name(etype, name, sizeof(name));
|
||||
+ k5_buf_add_fmt(&buf, ", tkt=%s(%ld)", name, (long)etype);
|
||||
}
|
||||
|
||||
- if (rep->ticket != NULL
|
||||
- && rep->ticket->enc_part2 != NULL
|
||||
- && rep->ticket->enc_part2->session != NULL) {
|
||||
- snprintf(stmp, sizeof(stmp), " ses=%ld",
|
||||
- (long)rep->ticket->enc_part2->session->enctype);
|
||||
- strlcat(s, stmp, len);
|
||||
+ if (rep->ticket != NULL && rep->ticket->enc_part2 != NULL &&
|
||||
+ rep->ticket->enc_part2->session != NULL) {
|
||||
+ etype = rep->ticket->enc_part2->session->enctype;
|
||||
+ enctype_name(etype, name, sizeof(name));
|
||||
+ k5_buf_add_fmt(&buf, ", ses=%s(%ld)", name, (long)etype);
|
||||
}
|
||||
- strlcat(s, "}", len);
|
||||
- return;
|
||||
+
|
||||
+ k5_buf_add(&buf, "}");
|
||||
+ return buf.data;
|
||||
}
|
||||
|
||||
static krb5_error_code
|
||||
diff --git a/src/kdc/kdc_util.h b/src/kdc/kdc_util.h
|
||||
index 6ec645fc3..25077cbf5 100644
|
||||
--- a/src/kdc/kdc_util.h
|
||||
+++ b/src/kdc/kdc_util.h
|
||||
@@ -110,11 +110,9 @@ select_session_keytype (kdc_realm_t *kdc_active_realm,
|
||||
|
||||
void limit_string (char *name);
|
||||
|
||||
-void
|
||||
-ktypes2str(char *s, size_t len, int nktypes, krb5_enctype *ktype);
|
||||
+char *ktypes2str(krb5_enctype *ktype, int nktypes);
|
||||
|
||||
-void
|
||||
-rep_etypes2str(char *s, size_t len, krb5_kdc_rep *rep);
|
||||
+char *rep_etypes2str(krb5_kdc_rep *rep);
|
||||
|
||||
/* authind.c */
|
||||
krb5_boolean
|
||||
|
|
@ -1,250 +0,0 @@
|
|||
From 945c21ddafbedfe57dfbf9ca3e7b0185cb4b7175 Mon Sep 17 00:00:00 2001
|
||||
From: Robbie Harwood <rharwood@redhat.com>
|
||||
Date: Thu, 10 Jan 2019 16:34:54 -0500
|
||||
Subject: [PATCH] Mark deprecated enctypes when used
|
||||
|
||||
Preface ETYPE_DEPRECATED enctypes with "DEPRECATED:" in klist output,
|
||||
KDC logs, and kadmin interactions. Also complain in krb5kdc when the
|
||||
stash file has a deprecated enctype or a deprecated enctype is
|
||||
requested with -k.
|
||||
|
||||
ticket: 8773 (new)
|
||||
(cherry picked from commit 8d8e68283b599e680f9fe45eff8af397e827bd6c)
|
||||
---
|
||||
src/clients/klist/klist.c | 14 ++++++++++----
|
||||
src/kadmin/cli/kadmin.c | 6 +++++-
|
||||
src/kdc/kdc_util.c | 9 +++++++++
|
||||
src/kdc/main.c | 19 +++++++++++++++++++
|
||||
src/tests/gssapi/t_enctypes.py | 15 +++++++++------
|
||||
src/tests/t_keyrollover.py | 8 +++++---
|
||||
src/tests/t_sesskeynego.py | 4 ++--
|
||||
7 files changed, 59 insertions(+), 16 deletions(-)
|
||||
|
||||
diff --git a/src/clients/klist/klist.c b/src/clients/klist/klist.c
|
||||
index 70adb54e8..8c307151a 100644
|
||||
--- a/src/clients/klist/klist.c
|
||||
+++ b/src/clients/klist/klist.c
|
||||
@@ -571,11 +571,17 @@ static char *
|
||||
etype_string(krb5_enctype enctype)
|
||||
{
|
||||
static char buf[100];
|
||||
- krb5_error_code ret;
|
||||
+ char *bp = buf;
|
||||
+ size_t deplen, buflen = sizeof(buf);
|
||||
|
||||
- ret = krb5_enctype_to_name(enctype, FALSE, buf, sizeof(buf));
|
||||
- if (ret)
|
||||
- snprintf(buf, sizeof(buf), "etype %d", enctype);
|
||||
+ if (krb5int_c_deprecated_enctype(enctype)) {
|
||||
+ deplen = strlcpy(bp, "DEPRECATED:", buflen);
|
||||
+ buflen -= deplen;
|
||||
+ bp += deplen;
|
||||
+ }
|
||||
+
|
||||
+ if (krb5_enctype_to_name(enctype, FALSE, bp, buflen))
|
||||
+ snprintf(bp, buflen, "etype %d", enctype);
|
||||
return buf;
|
||||
}
|
||||
|
||||
diff --git a/src/kadmin/cli/kadmin.c b/src/kadmin/cli/kadmin.c
|
||||
index ed581ee79..cc74921bf 100644
|
||||
--- a/src/kadmin/cli/kadmin.c
|
||||
+++ b/src/kadmin/cli/kadmin.c
|
||||
@@ -1451,12 +1451,16 @@ kadmin_getprinc(int argc, char *argv[])
|
||||
for (i = 0; i < dprinc.n_key_data; i++) {
|
||||
krb5_key_data *key_data = &dprinc.key_data[i];
|
||||
char enctype[BUFSIZ], salttype[BUFSIZ];
|
||||
+ char *deprecated = "";
|
||||
|
||||
if (krb5_enctype_to_name(key_data->key_data_type[0], FALSE,
|
||||
enctype, sizeof(enctype)))
|
||||
snprintf(enctype, sizeof(enctype), _("<Encryption type 0x%x>"),
|
||||
key_data->key_data_type[0]);
|
||||
- printf("Key: vno %d, %s", key_data->key_data_kvno, enctype);
|
||||
+ if (krb5int_c_deprecated_enctype(key_data->key_data_type[0]))
|
||||
+ deprecated = "DEPRECATED:";
|
||||
+ printf("Key: vno %d, %s%s", key_data->key_data_kvno, deprecated,
|
||||
+ enctype);
|
||||
if (key_data->key_data_ver > 1 &&
|
||||
key_data->key_data_type[1] != KRB5_KDB_SALTTYPE_NORMAL) {
|
||||
if (krb5_salttype_to_string(key_data->key_data_type[1],
|
||||
diff --git a/src/kdc/kdc_util.c b/src/kdc/kdc_util.c
|
||||
index f5c581c82..96c88edc1 100644
|
||||
--- a/src/kdc/kdc_util.c
|
||||
+++ b/src/kdc/kdc_util.c
|
||||
@@ -1048,11 +1048,20 @@ static krb5_error_code
|
||||
enctype_name(krb5_enctype ktype, char *buf, size_t buflen)
|
||||
{
|
||||
char *name;
|
||||
+ size_t len;
|
||||
|
||||
if (buflen == 0)
|
||||
return EINVAL;
|
||||
*buf = '\0'; /* ensure these are always valid C-strings */
|
||||
|
||||
+ if (krb5int_c_deprecated_enctype(ktype)) {
|
||||
+ len = strlcpy(buf, "DEPRECATED:", buflen);
|
||||
+ if (len >= buflen)
|
||||
+ return ENOMEM;
|
||||
+ buflen -= len;
|
||||
+ buf += len;
|
||||
+ }
|
||||
+
|
||||
/* rfc4556 recommends that clients wishing to indicate support for these
|
||||
* pkinit algorithms include them in the etype field of the AS-REQ. */
|
||||
if (ktype == ENCTYPE_DSA_SHA1_CMS)
|
||||
diff --git a/src/kdc/main.c b/src/kdc/main.c
|
||||
index 663fd6303..60092a0df 100644
|
||||
--- a/src/kdc/main.c
|
||||
+++ b/src/kdc/main.c
|
||||
@@ -210,12 +210,23 @@ init_realm(kdc_realm_t * rdp, krb5_pointer aprof, char *realm,
|
||||
char *svalue = NULL;
|
||||
const char *hierarchy[4];
|
||||
krb5_kvno mkvno = IGNORE_VNO;
|
||||
+ char ename[32];
|
||||
|
||||
memset(rdp, 0, sizeof(kdc_realm_t));
|
||||
if (!realm) {
|
||||
kret = EINVAL;
|
||||
goto whoops;
|
||||
}
|
||||
+
|
||||
+ if (def_enctype != ENCTYPE_UNKNOWN &&
|
||||
+ krb5int_c_deprecated_enctype(def_enctype)) {
|
||||
+ if (krb5_enctype_to_name(def_enctype, FALSE, ename, sizeof(ename)))
|
||||
+ ename[0] = '\0';
|
||||
+ fprintf(stderr,
|
||||
+ _("Requested master password enctype %s in %s is DEPRECATED!"),
|
||||
+ ename, realm);
|
||||
+ }
|
||||
+
|
||||
hierarchy[0] = KRB5_CONF_REALMS;
|
||||
hierarchy[1] = realm;
|
||||
hierarchy[3] = NULL;
|
||||
@@ -370,6 +381,14 @@ init_realm(kdc_realm_t * rdp, krb5_pointer aprof, char *realm,
|
||||
goto whoops;
|
||||
}
|
||||
|
||||
+ if (krb5int_c_deprecated_enctype(rdp->realm_mkey.enctype)) {
|
||||
+ if (krb5_enctype_to_name(rdp->realm_mkey.enctype, FALSE, ename,
|
||||
+ sizeof(ename)))
|
||||
+ ename[0] = '\0';
|
||||
+ fprintf(stderr, _("Stash file %s uses DEPRECATED enctype %s!"),
|
||||
+ rdp->realm_stash, ename);
|
||||
+ }
|
||||
+
|
||||
if ((kret = krb5_db_fetch_mkey_list(rdp->realm_context, rdp->realm_mprinc,
|
||||
&rdp->realm_mkey))) {
|
||||
kdc_err(rdp->realm_context, kret,
|
||||
diff --git a/src/tests/gssapi/t_enctypes.py b/src/tests/gssapi/t_enctypes.py
|
||||
index 5d9f80e04..ca3d32d21 100755
|
||||
--- a/src/tests/gssapi/t_enctypes.py
|
||||
+++ b/src/tests/gssapi/t_enctypes.py
|
||||
@@ -9,8 +9,11 @@ from k5test import *
|
||||
aes256 = 'aes256-cts-hmac-sha1-96'
|
||||
aes128 = 'aes128-cts-hmac-sha1-96'
|
||||
des3 = 'des3-cbc-sha1'
|
||||
+d_des3 = 'DEPRECATED:des3-cbc-sha1'
|
||||
des3raw = 'des3-cbc-raw'
|
||||
+d_des3raw = 'DEPRECATED:des3-cbc-raw'
|
||||
rc4 = 'arcfour-hmac'
|
||||
+d_rc4 = 'DEPRECATED:arcfour-hmac'
|
||||
|
||||
# These tests make assumptions about the default enctype lists, so set
|
||||
# them explicitly rather than relying on the library defaults.
|
||||
@@ -92,7 +95,7 @@ test_err('acc aes128', None, 'aes128-cts',
|
||||
# no acceptor subkey will be generated because we can't upgrade to a
|
||||
# CFX enctype.
|
||||
test('init des3', 'des3', None,
|
||||
- tktenc=aes256, tktsession=des3,
|
||||
+ tktenc=aes256, tktsession=d_des3,
|
||||
proto='rfc1964', isubkey=des3raw, asubkey=None)
|
||||
|
||||
# Force the ticket session key to be rc4, so we can test some subkey
|
||||
@@ -103,7 +106,7 @@ realm.run([kadminl, 'setstr', realm.host_princ, 'session_enctypes', 'rc4'])
|
||||
# [aes256 aes128 des3] and the acceptor should upgrade to an aes256
|
||||
# subkey.
|
||||
test('upgrade noargs', None, None,
|
||||
- tktenc=aes256, tktsession=rc4,
|
||||
+ tktenc=aes256, tktsession=d_rc4,
|
||||
proto='cfx', isubkey=rc4, asubkey=aes256)
|
||||
|
||||
# If the initiator won't permit rc4 as a session key, it won't be able
|
||||
@@ -113,14 +116,14 @@ test_err('upgrade init aes', 'aes', None, 'no support for encryption type')
|
||||
# If the initiator permits rc4 but prefers aes128, it will send an
|
||||
# upgrade list of [aes128] and the acceptor will upgrade to aes128.
|
||||
test('upgrade init aes128+rc4', 'aes128-cts rc4', None,
|
||||
- tktenc=aes256, tktsession=rc4,
|
||||
+ tktenc=aes256, tktsession=d_rc4,
|
||||
proto='cfx', isubkey=rc4, asubkey=aes128)
|
||||
|
||||
# If the initiator permits rc4 but prefers des3, it will send an
|
||||
# upgrade list of [des3], but the acceptor won't generate a subkey
|
||||
# because des3 isn't a CFX enctype.
|
||||
test('upgrade init des3+rc4', 'des3 rc4', None,
|
||||
- tktenc=aes256, tktsession=rc4,
|
||||
+ tktenc=aes256, tktsession=d_rc4,
|
||||
proto='rfc1964', isubkey=rc4, asubkey=None)
|
||||
|
||||
# If the acceptor permits only aes128, subkey negotiation will fail
|
||||
@@ -134,14 +137,14 @@ test_err('upgrade acc aes128', None, 'aes128-cts',
|
||||
# If the acceptor permits rc4 but prefers aes128, it will negotiate an
|
||||
# upgrade to aes128.
|
||||
test('upgrade acc aes128 rc4', None, 'aes128-cts rc4',
|
||||
- tktenc=aes256, tktsession=rc4,
|
||||
+ tktenc=aes256, tktsession=d_rc4,
|
||||
proto='cfx', isubkey=rc4, asubkey=aes128)
|
||||
|
||||
# In this test, the initiator and acceptor each prefer an AES enctype
|
||||
# to rc4, but they can't agree on which one, so no subkey is
|
||||
# generated.
|
||||
test('upgrade mismatch', 'aes128-cts rc4', 'aes256-cts rc4',
|
||||
- tktenc=aes256, tktsession=rc4,
|
||||
+ tktenc=aes256, tktsession=d_rc4,
|
||||
proto='rfc1964', isubkey=rc4, asubkey=None)
|
||||
|
||||
success('gss_krb5_set_allowable_enctypes tests')
|
||||
diff --git a/src/tests/t_keyrollover.py b/src/tests/t_keyrollover.py
|
||||
index 7c8d828f0..4af6804f2 100755
|
||||
--- a/src/tests/t_keyrollover.py
|
||||
+++ b/src/tests/t_keyrollover.py
|
||||
@@ -22,8 +22,9 @@ realm.run([kvno, princ1])
|
||||
realm.run([kadminl, 'purgekeys', realm.krbtgt_princ])
|
||||
# Make sure an old TGT fails after purging old TGS key.
|
||||
realm.run([kvno, princ2], expected_code=1)
|
||||
-msg = 'krbtgt/%s@%s\n\tEtype (skey, tkt): des-cbc-crc, des-cbc-crc' % \
|
||||
- (realm.realm, realm.realm)
|
||||
+ddes = "DEPRECATED:des-cbc-crc"
|
||||
+msg = 'krbtgt/%s@%s\n\tEtype (skey, tkt): %s, %s' % \
|
||||
+ (realm.realm, realm.realm, ddes, ddes)
|
||||
realm.run([klist, '-e'], expected_msg=msg)
|
||||
|
||||
# Check that new key actually works.
|
||||
@@ -48,7 +49,8 @@ realm.run([kadminl, 'cpw', '-randkey', '-keepold', '-e', 'aes256-cts',
|
||||
realm.krbtgt_princ])
|
||||
realm.run([kadminl, 'modprinc', '-kvno', '1', realm.krbtgt_princ])
|
||||
out = realm.run([kadminl, 'getprinc', realm.krbtgt_princ])
|
||||
-if 'vno 1, aes256' not in out or 'vno 1, des3' not in out:
|
||||
+if 'vno 1, aes256-cts' not in out or \
|
||||
+ 'vno 1, DEPRECATED:des3-cbc-sha1' not in out:
|
||||
fail('keyrollover: setup for TGS enctype test failed')
|
||||
# Now present the DES3 ticket to the KDC and make sure it's rejected.
|
||||
realm.run([kvno, realm.host_princ], expected_code=1)
|
||||
diff --git a/src/tests/t_sesskeynego.py b/src/tests/t_sesskeynego.py
|
||||
index 448092387..da02f224a 100755
|
||||
--- a/src/tests/t_sesskeynego.py
|
||||
+++ b/src/tests/t_sesskeynego.py
|
||||
@@ -62,11 +62,11 @@ test_kvno(realm, 'aes128-cts-hmac-sha1-96', 'aes256-cts-hmac-sha1-96')
|
||||
# 3b: Negotiate rc4-hmac session key when principal only has aes256 long-term.
|
||||
realm.run([kadminl, 'setstr', 'server', 'session_enctypes',
|
||||
'rc4-hmac,aes128-cts,aes256-cts'])
|
||||
-test_kvno(realm, 'arcfour-hmac', 'aes256-cts-hmac-sha1-96')
|
||||
+test_kvno(realm, 'DEPRECATED:arcfour-hmac', 'aes256-cts-hmac-sha1-96')
|
||||
|
||||
# 3c: Test des-cbc-crc default assumption.
|
||||
realm.run([kadminl, 'delstr', 'server', 'session_enctypes'])
|
||||
-test_kvno(realm, 'des-cbc-crc', 'aes256-cts-hmac-sha1-96')
|
||||
+test_kvno(realm, 'DEPRECATED:des-cbc-crc', 'aes256-cts-hmac-sha1-96')
|
||||
realm.stop()
|
||||
|
||||
# Last go: test that we can disable the des-cbc-crc assumption
|
||||
|
|
@ -1,139 +0,0 @@
|
|||
From b68ee166602b787c5acabe3d1b4780e527d672a7 Mon Sep 17 00:00:00 2001
|
||||
From: Robbie Harwood <rharwood@redhat.com>
|
||||
Date: Thu, 11 Apr 2019 18:33:04 -0400
|
||||
Subject: [PATCH] Mark the doc/kadm5 tex files as historic
|
||||
|
||||
Remove rcsid.sty and the uses of the \rcsId macro as git does not
|
||||
perform the keyword expansion necessary to make it work. Add comments
|
||||
indicating the historic status of the kadm5 documentation.
|
||||
|
||||
[ghudson@mit.edu: fix the tex files instead of marking them as
|
||||
non-building]
|
||||
|
||||
(cherry picked from commit e6047bdd6dec0d104417f9a1318bbafe022b81c1)
|
||||
---
|
||||
doc/kadm5/adb-unit-test.tex | 7 ++++---
|
||||
doc/kadm5/api-funcspec.tex | 9 +++++----
|
||||
doc/kadm5/api-server-design.tex | 9 +++++----
|
||||
doc/kadm5/api-unit-test.tex | 7 ++++---
|
||||
doc/kadm5/rcsid.sty | 5 -----
|
||||
5 files changed, 18 insertions(+), 19 deletions(-)
|
||||
delete mode 100644 doc/kadm5/rcsid.sty
|
||||
|
||||
diff --git a/doc/kadm5/adb-unit-test.tex b/doc/kadm5/adb-unit-test.tex
|
||||
index d401342df..987af1a5e 100644
|
||||
--- a/doc/kadm5/adb-unit-test.tex
|
||||
+++ b/doc/kadm5/adb-unit-test.tex
|
||||
@@ -1,6 +1,7 @@
|
||||
-\documentstyle[times,fullpage,rcsid]{article}
|
||||
+% This document is included for historical purposes only, and does not
|
||||
+% apply to krb5 today.
|
||||
|
||||
-\rcs$Id$
|
||||
+\documentstyle[times,fullpage]{article}
|
||||
|
||||
%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%
|
||||
%% Make _ actually generate an _, and allow line-breaking after it.
|
||||
@@ -39,7 +40,7 @@
|
||||
%\newcommand{\Priority}[1]{}
|
||||
|
||||
\title{OpenV*Secure Admin Database API\\
|
||||
-Unit Test Description\footnote{\rcsId}}
|
||||
+Unit Test Description}
|
||||
\author{Jonathan I. Kamens}
|
||||
|
||||
\begin{document}
|
||||
diff --git a/doc/kadm5/api-funcspec.tex b/doc/kadm5/api-funcspec.tex
|
||||
index c13090a51..76d2bb5d0 100644
|
||||
--- a/doc/kadm5/api-funcspec.tex
|
||||
+++ b/doc/kadm5/api-funcspec.tex
|
||||
@@ -1,4 +1,7 @@
|
||||
-\documentstyle[12pt,fullpage,rcsid]{article}
|
||||
+% This document is included for historical purposes only, and does not
|
||||
+% apply to krb5 today.
|
||||
+
|
||||
+\documentstyle[12pt,fullpage]{article}
|
||||
|
||||
%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%
|
||||
%% Make _ actually generate an _, and allow line-breaking after it.
|
||||
@@ -7,15 +10,13 @@
|
||||
\def_{\underscore\penalty75\relax}
|
||||
%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%
|
||||
|
||||
-\rcs$Id$
|
||||
-
|
||||
\setlength{\parskip}{.7\baselineskip}
|
||||
\setlength{\parindent}{0pt}
|
||||
|
||||
\def\v#1{\verb+#1+}
|
||||
|
||||
\title{Kerberos Administration System \\
|
||||
- KADM5 API Functional Specifications\thanks{\rcsId}}
|
||||
+ KADM5 API Functional Specifications}
|
||||
\author{Barry Jaspan}
|
||||
|
||||
\begin{document}
|
||||
diff --git a/doc/kadm5/api-server-design.tex b/doc/kadm5/api-server-design.tex
|
||||
index 228e83113..94e05b877 100644
|
||||
--- a/doc/kadm5/api-server-design.tex
|
||||
+++ b/doc/kadm5/api-server-design.tex
|
||||
@@ -1,4 +1,7 @@
|
||||
-\documentstyle[12pt,fullpage,rcsid]{article}
|
||||
+% This document is included for historical purposes only, and does not
|
||||
+% apply to krb5 today.
|
||||
+
|
||||
+\documentstyle[12pt,fullpage]{article}
|
||||
|
||||
%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%
|
||||
%% Make _ actually generate an _, and allow line-breaking after it.
|
||||
@@ -7,15 +10,13 @@
|
||||
\def_{\underscore\penalty75\relax}
|
||||
%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%
|
||||
|
||||
-\rcs$Id$
|
||||
-
|
||||
\setlength{\parskip}{.7\baselineskip}
|
||||
\setlength{\parindent}{0pt}
|
||||
|
||||
\def\v#1{\verb+#1+}
|
||||
\def\k#1{K$_#1$}
|
||||
|
||||
-\title{KADM5 Library and Server \\ Implementation Design\thanks{\rcsId}}
|
||||
+\title{KADM5 Library and Server \\ Implementation Design}
|
||||
\author{Barry Jaspan}
|
||||
|
||||
\begin{document}
|
||||
diff --git a/doc/kadm5/api-unit-test.tex b/doc/kadm5/api-unit-test.tex
|
||||
index 3e0eb503e..bfd6280bb 100644
|
||||
--- a/doc/kadm5/api-unit-test.tex
|
||||
+++ b/doc/kadm5/api-unit-test.tex
|
||||
@@ -1,6 +1,7 @@
|
||||
-\documentstyle[times,fullpage,rcsid]{article}
|
||||
+% This document is included for historical purposes only, and does not
|
||||
+% apply to krb5 today.
|
||||
|
||||
-\rcs$Id$
|
||||
+\documentstyle[times,fullpage]{article}
|
||||
|
||||
%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%
|
||||
%% Make _ actually generate an _, and allow line-breaking after it.
|
||||
@@ -41,7 +42,7 @@
|
||||
%\newcommand{\Priority}[1]{}
|
||||
|
||||
\title{KADM5 Admin API\\
|
||||
-Unit Test Description\footnote{\rcsId}}
|
||||
+Unit Test Description}
|
||||
\author{Jonathan I. Kamens}
|
||||
|
||||
\begin{document}
|
||||
diff --git a/doc/kadm5/rcsid.sty b/doc/kadm5/rcsid.sty
|
||||
deleted file mode 100644
|
||||
index 3ad7826ff..000000000
|
||||
--- a/doc/kadm5/rcsid.sty
|
||||
+++ /dev/null
|
||||
@@ -1,5 +0,0 @@
|
||||
-\def\rcs$#1: #2${\expandafter\def\csname rcs#1\endcsname{#2}}
|
||||
-
|
||||
-% example usage:
|
||||
-% \rcs$Version$
|
||||
-% Version \rcsVersion
|
||||
|
|
@ -1,231 +0,0 @@
|
|||
From eb4fb8cb24e6cac194acc2c507b334658fc5431d Mon Sep 17 00:00:00 2001
|
||||
From: Robbie Harwood <rharwood@redhat.com>
|
||||
Date: Thu, 11 Apr 2019 18:25:41 -0400
|
||||
Subject: [PATCH] Modernize example enctypes in documentation
|
||||
|
||||
ticket: 8805 (new)
|
||||
(cherry picked from commit ccb4a3e4b35fa9ea63af0e98a42eba4aadb099e2)
|
||||
---
|
||||
doc/admin/admin_commands/kadmin_local.rst | 8 ++++----
|
||||
doc/admin/admin_commands/kdb5_util.rst | 10 +++++-----
|
||||
doc/admin/database.rst | 2 +-
|
||||
doc/admin/install_appl_srv.rst | 19 +++++++------------
|
||||
doc/admin/install_kdc.rst | 2 +-
|
||||
src/man/kadmin.man | 10 +++++-----
|
||||
src/man/kdb5_util.man | 10 +++++-----
|
||||
.../kdb/ldap/libkdb_ldap/kerberos.ldif | 4 ++--
|
||||
.../kdb/ldap/libkdb_ldap/kerberos.schema | 4 ++--
|
||||
9 files changed, 32 insertions(+), 37 deletions(-)
|
||||
|
||||
diff --git a/doc/admin/admin_commands/kadmin_local.rst b/doc/admin/admin_commands/kadmin_local.rst
|
||||
index 150da1fad..71aa894f6 100644
|
||||
--- a/doc/admin/admin_commands/kadmin_local.rst
|
||||
+++ b/doc/admin/admin_commands/kadmin_local.rst
|
||||
@@ -569,16 +569,16 @@ Examples::
|
||||
Principal: tlyu/admin@BLEEP.COM
|
||||
Expiration date: [never]
|
||||
Last password change: Mon Aug 12 14:16:47 EDT 1996
|
||||
- Password expiration date: [none]
|
||||
+ Password expiration date: [never]
|
||||
Maximum ticket life: 0 days 10:00:00
|
||||
Maximum renewable life: 7 days 00:00:00
|
||||
Last modified: Mon Aug 12 14:16:47 EDT 1996 (bjaspan/admin@BLEEP.COM)
|
||||
Last successful authentication: [never]
|
||||
Last failed authentication: [never]
|
||||
Failed password attempts: 0
|
||||
- Number of keys: 2
|
||||
- Key: vno 1, des-cbc-crc
|
||||
- Key: vno 1, des-cbc-crc:v4
|
||||
+ Number of keys: 1
|
||||
+ Key: vno 1, aes256-cts-hmac-sha384-192
|
||||
+ MKey: vno 1
|
||||
Attributes:
|
||||
Policy: [none]
|
||||
|
||||
diff --git a/doc/admin/admin_commands/kdb5_util.rst b/doc/admin/admin_commands/kdb5_util.rst
|
||||
index 7dd54f797..444c58bcd 100644
|
||||
--- a/doc/admin/admin_commands/kdb5_util.rst
|
||||
+++ b/doc/admin/admin_commands/kdb5_util.rst
|
||||
@@ -476,17 +476,17 @@ Examples::
|
||||
$ kdb5_util tabdump -o keyinfo.txt keyinfo
|
||||
$ cat keyinfo.txt
|
||||
name keyindex kvno enctype salttype salt
|
||||
+ K/M@EXAMPLE.COM 0 1 aes256-cts-hmac-sha384-192 normal -1
|
||||
foo@EXAMPLE.COM 0 1 aes128-cts-hmac-sha1-96 normal -1
|
||||
bar@EXAMPLE.COM 0 1 aes128-cts-hmac-sha1-96 normal -1
|
||||
- bar@EXAMPLE.COM 1 1 des-cbc-crc normal -1
|
||||
$ sqlite3
|
||||
sqlite> .mode tabs
|
||||
sqlite> .import keyinfo.txt keyinfo
|
||||
- sqlite> select * from keyinfo where enctype like 'des-cbc-%';
|
||||
- bar@EXAMPLE.COM 1 1 des-cbc-crc normal -1
|
||||
+ sqlite> select * from keyinfo where enctype like 'aes256-%';
|
||||
+ K/M@EXAMPLE.COM 1 1 aes256-cts-hmac-sha384-192 normal -1
|
||||
sqlite> .quit
|
||||
- $ awk -F'\t' '$4 ~ /des-cbc-/ { print }' keyinfo.txt
|
||||
- bar@EXAMPLE.COM 1 1 des-cbc-crc normal -1
|
||||
+ $ awk -F'\t' '$4 ~ /aes256-/ { print }' keyinfo.txt
|
||||
+ K/M@EXAMPLE.COM 1 1 aes256-cts-hmac-sha384-192 normal -1
|
||||
|
||||
|
||||
ENVIRONMENT
|
||||
diff --git a/doc/admin/database.rst b/doc/admin/database.rst
|
||||
index 113a680a6..0eb5ccde7 100644
|
||||
--- a/doc/admin/database.rst
|
||||
+++ b/doc/admin/database.rst
|
||||
@@ -483,7 +483,7 @@ availability. To roll over the master key, follow these steps:
|
||||
|
||||
$ kdb5_util list_mkeys
|
||||
Master keys for Principal: K/M@KRBTEST.COM
|
||||
- KVNO: 1, Enctype: des-cbc-crc, Active on: Wed Dec 31 19:00:00 EST 1969 *
|
||||
+ KVNO: 1, Enctype: aes256-cts-hmac-sha384-192, Active on: Thu Jan 01 00:00:00 UTC 1970 *
|
||||
|
||||
#. On the master KDC, run ``kdb5_util use_mkey 1`` to ensure that a
|
||||
master key activation list is present in the database. This step
|
||||
diff --git a/doc/admin/install_appl_srv.rst b/doc/admin/install_appl_srv.rst
|
||||
index 6bae7248f..6b2d8e471 100644
|
||||
--- a/doc/admin/install_appl_srv.rst
|
||||
+++ b/doc/admin/install_appl_srv.rst
|
||||
@@ -44,18 +44,13 @@ pop, the administrator ``joeadmin`` would issue the command (on
|
||||
``trillium.mit.edu``)::
|
||||
|
||||
trillium% kadmin
|
||||
- kadmin5: ktadd host/trillium.mit.edu ftp/trillium.mit.edu
|
||||
- pop/trillium.mit.edu
|
||||
- kadmin: Entry for principal host/trillium.mit.edu@ATHENA.MIT.EDU with
|
||||
- kvno 3, encryption type DES-CBC-CRC added to keytab
|
||||
- FILE:/etc/krb5.keytab.
|
||||
- kadmin: Entry for principal ftp/trillium.mit.edu@ATHENA.MIT.EDU with
|
||||
- kvno 3, encryption type DES-CBC-CRC added to keytab
|
||||
- FILE:/etc/krb5.keytab.
|
||||
- kadmin: Entry for principal pop/trillium.mit.edu@ATHENA.MIT.EDU with
|
||||
- kvno 3, encryption type DES-CBC-CRC added to keytab
|
||||
- FILE:/etc/krb5.keytab.
|
||||
- kadmin5: quit
|
||||
+ Authenticating as principal root/admin@ATHENA.MIT.EDU with password.
|
||||
+ Password for root/admin@ATHENA.MIT.EDU:
|
||||
+ kadmin: ktadd host/trillium.mit.edu ftp/trillium.mit.edu pop/trillium.mit.edu
|
||||
+ Entry for principal host/trillium.mit.edu@ATHENA.MIT.EDU with kvno 3, encryption type aes256-cts-hmac-sha384-192 added to keytab FILE:/etc/krb5.keytab.
|
||||
+ kadmin: Entry for principal ftp/trillium.mit.edu@ATHENA.MIT.EDU with kvno 3, encryption type aes256-cts-hmac-sha384-192 added to keytab FILE:/etc/krb5.keytab.
|
||||
+ kadmin: Entry for principal pop/trillium.mit.edu@ATHENA.MIT.EDU with kvno 3, encryption type aes256-cts-hmac-sha384-192 added to keytab FILE:/etc/krb5.keytab.
|
||||
+ kadmin: quit
|
||||
trillium%
|
||||
|
||||
If you generate the keytab file on another host, you need to get a
|
||||
diff --git a/doc/admin/install_kdc.rst b/doc/admin/install_kdc.rst
|
||||
index 5d1e70ede..3bec59f96 100644
|
||||
--- a/doc/admin/install_kdc.rst
|
||||
+++ b/doc/admin/install_kdc.rst
|
||||
@@ -340,7 +340,7 @@ To extract a keytab directly on a replica KDC called
|
||||
Entry for principal host/kerberos-1.mit.edu with kvno 2, encryption
|
||||
type aes128-cts-hmac-sha1-96 added to keytab FILE:/etc/krb5.keytab.
|
||||
Entry for principal host/kerberos-1.mit.edu with kvno 2, encryption
|
||||
- type des3-cbc-sha1 added to keytab FILE:/etc/krb5.keytab.
|
||||
+ type aes256-cts-hmac-sha384-192 added to keytab FILE:/etc/krb5.keytab.
|
||||
Entry for principal host/kerberos-1.mit.edu with kvno 2, encryption
|
||||
type arcfour-hmac added to keytab FILE:/etc/krb5.keytab.
|
||||
|
||||
diff --git a/src/man/kadmin.man b/src/man/kadmin.man
|
||||
index 849677258..44859a378 100644
|
||||
--- a/src/man/kadmin.man
|
||||
+++ b/src/man/kadmin.man
|
||||
@@ -1,6 +1,6 @@
|
||||
.\" Man page generated from reStructuredText.
|
||||
.
|
||||
-.TH "KADMIN" "1" " " "1.17" "MIT Kerberos"
|
||||
+.TH "KADMIN" "1" " " "1.18" "MIT Kerberos"
|
||||
.SH NAME
|
||||
kadmin \- Kerberos V5 database administration program
|
||||
.
|
||||
@@ -610,16 +610,16 @@ kadmin: getprinc tlyu/admin
|
||||
Principal: tlyu/admin@BLEEP.COM
|
||||
Expiration date: [never]
|
||||
Last password change: Mon Aug 12 14:16:47 EDT 1996
|
||||
-Password expiration date: [none]
|
||||
+Password expiration date: [never]
|
||||
Maximum ticket life: 0 days 10:00:00
|
||||
Maximum renewable life: 7 days 00:00:00
|
||||
Last modified: Mon Aug 12 14:16:47 EDT 1996 (bjaspan/admin@BLEEP.COM)
|
||||
Last successful authentication: [never]
|
||||
Last failed authentication: [never]
|
||||
Failed password attempts: 0
|
||||
-Number of keys: 2
|
||||
-Key: vno 1, des\-cbc\-crc
|
||||
-Key: vno 1, des\-cbc\-crc:v4
|
||||
+Number of keys: 1
|
||||
+Key: vno 1, aes256\-cts\-hmac\-sha384\-192
|
||||
+MKey: vno 1
|
||||
Attributes:
|
||||
Policy: [none]
|
||||
|
||||
diff --git a/src/man/kdb5_util.man b/src/man/kdb5_util.man
|
||||
index 9a36ef0df..46772a236 100644
|
||||
--- a/src/man/kdb5_util.man
|
||||
+++ b/src/man/kdb5_util.man
|
||||
@@ -529,17 +529,17 @@ Examples:
|
||||
$ kdb5_util tabdump \-o keyinfo.txt keyinfo
|
||||
$ cat keyinfo.txt
|
||||
name keyindex kvno enctype salttype salt
|
||||
+K/M@EXAMPLE.COM 0 1 aes256\-cts\-hmac\-sha384\-192 normal \-1
|
||||
foo@EXAMPLE.COM 0 1 aes128\-cts\-hmac\-sha1\-96 normal \-1
|
||||
bar@EXAMPLE.COM 0 1 aes128\-cts\-hmac\-sha1\-96 normal \-1
|
||||
-bar@EXAMPLE.COM 1 1 des\-cbc\-crc normal \-1
|
||||
$ sqlite3
|
||||
sqlite> .mode tabs
|
||||
sqlite> .import keyinfo.txt keyinfo
|
||||
-sqlite> select * from keyinfo where enctype like \(aqdes\-cbc\-%\(aq;
|
||||
-bar@EXAMPLE.COM 1 1 des\-cbc\-crc normal \-1
|
||||
+sqlite> select * from keyinfo where enctype like \(aqaes256\-%\(aq;
|
||||
+K/M@EXAMPLE.COM 1 1 aes256\-cts\-hmac\-sha384\-192 normal \-1
|
||||
sqlite> .quit
|
||||
-$ awk \-F\(aq\et\(aq \(aq$4 ~ /des\-cbc\-/ { print }\(aq keyinfo.txt
|
||||
-bar@EXAMPLE.COM 1 1 des\-cbc\-crc normal \-1
|
||||
+$ awk \-F\(aq\et\(aq \(aq$4 ~ /aes256\-/ { print }\(aq keyinfo.txt
|
||||
+K/M@EXAMPLE.COM 1 1 aes256\-cts\-hmac\-sha384\-192 normal \-1
|
||||
.ft P
|
||||
.fi
|
||||
.UNINDENT
|
||||
diff --git a/src/plugins/kdb/ldap/libkdb_ldap/kerberos.ldif b/src/plugins/kdb/ldap/libkdb_ldap/kerberos.ldif
|
||||
index 13db48609..4224f0850 100644
|
||||
--- a/src/plugins/kdb/ldap/libkdb_ldap/kerberos.ldif
|
||||
+++ b/src/plugins/kdb/ldap/libkdb_ldap/kerberos.ldif
|
||||
@@ -512,7 +512,7 @@ attributetypes: ( 2.16.840.1.113719.1.301.4.41.1
|
||||
|
||||
##### Holds the default encryption/salt type combinations of principals for
|
||||
##### the Realm. Stores in the form of key:salt strings.
|
||||
-##### Example: des-cbc-crc:normal
|
||||
+##### Example: aes256-cts-hmac-sha384-192:normal
|
||||
|
||||
dn: cn=schema
|
||||
changetype: modify
|
||||
@@ -533,7 +533,7 @@ attributetypes: ( 2.16.840.1.113719.1.301.4.42.1
|
||||
##### ONLYREALM
|
||||
##### SPECIAL
|
||||
##### AFS3
|
||||
-##### Example: des-cbc-crc:normal
|
||||
+##### Example: aes256-cts-hmac-sha384-192:normal
|
||||
#####
|
||||
##### This attribute obsoletes the krbSupportedEncTypes and krbSupportedSaltTypes
|
||||
##### attributes.
|
||||
diff --git a/src/plugins/kdb/ldap/libkdb_ldap/kerberos.schema b/src/plugins/kdb/ldap/libkdb_ldap/kerberos.schema
|
||||
index 52036a178..171f66927 100644
|
||||
--- a/src/plugins/kdb/ldap/libkdb_ldap/kerberos.schema
|
||||
+++ b/src/plugins/kdb/ldap/libkdb_ldap/kerberos.schema
|
||||
@@ -410,7 +410,7 @@ attributetype ( 2.16.840.1.113719.1.301.4.41.1
|
||||
##### Holds the default encryption/salt type combinations of principals for
|
||||
##### the Realm. Stores in the form of key:salt strings. This will be
|
||||
##### subset of the supported encryption/salt types.
|
||||
-##### Example: des-cbc-crc:normal
|
||||
+##### Example: aes256-cts-hmac-sha384-192:normal
|
||||
|
||||
attributetype ( 2.16.840.1.113719.1.301.4.42.1
|
||||
NAME 'krbDefaultEncSaltTypes'
|
||||
@@ -428,7 +428,7 @@ attributetype ( 2.16.840.1.113719.1.301.4.42.1
|
||||
##### ONLYREALM
|
||||
##### SPECIAL
|
||||
##### AFS3
|
||||
-##### Example: des-cbc-crc:normal
|
||||
+##### Example: aes256-cts-hmac-sha384-192:normal
|
||||
|
||||
attributetype ( 2.16.840.1.113719.1.301.4.43.1
|
||||
NAME 'krbSupportedEncSaltTypes'
|
||||
|
|
@ -1,68 +0,0 @@
|
|||
From b3ccfda0de6a9dd1248d9b15f31819421e36848e Mon Sep 17 00:00:00 2001
|
||||
From: Robbie Harwood <rharwood@redhat.com>
|
||||
Date: Thu, 2 May 2019 14:32:33 -0400
|
||||
Subject: [PATCH] Modernize exit path in gss_krb5int_copy_ccache()
|
||||
|
||||
Move to a single lock / single unlock paradigm, and eliminate some
|
||||
dead code in the old error handling.
|
||||
|
||||
(cherry picked from commit 1b89e3d8e949f52901bce74c9afc7a1a64099520)
|
||||
---
|
||||
src/lib/gssapi/krb5/copy_ccache.c | 31 ++++++++++++-------------------
|
||||
1 file changed, 12 insertions(+), 19 deletions(-)
|
||||
|
||||
diff --git a/src/lib/gssapi/krb5/copy_ccache.c b/src/lib/gssapi/krb5/copy_ccache.c
|
||||
index 027ed4847..2b2806e70 100644
|
||||
--- a/src/lib/gssapi/krb5/copy_ccache.c
|
||||
+++ b/src/lib/gssapi/krb5/copy_ccache.c
|
||||
@@ -9,7 +9,7 @@ gss_krb5int_copy_ccache(OM_uint32 *minor_status,
|
||||
{
|
||||
krb5_gss_cred_id_t k5creds;
|
||||
krb5_error_code code;
|
||||
- krb5_context context;
|
||||
+ krb5_context context = NULL;
|
||||
krb5_ccache out_ccache;
|
||||
|
||||
assert(value->length == sizeof(out_ccache));
|
||||
@@ -23,30 +23,23 @@ gss_krb5int_copy_ccache(OM_uint32 *minor_status,
|
||||
k5creds = (krb5_gss_cred_id_t) *cred_handle;
|
||||
k5_mutex_lock(&k5creds->lock);
|
||||
if (k5creds->usage == GSS_C_ACCEPT) {
|
||||
- k5_mutex_unlock(&k5creds->lock);
|
||||
- *minor_status = (OM_uint32) G_BAD_USAGE;
|
||||
- return(GSS_S_FAILURE);
|
||||
+ code = G_BAD_USAGE;
|
||||
+ goto cleanup;
|
||||
}
|
||||
|
||||
code = krb5_gss_init_context(&context);
|
||||
- if (code) {
|
||||
- k5_mutex_unlock(&k5creds->lock);
|
||||
- *minor_status = code;
|
||||
- return GSS_S_FAILURE;
|
||||
- }
|
||||
+ if (code)
|
||||
+ goto cleanup;
|
||||
|
||||
code = krb5_cc_copy_creds(context, k5creds->ccache, out_ccache);
|
||||
- if (code) {
|
||||
- k5_mutex_unlock(&k5creds->lock);
|
||||
- *minor_status = code;
|
||||
- save_error_info(*minor_status, context);
|
||||
- krb5_free_context(context);
|
||||
- return(GSS_S_FAILURE);
|
||||
- }
|
||||
+
|
||||
+cleanup:
|
||||
k5_mutex_unlock(&k5creds->lock);
|
||||
*minor_status = code;
|
||||
- if (code)
|
||||
- save_error_info(*minor_status, context);
|
||||
- krb5_free_context(context);
|
||||
+ if (context != NULL) {
|
||||
+ if (code)
|
||||
+ save_error_info(*minor_status, context);
|
||||
+ krb5_free_context(context);
|
||||
+ }
|
||||
return code ? GSS_S_FAILURE : GSS_S_COMPLETE;
|
||||
}
|
||||
|
|
@ -1,33 +0,0 @@
|
|||
From 4b087e84f6c399df56143eca50858c185d31633f Mon Sep 17 00:00:00 2001
|
||||
From: Robbie Harwood <rharwood@redhat.com>
|
||||
Date: Thu, 14 Feb 2019 11:50:35 -0500
|
||||
Subject: [PATCH] Properly size #ifdef in k5_cccol_lock()
|
||||
|
||||
The cleanup code only could get executed in the USE_CCAPI_V3 case, so
|
||||
move it inside that block. Reported by Coverity.
|
||||
|
||||
(cherry picked from commit 444a15f9cf82b9a6c1bca3f20307f82fee91c228)
|
||||
---
|
||||
src/lib/krb5/ccache/ccbase.c | 2 +-
|
||||
1 file changed, 1 insertion(+), 1 deletion(-)
|
||||
|
||||
diff --git a/src/lib/krb5/ccache/ccbase.c b/src/lib/krb5/ccache/ccbase.c
|
||||
index 8198f2b9b..2702bef69 100644
|
||||
--- a/src/lib/krb5/ccache/ccbase.c
|
||||
+++ b/src/lib/krb5/ccache/ccbase.c
|
||||
@@ -511,7 +511,6 @@ krb5_cccol_lock(krb5_context context)
|
||||
#endif
|
||||
#ifdef USE_CCAPI_V3
|
||||
ret = krb5_stdccv3_context_lock(context);
|
||||
-#endif
|
||||
if (ret) {
|
||||
k5_cc_mutex_unlock(context, &krb5int_mcc_mutex);
|
||||
k5_cc_mutex_unlock(context, &krb5int_cc_file_mutex);
|
||||
@@ -519,6 +518,7 @@ krb5_cccol_lock(krb5_context context)
|
||||
k5_cc_mutex_unlock(context, &cccol_lock);
|
||||
return ret;
|
||||
}
|
||||
+#endif
|
||||
k5_mutex_unlock(&cc_typelist_lock);
|
||||
return ret;
|
||||
}
|
||||
File diff suppressed because it is too large
Load diff
|
|
@ -1,967 +0,0 @@
|
|||
From 054cd1bad9941e6936345da3e9a839c8fdbd9ba3 Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Tue, 18 Jun 2019 11:40:48 -0400
|
||||
Subject: [PATCH] Remove PKINIT draft 9 ASN.1 code and types
|
||||
|
||||
ticket: 8817
|
||||
(cherry picked from commit c82e21d8836d4cb4c6ac7047752c9f600cb1ce33)
|
||||
---
|
||||
src/include/k5-int-pkinit.h | 74 --------------------------
|
||||
src/include/k5-int.h | 30 +----------
|
||||
src/lib/krb5/asn.1/asn1_k_encode.c | 81 ----------------------------
|
||||
src/lib/krb5/os/accessor.c | 7 ---
|
||||
src/tests/asn.1/krb5_decode_test.c | 41 --------------
|
||||
src/tests/asn.1/krb5_encode_test.c | 40 --------------
|
||||
src/tests/asn.1/ktest.c | 85 ------------------------------
|
||||
src/tests/asn.1/ktest.h | 11 ----
|
||||
src/tests/asn.1/ktest_equal.c | 51 ------------------
|
||||
src/tests/asn.1/ktest_equal.h | 3 --
|
||||
src/tests/asn.1/pkinit_encode.out | 5 --
|
||||
src/tests/asn.1/pkinit_trval.out | 47 -----------------
|
||||
12 files changed, 1 insertion(+), 474 deletions(-)
|
||||
|
||||
diff --git a/src/include/k5-int-pkinit.h b/src/include/k5-int-pkinit.h
|
||||
index 4622a629e..c23cfd304 100644
|
||||
--- a/src/include/k5-int-pkinit.h
|
||||
+++ b/src/include/k5-int-pkinit.h
|
||||
@@ -45,14 +45,6 @@ typedef struct _krb5_pk_authenticator {
|
||||
krb5_data *freshnessToken;
|
||||
} krb5_pk_authenticator;
|
||||
|
||||
-/* PKAuthenticator draft9 */
|
||||
-typedef struct _krb5_pk_authenticator_draft9 {
|
||||
- krb5_principal kdcName;
|
||||
- krb5_int32 cusec; /* (0..999999) */
|
||||
- krb5_timestamp ctime;
|
||||
- krb5_int32 nonce; /* (0..4294967295) */
|
||||
-} krb5_pk_authenticator_draft9;
|
||||
-
|
||||
/* AlgorithmIdentifier */
|
||||
typedef struct _krb5_algorithm_identifier {
|
||||
krb5_data algorithm; /* OID */
|
||||
@@ -74,12 +66,6 @@ typedef struct _krb5_auth_pack {
|
||||
krb5_data **supportedKDFs; /* OIDs of KDFs; OPTIONAL */
|
||||
} krb5_auth_pack;
|
||||
|
||||
-/* AuthPack draft9 */
|
||||
-typedef struct _krb5_auth_pack_draft9 {
|
||||
- krb5_pk_authenticator_draft9 pkAuthenticator;
|
||||
- krb5_subject_pk_info *clientPublicValue; /* Optional */
|
||||
-} krb5_auth_pack_draft9;
|
||||
-
|
||||
/* ExternalPrincipalIdentifier */
|
||||
typedef struct _krb5_external_principal_identifier {
|
||||
krb5_data subjectName; /* Optional */
|
||||
@@ -87,14 +73,6 @@ typedef struct _krb5_external_principal_identifier {
|
||||
krb5_data subjectKeyIdentifier; /* Optional */
|
||||
} krb5_external_principal_identifier;
|
||||
|
||||
-/* PA-PK-AS-REQ (Draft 9 -- PA TYPE 14) */
|
||||
-/* This has four fields, but we only care about the first and third for
|
||||
- * encoding, and the only about the first for decoding. */
|
||||
-typedef struct _krb5_pa_pk_as_req_draft9 {
|
||||
- krb5_data signedAuthPack;
|
||||
- krb5_data kdcCert; /* Optional */
|
||||
-} krb5_pa_pk_as_req_draft9;
|
||||
-
|
||||
/* PA-PK-AS-REQ (rfc4556 -- PA TYPE 16) */
|
||||
typedef struct _krb5_pa_pk_as_req {
|
||||
krb5_data signedAuthPack;
|
||||
@@ -116,37 +94,12 @@ typedef struct _krb5_kdc_dh_key_info {
|
||||
krb5_timestamp dhKeyExpiration; /* Optional */
|
||||
} krb5_kdc_dh_key_info;
|
||||
|
||||
-/* KDCDHKeyInfo draft9*/
|
||||
-typedef struct _krb5_kdc_dh_key_info_draft9 {
|
||||
- krb5_data subjectPublicKey; /* BIT STRING */
|
||||
- krb5_int32 nonce; /* (0..4294967295) */
|
||||
-} krb5_kdc_dh_key_info_draft9;
|
||||
-
|
||||
/* ReplyKeyPack */
|
||||
typedef struct _krb5_reply_key_pack {
|
||||
krb5_keyblock replyKey;
|
||||
krb5_checksum asChecksum;
|
||||
} krb5_reply_key_pack;
|
||||
|
||||
-/* ReplyKeyPack */
|
||||
-typedef struct _krb5_reply_key_pack_draft9 {
|
||||
- krb5_keyblock replyKey;
|
||||
- krb5_int32 nonce;
|
||||
-} krb5_reply_key_pack_draft9;
|
||||
-
|
||||
-/* PA-PK-AS-REP (Draft 9 -- PA TYPE 15) */
|
||||
-typedef struct _krb5_pa_pk_as_rep_draft9 {
|
||||
- enum krb5_pa_pk_as_rep_draft9_selection {
|
||||
- choice_pa_pk_as_rep_draft9_UNKNOWN = -1,
|
||||
- choice_pa_pk_as_rep_draft9_dhSignedData = 0,
|
||||
- choice_pa_pk_as_rep_draft9_encKeyPack = 1
|
||||
- } choice;
|
||||
- union krb5_pa_pk_as_rep_draft9_choices {
|
||||
- krb5_data dhSignedData;
|
||||
- krb5_data encKeyPack;
|
||||
- } u;
|
||||
-} krb5_pa_pk_as_rep_draft9;
|
||||
-
|
||||
/* PA-PK-AS-REP (rfc4556 -- PA TYPE 17) */
|
||||
typedef struct _krb5_pa_pk_as_rep {
|
||||
enum krb5_pa_pk_as_rep_selection {
|
||||
@@ -186,34 +139,18 @@ typedef struct _krb5_pkinit_supp_pub_info {
|
||||
krb5_error_code
|
||||
encode_krb5_pa_pk_as_req(const krb5_pa_pk_as_req *rep, krb5_data **code);
|
||||
|
||||
-krb5_error_code
|
||||
-encode_krb5_pa_pk_as_req_draft9(const krb5_pa_pk_as_req_draft9 *rep,
|
||||
- krb5_data **code);
|
||||
-
|
||||
krb5_error_code
|
||||
encode_krb5_pa_pk_as_rep(const krb5_pa_pk_as_rep *rep, krb5_data **code);
|
||||
|
||||
-krb5_error_code
|
||||
-encode_krb5_pa_pk_as_rep_draft9(const krb5_pa_pk_as_rep_draft9 *rep,
|
||||
- krb5_data **code);
|
||||
-
|
||||
krb5_error_code
|
||||
encode_krb5_auth_pack(const krb5_auth_pack *rep, krb5_data **code);
|
||||
|
||||
-krb5_error_code
|
||||
-encode_krb5_auth_pack_draft9(const krb5_auth_pack_draft9 *rep,
|
||||
- krb5_data **code);
|
||||
-
|
||||
krb5_error_code
|
||||
encode_krb5_kdc_dh_key_info(const krb5_kdc_dh_key_info *rep, krb5_data **code);
|
||||
|
||||
krb5_error_code
|
||||
encode_krb5_reply_key_pack(const krb5_reply_key_pack *, krb5_data **code);
|
||||
|
||||
-krb5_error_code
|
||||
-encode_krb5_reply_key_pack_draft9(const krb5_reply_key_pack_draft9 *,
|
||||
- krb5_data **code);
|
||||
-
|
||||
krb5_error_code
|
||||
encode_krb5_td_trusted_certifiers(krb5_external_principal_identifier *const *,
|
||||
krb5_data **code);
|
||||
@@ -237,19 +174,12 @@ encode_krb5_pkinit_supp_pub_info(const krb5_pkinit_supp_pub_info *,
|
||||
krb5_error_code
|
||||
decode_krb5_pa_pk_as_req(const krb5_data *, krb5_pa_pk_as_req **);
|
||||
|
||||
-krb5_error_code
|
||||
-decode_krb5_pa_pk_as_req_draft9(const krb5_data *,
|
||||
- krb5_pa_pk_as_req_draft9 **);
|
||||
-
|
||||
krb5_error_code
|
||||
decode_krb5_pa_pk_as_rep(const krb5_data *, krb5_pa_pk_as_rep **);
|
||||
|
||||
krb5_error_code
|
||||
decode_krb5_auth_pack(const krb5_data *, krb5_auth_pack **);
|
||||
|
||||
-krb5_error_code
|
||||
-decode_krb5_auth_pack_draft9(const krb5_data *, krb5_auth_pack_draft9 **);
|
||||
-
|
||||
krb5_error_code
|
||||
decode_krb5_kdc_dh_key_info(const krb5_data *, krb5_kdc_dh_key_info **);
|
||||
|
||||
@@ -259,10 +189,6 @@ decode_krb5_principal_name(const krb5_data *, krb5_principal_data **);
|
||||
krb5_error_code
|
||||
decode_krb5_reply_key_pack(const krb5_data *, krb5_reply_key_pack **);
|
||||
|
||||
-krb5_error_code
|
||||
-decode_krb5_reply_key_pack_draft9(const krb5_data *,
|
||||
- krb5_reply_key_pack_draft9 **);
|
||||
-
|
||||
krb5_error_code
|
||||
decode_krb5_td_trusted_certifiers(const krb5_data *,
|
||||
krb5_external_principal_identifier ***);
|
||||
diff --git a/src/include/k5-int.h b/src/include/k5-int.h
|
||||
index 0857fd1cc..cb328785d 100644
|
||||
--- a/src/include/k5-int.h
|
||||
+++ b/src/include/k5-int.h
|
||||
@@ -1836,7 +1836,7 @@ krb5int_random_string(krb5_context, char *string, unsigned int length);
|
||||
/* To keep happy libraries which are (for now) accessing internal stuff */
|
||||
|
||||
/* Make sure to increment by one when changing the struct */
|
||||
-#define KRB5INT_ACCESS_STRUCT_VERSION 22
|
||||
+#define KRB5INT_ACCESS_STRUCT_VERSION 23
|
||||
|
||||
typedef struct _krb5int_access {
|
||||
krb5_error_code (*auth_con_get_subkey_enctype)(krb5_context,
|
||||
@@ -1865,10 +1865,6 @@ typedef struct _krb5int_access {
|
||||
krb5_error_code
|
||||
(*encode_krb5_auth_pack)(const krb5_auth_pack *rep, krb5_data **code);
|
||||
|
||||
- krb5_error_code
|
||||
- (*encode_krb5_auth_pack_draft9)(const krb5_auth_pack_draft9 *rep,
|
||||
- krb5_data **code);
|
||||
-
|
||||
krb5_error_code
|
||||
(*encode_krb5_kdc_dh_key_info)(const krb5_kdc_dh_key_info *rep,
|
||||
krb5_data **code);
|
||||
@@ -1877,26 +1873,14 @@ typedef struct _krb5int_access {
|
||||
(*encode_krb5_pa_pk_as_rep)(const krb5_pa_pk_as_rep *rep,
|
||||
krb5_data **code);
|
||||
|
||||
- krb5_error_code
|
||||
- (*encode_krb5_pa_pk_as_rep_draft9)(const krb5_pa_pk_as_rep_draft9 *rep,
|
||||
- krb5_data **code);
|
||||
-
|
||||
krb5_error_code
|
||||
(*encode_krb5_pa_pk_as_req)(const krb5_pa_pk_as_req *rep,
|
||||
krb5_data **code);
|
||||
|
||||
- krb5_error_code
|
||||
- (*encode_krb5_pa_pk_as_req_draft9)(const krb5_pa_pk_as_req_draft9 *rep,
|
||||
- krb5_data **code);
|
||||
-
|
||||
krb5_error_code
|
||||
(*encode_krb5_reply_key_pack)(const krb5_reply_key_pack *,
|
||||
krb5_data **code);
|
||||
|
||||
- krb5_error_code
|
||||
- (*encode_krb5_reply_key_pack_draft9)(const krb5_reply_key_pack_draft9 *,
|
||||
- krb5_data **code);
|
||||
-
|
||||
krb5_error_code
|
||||
(*encode_krb5_td_dh_parameters)(krb5_algorithm_identifier *const *,
|
||||
krb5_data **code);
|
||||
@@ -1908,17 +1892,9 @@ typedef struct _krb5int_access {
|
||||
krb5_error_code
|
||||
(*decode_krb5_auth_pack)(const krb5_data *, krb5_auth_pack **);
|
||||
|
||||
- krb5_error_code
|
||||
- (*decode_krb5_auth_pack_draft9)(const krb5_data *,
|
||||
- krb5_auth_pack_draft9 **);
|
||||
-
|
||||
krb5_error_code
|
||||
(*decode_krb5_pa_pk_as_req)(const krb5_data *, krb5_pa_pk_as_req **);
|
||||
|
||||
- krb5_error_code
|
||||
- (*decode_krb5_pa_pk_as_req_draft9)(const krb5_data *,
|
||||
- krb5_pa_pk_as_req_draft9 **);
|
||||
-
|
||||
krb5_error_code
|
||||
(*decode_krb5_pa_pk_as_rep)(const krb5_data *, krb5_pa_pk_as_rep **);
|
||||
|
||||
@@ -1931,10 +1907,6 @@ typedef struct _krb5int_access {
|
||||
krb5_error_code
|
||||
(*decode_krb5_reply_key_pack)(const krb5_data *, krb5_reply_key_pack **);
|
||||
|
||||
- krb5_error_code
|
||||
- (*decode_krb5_reply_key_pack_draft9)(const krb5_data *,
|
||||
- krb5_reply_key_pack_draft9 **);
|
||||
-
|
||||
krb5_error_code
|
||||
(*decode_krb5_td_dh_parameters)(const krb5_data *,
|
||||
krb5_algorithm_identifier ***);
|
||||
diff --git a/src/lib/krb5/asn.1/asn1_k_encode.c b/src/lib/krb5/asn.1/asn1_k_encode.c
|
||||
index 81a34bac9..a026ab390 100644
|
||||
--- a/src/lib/krb5/asn.1/asn1_k_encode.c
|
||||
+++ b/src/lib/krb5/asn.1/asn1_k_encode.c
|
||||
@@ -1446,19 +1446,6 @@ static const struct atype_info *pk_authenticator_fields[] = {
|
||||
};
|
||||
DEFSEQTYPE(pk_authenticator, krb5_pk_authenticator, pk_authenticator_fields);
|
||||
|
||||
-DEFFIELD(pkauth9_0, krb5_pk_authenticator_draft9, kdcName, 0, principal);
|
||||
-DEFFIELD(pkauth9_1, krb5_pk_authenticator_draft9, kdcName, 1,
|
||||
- realm_of_principal);
|
||||
-DEFFIELD(pkauth9_2, krb5_pk_authenticator_draft9, cusec, 2, int32);
|
||||
-DEFFIELD(pkauth9_3, krb5_pk_authenticator_draft9, ctime, 3, kerberos_time);
|
||||
-DEFFIELD(pkauth9_4, krb5_pk_authenticator_draft9, nonce, 4, int32);
|
||||
-static const struct atype_info *pk_authenticator_draft9_fields[] = {
|
||||
- &k5_atype_pkauth9_0, &k5_atype_pkauth9_1, &k5_atype_pkauth9_2,
|
||||
- &k5_atype_pkauth9_3, &k5_atype_pkauth9_4
|
||||
-};
|
||||
-DEFSEQTYPE(pk_authenticator_draft9, krb5_pk_authenticator_draft9,
|
||||
- pk_authenticator_draft9_fields);
|
||||
-
|
||||
DEFCOUNTEDSTRINGTYPE(s_bitstring, char *, unsigned int,
|
||||
k5_asn1_encode_bitstring, k5_asn1_decode_bitstring,
|
||||
ASN1_BITSTRING);
|
||||
@@ -1488,15 +1475,6 @@ static const struct atype_info *auth_pack_fields[] = {
|
||||
};
|
||||
DEFSEQTYPE(auth_pack, krb5_auth_pack, auth_pack_fields);
|
||||
|
||||
-DEFFIELD(auth_pack9_0, krb5_auth_pack_draft9, pkAuthenticator, 0,
|
||||
- pk_authenticator_draft9);
|
||||
-DEFFIELD(auth_pack9_1, krb5_auth_pack_draft9, clientPublicValue, 1,
|
||||
- opt_subject_pk_info_ptr);
|
||||
-static const struct atype_info *auth_pack_draft9_fields[] = {
|
||||
- &k5_atype_auth_pack9_0, &k5_atype_auth_pack9_1
|
||||
-};
|
||||
-DEFSEQTYPE(auth_pack_draft9, krb5_auth_pack_draft9, auth_pack_draft9_fields);
|
||||
-
|
||||
DEFFIELD_IMPLICIT(extprinc_0, krb5_external_principal_identifier,
|
||||
subjectName, 0, opt_ostring_data);
|
||||
DEFFIELD_IMPLICIT(extprinc_1, krb5_external_principal_identifier,
|
||||
@@ -1529,29 +1507,6 @@ static const struct atype_info *pa_pk_as_req_fields[] = {
|
||||
};
|
||||
DEFSEQTYPE(pa_pk_as_req, krb5_pa_pk_as_req, pa_pk_as_req_fields);
|
||||
|
||||
-/*
|
||||
- * In draft-ietf-cat-kerberos-pk-init-09, this sequence has four fields, but we
|
||||
- * only ever use the first and third. The fields are specified as explicitly
|
||||
- * tagged, but our historical behavior is to pretend that they are wrapped in
|
||||
- * IMPLICIT OCTET STRING (i.e., generate primitive context tags), and we don't
|
||||
- * want to change that without interop testing.
|
||||
- */
|
||||
-DEFFIELD_IMPLICIT(pa_pk_as_req9_0, krb5_pa_pk_as_req_draft9, signedAuthPack, 0,
|
||||
- ostring_data);
|
||||
-DEFFIELD_IMPLICIT(pa_pk_as_req9_2, krb5_pa_pk_as_req_draft9, kdcCert, 2,
|
||||
- opt_ostring_data);
|
||||
-static const struct atype_info *pa_pk_as_req_draft9_fields[] = {
|
||||
- &k5_atype_pa_pk_as_req9_0, &k5_atype_pa_pk_as_req9_2
|
||||
-};
|
||||
-DEFSEQTYPE(pa_pk_as_req_draft9, krb5_pa_pk_as_req_draft9,
|
||||
- pa_pk_as_req_draft9_fields);
|
||||
-/* For decoding, we only care about the first field; we can ignore the rest. */
|
||||
-static const struct atype_info *pa_pk_as_req_draft9_decode_fields[] = {
|
||||
- &k5_atype_pa_pk_as_req9_0
|
||||
-};
|
||||
-DEFSEQTYPE(pa_pk_as_req_draft9_decode, krb5_pa_pk_as_req_draft9,
|
||||
- pa_pk_as_req_draft9_decode_fields);
|
||||
-
|
||||
DEFFIELD_IMPLICIT(dh_rep_info_0, krb5_dh_rep_info, dhSignedData, 0,
|
||||
ostring_data);
|
||||
DEFFIELD(dh_rep_info_1, krb5_dh_rep_info, serverDHNonce, 1, opt_ostring_data);
|
||||
@@ -1577,14 +1532,6 @@ static const struct atype_info *reply_key_pack_fields[] = {
|
||||
};
|
||||
DEFSEQTYPE(reply_key_pack, krb5_reply_key_pack, reply_key_pack_fields);
|
||||
|
||||
-DEFFIELD(key_pack9_0, krb5_reply_key_pack_draft9, replyKey, 0, encryption_key);
|
||||
-DEFFIELD(key_pack9_1, krb5_reply_key_pack_draft9, nonce, 1, int32);
|
||||
-static const struct atype_info *reply_key_pack_draft9_fields[] = {
|
||||
- &k5_atype_key_pack9_0, &k5_atype_key_pack9_1
|
||||
-};
|
||||
-DEFSEQTYPE(reply_key_pack_draft9, krb5_reply_key_pack_draft9,
|
||||
- reply_key_pack_draft9_fields);
|
||||
-
|
||||
DEFCTAGGEDTYPE(pa_pk_as_rep_0, 0, dh_rep_info);
|
||||
DEFCTAGGEDTYPE_IMPLICIT(pa_pk_as_rep_1, 1, ostring_data);
|
||||
static const struct atype_info *pa_pk_as_rep_alternatives[] = {
|
||||
@@ -1595,44 +1542,16 @@ DEFCHOICETYPE(pa_pk_as_rep_choice, union krb5_pa_pk_as_rep_choices,
|
||||
DEFCOUNTEDTYPE_SIGNED(pa_pk_as_rep, krb5_pa_pk_as_rep, u, choice,
|
||||
pa_pk_as_rep_choice);
|
||||
|
||||
-/*
|
||||
- * draft-ietf-cat-kerberos-pk-init-09 specifies these alternatives as
|
||||
- * explicitly tagged SignedData and EnvelopedData respectively, which means
|
||||
- * they should have constructed context tags. However, our historical behavior
|
||||
- * is to use primitive context tags, and we don't want to change that behavior
|
||||
- * without interop testing. We have the encodings for each alternative in a
|
||||
- * krb5_data object; pretend that they are wrapped in IMPLICIT OCTET STRING in
|
||||
- * order to wrap them in primitive [0] and [1] tags.
|
||||
- */
|
||||
-DEFCTAGGEDTYPE_IMPLICIT(pa_pk_as_rep9_0, 0, ostring_data);
|
||||
-DEFCTAGGEDTYPE_IMPLICIT(pa_pk_as_rep9_1, 1, ostring_data);
|
||||
-static const struct atype_info *pa_pk_as_rep_draft9_alternatives[] = {
|
||||
- &k5_atype_pa_pk_as_rep9_0, &k5_atype_pa_pk_as_rep9_1
|
||||
-};
|
||||
-DEFCHOICETYPE(pa_pk_as_rep_draft9_choice,
|
||||
- union krb5_pa_pk_as_rep_draft9_choices,
|
||||
- enum krb5_pa_pk_as_rep_draft9_selection,
|
||||
- pa_pk_as_rep_draft9_alternatives);
|
||||
-DEFCOUNTEDTYPE_SIGNED(pa_pk_as_rep_draft9, krb5_pa_pk_as_rep_draft9, u, choice,
|
||||
- pa_pk_as_rep_draft9_choice);
|
||||
-
|
||||
MAKE_ENCODER(encode_krb5_pa_pk_as_req, pa_pk_as_req);
|
||||
MAKE_DECODER(decode_krb5_pa_pk_as_req, pa_pk_as_req);
|
||||
-MAKE_ENCODER(encode_krb5_pa_pk_as_req_draft9, pa_pk_as_req_draft9);
|
||||
-MAKE_DECODER(decode_krb5_pa_pk_as_req_draft9, pa_pk_as_req_draft9_decode);
|
||||
MAKE_ENCODER(encode_krb5_pa_pk_as_rep, pa_pk_as_rep);
|
||||
MAKE_DECODER(decode_krb5_pa_pk_as_rep, pa_pk_as_rep);
|
||||
-MAKE_ENCODER(encode_krb5_pa_pk_as_rep_draft9, pa_pk_as_rep_draft9);
|
||||
MAKE_ENCODER(encode_krb5_auth_pack, auth_pack);
|
||||
MAKE_DECODER(decode_krb5_auth_pack, auth_pack);
|
||||
-MAKE_ENCODER(encode_krb5_auth_pack_draft9, auth_pack_draft9);
|
||||
-MAKE_DECODER(decode_krb5_auth_pack_draft9, auth_pack_draft9);
|
||||
MAKE_ENCODER(encode_krb5_kdc_dh_key_info, kdc_dh_key_info);
|
||||
MAKE_DECODER(decode_krb5_kdc_dh_key_info, kdc_dh_key_info);
|
||||
MAKE_ENCODER(encode_krb5_reply_key_pack, reply_key_pack);
|
||||
MAKE_DECODER(decode_krb5_reply_key_pack, reply_key_pack);
|
||||
-MAKE_ENCODER(encode_krb5_reply_key_pack_draft9, reply_key_pack_draft9);
|
||||
-MAKE_DECODER(decode_krb5_reply_key_pack_draft9, reply_key_pack_draft9);
|
||||
MAKE_ENCODER(encode_krb5_td_trusted_certifiers,
|
||||
seqof_external_principal_identifier);
|
||||
MAKE_DECODER(decode_krb5_td_trusted_certifiers,
|
||||
diff --git a/src/lib/krb5/os/accessor.c b/src/lib/krb5/os/accessor.c
|
||||
index d77f8c6b7..12a39a2ab 100644
|
||||
--- a/src/lib/krb5/os/accessor.c
|
||||
+++ b/src/lib/krb5/os/accessor.c
|
||||
@@ -80,25 +80,18 @@ krb5int_accessor(krb5int_access *internals, krb5_int32 version)
|
||||
#define SC(FIELD, VAL) S(FIELD, 0)
|
||||
#endif
|
||||
SC (encode_krb5_pa_pk_as_req, encode_krb5_pa_pk_as_req),
|
||||
- SC (encode_krb5_pa_pk_as_req_draft9, encode_krb5_pa_pk_as_req_draft9),
|
||||
SC (encode_krb5_pa_pk_as_rep, encode_krb5_pa_pk_as_rep),
|
||||
- SC (encode_krb5_pa_pk_as_rep_draft9, encode_krb5_pa_pk_as_rep_draft9),
|
||||
SC (encode_krb5_auth_pack, encode_krb5_auth_pack),
|
||||
- SC (encode_krb5_auth_pack_draft9, encode_krb5_auth_pack_draft9),
|
||||
SC (encode_krb5_kdc_dh_key_info, encode_krb5_kdc_dh_key_info),
|
||||
SC (encode_krb5_reply_key_pack, encode_krb5_reply_key_pack),
|
||||
- SC (encode_krb5_reply_key_pack_draft9, encode_krb5_reply_key_pack_draft9),
|
||||
SC (encode_krb5_td_trusted_certifiers, encode_krb5_td_trusted_certifiers),
|
||||
SC (encode_krb5_td_dh_parameters, encode_krb5_td_dh_parameters),
|
||||
SC (decode_krb5_pa_pk_as_req, decode_krb5_pa_pk_as_req),
|
||||
- SC (decode_krb5_pa_pk_as_req_draft9, decode_krb5_pa_pk_as_req_draft9),
|
||||
SC (decode_krb5_pa_pk_as_rep, decode_krb5_pa_pk_as_rep),
|
||||
SC (decode_krb5_auth_pack, decode_krb5_auth_pack),
|
||||
- SC (decode_krb5_auth_pack_draft9, decode_krb5_auth_pack_draft9),
|
||||
SC (decode_krb5_kdc_dh_key_info, decode_krb5_kdc_dh_key_info),
|
||||
SC (decode_krb5_principal_name, decode_krb5_principal_name),
|
||||
SC (decode_krb5_reply_key_pack, decode_krb5_reply_key_pack),
|
||||
- SC (decode_krb5_reply_key_pack_draft9, decode_krb5_reply_key_pack_draft9),
|
||||
SC (decode_krb5_td_trusted_certifiers, decode_krb5_td_trusted_certifiers),
|
||||
SC (decode_krb5_td_dh_parameters, decode_krb5_td_dh_parameters),
|
||||
SC (encode_krb5_kdc_req_body, encode_krb5_kdc_req_body),
|
||||
diff --git a/src/tests/asn.1/krb5_decode_test.c b/src/tests/asn.1/krb5_decode_test.c
|
||||
index cbd99ba63..7a116b40d 100644
|
||||
--- a/src/tests/asn.1/krb5_decode_test.c
|
||||
+++ b/src/tests/asn.1/krb5_decode_test.c
|
||||
@@ -42,8 +42,6 @@ void krb5_ktest_free_enc_data(krb5_context context, krb5_enc_data *val);
|
||||
#ifndef DISABLE_PKINIT
|
||||
static int equal_principal(krb5_principal *ref, krb5_principal var);
|
||||
static void ktest_free_auth_pack(krb5_context context, krb5_auth_pack *val);
|
||||
-static void ktest_free_auth_pack_draft9(krb5_context context,
|
||||
- krb5_auth_pack_draft9 *val);
|
||||
static void ktest_free_kdc_dh_key_info(krb5_context context,
|
||||
krb5_kdc_dh_key_info *val);
|
||||
static void ktest_free_pa_pk_as_req(krb5_context context,
|
||||
@@ -52,8 +50,6 @@ static void ktest_free_pa_pk_as_rep(krb5_context context,
|
||||
krb5_pa_pk_as_rep *val);
|
||||
static void ktest_free_reply_key_pack(krb5_context context,
|
||||
krb5_reply_key_pack *val);
|
||||
-static void ktest_free_reply_key_pack_draft9(krb5_context context,
|
||||
- krb5_reply_key_pack_draft9 *val);
|
||||
#endif
|
||||
static void ktest_free_kkdcp_message(krb5_context context,
|
||||
krb5_kkdcp_message *val);
|
||||
@@ -1183,16 +1179,6 @@ int main(argc, argv)
|
||||
ktest_empty_auth_pack(&ref);
|
||||
}
|
||||
|
||||
- /****************************************************************/
|
||||
- /* decode_krb5_auth_pack_draft9 */
|
||||
- {
|
||||
- setup(krb5_auth_pack_draft9,ktest_make_sample_auth_pack_draft9);
|
||||
- decode_run("krb5_auth_pack_draft9","","30 75 A0 4F 30 4D A0 1A 30 18 A0 03 02 01 01 A1 11 30 0F 1B 06 68 66 74 73 61 69 1B 05 65 78 74 72 61 A1 10 1B 0E 41 54 48 45 4E 41 2E 4D 49 54 2E 45 44 55 A2 05 02 03 01 E2 40 A3 11 18 0F 31 39 39 34 30 36 31 30 30 36 30 33 31 37 5A A4 03 02 01 2A A1 22 30 20 30 13 06 09 2A 86 48 86 F7 12 01 02 02 04 06 70 61 72 61 6D 73 03 09 00 6B 72 62 35 64 61 74 61",
|
||||
- acc.decode_krb5_auth_pack_draft9,
|
||||
- ktest_equal_auth_pack_draft9,ktest_free_auth_pack_draft9);
|
||||
- ktest_empty_auth_pack_draft9(&ref);
|
||||
- }
|
||||
-
|
||||
/****************************************************************/
|
||||
/* decode_krb5_kdc_dh_key_info */
|
||||
{
|
||||
@@ -1213,16 +1199,6 @@ int main(argc, argv)
|
||||
ktest_empty_reply_key_pack(&ref);
|
||||
}
|
||||
|
||||
- /****************************************************************/
|
||||
- /* decode_krb5_reply_key_pack_draft9 */
|
||||
- {
|
||||
- setup(krb5_reply_key_pack_draft9,ktest_make_sample_reply_key_pack_draft9);
|
||||
- decode_run("krb5_reply_key_pack_draft9","","30 1A A0 13 30 11 A0 03 02 01 01 A1 0A 04 08 31 32 33 34 35 36 37 38 A1 03 02 01 2A",
|
||||
- acc.decode_krb5_reply_key_pack_draft9,
|
||||
- ktest_equal_reply_key_pack_draft9,ktest_free_reply_key_pack_draft9);
|
||||
- ktest_empty_reply_key_pack_draft9(&ref);
|
||||
- }
|
||||
-
|
||||
/****************************************************************/
|
||||
/* decode_krb5_principal_name */
|
||||
/* We have no encoder for this type (KerberosName from RFC 4556); the
|
||||
@@ -1279,14 +1255,6 @@ ktest_free_auth_pack(krb5_context context, krb5_auth_pack *val)
|
||||
free(val);
|
||||
}
|
||||
|
||||
-static void
|
||||
-ktest_free_auth_pack_draft9(krb5_context context, krb5_auth_pack_draft9 *val)
|
||||
-{
|
||||
- if (val)
|
||||
- ktest_empty_auth_pack_draft9(val);
|
||||
- free(val);
|
||||
-}
|
||||
-
|
||||
static void
|
||||
ktest_free_kdc_dh_key_info(krb5_context context, krb5_kdc_dh_key_info *val)
|
||||
{
|
||||
@@ -1319,15 +1287,6 @@ ktest_free_reply_key_pack(krb5_context context, krb5_reply_key_pack *val)
|
||||
free(val);
|
||||
}
|
||||
|
||||
-static void
|
||||
-ktest_free_reply_key_pack_draft9(krb5_context context,
|
||||
- krb5_reply_key_pack_draft9 *val)
|
||||
-{
|
||||
- if (val)
|
||||
- ktest_empty_reply_key_pack_draft9(val);
|
||||
- free(val);
|
||||
-}
|
||||
-
|
||||
#endif /* not DISABLE_PKINIT */
|
||||
|
||||
static void
|
||||
diff --git a/src/tests/asn.1/krb5_encode_test.c b/src/tests/asn.1/krb5_encode_test.c
|
||||
index 3efbfb4c0..72c013468 100644
|
||||
--- a/src/tests/asn.1/krb5_encode_test.c
|
||||
+++ b/src/tests/asn.1/krb5_encode_test.c
|
||||
@@ -798,15 +798,6 @@ main(argc, argv)
|
||||
ktest_empty_pa_pk_as_req(&req);
|
||||
}
|
||||
/****************************************************************/
|
||||
- /* encode_krb5_pa_pk_as_req_draft9 */
|
||||
- {
|
||||
- krb5_pa_pk_as_req_draft9 req;
|
||||
- ktest_make_sample_pa_pk_as_req_draft9(&req);
|
||||
- encode_run(req, "pa_pk_as_req_draft9", "",
|
||||
- acc.encode_krb5_pa_pk_as_req_draft9);
|
||||
- ktest_empty_pa_pk_as_req_draft9(&req);
|
||||
- }
|
||||
- /****************************************************************/
|
||||
/* encode_krb5_pa_pk_as_rep */
|
||||
{
|
||||
krb5_pa_pk_as_rep rep;
|
||||
@@ -820,19 +811,6 @@ main(argc, argv)
|
||||
ktest_empty_pa_pk_as_rep(&rep);
|
||||
}
|
||||
/****************************************************************/
|
||||
- /* encode_krb5_pa_pk_as_rep_draft9 */
|
||||
- {
|
||||
- krb5_pa_pk_as_rep_draft9 rep;
|
||||
- ktest_make_sample_pa_pk_as_rep_draft9_dhSignedData(&rep);
|
||||
- encode_run(rep, "pa_pk_as_rep_draft9", "(dhSignedData)",
|
||||
- acc.encode_krb5_pa_pk_as_rep_draft9);
|
||||
- ktest_empty_pa_pk_as_rep_draft9(&rep);
|
||||
- ktest_make_sample_pa_pk_as_rep_draft9_encKeyPack(&rep);
|
||||
- encode_run(rep, "pa_pk_as_rep_draft9", "(encKeyPack)",
|
||||
- acc.encode_krb5_pa_pk_as_rep_draft9);
|
||||
- ktest_empty_pa_pk_as_rep_draft9(&rep);
|
||||
- }
|
||||
- /****************************************************************/
|
||||
/* encode_krb5_auth_pack */
|
||||
{
|
||||
krb5_auth_pack pack;
|
||||
@@ -841,15 +819,6 @@ main(argc, argv)
|
||||
ktest_empty_auth_pack(&pack);
|
||||
}
|
||||
/****************************************************************/
|
||||
- /* encode_krb5_auth_pack_draft9_draft9 */
|
||||
- {
|
||||
- krb5_auth_pack_draft9 pack;
|
||||
- ktest_make_sample_auth_pack_draft9(&pack);
|
||||
- encode_run(pack, "auth_pack_draft9", "",
|
||||
- acc.encode_krb5_auth_pack_draft9);
|
||||
- ktest_empty_auth_pack_draft9(&pack);
|
||||
- }
|
||||
- /****************************************************************/
|
||||
/* encode_krb5_kdc_dh_key_info */
|
||||
{
|
||||
krb5_kdc_dh_key_info ki;
|
||||
@@ -866,15 +835,6 @@ main(argc, argv)
|
||||
ktest_empty_reply_key_pack(&pack);
|
||||
}
|
||||
/****************************************************************/
|
||||
- /* encode_krb5_reply_key_pack_draft9 */
|
||||
- {
|
||||
- krb5_reply_key_pack_draft9 pack;
|
||||
- ktest_make_sample_reply_key_pack_draft9(&pack);
|
||||
- encode_run(pack, "reply_key_pack_draft9", "",
|
||||
- acc.encode_krb5_reply_key_pack_draft9);
|
||||
- ktest_empty_reply_key_pack_draft9(&pack);
|
||||
- }
|
||||
- /****************************************************************/
|
||||
/* encode_krb5_sp80056a_other_info */
|
||||
{
|
||||
krb5_sp80056a_other_info info;
|
||||
diff --git a/src/tests/asn.1/ktest.c b/src/tests/asn.1/ktest.c
|
||||
index 258377299..7bb698732 100644
|
||||
--- a/src/tests/asn.1/ktest.c
|
||||
+++ b/src/tests/asn.1/ktest.c
|
||||
@@ -729,15 +729,6 @@ ktest_make_sample_pk_authenticator(krb5_pk_authenticator *p)
|
||||
ktest_make_sample_data(p->freshnessToken);
|
||||
}
|
||||
|
||||
-static void
|
||||
-ktest_make_sample_pk_authenticator_draft9(krb5_pk_authenticator_draft9 *p)
|
||||
-{
|
||||
- ktest_make_sample_principal(&p->kdcName);
|
||||
- p->cusec = SAMPLE_USEC;
|
||||
- p->ctime = SAMPLE_TIME;
|
||||
- p->nonce = SAMPLE_NONCE;
|
||||
-}
|
||||
-
|
||||
static void
|
||||
ktest_make_sample_oid(krb5_data *p)
|
||||
{
|
||||
@@ -788,13 +779,6 @@ ktest_make_sample_pa_pk_as_req(krb5_pa_pk_as_req *p)
|
||||
ktest_make_sample_data(&p->kdcPkId);
|
||||
}
|
||||
|
||||
-void
|
||||
-ktest_make_sample_pa_pk_as_req_draft9(krb5_pa_pk_as_req_draft9 *p)
|
||||
-{
|
||||
- ktest_make_sample_data(&p->signedAuthPack);
|
||||
- ktest_make_sample_data(&p->kdcCert);
|
||||
-}
|
||||
-
|
||||
static void
|
||||
ktest_make_sample_dh_rep_info(krb5_dh_rep_info *p)
|
||||
{
|
||||
@@ -818,20 +802,6 @@ ktest_make_sample_pa_pk_as_rep_encKeyPack(krb5_pa_pk_as_rep *p)
|
||||
ktest_make_sample_data(&p->u.encKeyPack);
|
||||
}
|
||||
|
||||
-void
|
||||
-ktest_make_sample_pa_pk_as_rep_draft9_dhSignedData(krb5_pa_pk_as_rep_draft9 *p)
|
||||
-{
|
||||
- p->choice = choice_pa_pk_as_rep_draft9_dhSignedData;
|
||||
- ktest_make_sample_data(&p->u.dhSignedData);
|
||||
-}
|
||||
-
|
||||
-void
|
||||
-ktest_make_sample_pa_pk_as_rep_draft9_encKeyPack(krb5_pa_pk_as_rep_draft9 *p)
|
||||
-{
|
||||
- p->choice = choice_pa_pk_as_rep_draft9_encKeyPack;
|
||||
- ktest_make_sample_data(&p->u.encKeyPack);
|
||||
-}
|
||||
-
|
||||
void
|
||||
ktest_make_sample_auth_pack(krb5_auth_pack *p)
|
||||
{
|
||||
@@ -851,14 +821,6 @@ ktest_make_sample_auth_pack(krb5_auth_pack *p)
|
||||
p->supportedKDFs[1] = NULL;
|
||||
}
|
||||
|
||||
-void
|
||||
-ktest_make_sample_auth_pack_draft9(krb5_auth_pack_draft9 *p)
|
||||
-{
|
||||
- ktest_make_sample_pk_authenticator_draft9(&p->pkAuthenticator);
|
||||
- p->clientPublicValue = ealloc(sizeof(krb5_subject_pk_info));
|
||||
- ktest_make_sample_subject_pk_info(p->clientPublicValue);
|
||||
-}
|
||||
-
|
||||
void
|
||||
ktest_make_sample_kdc_dh_key_info(krb5_kdc_dh_key_info *p)
|
||||
{
|
||||
@@ -874,13 +836,6 @@ ktest_make_sample_reply_key_pack(krb5_reply_key_pack *p)
|
||||
ktest_make_sample_checksum(&p->asChecksum);
|
||||
}
|
||||
|
||||
-void
|
||||
-ktest_make_sample_reply_key_pack_draft9(krb5_reply_key_pack_draft9 *p)
|
||||
-{
|
||||
- ktest_make_sample_keyblock(&p->replyKey);
|
||||
- p->nonce = SAMPLE_NONCE;
|
||||
-}
|
||||
-
|
||||
void
|
||||
ktest_make_sample_sp80056a_other_info(krb5_sp80056a_other_info *p)
|
||||
{
|
||||
@@ -1717,12 +1672,6 @@ ktest_empty_pk_authenticator(krb5_pk_authenticator *p)
|
||||
p->freshnessToken = NULL;
|
||||
}
|
||||
|
||||
-static void
|
||||
-ktest_empty_pk_authenticator_draft9(krb5_pk_authenticator_draft9 *p)
|
||||
-{
|
||||
- ktest_destroy_principal(&p->kdcName);
|
||||
-}
|
||||
-
|
||||
static void
|
||||
ktest_empty_subject_pk_info(krb5_subject_pk_info *p)
|
||||
{
|
||||
@@ -1754,13 +1703,6 @@ ktest_empty_pa_pk_as_req(krb5_pa_pk_as_req *p)
|
||||
ktest_empty_data(&p->kdcPkId);
|
||||
}
|
||||
|
||||
-void
|
||||
-ktest_empty_pa_pk_as_req_draft9(krb5_pa_pk_as_req_draft9 *p)
|
||||
-{
|
||||
- ktest_empty_data(&p->signedAuthPack);
|
||||
- ktest_empty_data(&p->kdcCert);
|
||||
-}
|
||||
-
|
||||
static void
|
||||
ktest_empty_dh_rep_info(krb5_dh_rep_info *p)
|
||||
{
|
||||
@@ -1779,16 +1721,6 @@ ktest_empty_pa_pk_as_rep(krb5_pa_pk_as_rep *p)
|
||||
p->choice = choice_pa_pk_as_rep_UNKNOWN;
|
||||
}
|
||||
|
||||
-void
|
||||
-ktest_empty_pa_pk_as_rep_draft9(krb5_pa_pk_as_rep_draft9 *p)
|
||||
-{
|
||||
- if (p->choice == choice_pa_pk_as_rep_draft9_dhSignedData)
|
||||
- ktest_empty_data(&p->u.dhSignedData);
|
||||
- else if (p->choice == choice_pa_pk_as_rep_draft9_encKeyPack)
|
||||
- ktest_empty_data(&p->u.encKeyPack);
|
||||
- p->choice = choice_pa_pk_as_rep_draft9_UNKNOWN;
|
||||
-}
|
||||
-
|
||||
void
|
||||
ktest_empty_auth_pack(krb5_auth_pack *p)
|
||||
{
|
||||
@@ -1820,17 +1752,6 @@ ktest_empty_auth_pack(krb5_auth_pack *p)
|
||||
}
|
||||
}
|
||||
|
||||
-void
|
||||
-ktest_empty_auth_pack_draft9(krb5_auth_pack_draft9 *p)
|
||||
-{
|
||||
- ktest_empty_pk_authenticator_draft9(&p->pkAuthenticator);
|
||||
- if (p->clientPublicValue != NULL) {
|
||||
- ktest_empty_subject_pk_info(p->clientPublicValue);
|
||||
- free(p->clientPublicValue);
|
||||
- p->clientPublicValue = NULL;
|
||||
- }
|
||||
-}
|
||||
-
|
||||
void
|
||||
ktest_empty_kdc_dh_key_info(krb5_kdc_dh_key_info *p)
|
||||
{
|
||||
@@ -1844,12 +1765,6 @@ ktest_empty_reply_key_pack(krb5_reply_key_pack *p)
|
||||
ktest_empty_checksum(&p->asChecksum);
|
||||
}
|
||||
|
||||
-void
|
||||
-ktest_empty_reply_key_pack_draft9(krb5_reply_key_pack_draft9 *p)
|
||||
-{
|
||||
- ktest_empty_keyblock(&p->replyKey);
|
||||
-}
|
||||
-
|
||||
void ktest_empty_sp80056a_other_info(krb5_sp80056a_other_info *p)
|
||||
{
|
||||
ktest_empty_algorithm_identifier(&p->algorithm_identifier);
|
||||
diff --git a/src/tests/asn.1/ktest.h b/src/tests/asn.1/ktest.h
|
||||
index 1413cfae1..d9cc90a5c 100644
|
||||
--- a/src/tests/asn.1/ktest.h
|
||||
+++ b/src/tests/asn.1/ktest.h
|
||||
@@ -101,18 +101,11 @@ void ktest_make_maximal_pa_otp_req(krb5_pa_otp_req *p);
|
||||
|
||||
#ifndef DISABLE_PKINIT
|
||||
void ktest_make_sample_pa_pk_as_req(krb5_pa_pk_as_req *p);
|
||||
-void ktest_make_sample_pa_pk_as_req_draft9(krb5_pa_pk_as_req_draft9 *p);
|
||||
void ktest_make_sample_pa_pk_as_rep_dhInfo(krb5_pa_pk_as_rep *p);
|
||||
void ktest_make_sample_pa_pk_as_rep_encKeyPack(krb5_pa_pk_as_rep *p);
|
||||
-void ktest_make_sample_pa_pk_as_rep_draft9_dhSignedData(
|
||||
- krb5_pa_pk_as_rep_draft9 *p);
|
||||
-void ktest_make_sample_pa_pk_as_rep_draft9_encKeyPack(
|
||||
- krb5_pa_pk_as_rep_draft9 *p);
|
||||
void ktest_make_sample_auth_pack(krb5_auth_pack *p);
|
||||
-void ktest_make_sample_auth_pack_draft9(krb5_auth_pack_draft9 *p);
|
||||
void ktest_make_sample_kdc_dh_key_info(krb5_kdc_dh_key_info *p);
|
||||
void ktest_make_sample_reply_key_pack(krb5_reply_key_pack *p);
|
||||
-void ktest_make_sample_reply_key_pack_draft9(krb5_reply_key_pack_draft9 *p);
|
||||
void ktest_make_sample_sp80056a_other_info(krb5_sp80056a_other_info *p);
|
||||
void ktest_make_sample_pkinit_supp_pub_info(krb5_pkinit_supp_pub_info *p);
|
||||
#endif
|
||||
@@ -197,14 +190,10 @@ void ktest_empty_pa_otp_req(krb5_pa_otp_req *p);
|
||||
|
||||
#ifndef DISABLE_PKINIT
|
||||
void ktest_empty_pa_pk_as_req(krb5_pa_pk_as_req *p);
|
||||
-void ktest_empty_pa_pk_as_req_draft9(krb5_pa_pk_as_req_draft9 *p);
|
||||
void ktest_empty_pa_pk_as_rep(krb5_pa_pk_as_rep *p);
|
||||
-void ktest_empty_pa_pk_as_rep_draft9(krb5_pa_pk_as_rep_draft9 *p);
|
||||
void ktest_empty_auth_pack(krb5_auth_pack *p);
|
||||
-void ktest_empty_auth_pack_draft9(krb5_auth_pack_draft9 *p);
|
||||
void ktest_empty_kdc_dh_key_info(krb5_kdc_dh_key_info *p);
|
||||
void ktest_empty_reply_key_pack(krb5_reply_key_pack *p);
|
||||
-void ktest_empty_reply_key_pack_draft9(krb5_reply_key_pack_draft9 *p);
|
||||
void ktest_empty_sp80056a_other_info(krb5_sp80056a_other_info *p);
|
||||
void ktest_empty_pkinit_supp_pub_info(krb5_pkinit_supp_pub_info *p);
|
||||
#endif
|
||||
diff --git a/src/tests/asn.1/ktest_equal.c b/src/tests/asn.1/ktest_equal.c
|
||||
index 714cc4398..8a3911cdc 100644
|
||||
--- a/src/tests/asn.1/ktest_equal.c
|
||||
+++ b/src/tests/asn.1/ktest_equal.c
|
||||
@@ -876,20 +876,6 @@ ktest_equal_pk_authenticator(krb5_pk_authenticator *ref,
|
||||
return p;
|
||||
}
|
||||
|
||||
-static int
|
||||
-ktest_equal_pk_authenticator_draft9(krb5_pk_authenticator_draft9 *ref,
|
||||
- krb5_pk_authenticator_draft9 *var)
|
||||
-{
|
||||
- int p = TRUE;
|
||||
- if (ref == var) return TRUE;
|
||||
- else if (ref == NULL || var == NULL) return FALSE;
|
||||
- p = p && ptr_equal(kdcName, ktest_equal_principal_data);
|
||||
- p = p && scalar_equal(cusec);
|
||||
- p = p && scalar_equal(ctime);
|
||||
- p = p && scalar_equal(nonce);
|
||||
- return p;
|
||||
-}
|
||||
-
|
||||
static int
|
||||
ktest_equal_subject_pk_info(krb5_subject_pk_info *ref,
|
||||
krb5_subject_pk_info *var)
|
||||
@@ -937,18 +923,6 @@ ktest_equal_pa_pk_as_req(krb5_pa_pk_as_req *ref, krb5_pa_pk_as_req *var)
|
||||
return p;
|
||||
}
|
||||
|
||||
-int
|
||||
-ktest_equal_pa_pk_as_req_draft9(krb5_pa_pk_as_req_draft9 *ref,
|
||||
- krb5_pa_pk_as_req_draft9 *var)
|
||||
-{
|
||||
- int p = TRUE;
|
||||
- if (ref == var) return TRUE;
|
||||
- else if (ref == NULL || var == NULL) return FALSE;
|
||||
- p = p && equal_str(signedAuthPack);
|
||||
- p = p && equal_str(kdcCert);
|
||||
- return p;
|
||||
-}
|
||||
-
|
||||
static int
|
||||
ktest_equal_dh_rep_info(krb5_dh_rep_info *ref, krb5_dh_rep_info *var)
|
||||
{
|
||||
@@ -996,19 +970,6 @@ ktest_equal_auth_pack(krb5_auth_pack *ref, krb5_auth_pack *var)
|
||||
return p;
|
||||
}
|
||||
|
||||
-int
|
||||
-ktest_equal_auth_pack_draft9(krb5_auth_pack_draft9 *ref,
|
||||
- krb5_auth_pack_draft9 *var)
|
||||
-{
|
||||
- int p = TRUE;
|
||||
- if (ref == var) return TRUE;
|
||||
- else if (ref == NULL || var == NULL) return FALSE;
|
||||
- p = p && struct_equal(pkAuthenticator,
|
||||
- ktest_equal_pk_authenticator_draft9);
|
||||
- p = p && ptr_equal(clientPublicValue, ktest_equal_subject_pk_info);
|
||||
- return p;
|
||||
-}
|
||||
-
|
||||
int
|
||||
ktest_equal_kdc_dh_key_info(krb5_kdc_dh_key_info *ref,
|
||||
krb5_kdc_dh_key_info *var)
|
||||
@@ -1033,18 +994,6 @@ ktest_equal_reply_key_pack(krb5_reply_key_pack *ref, krb5_reply_key_pack *var)
|
||||
return p;
|
||||
}
|
||||
|
||||
-int
|
||||
-ktest_equal_reply_key_pack_draft9(krb5_reply_key_pack_draft9 *ref,
|
||||
- krb5_reply_key_pack_draft9 *var)
|
||||
-{
|
||||
- int p = TRUE;
|
||||
- if (ref == var) return TRUE;
|
||||
- else if (ref == NULL || var == NULL) return FALSE;
|
||||
- p = p && struct_equal(replyKey, ktest_equal_keyblock);
|
||||
- p = p && scalar_equal(nonce);
|
||||
- return p;
|
||||
-}
|
||||
-
|
||||
#endif /* not DISABLE_PKINIT */
|
||||
|
||||
int
|
||||
diff --git a/src/tests/asn.1/ktest_equal.h b/src/tests/asn.1/ktest_equal.h
|
||||
index cfa82ac6e..80a0d781a 100644
|
||||
--- a/src/tests/asn.1/ktest_equal.h
|
||||
+++ b/src/tests/asn.1/ktest_equal.h
|
||||
@@ -139,13 +139,10 @@ int ktest_equal_ldap_sequence_of_keys(ldap_seqof_key_data *ref,
|
||||
|
||||
#ifndef DISABLE_PKINIT
|
||||
generic(ktest_equal_pa_pk_as_req, krb5_pa_pk_as_req);
|
||||
-generic(ktest_equal_pa_pk_as_req_draft9, krb5_pa_pk_as_req_draft9);
|
||||
generic(ktest_equal_pa_pk_as_rep, krb5_pa_pk_as_rep);
|
||||
generic(ktest_equal_auth_pack, krb5_auth_pack);
|
||||
-generic(ktest_equal_auth_pack_draft9, krb5_auth_pack_draft9);
|
||||
generic(ktest_equal_kdc_dh_key_info, krb5_kdc_dh_key_info);
|
||||
generic(ktest_equal_reply_key_pack, krb5_reply_key_pack);
|
||||
-generic(ktest_equal_reply_key_pack_draft9, krb5_reply_key_pack_draft9);
|
||||
#endif /* not DISABLE_PKINIT */
|
||||
|
||||
int ktest_equal_kkdcp_message(krb5_kkdcp_message *ref,
|
||||
diff --git a/src/tests/asn.1/pkinit_encode.out b/src/tests/asn.1/pkinit_encode.out
|
||||
index 55a60bbef..9bd08e159 100644
|
||||
--- a/src/tests/asn.1/pkinit_encode.out
|
||||
+++ b/src/tests/asn.1/pkinit_encode.out
|
||||
@@ -1,13 +1,8 @@
|
||||
encode_krb5_pa_pk_as_req: 30 38 80 08 6B 72 62 35 64 61 74 61 A1 22 30 20 30 1E 80 08 6B 72 62 35 64 61 74 61 81 08 6B 72 62 35 64 61 74 61 82 08 6B 72 62 35 64 61 74 61 82 08 6B 72 62 35 64 61 74 61
|
||||
-encode_krb5_pa_pk_as_req_draft9: 30 14 80 08 6B 72 62 35 64 61 74 61 82 08 6B 72 62 35 64 61 74 61
|
||||
encode_krb5_pa_pk_as_rep(dhInfo): A0 28 30 26 80 08 6B 72 62 35 64 61 74 61 A1 0A 04 08 6B 72 62 35 64 61 74 61 A2 0E 30 0C A0 0A 06 08 6B 72 62 35 64 61 74 61
|
||||
encode_krb5_pa_pk_as_rep(encKeyPack): 81 08 6B 72 62 35 64 61 74 61
|
||||
-encode_krb5_pa_pk_as_rep_draft9(dhSignedData): 80 08 6B 72 62 35 64 61 74 61
|
||||
-encode_krb5_pa_pk_as_rep_draft9(encKeyPack): 81 08 6B 72 62 35 64 61 74 61
|
||||
encode_krb5_auth_pack: 30 81 9F A0 35 30 33 A0 05 02 03 01 E2 40 A1 11 18 0F 31 39 39 34 30 36 31 30 30 36 30 33 31 37 5A A2 03 02 01 2A A3 06 04 04 31 32 33 34 A4 0A 04 08 6B 72 62 35 64 61 74 61 A1 22 30 20 30 13 06 09 2A 86 48 86 F7 12 01 02 02 04 06 70 61 72 61 6D 73 03 09 00 6B 72 62 35 64 61 74 61 A2 24 30 22 30 13 06 09 2A 86 48 86 F7 12 01 02 02 04 06 70 61 72 61 6D 73 30 0B 06 09 2A 86 48 86 F7 12 01 02 02 A3 0A 04 08 6B 72 62 35 64 61 74 61 A4 10 30 0E 30 0C A0 0A 06 08 6B 72 62 35 64 61 74 61
|
||||
-encode_krb5_auth_pack_draft9: 30 75 A0 4F 30 4D A0 1A 30 18 A0 03 02 01 01 A1 11 30 0F 1B 06 68 66 74 73 61 69 1B 05 65 78 74 72 61 A1 10 1B 0E 41 54 48 45 4E 41 2E 4D 49 54 2E 45 44 55 A2 05 02 03 01 E2 40 A3 11 18 0F 31 39 39 34 30 36 31 30 30 36 30 33 31 37 5A A4 03 02 01 2A A1 22 30 20 30 13 06 09 2A 86 48 86 F7 12 01 02 02 04 06 70 61 72 61 6D 73 03 09 00 6B 72 62 35 64 61 74 61
|
||||
encode_krb5_kdc_dh_key_info: 30 25 A0 0B 03 09 00 6B 72 62 35 64 61 74 61 A1 03 02 01 2A A2 11 18 0F 31 39 39 34 30 36 31 30 30 36 30 33 31 37 5A
|
||||
encode_krb5_reply_key_pack: 30 26 A0 13 30 11 A0 03 02 01 01 A1 0A 04 08 31 32 33 34 35 36 37 38 A1 0F 30 0D A0 03 02 01 01 A1 06 04 04 31 32 33 34
|
||||
-encode_krb5_reply_key_pack_draft9: 30 1A A0 13 30 11 A0 03 02 01 01 A1 0A 04 08 31 32 33 34 35 36 37 38 A1 03 02 01 2A
|
||||
encode_krb5_sp80056a_other_info: 30 81 81 30 0B 06 09 2A 86 48 86 F7 12 01 02 02 A0 32 04 30 30 2E A0 10 1B 0E 41 54 48 45 4E 41 2E 4D 49 54 2E 45 44 55 A1 1A 30 18 A0 03 02 01 01 A1 11 30 0F 1B 06 68 66 74 73 61 69 1B 05 65 78 74 72 61 A1 32 04 30 30 2E A0 10 1B 0E 41 54 48 45 4E 41 2E 4D 49 54 2E 45 44 55 A1 1A 30 18 A0 03 02 01 01 A1 11 30 0F 1B 06 68 66 74 73 61 69 1B 05 65 78 74 72 61 A2 0A 04 08 6B 72 62 35 64 61 74 61
|
||||
encode_krb5_pkinit_supp_pub_info: 30 1D A0 03 02 01 14 A1 0A 04 08 6B 72 62 35 64 61 74 61 A2 0A 04 08 6B 72 62 35 64 61 74 61
|
||||
diff --git a/src/tests/asn.1/pkinit_trval.out b/src/tests/asn.1/pkinit_trval.out
|
||||
index 9557188a8..3675fba38 100644
|
||||
--- a/src/tests/asn.1/pkinit_trval.out
|
||||
+++ b/src/tests/asn.1/pkinit_trval.out
|
||||
@@ -15,14 +15,6 @@ encode_krb5_pa_pk_as_req:
|
||||
. [2] <8>
|
||||
6b 72 62 35 64 61 74 61 krb5data
|
||||
|
||||
-encode_krb5_pa_pk_as_req_draft9:
|
||||
-
|
||||
-[Sequence/Sequence Of]
|
||||
-. [0] <8>
|
||||
- 6b 72 62 35 64 61 74 61 krb5data
|
||||
-. [2] <8>
|
||||
- 6b 72 62 35 64 61 74 61 krb5data
|
||||
-
|
||||
encode_krb5_pa_pk_as_rep(dhInfo):
|
||||
|
||||
[CONT 0]
|
||||
@@ -36,16 +28,6 @@ encode_krb5_pa_pk_as_rep(dhInfo):
|
||||
|
||||
encode_krb5_pa_pk_as_rep(encKeyPack):
|
||||
|
||||
-[CONT 1] <8>
|
||||
- 6b 72 62 35 64 61 74 61 krb5data
|
||||
-
|
||||
-encode_krb5_pa_pk_as_rep_draft9(dhSignedData):
|
||||
-
|
||||
-[CONT 0] <8>
|
||||
- 6b 72 62 35 64 61 74 61 krb5data
|
||||
-
|
||||
-encode_krb5_pa_pk_as_rep_draft9(encKeyPack):
|
||||
-
|
||||
[CONT 1] <8>
|
||||
6b 72 62 35 64 61 74 61 krb5data
|
||||
|
||||
@@ -79,27 +61,6 @@ encode_krb5_auth_pack:
|
||||
. . . [0] [Object Identifier] <8>
|
||||
6b 72 62 35 64 61 74 61 krb5data
|
||||
|
||||
-encode_krb5_auth_pack_draft9:
|
||||
-
|
||||
-[Sequence/Sequence Of]
|
||||
-. [0] [Sequence/Sequence Of]
|
||||
-. . [0] [Sequence/Sequence Of]
|
||||
-. . . [0] [Integer] 1
|
||||
-. . . [1] [Sequence/Sequence Of]
|
||||
-. . . . [General string] "hftsai"
|
||||
-. . . . [General string] "extra"
|
||||
-. . [1] [General string] "ATHENA.MIT.EDU"
|
||||
-. . [2] [Integer] 123456
|
||||
-. . [3] [Generalized Time] "19940610060317Z"
|
||||
-. . [4] [Integer] 42
|
||||
-. [1] [Sequence/Sequence Of]
|
||||
-. . [Sequence/Sequence Of]
|
||||
-. . . [Object Identifier] <9>
|
||||
- 2a 86 48 86 f7 12 01 02 02 *.H......
|
||||
-. . . [Octet String] "params"
|
||||
-. . [Bit String] <9>
|
||||
- 00 6b 72 62 35 64 61 74 61 .krb5data
|
||||
-
|
||||
encode_krb5_kdc_dh_key_info:
|
||||
|
||||
[Sequence/Sequence Of]
|
||||
@@ -118,14 +79,6 @@ encode_krb5_reply_key_pack:
|
||||
. . [0] [Integer] 1
|
||||
. . [1] [Octet String] "1234"
|
||||
|
||||
-encode_krb5_reply_key_pack_draft9:
|
||||
-
|
||||
-[Sequence/Sequence Of]
|
||||
-. [0] [Sequence/Sequence Of]
|
||||
-. . [0] [Integer] 1
|
||||
-. . [1] [Octet String] "12345678"
|
||||
-. [1] [Integer] 42
|
||||
-
|
||||
encode_krb5_sp80056a_other_info:
|
||||
|
||||
[Sequence/Sequence Of]
|
||||
File diff suppressed because it is too large
Load diff
|
|
@ -1,34 +0,0 @@
|
|||
From 68fdf968da2ed338340a835a0c942991c7c02986 Mon Sep 17 00:00:00 2001
|
||||
From: Robbie Harwood <rharwood@redhat.com>
|
||||
Date: Wed, 3 Apr 2019 16:01:22 -0400
|
||||
Subject: [PATCH] Remove ccapi-related comments in configure.ac
|
||||
|
||||
These suggested ccapi is buildable on non-Windows, and empirically it
|
||||
is not.
|
||||
|
||||
(cherry picked from commit eb48b176bccf3634b9c82f588dce85125a5c4bd8)
|
||||
---
|
||||
src/configure.in | 3 ---
|
||||
1 file changed, 3 deletions(-)
|
||||
|
||||
diff --git a/src/configure.in b/src/configure.in
|
||||
index 7c309a26b..8d781a7c8 100644
|
||||
--- a/src/configure.in
|
||||
+++ b/src/configure.in
|
||||
@@ -1450,7 +1450,6 @@ V5_AC_OUTPUT_MAKEFILE(.
|
||||
lib/crypto/crypto_tests
|
||||
|
||||
lib/krb5 lib/krb5/error_tables lib/krb5/asn.1 lib/krb5/ccache
|
||||
-dnl lib/krb5/ccache/ccapi
|
||||
lib/krb5/keytab lib/krb5/krb lib/krb5/rcache lib/krb5/os
|
||||
lib/krb5/unicode
|
||||
|
||||
@@ -1463,8 +1462,6 @@ dnl lib/krb5/ccache/ccapi
|
||||
lib/krad
|
||||
lib/apputils
|
||||
|
||||
-dnl ccapi ccapi/lib ccapi/lib/unix ccapi/server ccapi/server/unix ccapi/test
|
||||
-
|
||||
kdc kprop config-files build-tools man doc include
|
||||
|
||||
plugins/certauth/test
|
||||
|
|
@ -1,428 +0,0 @@
|
|||
From 46aa5ffd844a280f368d78c7c395bb1b2323dfbe Mon Sep 17 00:00:00 2001
|
||||
From: Robbie Harwood <rharwood@redhat.com>
|
||||
Date: Mon, 13 May 2019 14:19:57 -0400
|
||||
Subject: [PATCH] Remove checksum type profile variables
|
||||
|
||||
Remove support for the krb5.conf relations ap_req_checksum_type,
|
||||
kdc_req_checksum_type, and safe_checksum_type. These values were
|
||||
useful for interoperating with very old KDCs, which should no longer
|
||||
be deployed.
|
||||
|
||||
Additionally, kdc_req_checksum_type was incorrectly documented as only
|
||||
applying to single-DES keys; in practice it also worked for RC4. The
|
||||
other two were not clearly documented, but safe_checksum_type did
|
||||
allow use of hmac-md5-rc4 for any enctype, and ap_req_checksum_type
|
||||
did not impose any limitations.
|
||||
|
||||
[ghudson@mit.edu: edited commit message]
|
||||
|
||||
ticket: 8804 (new)
|
||||
(cherry picked from commit a5a140dc85201faf1ba3a687553058354722a1b4)
|
||||
---
|
||||
doc/admin/conf_files/krb5_conf.rst | 37 ------------
|
||||
src/include/k5-int.h | 6 --
|
||||
src/lib/krb5/krb/auth_con.c | 2 -
|
||||
src/lib/krb5/krb/init_ctx.c | 13 -----
|
||||
src/lib/krb5/krb/send_tgs.c | 19 +------
|
||||
src/lib/krb5/krb/ser_ctx.c | 38 +------------
|
||||
src/lib/krb5/krb/t_copy_context.c | 6 --
|
||||
src/man/krb5.conf.man | 90 ++----------------------------
|
||||
8 files changed, 7 insertions(+), 204 deletions(-)
|
||||
|
||||
diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst
|
||||
index e9f7e8c59..5df3bfe36 100644
|
||||
--- a/doc/admin/conf_files/krb5_conf.rst
|
||||
+++ b/doc/admin/conf_files/krb5_conf.rst
|
||||
@@ -111,14 +111,6 @@ The libdefaults section may contain any of the following relations:
|
||||
strong crypto. Users in affected environments should set this tag
|
||||
to true until their infrastructure adopts stronger ciphers.
|
||||
|
||||
-**ap_req_checksum_type**
|
||||
- An integer which specifies the type of AP-REQ checksum to use in
|
||||
- authenticators. This variable should be unset so the appropriate
|
||||
- checksum for the encryption key in use will be used. This can be
|
||||
- set if backward compatibility requires a specific checksum type.
|
||||
- See the **kdc_req_checksum_type** configuration option for the
|
||||
- possible values and their meanings.
|
||||
-
|
||||
**canonicalize**
|
||||
If this flag is set to true, initial ticket requests to the KDC
|
||||
will request canonicalization of the client principal name, and
|
||||
@@ -297,26 +289,6 @@ The libdefaults section may contain any of the following relations:
|
||||
corrective factor is only used by the Kerberos library; it is not
|
||||
used to change the system clock. The default value is 1.
|
||||
|
||||
-**kdc_req_checksum_type**
|
||||
- An integer which specifies the type of checksum to use for the KDC
|
||||
- requests, for compatibility with very old KDC implementations.
|
||||
- This value is only used for DES keys; other keys use the preferred
|
||||
- checksum type for those keys.
|
||||
-
|
||||
- The possible values and their meanings are as follows.
|
||||
-
|
||||
- ======== ===============================
|
||||
- 1 CRC32
|
||||
- 2 RSA MD4
|
||||
- 3 RSA MD4 DES
|
||||
- 4 DES CBC
|
||||
- 7 RSA MD5
|
||||
- 8 RSA MD5 DES
|
||||
- 9 NIST SHA
|
||||
- 12 HMAC SHA1 DES3
|
||||
- -138 Microsoft MD5 HMAC checksum type
|
||||
- ======== ===============================
|
||||
-
|
||||
**noaddresses**
|
||||
If this flag is true, requests for initial tickets will not be
|
||||
made with address restrictions set, allowing the tickets to be
|
||||
@@ -365,15 +337,6 @@ The libdefaults section may contain any of the following relations:
|
||||
(:ref:`duration` string.) Sets the default renewable lifetime
|
||||
for initial ticket requests. The default value is 0.
|
||||
|
||||
-**safe_checksum_type**
|
||||
- An integer which specifies the type of checksum to use for the
|
||||
- KRB-SAFE requests. By default it is set to 8 (RSA MD5 DES). For
|
||||
- compatibility with applications linked against DCE version 1.1 or
|
||||
- earlier Kerberos libraries, use a value of 3 to use the RSA MD4
|
||||
- DES instead. This field is ignored when its value is incompatible
|
||||
- with the session key type. See the **kdc_req_checksum_type**
|
||||
- configuration option for the possible values and their meanings.
|
||||
-
|
||||
**spake_preauth_groups**
|
||||
A whitespace or comma-separated list of words which specifies the
|
||||
groups allowed for SPAKE preauthentication. The possible values
|
||||
diff --git a/src/include/k5-int.h b/src/include/k5-int.h
|
||||
index 1e6a739e9..1a78fd7a9 100644
|
||||
--- a/src/include/k5-int.h
|
||||
+++ b/src/include/k5-int.h
|
||||
@@ -182,7 +182,6 @@ typedef unsigned char u_char;
|
||||
#define KRB5_CONF_ACL_FILE "acl_file"
|
||||
#define KRB5_CONF_ADMIN_SERVER "admin_server"
|
||||
#define KRB5_CONF_ALLOW_WEAK_CRYPTO "allow_weak_crypto"
|
||||
-#define KRB5_CONF_AP_REQ_CHECKSUM_TYPE "ap_req_checksum_type"
|
||||
#define KRB5_CONF_AUTH_TO_LOCAL "auth_to_local"
|
||||
#define KRB5_CONF_AUTH_TO_LOCAL_NAMES "auth_to_local_names"
|
||||
#define KRB5_CONF_CANONICALIZE "canonicalize"
|
||||
@@ -241,7 +240,6 @@ typedef unsigned char u_char;
|
||||
#define KRB5_CONF_KDC_LISTEN "kdc_listen"
|
||||
#define KRB5_CONF_KDC_MAX_DGRAM_REPLY_SIZE "kdc_max_dgram_reply_size"
|
||||
#define KRB5_CONF_KDC_PORTS "kdc_ports"
|
||||
-#define KRB5_CONF_KDC_REQ_CHECKSUM_TYPE "kdc_req_checksum_type"
|
||||
#define KRB5_CONF_KDC_TCP_PORTS "kdc_tcp_ports"
|
||||
#define KRB5_CONF_KDC_TCP_LISTEN "kdc_tcp_listen"
|
||||
#define KRB5_CONF_KDC_TCP_LISTEN_BACKLOG "kdc_tcp_listen_backlog"
|
||||
@@ -289,7 +287,6 @@ typedef unsigned char u_char;
|
||||
#define KRB5_CONF_REJECT_BAD_TRANSIT "reject_bad_transit"
|
||||
#define KRB5_CONF_RENEW_LIFETIME "renew_lifetime"
|
||||
#define KRB5_CONF_RESTRICT_ANONYMOUS_TO_TGT "restrict_anonymous_to_tgt"
|
||||
-#define KRB5_CONF_SAFE_CHECKSUM_TYPE "safe_checksum_type"
|
||||
#define KRB5_CONF_SUPPORTED_ENCTYPES "supported_enctypes"
|
||||
#define KRB5_CONF_SPAKE_PREAUTH_INDICATOR "spake_preauth_indicator"
|
||||
#define KRB5_CONF_SPAKE_PREAUTH_KDC_CHALLENGE "spake_preauth_kdc_challenge"
|
||||
@@ -1185,9 +1182,6 @@ struct _krb5_context {
|
||||
void *ser_ctx;
|
||||
/* allowable clock skew */
|
||||
krb5_deltat clockskew;
|
||||
- krb5_cksumtype kdc_req_sumtype;
|
||||
- krb5_cksumtype default_ap_req_sumtype;
|
||||
- krb5_cksumtype default_safe_sumtype;
|
||||
krb5_flags kdc_default_options;
|
||||
krb5_flags library_options;
|
||||
krb5_boolean profile_secure;
|
||||
diff --git a/src/lib/krb5/krb/auth_con.c b/src/lib/krb5/krb/auth_con.c
|
||||
index c86a4af63..1dfce631c 100644
|
||||
--- a/src/lib/krb5/krb/auth_con.c
|
||||
+++ b/src/lib/krb5/krb/auth_con.c
|
||||
@@ -40,8 +40,6 @@ krb5_auth_con_init(krb5_context context, krb5_auth_context *auth_context)
|
||||
(*auth_context)->auth_context_flags =
|
||||
KRB5_AUTH_CONTEXT_DO_TIME | KRB5_AUTH_CONN_INITIALIZED;
|
||||
|
||||
- (*auth_context)->req_cksumtype = context->default_ap_req_sumtype;
|
||||
- (*auth_context)->safe_cksumtype = context->default_safe_sumtype;
|
||||
(*auth_context)->checksum_func = NULL;
|
||||
(*auth_context)->checksum_func_data = NULL;
|
||||
(*auth_context)->negotiated_etype = ENCTYPE_NULL;
|
||||
diff --git a/src/lib/krb5/krb/init_ctx.c b/src/lib/krb5/krb/init_ctx.c
|
||||
index d263d5cc5..37405728c 100644
|
||||
--- a/src/lib/krb5/krb/init_ctx.c
|
||||
+++ b/src/lib/krb5/krb/init_ctx.c
|
||||
@@ -258,19 +258,6 @@ krb5_init_context_profile(profile_t profile, krb5_flags flags,
|
||||
get_integer(ctx, KRB5_CONF_CLOCKSKEW, DEFAULT_CLOCKSKEW, &tmp);
|
||||
ctx->clockskew = tmp;
|
||||
|
||||
- /* DCE 1.1 and below only support CKSUMTYPE_RSA_MD4 (2) */
|
||||
- /* DCE add kdc_req_checksum_type = 2 to krb5.conf */
|
||||
- get_integer(ctx, KRB5_CONF_KDC_REQ_CHECKSUM_TYPE, CKSUMTYPE_RSA_MD5,
|
||||
- &tmp);
|
||||
- ctx->kdc_req_sumtype = tmp;
|
||||
-
|
||||
- get_integer(ctx, KRB5_CONF_AP_REQ_CHECKSUM_TYPE, 0, &tmp);
|
||||
- ctx->default_ap_req_sumtype = tmp;
|
||||
-
|
||||
- get_integer(ctx, KRB5_CONF_SAFE_CHECKSUM_TYPE, CKSUMTYPE_RSA_MD5_DES,
|
||||
- &tmp);
|
||||
- ctx->default_safe_sumtype = tmp;
|
||||
-
|
||||
get_integer(ctx, KRB5_CONF_KDC_DEFAULT_OPTIONS, KDC_OPT_RENEWABLE_OK,
|
||||
&tmp);
|
||||
ctx->kdc_default_options = tmp;
|
||||
diff --git a/src/lib/krb5/krb/send_tgs.c b/src/lib/krb5/krb/send_tgs.c
|
||||
index e43a5cc5b..3dda2fdaa 100644
|
||||
--- a/src/lib/krb5/krb/send_tgs.c
|
||||
+++ b/src/lib/krb5/krb/send_tgs.c
|
||||
@@ -53,7 +53,6 @@ tgs_construct_ap_req(krb5_context context, krb5_data *checksum_data,
|
||||
krb5_creds *tgt, krb5_keyblock *subkey,
|
||||
krb5_data **ap_req_asn1_out)
|
||||
{
|
||||
- krb5_cksumtype cksumtype;
|
||||
krb5_error_code ret;
|
||||
krb5_checksum checksum;
|
||||
krb5_authenticator authent;
|
||||
@@ -67,24 +66,8 @@ tgs_construct_ap_req(krb5_context context, krb5_data *checksum_data,
|
||||
memset(&ap_req, 0, sizeof(ap_req));
|
||||
memset(&authent_enc, 0, sizeof(authent_enc));
|
||||
|
||||
- /* Determine the authenticator checksum type. */
|
||||
- switch (tgt->keyblock.enctype) {
|
||||
- case ENCTYPE_DES_CBC_CRC:
|
||||
- case ENCTYPE_DES_CBC_MD4:
|
||||
- case ENCTYPE_DES_CBC_MD5:
|
||||
- case ENCTYPE_ARCFOUR_HMAC:
|
||||
- case ENCTYPE_ARCFOUR_HMAC_EXP:
|
||||
- cksumtype = context->kdc_req_sumtype;
|
||||
- break;
|
||||
- default:
|
||||
- ret = krb5int_c_mandatory_cksumtype(context, tgt->keyblock.enctype,
|
||||
- &cksumtype);
|
||||
- if (ret)
|
||||
- goto cleanup;
|
||||
- }
|
||||
-
|
||||
/* Generate checksum. */
|
||||
- ret = krb5_c_make_checksum(context, cksumtype, &tgt->keyblock,
|
||||
+ ret = krb5_c_make_checksum(context, 0, &tgt->keyblock,
|
||||
KRB5_KEYUSAGE_TGS_REQ_AUTH_CKSUM, checksum_data,
|
||||
&checksum);
|
||||
if (ret)
|
||||
diff --git a/src/lib/krb5/krb/ser_ctx.c b/src/lib/krb5/krb/ser_ctx.c
|
||||
index a9f50b239..39f656322 100644
|
||||
--- a/src/lib/krb5/krb/ser_ctx.c
|
||||
+++ b/src/lib/krb5/krb/ser_ctx.c
|
||||
@@ -124,9 +124,6 @@ krb5_context_size(krb5_context kcontext, krb5_pointer arg, size_t *sizep)
|
||||
* krb5_int32 for n_tgs_etypes*sizeof(krb5_int32)
|
||||
* nktypes*sizeof(krb5_int32) for tgs_etypes.
|
||||
* krb5_int32 for clockskew
|
||||
- * krb5_int32 for kdc_req_sumtype
|
||||
- * krb5_int32 for ap_req_sumtype
|
||||
- * krb5_int32 for safe_sumtype
|
||||
* krb5_int32 for kdc_default_options
|
||||
* krb5_int32 for library_options
|
||||
* krb5_int32 for profile_secure
|
||||
@@ -139,7 +136,7 @@ krb5_context_size(krb5_context kcontext, krb5_pointer arg, size_t *sizep)
|
||||
kret = EINVAL;
|
||||
if ((context = (krb5_context) arg)) {
|
||||
/* Calculate base length */
|
||||
- required = (14 * sizeof(krb5_int32) +
|
||||
+ required = (11 * sizeof(krb5_int32) +
|
||||
(etypes_len(context->in_tkt_etypes) * sizeof(krb5_int32)) +
|
||||
(etypes_len(context->tgs_etypes) * sizeof(krb5_int32)));
|
||||
|
||||
@@ -255,24 +252,6 @@ krb5_context_externalize(krb5_context kcontext, krb5_pointer arg, krb5_octet **b
|
||||
if (kret)
|
||||
return (kret);
|
||||
|
||||
- /* Now kdc_req_sumtype */
|
||||
- kret = krb5_ser_pack_int32((krb5_int32) context->kdc_req_sumtype,
|
||||
- &bp, &remain);
|
||||
- if (kret)
|
||||
- return (kret);
|
||||
-
|
||||
- /* Now default ap_req_sumtype */
|
||||
- kret = krb5_ser_pack_int32((krb5_int32) context->default_ap_req_sumtype,
|
||||
- &bp, &remain);
|
||||
- if (kret)
|
||||
- return (kret);
|
||||
-
|
||||
- /* Now default safe_sumtype */
|
||||
- kret = krb5_ser_pack_int32((krb5_int32) context->default_safe_sumtype,
|
||||
- &bp, &remain);
|
||||
- if (kret)
|
||||
- return (kret);
|
||||
-
|
||||
/* Now kdc_default_options */
|
||||
kret = krb5_ser_pack_int32((krb5_int32) context->kdc_default_options,
|
||||
&bp, &remain);
|
||||
@@ -426,21 +405,6 @@ krb5_context_internalize(krb5_context kcontext, krb5_pointer *argp, krb5_octet *
|
||||
goto cleanup;
|
||||
context->clockskew = (krb5_deltat) ibuf;
|
||||
|
||||
- /* kdc_req_sumtype */
|
||||
- if ((kret = krb5_ser_unpack_int32(&ibuf, &bp, &remain)))
|
||||
- goto cleanup;
|
||||
- context->kdc_req_sumtype = (krb5_cksumtype) ibuf;
|
||||
-
|
||||
- /* default ap_req_sumtype */
|
||||
- if ((kret = krb5_ser_unpack_int32(&ibuf, &bp, &remain)))
|
||||
- goto cleanup;
|
||||
- context->default_ap_req_sumtype = (krb5_cksumtype) ibuf;
|
||||
-
|
||||
- /* default_safe_sumtype */
|
||||
- if ((kret = krb5_ser_unpack_int32(&ibuf, &bp, &remain)))
|
||||
- goto cleanup;
|
||||
- context->default_safe_sumtype = (krb5_cksumtype) ibuf;
|
||||
-
|
||||
/* kdc_default_options */
|
||||
if ((kret = krb5_ser_unpack_int32(&ibuf, &bp, &remain)))
|
||||
goto cleanup;
|
||||
diff --git a/src/lib/krb5/krb/t_copy_context.c b/src/lib/krb5/krb/t_copy_context.c
|
||||
index a6e48cd25..22be2198b 100644
|
||||
--- a/src/lib/krb5/krb/t_copy_context.c
|
||||
+++ b/src/lib/krb5/krb/t_copy_context.c
|
||||
@@ -77,9 +77,6 @@ check_context(krb5_context c, krb5_context r)
|
||||
check(c->os_context.os_flags == r->os_context.os_flags);
|
||||
compare_string(c->os_context.default_ccname, r->os_context.default_ccname);
|
||||
check(c->clockskew == r->clockskew);
|
||||
- check(c->kdc_req_sumtype == r->kdc_req_sumtype);
|
||||
- check(c->default_ap_req_sumtype == r->default_ap_req_sumtype);
|
||||
- check(c->default_safe_sumtype == r->default_safe_sumtype);
|
||||
check(c->kdc_default_options == r->kdc_default_options);
|
||||
check(c->library_options == r->library_options);
|
||||
check(c->profile_secure == r->profile_secure);
|
||||
@@ -136,9 +133,6 @@ main(int argc, char **argv)
|
||||
check(krb5_cc_set_default_name(ctx, "defccname") == 0);
|
||||
check(krb5_set_default_realm(ctx, "defrealm") == 0);
|
||||
ctx->clockskew = 18;
|
||||
- ctx->kdc_req_sumtype = CKSUMTYPE_NIST_SHA;
|
||||
- ctx->default_ap_req_sumtype = CKSUMTYPE_HMAC_SHA1_96_AES128;
|
||||
- ctx->default_safe_sumtype = CKSUMTYPE_HMAC_SHA1_96_AES256;
|
||||
ctx->kdc_default_options = KDC_OPT_FORWARDABLE;
|
||||
ctx->library_options = 0;
|
||||
ctx->profile_secure = TRUE;
|
||||
diff --git a/src/man/krb5.conf.man b/src/man/krb5.conf.man
|
||||
index d431dce75..aafdf7f83 100644
|
||||
--- a/src/man/krb5.conf.man
|
||||
+++ b/src/man/krb5.conf.man
|
||||
@@ -1,6 +1,6 @@
|
||||
.\" Man page generated from reStructuredText.
|
||||
.
|
||||
-.TH "KRB5.CONF" "5" " " "1.17" "MIT Kerberos"
|
||||
+.TH "KRB5.CONF" "5" " " "1.18" "MIT Kerberos"
|
||||
.SH NAME
|
||||
krb5.conf \- Kerberos configuration file
|
||||
.
|
||||
@@ -202,14 +202,6 @@ failures in existing Kerberos infrastructures that do not support
|
||||
strong crypto. Users in affected environments should set this tag
|
||||
to true until their infrastructure adopts stronger ciphers.
|
||||
.TP
|
||||
-\fBap_req_checksum_type\fP
|
||||
-An integer which specifies the type of AP\-REQ checksum to use in
|
||||
-authenticators. This variable should be unset so the appropriate
|
||||
-checksum for the encryption key in use will be used. This can be
|
||||
-set if backward compatibility requires a specific checksum type.
|
||||
-See the \fBkdc_req_checksum_type\fP configuration option for the
|
||||
-possible values and their meanings.
|
||||
-.TP
|
||||
\fBcanonicalize\fP
|
||||
If this flag is set to true, initial ticket requests to the KDC
|
||||
will request canonicalization of the client principal name, and
|
||||
@@ -291,6 +283,10 @@ hostnames for use in service principal names. Setting this flag
|
||||
to false can improve security by reducing reliance on DNS, but
|
||||
means that short hostnames will not be canonicalized to
|
||||
fully\-qualified hostnames. The default value is true.
|
||||
+.sp
|
||||
+If this option is set to \fBfallback\fP (new in release 1.18), DNS
|
||||
+canonicalization will only be performed the server hostname is not
|
||||
+found with the original name when requesting credentials.
|
||||
.TP
|
||||
\fBdns_lookup_kdc\fP
|
||||
Indicate whether DNS SRV records should be used to locate the KDCs
|
||||
@@ -384,73 +380,6 @@ requesting service tickets or authenticating to services. This
|
||||
corrective factor is only used by the Kerberos library; it is not
|
||||
used to change the system clock. The default value is 1.
|
||||
.TP
|
||||
-\fBkdc_req_checksum_type\fP
|
||||
-An integer which specifies the type of checksum to use for the KDC
|
||||
-requests, for compatibility with very old KDC implementations.
|
||||
-This value is only used for DES keys; other keys use the preferred
|
||||
-checksum type for those keys.
|
||||
-.sp
|
||||
-The possible values and their meanings are as follows.
|
||||
-.TS
|
||||
-center;
|
||||
-|l|l|.
|
||||
-_
|
||||
-T{
|
||||
-1
|
||||
-T} T{
|
||||
-CRC32
|
||||
-T}
|
||||
-_
|
||||
-T{
|
||||
-2
|
||||
-T} T{
|
||||
-RSA MD4
|
||||
-T}
|
||||
-_
|
||||
-T{
|
||||
-3
|
||||
-T} T{
|
||||
-RSA MD4 DES
|
||||
-T}
|
||||
-_
|
||||
-T{
|
||||
-4
|
||||
-T} T{
|
||||
-DES CBC
|
||||
-T}
|
||||
-_
|
||||
-T{
|
||||
-7
|
||||
-T} T{
|
||||
-RSA MD5
|
||||
-T}
|
||||
-_
|
||||
-T{
|
||||
-8
|
||||
-T} T{
|
||||
-RSA MD5 DES
|
||||
-T}
|
||||
-_
|
||||
-T{
|
||||
-9
|
||||
-T} T{
|
||||
-NIST SHA
|
||||
-T}
|
||||
-_
|
||||
-T{
|
||||
-12
|
||||
-T} T{
|
||||
-HMAC SHA1 DES3
|
||||
-T}
|
||||
-_
|
||||
-T{
|
||||
-\-138
|
||||
-T} T{
|
||||
-Microsoft MD5 HMAC checksum type
|
||||
-T}
|
||||
-_
|
||||
-.TE
|
||||
-.TP
|
||||
\fBnoaddresses\fP
|
||||
If this flag is true, requests for initial tickets will not be
|
||||
made with address restrictions set, allowing the tickets to be
|
||||
@@ -499,15 +428,6 @@ set. The default is not to search domain components.
|
||||
(duration string.) Sets the default renewable lifetime
|
||||
for initial ticket requests. The default value is 0.
|
||||
.TP
|
||||
-\fBsafe_checksum_type\fP
|
||||
-An integer which specifies the type of checksum to use for the
|
||||
-KRB\-SAFE requests. By default it is set to 8 (RSA MD5 DES). For
|
||||
-compatibility with applications linked against DCE version 1.1 or
|
||||
-earlier Kerberos libraries, use a value of 3 to use the RSA MD4
|
||||
-DES instead. This field is ignored when its value is incompatible
|
||||
-with the session key type. See the \fBkdc_req_checksum_type\fP
|
||||
-configuration option for the possible values and their meanings.
|
||||
-.TP
|
||||
\fBspake_preauth_groups\fP
|
||||
A whitespace or comma\-separated list of words which specifies the
|
||||
groups allowed for SPAKE preauthentication. The possible values
|
||||
|
|
@ -1,430 +0,0 @@
|
|||
From f7b50b3e40ae43666fb10b0a1502f9cd88b6a2fe Mon Sep 17 00:00:00 2001
|
||||
From: Robbie Harwood <rharwood@redhat.com>
|
||||
Date: Wed, 3 Apr 2019 14:58:19 -0400
|
||||
Subject: [PATCH] Remove confvalidator utility
|
||||
|
||||
This utility has not been maintained with encryption types and salt
|
||||
changes, which suggests it is unused.
|
||||
|
||||
(cherry picked from commit 482a366793d9338e9edb504b407d7704a4bb2f8f)
|
||||
---
|
||||
src/util/confvalidator/README | 25 ----
|
||||
src/util/confvalidator/confparser.py | 144 -------------------
|
||||
src/util/confvalidator/rules.yml | 13 --
|
||||
src/util/confvalidator/validator.conf | 2 -
|
||||
src/util/confvalidator/validator.py | 194 --------------------------
|
||||
5 files changed, 378 deletions(-)
|
||||
delete mode 100644 src/util/confvalidator/README
|
||||
delete mode 100644 src/util/confvalidator/confparser.py
|
||||
delete mode 100644 src/util/confvalidator/rules.yml
|
||||
delete mode 100644 src/util/confvalidator/validator.conf
|
||||
delete mode 100644 src/util/confvalidator/validator.py
|
||||
|
||||
diff --git a/src/util/confvalidator/README b/src/util/confvalidator/README
|
||||
deleted file mode 100644
|
||||
index 7bf7a106a..000000000
|
||||
--- a/src/util/confvalidator/README
|
||||
+++ /dev/null
|
||||
@@ -1,25 +0,0 @@
|
||||
-validator.py is a command line tool for identifying invalid attributes, values and some formating problems in Kerberos configuration files.
|
||||
-The list of the valid attributes is created based on the “configuration variables” section in k5-int.h and user defined attributes from the rules file.
|
||||
-
|
||||
-Usage:
|
||||
-
|
||||
-validator.py path [-d defPath] [-r rulesPath] [-c validatorConfPath]
|
||||
-
|
||||
-Options:
|
||||
-
|
||||
-path – the path to the configuration file to validate
|
||||
-
|
||||
--d defPath – path to the k5-int.h file. Starting from the 1.7 release this header holds the profile attribute names in the form #define KRB5_CONF_xxx ”ZZZ”.
|
||||
-
|
||||
--r rulesPath - path the rules file in yaml format. It may be used to manage the list of the valid attributes and to define the additional validation rules.
|
||||
-
|
||||
--c validatorConfPath – the same as -r and -d options, but in validator configuration file format.
|
||||
-
|
||||
-Example:
|
||||
-
|
||||
-python validator.py src/config-files/krb5.conf -r rules.yml -d src/include/k5-int.h
|
||||
-or
|
||||
-python validator.py src/config-files/krb5.conf -c validator.conf
|
||||
-
|
||||
-For more details please refer to the sample files validator.conf and rules.yml
|
||||
-
|
||||
diff --git a/src/util/confvalidator/confparser.py b/src/util/confvalidator/confparser.py
|
||||
deleted file mode 100644
|
||||
index 2fea142a5..000000000
|
||||
--- a/src/util/confvalidator/confparser.py
|
||||
+++ /dev/null
|
||||
@@ -1,144 +0,0 @@
|
||||
-'''
|
||||
-Created on Jan 31, 2010
|
||||
-
|
||||
-@author: tsitkova
|
||||
-'''
|
||||
-import re
|
||||
-import copy
|
||||
-import yaml
|
||||
-
|
||||
-class ConfParser(object):
|
||||
- def __init__(self, path):
|
||||
- self.configuration = self._parse(path)
|
||||
-
|
||||
- def walk(self):
|
||||
- for trio in self._walk(self.configuration):
|
||||
- yield trio
|
||||
-
|
||||
- def _parse(self, path):
|
||||
- comment_pattern = re.compile(r'(\s*[#].*)')
|
||||
- section_pattern = re.compile(r'^\s*\[(?P<section>\w+)\]\s+$')
|
||||
- empty_pattern = re.compile(r'^\s*$')
|
||||
- equalsign_pattern = re.compile(r'=')
|
||||
-
|
||||
- section = None
|
||||
- parser_stack = list()
|
||||
- result = dict()
|
||||
- value = None
|
||||
- f = open(path, 'r')
|
||||
- for (ln,line) in enumerate(f):
|
||||
- line = comment_pattern.sub('', line)
|
||||
- line = equalsign_pattern.sub(' = ',line,count=1)
|
||||
- if empty_pattern.match(line) is not None:
|
||||
- continue
|
||||
- m = section_pattern.match(line)
|
||||
- if m is not None:
|
||||
- section = m.group('section')
|
||||
- value = dict()
|
||||
- result[section] = value
|
||||
- continue
|
||||
- if section is None:
|
||||
- msg = 'Failed to determine section for line #%i' % ln
|
||||
- raise ValueError(msg)
|
||||
- try:
|
||||
- value = self._parseLine(value, line, parser_stack)
|
||||
- except:
|
||||
- print 'Error while parsing line %i: %s' % (ln+1, line)
|
||||
- raise
|
||||
- f.close()
|
||||
-
|
||||
- if len(parser_stack):
|
||||
- raise 'Parsing error.'
|
||||
-
|
||||
- return result
|
||||
-
|
||||
- def _parseLine(self, value, content, stack):
|
||||
- token_pattern = re.compile(r'(?P<token>\S+)(?=\s+)')
|
||||
- attr = None
|
||||
- token_stack = list()
|
||||
-
|
||||
- for m in token_pattern.finditer(content):
|
||||
- token = m.group('token')
|
||||
- if not self._validate(token):
|
||||
- raise ValueError('Invalid token %s' % token)
|
||||
- if token == '=':
|
||||
- if len(token_stack) == 0:
|
||||
- raise ValueError('Failed to find attribute.')
|
||||
- elif len(token_stack) == 1:
|
||||
- attr = token_stack.pop()
|
||||
- else:
|
||||
- value[attr] = token_stack[:-1]
|
||||
- attr = token_stack[-1]
|
||||
- token_stack = list()
|
||||
- elif token == '{':
|
||||
- if attr is None:
|
||||
- raise ValueError('Failed to find attribute.')
|
||||
- stack.append((attr,value))
|
||||
- value = dict()
|
||||
- elif token == '}':
|
||||
- if len(stack) == 0:
|
||||
- raise ValueError('Failed to parse: unbalanced braces')
|
||||
- if len(token_stack):
|
||||
- if attr is None:
|
||||
- raise ValueError('Missing attribute')
|
||||
- value[attr] = token_stack
|
||||
- attr = None
|
||||
- token_stack = list()
|
||||
- (attr,parent_value) = stack.pop()
|
||||
- parent_value[attr] = value
|
||||
- value = parent_value
|
||||
- else:
|
||||
- token_stack.append(token)
|
||||
- if len(token_stack):
|
||||
- if attr is None:
|
||||
- raise ValueError('Missing attribute')
|
||||
- value[attr] = token_stack
|
||||
-
|
||||
- return value
|
||||
-
|
||||
- def _validate(self, token):
|
||||
- result = True
|
||||
- for s in ['{','}']:
|
||||
- if s in token and s != token:
|
||||
- result = False
|
||||
-
|
||||
- return result
|
||||
-
|
||||
- def _walk(self, parsedData, path='root'):
|
||||
- dirs = list()
|
||||
- av = list()
|
||||
- for (key, value) in parsedData.iteritems():
|
||||
- if type(value) == dict:
|
||||
- new_path = path + '.' + key
|
||||
- for trio in self._walk(value, new_path):
|
||||
- yield trio
|
||||
- dirs.append(key)
|
||||
- else:
|
||||
- av.append((key,value))
|
||||
- yield (path, dirs, av)
|
||||
-
|
||||
-
|
||||
-
|
||||
-class ConfParserTest(ConfParser):
|
||||
- def __init__(self):
|
||||
- self.conf_path = '../tests/krb5.conf'
|
||||
- super(ConfParserTest, self).__init__(self.conf_path)
|
||||
-
|
||||
- def run_tests(self):
|
||||
- self._test_walk()
|
||||
-
|
||||
- def _test_parse(self):
|
||||
- result = self._parse(self.conf_path)
|
||||
- print yaml.dump(result)
|
||||
-
|
||||
- def _test_walk(self):
|
||||
- configuration = self._parse(self.conf_path)
|
||||
- for (path,dirs,av) in self.walk():
|
||||
- print path,dirs,av
|
||||
-
|
||||
-
|
||||
-
|
||||
-
|
||||
-if __name__ == '__main__':
|
||||
- tester = ConfParserTest()
|
||||
- tester.run_tests()
|
||||
diff --git a/src/util/confvalidator/rules.yml b/src/util/confvalidator/rules.yml
|
||||
deleted file mode 100644
|
||||
index c6ccc89fe..000000000
|
||||
--- a/src/util/confvalidator/rules.yml
|
||||
+++ /dev/null
|
||||
@@ -1,13 +0,0 @@
|
||||
-# Extend the list of the allowed enctypes and salts as needed
|
||||
-Types:
|
||||
- supported_enctypes:
|
||||
- '(aes256-cts-hmac-sha1-96|aes256-cts|aes128-cts-hmac-sha1-96|aes128-cts|des3-hmac-sha1|des3-cbc-raw|des3-cbc-sha1|des3-hmac-sha1|rc4-hmac|arcfour-hmac-md5)(:(normal|v4))?$'
|
||||
- default_tgs_enctypes:
|
||||
- '(aes256-cts-hmac-sha1-96|aes256-cts|aes128-cts-hmac-sha1-96|aes128-cts|des3-hmac-sha1|des3-cbc-raw|des3-cbc-sha1|des3-hmac-sha1|rc4-hmac|arcfour-hmac-md5)'
|
||||
- default_tkt_enctypes:
|
||||
- '(aes256-cts-hmac-sha1-96|aes256-cts|aes128-cts-hmac-sha1-96|aes128-cts|des3-hmac-sha1|des3-cbc-raw|des3-cbc-sha1|des3-hmac-sha1|rc4-hmac|arcfour-hmac-md5)'
|
||||
-
|
||||
-# Add all valid profile attributes that are not listed in k5-int.h
|
||||
-Attributes:
|
||||
- - logging
|
||||
- - dbmodules
|
||||
diff --git a/src/util/confvalidator/validator.conf b/src/util/confvalidator/validator.conf
|
||||
deleted file mode 100644
|
||||
index 71e205c3b..000000000
|
||||
--- a/src/util/confvalidator/validator.conf
|
||||
+++ /dev/null
|
||||
@@ -1,2 +0,0 @@
|
||||
-RulesPath=./rules.yml
|
||||
-HfilePath=../../include/k5-int.h
|
||||
diff --git a/src/util/confvalidator/validator.py b/src/util/confvalidator/validator.py
|
||||
deleted file mode 100644
|
||||
index d739bc091..000000000
|
||||
--- a/src/util/confvalidator/validator.py
|
||||
+++ /dev/null
|
||||
@@ -1,194 +0,0 @@
|
||||
-'''
|
||||
-Created on Jan 25, 2010
|
||||
-
|
||||
-@author: tsitkova
|
||||
-'''
|
||||
-import os
|
||||
-import sys
|
||||
-import re
|
||||
-import yaml
|
||||
-from optparse import OptionParser
|
||||
-from confparser import ConfParser
|
||||
-
|
||||
-class Rule(object):
|
||||
- def __init__(self):
|
||||
- pass
|
||||
-
|
||||
- def validate(self,node):
|
||||
- (path,dirs,avs) = node
|
||||
-
|
||||
-
|
||||
-class Validator(object):
|
||||
- def __init__(self, kerberosPath, confPath=None, rulesPath=None, hfilePath=None):
|
||||
- self.parser = ConfParser(kerberosPath)
|
||||
- if confPath is not None:
|
||||
- content = self._readConfigFile(confPath)
|
||||
- rulesPath = content['RulesPath']
|
||||
- hfilePath = content['HfilePath']
|
||||
- if rulesPath is not None and hfilePath is not None:
|
||||
- self.rules = self._loadRules(rulesPath)
|
||||
- self.validKeys = SupportedKeys(hfilePath).validKeys.union(self.rules['Attributes'])
|
||||
- else:
|
||||
- raise ValueError('Invalid arguments for validator: no path to rules and definition files')
|
||||
-
|
||||
- self._attribute_pattern = re.compile(r'^\w+$')
|
||||
- self._lowercase_pattern = re.compile(r'[a-z]')
|
||||
-
|
||||
- def _readConfigFile(self,path):
|
||||
- f = open(path)
|
||||
- result = dict()
|
||||
- for line in f:
|
||||
- line = line.rstrip()
|
||||
- fields = line.split('=')
|
||||
- result[fields[0]] = fields[1]
|
||||
-
|
||||
- return result
|
||||
-
|
||||
- def _loadRules(self, path):
|
||||
- f = open(path)
|
||||
- rules = yaml.load(f)
|
||||
- f.close()
|
||||
-
|
||||
- return rules
|
||||
-
|
||||
- def validate(self):
|
||||
- typeInfo = self.rules['Types']
|
||||
-
|
||||
- for node in self.parser.walk():
|
||||
- self._validateTypes(node, typeInfo)
|
||||
- self._validateAttrubutes(node, self.validKeys)
|
||||
- # self._validateRealm(node)
|
||||
-
|
||||
-
|
||||
- def _validateTypes(self, node, typeInfo):
|
||||
- (path, dirs, avs) = node
|
||||
- for (key, value) in avs:
|
||||
- valid_type_pattern = typeInfo.get(key)
|
||||
- if valid_type_pattern is not None:
|
||||
- for t in value:
|
||||
- if re.match(valid_type_pattern, t) is None:
|
||||
- print 'Wrong type %s for attribute %s.%s' % (t,path,key)
|
||||
-
|
||||
- def _validateAttrubutes(self, node, validKeys):
|
||||
- (path, dirs, avs) = node
|
||||
- attributes = list()
|
||||
- for attr in dirs:
|
||||
- if self._attribute_pattern.match(attr) is not None:
|
||||
- attributes.append(attr)
|
||||
- for (attr, value) in avs:
|
||||
- if self._attribute_pattern.match(attr) is not None:
|
||||
- attributes.append(attr)
|
||||
-
|
||||
- for attr in attributes:
|
||||
- if attr not in validKeys:
|
||||
- print 'Unrecognized attribute %s at %s' % (attr, path)
|
||||
-
|
||||
-# def _validateRealm(self, node):
|
||||
-# (path, dirs, avs) = node
|
||||
-# if path == 'root.realms':
|
||||
-# for attr in dirs:
|
||||
-# if self._lowercase_pattern.search(attr) is not None:
|
||||
-# print 'Lower case letter in realm attribute: %s at %s' % (attr, path)
|
||||
-
|
||||
-class SupportedKeys(object):
|
||||
- def __init__(self, path):
|
||||
- self.validKeys = self.getKeysFromHfile(path)
|
||||
-
|
||||
- def getKeysFromHfile(self, path):
|
||||
- pattern = re.compile(r'^[#]define KRB5_CONF_\w+\s+["](\w+)["]')
|
||||
- f = open(path)
|
||||
- result = set()
|
||||
- for l in f:
|
||||
- l = l.rstrip()
|
||||
- m = pattern.match(l)
|
||||
- if m is not None:
|
||||
- result.add(m.groups()[0])
|
||||
- f.close()
|
||||
-
|
||||
- return result
|
||||
-
|
||||
-
|
||||
-class ValidatorTest(Validator):
|
||||
- def __init__(self):
|
||||
- self.kerberosPath = '../tests/kdc1.conf'
|
||||
- self.rulesPath = '../tests/rules.yml'
|
||||
- self.hfilePath = '../tests/k5-int.h'
|
||||
- self.confPath = '../tests/validator.conf'
|
||||
-
|
||||
- super(ValidatorTest, self).__init__(self.kerberosPath,
|
||||
- rulesPath=self.rulesPath,
|
||||
- hfilePath=self.hfilePath)
|
||||
-
|
||||
- def run_tests(self):
|
||||
- self._test_validate()
|
||||
-
|
||||
- def _test__loadRules(self):
|
||||
- result = self._loadRules(self.rulesPath)
|
||||
- print result
|
||||
-
|
||||
- def _test_validate(self):
|
||||
- self.validate()
|
||||
-
|
||||
- def _test__readConfigFile(self):
|
||||
- result = self._readConfigFile(self.confPath)
|
||||
- print result
|
||||
-
|
||||
-class SupportedKeysTest(SupportedKeys):
|
||||
- def __init__(self):
|
||||
- self.path = '../tests/k5-int.h'
|
||||
-
|
||||
- def run_tests(self):
|
||||
- self._test_getKeysFromHFile()
|
||||
-
|
||||
- def _test_getKeysFromHFile(self):
|
||||
- result = set()
|
||||
- krb5keys = self.getKeysFromHfile(self.path)
|
||||
- for key in krb5keys:
|
||||
- print key
|
||||
- result.update(key)
|
||||
- print len(krb5keys)
|
||||
-
|
||||
- return result
|
||||
-
|
||||
-def _test():
|
||||
- tester = ValidatorTest()
|
||||
- krb5keys = tester.run_tests()
|
||||
-
|
||||
-if __name__ == '__main__':
|
||||
- TEST = False
|
||||
- if TEST:
|
||||
- _test()
|
||||
- sys.exit()
|
||||
-
|
||||
-
|
||||
- usage = "\n\t%prog path [-d defPath] [-r rulesPath] [-c validatorConfPath]"
|
||||
- description = 'Description: validates kerberos configuration file'
|
||||
- parser = OptionParser(usage = usage, description = description)
|
||||
- parser.add_option("-c", dest="confPath",
|
||||
- help='path to validator config file')
|
||||
- parser.add_option("-d", dest="hfilePath",
|
||||
- help='path to h-file with attribute definition')
|
||||
- parser.add_option("-r", dest="rulesPath",
|
||||
- help='path to file with validation rules')
|
||||
- (options, args) = parser.parse_args()
|
||||
-
|
||||
- if len(args) != 1 and len(sys.argv) <= 3:
|
||||
- print '\n%s' % parser.get_usage()
|
||||
- sys.exit()
|
||||
-
|
||||
- validator = None
|
||||
- if options.confPath is not None:
|
||||
- validator = Validator(args[0], confPath=options.confPath)
|
||||
- elif options.hfilePath is not None and options.rulesPath is not None:
|
||||
- validator = Validator(args[0], hfilePath=options.hfilePath, rulesPath=options.rulesPath)
|
||||
- else:
|
||||
- print '\nMust specify either configuration file or paths to rules and definitions files'
|
||||
- print '%s' % parser.get_usage()
|
||||
- sys.exit()
|
||||
-
|
||||
- validator.validate()
|
||||
-
|
||||
-
|
||||
-
|
||||
-
|
||||
-
|
||||
|
|
@ -1,69 +0,0 @@
|
|||
From cc4aace493d1caaca9edebcc5d836e847e358afd Mon Sep 17 00:00:00 2001
|
||||
From: Robbie Harwood <rharwood@redhat.com>
|
||||
Date: Thu, 2 May 2019 16:57:51 -0400
|
||||
Subject: [PATCH] Remove dead variable def_kslist from two files
|
||||
|
||||
def_kslist was part of kdb5_create.c since its addition (commit
|
||||
edf8b4d8a6a665c2aa150993cd813ea6c5cf12e1) and has always been
|
||||
irrelevant since the rblock structure is fully initialized in
|
||||
kdb5_create().
|
||||
|
||||
def_klist was copied into kdb5_ldap_realm.c (present in addition at
|
||||
commit 42d9d6ab320ee3a661fe21472be542acd542d5be). The global rblock
|
||||
structure (and therefore the initializer) was removed in commit
|
||||
9c850f8b62784170a5e42315c1a9552ddcf4ca2b, leaving def_kslist
|
||||
unreferenced.
|
||||
|
||||
Remove def_kslist from both files, and remove the rblock initializer
|
||||
from kdb5_create.c.
|
||||
|
||||
[ghudson@mit.edu: edited commit message]
|
||||
|
||||
(cherry picked from commit 6309f5e3508cd24151222b2cd095766283e205f2)
|
||||
---
|
||||
src/kadmin/dbutil/kdb5_create.c | 12 +-----------
|
||||
src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c | 1 -
|
||||
2 files changed, 1 insertion(+), 12 deletions(-)
|
||||
|
||||
diff --git a/src/kadmin/dbutil/kdb5_create.c b/src/kadmin/dbutil/kdb5_create.c
|
||||
index bc1b9195d..efdb8adb0 100644
|
||||
--- a/src/kadmin/dbutil/kdb5_create.c
|
||||
+++ b/src/kadmin/dbutil/kdb5_create.c
|
||||
@@ -66,8 +66,6 @@ enum ap_op {
|
||||
TGT_KEY /* special handling for tgt key */
|
||||
};
|
||||
|
||||
-krb5_key_salt_tuple def_kslist = { ENCTYPE_DES_CBC_CRC, KRB5_KDB_SALTTYPE_NORMAL };
|
||||
-
|
||||
struct realm_info {
|
||||
krb5_deltat max_life;
|
||||
krb5_deltat max_rlife;
|
||||
@@ -76,15 +74,7 @@ struct realm_info {
|
||||
krb5_keyblock *key;
|
||||
krb5_int32 nkslist;
|
||||
krb5_key_salt_tuple *kslist;
|
||||
-} rblock = { /* XXX */
|
||||
- KRB5_KDB_MAX_LIFE,
|
||||
- KRB5_KDB_MAX_RLIFE,
|
||||
- KRB5_KDB_EXPIRATION,
|
||||
- KRB5_KDB_DEF_FLAGS,
|
||||
- (krb5_keyblock *) NULL,
|
||||
- 1,
|
||||
- &def_kslist
|
||||
-};
|
||||
+} rblock;
|
||||
|
||||
struct iterate_args {
|
||||
krb5_context ctx;
|
||||
diff --git a/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c b/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c
|
||||
index 5a745e21d..c21d19981 100644
|
||||
--- a/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c
|
||||
+++ b/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c
|
||||
@@ -91,7 +91,6 @@
|
||||
extern time_t get_date(char *); /* kadmin/cli/getdate.o */
|
||||
|
||||
char *yes = "yes\n"; /* \n to compare against result of fgets */
|
||||
-krb5_key_salt_tuple def_kslist = {ENCTYPE_DES_CBC_CRC, KRB5_KDB_SALTTYPE_NORMAL};
|
||||
|
||||
krb5_data tgt_princ_entries[] = {
|
||||
{0, KRB5_TGS_NAME_SIZE, KRB5_TGS_NAME},
|
||||
File diff suppressed because it is too large
Load diff
|
|
@ -1,466 +0,0 @@
|
|||
From 43c7d037b5e6bac3345c069af70f3cd6fd947f3f Mon Sep 17 00:00:00 2001
|
||||
From: Robbie Harwood <rharwood@redhat.com>
|
||||
Date: Thu, 4 Apr 2019 16:14:46 -0400
|
||||
Subject: [PATCH] Remove kadmin RPC support for setting v4 key
|
||||
|
||||
ticket: 8794 (new)
|
||||
(cherry picked from commit 752187a441ed0f301f1a8adb1fea843080ac8c97)
|
||||
---
|
||||
src/kadmin/server/kadm_rpc_svc.c | 7 --
|
||||
src/kadmin/server/ovsec_kadmd.c | 2 +-
|
||||
src/kadmin/server/server_stubs.c | 50 ---------
|
||||
src/lib/kadm5/admin.h | 3 -
|
||||
src/lib/kadm5/admin_xdr.h | 1 -
|
||||
src/lib/kadm5/clnt/Makefile.in | 2 +-
|
||||
src/lib/kadm5/clnt/client_principal.c | 22 ----
|
||||
src/lib/kadm5/clnt/client_rpc.c | 8 --
|
||||
src/lib/kadm5/clnt/libkadm5clnt_mit.exports | 2 -
|
||||
src/lib/kadm5/kadm_rpc.h | 16 +--
|
||||
src/lib/kadm5/kadm_rpc_xdr.c | 19 ----
|
||||
src/lib/kadm5/srv/Makefile.in | 2 +-
|
||||
src/lib/kadm5/srv/libkadm5srv_mit.exports | 2 -
|
||||
src/lib/kadm5/srv/svr_principal.c | 118 --------------------
|
||||
14 files changed, 6 insertions(+), 248 deletions(-)
|
||||
|
||||
diff --git a/src/kadmin/server/kadm_rpc_svc.c b/src/kadmin/server/kadm_rpc_svc.c
|
||||
index 41fc88ac8..d343e2c25 100644
|
||||
--- a/src/kadmin/server/kadm_rpc_svc.c
|
||||
+++ b/src/kadmin/server/kadm_rpc_svc.c
|
||||
@@ -53,7 +53,6 @@ void kadm_1(rqstp, transp)
|
||||
mpol_arg modify_policy_2_arg;
|
||||
gpol_arg get_policy_2_arg;
|
||||
setkey_arg setkey_principal_2_arg;
|
||||
- setv4key_arg setv4key_principal_2_arg;
|
||||
cprinc3_arg create_principal3_2_arg;
|
||||
chpass3_arg chpass_principal3_2_arg;
|
||||
chrand3_arg chrand_principal3_2_arg;
|
||||
@@ -134,12 +133,6 @@ void kadm_1(rqstp, transp)
|
||||
local = (bool_t (*)()) chpass_principal_2_svc;
|
||||
break;
|
||||
|
||||
- case SETV4KEY_PRINCIPAL:
|
||||
- xdr_argument = xdr_setv4key_arg;
|
||||
- xdr_result = xdr_generic_ret;
|
||||
- local = (bool_t (*)()) setv4key_principal_2_svc;
|
||||
- break;
|
||||
-
|
||||
case SETKEY_PRINCIPAL:
|
||||
xdr_argument = xdr_setkey_arg;
|
||||
xdr_result = xdr_generic_ret;
|
||||
diff --git a/src/kadmin/server/ovsec_kadmd.c b/src/kadmin/server/ovsec_kadmd.c
|
||||
index 6a6b21401..3737791b6 100644
|
||||
--- a/src/kadmin/server/ovsec_kadmd.c
|
||||
+++ b/src/kadmin/server/ovsec_kadmd.c
|
||||
@@ -227,7 +227,7 @@ log_badverf(gss_name_t client_name, gss_name_t server_name,
|
||||
{14, "GET_PRINCS"},
|
||||
{15, "GET_POLS"},
|
||||
{16, "SETKEY_PRINCIPAL"},
|
||||
- {17, "SETV4KEY_PRINCIPAL"},
|
||||
+ /* 17 was "SETV4KEY_PRINCIPAL" */
|
||||
{18, "CREATE_PRINCIPAL3"},
|
||||
{19, "CHPASS_PRINCIPAL3"},
|
||||
{20, "CHRAND_PRINCIPAL3"},
|
||||
diff --git a/src/kadmin/server/server_stubs.c b/src/kadmin/server/server_stubs.c
|
||||
index cfef97fec..d5a25e502 100644
|
||||
--- a/src/kadmin/server/server_stubs.c
|
||||
+++ b/src/kadmin/server/server_stubs.c
|
||||
@@ -893,56 +893,6 @@ exit_func:
|
||||
return TRUE;
|
||||
}
|
||||
|
||||
-bool_t
|
||||
-setv4key_principal_2_svc(setv4key_arg *arg, generic_ret *ret,
|
||||
- struct svc_req *rqstp)
|
||||
-{
|
||||
- char *prime_arg = NULL;
|
||||
- gss_buffer_desc client_name = GSS_C_EMPTY_BUFFER;
|
||||
- gss_buffer_desc service_name = GSS_C_EMPTY_BUFFER;
|
||||
- kadm5_server_handle_t handle;
|
||||
- const char *errmsg = NULL;
|
||||
-
|
||||
- ret->code = stub_setup(arg->api_version, rqstp, arg->princ, &handle,
|
||||
- &ret->api_version, &client_name, &service_name,
|
||||
- &prime_arg);
|
||||
- if (ret->code)
|
||||
- goto exit_func;
|
||||
-
|
||||
- ret->code = check_lockdown_keys(handle, arg->princ);
|
||||
- if (ret->code != KADM5_OK) {
|
||||
- if (ret->code == KADM5_PROTECT_KEYS) {
|
||||
- log_unauth("kadm5_setv4key_principal", prime_arg, &client_name,
|
||||
- &service_name, rqstp);
|
||||
- ret->code = KADM5_AUTH_SETKEY;
|
||||
- }
|
||||
- } else if (!(CHANGEPW_SERVICE(rqstp)) &&
|
||||
- stub_auth(handle, OP_SETKEY, arg->princ, NULL, NULL, NULL)) {
|
||||
- ret->code = kadm5_setv4key_principal(handle, arg->princ,
|
||||
- arg->keyblock);
|
||||
- } else {
|
||||
- log_unauth("kadm5_setv4key_principal", prime_arg,
|
||||
- &client_name, &service_name, rqstp);
|
||||
- ret->code = KADM5_AUTH_SETKEY;
|
||||
- }
|
||||
-
|
||||
- if (ret->code != KADM5_AUTH_SETKEY) {
|
||||
- if (ret->code != 0)
|
||||
- errmsg = krb5_get_error_message(handle->context, ret->code);
|
||||
-
|
||||
- log_done("kadm5_setv4key_principal", prime_arg, errmsg,
|
||||
- &client_name, &service_name, rqstp);
|
||||
-
|
||||
- if (errmsg != NULL)
|
||||
- krb5_free_error_message(handle->context, errmsg);
|
||||
- }
|
||||
-
|
||||
-exit_func:
|
||||
- stub_cleanup(handle, prime_arg, &client_name, &service_name);
|
||||
- return TRUE;
|
||||
-}
|
||||
-
|
||||
-
|
||||
bool_t
|
||||
setkey_principal_2_svc(setkey_arg *arg, generic_ret *ret,
|
||||
struct svc_req *rqstp)
|
||||
diff --git a/src/lib/kadm5/admin.h b/src/lib/kadm5/admin.h
|
||||
index b765148b3..7268be44e 100644
|
||||
--- a/src/lib/kadm5/admin.h
|
||||
+++ b/src/lib/kadm5/admin.h
|
||||
@@ -394,9 +394,6 @@ kadm5_ret_t kadm5_randkey_principal_3(void *server_handle,
|
||||
krb5_key_salt_tuple *ks_tuple,
|
||||
krb5_keyblock **keyblocks,
|
||||
int *n_keys);
|
||||
-kadm5_ret_t kadm5_setv4key_principal(void *server_handle,
|
||||
- krb5_principal principal,
|
||||
- krb5_keyblock *keyblock);
|
||||
|
||||
kadm5_ret_t kadm5_setkey_principal(void *server_handle,
|
||||
krb5_principal principal,
|
||||
diff --git a/src/lib/kadm5/admin_xdr.h b/src/lib/kadm5/admin_xdr.h
|
||||
index 2d22611e7..9da98451e 100644
|
||||
--- a/src/lib/kadm5/admin_xdr.h
|
||||
+++ b/src/lib/kadm5/admin_xdr.h
|
||||
@@ -37,7 +37,6 @@ bool_t xdr_mprinc_arg(XDR *xdrs, mprinc_arg *objp);
|
||||
bool_t xdr_rprinc_arg(XDR *xdrs, rprinc_arg *objp);
|
||||
bool_t xdr_chpass_arg(XDR *xdrs, chpass_arg *objp);
|
||||
bool_t xdr_chpass3_arg(XDR *xdrs, chpass3_arg *objp);
|
||||
-bool_t xdr_setv4key_arg(XDR *xdrs, setv4key_arg *objp);
|
||||
bool_t xdr_setkey_arg(XDR *xdrs, setkey_arg *objp);
|
||||
bool_t xdr_setkey3_arg(XDR *xdrs, setkey3_arg *objp);
|
||||
bool_t xdr_setkey4_arg(XDR *xdrs, setkey4_arg *objp);
|
||||
diff --git a/src/lib/kadm5/clnt/Makefile.in b/src/lib/kadm5/clnt/Makefile.in
|
||||
index a180e85cd..2bc385afe 100644
|
||||
--- a/src/lib/kadm5/clnt/Makefile.in
|
||||
+++ b/src/lib/kadm5/clnt/Makefile.in
|
||||
@@ -3,7 +3,7 @@ BUILDTOP=$(REL)..$(S)..$(S)..
|
||||
LOCALINCLUDES = -I$(BUILDTOP)/include/kadm5
|
||||
|
||||
LIBBASE=kadm5clnt_mit
|
||||
-LIBMAJOR=11
|
||||
+LIBMAJOR=12
|
||||
LIBMINOR=0
|
||||
STOBJLISTS=../OBJS.ST OBJS.ST
|
||||
SHLIB_EXPDEPS=\
|
||||
diff --git a/src/lib/kadm5/clnt/client_principal.c b/src/lib/kadm5/clnt/client_principal.c
|
||||
index 18714bf37..96d9d1932 100644
|
||||
--- a/src/lib/kadm5/clnt/client_principal.c
|
||||
+++ b/src/lib/kadm5/clnt/client_principal.c
|
||||
@@ -273,28 +273,6 @@ kadm5_chpass_principal_3(void *server_handle,
|
||||
return r.code;
|
||||
}
|
||||
|
||||
-kadm5_ret_t
|
||||
-kadm5_setv4key_principal(void *server_handle,
|
||||
- krb5_principal princ,
|
||||
- krb5_keyblock *keyblock)
|
||||
-{
|
||||
- setv4key_arg arg;
|
||||
- generic_ret r = { 0, 0 };
|
||||
- kadm5_server_handle_t handle = server_handle;
|
||||
-
|
||||
- CHECK_HANDLE(server_handle);
|
||||
-
|
||||
- arg.princ = princ;
|
||||
- arg.keyblock = keyblock;
|
||||
- arg.api_version = handle->api_version;
|
||||
-
|
||||
- if(princ == NULL || keyblock == NULL)
|
||||
- return EINVAL;
|
||||
- if (setv4key_principal_2(&arg, &r, handle->clnt))
|
||||
- eret();
|
||||
- return r.code;
|
||||
-}
|
||||
-
|
||||
kadm5_ret_t
|
||||
kadm5_setkey_principal(void *server_handle,
|
||||
krb5_principal princ,
|
||||
diff --git a/src/lib/kadm5/clnt/client_rpc.c b/src/lib/kadm5/clnt/client_rpc.c
|
||||
index df5455fd8..d84d158b4 100644
|
||||
--- a/src/lib/kadm5/clnt/client_rpc.c
|
||||
+++ b/src/lib/kadm5/clnt/client_rpc.c
|
||||
@@ -84,14 +84,6 @@ chpass_principal3_2(chpass3_arg *argp, generic_ret *res, CLIENT *clnt)
|
||||
(xdrproc_t)xdr_generic_ret, (caddr_t)res, TIMEOUT);
|
||||
}
|
||||
|
||||
-enum clnt_stat
|
||||
-setv4key_principal_2(setv4key_arg *argp, generic_ret *res, CLIENT *clnt)
|
||||
-{
|
||||
- return clnt_call(clnt, SETV4KEY_PRINCIPAL,
|
||||
- (xdrproc_t)xdr_setv4key_arg, (caddr_t)argp,
|
||||
- (xdrproc_t)xdr_generic_ret, (caddr_t)res, TIMEOUT);
|
||||
-}
|
||||
-
|
||||
enum clnt_stat
|
||||
setkey_principal_2(setkey_arg *argp, generic_ret *res, CLIENT *clnt)
|
||||
{
|
||||
diff --git a/src/lib/kadm5/clnt/libkadm5clnt_mit.exports b/src/lib/kadm5/clnt/libkadm5clnt_mit.exports
|
||||
index f122b31ab..e41c8e4f7 100644
|
||||
--- a/src/lib/kadm5/clnt/libkadm5clnt_mit.exports
|
||||
+++ b/src/lib/kadm5/clnt/libkadm5clnt_mit.exports
|
||||
@@ -44,7 +44,6 @@ kadm5_set_string
|
||||
kadm5_setkey_principal
|
||||
kadm5_setkey_principal_3
|
||||
kadm5_setkey_principal_4
|
||||
-kadm5_setv4key_principal
|
||||
kadm5_unlock
|
||||
krb5_aprof_finish
|
||||
krb5_aprof_get_boolean
|
||||
@@ -114,6 +113,5 @@ xdr_rprinc_arg
|
||||
xdr_setkey3_arg
|
||||
xdr_setkey4_arg
|
||||
xdr_setkey_arg
|
||||
-xdr_setv4key_arg
|
||||
xdr_ui_4
|
||||
kadm5_init_iprop
|
||||
diff --git a/src/lib/kadm5/kadm_rpc.h b/src/lib/kadm5/kadm_rpc.h
|
||||
index 8d7cf3b36..5099c6c14 100644
|
||||
--- a/src/lib/kadm5/kadm_rpc.h
|
||||
+++ b/src/lib/kadm5/kadm_rpc.h
|
||||
@@ -82,13 +82,6 @@ struct chpass3_arg {
|
||||
};
|
||||
typedef struct chpass3_arg chpass3_arg;
|
||||
|
||||
-struct setv4key_arg {
|
||||
- krb5_ui_4 api_version;
|
||||
- krb5_principal princ;
|
||||
- krb5_keyblock *keyblock;
|
||||
-};
|
||||
-typedef struct setv4key_arg setv4key_arg;
|
||||
-
|
||||
struct setkey_arg {
|
||||
krb5_ui_4 api_version;
|
||||
krb5_principal princ;
|
||||
@@ -322,11 +315,9 @@ extern enum clnt_stat setkey_principal_2(setkey_arg *, generic_ret *,
|
||||
CLIENT *);
|
||||
extern bool_t setkey_principal_2_svc(setkey_arg *, generic_ret *,
|
||||
struct svc_req *);
|
||||
-#define SETV4KEY_PRINCIPAL 17
|
||||
-extern enum clnt_stat setv4key_principal_2(setv4key_arg *, generic_ret *,
|
||||
- CLIENT *);
|
||||
-extern bool_t setv4key_principal_2_svc(setv4key_arg *, generic_ret *,
|
||||
- struct svc_req *);
|
||||
+
|
||||
+/* 17 was SETV4KEY_PRINCIPAL (removed in 1.18). */
|
||||
+
|
||||
#define CREATE_PRINCIPAL3 18
|
||||
extern enum clnt_stat create_principal3_2(cprinc3_arg *, generic_ret *,
|
||||
CLIENT *);
|
||||
@@ -380,7 +371,6 @@ extern bool_t xdr_gprincs_arg ();
|
||||
extern bool_t xdr_gprincs_ret ();
|
||||
extern bool_t xdr_chpass_arg ();
|
||||
extern bool_t xdr_chpass3_arg ();
|
||||
-extern bool_t xdr_setv4key_arg ();
|
||||
extern bool_t xdr_setkey_arg ();
|
||||
extern bool_t xdr_setkey3_arg ();
|
||||
extern bool_t xdr_setkey4_arg ();
|
||||
diff --git a/src/lib/kadm5/kadm_rpc_xdr.c b/src/lib/kadm5/kadm_rpc_xdr.c
|
||||
index 2892d4147..745ee857e 100644
|
||||
--- a/src/lib/kadm5/kadm_rpc_xdr.c
|
||||
+++ b/src/lib/kadm5/kadm_rpc_xdr.c
|
||||
@@ -710,25 +710,6 @@ xdr_chpass3_arg(XDR *xdrs, chpass3_arg *objp)
|
||||
return (TRUE);
|
||||
}
|
||||
|
||||
-bool_t
|
||||
-xdr_setv4key_arg(XDR *xdrs, setv4key_arg *objp)
|
||||
-{
|
||||
- unsigned int n_keys = 1;
|
||||
-
|
||||
- if (!xdr_ui_4(xdrs, &objp->api_version)) {
|
||||
- return (FALSE);
|
||||
- }
|
||||
- if (!xdr_krb5_principal(xdrs, &objp->princ)) {
|
||||
- return (FALSE);
|
||||
- }
|
||||
- if (!xdr_array(xdrs, (caddr_t *) &objp->keyblock,
|
||||
- &n_keys, ~0,
|
||||
- sizeof(krb5_keyblock), xdr_krb5_keyblock)) {
|
||||
- return (FALSE);
|
||||
- }
|
||||
- return (TRUE);
|
||||
-}
|
||||
-
|
||||
bool_t
|
||||
xdr_setkey_arg(XDR *xdrs, setkey_arg *objp)
|
||||
{
|
||||
diff --git a/src/lib/kadm5/srv/Makefile.in b/src/lib/kadm5/srv/Makefile.in
|
||||
index 617d65666..89e6097cf 100644
|
||||
--- a/src/lib/kadm5/srv/Makefile.in
|
||||
+++ b/src/lib/kadm5/srv/Makefile.in
|
||||
@@ -9,7 +9,7 @@ DEFINES = @HESIOD_DEFS@
|
||||
##DOSLIBNAME = libkadm5srv.lib
|
||||
|
||||
LIBBASE=kadm5srv_mit
|
||||
-LIBMAJOR=11
|
||||
+LIBMAJOR=12
|
||||
LIBMINOR=0
|
||||
STOBJLISTS=../OBJS.ST OBJS.ST
|
||||
|
||||
diff --git a/src/lib/kadm5/srv/libkadm5srv_mit.exports b/src/lib/kadm5/srv/libkadm5srv_mit.exports
|
||||
index 64ad5dd69..e3c04e690 100644
|
||||
--- a/src/lib/kadm5/srv/libkadm5srv_mit.exports
|
||||
+++ b/src/lib/kadm5/srv/libkadm5srv_mit.exports
|
||||
@@ -45,7 +45,6 @@ kadm5_set_string
|
||||
kadm5_setkey_principal
|
||||
kadm5_setkey_principal_3
|
||||
kadm5_setkey_principal_4
|
||||
-kadm5_setv4key_principal
|
||||
kadm5_unlock
|
||||
kdb_delete_entry
|
||||
kdb_free_entry
|
||||
@@ -133,7 +132,6 @@ xdr_rprinc_arg
|
||||
xdr_setkey3_arg
|
||||
xdr_setkey4_arg
|
||||
xdr_setkey_arg
|
||||
-xdr_setv4key_arg
|
||||
xdr_sstring_arg
|
||||
xdr_ui_4
|
||||
kadm5_init_iprop
|
||||
diff --git a/src/lib/kadm5/srv/svr_principal.c b/src/lib/kadm5/srv/svr_principal.c
|
||||
index 9ab2c5a74..48cac0c11 100644
|
||||
--- a/src/lib/kadm5/srv/svr_principal.c
|
||||
+++ b/src/lib/kadm5/srv/svr_principal.c
|
||||
@@ -1645,124 +1645,6 @@ done:
|
||||
return ret;
|
||||
}
|
||||
|
||||
-/*
|
||||
- * kadm5_setv4key_principal:
|
||||
- *
|
||||
- * Set only ONE key of the principal, removing all others. This key
|
||||
- * must have the DES_CBC_CRC enctype and is entered as having the
|
||||
- * krb4 salttype. This is to enable things like kadmind4 to work.
|
||||
- */
|
||||
-kadm5_ret_t
|
||||
-kadm5_setv4key_principal(void *server_handle,
|
||||
- krb5_principal principal,
|
||||
- krb5_keyblock *keyblock)
|
||||
-{
|
||||
- krb5_db_entry *kdb;
|
||||
- osa_princ_ent_rec adb;
|
||||
- krb5_timestamp now;
|
||||
- kadm5_policy_ent_rec pol;
|
||||
- krb5_keysalt keysalt;
|
||||
- int i, kvno, ret;
|
||||
- krb5_boolean have_pol = FALSE;
|
||||
- kadm5_server_handle_t handle = server_handle;
|
||||
- krb5_key_data tmp_key_data;
|
||||
- krb5_keyblock *act_mkey;
|
||||
-
|
||||
- memset( &tmp_key_data, 0, sizeof(tmp_key_data));
|
||||
-
|
||||
- CHECK_HANDLE(server_handle);
|
||||
-
|
||||
- krb5_clear_error_message(handle->context);
|
||||
-
|
||||
- if (principal == NULL || keyblock == NULL)
|
||||
- return EINVAL;
|
||||
- if (hist_princ && /* this will be NULL when initializing the databse */
|
||||
- ((krb5_principal_compare(handle->context,
|
||||
- principal, hist_princ)) == TRUE))
|
||||
- return KADM5_PROTECT_PRINCIPAL;
|
||||
-
|
||||
- if (keyblock->enctype != ENCTYPE_DES_CBC_CRC)
|
||||
- return KADM5_SETV4KEY_INVAL_ENCTYPE;
|
||||
-
|
||||
- if ((ret = kdb_get_entry(handle, principal, &kdb, &adb)))
|
||||
- return(ret);
|
||||
-
|
||||
- for (kvno = 0, i=0; i<kdb->n_key_data; i++)
|
||||
- if (kdb->key_data[i].key_data_kvno > kvno)
|
||||
- kvno = kdb->key_data[i].key_data_kvno;
|
||||
-
|
||||
- if (kdb->key_data != NULL)
|
||||
- cleanup_key_data(handle->context, kdb->n_key_data, kdb->key_data);
|
||||
-
|
||||
- kdb->key_data = calloc(1, sizeof(krb5_key_data));
|
||||
- if (kdb->key_data == NULL)
|
||||
- return ENOMEM;
|
||||
- kdb->n_key_data = 1;
|
||||
- keysalt.type = KRB5_KDB_SALTTYPE_V4;
|
||||
- /* XXX data.magic? */
|
||||
- keysalt.data.length = 0;
|
||||
- keysalt.data.data = NULL;
|
||||
-
|
||||
- ret = kdb_get_active_mkey(handle, NULL, &act_mkey);
|
||||
- if (ret)
|
||||
- goto done;
|
||||
-
|
||||
- /* use tmp_key_data as temporary location and reallocate later */
|
||||
- ret = krb5_dbe_encrypt_key_data(handle->context, act_mkey, keyblock,
|
||||
- &keysalt, kvno + 1, kdb->key_data);
|
||||
- if (ret) {
|
||||
- goto done;
|
||||
- }
|
||||
-
|
||||
- kdb->attributes &= ~KRB5_KDB_REQUIRES_PWCHANGE;
|
||||
-
|
||||
- ret = krb5_timeofday(handle->context, &now);
|
||||
- if (ret)
|
||||
- goto done;
|
||||
-
|
||||
- if ((adb.aux_attributes & KADM5_POLICY)) {
|
||||
- ret = get_policy(handle, adb.policy, &pol, &have_pol);
|
||||
- if (ret)
|
||||
- goto done;
|
||||
- }
|
||||
- if (have_pol) {
|
||||
- if (pol.pw_max_life)
|
||||
- kdb->pw_expiration = ts_incr(now, pol.pw_max_life);
|
||||
- else
|
||||
- kdb->pw_expiration = 0;
|
||||
- } else {
|
||||
- kdb->pw_expiration = 0;
|
||||
- }
|
||||
-
|
||||
- ret = krb5_dbe_update_last_pwd_change(handle->context, kdb, now);
|
||||
- if (ret)
|
||||
- goto done;
|
||||
-
|
||||
- /* unlock principal on this KDC */
|
||||
- kdb->fail_auth_count = 0;
|
||||
-
|
||||
- /* key data changed, let the database provider know */
|
||||
- kdb->mask = KADM5_KEY_DATA | KADM5_FAIL_AUTH_COUNT;
|
||||
-
|
||||
- if ((ret = kdb_put_entry(handle, kdb, &adb)))
|
||||
- goto done;
|
||||
-
|
||||
- ret = KADM5_OK;
|
||||
-done:
|
||||
- for (i = 0; i < tmp_key_data.key_data_ver; i++) {
|
||||
- if (tmp_key_data.key_data_contents[i]) {
|
||||
- memset (tmp_key_data.key_data_contents[i], 0, tmp_key_data.key_data_length[i]);
|
||||
- free (tmp_key_data.key_data_contents[i]);
|
||||
- }
|
||||
- }
|
||||
-
|
||||
- kdb_free_entry(handle, kdb, &adb);
|
||||
- if (have_pol)
|
||||
- kadm5_free_policy_ent(handle->lhandle, &pol);
|
||||
-
|
||||
- return ret;
|
||||
-}
|
||||
-
|
||||
kadm5_ret_t
|
||||
kadm5_setkey_principal(void *server_handle,
|
||||
krb5_principal principal,
|
||||
|
|
@ -1,479 +0,0 @@
|
|||
From 343e236ed2637a826f4d53ff60d2b2bc349100d6 Mon Sep 17 00:00:00 2001
|
||||
From: Robbie Harwood <rharwood@redhat.com>
|
||||
Date: Thu, 18 Apr 2019 17:27:07 -0400
|
||||
Subject: [PATCH] Remove krb5int_c_combine_keys()
|
||||
|
||||
This method of combining keys was specified by
|
||||
draft-ietf-krb-wg-kerberos-sam for DES and 3DES enctypes, and is
|
||||
otherwise unused. Remove it.
|
||||
|
||||
[ghudson@mit.edu: rewrote commit message]
|
||||
|
||||
ticket: 8812
|
||||
(cherry picked from commit 925a7df2f486aaa3ff137d2bcdf8ff57186638c6)
|
||||
[rharwood@redhat.com: conflicts: .gitignore]
|
||||
---
|
||||
src/include/k5-int.h | 7 -
|
||||
src/lib/crypto/crypto_tests/Makefile.in | 12 +-
|
||||
src/lib/crypto/crypto_tests/deps | 10 --
|
||||
src/lib/crypto/crypto_tests/t_combine.c | 62 -------
|
||||
src/lib/crypto/krb/Makefile.in | 3 -
|
||||
src/lib/crypto/krb/combine_keys.c | 227 ------------------------
|
||||
src/lib/crypto/krb/deps | 13 --
|
||||
src/lib/crypto/libk5crypto.exports | 1 -
|
||||
8 files changed, 3 insertions(+), 332 deletions(-)
|
||||
delete mode 100644 src/lib/crypto/crypto_tests/t_combine.c
|
||||
delete mode 100644 src/lib/crypto/krb/combine_keys.c
|
||||
|
||||
diff --git a/src/include/k5-int.h b/src/include/k5-int.h
|
||||
index 2bc59e636..0857fd1cc 100644
|
||||
--- a/src/include/k5-int.h
|
||||
+++ b/src/include/k5-int.h
|
||||
@@ -673,13 +673,6 @@ zapfreedata(krb5_data *data)
|
||||
}
|
||||
}
|
||||
|
||||
-/*
|
||||
- * Combine two keys (normally used by the hardware preauth mechanism)
|
||||
- */
|
||||
-krb5_error_code
|
||||
-krb5int_c_combine_keys(krb5_context context, krb5_keyblock *key1,
|
||||
- krb5_keyblock *key2, krb5_keyblock *outkey);
|
||||
-
|
||||
void krb5int_c_free_keyblock(krb5_context, krb5_keyblock *key);
|
||||
void krb5int_c_free_keyblock_contents(krb5_context, krb5_keyblock *);
|
||||
krb5_error_code krb5int_c_init_keyblock(krb5_context, krb5_enctype enctype,
|
||||
diff --git a/src/lib/crypto/crypto_tests/Makefile.in b/src/lib/crypto/crypto_tests/Makefile.in
|
||||
index 09feeb50e..0295ee14f 100644
|
||||
--- a/src/lib/crypto/crypto_tests/Makefile.in
|
||||
+++ b/src/lib/crypto/crypto_tests/Makefile.in
|
||||
@@ -23,8 +23,7 @@ EXTRADEPSRCS=\
|
||||
$(srcdir)/t_short.c \
|
||||
$(srcdir)/t_str2key.c \
|
||||
$(srcdir)/t_derive.c \
|
||||
- $(srcdir)/t_fork.c \
|
||||
- $(srcdir)/t_combine.c
|
||||
+ $(srcdir)/t_fork.c
|
||||
|
||||
##DOS##BUILDTOP = ..\..\..
|
||||
|
||||
@@ -33,8 +32,7 @@ check-unix: t_nfold t_encrypt t_decrypt t_prf t_prng t_cmac t_hmac \
|
||||
aes-test \
|
||||
camellia-test \
|
||||
t_mddriver4 t_mddriver \
|
||||
- t_cts t_sha2 t_short t_str2key t_derive t_fork t_cf2 \
|
||||
- t_combine
|
||||
+ t_cts t_sha2 t_short t_str2key t_derive t_fork t_cf2
|
||||
$(RUN_TEST) ./t_nfold
|
||||
$(RUN_TEST) ./t_encrypt
|
||||
$(RUN_TEST) ./t_decrypt
|
||||
@@ -59,7 +57,6 @@ check-unix: t_nfold t_encrypt t_decrypt t_prf t_prng t_cmac t_hmac \
|
||||
$(RUN_TEST) ./t_fork
|
||||
$(RUN_TEST) ./t_cf2 <$(srcdir)/t_cf2.in >t_cf2.output
|
||||
diff t_cf2.output $(srcdir)/t_cf2.expected
|
||||
- $(RUN_TEST) ./t_combine
|
||||
# $(RUN_TEST) ./t_pkcs5
|
||||
|
||||
t_nfold$(EXEEXT): t_nfold.$(OBJEXT) $(KRB5_BASE_DEPLIBS)
|
||||
@@ -134,9 +131,6 @@ t_fork$(EXEEXT): t_fork.$(OBJEXT) $(KRB5_BASE_DEPLIBS)
|
||||
t_cf2$(EXEEXT): t_cf2.$(OBJEXT) $(KRB5_BASE_DEPLIBS)
|
||||
$(CC_LINK) -o $@ t_cf2.$(OBJEXT) $(KRB5_BASE_LIBS)
|
||||
|
||||
-t_combine$(EXEEXT): t_combine.$(OBJEXT) $(KRB5_BASE_DEPLIBS)
|
||||
- $(CC_LINK) -o $@ t_combine.$(OBJEXT) $(KRB5_BASE_LIBS)
|
||||
-
|
||||
clean:
|
||||
$(RM) t_nfold.o t_nfold t_encrypt t_encrypt.o \
|
||||
t_decrypt.o t_decrypt t_prng.o t_prng t_cmac.o t_cmac \
|
||||
@@ -149,7 +143,7 @@ clean:
|
||||
t_str2key.o t_derive t_derive.o t_fork t_fork.o \
|
||||
t_mddriver$(EXEEXT) $(OUTPRE)t_mddriver.$(OBJEXT) \
|
||||
camellia-test camellia-test.o camellia-vt.txt \
|
||||
- t_cf2 t_cf2.o t_cf2.output t_combine.o t_combine
|
||||
+ t_cf2 t_cf2.o t_cf2.output
|
||||
|
||||
-$(RM) t_prng.output
|
||||
-$(RM) t_prf.output
|
||||
diff --git a/src/lib/crypto/crypto_tests/deps b/src/lib/crypto/crypto_tests/deps
|
||||
index 19fef2582..0d10d4a1a 100644
|
||||
--- a/src/lib/crypto/crypto_tests/deps
|
||||
+++ b/src/lib/crypto/crypto_tests/deps
|
||||
@@ -226,13 +226,3 @@ $(OUTPRE)t_fork.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \
|
||||
$(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \
|
||||
$(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \
|
||||
$(top_srcdir)/include/socket-utils.h t_fork.c
|
||||
-$(OUTPRE)t_combine.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \
|
||||
- $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \
|
||||
- $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h \
|
||||
- $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \
|
||||
- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \
|
||||
- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \
|
||||
- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \
|
||||
- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \
|
||||
- $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \
|
||||
- $(top_srcdir)/include/socket-utils.h t_combine.c
|
||||
diff --git a/src/lib/crypto/crypto_tests/t_combine.c b/src/lib/crypto/crypto_tests/t_combine.c
|
||||
deleted file mode 100644
|
||||
index ba0622bcf..000000000
|
||||
--- a/src/lib/crypto/crypto_tests/t_combine.c
|
||||
+++ /dev/null
|
||||
@@ -1,62 +0,0 @@
|
||||
-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */
|
||||
-/* lib/crypto/crypto_tests/t_combine.c - krb5int_c_combine_keys tests */
|
||||
-/*
|
||||
- * Copyright (C) 2014 by the Massachusetts Institute of Technology.
|
||||
- * All rights reserved.
|
||||
- *
|
||||
- * Redistribution and use in source and binary forms, with or without
|
||||
- * modification, are permitted provided that the following conditions
|
||||
- * are met:
|
||||
- *
|
||||
- * * Redistributions of source code must retain the above copyright
|
||||
- * notice, this list of conditions and the following disclaimer.
|
||||
- *
|
||||
- * * Redistributions in binary form must reproduce the above copyright
|
||||
- * notice, this list of conditions and the following disclaimer in
|
||||
- * the documentation and/or other materials provided with the
|
||||
- * distribution.
|
||||
- *
|
||||
- * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
|
||||
- * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
|
||||
- * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS
|
||||
- * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE
|
||||
- * COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT,
|
||||
- * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES
|
||||
- * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR
|
||||
- * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
|
||||
- * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
|
||||
- * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
|
||||
- * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED
|
||||
- * OF THE POSSIBILITY OF SUCH DAMAGE.
|
||||
- */
|
||||
-
|
||||
-#include "k5-int.h"
|
||||
-
|
||||
-unsigned char des3_key1[] = "\x10\xB6\x75\xD5\x5B\xD9\x6E\x73"
|
||||
- "\xFD\x54\xB3\x3D\x37\x52\xC1\x2A\xF7\x43\x91\xFE\x1C\x02\x37\x13";
|
||||
-unsigned char des3_key2[] = "\xC8\xDA\x3E\xA7\xB6\x64\xAE\x7A"
|
||||
- "\xB5\x70\x2A\x29\xB3\xBF\x9B\xA8\x46\x7C\x5B\xA8\x8A\x46\x70\x10";
|
||||
-unsigned char des3_result[] = "\x2F\x79\x97\x3E\x3E\xA4\x73\x1A"
|
||||
- "\xB9\x3D\xEF\x5E\x7C\x29\xFB\x2A\x68\x86\x1F\xC1\x85\x0E\x79\x92";
|
||||
-
|
||||
-int
|
||||
-main(int argc, char **argv)
|
||||
-{
|
||||
- krb5_keyblock kb1, kb2, result;
|
||||
-
|
||||
- kb1.enctype = ENCTYPE_DES3_CBC_SHA1;
|
||||
- kb1.contents = des3_key1;
|
||||
- kb1.length = 24;
|
||||
- kb2.enctype = ENCTYPE_DES3_CBC_SHA1;
|
||||
- kb2.contents = des3_key2;
|
||||
- kb2.length = 24;
|
||||
- memset(&result, 0, sizeof(result));
|
||||
- if (krb5int_c_combine_keys(NULL, &kb1, &kb2, &result) != 0)
|
||||
- abort();
|
||||
- if (result.enctype != ENCTYPE_DES3_CBC_SHA1 || result.length != 24 ||
|
||||
- memcmp(result.contents, des3_result, 24) != 0)
|
||||
- abort();
|
||||
- krb5_free_keyblock_contents(NULL, &result);
|
||||
-
|
||||
- return 0;
|
||||
-}
|
||||
diff --git a/src/lib/crypto/krb/Makefile.in b/src/lib/crypto/krb/Makefile.in
|
||||
index c0e0b791b..536bacb6e 100644
|
||||
--- a/src/lib/crypto/krb/Makefile.in
|
||||
+++ b/src/lib/crypto/krb/Makefile.in
|
||||
@@ -22,7 +22,6 @@ STLIBOBJS=\
|
||||
cksumtypes.o \
|
||||
cmac.o \
|
||||
coll_proof_cksum.o \
|
||||
- combine_keys.o \
|
||||
crypto_length.o \
|
||||
crypto_libinit.o \
|
||||
default_state.o \
|
||||
@@ -84,7 +83,6 @@ OBJS=\
|
||||
$(OUTPRE)cksumtypes.$(OBJEXT) \
|
||||
$(OUTPRE)cmac.$(OBJEXT) \
|
||||
$(OUTPRE)coll_proof_cksum.$(OBJEXT) \
|
||||
- $(OUTPRE)combine_keys.$(OBJEXT) \
|
||||
$(OUTPRE)crypto_length.$(OBJEXT) \
|
||||
$(OUTPRE)crypto_libinit.$(OBJEXT) \
|
||||
$(OUTPRE)default_state.$(OBJEXT) \
|
||||
@@ -146,7 +144,6 @@ SRCS=\
|
||||
$(srcdir)/cksumtypes.c \
|
||||
$(srcdir)/cmac.c \
|
||||
$(srcdir)/coll_proof_cksum.c \
|
||||
- $(srcdir)/combine_keys.c \
|
||||
$(srcdir)/crypto_length.c \
|
||||
$(srcdir)/crypto_libinit.c \
|
||||
$(srcdir)/default_state.c \
|
||||
diff --git a/src/lib/crypto/krb/combine_keys.c b/src/lib/crypto/krb/combine_keys.c
|
||||
deleted file mode 100644
|
||||
index c36434e17..000000000
|
||||
--- a/src/lib/crypto/krb/combine_keys.c
|
||||
+++ /dev/null
|
||||
@@ -1,227 +0,0 @@
|
||||
-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */
|
||||
-/* Copyright (c) 2002 Naval Research Laboratory (NRL/CCS) */
|
||||
-/*
|
||||
- * Permission to use, copy, modify and distribute this software and its
|
||||
- * documentation is hereby granted, provided that both the copyright
|
||||
- * notice and this permission notice appear in all copies of the software,
|
||||
- * derivative works or modified versions, and any portions thereof.
|
||||
- *
|
||||
- * NRL ALLOWS FREE USE OF THIS SOFTWARE IN ITS "AS IS" CONDITION AND
|
||||
- * DISCLAIMS ANY LIABILITY OF ANY KIND FOR ANY DAMAGES WHATSOEVER
|
||||
- * RESULTING FROM THE USE OF THIS SOFTWARE.
|
||||
- */
|
||||
-
|
||||
-/*
|
||||
- * Key combination function.
|
||||
- *
|
||||
- * If Key1 and Key2 are two keys to be combined, the algorithm to combine
|
||||
- * them is as follows.
|
||||
- *
|
||||
- * Definitions:
|
||||
- *
|
||||
- * k-truncate is defined as truncating to the key size the input.
|
||||
- *
|
||||
- * DR is defined as the generate "random" data from a key
|
||||
- * (defined in crypto draft)
|
||||
- *
|
||||
- * DK is defined as the key derivation function (krb5int_derive_key())
|
||||
- *
|
||||
- * (note: | means "concatenate")
|
||||
- *
|
||||
- * Combine key algorithm:
|
||||
- *
|
||||
- * R1 = DR(Key1, n-fold(Key2)) [ Output is length of Key1 ]
|
||||
- * R2 = DR(Key2, n-fold(Key1)) [ Output is length of Key2 ]
|
||||
- *
|
||||
- * rnd = n-fold(R1 | R2) [ Note: output size of nfold must be appropriately
|
||||
- * sized for random-to-key function ]
|
||||
- * tkey = random-to-key(rnd)
|
||||
- * Combine-Key(Key1, Key2) = DK(tkey, CombineConstant)
|
||||
- *
|
||||
- * CombineConstant is defined as the byte string:
|
||||
- *
|
||||
- * { 0x63 0x6f 0x6d 0x62 0x69 0x6e 0x65 }, which corresponds to the
|
||||
- * ASCII encoding of the string "combine"
|
||||
- */
|
||||
-
|
||||
-#include "crypto_int.h"
|
||||
-
|
||||
-static krb5_error_code dr(const struct krb5_enc_provider *enc,
|
||||
- const krb5_keyblock *inkey, unsigned char *outdata,
|
||||
- const krb5_data *in_constant);
|
||||
-
|
||||
-/*
|
||||
- * We only support this combine_keys algorithm for des and 3des keys.
|
||||
- * Everything else should use the PRF defined in the crypto framework.
|
||||
- * We don't implement that yet.
|
||||
- */
|
||||
-
|
||||
-static krb5_boolean
|
||||
-enctype_ok(krb5_enctype e)
|
||||
-{
|
||||
- switch (e) {
|
||||
- case ENCTYPE_DES3_CBC_SHA1:
|
||||
- return TRUE;
|
||||
- default:
|
||||
- return FALSE;
|
||||
- }
|
||||
-}
|
||||
-
|
||||
-krb5_error_code
|
||||
-krb5int_c_combine_keys(krb5_context context, krb5_keyblock *key1,
|
||||
- krb5_keyblock *key2, krb5_keyblock *outkey)
|
||||
-{
|
||||
- unsigned char *r1 = NULL, *r2 = NULL, *combined = NULL, *rnd = NULL;
|
||||
- unsigned char *output = NULL;
|
||||
- size_t keybytes, keylength;
|
||||
- const struct krb5_enc_provider *enc;
|
||||
- krb5_data input, randbits;
|
||||
- krb5_keyblock tkeyblock;
|
||||
- krb5_key tkey = NULL;
|
||||
- krb5_error_code ret;
|
||||
- const struct krb5_keytypes *ktp;
|
||||
- krb5_boolean myalloc = FALSE;
|
||||
-
|
||||
- if (!enctype_ok(key1->enctype) || !enctype_ok(key2->enctype))
|
||||
- return KRB5_CRYPTO_INTERNAL;
|
||||
-
|
||||
- if (key1->length != key2->length || key1->enctype != key2->enctype)
|
||||
- return KRB5_CRYPTO_INTERNAL;
|
||||
-
|
||||
- /* Find our encryption algorithm. */
|
||||
- ktp = find_enctype(key1->enctype);
|
||||
- if (ktp == NULL)
|
||||
- return KRB5_BAD_ENCTYPE;
|
||||
- enc = ktp->enc;
|
||||
-
|
||||
- keybytes = enc->keybytes;
|
||||
- keylength = enc->keylength;
|
||||
-
|
||||
- /* Allocate and set up buffers. */
|
||||
- r1 = k5alloc(keybytes, &ret);
|
||||
- if (ret)
|
||||
- goto cleanup;
|
||||
- r2 = k5alloc(keybytes, &ret);
|
||||
- if (ret)
|
||||
- goto cleanup;
|
||||
- rnd = k5alloc(keybytes, &ret);
|
||||
- if (ret)
|
||||
- goto cleanup;
|
||||
- combined = k5calloc(2, keybytes, &ret);
|
||||
- if (ret)
|
||||
- goto cleanup;
|
||||
- output = k5alloc(keylength, &ret);
|
||||
- if (ret)
|
||||
- goto cleanup;
|
||||
-
|
||||
- /*
|
||||
- * Get R1 and R2 (by running the input keys through the DR algorithm.
|
||||
- * Note this is most of derive-key, but not all.
|
||||
- */
|
||||
-
|
||||
- input.length = key2->length;
|
||||
- input.data = (char *) key2->contents;
|
||||
- ret = dr(enc, key1, r1, &input);
|
||||
- if (ret)
|
||||
- goto cleanup;
|
||||
-
|
||||
- input.length = key1->length;
|
||||
- input.data = (char *) key1->contents;
|
||||
- ret = dr(enc, key2, r2, &input);
|
||||
- if (ret)
|
||||
- goto cleanup;
|
||||
-
|
||||
- /*
|
||||
- * Concatenate the two keys together, and then run them through
|
||||
- * n-fold to reduce them to a length appropriate for the random-to-key
|
||||
- * operation. Note here that krb5int_nfold() takes sizes in bits, hence
|
||||
- * the multiply by 8.
|
||||
- */
|
||||
-
|
||||
- memcpy(combined, r1, keybytes);
|
||||
- memcpy(combined + keybytes, r2, keybytes);
|
||||
-
|
||||
- krb5int_nfold((keybytes * 2) * 8, combined, keybytes * 8, rnd);
|
||||
-
|
||||
- /*
|
||||
- * Run the "random" bits through random-to-key to produce a encryption
|
||||
- * key.
|
||||
- */
|
||||
-
|
||||
- randbits.length = keybytes;
|
||||
- randbits.data = (char *) rnd;
|
||||
- tkeyblock.length = keylength;
|
||||
- tkeyblock.contents = output;
|
||||
- tkeyblock.enctype = key1->enctype;
|
||||
-
|
||||
- ret = (*ktp->rand2key)(&randbits, &tkeyblock);
|
||||
- if (ret)
|
||||
- goto cleanup;
|
||||
-
|
||||
- ret = krb5_k_create_key(NULL, &tkeyblock, &tkey);
|
||||
- if (ret)
|
||||
- goto cleanup;
|
||||
-
|
||||
- /*
|
||||
- * Run through derive-key one more time to produce the final key.
|
||||
- * Note that the input to derive-key is the ASCII string "combine".
|
||||
- */
|
||||
-
|
||||
- input.length = 7;
|
||||
- input.data = "combine";
|
||||
-
|
||||
- /*
|
||||
- * Just FYI: _if_ we have space here in the key, then simply use it
|
||||
- * without modification. But if the key is blank (no allocated storage)
|
||||
- * then allocate some memory for it. This allows programs to use one of
|
||||
- * the existing keys as the output key, _or_ pass in a blank keyblock
|
||||
- * for us to allocate. It's easier for us to allocate it since we already
|
||||
- * know the crypto library internals
|
||||
- */
|
||||
-
|
||||
- if (outkey->length == 0 || outkey->contents == NULL) {
|
||||
- outkey->contents = k5alloc(keylength, &ret);
|
||||
- if (ret)
|
||||
- goto cleanup;
|
||||
- outkey->length = keylength;
|
||||
- outkey->enctype = key1->enctype;
|
||||
- myalloc = TRUE;
|
||||
- }
|
||||
-
|
||||
- ret = krb5int_derive_keyblock(enc, NULL, tkey, outkey, &input,
|
||||
- DERIVE_RFC3961);
|
||||
- if (ret) {
|
||||
- if (myalloc) {
|
||||
- free(outkey->contents);
|
||||
- outkey->contents = NULL;
|
||||
- }
|
||||
- goto cleanup;
|
||||
- }
|
||||
-
|
||||
-cleanup:
|
||||
- zapfree(r1, keybytes);
|
||||
- zapfree(r2, keybytes);
|
||||
- zapfree(rnd, keybytes);
|
||||
- zapfree(combined, keybytes * 2);
|
||||
- zapfree(output, keylength);
|
||||
- krb5_k_free_key(NULL, tkey);
|
||||
- return ret;
|
||||
-}
|
||||
-
|
||||
-/* Our DR function, a simple wrapper around krb5int_derive_random(). */
|
||||
-static krb5_error_code
|
||||
-dr(const struct krb5_enc_provider *enc, const krb5_keyblock *inkey,
|
||||
- unsigned char *out, const krb5_data *in_constant)
|
||||
-{
|
||||
- krb5_data outdata = make_data(out, enc->keybytes);
|
||||
- krb5_key key = NULL;
|
||||
- krb5_error_code ret;
|
||||
-
|
||||
- ret = krb5_k_create_key(NULL, inkey, &key);
|
||||
- if (ret != 0)
|
||||
- return ret;
|
||||
- ret = krb5int_derive_random(enc, NULL, key, &outdata, in_constant,
|
||||
- DERIVE_RFC3961);
|
||||
- krb5_k_free_key(NULL, key);
|
||||
- return ret;
|
||||
-}
|
||||
diff --git a/src/lib/crypto/krb/deps b/src/lib/crypto/krb/deps
|
||||
index f9a740860..2f4af1906 100644
|
||||
--- a/src/lib/crypto/krb/deps
|
||||
+++ b/src/lib/crypto/krb/deps
|
||||
@@ -191,19 +191,6 @@ coll_proof_cksum.so coll_proof_cksum.po $(OUTPRE)coll_proof_cksum.$(OBJEXT): \
|
||||
$(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \
|
||||
$(top_srcdir)/include/socket-utils.h coll_proof_cksum.c \
|
||||
crypto_int.h
|
||||
-combine_keys.so combine_keys.po $(OUTPRE)combine_keys.$(OBJEXT): \
|
||||
- $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \
|
||||
- $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \
|
||||
- $(COM_ERR_DEPS) $(srcdir)/../builtin/aes/aes.h $(srcdir)/../builtin/crypto_mod.h \
|
||||
- $(srcdir)/../builtin/sha2/sha2.h $(top_srcdir)/include/k5-buf.h \
|
||||
- $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \
|
||||
- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \
|
||||
- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \
|
||||
- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \
|
||||
- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \
|
||||
- $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \
|
||||
- $(top_srcdir)/include/socket-utils.h combine_keys.c \
|
||||
- crypto_int.h
|
||||
crypto_length.so crypto_length.po $(OUTPRE)crypto_length.$(OBJEXT): \
|
||||
$(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \
|
||||
$(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \
|
||||
diff --git a/src/lib/crypto/libk5crypto.exports b/src/lib/crypto/libk5crypto.exports
|
||||
index 63804299f..451d5e035 100644
|
||||
--- a/src/lib/crypto/libk5crypto.exports
|
||||
+++ b/src/lib/crypto/libk5crypto.exports
|
||||
@@ -58,7 +58,6 @@ krb5_c_prf_length
|
||||
krb5int_c_mandatory_cksumtype
|
||||
krb5_c_fx_cf2_simple
|
||||
krb5int_c_weak_enctype
|
||||
-krb5int_c_combine_keys
|
||||
krb5_encrypt_data
|
||||
krb5int_c_copy_keyblock
|
||||
krb5int_c_copy_keyblock_contents
|
||||
|
|
@ -1,276 +0,0 @@
|
|||
From 740ab812bedd022ec60e7ef63bf4be12dd730d67 Mon Sep 17 00:00:00 2001
|
||||
From: Robbie Harwood <rharwood@redhat.com>
|
||||
Date: Thu, 9 May 2019 14:07:24 -0400
|
||||
Subject: [PATCH] Remove more dead code
|
||||
|
||||
(cherry picked from commit 0269810b1aec6c554fb746433f045d59fd34ab3a)
|
||||
---
|
||||
src/clients/klist/klist.c | 5 ---
|
||||
src/kadmin/dbutil/kdb5_mkey.c | 2 --
|
||||
src/kadmin/server/ipropd_svc.c | 4 ---
|
||||
src/lib/gssapi/krb5/gssapi_krb5.c | 2 +-
|
||||
src/lib/gssapi/krb5/k5sealv3.c | 5 ++-
|
||||
src/lib/gssapi/krb5/k5sealv3iov.c | 5 ++-
|
||||
src/lib/kdb/kdb_convert.c | 36 +++----------------
|
||||
.../kdb/ldap/ldap_util/kdb5_ldap_services.c | 4 ---
|
||||
.../kdb/ldap/libkdb_ldap/ldap_create.c | 10 ------
|
||||
src/plugins/preauth/pkinit/pkinit_srv.c | 8 -----
|
||||
src/tests/hammer/kdc5_hammer.c | 4 +--
|
||||
11 files changed, 10 insertions(+), 75 deletions(-)
|
||||
|
||||
diff --git a/src/clients/klist/klist.c b/src/clients/klist/klist.c
|
||||
index 8c307151a..4261ac96c 100644
|
||||
--- a/src/clients/klist/klist.c
|
||||
+++ b/src/clients/klist/klist.c
|
||||
@@ -720,11 +720,6 @@ show_credential(krb5_creds *cred)
|
||||
extra_field += 2;
|
||||
}
|
||||
|
||||
- if (extra_field > 3) {
|
||||
- fputs("\n", stdout);
|
||||
- extra_field = 0;
|
||||
- }
|
||||
-
|
||||
if (show_flags) {
|
||||
flags = flags_string(cred);
|
||||
if (flags && *flags) {
|
||||
diff --git a/src/kadmin/dbutil/kdb5_mkey.c b/src/kadmin/dbutil/kdb5_mkey.c
|
||||
index 19796c202..aceb0a9b8 100644
|
||||
--- a/src/kadmin/dbutil/kdb5_mkey.c
|
||||
+++ b/src/kadmin/dbutil/kdb5_mkey.c
|
||||
@@ -1240,7 +1240,6 @@ kdb5_purge_mkeys(int argc, char *argv[])
|
||||
if (actkvno_entry == actkvno_list) {
|
||||
/* remove from head */
|
||||
actkvno_list = actkvno_entry->next;
|
||||
- prev_actkvno_entry = actkvno_list;
|
||||
} else if (actkvno_entry->next == NULL) {
|
||||
/* remove from tail */
|
||||
prev_actkvno_entry->next = NULL;
|
||||
@@ -1263,7 +1262,6 @@ kdb5_purge_mkeys(int argc, char *argv[])
|
||||
if (mkey_aux_entry->mkey_kvno == args.kvnos[j].kvno) {
|
||||
if (mkey_aux_entry == mkey_aux_list) {
|
||||
mkey_aux_list = mkey_aux_entry->next;
|
||||
- prev_mkey_aux_entry = mkey_aux_list;
|
||||
} else if (mkey_aux_entry->next == NULL) {
|
||||
prev_mkey_aux_entry->next = NULL;
|
||||
} else {
|
||||
diff --git a/src/kadmin/server/ipropd_svc.c b/src/kadmin/server/ipropd_svc.c
|
||||
index dc9984c2c..56e9b90b2 100644
|
||||
--- a/src/kadmin/server/ipropd_svc.c
|
||||
+++ b/src/kadmin/server/ipropd_svc.c
|
||||
@@ -263,8 +263,6 @@ ipropx_resync(uint32_t vers, struct svc_req *rqstp)
|
||||
int pret, fret;
|
||||
FILE *p;
|
||||
kadm5_server_handle_t handle = global_server_handle;
|
||||
- OM_uint32 min_stat;
|
||||
- gss_name_t name = NULL;
|
||||
char *client_name = NULL, *service_name = NULL;
|
||||
char *whoami = "iprop_full_resync_1";
|
||||
|
||||
@@ -440,8 +438,6 @@ out:
|
||||
debprret(whoami, ret.ret, 0);
|
||||
free(client_name);
|
||||
free(service_name);
|
||||
- if (name)
|
||||
- gss_release_name(&min_stat, &name);
|
||||
free(ubuf);
|
||||
return (&ret);
|
||||
}
|
||||
diff --git a/src/lib/gssapi/krb5/gssapi_krb5.c b/src/lib/gssapi/krb5/gssapi_krb5.c
|
||||
index 79b83e0c6..f09cda007 100644
|
||||
--- a/src/lib/gssapi/krb5/gssapi_krb5.c
|
||||
+++ b/src/lib/gssapi/krb5/gssapi_krb5.c
|
||||
@@ -780,7 +780,7 @@ krb5_gss_localname(OM_uint32 *minor,
|
||||
localname->value = gssalloc_strdup(lname);
|
||||
localname->length = strlen(lname);
|
||||
|
||||
- return (code == 0) ? GSS_S_COMPLETE : GSS_S_FAILURE;
|
||||
+ return GSS_S_COMPLETE;
|
||||
}
|
||||
|
||||
|
||||
diff --git a/src/lib/gssapi/krb5/k5sealv3.c b/src/lib/gssapi/krb5/k5sealv3.c
|
||||
index 25d9f2711..3b4f8cb83 100644
|
||||
--- a/src/lib/gssapi/krb5/k5sealv3.c
|
||||
+++ b/src/lib/gssapi/krb5/k5sealv3.c
|
||||
@@ -145,9 +145,8 @@ gss_krb5int_make_seal_token_v3 (krb5_context context,
|
||||
/* TOK_ID */
|
||||
store_16_be(KG2_TOK_WRAP_MSG, outbuf);
|
||||
/* flags */
|
||||
- outbuf[2] = (acceptor_flag
|
||||
- | (conf_req_flag ? FLAG_WRAP_CONFIDENTIAL : 0)
|
||||
- | (ctx->have_acceptor_subkey ? FLAG_ACCEPTOR_SUBKEY : 0));
|
||||
+ outbuf[2] = (acceptor_flag | FLAG_WRAP_CONFIDENTIAL |
|
||||
+ (ctx->have_acceptor_subkey ? FLAG_ACCEPTOR_SUBKEY : 0));
|
||||
/* filler */
|
||||
outbuf[3] = 0xff;
|
||||
/* EC */
|
||||
diff --git a/src/lib/gssapi/krb5/k5sealv3iov.c b/src/lib/gssapi/krb5/k5sealv3iov.c
|
||||
index a73edb6a4..333ee124d 100644
|
||||
--- a/src/lib/gssapi/krb5/k5sealv3iov.c
|
||||
+++ b/src/lib/gssapi/krb5/k5sealv3iov.c
|
||||
@@ -144,9 +144,8 @@ gss_krb5int_make_seal_token_v3_iov(krb5_context context,
|
||||
/* TOK_ID */
|
||||
store_16_be(KG2_TOK_WRAP_MSG, outbuf);
|
||||
/* flags */
|
||||
- outbuf[2] = (acceptor_flag
|
||||
- | (conf_req_flag ? FLAG_WRAP_CONFIDENTIAL : 0)
|
||||
- | (ctx->have_acceptor_subkey ? FLAG_ACCEPTOR_SUBKEY : 0));
|
||||
+ outbuf[2] = (acceptor_flag | FLAG_WRAP_CONFIDENTIAL |
|
||||
+ (ctx->have_acceptor_subkey ? FLAG_ACCEPTOR_SUBKEY : 0));
|
||||
/* filler */
|
||||
outbuf[3] = 0xFF;
|
||||
/* EC */
|
||||
diff --git a/src/lib/kdb/kdb_convert.c b/src/lib/kdb/kdb_convert.c
|
||||
index 76140732f..e1bf1919f 100644
|
||||
--- a/src/lib/kdb/kdb_convert.c
|
||||
+++ b/src/lib/kdb/kdb_convert.c
|
||||
@@ -305,8 +305,6 @@ ulog_conv_2logentry(krb5_context context, krb5_db_entry *entry,
|
||||
krb5_error_code ret;
|
||||
kdbe_attr_type_t *attr_types;
|
||||
int kadm_data_yes;
|
||||
- /* always exclude non-replicated attributes, for now */
|
||||
- krb5_boolean exclude_nra = TRUE;
|
||||
|
||||
nattrs = tmpint = 0;
|
||||
final = -1;
|
||||
@@ -356,7 +354,8 @@ ulog_conv_2logentry(krb5_context context, krb5_db_entry *entry,
|
||||
nattrs++;
|
||||
}
|
||||
} else {
|
||||
- find_changed_attrs(curr, entry, exclude_nra, attr_types, &nattrs);
|
||||
+ /* Always exclude non-replicated attributes for now. */
|
||||
+ find_changed_attrs(curr, entry, TRUE, attr_types, &nattrs);
|
||||
krb5_db_free_principal(context, curr);
|
||||
}
|
||||
|
||||
@@ -402,31 +401,6 @@ ulog_conv_2logentry(krb5_context context, krb5_db_entry *entry,
|
||||
}
|
||||
break;
|
||||
|
||||
- case AT_LAST_SUCCESS:
|
||||
- if (!exclude_nra && entry->last_success >= 0) {
|
||||
- ULOG_ENTRY_TYPE(update, ++final).av_type = AT_LAST_SUCCESS;
|
||||
- ULOG_ENTRY(update, final).av_last_success =
|
||||
- (uint32_t)entry->last_success;
|
||||
- }
|
||||
- break;
|
||||
-
|
||||
- case AT_LAST_FAILED:
|
||||
- if (!exclude_nra && entry->last_failed >= 0) {
|
||||
- ULOG_ENTRY_TYPE(update, ++final).av_type = AT_LAST_FAILED;
|
||||
- ULOG_ENTRY(update, final).av_last_failed =
|
||||
- (uint32_t)entry->last_failed;
|
||||
- }
|
||||
- break;
|
||||
-
|
||||
- case AT_FAIL_AUTH_COUNT:
|
||||
- if (!exclude_nra) {
|
||||
- ULOG_ENTRY_TYPE(update, ++final).av_type =
|
||||
- AT_FAIL_AUTH_COUNT;
|
||||
- ULOG_ENTRY(update, final).av_fail_auth_count =
|
||||
- (uint32_t)entry->fail_auth_count;
|
||||
- }
|
||||
- break;
|
||||
-
|
||||
case AT_PRINC:
|
||||
if (entry->princ->length > 0) {
|
||||
ULOG_ENTRY_TYPE(update, ++final).av_type = AT_PRINC;
|
||||
@@ -552,10 +526,8 @@ ulog_conv_2logentry(krb5_context context, krb5_db_entry *entry,
|
||||
/* END CSTYLED */
|
||||
|
||||
case AT_LEN:
|
||||
- if (entry->len >= 0) {
|
||||
- ULOG_ENTRY_TYPE(update, ++final).av_type = AT_LEN;
|
||||
- ULOG_ENTRY(update, final).av_len = (int16_t)entry->len;
|
||||
- }
|
||||
+ ULOG_ENTRY_TYPE(update, ++final).av_type = AT_LEN;
|
||||
+ ULOG_ENTRY(update, final).av_len = (int16_t)entry->len;
|
||||
break;
|
||||
|
||||
default:
|
||||
diff --git a/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c b/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c
|
||||
index ce038fc3d..0a95101ad 100644
|
||||
--- a/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c
|
||||
+++ b/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c
|
||||
@@ -135,10 +135,6 @@ kdb5_ldap_stash_service_password(int argc, char **argv)
|
||||
print_usage = TRUE;
|
||||
goto cleanup;
|
||||
}
|
||||
- if (file_name == NULL) {
|
||||
- com_err(me, ENOMEM, _("while setting service object password"));
|
||||
- goto cleanup;
|
||||
- }
|
||||
} else { /* argc == 2 */
|
||||
service_object = strdup (argv[1]);
|
||||
if (service_object == NULL) {
|
||||
diff --git a/src/plugins/kdb/ldap/libkdb_ldap/ldap_create.c b/src/plugins/kdb/ldap/libkdb_ldap/ldap_create.c
|
||||
index 1e6fffee5..5b57c799a 100644
|
||||
--- a/src/plugins/kdb/ldap/libkdb_ldap/ldap_create.c
|
||||
+++ b/src/plugins/kdb/ldap/libkdb_ldap/ldap_create.c
|
||||
@@ -56,7 +56,6 @@ krb5_ldap_create(krb5_context context, char *conf_section, char **db_args)
|
||||
krb5_ldap_realm_params *rparams = NULL;
|
||||
krb5_ldap_context *ldap_context=NULL;
|
||||
krb5_boolean realm_obj_created = FALSE;
|
||||
- krb5_boolean krbcontainer_obj_created = FALSE;
|
||||
int mask = 0;
|
||||
|
||||
/* Clear the global error string */
|
||||
@@ -121,15 +120,6 @@ krb5_ldap_create(krb5_context context, char *conf_section, char **db_args)
|
||||
goto cleanup;
|
||||
|
||||
cleanup:
|
||||
- /* If the krbcontainer/realm creation is not complete, do the roll-back here */
|
||||
- if ((krbcontainer_obj_created) && (!realm_obj_created)) {
|
||||
- int rc;
|
||||
- rc = krb5_ldap_delete_krbcontainer(context,
|
||||
- ldap_context->container_dn);
|
||||
- k5_setmsg(context, rc, _("could not complete roll-back, error "
|
||||
- "deleting Kerberos Container"));
|
||||
- }
|
||||
-
|
||||
if (rparams)
|
||||
krb5_ldap_free_realm_params(rparams);
|
||||
|
||||
diff --git a/src/plugins/preauth/pkinit/pkinit_srv.c b/src/plugins/preauth/pkinit/pkinit_srv.c
|
||||
index 27e6ef4d2..6aa646cc6 100644
|
||||
--- a/src/plugins/preauth/pkinit/pkinit_srv.c
|
||||
+++ b/src/plugins/preauth/pkinit/pkinit_srv.c
|
||||
@@ -258,15 +258,7 @@ verify_client_san(krb5_context context,
|
||||
}
|
||||
pkiDebug("%s: no upn san match found\n", __FUNCTION__);
|
||||
|
||||
- /* We found no match */
|
||||
- if (princs != NULL || upns != NULL) {
|
||||
- *valid_san = 0;
|
||||
- /* XXX ??? If there was one or more name in the cert, but
|
||||
- * none matched the client name, then return mismatch? */
|
||||
- retval = KRB5KDC_ERR_CLIENT_NAME_MISMATCH;
|
||||
- }
|
||||
retval = 0;
|
||||
-
|
||||
out:
|
||||
if (princs != NULL) {
|
||||
for (i = 0; princs[i] != NULL; i++)
|
||||
diff --git a/src/tests/hammer/kdc5_hammer.c b/src/tests/hammer/kdc5_hammer.c
|
||||
index 086c21d1c..8220fd97b 100644
|
||||
--- a/src/tests/hammer/kdc5_hammer.c
|
||||
+++ b/src/tests/hammer/kdc5_hammer.c
|
||||
@@ -439,7 +439,6 @@ int get_tgt (context, p_client_str, p_client, ccache)
|
||||
krb5_principal *p_client;
|
||||
krb5_ccache ccache;
|
||||
{
|
||||
- char *cache_name = NULL; /* -f option */
|
||||
long lifetime = KRB5_DEFAULT_LIFE; /* -l option */
|
||||
krb5_error_code code;
|
||||
krb5_creds my_creds;
|
||||
@@ -464,8 +463,7 @@ int get_tgt (context, p_client_str, p_client, ccache)
|
||||
|
||||
code = krb5_cc_initialize (context, ccache, *p_client);
|
||||
if (code != 0) {
|
||||
- com_err (prog, code, "when initializing cache %s",
|
||||
- cache_name?cache_name:"");
|
||||
+ com_err (prog, code, "when initializing cache");
|
||||
return(-1);
|
||||
}
|
||||
|
||||
|
|
@ -1,335 +0,0 @@
|
|||
From 25418e054868301e1a1a5824913b74f2479e1b15 Mon Sep 17 00:00:00 2001
|
||||
From: Robbie Harwood <rharwood@redhat.com>
|
||||
Date: Fri, 28 Jun 2019 13:09:47 -0400
|
||||
Subject: [PATCH] Remove now-unused checksum functions
|
||||
|
||||
fb2dada5eb89c4cd4e39dedd6dbb7dbd5e94f8b8 removed all call sites of
|
||||
krb5int_cbc_checksum(), krb5int_confounder_verify(), and
|
||||
krb5int_confounder_checksum(), but neglected the functions themselves.
|
||||
|
||||
ticket: 8808
|
||||
(cherry picked from commit 2063ff09b384d466c15aca8970c01d074230c815)
|
||||
---
|
||||
src/lib/crypto/krb/Makefile.in | 6 -
|
||||
src/lib/crypto/krb/checksum_cbc.c | 41 ------
|
||||
src/lib/crypto/krb/checksum_confounder.c | 159 -----------------------
|
||||
src/lib/crypto/krb/crypto_int.h | 16 ---
|
||||
src/lib/crypto/krb/deps | 26 ----
|
||||
5 files changed, 248 deletions(-)
|
||||
delete mode 100644 src/lib/crypto/krb/checksum_cbc.c
|
||||
delete mode 100644 src/lib/crypto/krb/checksum_confounder.c
|
||||
|
||||
diff --git a/src/lib/crypto/krb/Makefile.in b/src/lib/crypto/krb/Makefile.in
|
||||
index b587f7e19..2b0c4163d 100644
|
||||
--- a/src/lib/crypto/krb/Makefile.in
|
||||
+++ b/src/lib/crypto/krb/Makefile.in
|
||||
@@ -10,8 +10,6 @@ STLIBOBJS=\
|
||||
aead.o \
|
||||
block_size.o \
|
||||
cf2.o \
|
||||
- checksum_cbc.o \
|
||||
- checksum_confounder.o \
|
||||
checksum_dk_cmac.o \
|
||||
checksum_dk_hmac.o \
|
||||
checksum_etm.o \
|
||||
@@ -70,8 +68,6 @@ OBJS=\
|
||||
$(OUTPRE)aead.$(OBJEXT) \
|
||||
$(OUTPRE)block_size.$(OBJEXT) \
|
||||
$(OUTPRE)cf2.$(OBJEXT) \
|
||||
- $(OUTPRE)checksum_cbc.$(OBJEXT) \
|
||||
- $(OUTPRE)checksum_confounder.$(OBJEXT) \
|
||||
$(OUTPRE)checksum_dk_cmac.$(OBJEXT) \
|
||||
$(OUTPRE)checksum_dk_hmac.$(OBJEXT) \
|
||||
$(OUTPRE)checksum_etm.$(OBJEXT) \
|
||||
@@ -130,8 +126,6 @@ SRCS=\
|
||||
$(srcdir)/aead.c \
|
||||
$(srcdir)/block_size.c \
|
||||
$(srcdir)/cf2.c \
|
||||
- $(srcdir)/checksum_cbc.c \
|
||||
- $(srcdir)/checksum_confounder.c \
|
||||
$(srcdir)/checksum_dk_cmac.c \
|
||||
$(srcdir)/checksum_dk_hmac.c \
|
||||
$(srcdir)/checksum_etm.c \
|
||||
diff --git a/src/lib/crypto/krb/checksum_cbc.c b/src/lib/crypto/krb/checksum_cbc.c
|
||||
deleted file mode 100644
|
||||
index 48afeb0e5..000000000
|
||||
--- a/src/lib/crypto/krb/checksum_cbc.c
|
||||
+++ /dev/null
|
||||
@@ -1,41 +0,0 @@
|
||||
-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */
|
||||
-/* lib/crypto/krb/checksum_cbc.c */
|
||||
-/*
|
||||
- * Copyright (C) 2009 by the Massachusetts Institute of Technology.
|
||||
- * All rights reserved.
|
||||
- *
|
||||
- * Export of this software from the United States of America may
|
||||
- * require a specific license from the United States Government.
|
||||
- * It is the responsibility of any person or organization contemplating
|
||||
- * export to obtain such a license before exporting.
|
||||
- *
|
||||
- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and
|
||||
- * distribute this software and its documentation for any purpose and
|
||||
- * without fee is hereby granted, provided that the above copyright
|
||||
- * notice appear in all copies and that both that copyright notice and
|
||||
- * this permission notice appear in supporting documentation, and that
|
||||
- * the name of M.I.T. not be used in advertising or publicity pertaining
|
||||
- * to distribution of the software without specific, written prior
|
||||
- * permission. Furthermore if you modify this software you must label
|
||||
- * your software as modified software and not distribute it in such a
|
||||
- * fashion that it might be confused with the original M.I.T. software.
|
||||
- * M.I.T. makes no representations about the suitability of
|
||||
- * this software for any purpose. It is provided "as is" without express
|
||||
- * or implied warranty.
|
||||
- */
|
||||
-
|
||||
-/* CBC checksum, which computes the ivec resulting from CBC encryption of the
|
||||
- * input. */
|
||||
-
|
||||
-#include "crypto_int.h"
|
||||
-
|
||||
-krb5_error_code
|
||||
-krb5int_cbc_checksum(const struct krb5_cksumtypes *ctp,
|
||||
- krb5_key key, krb5_keyusage usage,
|
||||
- const krb5_crypto_iov *data, size_t num_data,
|
||||
- krb5_data *output)
|
||||
-{
|
||||
- if (ctp->enc->cbc_mac == NULL)
|
||||
- return KRB5_CRYPTO_INTERNAL;
|
||||
- return ctp->enc->cbc_mac(key, data, num_data, NULL, output);
|
||||
-}
|
||||
diff --git a/src/lib/crypto/krb/checksum_confounder.c b/src/lib/crypto/krb/checksum_confounder.c
|
||||
deleted file mode 100644
|
||||
index 34941562c..000000000
|
||||
--- a/src/lib/crypto/krb/checksum_confounder.c
|
||||
+++ /dev/null
|
||||
@@ -1,159 +0,0 @@
|
||||
-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */
|
||||
-/* lib/crypto/krb/checksum_confounder.c */
|
||||
-/*
|
||||
- * Copyright (C) 2009 by the Massachusetts Institute of Technology.
|
||||
- * All rights reserved.
|
||||
- *
|
||||
- * Export of this software from the United States of America may
|
||||
- * require a specific license from the United States Government.
|
||||
- * It is the responsibility of any person or organization contemplating
|
||||
- * export to obtain such a license before exporting.
|
||||
- *
|
||||
- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and
|
||||
- * distribute this software and its documentation for any purpose and
|
||||
- * without fee is hereby granted, provided that the above copyright
|
||||
- * notice appear in all copies and that both that copyright notice and
|
||||
- * this permission notice appear in supporting documentation, and that
|
||||
- * the name of M.I.T. not be used in advertising or publicity pertaining
|
||||
- * to distribution of the software without specific, written prior
|
||||
- * permission. Furthermore if you modify this software you must label
|
||||
- * your software as modified software and not distribute it in such a
|
||||
- * fashion that it might be confused with the original M.I.T. software.
|
||||
- * M.I.T. makes no representations about the suitability of
|
||||
- * this software for any purpose. It is provided "as is" without express
|
||||
- * or implied warranty.
|
||||
- */
|
||||
-
|
||||
-/*
|
||||
- * Confounder checksum implementation, using tokens of the form:
|
||||
- * enc(xorkey, confounder | hash(confounder | data))
|
||||
- * where xorkey is the key XOR'd with 0xf0 bytes.
|
||||
- */
|
||||
-
|
||||
-#include "crypto_int.h"
|
||||
-
|
||||
-/* Derive a key by XOR with 0xF0 bytes. */
|
||||
-static krb5_error_code
|
||||
-mk_xorkey(krb5_key origkey, krb5_key *xorkey)
|
||||
-{
|
||||
- krb5_error_code retval = 0;
|
||||
- unsigned char *xorbytes;
|
||||
- krb5_keyblock xorkeyblock;
|
||||
- size_t i = 0;
|
||||
-
|
||||
- xorbytes = k5memdup(origkey->keyblock.contents, origkey->keyblock.length,
|
||||
- &retval);
|
||||
- if (xorbytes == NULL)
|
||||
- return retval;
|
||||
- for (i = 0; i < origkey->keyblock.length; i++)
|
||||
- xorbytes[i] ^= 0xf0;
|
||||
-
|
||||
- /* Do a shallow copy here. */
|
||||
- xorkeyblock = origkey->keyblock;
|
||||
- xorkeyblock.contents = xorbytes;
|
||||
-
|
||||
- retval = krb5_k_create_key(0, &xorkeyblock, xorkey);
|
||||
- zapfree(xorbytes, origkey->keyblock.length);
|
||||
- return retval;
|
||||
-}
|
||||
-
|
||||
-krb5_error_code
|
||||
-krb5int_confounder_checksum(const struct krb5_cksumtypes *ctp,
|
||||
- krb5_key key, krb5_keyusage usage,
|
||||
- const krb5_crypto_iov *data, size_t num_data,
|
||||
- krb5_data *output)
|
||||
-{
|
||||
- krb5_error_code ret;
|
||||
- krb5_data conf, hashval;
|
||||
- krb5_key xorkey = NULL;
|
||||
- krb5_crypto_iov *hash_iov, iov;
|
||||
- size_t blocksize = ctp->enc->block_size, hashsize = ctp->hash->hashsize;
|
||||
-
|
||||
- /* Partition the output buffer into confounder and hash. */
|
||||
- conf = make_data(output->data, blocksize);
|
||||
- hashval = make_data(output->data + blocksize, hashsize);
|
||||
-
|
||||
- /* Create the confounder. */
|
||||
- ret = krb5_c_random_make_octets(NULL, &conf);
|
||||
- if (ret != 0)
|
||||
- return ret;
|
||||
-
|
||||
- ret = mk_xorkey(key, &xorkey);
|
||||
- if (ret)
|
||||
- return ret;
|
||||
-
|
||||
- /* Hash the confounder, then the input data. */
|
||||
- hash_iov = k5calloc(num_data + 1, sizeof(krb5_crypto_iov), &ret);
|
||||
- if (hash_iov == NULL)
|
||||
- goto cleanup;
|
||||
- hash_iov[0].flags = KRB5_CRYPTO_TYPE_DATA;
|
||||
- hash_iov[0].data = conf;
|
||||
- memcpy(hash_iov + 1, data, num_data * sizeof(krb5_crypto_iov));
|
||||
- ret = ctp->hash->hash(hash_iov, num_data + 1, &hashval);
|
||||
- if (ret != 0)
|
||||
- goto cleanup;
|
||||
-
|
||||
- /* Confounder and hash are in output buffer; encrypt them in place. */
|
||||
- iov.flags = KRB5_CRYPTO_TYPE_DATA;
|
||||
- iov.data = *output;
|
||||
- ret = ctp->enc->encrypt(xorkey, NULL, &iov, 1);
|
||||
-
|
||||
-cleanup:
|
||||
- free(hash_iov);
|
||||
- krb5_k_free_key(NULL, xorkey);
|
||||
- return ret;
|
||||
-}
|
||||
-
|
||||
-krb5_error_code krb5int_confounder_verify(const struct krb5_cksumtypes *ctp,
|
||||
- krb5_key key, krb5_keyusage usage,
|
||||
- const krb5_crypto_iov *data,
|
||||
- size_t num_data,
|
||||
- const krb5_data *input,
|
||||
- krb5_boolean *valid)
|
||||
-{
|
||||
- krb5_error_code ret;
|
||||
- unsigned char *plaintext = NULL;
|
||||
- krb5_key xorkey = NULL;
|
||||
- krb5_data computed = empty_data();
|
||||
- krb5_crypto_iov *hash_iov = NULL, iov;
|
||||
- size_t blocksize = ctp->enc->block_size, hashsize = ctp->hash->hashsize;
|
||||
-
|
||||
- plaintext = k5memdup(input->data, input->length, &ret);
|
||||
- if (plaintext == NULL)
|
||||
- return ret;
|
||||
-
|
||||
- ret = mk_xorkey(key, &xorkey);
|
||||
- if (ret != 0)
|
||||
- goto cleanup;
|
||||
-
|
||||
- /* Decrypt the input checksum. */
|
||||
- iov.flags = KRB5_CRYPTO_TYPE_DATA;
|
||||
- iov.data = make_data(plaintext, input->length);
|
||||
- ret = ctp->enc->decrypt(xorkey, NULL, &iov, 1);
|
||||
- if (ret != 0)
|
||||
- goto cleanup;
|
||||
-
|
||||
- /* Hash the confounder, then the input data. */
|
||||
- hash_iov = k5calloc(num_data + 1, sizeof(krb5_crypto_iov), &ret);
|
||||
- if (hash_iov == NULL)
|
||||
- goto cleanup;
|
||||
- hash_iov[0].flags = KRB5_CRYPTO_TYPE_DATA;
|
||||
- hash_iov[0].data = make_data(plaintext, blocksize);
|
||||
- memcpy(hash_iov + 1, data, num_data * sizeof(krb5_crypto_iov));
|
||||
- ret = alloc_data(&computed, hashsize);
|
||||
- if (ret != 0)
|
||||
- goto cleanup;
|
||||
- ret = ctp->hash->hash(hash_iov, num_data + 1, &computed);
|
||||
- if (ret != 0)
|
||||
- goto cleanup;
|
||||
-
|
||||
- /* Compare the decrypted hash to the computed one. */
|
||||
- *valid = (k5_bcmp(plaintext + blocksize, computed.data, hashsize) == 0);
|
||||
-
|
||||
-cleanup:
|
||||
- zapfree(plaintext, input->length);
|
||||
- zapfree(computed.data, hashsize);
|
||||
- free(hash_iov);
|
||||
- krb5_k_free_key(NULL, xorkey);
|
||||
- return ret;
|
||||
-}
|
||||
diff --git a/src/lib/crypto/krb/crypto_int.h b/src/lib/crypto/krb/crypto_int.h
|
||||
index 1b4324d71..5cc1f8e43 100644
|
||||
--- a/src/lib/crypto/krb/crypto_int.h
|
||||
+++ b/src/lib/crypto/krb/crypto_int.h
|
||||
@@ -299,11 +299,6 @@ krb5_error_code krb5int_unkeyed_checksum(const struct krb5_cksumtypes *ctp,
|
||||
const krb5_crypto_iov *data,
|
||||
size_t num_data,
|
||||
krb5_data *output);
|
||||
-krb5_error_code krb5int_cbc_checksum(const struct krb5_cksumtypes *ctp,
|
||||
- krb5_key key, krb5_keyusage usage,
|
||||
- const krb5_crypto_iov *data,
|
||||
- size_t num_data,
|
||||
- krb5_data *output);
|
||||
krb5_error_code krb5int_hmacmd5_checksum(const struct krb5_cksumtypes *ctp,
|
||||
krb5_key key, krb5_keyusage usage,
|
||||
const krb5_crypto_iov *data,
|
||||
@@ -317,17 +312,6 @@ krb5_error_code krb5int_dk_cmac_checksum(const struct krb5_cksumtypes *ctp,
|
||||
krb5_key key, krb5_keyusage usage,
|
||||
const krb5_crypto_iov *data,
|
||||
size_t num_data, krb5_data *output);
|
||||
-krb5_error_code krb5int_confounder_checksum(const struct krb5_cksumtypes *ctp,
|
||||
- krb5_key key, krb5_keyusage usage,
|
||||
- const krb5_crypto_iov *data,
|
||||
- size_t num_data,
|
||||
- krb5_data *output);
|
||||
-krb5_error_code krb5int_confounder_verify(const struct krb5_cksumtypes *ctp,
|
||||
- krb5_key key, krb5_keyusage usage,
|
||||
- const krb5_crypto_iov *data,
|
||||
- size_t num_data,
|
||||
- const krb5_data *input,
|
||||
- krb5_boolean *valid);
|
||||
krb5_error_code krb5int_etm_checksum(const struct krb5_cksumtypes *ctp,
|
||||
krb5_key key, krb5_keyusage usage,
|
||||
const krb5_crypto_iov *data,
|
||||
diff --git a/src/lib/crypto/krb/deps b/src/lib/crypto/krb/deps
|
||||
index 2f4af1906..883d12c56 100644
|
||||
--- a/src/lib/crypto/krb/deps
|
||||
+++ b/src/lib/crypto/krb/deps
|
||||
@@ -37,32 +37,6 @@ cf2.so cf2.po $(OUTPRE)cf2.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \
|
||||
$(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \
|
||||
$(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \
|
||||
cf2.c crypto_int.h
|
||||
-checksum_cbc.so checksum_cbc.po $(OUTPRE)checksum_cbc.$(OBJEXT): \
|
||||
- $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \
|
||||
- $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \
|
||||
- $(COM_ERR_DEPS) $(srcdir)/../builtin/aes/aes.h $(srcdir)/../builtin/crypto_mod.h \
|
||||
- $(srcdir)/../builtin/sha2/sha2.h $(top_srcdir)/include/k5-buf.h \
|
||||
- $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \
|
||||
- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \
|
||||
- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \
|
||||
- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \
|
||||
- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \
|
||||
- $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \
|
||||
- $(top_srcdir)/include/socket-utils.h checksum_cbc.c \
|
||||
- crypto_int.h
|
||||
-checksum_confounder.so checksum_confounder.po $(OUTPRE)checksum_confounder.$(OBJEXT): \
|
||||
- $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \
|
||||
- $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \
|
||||
- $(COM_ERR_DEPS) $(srcdir)/../builtin/aes/aes.h $(srcdir)/../builtin/crypto_mod.h \
|
||||
- $(srcdir)/../builtin/sha2/sha2.h $(top_srcdir)/include/k5-buf.h \
|
||||
- $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \
|
||||
- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \
|
||||
- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \
|
||||
- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \
|
||||
- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \
|
||||
- $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \
|
||||
- $(top_srcdir)/include/socket-utils.h checksum_confounder.c \
|
||||
- crypto_int.h
|
||||
checksum_dk_cmac.so checksum_dk_cmac.po $(OUTPRE)checksum_dk_cmac.$(OBJEXT): \
|
||||
$(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \
|
||||
$(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \
|
||||
|
|
@ -1,28 +0,0 @@
|
|||
From 7016aa77499732446d7bc838b95810c8cdf5b15b Mon Sep 17 00:00:00 2001
|
||||
From: Robbie Harwood <rharwood@redhat.com>
|
||||
Date: Fri, 30 Aug 2019 11:19:52 -0400
|
||||
Subject: [PATCH] Remove null check in krb5_gss_duplicate_name()
|
||||
|
||||
Within the krb5 mechanism, we require minor_status to be writable
|
||||
without checking. Remove the null check in krb5_gss_duplicate_name()
|
||||
to squash a forward-null defect.
|
||||
|
||||
(cherry picked from commit 9fd7bc179f0bd74fc83c1edf0247dcfd87fc73e6)
|
||||
---
|
||||
src/lib/gssapi/krb5/duplicate_name.c | 3 +--
|
||||
1 file changed, 1 insertion(+), 2 deletions(-)
|
||||
|
||||
diff --git a/src/lib/gssapi/krb5/duplicate_name.c b/src/lib/gssapi/krb5/duplicate_name.c
|
||||
index b88d97d9d..ea53e9c0d 100644
|
||||
--- a/src/lib/gssapi/krb5/duplicate_name.c
|
||||
+++ b/src/lib/gssapi/krb5/duplicate_name.c
|
||||
@@ -34,8 +34,7 @@ krb5_gss_duplicate_name(OM_uint32 *minor_status, const gss_name_t input_name,
|
||||
krb5_error_code code;
|
||||
krb5_gss_name_t princ, outprinc;
|
||||
|
||||
- if (minor_status)
|
||||
- *minor_status = 0;
|
||||
+ *minor_status = 0;
|
||||
|
||||
code = krb5_gss_init_context(&context);
|
||||
if (code) {
|
||||
|
|
@ -1,385 +0,0 @@
|
|||
From 5125a9bd20b2fa2b0f420dc20780d08af1cc91a6 Mon Sep 17 00:00:00 2001
|
||||
From: Robbie Harwood <rharwood@redhat.com>
|
||||
Date: Tue, 22 Jan 2019 18:34:58 -0500
|
||||
Subject: [PATCH] Remove ovsec_adm_export dump format support
|
||||
|
||||
Dumping only suported single-DES principals. While importing still
|
||||
functioned, it would only have been useful for extremely old (1.3-era)
|
||||
KDCs.
|
||||
|
||||
ticket: 8798 (new)
|
||||
(cherry picked from commit 23b93fd48bc445005436c5be98a7269b599b1800)
|
||||
---
|
||||
doc/admin/admin_commands/kdb5_util.rst | 11 +--
|
||||
doc/admin/database.rst | 14 ----
|
||||
src/kadmin/dbutil/dump.c | 109 ++-----------------------
|
||||
src/kadmin/dbutil/kdb5_util.c | 4 +-
|
||||
src/man/kdb5_util.man | 13 +--
|
||||
src/tests/Makefile.in | 6 --
|
||||
src/tests/t_dump.py | 8 --
|
||||
7 files changed, 13 insertions(+), 152 deletions(-)
|
||||
|
||||
diff --git a/doc/admin/admin_commands/kdb5_util.rst b/doc/admin/admin_commands/kdb5_util.rst
|
||||
index fee68261a..7dd54f797 100644
|
||||
--- a/doc/admin/admin_commands/kdb5_util.rst
|
||||
+++ b/doc/admin/admin_commands/kdb5_util.rst
|
||||
@@ -136,7 +136,7 @@ dump
|
||||
|
||||
.. _kdb5_util_dump:
|
||||
|
||||
- **dump** [**-b7**\|\ **-ov**\|\ **-r13**\|\ **-r18**]
|
||||
+ **dump** [**-b7**\|\ **-r13**\|\ **-r18**]
|
||||
[**-verbose**] [**-mkey_convert**] [**-new_mkey_file**
|
||||
*mkey_file*] [**-rev**] [**-recurse**] [*filename*
|
||||
[*principals*...]]
|
||||
@@ -151,9 +151,6 @@ load_dump version 7". If filename is not specified, or is the string
|
||||
load_dump version 4"). This was the dump format produced on
|
||||
releases prior to 1.2.2.
|
||||
|
||||
-**-ov**
|
||||
- causes the dump to be in "ovsec_adm_export" format.
|
||||
-
|
||||
**-r13**
|
||||
causes the dump to be in the Kerberos 5 1.3 format ("kdb5_util
|
||||
load_dump version 5"). This was the dump format produced on
|
||||
@@ -204,7 +201,7 @@ load
|
||||
|
||||
.. _kdb5_util_load:
|
||||
|
||||
- **load** [**-b7**\|\ **-ov**\|\ **-r13**\|\ **-r18**] [**-hash**]
|
||||
+ **load** [**-b7**\|\ **-r13**\|\ **-r18**] [**-hash**]
|
||||
[**-verbose**] [**-update**] *filename*
|
||||
|
||||
Loads a database dump from the named file into the named database. If
|
||||
@@ -222,10 +219,6 @@ Options:
|
||||
("kdb5_util load_dump version 4"). This was the dump format
|
||||
produced on releases prior to 1.2.2.
|
||||
|
||||
-**-ov**
|
||||
- requires the database to be in "ovsec_adm_import" format. Must be
|
||||
- used with the **-update** option.
|
||||
-
|
||||
**-r13**
|
||||
requires the database to be in Kerberos 5 1.3 format ("kdb5_util
|
||||
load_dump version 5"). This was the dump format produced on
|
||||
diff --git a/doc/admin/database.rst b/doc/admin/database.rst
|
||||
index 2b02af3a0..113a680a6 100644
|
||||
--- a/doc/admin/database.rst
|
||||
+++ b/doc/admin/database.rst
|
||||
@@ -393,20 +393,6 @@ To dump a single principal and later load it, updating the database:
|
||||
If the database file exists, and the *-update* flag was not
|
||||
given, *kdb5_util* will overwrite the existing database.
|
||||
|
||||
-Using kdb5_util to upgrade a master KDC from krb5 1.1.x:
|
||||
-
|
||||
-::
|
||||
-
|
||||
- shell% kdb5_util dump old-kdb-dump
|
||||
- shell% kdb5_util dump -ov old-kdb-dump.ov
|
||||
- [Create a new KDC installation, using the old stash file/master password]
|
||||
- shell% kdb5_util load old-kdb-dump
|
||||
- shell% kdb5_util load -update old-kdb-dump.ov
|
||||
-
|
||||
-The use of old-kdb-dump.ov for an extra dump and load is necessary
|
||||
-to preserve per-principal policy information, which is not included in
|
||||
-the default dump format of krb5 1.1.x.
|
||||
-
|
||||
.. note::
|
||||
|
||||
Using kdb5_util to dump and reload the principal database is
|
||||
diff --git a/src/kadmin/dbutil/dump.c b/src/kadmin/dbutil/dump.c
|
||||
index 8301a33d0..19f2cc230 100644
|
||||
--- a/src/kadmin/dbutil/dump.c
|
||||
+++ b/src/kadmin/dbutil/dump.c
|
||||
@@ -484,83 +484,6 @@ dump_r1_11_policy(void *data, osa_policy_ent_t entry)
|
||||
fprintf(arg->ofile, "\n");
|
||||
}
|
||||
|
||||
-static void
|
||||
-print_key_data(FILE *f, krb5_key_data *kd)
|
||||
-{
|
||||
- int c;
|
||||
-
|
||||
- fprintf(f, "%d\t%d\t", kd->key_data_type[0], kd->key_data_length[0]);
|
||||
- for (c = 0; c < kd->key_data_length[0]; c++)
|
||||
- fprintf(f, "%02x ", kd->key_data_contents[0][c]);
|
||||
-}
|
||||
-
|
||||
-/* Output osa_adb_princ_ent data in a printable serialized format, suitable for
|
||||
- * ovsec_adm_import consumption. */
|
||||
-static krb5_error_code
|
||||
-dump_ov_princ(krb5_context context, krb5_db_entry *entry, const char *name,
|
||||
- FILE *fp, krb5_boolean verbose, krb5_boolean omit_nra)
|
||||
-{
|
||||
- char *princstr;
|
||||
- unsigned int x;
|
||||
- int y, foundcrc;
|
||||
- krb5_tl_data tl_data;
|
||||
- osa_princ_ent_rec adb;
|
||||
- XDR xdrs;
|
||||
- krb5_key_data *key_data;
|
||||
-
|
||||
- tl_data.tl_data_type = KRB5_TL_KADM_DATA;
|
||||
- if (krb5_dbe_lookup_tl_data(context, entry, &tl_data) ||
|
||||
- tl_data.tl_data_length == 0)
|
||||
- return 0;
|
||||
-
|
||||
- memset(&adb, 0, sizeof(adb));
|
||||
- xdrmem_create(&xdrs, (caddr_t)tl_data.tl_data_contents,
|
||||
- tl_data.tl_data_length, XDR_DECODE);
|
||||
- if (!xdr_osa_princ_ent_rec(&xdrs, &adb)) {
|
||||
- xdr_destroy(&xdrs);
|
||||
- return KADM5_XDR_FAILURE;
|
||||
- }
|
||||
- xdr_destroy(&xdrs);
|
||||
-
|
||||
- krb5_unparse_name(context, entry->princ, &princstr);
|
||||
- fprintf(fp, "princ\t%s\t", princstr);
|
||||
- if (adb.policy == NULL)
|
||||
- fputc('\t', fp);
|
||||
- else
|
||||
- fprintf(fp, "%s\t", adb.policy);
|
||||
- fprintf(fp, "%lx\t%d\t%d\t%d", adb.aux_attributes, adb.old_key_len,
|
||||
- adb.old_key_next, adb.admin_history_kvno);
|
||||
-
|
||||
- for (x = 0; x < adb.old_key_len; x++) {
|
||||
- foundcrc = 0;
|
||||
- for (y = 0; y < adb.old_keys[x].n_key_data; y++) {
|
||||
- key_data = &adb.old_keys[x].key_data[y];
|
||||
- if (key_data->key_data_type[0] != ENCTYPE_DES_CBC_CRC)
|
||||
- continue;
|
||||
- if (foundcrc) {
|
||||
- fprintf(stderr, _("Warning! Multiple DES-CBC-CRC keys for "
|
||||
- "principal %s; skipping duplicates.\n"),
|
||||
- princstr);
|
||||
- continue;
|
||||
- }
|
||||
- foundcrc++;
|
||||
-
|
||||
- fputc('\t', fp);
|
||||
- print_key_data(fp, key_data);
|
||||
- }
|
||||
- if (!foundcrc) {
|
||||
- fprintf(stderr, _("Warning! No DES-CBC-CRC key for principal %s, "
|
||||
- "cannot generate OV-compatible record; "
|
||||
- "skipping\n"), princstr);
|
||||
- }
|
||||
- }
|
||||
-
|
||||
- fputc('\n', fp);
|
||||
- free(princstr);
|
||||
- xdr_free(xdr_osa_princ_ent_rec, &adb);
|
||||
- return 0;
|
||||
-}
|
||||
-
|
||||
static krb5_error_code
|
||||
dump_iterator(void *ptr, krb5_db_entry *entry)
|
||||
{
|
||||
@@ -1101,14 +1024,6 @@ process_k5beta7_record(krb5_context context, const char *fname, FILE *filep,
|
||||
process_k5beta7_princ, process_k5beta7_policy);
|
||||
}
|
||||
|
||||
-static int
|
||||
-process_ov_record(krb5_context context, const char *fname, FILE *filep,
|
||||
- krb5_boolean verbose, int *linenop)
|
||||
-{
|
||||
- return process_tagged(context, fname, filep, verbose, linenop,
|
||||
- process_ov_principal, process_k5beta7_policy);
|
||||
-}
|
||||
-
|
||||
static int
|
||||
process_r1_8_record(krb5_context context, const char *fname, FILE *filep,
|
||||
krb5_boolean verbose, int *linenop)
|
||||
@@ -1135,16 +1050,6 @@ dump_version beta7_version = {
|
||||
dump_k5beta7_policy,
|
||||
process_k5beta7_record,
|
||||
};
|
||||
-dump_version ov_version = {
|
||||
- "OpenV*Secure V1.0",
|
||||
- "OpenV*Secure V1.0\t",
|
||||
- 1,
|
||||
- 0,
|
||||
- 0,
|
||||
- dump_ov_princ,
|
||||
- dump_k5beta7_policy,
|
||||
- process_ov_record
|
||||
-};
|
||||
dump_version r1_3_version = {
|
||||
"Kerberos version 5 release 1.3",
|
||||
"kdb5_util load_dump version 5\n",
|
||||
@@ -1267,7 +1172,7 @@ current_dump_sno_in_ulog(krb5_context context, const char *ifile)
|
||||
|
||||
/*
|
||||
* usage is:
|
||||
- * dump_db [-b7] [-ov] [-r13] [-r18] [-verbose] [-mkey_convert]
|
||||
+ * dump_db [-b7] [-r13] [-r18] [-verbose] [-mkey_convert]
|
||||
* [-new_mkey_file mkey_file] [-rev] [-recurse]
|
||||
* [filename [principals...]]
|
||||
*/
|
||||
@@ -1302,7 +1207,8 @@ dump_db(int argc, char **argv)
|
||||
if (!strcmp(argv[aindex], "-b7")) {
|
||||
dump = &beta7_version;
|
||||
} else if (!strcmp(argv[aindex], "-ov")) {
|
||||
- dump = &ov_version;
|
||||
+ fprintf(stderr, _("OV dump format not supported\n"));
|
||||
+ goto error;
|
||||
} else if (!strcmp(argv[aindex], "-r13")) {
|
||||
dump = &r1_3_version;
|
||||
} else if (!strcmp(argv[aindex], "-r18")) {
|
||||
@@ -1515,8 +1421,7 @@ restore_dump(krb5_context context, char *dumpfile, FILE *f,
|
||||
}
|
||||
|
||||
/*
|
||||
- * Usage: load_db [-ov] [-b7] [-r13] [-r18] [-verbose] [-update] [-hash]
|
||||
- * filename
|
||||
+ * Usage: load_db [-b7] [-r13] [-r18] [-verbose] [-update] [-hash] filename
|
||||
*/
|
||||
void
|
||||
load_db(int argc, char **argv)
|
||||
@@ -1540,7 +1445,8 @@ load_db(int argc, char **argv)
|
||||
if (!strcmp(argv[aindex], "-b7")){
|
||||
load = &beta7_version;
|
||||
} else if (!strcmp(argv[aindex], "-ov")) {
|
||||
- load = &ov_version;
|
||||
+ fprintf(stderr, _("OV dump format not supported\n"));
|
||||
+ goto error;
|
||||
} else if (!strcmp(argv[aindex], "-r13")) {
|
||||
load = &r1_3_version;
|
||||
} else if (!strcmp(argv[aindex], "-r18")){
|
||||
@@ -1605,9 +1511,6 @@ load_db(int argc, char **argv)
|
||||
load = &r1_8_version;
|
||||
} else if (strcmp(buf, r1_11_version.header) == 0) {
|
||||
load = &r1_11_version;
|
||||
- } else if (strncmp(buf, ov_version.header,
|
||||
- strlen(ov_version.header)) == 0) {
|
||||
- load = &ov_version;
|
||||
} else {
|
||||
fprintf(stderr, _("%s: dump header bad in %s\n"), progname,
|
||||
dumpfile);
|
||||
diff --git a/src/kadmin/dbutil/kdb5_util.c b/src/kadmin/dbutil/kdb5_util.c
|
||||
index accc959e0..e73e2c68e 100644
|
||||
--- a/src/kadmin/dbutil/kdb5_util.c
|
||||
+++ b/src/kadmin/dbutil/kdb5_util.c
|
||||
@@ -85,10 +85,10 @@ void usage()
|
||||
"\tcreate [-s]\n"
|
||||
"\tdestroy [-f]\n"
|
||||
"\tstash [-f keyfile]\n"
|
||||
- "\tdump [-old|-ov|-b6|-b7|-r13|-r18] [-verbose]\n"
|
||||
+ "\tdump [-old|-b6|-b7|-r13|-r18] [-verbose]\n"
|
||||
"\t [-mkey_convert] [-new_mkey_file mkey_file]\n"
|
||||
"\t [-rev] [-recurse] [filename [princs...]]\n"
|
||||
- "\tload [-old|-ov|-b6|-b7|-r13|-r18] [-verbose] [-update] "
|
||||
+ "\tload [-old|-b6|-b7|-r13|-r18] [-verbose] [-update] "
|
||||
"filename\n"
|
||||
"\tark [-e etype_list] principal\n"
|
||||
"\tadd_mkey [-e etype] [-s]\n"
|
||||
diff --git a/src/man/kdb5_util.man b/src/man/kdb5_util.man
|
||||
index 5ebc68a57..9a36ef0df 100644
|
||||
--- a/src/man/kdb5_util.man
|
||||
+++ b/src/man/kdb5_util.man
|
||||
@@ -1,6 +1,6 @@
|
||||
.\" Man page generated from reStructuredText.
|
||||
.
|
||||
-.TH "KDB5_UTIL" "8" " " "1.17" "MIT Kerberos"
|
||||
+.TH "KDB5_UTIL" "8" " " "1.18" "MIT Kerberos"
|
||||
.SH NAME
|
||||
kdb5_util \- Kerberos database maintenance utility
|
||||
.
|
||||
@@ -136,7 +136,7 @@ kdc.conf(5)\&.
|
||||
.SS dump
|
||||
.INDENT 0.0
|
||||
.INDENT 3.5
|
||||
-\fBdump\fP [\fB\-b7\fP|\fB\-ov\fP|\fB\-r13\fP|\fB\-r18\fP]
|
||||
+\fBdump\fP [\fB\-b7\fP|\fB\-r13\fP|\fB\-r18\fP]
|
||||
[\fB\-verbose\fP] [\fB\-mkey_convert\fP] [\fB\-new_mkey_file\fP
|
||||
\fImkey_file\fP] [\fB\-rev\fP] [\fB\-recurse\fP] [\fIfilename\fP
|
||||
[\fIprincipals\fP\&...]]
|
||||
@@ -154,9 +154,6 @@ causes the dump to be in the Kerberos 5 Beta 7 format ("kdb5_util
|
||||
load_dump version 4"). This was the dump format produced on
|
||||
releases prior to 1.2.2.
|
||||
.TP
|
||||
-\fB\-ov\fP
|
||||
-causes the dump to be in "ovsec_adm_export" format.
|
||||
-.TP
|
||||
\fB\-r13\fP
|
||||
causes the dump to be in the Kerberos 5 1.3 format ("kdb5_util
|
||||
load_dump version 5"). This was the dump format produced on
|
||||
@@ -203,7 +200,7 @@ doing a normal dump instead of a recursive traversal.
|
||||
.SS load
|
||||
.INDENT 0.0
|
||||
.INDENT 3.5
|
||||
-\fBload\fP [\fB\-b7\fP|\fB\-ov\fP|\fB\-r13\fP|\fB\-r18\fP] [\fB\-hash\fP]
|
||||
+\fBload\fP [\fB\-b7\fP|\fB\-r13\fP|\fB\-r18\fP] [\fB\-hash\fP]
|
||||
[\fB\-verbose\fP] [\fB\-update\fP] \fIfilename\fP
|
||||
.UNINDENT
|
||||
.UNINDENT
|
||||
@@ -224,10 +221,6 @@ requires the database to be in the Kerberos 5 Beta 7 format
|
||||
("kdb5_util load_dump version 4"). This was the dump format
|
||||
produced on releases prior to 1.2.2.
|
||||
.TP
|
||||
-\fB\-ov\fP
|
||||
-requires the database to be in "ovsec_adm_import" format. Must be
|
||||
-used with the \fB\-update\fP option.
|
||||
-.TP
|
||||
\fB\-r13\fP
|
||||
requires the database to be in Kerberos 5 1.3 format ("kdb5_util
|
||||
load_dump version 5"). This was the dump format produced on
|
||||
diff --git a/src/tests/Makefile.in b/src/tests/Makefile.in
|
||||
index e27617ee2..c96c5d6b7 100644
|
||||
--- a/src/tests/Makefile.in
|
||||
+++ b/src/tests/Makefile.in
|
||||
@@ -97,7 +97,6 @@ kdb_check: kdc.conf krb5.conf
|
||||
$(RUN_DB_TEST) ../tests/create/kdb5_mkdums $(KTEST_OPTS)
|
||||
$(RUN_DB_TEST) ../tests/verify/kdb5_verify $(KTEST_OPTS)
|
||||
$(RUN_DB_TEST) ../kadmin/dbutil/kdb5_util $(KADMIN_OPTS) dump $(TEST_DB).dump
|
||||
- $(RUN_DB_TEST) ../kadmin/dbutil/kdb5_util $(KADMIN_OPTS) dump -ov $(TEST_DB).ovdump
|
||||
$(RUN_DB_TEST) ../kadmin/dbutil/kdb5_util $(KADMIN_OPTS) destroy -f
|
||||
@echo "====> NOTE!"
|
||||
@echo "The following 'create' command is needed due to a change"
|
||||
@@ -105,16 +104,11 @@ kdb_check: kdc.conf krb5.conf
|
||||
@echo ====
|
||||
$(RUN_DB_TEST) ../kadmin/dbutil/kdb5_util $(KADMIN_OPTS) create -W
|
||||
$(RUN_DB_TEST) ../kadmin/dbutil/kdb5_util $(KADMIN_OPTS) load $(TEST_DB).dump
|
||||
- $(RUN_DB_TEST) ../kadmin/dbutil/kdb5_util $(KADMIN_OPTS) load -update -ov $(TEST_DB).ovdump
|
||||
$(RUN_DB_TEST) ../tests/verify/kdb5_verify $(KTEST_OPTS)
|
||||
$(RUN_DB_TEST) ../kadmin/dbutil/kdb5_util $(KADMIN_OPTS) dump $(TEST_DB).dump2
|
||||
- $(RUN_DB_TEST) ../kadmin/dbutil/kdb5_util $(KADMIN_OPTS) dump -ov $(TEST_DB).ovdump2
|
||||
sort $(TEST_DB).dump > $(TEST_DB).sort
|
||||
sort $(TEST_DB).dump2 > $(TEST_DB).sort2
|
||||
- sort $(TEST_DB).ovdump > $(TEST_DB).ovsort
|
||||
- sort $(TEST_DB).ovdump2 > $(TEST_DB).ovsort2
|
||||
cmp $(TEST_DB).sort $(TEST_DB).sort2
|
||||
- cmp $(TEST_DB).ovsort $(TEST_DB).ovsort2
|
||||
$(RUN_DB_TEST) ../kadmin/dbutil/kdb5_util $(KADMIN_OPTS) destroy -f
|
||||
$(RM) $(TEST_DB)* stash_file
|
||||
|
||||
diff --git a/src/tests/t_dump.py b/src/tests/t_dump.py
|
||||
index d803d5602..5d692df99 100755
|
||||
--- a/src/tests/t_dump.py
|
||||
+++ b/src/tests/t_dump.py
|
||||
@@ -73,7 +73,6 @@ for realm in multidb_realms(start_kdc=False):
|
||||
srcdump_r18 = os.path.join(srcdumpdir, 'dump.r18')
|
||||
srcdump_r13 = os.path.join(srcdumpdir, 'dump.r13')
|
||||
srcdump_b7 = os.path.join(srcdumpdir, 'dump.b7')
|
||||
- srcdump_ov = os.path.join(srcdumpdir, 'dump.ov')
|
||||
|
||||
# Load a dump file from the source directory.
|
||||
realm.run([kdb5_util, 'destroy', '-f'])
|
||||
@@ -86,17 +85,10 @@ for realm in multidb_realms(start_kdc=False):
|
||||
dump_compare(realm, ['-r18'], srcdump_r18)
|
||||
dump_compare(realm, ['-r13'], srcdump_r13)
|
||||
dump_compare(realm, ['-b7'], srcdump_b7)
|
||||
- dump_compare(realm, ['-ov'], srcdump_ov)
|
||||
|
||||
# Load each format of dump, check it, re-dump it, and compare.
|
||||
load_dump_check_compare(realm, ['-r18'], srcdump_r18)
|
||||
load_dump_check_compare(realm, ['-r13'], srcdump_r13)
|
||||
load_dump_check_compare(realm, ['-b7'], srcdump_b7)
|
||||
|
||||
- # Loading the last (-b7 format) dump won't have loaded the
|
||||
- # per-principal kadm data. Load that incrementally with -ov.
|
||||
- realm.run([kadminl, 'getprinc', 'user'], expected_msg='Policy: [none]')
|
||||
- realm.run([kdb5_util, 'load', '-update', '-ov', srcdump_ov])
|
||||
- realm.run([kadminl, 'getprinc', 'user'], expected_msg='Policy: testpol')
|
||||
-
|
||||
success('Dump/load tests')
|
||||
File diff suppressed because it is too large
Load diff
|
|
@ -1,34 +0,0 @@
|
|||
From bf8f84d2116af9aba33202f44fdaf04a76430410 Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Thu, 6 Jun 2019 11:46:58 -0400
|
||||
Subject: [PATCH] Remove strerror() calls from k5_get_error()
|
||||
|
||||
Coverity models strerror() as a function which cannot accept negative
|
||||
values, even though it has defined behavior on all integers.
|
||||
k5_get_error() contains code to call strerror_r() and strerror() if
|
||||
its fptr global is unset, which isn't an expected case in practice.
|
||||
To silence a large number of Coverity false positives, just return a
|
||||
fixed string if fptr is null.
|
||||
|
||||
(cherry picked from commit 2d400bea7a81a5a834a1be6ded439f18e0afa5ba)
|
||||
---
|
||||
src/util/support/errors.c | 5 ++---
|
||||
1 file changed, 2 insertions(+), 3 deletions(-)
|
||||
|
||||
diff --git a/src/util/support/errors.c b/src/util/support/errors.c
|
||||
index 70e1d59d0..f8bea07a3 100644
|
||||
--- a/src/util/support/errors.c
|
||||
+++ b/src/util/support/errors.c
|
||||
@@ -78,10 +78,9 @@ k5_get_error(struct errinfo *ep, long code)
|
||||
|
||||
lock();
|
||||
if (fptr == NULL) {
|
||||
+ /* Should be rare; fptr should be set whenever libkrb5 is loaded. */
|
||||
unlock();
|
||||
- if (strerror_r(code, buf, sizeof(buf)) == 0)
|
||||
- return oom_check(strdup(buf));
|
||||
- return oom_check(strdup(strerror(code)));
|
||||
+ return oom_check(strdup(_("Error code translation unavailable")));
|
||||
}
|
||||
r = fptr(code);
|
||||
#ifndef HAVE_COM_ERR_INTL
|
||||
|
|
@ -1,73 +0,0 @@
|
|||
From 9e71fcd5db98fb7ace02e8684486cc7f092d82ad Mon Sep 17 00:00:00 2001
|
||||
From: Robbie Harwood <rharwood@redhat.com>
|
||||
Date: Wed, 17 Apr 2019 17:07:46 -0400
|
||||
Subject: [PATCH] Remove support for no-flags SAM-2 preauth
|
||||
|
||||
When neither the send-encrypted-sad nor the use-sad-as-key flag is set
|
||||
in the SAM-2 challenge, the protocol calls for the AS key to be
|
||||
combined with the string-to-key of the SAD using a key combination
|
||||
method which has only been implemented for DES and 3DES enctypes.
|
||||
Rather than extending key combination, remove support for this case.
|
||||
|
||||
[ghudson@mit.edu: rewrote commit message, added comment]
|
||||
|
||||
ticket: 8812 (new)
|
||||
(cherry picked from commit c30e0af224ef3716513744fd86aec3eeea90abf9)
|
||||
---
|
||||
src/lib/krb5/krb/preauth_sam2.c | 40 +++++++++------------------------
|
||||
1 file changed, 11 insertions(+), 29 deletions(-)
|
||||
|
||||
diff --git a/src/lib/krb5/krb/preauth_sam2.c b/src/lib/krb5/krb/preauth_sam2.c
|
||||
index c7484c47e..fda86bee2 100644
|
||||
--- a/src/lib/krb5/krb/preauth_sam2.c
|
||||
+++ b/src/lib/krb5/krb/preauth_sam2.c
|
||||
@@ -211,38 +211,20 @@ sam2_process(krb5_context context, krb5_clpreauth_moddata moddata,
|
||||
/* Get encryption key to be used for checksum and sam_response */
|
||||
if (!(sc2b->sam_flags & KRB5_SAM_USE_SAD_AS_KEY)) {
|
||||
/* Retain as_key from above gak_fct call. */
|
||||
-
|
||||
- if (!(sc2b->sam_flags & KRB5_SAM_SEND_ENCRYPTED_SAD)) {
|
||||
- /* as_key = combine_key (as_key, string_to_key(SAD)) */
|
||||
- krb5_keyblock tmp_kb;
|
||||
-
|
||||
- retval = krb5_c_string_to_key(context, sc2b->sam_etype,
|
||||
- &response_data, salt, &tmp_kb);
|
||||
-
|
||||
- if (retval) {
|
||||
- krb5_free_sam_challenge_2(context, sc2);
|
||||
- krb5_free_sam_challenge_2_body(context, sc2b);
|
||||
- if (defsalt.length) free(defsalt.data);
|
||||
- return(retval);
|
||||
- }
|
||||
-
|
||||
- /* This should be a call to the crypto library some day */
|
||||
- /* key types should already match the sam_etype */
|
||||
- retval = krb5int_c_combine_keys(context, &ctx->as_key, &tmp_kb,
|
||||
- &ctx->as_key);
|
||||
-
|
||||
- if (retval) {
|
||||
- krb5_free_sam_challenge_2(context, sc2);
|
||||
- krb5_free_sam_challenge_2_body(context, sc2b);
|
||||
- if (defsalt.length) free(defsalt.data);
|
||||
- return(retval);
|
||||
- }
|
||||
- krb5_free_keyblock_contents(context, &tmp_kb);
|
||||
- }
|
||||
-
|
||||
if (defsalt.length)
|
||||
free(defsalt.data);
|
||||
|
||||
+ if (!(sc2b->sam_flags & KRB5_SAM_SEND_ENCRYPTED_SAD)) {
|
||||
+ /*
|
||||
+ * If no flags are set, the protocol calls for us to combine the
|
||||
+ * initial reply key with the SAD, using a method which is only
|
||||
+ * specified for DES and 3DES enctypes. We no longer support this
|
||||
+ * case.
|
||||
+ */
|
||||
+ krb5_free_sam_challenge_2(context, sc2);
|
||||
+ krb5_free_sam_challenge_2_body(context, sc2b);
|
||||
+ return(KRB5_SAM_UNSUPPORTED);
|
||||
+ }
|
||||
} else {
|
||||
/* as_key = string_to_key(SAD) */
|
||||
|
||||
File diff suppressed because it is too large
Load diff
|
|
@ -1,508 +0,0 @@
|
|||
From 35395701a34f68e99abfe23d07b93c59cd63ad50 Mon Sep 17 00:00:00 2001
|
||||
From: Robbie Harwood <rharwood@redhat.com>
|
||||
Date: Fri, 24 May 2019 13:11:44 -0400
|
||||
Subject: [PATCH] Remove the v4 and afs3 salt types
|
||||
|
||||
In preparation for removing single-DES support, remove the v4 and afs3
|
||||
salt types. The afs3 salt type could only be used with single-DES
|
||||
keys, and the v4 salt type was only useful for single-DES keys from
|
||||
krb4 databases.
|
||||
|
||||
[ghudson@mit.edu: wrote commit message]
|
||||
|
||||
ticket: 8808
|
||||
(cherry picked from commit e0a35ff48c09a26ebb9aefd7e98855a84574b8be)
|
||||
---
|
||||
doc/admin/conf_files/kdc_conf.rst | 2 -
|
||||
src/include/kdb.h | 4 +-
|
||||
src/kadmin/testing/proto/kdc.conf.proto | 2 +-
|
||||
src/kdc/kdc_preauth.c | 40 +++++--------------
|
||||
.../api.current/chpass-principal-v2.exp | 8 ++--
|
||||
.../api.current/get-principal-v2.exp | 4 +-
|
||||
src/lib/kdb/kdb5.c | 4 --
|
||||
src/lib/kdb/kdb_cpw.c | 16 +-------
|
||||
src/lib/krb5/krb/str_conv.c | 2 -
|
||||
src/lib/krb5/krb/t_get_etype_info.py | 7 ----
|
||||
src/man/kdc.conf.man | 14 +------
|
||||
src/tests/dejagnu/config/default.exp | 17 --------
|
||||
src/tests/t_etype_info.py | 24 +----------
|
||||
src/tests/t_keytab.py | 5 ---
|
||||
src/tests/t_renprinc.py | 2 +-
|
||||
src/tests/t_salt.py | 26 +-----------
|
||||
src/util/k5test.py | 11 -----
|
||||
17 files changed, 24 insertions(+), 164 deletions(-)
|
||||
|
||||
diff --git a/doc/admin/conf_files/kdc_conf.rst b/doc/admin/conf_files/kdc_conf.rst
|
||||
index c73791ceb..62d1bfc05 100644
|
||||
--- a/doc/admin/conf_files/kdc_conf.rst
|
||||
+++ b/doc/admin/conf_files/kdc_conf.rst
|
||||
@@ -917,10 +917,8 @@ follows:
|
||||
|
||||
================= ============================================
|
||||
normal default for Kerberos Version 5
|
||||
-v4 the only type used by Kerberos Version 4 (no salt)
|
||||
norealm same as the default, without using realm information
|
||||
onlyrealm uses only realm information as the salt
|
||||
-afs3 AFS version 3, only used for compatibility with Kerberos 4 in AFS
|
||||
special generate a random salt
|
||||
================= ============================================
|
||||
|
||||
diff --git a/src/include/kdb.h b/src/include/kdb.h
|
||||
index 9812a35e6..7749cfc99 100644
|
||||
--- a/src/include/kdb.h
|
||||
+++ b/src/include/kdb.h
|
||||
@@ -73,11 +73,11 @@
|
||||
|
||||
/* Salt types */
|
||||
#define KRB5_KDB_SALTTYPE_NORMAL 0
|
||||
-#define KRB5_KDB_SALTTYPE_V4 1
|
||||
+/* #define KRB5_KDB_SALTTYPE_V4 1 */
|
||||
#define KRB5_KDB_SALTTYPE_NOREALM 2
|
||||
#define KRB5_KDB_SALTTYPE_ONLYREALM 3
|
||||
#define KRB5_KDB_SALTTYPE_SPECIAL 4
|
||||
-#define KRB5_KDB_SALTTYPE_AFS3 5
|
||||
+/* #define KRB5_KDB_SALTTYPE_AFS3 5 */
|
||||
#define KRB5_KDB_SALTTYPE_CERTHASH 6
|
||||
|
||||
/* Attributes */
|
||||
diff --git a/src/kadmin/testing/proto/kdc.conf.proto b/src/kadmin/testing/proto/kdc.conf.proto
|
||||
index 61283ac77..45df78b91 100644
|
||||
--- a/src/kadmin/testing/proto/kdc.conf.proto
|
||||
+++ b/src/kadmin/testing/proto/kdc.conf.proto
|
||||
@@ -12,5 +12,5 @@
|
||||
kadmind_port = 1751
|
||||
kpasswd_port = 1752
|
||||
master_key_type = des3-hmac-sha1
|
||||
- supported_enctypes = des3-hmac-sha1:normal des-cbc-crc:normal des-cbc-crc:v4 des-cbc-md5:normal des-cbc-raw:normal
|
||||
+ supported_enctypes = des3-hmac-sha1:normal des-cbc-crc:normal des-cbc-md5:normal des-cbc-raw:normal
|
||||
}
|
||||
diff --git a/src/kdc/kdc_preauth.c b/src/kdc/kdc_preauth.c
|
||||
index caf133c14..508a5cf89 100644
|
||||
--- a/src/kdc/kdc_preauth.c
|
||||
+++ b/src/kdc/kdc_preauth.c
|
||||
@@ -781,8 +781,8 @@ add_etype_info(krb5_context context, krb5_kdcpreauth_rock rock,
|
||||
return add_pa_data_element(pa_list, pa);
|
||||
}
|
||||
|
||||
-/* Add PW-SALT or AFS3-SALT entries to pa_list as appropriate for the request
|
||||
- * and client principal. */
|
||||
+/* Add PW-SALT entries to pa_list as appropriate for the request and client
|
||||
+ * principal. */
|
||||
static krb5_error_code
|
||||
add_pw_salt(krb5_context context, krb5_kdcpreauth_rock rock,
|
||||
krb5_pa_data ***pa_list)
|
||||
@@ -801,21 +801,13 @@ add_pw_salt(krb5_context context, krb5_kdcpreauth_rock rock,
|
||||
if (ret)
|
||||
return 0;
|
||||
|
||||
- if (salttype == KRB5_KDB_SALTTYPE_AFS3) {
|
||||
- ret = alloc_pa_data(KRB5_PADATA_AFS3_SALT, salt->length + 1, &pa);
|
||||
- if (ret)
|
||||
- goto cleanup;
|
||||
- memcpy(pa->contents, salt->data, salt->length);
|
||||
- pa->contents[salt->length] = '\0';
|
||||
- } else {
|
||||
- /* Steal memory from salt to make the pa-data entry. */
|
||||
- ret = alloc_pa_data(KRB5_PADATA_PW_SALT, 0, &pa);
|
||||
- if (ret)
|
||||
- goto cleanup;
|
||||
- pa->length = salt->length;
|
||||
- pa->contents = (uint8_t *)salt->data;
|
||||
- salt->data = NULL;
|
||||
- }
|
||||
+ /* Steal memory from salt to make the pa-data entry. */
|
||||
+ ret = alloc_pa_data(KRB5_PADATA_PW_SALT, 0, &pa);
|
||||
+ if (ret)
|
||||
+ goto cleanup;
|
||||
+ pa->length = salt->length;
|
||||
+ pa->contents = (uint8_t *)salt->data;
|
||||
+ salt->data = NULL;
|
||||
|
||||
/* add_pa_data_element() claims pa on success or failure. */
|
||||
ret = add_pa_data_element(pa_list, pa);
|
||||
@@ -1545,20 +1537,6 @@ _make_etype_info_entry(krb5_context context,
|
||||
&salttype, &salt);
|
||||
if (retval)
|
||||
goto cleanup;
|
||||
- if (etype_info2 && salttype == KRB5_KDB_SALTTYPE_AFS3) {
|
||||
- switch (etype) {
|
||||
- case ENCTYPE_DES_CBC_CRC:
|
||||
- case ENCTYPE_DES_CBC_MD4:
|
||||
- case ENCTYPE_DES_CBC_MD5:
|
||||
- retval = alloc_data(&entry->s2kparams, 1);
|
||||
- if (retval)
|
||||
- goto cleanup;
|
||||
- entry->s2kparams.data[0] = 1;
|
||||
- break;
|
||||
- default:
|
||||
- break;
|
||||
- }
|
||||
- }
|
||||
|
||||
entry->length = salt->length;
|
||||
entry->salt = (unsigned char *)salt->data;
|
||||
diff --git a/src/lib/kadm5/unit-test/api.current/chpass-principal-v2.exp b/src/lib/kadm5/unit-test/api.current/chpass-principal-v2.exp
|
||||
index 8361fb085..db899a1dc 100644
|
||||
--- a/src/lib/kadm5/unit-test/api.current/chpass-principal-v2.exp
|
||||
+++ b/src/lib/kadm5/unit-test/api.current/chpass-principal-v2.exp
|
||||
@@ -18,8 +18,8 @@ proc test200 {} {
|
||||
|
||||
# I'd like to specify a long list of keysalt tuples and make sure
|
||||
# that chpass does the right thing, but we can only use those
|
||||
- # enctypes that krbtgt has a key for: des-cbc-crc:normal and
|
||||
- # des-cbc-crc:v4, according to the prototype kdc.conf.
|
||||
+ # enctypes that krbtgt has a key for: des-cbc-crc:normal
|
||||
+ # according to the prototype kdc.conf.
|
||||
if {! [cmd [format {
|
||||
kadm5_init admin admin $KADM5_ADMIN_SERVICE null \
|
||||
$KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \
|
||||
@@ -53,10 +53,10 @@ proc test200 {} {
|
||||
}
|
||||
|
||||
# XXX Perhaps I should actually check the key type returned.
|
||||
- if {$num_keys == 3} {
|
||||
+ if {$num_keys == 2} {
|
||||
pass "$test"
|
||||
} else {
|
||||
- fail "$test: $num_keys keys, should be 3"
|
||||
+ fail "$test: $num_keys keys, should be 2"
|
||||
}
|
||||
if { ! [cmd {kadm5_destroy $server_handle}]} {
|
||||
perror "$test: unexpected failure in destroy"
|
||||
diff --git a/src/lib/kadm5/unit-test/api.current/get-principal-v2.exp b/src/lib/kadm5/unit-test/api.current/get-principal-v2.exp
|
||||
index 86c45f49e..8526897ed 100644
|
||||
--- a/src/lib/kadm5/unit-test/api.current/get-principal-v2.exp
|
||||
+++ b/src/lib/kadm5/unit-test/api.current/get-principal-v2.exp
|
||||
@@ -143,8 +143,8 @@ proc test101_102 {rpc} {
|
||||
}
|
||||
|
||||
set failed 0
|
||||
- if {$num_keys != 3} {
|
||||
- fail "$test: num_keys $num_keys should be 3"
|
||||
+ if {$num_keys != 2} {
|
||||
+ fail "$test: num_keys $num_keys should be 2"
|
||||
set failed 1
|
||||
}
|
||||
for {set i 0} {$i < $num_keys} {incr i} {
|
||||
diff --git a/src/lib/kdb/kdb5.c b/src/lib/kdb/kdb5.c
|
||||
index da5332217..b81a44312 100644
|
||||
--- a/src/lib/kdb/kdb5.c
|
||||
+++ b/src/lib/kdb/kdb5.c
|
||||
@@ -2312,15 +2312,11 @@ krb5_dbe_compute_salt(krb5_context context, const krb5_key_data *key,
|
||||
if (retval)
|
||||
return retval;
|
||||
break;
|
||||
- case KRB5_KDB_SALTTYPE_V4:
|
||||
- sdata = empty_data();
|
||||
- break;
|
||||
case KRB5_KDB_SALTTYPE_NOREALM:
|
||||
retval = krb5_principal2salt_norealm(context, princ, &sdata);
|
||||
if (retval)
|
||||
return retval;
|
||||
break;
|
||||
- case KRB5_KDB_SALTTYPE_AFS3:
|
||||
case KRB5_KDB_SALTTYPE_ONLYREALM:
|
||||
return krb5_copy_data(context, &princ->realm, salt_out);
|
||||
case KRB5_KDB_SALTTYPE_SPECIAL:
|
||||
diff --git a/src/lib/kdb/kdb_cpw.c b/src/lib/kdb/kdb_cpw.c
|
||||
index 03efc28ed..450860f47 100644
|
||||
--- a/src/lib/kdb/kdb_cpw.c
|
||||
+++ b/src/lib/kdb/kdb_cpw.c
|
||||
@@ -260,7 +260,6 @@ add_key_pwd(context, master_key, ks_tuple, ks_tuple_count, passwd,
|
||||
krb5_keysalt key_salt;
|
||||
krb5_keyblock key;
|
||||
krb5_data pwd;
|
||||
- krb5_data afs_params = string2data("\1"), *s2k_params;
|
||||
int i, j;
|
||||
krb5_key_data *kd_slot;
|
||||
|
||||
@@ -268,7 +267,6 @@ add_key_pwd(context, master_key, ks_tuple, ks_tuple_count, passwd,
|
||||
krb5_boolean similar;
|
||||
|
||||
similar = 0;
|
||||
- s2k_params = NULL;
|
||||
|
||||
/*
|
||||
* We could use krb5_keysalt_iterate to replace this loop, or use
|
||||
@@ -316,18 +314,6 @@ add_key_pwd(context, master_key, ks_tuple, ks_tuple_count, passwd,
|
||||
&key_salt.data)))
|
||||
return(retval);
|
||||
break;
|
||||
- case KRB5_KDB_SALTTYPE_V4:
|
||||
- key_salt.data.length = 0;
|
||||
- key_salt.data.data = 0;
|
||||
- break;
|
||||
- case KRB5_KDB_SALTTYPE_AFS3:
|
||||
- retval = krb5int_copy_data_contents(context,
|
||||
- &db_entry->princ->realm,
|
||||
- &key_salt.data);
|
||||
- if (retval)
|
||||
- return retval;
|
||||
- s2k_params = &afs_params;
|
||||
- break;
|
||||
case KRB5_KDB_SALTTYPE_SPECIAL:
|
||||
retval = make_random_salt(context, &key_salt);
|
||||
if (retval)
|
||||
@@ -342,7 +328,7 @@ add_key_pwd(context, master_key, ks_tuple, ks_tuple_count, passwd,
|
||||
retval = krb5_c_string_to_key_with_params(context,
|
||||
ks_tuple[i].ks_enctype,
|
||||
&pwd, &key_salt.data,
|
||||
- s2k_params, &key);
|
||||
+ NULL, &key);
|
||||
if (retval) {
|
||||
free(key_salt.data.data);
|
||||
return retval;
|
||||
diff --git a/src/lib/krb5/krb/str_conv.c b/src/lib/krb5/krb/str_conv.c
|
||||
index 3d057241b..c8421a8c1 100644
|
||||
--- a/src/lib/krb5/krb/str_conv.c
|
||||
+++ b/src/lib/krb5/krb/str_conv.c
|
||||
@@ -61,11 +61,9 @@ struct salttype_lookup_entry {
|
||||
#include "kdb.h"
|
||||
static const struct salttype_lookup_entry salttype_table[] = {
|
||||
{ KRB5_KDB_SALTTYPE_NORMAL, "normal" },
|
||||
- { KRB5_KDB_SALTTYPE_V4, "v4", },
|
||||
{ KRB5_KDB_SALTTYPE_NOREALM, "norealm", },
|
||||
{ KRB5_KDB_SALTTYPE_ONLYREALM, "onlyrealm", },
|
||||
{ KRB5_KDB_SALTTYPE_SPECIAL, "special", },
|
||||
- { KRB5_KDB_SALTTYPE_AFS3, "afs3", },
|
||||
};
|
||||
static const int salttype_table_nents = sizeof(salttype_table)/
|
||||
sizeof(salttype_table[0]);
|
||||
diff --git a/src/lib/krb5/krb/t_get_etype_info.py b/src/lib/krb5/krb/t_get_etype_info.py
|
||||
index 7c400be86..3c9168591 100644
|
||||
--- a/src/lib/krb5/krb/t_get_etype_info.py
|
||||
+++ b/src/lib/krb5/krb/t_get_etype_info.py
|
||||
@@ -9,9 +9,6 @@ realm.run([kadminl, 'ank', '-nokey', '+preauth', 'pnokey'])
|
||||
realm.run([kadminl, 'ank', '-e', 'aes256-cts:special', '-pw', 'pw', 'exp'])
|
||||
realm.run([kadminl, 'ank', '-e', 'aes256-cts:special', '-pw', 'pw', '+preauth',
|
||||
'pexp'])
|
||||
-realm.run([kadminl, 'ank', '-e', 'des-cbc-crc:afs3', '-pw', 'pw', 'afs'])
|
||||
-realm.run([kadminl, 'ank', '-e', 'des-cbc-crc:afs3', '-pw', 'pw', '+preauth',
|
||||
- 'pafs'])
|
||||
|
||||
# Extract the explicit salt values from the database.
|
||||
out = realm.run([kdb5_util, 'tabdump', 'keyinfo'])
|
||||
@@ -56,8 +53,4 @@ realm.run(['./t_get_etype_info', 'exp'],
|
||||
realm.run(['./t_get_etype_info', 'pexp'],
|
||||
expected_msg='etype: aes256-cts\nsalt: ' + pexp_salt + '\n')
|
||||
|
||||
-msg = 'etype: des-cbc-crc\nsalt: KRBTEST.COM\ns2kparams: 01\n'
|
||||
-realm.run(['./t_get_etype_info', 'afs'], expected_msg=msg)
|
||||
-realm.run(['./t_get_etype_info', 'pafs'], expected_msg=msg)
|
||||
-
|
||||
success('krb5_get_etype_info() tests')
|
||||
diff --git a/src/man/kdc.conf.man b/src/man/kdc.conf.man
|
||||
index ab3ee0289..4a75be8cb 100644
|
||||
--- a/src/man/kdc.conf.man
|
||||
+++ b/src/man/kdc.conf.man
|
||||
@@ -1,6 +1,6 @@
|
||||
.\" Man page generated from reStructuredText.
|
||||
.
|
||||
-.TH "KDC.CONF" "5" " " "1.17" "MIT Kerberos"
|
||||
+.TH "KDC.CONF" "5" " " "1.18" "MIT Kerberos"
|
||||
.SH NAME
|
||||
kdc.conf \- Kerberos V5 KDC configuration file
|
||||
.
|
||||
@@ -1148,12 +1148,6 @@ default for Kerberos Version 5
|
||||
T}
|
||||
_
|
||||
T{
|
||||
-v4
|
||||
-T} T{
|
||||
-the only type used by Kerberos Version 4 (no salt)
|
||||
-T}
|
||||
-_
|
||||
-T{
|
||||
norealm
|
||||
T} T{
|
||||
same as the default, without using realm information
|
||||
@@ -1166,12 +1160,6 @@ uses only realm information as the salt
|
||||
T}
|
||||
_
|
||||
T{
|
||||
-afs3
|
||||
-T} T{
|
||||
-AFS version 3, only used for compatibility with Kerberos 4 in AFS
|
||||
-T}
|
||||
-_
|
||||
-T{
|
||||
special
|
||||
T} T{
|
||||
generate a random salt
|
||||
diff --git a/src/tests/dejagnu/config/default.exp b/src/tests/dejagnu/config/default.exp
|
||||
index ea9bedd45..c061d764e 100644
|
||||
--- a/src/tests/dejagnu/config/default.exp
|
||||
+++ b/src/tests/dejagnu/config/default.exp
|
||||
@@ -238,22 +238,6 @@ set passes {
|
||||
{master_key_type=aes256-cts-hmac-sha1-96}
|
||||
{dummy=[verbose -log "AES + DES enctypes, DES3 TGT"]}
|
||||
}
|
||||
- {
|
||||
- des-v4
|
||||
- mode=udp
|
||||
- des3_krbtgt=0
|
||||
- {supported_enctypes=des-cbc-crc:v4}
|
||||
- {default_tkt_enctypes(client)=des-cbc-crc}
|
||||
- {dummy=[verbose -log "DES TGT, DES-CRC enctype, V4 salt"]}
|
||||
- }
|
||||
- {
|
||||
- des-md5-v4
|
||||
- mode=udp
|
||||
- des3_krbtgt=0
|
||||
- {supported_enctypes=des-cbc-md5:v4 des-cbc-crc:v4}
|
||||
- {default_tkt_enctypes(client)=des-cbc-md5 des-cbc-crc}
|
||||
- {dummy=[verbose -log "DES TGT, DES-MD5 and -CRC enctypes, V4 salt"]}
|
||||
- }
|
||||
{
|
||||
all-enctypes
|
||||
mode=udp
|
||||
@@ -356,7 +340,6 @@ set unused_passes {
|
||||
aes128-cts-hmac-sha1-96:normal aes128-cts-hmac-sha1-96:norealm \
|
||||
des3-cbc-sha1:normal des3-cbc-sha1:none \
|
||||
des-cbc-md5:normal des-cbc-md4:normal des-cbc-crc:normal \
|
||||
- des-cbc-md5:v4 des-cbc-md4:v4 des-cbc-crc:v4 \
|
||||
}
|
||||
{dummy=[verbose -log "DES3 TGT, default enctypes"]}
|
||||
}
|
||||
diff --git a/src/tests/t_etype_info.py b/src/tests/t_etype_info.py
|
||||
index 2026e7876..c21d054f1 100644
|
||||
--- a/src/tests/t_etype_info.py
|
||||
+++ b/src/tests/t_etype_info.py
|
||||
@@ -1,6 +1,6 @@
|
||||
from k5test import *
|
||||
|
||||
-supported_enctypes = 'aes128-cts des3-cbc-sha1 rc4-hmac des-cbc-crc:afs3'
|
||||
+supported_enctypes = 'aes128-cts des3-cbc-sha1 rc4-hmac'
|
||||
conf = {'libdefaults': {'allow_weak_crypto': 'true'},
|
||||
'realms': {'$realm': {'supported_enctypes': supported_enctypes}}}
|
||||
realm = K5Realm(create_host=False, get_creds=False, krb5_conf=conf)
|
||||
@@ -43,28 +43,6 @@ test_etinfo('preauthuser', 'rc4-hmac-exp des3 rc4 des-cbc-crc',
|
||||
test_etinfo('preauthuser', 'rc4 aes256-cts',
|
||||
['error etype_info2 rc4-hmac KRBTEST.COMpreauthuser'])
|
||||
|
||||
-# AFS3 salt for DES enctypes is conveyed using s2kparams in
|
||||
-# PA-ETYPE-INFO2, not at all in PA-ETYPE-INFO, and with a special padata
|
||||
-# type instead of PA-PW-SALT.
|
||||
-test_etinfo('user', 'des-cbc-crc rc4',
|
||||
- ['asrep etype_info2 des-cbc-crc KRBTEST.COM 01',
|
||||
- 'asrep etype_info des-cbc-crc KRBTEST.COM',
|
||||
- 'asrep afs3_salt KRBTEST.COM'])
|
||||
-test_etinfo('preauthuser', 'des-cbc-crc rc4',
|
||||
- ['error etype_info2 des-cbc-crc KRBTEST.COM 01',
|
||||
- 'error etype_info des-cbc-crc KRBTEST.COM'])
|
||||
-
|
||||
-# DES keys can be used with other DES enctypes. The requested enctype
|
||||
-# shows up in the etype-info, not the database key enctype.
|
||||
-test_etinfo('user', 'des-cbc-md4 rc4',
|
||||
- ['asrep etype_info2 des-cbc-md4 KRBTEST.COM 01',
|
||||
- 'asrep etype_info des-cbc-md4 KRBTEST.COM',
|
||||
- 'asrep afs3_salt KRBTEST.COM'])
|
||||
-test_etinfo('user', 'des-cbc-md5 rc4',
|
||||
- ['asrep etype_info2 des KRBTEST.COM 01',
|
||||
- 'asrep etype_info des KRBTEST.COM',
|
||||
- 'asrep afs3_salt KRBTEST.COM'])
|
||||
-
|
||||
# If no keys are found matching the request enctypes, a
|
||||
# preauth-required error can be generated with no etype-info at all
|
||||
# (to allow for preauth mechs which don't depend on long-term keys).
|
||||
diff --git a/src/tests/t_keytab.py b/src/tests/t_keytab.py
|
||||
index 72e09daac..633f7c7ef 100755
|
||||
--- a/src/tests/t_keytab.py
|
||||
+++ b/src/tests/t_keytab.py
|
||||
@@ -155,9 +155,6 @@ realm.run([kadminl, 'ank', '-pw', 'pw', 'default'])
|
||||
realm.run([kadminl, 'ank', '-e', 'aes256-cts:special', '-pw', 'pw', 'exp'])
|
||||
realm.run([kadminl, 'ank', '-e', 'aes256-cts:special', '-pw', 'pw', '+preauth',
|
||||
'pexp'])
|
||||
-realm.run([kadminl, 'ank', '-e', 'des-cbc-crc:afs3', '-pw', 'pw', 'afs'])
|
||||
-realm.run([kadminl, 'ank', '-e', 'des-cbc-crc:afs3', '-pw', 'pw', '+preauth',
|
||||
- 'pafs'])
|
||||
|
||||
# Extract one of the explicit salt values from the database.
|
||||
out = realm.run([kdb5_util, 'tabdump', 'keyinfo'])
|
||||
@@ -187,8 +184,6 @@ test_addent(realm, 'default', '-f')
|
||||
test_addent(realm, 'default', '-f -e aes128-cts')
|
||||
test_addent(realm, 'exp', '-f')
|
||||
test_addent(realm, 'pexp', '-f')
|
||||
-test_addent(realm, 'afs', '-f')
|
||||
-test_addent(realm, 'pafs', '-f')
|
||||
|
||||
success('Keytab-related tests')
|
||||
success('Keytab-related tests')
|
||||
diff --git a/src/tests/t_renprinc.py b/src/tests/t_renprinc.py
|
||||
index 46cbed441..3dbb3e77e 100755
|
||||
--- a/src/tests/t_renprinc.py
|
||||
+++ b/src/tests/t_renprinc.py
|
||||
@@ -25,7 +25,7 @@ from k5test import *
|
||||
enctype = "aes128-cts"
|
||||
|
||||
realm = K5Realm(create_host=False, create_user=False)
|
||||
-salttypes = ('normal', 'v4', 'norealm', 'onlyrealm')
|
||||
+salttypes = ('normal', 'norealm', 'onlyrealm')
|
||||
|
||||
# For a variety of salt types, test that we can rename a principal and
|
||||
# still get tickets with the same password.
|
||||
diff --git a/src/tests/t_salt.py b/src/tests/t_salt.py
|
||||
index 278911a22..008efcb03 100755
|
||||
--- a/src/tests/t_salt.py
|
||||
+++ b/src/tests/t_salt.py
|
||||
@@ -15,13 +15,9 @@ def test_salt(realm, e1, salt, e2):
|
||||
realm.run([kadminl, 'delprinc', 'user'])
|
||||
|
||||
# Enctype/salt pairs chosen with non-default salt types.
|
||||
-# The enctypes are mostly arbitrary, though afs3 must only be used with des.
|
||||
-# We do not enforce that v4 salts must only be used with des, but it seems
|
||||
-# like a good idea.
|
||||
-salts = [('des-cbc-crc', 'afs3'),
|
||||
- ('des3-cbc-sha1', 'norealm'),
|
||||
+# The enctypes are mostly arbitrary.
|
||||
+salts = [('des3-cbc-sha1', 'norealm'),
|
||||
('arcfour-hmac', 'onlyrealm'),
|
||||
- ('des-cbc-crc', 'v4'),
|
||||
('aes128-cts-hmac-sha1-96', 'special')]
|
||||
# These enctypes are chosen to cover the different string-to-key routines.
|
||||
# Omit ":normal" from aes256 to check that salttype defaulting works.
|
||||
@@ -56,22 +52,4 @@ dup_kstypes = ['arcfour-hmac-md5:normal,rc4-hmac:normal',
|
||||
for ks in dup_kstypes:
|
||||
test_dup(realm, ks)
|
||||
|
||||
-# Attempt to create a principal with a non-des enctype and the afs3 salt,
|
||||
-# verifying that the expected error is received and the principal creation
|
||||
-# fails.
|
||||
-def test_reject_afs3(realm, etype):
|
||||
- query = 'ank -e ' + etype + ':afs3 -pw password princ1'
|
||||
- realm.run([kadminl, 'ank', '-e', etype + ':afs3', '-pw', 'password',
|
||||
- 'princ1'], expected_code=1,
|
||||
- expected_msg='Invalid key generation parameters from KDC')
|
||||
- realm.run([kadminl, 'getprinc', 'princ1'], expected_code=1,
|
||||
- expected_msg='Principal does not exist')
|
||||
-
|
||||
-# Verify that the afs3 salt is rejected for arcfour and pbkdf2 enctypes.
|
||||
-# We do not currently do any verification on the key-generation parameters
|
||||
-# for the triple-DES enctypes, so that test is commented out.
|
||||
-test_reject_afs3(realm, 'arcfour-hmac')
|
||||
-test_reject_afs3(realm, 'aes256-cts-hmac-sha1-96')
|
||||
-#test_reject_afs3(realm, 'des3-cbc-sha1')
|
||||
-
|
||||
success("Salt types")
|
||||
diff --git a/src/util/k5test.py b/src/util/k5test.py
|
||||
index 3aec1ef92..b6d93f1d8 100644
|
||||
--- a/src/util/k5test.py
|
||||
+++ b/src/util/k5test.py
|
||||
@@ -1246,17 +1246,6 @@ _passes = [
|
||||
# No special settings; exercises AES256.
|
||||
('default', None, None, None),
|
||||
|
||||
- # Exercise a DES enctype and the v4 salt type.
|
||||
- ('desv4', None,
|
||||
- {'libdefaults': {
|
||||
- 'default_tgs_enctypes': 'des-cbc-crc',
|
||||
- 'default_tkt_enctypes': 'des-cbc-crc',
|
||||
- 'permitted_enctypes': 'des-cbc-crc',
|
||||
- 'allow_weak_crypto': 'true'}},
|
||||
- {'realms': {'$realm': {
|
||||
- 'supported_enctypes': 'des-cbc-crc:v4',
|
||||
- 'master_key_type': 'des-cbc-crc'}}}),
|
||||
-
|
||||
# Exercise the DES3 enctype.
|
||||
('des3', None,
|
||||
{'libdefaults': {
|
||||
|
|
@ -1,26 +0,0 @@
|
|||
From 6b50f9c5b2a1b856e65fa69de05e7c05d2b89614 Mon Sep 17 00:00:00 2001
|
||||
From: Robbie Harwood <rharwood@redhat.com>
|
||||
Date: Tue, 23 Aug 2016 16:32:09 -0400
|
||||
Subject: [PATCH] Set a more modern default ksu CMD_PATH
|
||||
|
||||
ksu uses CMD_PATH to expand command names in .k5users. Include the /usr
|
||||
tree and .../sbin variants. Drop nonstandard /local.
|
||||
|
||||
ticket: 8807 (new)
|
||||
(cherry picked from commit 9eb937a6e1f740d323221813e5da096d30bd68de)
|
||||
---
|
||||
src/clients/ksu/Makefile.in | 2 +-
|
||||
1 file changed, 1 insertion(+), 1 deletion(-)
|
||||
|
||||
diff --git a/src/clients/ksu/Makefile.in b/src/clients/ksu/Makefile.in
|
||||
index 5755bb58a..9d58f29b5 100644
|
||||
--- a/src/clients/ksu/Makefile.in
|
||||
+++ b/src/clients/ksu/Makefile.in
|
||||
@@ -1,6 +1,6 @@
|
||||
mydir=clients$(S)ksu
|
||||
BUILDTOP=$(REL)..$(S)..
|
||||
-DEFINES = -DGET_TGT_VIA_PASSWD -DPRINC_LOOK_AHEAD -DCMD_PATH='"/bin /local/bin"'
|
||||
+DEFINES = -DGET_TGT_VIA_PASSWD -DPRINC_LOOK_AHEAD -DCMD_PATH='"/usr/local/sbin /usr/local/bin /sbin /bin /usr/sbin /usr/bin"'
|
||||
|
||||
KSU_LIBS=@KSU_LIBS@
|
||||
PAM_LIBS=@PAM_LIBS@
|
||||
|
|
@ -1,76 +0,0 @@
|
|||
From 3b4f517a3a403943877e925ae0eb1745611b996f Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Sun, 5 May 2019 18:53:27 -0400
|
||||
Subject: [PATCH] Simplify SAM-2 as_key handling
|
||||
|
||||
The ctx->gak_fct() call in sam2_process() used an empty salt instead
|
||||
of the default salt when the KDC did not supply an explicit salt.
|
||||
This bug arose when commit bc096a77ffdab283d77c2e0fc1fdd15b9f77eb41
|
||||
changed the internal contracts around salts but did not adjust the
|
||||
SAM-2 code. Commit e9aa891fcdb4c08d39902ab89afb268042b60c86 fixed the
|
||||
resulting bug, but mistakenly did not adjust the gak_fct call to use
|
||||
the correct salt.
|
||||
|
||||
Later on, the code contains a redundant call to krb5_c_string_to_key()
|
||||
in the non-USE_SAD_AS_KEY modes, replacing ctx->as_key. This call was
|
||||
properly adjusted by commit e9aa891fcdb4c08d39902ab89afb268042b60c86,
|
||||
so the improper gak_fct call did not manifest as a bug.
|
||||
|
||||
Fix the gak_fct call to supply the correct salt, and remove the
|
||||
redundant string_to_key operation.
|
||||
|
||||
(cherry picked from commit d48670c51460e9a74b4f4a9966f85ca6f77c1d8b)
|
||||
---
|
||||
src/lib/krb5/krb/preauth_sam2.c | 25 +++----------------------
|
||||
1 file changed, 3 insertions(+), 22 deletions(-)
|
||||
|
||||
diff --git a/src/lib/krb5/krb/preauth_sam2.c b/src/lib/krb5/krb/preauth_sam2.c
|
||||
index 4c70021a9..c7484c47e 100644
|
||||
--- a/src/lib/krb5/krb/preauth_sam2.c
|
||||
+++ b/src/lib/krb5/krb/preauth_sam2.c
|
||||
@@ -95,7 +95,6 @@ sam2_process(krb5_context context, krb5_clpreauth_moddata moddata,
|
||||
krb5_prompt kprompt;
|
||||
krb5_prompt_type prompt_type;
|
||||
krb5_data defsalt, *salt;
|
||||
- struct gak_password *gakpw;
|
||||
krb5_checksum **cksum;
|
||||
krb5_data *scratch = NULL;
|
||||
krb5_boolean valid_cksum = 0;
|
||||
@@ -152,9 +151,8 @@ sam2_process(krb5_context context, krb5_clpreauth_moddata moddata,
|
||||
|
||||
salt = ctx->default_salt ? NULL : &ctx->salt;
|
||||
retval = ctx->gak_fct(context, request->client, sc2b->sam_etype,
|
||||
- prompter, prompter_data, &ctx->salt,
|
||||
- &ctx->s2kparams, &ctx->as_key,
|
||||
- ctx->gak_data, ctx->rctx.items);
|
||||
+ prompter, prompter_data, salt, &ctx->s2kparams,
|
||||
+ &ctx->as_key, ctx->gak_data, ctx->rctx.items);
|
||||
if (retval) {
|
||||
krb5_free_sam_challenge_2(context, sc2);
|
||||
krb5_free_sam_challenge_2_body(context, sc2b);
|
||||
@@ -212,24 +210,7 @@ sam2_process(krb5_context context, krb5_clpreauth_moddata moddata,
|
||||
|
||||
/* Get encryption key to be used for checksum and sam_response */
|
||||
if (!(sc2b->sam_flags & KRB5_SAM_USE_SAD_AS_KEY)) {
|
||||
- /* as_key = string_to_key(password) */
|
||||
-
|
||||
- if (ctx->as_key.length) {
|
||||
- krb5_free_keyblock_contents(context, &ctx->as_key);
|
||||
- ctx->as_key.length = 0;
|
||||
- }
|
||||
-
|
||||
- /* generate a key using the supplied password */
|
||||
- gakpw = ctx->gak_data;
|
||||
- retval = krb5_c_string_to_key(context, sc2b->sam_etype,
|
||||
- gakpw->password, salt, &ctx->as_key);
|
||||
-
|
||||
- if (retval) {
|
||||
- krb5_free_sam_challenge_2(context, sc2);
|
||||
- krb5_free_sam_challenge_2_body(context, sc2b);
|
||||
- if (defsalt.length) free(defsalt.data);
|
||||
- return(retval);
|
||||
- }
|
||||
+ /* Retain as_key from above gak_fct call. */
|
||||
|
||||
if (!(sc2b->sam_flags & KRB5_SAM_SEND_ENCRYPTED_SAD)) {
|
||||
/* as_key = combine_key (as_key, string_to_key(SAD)) */
|
||||
|
|
@ -1,165 +0,0 @@
|
|||
From 18bd513161900357110e96b06c53144a212ab00c Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Thu, 22 Aug 2019 16:19:12 -0400
|
||||
Subject: [PATCH] Simplify krb5_dbe_def_search_enctype()
|
||||
|
||||
Key data is now sorted in descending kvno order (since commit
|
||||
44ad57d8d38efc944f64536354435f5b721c0ee0) and key enctypes can be
|
||||
compared with a simple equality test (since single-DES support was
|
||||
removed in commit fb2dada5eb89c4cd4e39dedd6dbb7dbd5e94f8b8). Use
|
||||
these assumptions to simplify krb5_dbe_def_search_enctype().
|
||||
|
||||
The rewrite contains one probably-unnoticeable bugfix: if enctype,
|
||||
salttype, and kvno are all given as -1 in a repeated search, yield all
|
||||
key entries of permitted enctype, not just entries of the maximum
|
||||
kvno.
|
||||
|
||||
(cherry picked from commit fcfb0e47c995a7e9f956c3716be3175f44ad26e0)
|
||||
---
|
||||
src/lib/kdb/kdb_default.c | 117 +++++++++++++++-----------------------
|
||||
1 file changed, 45 insertions(+), 72 deletions(-)
|
||||
|
||||
diff --git a/src/lib/kdb/kdb_default.c b/src/lib/kdb/kdb_default.c
|
||||
index a1021f13a..231a0d8b4 100644
|
||||
--- a/src/lib/kdb/kdb_default.c
|
||||
+++ b/src/lib/kdb/kdb_default.c
|
||||
@@ -37,94 +37,67 @@
|
||||
|
||||
|
||||
/*
|
||||
- * Given a particular enctype and optional salttype and kvno, find the
|
||||
- * most appropriate krb5_key_data entry of the database entry.
|
||||
- *
|
||||
- * If stype or kvno is negative, it is ignored.
|
||||
- * If kvno is 0 get the key which is maxkvno for the princ and matches
|
||||
- * the other attributes.
|
||||
+ * Set *kd_out to the key data entry matching kvno, enctype, and salttype. If
|
||||
+ * any of those three parameters are -1, ignore them. If kvno is 0, match only
|
||||
+ * the highest kvno. Begin searching at the index *start and set *start to the
|
||||
+ * index after the match. Do not return keys of non-permitted enctypes; return
|
||||
+ * KRB5_KDB_NO_PERMITTED_KEY if the whole list was searched and only
|
||||
+ * non-permitted matches were found.
|
||||
*/
|
||||
krb5_error_code
|
||||
-krb5_dbe_def_search_enctype(kcontext, dbentp, start, ktype, stype, kvno, kdatap)
|
||||
- krb5_context kcontext;
|
||||
- krb5_db_entry *dbentp;
|
||||
- krb5_int32 *start;
|
||||
- krb5_int32 ktype;
|
||||
- krb5_int32 stype;
|
||||
- krb5_int32 kvno;
|
||||
- krb5_key_data **kdatap;
|
||||
+krb5_dbe_def_search_enctype(krb5_context context, krb5_db_entry *ent,
|
||||
+ krb5_int32 *start, krb5_int32 enctype,
|
||||
+ krb5_int32 salttype, krb5_int32 kvno,
|
||||
+ krb5_key_data **kd_out)
|
||||
{
|
||||
- int i, idx;
|
||||
- int maxkvno;
|
||||
- krb5_key_data *datap;
|
||||
- krb5_error_code ret;
|
||||
- krb5_boolean saw_non_permitted = FALSE;
|
||||
-
|
||||
- ret = 0;
|
||||
- if (ktype != -1 && !krb5_is_permitted_enctype(kcontext, ktype))
|
||||
- return KRB5_KDB_NO_PERMITTED_KEY;
|
||||
-
|
||||
- if (kvno == -1 && stype == -1 && ktype == -1)
|
||||
- kvno = 0;
|
||||
+ krb5_key_data *kd;
|
||||
+ krb5_int32 db_salttype;
|
||||
+ krb5_boolean saw_non_permitted = FALSE;
|
||||
+ int i;
|
||||
|
||||
- if (kvno == 0) {
|
||||
- /* Get the max key version */
|
||||
- for (i = 0; i < dbentp->n_key_data; i++) {
|
||||
- if (kvno < dbentp->key_data[i].key_data_kvno) {
|
||||
- kvno = dbentp->key_data[i].key_data_kvno;
|
||||
- }
|
||||
- }
|
||||
- }
|
||||
+ *kd_out = NULL;
|
||||
|
||||
- maxkvno = -1;
|
||||
- idx = -1;
|
||||
- datap = (krb5_key_data *) NULL;
|
||||
- for (i = *start; i < dbentp->n_key_data; i++) {
|
||||
- krb5_boolean similar;
|
||||
- krb5_int32 db_stype;
|
||||
-
|
||||
- ret = 0;
|
||||
- if (dbentp->key_data[i].key_data_ver > 1) {
|
||||
- db_stype = dbentp->key_data[i].key_data_type[1];
|
||||
- } else {
|
||||
- db_stype = KRB5_KDB_SALTTYPE_NORMAL;
|
||||
- }
|
||||
-
|
||||
- /* Match this entry against the arguments. */
|
||||
- if (ktype != -1) {
|
||||
- ret = krb5_c_enctype_compare(kcontext, (krb5_enctype) ktype,
|
||||
- dbentp->key_data[i].key_data_type[0],
|
||||
- &similar);
|
||||
- if (ret != 0 || !similar)
|
||||
- continue;
|
||||
- }
|
||||
- if (stype >= 0 && db_stype != stype)
|
||||
+ if (enctype != -1 && !krb5_is_permitted_enctype(context, enctype))
|
||||
+ return KRB5_KDB_NO_PERMITTED_KEY;
|
||||
+ if (ent->n_key_data == 0)
|
||||
+ return KRB5_KDB_NO_MATCHING_KEY;
|
||||
+
|
||||
+ /* Match the highest kvno if kvno is 0. Key data is sorted in descending
|
||||
+ * order of kvno. */
|
||||
+ if (kvno == 0)
|
||||
+ kvno = ent->key_data[0].key_data_kvno;
|
||||
+
|
||||
+ for (i = *start; i < ent->n_key_data; i++) {
|
||||
+ kd = &ent->key_data[i];
|
||||
+ db_salttype = (kd->key_data_ver > 1) ? kd->key_data_type[1] :
|
||||
+ KRB5_KDB_SALTTYPE_NORMAL;
|
||||
+
|
||||
+ /* Match this entry against the arguments. Stop searching if we have
|
||||
+ * passed the entries for the requested kvno. */
|
||||
+ if (enctype != -1 && kd->key_data_type[0] != enctype)
|
||||
+ continue;
|
||||
+ if (salttype >= 0 && db_salttype != salttype)
|
||||
continue;
|
||||
- if (kvno >= 0 && dbentp->key_data[i].key_data_kvno != kvno)
|
||||
+ if (kvno >= 0 && kd->key_data_kvno < kvno)
|
||||
+ break;
|
||||
+ if (kvno >= 0 && kd->key_data_kvno != kvno)
|
||||
continue;
|
||||
|
||||
/* Filter out non-permitted enctypes. */
|
||||
- if (!krb5_is_permitted_enctype(kcontext,
|
||||
- dbentp->key_data[i].key_data_type[0])) {
|
||||
+ if (!krb5_is_permitted_enctype(context, kd->key_data_type[0])) {
|
||||
saw_non_permitted = TRUE;
|
||||
continue;
|
||||
}
|
||||
|
||||
- if (dbentp->key_data[i].key_data_kvno > maxkvno) {
|
||||
- maxkvno = dbentp->key_data[i].key_data_kvno;
|
||||
- datap = &dbentp->key_data[i];
|
||||
- idx = i;
|
||||
- }
|
||||
+ *start = i + 1;
|
||||
+ *kd_out = kd;
|
||||
+ return 0;
|
||||
}
|
||||
+
|
||||
/* If we scanned the whole set of keys and matched only non-permitted
|
||||
* enctypes, indicate that. */
|
||||
- if (maxkvno < 0 && *start == 0 && saw_non_permitted)
|
||||
- ret = KRB5_KDB_NO_PERMITTED_KEY;
|
||||
- if (maxkvno < 0)
|
||||
- return ret ? ret : KRB5_KDB_NO_MATCHING_KEY;
|
||||
- *kdatap = datap;
|
||||
- *start = idx+1;
|
||||
- return 0;
|
||||
+ return (*start == 0 && saw_non_permitted) ? KRB5_KDB_NO_PERMITTED_KEY :
|
||||
+ KRB5_KDB_NO_MATCHING_KEY;
|
||||
}
|
||||
|
||||
/*
|
||||
Some files were not shown because too many files have changed in this diff Show more
Loading…
Add table
Add a link
Reference in a new issue