Compare commits
4 commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
dd7274809c | ||
|
|
0b47ef8960 | ||
|
|
19b9dd17ff | ||
|
|
9e69bcd277 |
136 changed files with 29545 additions and 32390 deletions
|
|
@ -1 +0,0 @@
|
|||
1
|
||||
134
.gitignore
vendored
134
.gitignore
vendored
|
|
@ -1,50 +1,49 @@
|
|||
/results_krb5
|
||||
/krb5-1.3.4.tar.gz
|
||||
/krb5-1.3.5.tar.gz
|
||||
/krb5-1.3.5.tar.gz.asc
|
||||
/krb5-1.3.6.tar.gz
|
||||
/krb5-1.3.6.tar.gz.asc
|
||||
/krb5-1.4.tar.gz
|
||||
/krb5-1.4.tar.gz.asc
|
||||
/krb5-1.4.1.tar.gz
|
||||
/krb5-1.4.1.tar.gz.asc
|
||||
/krb5-1.4.2.tar.gz
|
||||
/krb5-1.4.2.tar.gz.asc
|
||||
/krb5-1.4.3.tar.gz
|
||||
/krb5-1.4.3.tar.gz.asc
|
||||
/krb5-1.5.tar.gz
|
||||
/krb5-1.5.tar.gz.asc
|
||||
/krb5-1.6.tar.gz
|
||||
/krb5-1.6.tar.gz.asc
|
||||
/krb5-1.6-pdf.tar.gz
|
||||
/krb5-1.6.1.tar.gz
|
||||
/krb5-1.6.1.tar.gz.asc
|
||||
/krb5-1.6.1-pdf.tar.gz
|
||||
/krb5-1.6.2.tar.gz
|
||||
/krb5-1.6.2.tar.gz.asc
|
||||
/krb5-1.6.2-pdf.tar.gz
|
||||
/krb5-1.6.3.tar.gz
|
||||
/krb5-1.6.3.tar.gz.asc
|
||||
/krb5-1.6.3-pdf.tar.gz
|
||||
/krb5-1.7.tar.gz
|
||||
/krb5-1.7.tar.gz.asc
|
||||
/krb5-1.7-pdf.tar.gz
|
||||
/krb5-1.7.1.tar.gz
|
||||
/krb5-1.7.1.tar.gz.asc
|
||||
/krb5-1.7.1-pdf.tar.gz
|
||||
/krb5-1.8.tar.gz
|
||||
/krb5-1.8.tar.gz.asc
|
||||
/krb5-appl-1.0.tar.gz
|
||||
/krb5-appl-1.0.tar.gz.asc
|
||||
/krb5-1.8-pdf.tar.gz
|
||||
/krb5-1.8.1.tar.gz
|
||||
/krb5-1.8.1.tar.gz.asc
|
||||
/krb5-1.8.1-pdf.tar.gz
|
||||
/krb5-1.8.2.tar.gz.asc
|
||||
/krb5-1.8.2-pdf.tar.gz
|
||||
/krb5-1.8.3.tar.gz
|
||||
/krb5-1.8.3.tar.gz.asc
|
||||
/krb5-1.8.3-pdf.tar.gz
|
||||
krb5-1.3.4.tar.gz
|
||||
krb5-1.3.5.tar.gz
|
||||
krb5-1.3.5.tar.gz.asc
|
||||
krb5-1.3.6.tar.gz
|
||||
krb5-1.3.6.tar.gz.asc
|
||||
krb5-1.4.tar.gz
|
||||
krb5-1.4.tar.gz.asc
|
||||
krb5-1.4.1.tar.gz
|
||||
krb5-1.4.1.tar.gz.asc
|
||||
krb5-1.4.2.tar.gz
|
||||
krb5-1.4.2.tar.gz.asc
|
||||
krb5-1.4.3.tar.gz
|
||||
krb5-1.4.3.tar.gz.asc
|
||||
krb5-1.5.tar.gz
|
||||
krb5-1.5.tar.gz.asc
|
||||
krb5-1.6.tar.gz
|
||||
krb5-1.6.tar.gz.asc
|
||||
krb5-1.6-pdf.tar.gz
|
||||
krb5-1.6.1.tar.gz
|
||||
krb5-1.6.1.tar.gz.asc
|
||||
krb5-1.6.1-pdf.tar.gz
|
||||
krb5-1.6.2.tar.gz
|
||||
krb5-1.6.2.tar.gz.asc
|
||||
krb5-1.6.2-pdf.tar.gz
|
||||
krb5-1.6.3.tar.gz
|
||||
krb5-1.6.3.tar.gz.asc
|
||||
krb5-1.6.3-pdf.tar.gz
|
||||
krb5-1.7.tar.gz
|
||||
krb5-1.7.tar.gz.asc
|
||||
krb5-1.7-pdf.tar.gz
|
||||
krb5-1.7.1.tar.gz
|
||||
krb5-1.7.1.tar.gz.asc
|
||||
krb5-1.7.1-pdf.tar.gz
|
||||
krb5-1.8.tar.gz
|
||||
krb5-1.8.tar.gz.asc
|
||||
krb5-appl-1.0.tar.gz
|
||||
krb5-appl-1.0.tar.gz.asc
|
||||
krb5-1.8-pdf.tar.gz
|
||||
krb5-1.8.1.tar.gz
|
||||
krb5-1.8.1.tar.gz.asc
|
||||
krb5-1.8.1-pdf.tar.gz
|
||||
krb5-1.8.2.tar.gz.asc
|
||||
krb5-1.8.2-pdf.tar.gz
|
||||
krb5-1.8.3.tar.gz
|
||||
krb5-1.8.3.tar.gz.asc
|
||||
krb5-1.8.3-pdf.tar.gz
|
||||
/krb5-1.9-beta2.tar.gz
|
||||
/krb5-1.9-beta2.tar.gz.asc
|
||||
/krb5-1.9-beta2-pdf.tar.bz2
|
||||
|
|
@ -167,44 +166,3 @@
|
|||
/krb5-1.16.1-pdfs.tar
|
||||
/krb5-1.16.1.tar.gz
|
||||
/krb5-1.16.1.tar.gz.asc
|
||||
/krb5-1.17-beta1.tar.gz
|
||||
/krb5-1.17-beta1.tar.gz.asc
|
||||
/krb5-1.17-beta1-pdfs.tar
|
||||
/krb5-1.17-beta2.tar.gz
|
||||
/krb5-1.17-beta2.tar.gz.asc
|
||||
/krb5-1.17-beta2-pdfs.tar
|
||||
/krb5-1.17-pdfs.tar
|
||||
/krb5-1.17.tar.gz
|
||||
/krb5-1.17.tar.gz.asc
|
||||
/krb5-1.17.1.tar.gz
|
||||
/krb5-1.17.1.tar.gz.asc
|
||||
/krb5-1.18-beta1.tar.gz
|
||||
/krb5-1.18-beta1.tar.gz.asc
|
||||
/krb5-1.18-beta2.tar.gz
|
||||
/krb5-1.18-beta2.tar.gz.asc
|
||||
/krb5-1.18.tar.gz
|
||||
/krb5-1.18.tar.gz.asc
|
||||
/krb5-1.18.1.tar.gz
|
||||
/krb5-1.18.1.tar.gz.asc
|
||||
/krb5-1.18.2.tar.gz
|
||||
/krb5-1.18.2.tar.gz.asc
|
||||
/krb5-1.18.3.tar.gz
|
||||
/krb5-1.18.3.tar.gz.asc
|
||||
/krb5-1.19-beta1.tar.gz
|
||||
/krb5-1.19-beta1.tar.gz.asc
|
||||
/krb5-1.19-beta2.tar.gz
|
||||
/krb5-1.19-beta2.tar.gz.asc
|
||||
/krb5-1.19.tar.gz
|
||||
/krb5-1.19.tar.gz.asc
|
||||
/krb5-1.19.1.tar.gz
|
||||
/krb5-1.19.1.tar.gz.asc
|
||||
/krb5-1.19.2.tar.gz
|
||||
/krb5-1.19.2.tar.gz.asc
|
||||
/krb5-1.20.1.tar.gz
|
||||
/krb5-1.20.1.tar.gz.asc
|
||||
/krb5-1.21.tar.gz
|
||||
/krb5-1.21.tar.gz.asc
|
||||
/krb5-1.21.2.tar.gz
|
||||
/krb5-1.21.2.tar.gz.asc
|
||||
/krb5-1.21.3.tar.gz
|
||||
/krb5-1.21.3.tar.gz.asc
|
||||
|
|
|
|||
|
|
@ -1,310 +0,0 @@
|
|||
From 6f7fd964539dfe4a885068f43a91db9738661870 Mon Sep 17 00:00:00 2001
|
||||
From: Julien Rische <jrische@redhat.com>
|
||||
Date: Tue, 9 Jul 2024 11:15:33 +0200
|
||||
Subject: [PATCH] [downstream] Revert "Don't issue session keys with
|
||||
deprecated enctypes"
|
||||
|
||||
This reverts commit 1b57a4d134bbd0e7c52d5885a92eccc815726463.
|
||||
---
|
||||
doc/admin/conf_files/krb5_conf.rst | 12 ------------
|
||||
doc/admin/enctypes.rst | 23 +++-------------------
|
||||
src/include/k5-int.h | 4 ----
|
||||
src/kdc/kdc_util.c | 10 ----------
|
||||
src/lib/krb5/krb/get_in_tkt.c | 31 +++++++++++-------------------
|
||||
src/lib/krb5/krb/init_ctx.c | 10 ----------
|
||||
src/tests/gssapi/t_enctypes.py | 3 +--
|
||||
src/tests/t_etype_info.py | 2 +-
|
||||
src/tests/t_sesskeynego.py | 28 ++-------------------------
|
||||
src/util/k5test.py | 4 ++--
|
||||
10 files changed, 20 insertions(+), 107 deletions(-)
|
||||
|
||||
diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst
|
||||
index ecdf917501..f22d5db11b 100644
|
||||
--- a/doc/admin/conf_files/krb5_conf.rst
|
||||
+++ b/doc/admin/conf_files/krb5_conf.rst
|
||||
@@ -95,18 +95,6 @@ Additionally, krb5.conf may include any of the relations described in
|
||||
|
||||
The libdefaults section may contain any of the following relations:
|
||||
|
||||
-**allow_des3**
|
||||
- Permit the KDC to issue tickets with des3-cbc-sha1 session keys.
|
||||
- In future releases, this flag will allow des3-cbc-sha1 to be used
|
||||
- at all. The default value for this tag is false. (Added in
|
||||
- release 1.21.)
|
||||
-
|
||||
-**allow_rc4**
|
||||
- Permit the KDC to issue tickets with arcfour-hmac session keys.
|
||||
- In future releases, this flag will allow arcfour-hmac to be used
|
||||
- at all. The default value for this tag is false. (Added in
|
||||
- release 1.21.)
|
||||
-
|
||||
**allow_weak_crypto**
|
||||
If this flag is set to false, then weak encryption types (as noted
|
||||
in :ref:`Encryption_types` in :ref:`kdc.conf(5)`) will be filtered
|
||||
diff --git a/doc/admin/enctypes.rst b/doc/admin/enctypes.rst
|
||||
index dce19ad43e..694922c0d9 100644
|
||||
--- a/doc/admin/enctypes.rst
|
||||
+++ b/doc/admin/enctypes.rst
|
||||
@@ -48,15 +48,12 @@ Session key selection
|
||||
The KDC chooses the session key enctype by taking the intersection of
|
||||
its **permitted_enctypes** list, the list of long-term keys for the
|
||||
most recent kvno of the service, and the client's requested list of
|
||||
-enctypes. Starting in krb5-1.21, all services are assumed to support
|
||||
-aes256-cts-hmac-sha1-96; also, des3-cbc-sha1 and arcfour-hmac session
|
||||
-keys will not be issued by default.
|
||||
+enctypes.
|
||||
|
||||
Starting in krb5-1.11, it is possible to set a string attribute on a
|
||||
service principal to control what session key enctypes the KDC may
|
||||
-issue for service tickets for that principal, overriding the service's
|
||||
-long-term keys and the assumption of aes256-cts-hmac-sha1-96 support.
|
||||
-See :ref:`set_string` in :ref:`kadmin(1)` for details.
|
||||
+issue for service tickets for that principal. See :ref:`set_string`
|
||||
+in :ref:`kadmin(1)` for details.
|
||||
|
||||
|
||||
Choosing enctypes for a service
|
||||
@@ -90,20 +87,6 @@ affect how enctypes are chosen.
|
||||
acceptable risk for your environment and the weak enctypes are
|
||||
required for backward compatibility.
|
||||
|
||||
-**allow_des3**
|
||||
- was added in release 1.21 and defaults to *false*. Unless this
|
||||
- flag is set to *true*, the KDC will not issue tickets with
|
||||
- des3-cbc-sha1 session keys. In a future release, this flag will
|
||||
- control whether des3-cbc-sha1 is permitted in similar fashion to
|
||||
- weak enctypes.
|
||||
-
|
||||
-**allow_rc4**
|
||||
- was added in release 1.21 and defaults to *false*. Unless this
|
||||
- flag is set to *true*, the KDC will not issue tickets with
|
||||
- arcfour-hmac session keys. In a future release, this flag will
|
||||
- control whether arcfour-hmac is permitted in similar fashion to
|
||||
- weak enctypes.
|
||||
-
|
||||
**permitted_enctypes**
|
||||
controls the set of enctypes that a service will permit for
|
||||
session keys and for ticket and authenticator encryption. The KDC
|
||||
diff --git a/src/include/k5-int.h b/src/include/k5-int.h
|
||||
index 2f7791b775..1d1c8293f4 100644
|
||||
--- a/src/include/k5-int.h
|
||||
+++ b/src/include/k5-int.h
|
||||
@@ -180,8 +180,6 @@ typedef unsigned char u_char;
|
||||
* matches the variable name. Keep these alphabetized. */
|
||||
#define KRB5_CONF_ACL_FILE "acl_file"
|
||||
#define KRB5_CONF_ADMIN_SERVER "admin_server"
|
||||
-#define KRB5_CONF_ALLOW_DES3 "allow_des3"
|
||||
-#define KRB5_CONF_ALLOW_RC4 "allow_rc4"
|
||||
#define KRB5_CONF_ALLOW_WEAK_CRYPTO "allow_weak_crypto"
|
||||
#define KRB5_CONF_AUTH_TO_LOCAL "auth_to_local"
|
||||
#define KRB5_CONF_AUTH_TO_LOCAL_NAMES "auth_to_local_names"
|
||||
@@ -1240,8 +1238,6 @@ struct _krb5_context {
|
||||
struct _kdb_log_context *kdblog_context;
|
||||
|
||||
krb5_boolean allow_weak_crypto;
|
||||
- krb5_boolean allow_des3;
|
||||
- krb5_boolean allow_rc4;
|
||||
krb5_boolean ignore_acceptor_hostname;
|
||||
krb5_boolean enforce_ok_as_delegate;
|
||||
enum dns_canonhost dns_canonicalize_hostname;
|
||||
diff --git a/src/kdc/kdc_util.c b/src/kdc/kdc_util.c
|
||||
index e54cc751f9..75e04b73db 100644
|
||||
--- a/src/kdc/kdc_util.c
|
||||
+++ b/src/kdc/kdc_util.c
|
||||
@@ -1088,16 +1088,6 @@ select_session_keytype(krb5_context context, krb5_db_entry *server,
|
||||
if (!krb5_is_permitted_enctype(context, ktype[i]))
|
||||
continue;
|
||||
|
||||
- /*
|
||||
- * Prevent these deprecated enctypes from being used as session keys
|
||||
- * unless they are explicitly allowed. In the future they will be more
|
||||
- * comprehensively disabled and eventually removed.
|
||||
- */
|
||||
- if (ktype[i] == ENCTYPE_DES3_CBC_SHA1 && !context->allow_des3)
|
||||
- continue;
|
||||
- if (ktype[i] == ENCTYPE_ARCFOUR_HMAC && !context->allow_rc4)
|
||||
- continue;
|
||||
-
|
||||
if (dbentry_supports_enctype(context, server, ktype[i]))
|
||||
return ktype[i];
|
||||
}
|
||||
diff --git a/src/lib/krb5/krb/get_in_tkt.c b/src/lib/krb5/krb/get_in_tkt.c
|
||||
index ea089f0fcc..1b420a3ac2 100644
|
||||
--- a/src/lib/krb5/krb/get_in_tkt.c
|
||||
+++ b/src/lib/krb5/krb/get_in_tkt.c
|
||||
@@ -1582,31 +1582,22 @@ warn_pw_expiry(krb5_context context, krb5_get_init_creds_opt *options,
|
||||
(*prompter)(context, data, 0, banner, 0, 0);
|
||||
}
|
||||
|
||||
-/* Display a warning via the prompter if a deprecated enctype was used for
|
||||
- * either the reply key or the session key. */
|
||||
+/* Display a warning via the prompter if des3-cbc-sha1 was used for either the
|
||||
+ * reply key or the session key. */
|
||||
static void
|
||||
-warn_deprecated(krb5_context context, krb5_init_creds_context ctx,
|
||||
- krb5_enctype as_key_enctype)
|
||||
+warn_des3(krb5_context context, krb5_init_creds_context ctx,
|
||||
+ krb5_enctype as_key_enctype)
|
||||
{
|
||||
- krb5_enctype etype;
|
||||
- char encbuf[128], banner[256];
|
||||
+ const char *banner;
|
||||
|
||||
- if (ctx->prompter == NULL)
|
||||
- return;
|
||||
-
|
||||
- if (krb5int_c_deprecated_enctype(as_key_enctype))
|
||||
- etype = as_key_enctype;
|
||||
- else if (krb5int_c_deprecated_enctype(ctx->cred.keyblock.enctype))
|
||||
- etype = ctx->cred.keyblock.enctype;
|
||||
- else
|
||||
+ if (as_key_enctype != ENCTYPE_DES3_CBC_SHA1 &&
|
||||
+ ctx->cred.keyblock.enctype != ENCTYPE_DES3_CBC_SHA1)
|
||||
return;
|
||||
-
|
||||
- if (krb5_enctype_to_name(etype, FALSE, encbuf, sizeof(encbuf)) != 0)
|
||||
+ if (ctx->prompter == NULL)
|
||||
return;
|
||||
- snprintf(banner, sizeof(banner),
|
||||
- _("Warning: encryption type %s used for authentication is "
|
||||
- "deprecated and will be disabled"), encbuf);
|
||||
|
||||
+ banner = _("Warning: encryption type des3-cbc-sha1 used for "
|
||||
+ "authentication is weak and will be disabled");
|
||||
/* PROMPTER_INVOCATION */
|
||||
(*ctx->prompter)(context, ctx->prompter_data, NULL, banner, 0, NULL);
|
||||
}
|
||||
@@ -1857,7 +1848,7 @@ init_creds_step_reply(krb5_context context,
|
||||
ctx->complete = TRUE;
|
||||
warn_pw_expiry(context, ctx->opt, ctx->prompter, ctx->prompter_data,
|
||||
ctx->in_tkt_service, ctx->reply);
|
||||
- warn_deprecated(context, ctx, encrypting_key.enctype);
|
||||
+ warn_des3(context, ctx, encrypting_key.enctype);
|
||||
|
||||
cleanup:
|
||||
krb5_free_pa_data(context, kdc_padata);
|
||||
diff --git a/src/lib/krb5/krb/init_ctx.c b/src/lib/krb5/krb/init_ctx.c
|
||||
index a6c2bbeb54..87b486c53f 100644
|
||||
--- a/src/lib/krb5/krb/init_ctx.c
|
||||
+++ b/src/lib/krb5/krb/init_ctx.c
|
||||
@@ -221,16 +221,6 @@ krb5_init_context_profile(profile_t profile, krb5_flags flags,
|
||||
goto cleanup;
|
||||
ctx->allow_weak_crypto = tmp;
|
||||
|
||||
- retval = get_boolean(ctx, KRB5_CONF_ALLOW_DES3, 0, &tmp);
|
||||
- if (retval)
|
||||
- goto cleanup;
|
||||
- ctx->allow_des3 = tmp;
|
||||
-
|
||||
- retval = get_boolean(ctx, KRB5_CONF_ALLOW_RC4, 0, &tmp);
|
||||
- if (retval)
|
||||
- goto cleanup;
|
||||
- ctx->allow_rc4 = tmp;
|
||||
-
|
||||
retval = get_boolean(ctx, KRB5_CONF_IGNORE_ACCEPTOR_HOSTNAME, 0, &tmp);
|
||||
if (retval)
|
||||
goto cleanup;
|
||||
diff --git a/src/tests/gssapi/t_enctypes.py b/src/tests/gssapi/t_enctypes.py
|
||||
index f5f11842e2..7494d7fcdb 100755
|
||||
--- a/src/tests/gssapi/t_enctypes.py
|
||||
+++ b/src/tests/gssapi/t_enctypes.py
|
||||
@@ -18,8 +18,7 @@ d_rc4 = 'DEPRECATED:arcfour-hmac'
|
||||
# These tests make assumptions about the default enctype lists, so set
|
||||
# them explicitly rather than relying on the library defaults.
|
||||
supp='aes256-cts:normal aes128-cts:normal des3-cbc-sha1:normal rc4-hmac:normal'
|
||||
-conf = {'libdefaults': {'permitted_enctypes': 'aes des3 rc4',
|
||||
- 'allow_des3': 'true', 'allow_rc4': 'true'},
|
||||
+conf = {'libdefaults': {'permitted_enctypes': 'aes des3 rc4'},
|
||||
'realms': {'$realm': {'supported_enctypes': supp}}}
|
||||
realm = K5Realm(krb5_conf=conf)
|
||||
shutil.copyfile(realm.ccache, os.path.join(realm.testdir, 'save'))
|
||||
diff --git a/src/tests/t_etype_info.py b/src/tests/t_etype_info.py
|
||||
index 38cf96ca8f..c982508d8b 100644
|
||||
--- a/src/tests/t_etype_info.py
|
||||
+++ b/src/tests/t_etype_info.py
|
||||
@@ -1,7 +1,7 @@
|
||||
from k5test import *
|
||||
|
||||
supported_enctypes = 'aes128-cts des3-cbc-sha1 rc4-hmac'
|
||||
-conf = {'libdefaults': {'allow_des3': 'true', 'allow_rc4': 'true'},
|
||||
+conf = {'libdefaults': {'allow_weak_crypto': 'true'},
|
||||
'realms': {'$realm': {'supported_enctypes': supported_enctypes}}}
|
||||
realm = K5Realm(create_host=False, get_creds=False, krb5_conf=conf)
|
||||
|
||||
diff --git a/src/tests/t_sesskeynego.py b/src/tests/t_sesskeynego.py
|
||||
index 5a213617b5..9024aee838 100755
|
||||
--- a/src/tests/t_sesskeynego.py
|
||||
+++ b/src/tests/t_sesskeynego.py
|
||||
@@ -25,8 +25,6 @@ conf3 = {'libdefaults': {
|
||||
'default_tkt_enctypes': 'aes128-cts',
|
||||
'default_tgs_enctypes': 'rc4-hmac,aes128-cts'}}
|
||||
conf4 = {'libdefaults': {'permitted_enctypes': 'aes256-cts'}}
|
||||
-conf5 = {'libdefaults': {'allow_rc4': 'true'}}
|
||||
-conf6 = {'libdefaults': {'allow_des3': 'true'}}
|
||||
# Test with client request and session_enctypes preferring aes128, but
|
||||
# aes256 long-term key.
|
||||
realm = K5Realm(krb5_conf=conf1, create_host=False, get_creds=False)
|
||||
@@ -56,12 +54,10 @@ realm.run([kadminl, 'setstr', 'server', 'session_enctypes',
|
||||
'aes128-cts,aes256-cts'])
|
||||
test_kvno(realm, 'aes128-cts-hmac-sha1-96', 'aes256-cts-hmac-sha1-96')
|
||||
|
||||
-# 3b: Skip RC4 (as the KDC does not allow it for session keys by
|
||||
-# default) and negotiate aes128-cts session key, with only an aes256
|
||||
-# long-term service key.
|
||||
+# 3b: Negotiate rc4-hmac session key when principal only has aes256 long-term.
|
||||
realm.run([kadminl, 'setstr', 'server', 'session_enctypes',
|
||||
'rc4-hmac,aes128-cts,aes256-cts'])
|
||||
-test_kvno(realm, 'aes128-cts-hmac-sha1-96', 'aes256-cts-hmac-sha1-96')
|
||||
+test_kvno(realm, 'DEPRECATED:arcfour-hmac', 'aes256-cts-hmac-sha1-96')
|
||||
realm.stop()
|
||||
|
||||
# 4: Check that permitted_enctypes is a default for session key enctypes.
|
||||
@@ -71,24 +67,4 @@ realm.run([kvno, 'user'],
|
||||
expected_trace=('etypes requested in TGS request: aes256-cts',))
|
||||
realm.stop()
|
||||
|
||||
-# 5: allow_rc4 permits negotiation of rc4-hmac session key.
|
||||
-realm = K5Realm(krb5_conf=conf5, create_host=False, get_creds=False)
|
||||
-realm.run([kadminl, 'addprinc', '-randkey', '-e', 'aes256-cts', 'server'])
|
||||
-realm.run([kadminl, 'setstr', 'server', 'session_enctypes', 'rc4-hmac'])
|
||||
-test_kvno(realm, 'DEPRECATED:arcfour-hmac', 'aes256-cts-hmac-sha1-96')
|
||||
-realm.stop()
|
||||
-
|
||||
-# 6: allow_des3 permits negotiation of des3-cbc-sha1 session key.
|
||||
-realm = K5Realm(krb5_conf=conf6, create_host=False, get_creds=False)
|
||||
-realm.run([kadminl, 'addprinc', '-randkey', '-e', 'aes256-cts', 'server'])
|
||||
-realm.run([kadminl, 'setstr', 'server', 'session_enctypes', 'des3-cbc-sha1'])
|
||||
-test_kvno(realm, 'DEPRECATED:des3-cbc-sha1', 'aes256-cts-hmac-sha1-96')
|
||||
-realm.stop()
|
||||
-
|
||||
-# 7: default config negotiates aes256-sha1 session key for RC4-only service.
|
||||
-realm = K5Realm(create_host=False, get_creds=False)
|
||||
-realm.run([kadminl, 'addprinc', '-randkey', '-e', 'rc4-hmac', 'server'])
|
||||
-test_kvno(realm, 'aes256-cts-hmac-sha1-96', 'DEPRECATED:arcfour-hmac')
|
||||
-realm.stop()
|
||||
-
|
||||
success('sesskeynego')
|
||||
diff --git a/src/util/k5test.py b/src/util/k5test.py
|
||||
index 8e5f5ba8e9..2a86c5cdfc 100644
|
||||
--- a/src/util/k5test.py
|
||||
+++ b/src/util/k5test.py
|
||||
@@ -1340,14 +1340,14 @@ _passes = [
|
||||
|
||||
# Exercise the DES3 enctype.
|
||||
('des3', None,
|
||||
- {'libdefaults': {'permitted_enctypes': 'des3 aes256-sha1'}},
|
||||
+ {'libdefaults': {'permitted_enctypes': 'des3'}},
|
||||
{'realms': {'$realm': {
|
||||
'supported_enctypes': 'des3-cbc-sha1:normal',
|
||||
'master_key_type': 'des3-cbc-sha1'}}}),
|
||||
|
||||
# Exercise the arcfour enctype.
|
||||
('arcfour', None,
|
||||
- {'libdefaults': {'permitted_enctypes': 'rc4 aes256-sha1'}},
|
||||
+ {'libdefaults': {'permitted_enctypes': 'rc4'}},
|
||||
{'realms': {'$realm': {
|
||||
'supported_enctypes': 'arcfour-hmac:normal',
|
||||
'master_key_type': 'arcfour-hmac'}}}),
|
||||
--
|
||||
2.45.1
|
||||
|
||||
File diff suppressed because it is too large
Load diff
|
|
@ -1,612 +0,0 @@
|
|||
From 7b6453903c248a761d3ceb538dfacebbf3d3a9ff Mon Sep 17 00:00:00 2001
|
||||
From: Robbie Harwood <rharwood@redhat.com>
|
||||
Date: Fri, 9 Nov 2018 15:12:21 -0500
|
||||
Subject: [PATCH] [downstream] FIPS with PRNG and RADIUS and MD4
|
||||
|
||||
NB: Use openssl's PRNG in FIPS mode and taint within krad.
|
||||
|
||||
A lot of the FIPS error conditions from OpenSSL are incredibly
|
||||
mysterious (at best, things return NULL unexpectedly; at worst,
|
||||
internal assertions are tripped; most of the time, you just get
|
||||
ENOMEM). In order to cope with this, we need to have some level of
|
||||
awareness of what we can and can't safely call.
|
||||
|
||||
This will slow down some calls slightly (FIPS_mode() takes multiple
|
||||
locks), but not for any ciphers we care about - which is to say that
|
||||
AES is fine. Shame about SPAKE though.
|
||||
|
||||
post6 restores MD4 (and therefore keygen-only RC4).
|
||||
|
||||
post7 restores MD5 and adds radius_md5_fips_override.
|
||||
|
||||
post8 silences a static analyzer warning.
|
||||
|
||||
Last-updated: krb5-1.20
|
||||
---
|
||||
doc/admin/conf_files/krb5_conf.rst | 6 +++
|
||||
src/lib/crypto/krb/prng.c | 15 +++++-
|
||||
.../crypto/openssl/enc_provider/camellia.c | 6 +++
|
||||
src/lib/crypto/openssl/enc_provider/rc4.c | 13 +++++-
|
||||
.../crypto/openssl/hash_provider/hash_evp.c | 12 +++++
|
||||
src/lib/crypto/openssl/hmac.c | 6 ++-
|
||||
src/lib/krad/attr.c | 46 ++++++++++++++-----
|
||||
src/lib/krad/attrset.c | 5 +-
|
||||
src/lib/krad/internal.h | 28 ++++++++++-
|
||||
src/lib/krad/packet.c | 22 +++++----
|
||||
src/lib/krad/remote.c | 10 +++-
|
||||
src/lib/krad/t_attr.c | 3 +-
|
||||
src/lib/krad/t_attrset.c | 4 +-
|
||||
src/plugins/preauth/spake/spake_client.c | 6 +++
|
||||
src/plugins/preauth/spake/spake_kdc.c | 6 +++
|
||||
15 files changed, 155 insertions(+), 33 deletions(-)
|
||||
|
||||
diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst
|
||||
index f22d5db11b..a33711d918 100644
|
||||
--- a/doc/admin/conf_files/krb5_conf.rst
|
||||
+++ b/doc/admin/conf_files/krb5_conf.rst
|
||||
@@ -330,6 +330,12 @@ The libdefaults section may contain any of the following relations:
|
||||
qualification of shortnames, set this relation to the empty string
|
||||
with ``qualify_shortname = ""``. (New in release 1.18.)
|
||||
|
||||
+**radius_md5_fips_override**
|
||||
+ Downstream-only option to enable use of MD5 in RADIUS
|
||||
+ communication (libkrad). This allows for local (or protected
|
||||
+ tunnel) communication with a RADIUS server that doesn't use krad
|
||||
+ (e.g., freeradius) while in FIPS mode.
|
||||
+
|
||||
**rdns**
|
||||
If this flag is true, reverse name lookup will be used in addition
|
||||
to forward name lookup to canonicalizing hostnames for use in
|
||||
diff --git a/src/lib/crypto/krb/prng.c b/src/lib/crypto/krb/prng.c
|
||||
index d6b79e2dea..9e80a03d21 100644
|
||||
--- a/src/lib/crypto/krb/prng.c
|
||||
+++ b/src/lib/crypto/krb/prng.c
|
||||
@@ -26,6 +26,12 @@
|
||||
|
||||
#include "crypto_int.h"
|
||||
|
||||
+#include <openssl/rand.h>
|
||||
+
|
||||
+#if OPENSSL_VERSION_NUMBER < 0x30000000L
|
||||
+#include <openssl/crypto.h>
|
||||
+#endif
|
||||
+
|
||||
krb5_error_code KRB5_CALLCONV
|
||||
krb5_c_random_seed(krb5_context context, krb5_data *data)
|
||||
{
|
||||
@@ -96,9 +102,16 @@ cleanup:
|
||||
static krb5_boolean
|
||||
get_os_entropy(unsigned char *buf, size_t len)
|
||||
{
|
||||
-#if defined(__linux__) && defined(SYS_getrandom)
|
||||
int r;
|
||||
|
||||
+ /* A wild FIPS mode appeared! */
|
||||
+ if (FIPS_mode()) {
|
||||
+ /* The return codes on this API are not good */
|
||||
+ r = RAND_bytes(buf, len);
|
||||
+ return r == 1;
|
||||
+ }
|
||||
+
|
||||
+#if defined(__linux__) && defined(SYS_getrandom)
|
||||
while (len > 0) {
|
||||
/*
|
||||
* Pull from the /dev/urandom pool, but require it to have been seeded.
|
||||
diff --git a/src/lib/crypto/openssl/enc_provider/camellia.c b/src/lib/crypto/openssl/enc_provider/camellia.c
|
||||
index 01920e6ce1..d9f327add6 100644
|
||||
--- a/src/lib/crypto/openssl/enc_provider/camellia.c
|
||||
+++ b/src/lib/crypto/openssl/enc_provider/camellia.c
|
||||
@@ -387,6 +387,9 @@ krb5int_camellia_cbc_mac(krb5_key key, const krb5_crypto_iov *data,
|
||||
unsigned char blockY[CAMELLIA_BLOCK_SIZE], blockB[CAMELLIA_BLOCK_SIZE];
|
||||
struct iov_cursor cursor;
|
||||
|
||||
+ if (FIPS_mode())
|
||||
+ return KRB5_CRYPTO_INTERNAL;
|
||||
+
|
||||
if (output->length < CAMELLIA_BLOCK_SIZE)
|
||||
return KRB5_BAD_MSIZE;
|
||||
|
||||
@@ -418,6 +421,9 @@ static krb5_error_code
|
||||
krb5int_camellia_init_state (const krb5_keyblock *key, krb5_keyusage usage,
|
||||
krb5_data *state)
|
||||
{
|
||||
+ if (FIPS_mode())
|
||||
+ return KRB5_CRYPTO_INTERNAL;
|
||||
+
|
||||
state->length = 16;
|
||||
state->data = (void *) malloc(16);
|
||||
if (state->data == NULL)
|
||||
diff --git a/src/lib/crypto/openssl/enc_provider/rc4.c b/src/lib/crypto/openssl/enc_provider/rc4.c
|
||||
index 448d563348..ce63cb5f1b 100644
|
||||
--- a/src/lib/crypto/openssl/enc_provider/rc4.c
|
||||
+++ b/src/lib/crypto/openssl/enc_provider/rc4.c
|
||||
@@ -69,6 +69,9 @@ k5_arcfour_docrypt(krb5_key key, const krb5_data *state, krb5_crypto_iov *data,
|
||||
EVP_CIPHER_CTX *ctx = NULL;
|
||||
struct arcfour_state *arcstate;
|
||||
|
||||
+ if (FIPS_mode())
|
||||
+ return KRB5_CRYPTO_INTERNAL;
|
||||
+
|
||||
arcstate = (state != NULL) ? (void *)state->data : NULL;
|
||||
if (arcstate != NULL) {
|
||||
ctx = arcstate->ctx;
|
||||
@@ -116,7 +119,12 @@ k5_arcfour_docrypt(krb5_key key, const krb5_data *state, krb5_crypto_iov *data,
|
||||
static void
|
||||
k5_arcfour_free_state(krb5_data *state)
|
||||
{
|
||||
- struct arcfour_state *arcstate = (void *)state->data;
|
||||
+ struct arcfour_state *arcstate;
|
||||
+
|
||||
+ if (FIPS_mode())
|
||||
+ return;
|
||||
+
|
||||
+ arcstate = (void *) state->data;
|
||||
|
||||
EVP_CIPHER_CTX_free(arcstate->ctx);
|
||||
free(arcstate);
|
||||
@@ -128,6 +136,9 @@ k5_arcfour_init_state(const krb5_keyblock *key,
|
||||
{
|
||||
struct arcfour_state *arcstate;
|
||||
|
||||
+ if (FIPS_mode())
|
||||
+ return KRB5_CRYPTO_INTERNAL;
|
||||
+
|
||||
/*
|
||||
* The cipher state here is a saved pointer to a struct arcfour_state
|
||||
* object, rather than a flat byte array as in most enc providers. The
|
||||
diff --git a/src/lib/crypto/openssl/hash_provider/hash_evp.c b/src/lib/crypto/openssl/hash_provider/hash_evp.c
|
||||
index f2fbffdb29..11659908bb 100644
|
||||
--- a/src/lib/crypto/openssl/hash_provider/hash_evp.c
|
||||
+++ b/src/lib/crypto/openssl/hash_provider/hash_evp.c
|
||||
@@ -60,6 +60,11 @@ hash_evp(const EVP_MD *type, const krb5_crypto_iov *data, size_t num_data,
|
||||
if (ctx == NULL)
|
||||
return ENOMEM;
|
||||
|
||||
+ if (type == EVP_md4() || type == EVP_md5()) {
|
||||
+ /* See comments below in hash_md4() and hash_md5(). */
|
||||
+ EVP_MD_CTX_set_flags(ctx, EVP_MD_CTX_FLAG_NON_FIPS_ALLOW);
|
||||
+ }
|
||||
+
|
||||
ok = EVP_DigestInit_ex(ctx, type, NULL);
|
||||
for (i = 0; i < num_data; i++) {
|
||||
if (!SIGN_IOV(&data[i]))
|
||||
@@ -78,6 +83,11 @@ hash_evp(const EVP_MD *type, const krb5_crypto_iov *data, size_t num_data,
|
||||
static krb5_error_code
|
||||
hash_md4(const krb5_crypto_iov *data, size_t num_data, krb5_data *output)
|
||||
{
|
||||
+ /*
|
||||
+ * MD4 is needed in FIPS mode to perform key generation for RC4 keys used
|
||||
+ * by IPA. These keys are only used along a (separately) secured channel
|
||||
+ * for legacy reasons when performing trusts to Active Directory.
|
||||
+ */
|
||||
return hash_evp(EVP_md4(), data, num_data, output);
|
||||
}
|
||||
|
||||
@@ -90,6 +100,8 @@ const struct krb5_hash_provider krb5int_hash_md4 = {
|
||||
static krb5_error_code
|
||||
hash_md5(const krb5_crypto_iov *data, size_t num_data, krb5_data *output)
|
||||
{
|
||||
+ /* MD5 is needed in FIPS mode for communication with RADIUS servers. This
|
||||
+ * is gated in libkrad by libdefaults->radius_md5_fips_override. */
|
||||
return hash_evp(EVP_md5(), data, num_data, output);
|
||||
}
|
||||
|
||||
diff --git a/src/lib/crypto/openssl/hmac.c b/src/lib/crypto/openssl/hmac.c
|
||||
index bf12b8d6a0..f21e268f7f 100644
|
||||
--- a/src/lib/crypto/openssl/hmac.c
|
||||
+++ b/src/lib/crypto/openssl/hmac.c
|
||||
@@ -111,7 +111,11 @@ map_digest(const struct krb5_hash_provider *hash)
|
||||
return EVP_sha256();
|
||||
else if (hash == &krb5int_hash_sha384)
|
||||
return EVP_sha384();
|
||||
- else if (hash == &krb5int_hash_md5)
|
||||
+
|
||||
+ if (FIPS_mode())
|
||||
+ return NULL;
|
||||
+
|
||||
+ if (hash == &krb5int_hash_md5)
|
||||
return EVP_md5();
|
||||
else if (hash == &krb5int_hash_md4)
|
||||
return EVP_md4();
|
||||
diff --git a/src/lib/krad/attr.c b/src/lib/krad/attr.c
|
||||
index 9c13d9d755..42d354a3b5 100644
|
||||
--- a/src/lib/krad/attr.c
|
||||
+++ b/src/lib/krad/attr.c
|
||||
@@ -38,7 +38,8 @@
|
||||
typedef krb5_error_code
|
||||
(*attribute_transform_fn)(krb5_context ctx, const char *secret,
|
||||
const unsigned char *auth, const krb5_data *in,
|
||||
- unsigned char outbuf[MAX_ATTRSIZE], size_t *outlen);
|
||||
+ unsigned char outbuf[MAX_ATTRSIZE], size_t *outlen,
|
||||
+ krb5_boolean *is_fips);
|
||||
|
||||
typedef struct {
|
||||
const char *name;
|
||||
@@ -51,12 +52,14 @@ typedef struct {
|
||||
static krb5_error_code
|
||||
user_password_encode(krb5_context ctx, const char *secret,
|
||||
const unsigned char *auth, const krb5_data *in,
|
||||
- unsigned char outbuf[MAX_ATTRSIZE], size_t *outlen);
|
||||
+ unsigned char outbuf[MAX_ATTRSIZE], size_t *outlen,
|
||||
+ krb5_boolean *is_fips);
|
||||
|
||||
static krb5_error_code
|
||||
user_password_decode(krb5_context ctx, const char *secret,
|
||||
const unsigned char *auth, const krb5_data *in,
|
||||
- unsigned char outbuf[MAX_ATTRSIZE], size_t *outlen);
|
||||
+ unsigned char outbuf[MAX_ATTRSIZE], size_t *outlen,
|
||||
+ krb5_boolean *ignored);
|
||||
|
||||
static const attribute_record attributes[UCHAR_MAX] = {
|
||||
{"User-Name", 1, MAX_ATTRSIZE, NULL, NULL},
|
||||
@@ -128,7 +131,8 @@ static const attribute_record attributes[UCHAR_MAX] = {
|
||||
static krb5_error_code
|
||||
user_password_encode(krb5_context ctx, const char *secret,
|
||||
const unsigned char *auth, const krb5_data *in,
|
||||
- unsigned char outbuf[MAX_ATTRSIZE], size_t *outlen)
|
||||
+ unsigned char outbuf[MAX_ATTRSIZE], size_t *outlen,
|
||||
+ krb5_boolean *is_fips)
|
||||
{
|
||||
const unsigned char *indx;
|
||||
krb5_error_code retval;
|
||||
@@ -154,8 +158,15 @@ user_password_encode(krb5_context ctx, const char *secret,
|
||||
for (blck = 0, indx = auth; blck * BLOCKSIZE < len; blck++) {
|
||||
memcpy(tmp.data + seclen, indx, BLOCKSIZE);
|
||||
|
||||
- retval = krb5_c_make_checksum(ctx, CKSUMTYPE_RSA_MD5, NULL, 0, &tmp,
|
||||
- &sum);
|
||||
+ if (kr_use_fips(ctx)) {
|
||||
+ /* Skip encryption here. Taint so that we won't pass it out of
|
||||
+ * the machine by accident. */
|
||||
+ *is_fips = TRUE;
|
||||
+ sum.contents = calloc(1, BLOCKSIZE);
|
||||
+ } else {
|
||||
+ retval = krb5_c_make_checksum(ctx, CKSUMTYPE_RSA_MD5, NULL, 0, &tmp,
|
||||
+ &sum);
|
||||
+ }
|
||||
if (retval != 0) {
|
||||
zap(tmp.data, tmp.length);
|
||||
zap(outbuf, len);
|
||||
@@ -180,7 +191,8 @@ user_password_encode(krb5_context ctx, const char *secret,
|
||||
static krb5_error_code
|
||||
user_password_decode(krb5_context ctx, const char *secret,
|
||||
const unsigned char *auth, const krb5_data *in,
|
||||
- unsigned char outbuf[MAX_ATTRSIZE], size_t *outlen)
|
||||
+ unsigned char outbuf[MAX_ATTRSIZE], size_t *outlen,
|
||||
+ krb5_boolean *is_fips)
|
||||
{
|
||||
const unsigned char *indx;
|
||||
krb5_error_code retval;
|
||||
@@ -204,8 +216,15 @@ user_password_decode(krb5_context ctx, const char *secret,
|
||||
for (blck = 0, indx = auth; blck * BLOCKSIZE < in->length; blck++) {
|
||||
memcpy(tmp.data + seclen, indx, BLOCKSIZE);
|
||||
|
||||
- retval = krb5_c_make_checksum(ctx, CKSUMTYPE_RSA_MD5, NULL, 0,
|
||||
- &tmp, &sum);
|
||||
+ if (kr_use_fips(ctx)) {
|
||||
+ /* Skip encryption here. Taint so that we won't pass it out of
|
||||
+ * the machine by accident. */
|
||||
+ *is_fips = TRUE;
|
||||
+ sum.contents = calloc(1, BLOCKSIZE);
|
||||
+ } else {
|
||||
+ retval = krb5_c_make_checksum(ctx, CKSUMTYPE_RSA_MD5, NULL, 0,
|
||||
+ &tmp, &sum);
|
||||
+ }
|
||||
if (retval != 0) {
|
||||
zap(tmp.data, tmp.length);
|
||||
zap(outbuf, in->length);
|
||||
@@ -248,7 +267,7 @@ krb5_error_code
|
||||
kr_attr_encode(krb5_context ctx, const char *secret,
|
||||
const unsigned char *auth, krad_attr type,
|
||||
const krb5_data *in, unsigned char outbuf[MAX_ATTRSIZE],
|
||||
- size_t *outlen)
|
||||
+ size_t *outlen, krb5_boolean *is_fips)
|
||||
{
|
||||
krb5_error_code retval;
|
||||
|
||||
@@ -265,7 +284,8 @@ kr_attr_encode(krb5_context ctx, const char *secret,
|
||||
return 0;
|
||||
}
|
||||
|
||||
- return attributes[type - 1].encode(ctx, secret, auth, in, outbuf, outlen);
|
||||
+ return attributes[type - 1].encode(ctx, secret, auth, in, outbuf, outlen,
|
||||
+ is_fips);
|
||||
}
|
||||
|
||||
krb5_error_code
|
||||
@@ -274,6 +294,7 @@ kr_attr_decode(krb5_context ctx, const char *secret, const unsigned char *auth,
|
||||
unsigned char outbuf[MAX_ATTRSIZE], size_t *outlen)
|
||||
{
|
||||
krb5_error_code retval;
|
||||
+ krb5_boolean ignored;
|
||||
|
||||
retval = kr_attr_valid(type, in);
|
||||
if (retval != 0)
|
||||
@@ -288,7 +309,8 @@ kr_attr_decode(krb5_context ctx, const char *secret, const unsigned char *auth,
|
||||
return 0;
|
||||
}
|
||||
|
||||
- return attributes[type - 1].decode(ctx, secret, auth, in, outbuf, outlen);
|
||||
+ return attributes[type - 1].decode(ctx, secret, auth, in, outbuf, outlen,
|
||||
+ &ignored);
|
||||
}
|
||||
|
||||
krad_attr
|
||||
diff --git a/src/lib/krad/attrset.c b/src/lib/krad/attrset.c
|
||||
index f309f1581c..6ec031e320 100644
|
||||
--- a/src/lib/krad/attrset.c
|
||||
+++ b/src/lib/krad/attrset.c
|
||||
@@ -167,7 +167,8 @@ krad_attrset_copy(const krad_attrset *set, krad_attrset **copy)
|
||||
krb5_error_code
|
||||
kr_attrset_encode(const krad_attrset *set, const char *secret,
|
||||
const unsigned char *auth,
|
||||
- unsigned char outbuf[MAX_ATTRSETSIZE], size_t *outlen)
|
||||
+ unsigned char outbuf[MAX_ATTRSETSIZE], size_t *outlen,
|
||||
+ krb5_boolean *is_fips)
|
||||
{
|
||||
unsigned char buffer[MAX_ATTRSIZE];
|
||||
krb5_error_code retval;
|
||||
@@ -181,7 +182,7 @@ kr_attrset_encode(const krad_attrset *set, const char *secret,
|
||||
|
||||
K5_TAILQ_FOREACH(a, &set->list, list) {
|
||||
retval = kr_attr_encode(set->ctx, secret, auth, a->type, &a->attr,
|
||||
- buffer, &attrlen);
|
||||
+ buffer, &attrlen, is_fips);
|
||||
if (retval != 0)
|
||||
return retval;
|
||||
|
||||
diff --git a/src/lib/krad/internal.h b/src/lib/krad/internal.h
|
||||
index 7619563fc5..e123763954 100644
|
||||
--- a/src/lib/krad/internal.h
|
||||
+++ b/src/lib/krad/internal.h
|
||||
@@ -39,6 +39,8 @@
|
||||
#include <sys/socket.h>
|
||||
#include <netdb.h>
|
||||
|
||||
+#include <openssl/crypto.h>
|
||||
+
|
||||
#ifndef UCHAR_MAX
|
||||
#define UCHAR_MAX 255
|
||||
#endif
|
||||
@@ -49,6 +51,13 @@
|
||||
|
||||
typedef struct krad_remote_st krad_remote;
|
||||
|
||||
+struct krad_packet_st {
|
||||
+ char buffer[KRAD_PACKET_SIZE_MAX];
|
||||
+ krad_attrset *attrset;
|
||||
+ krb5_data pkt;
|
||||
+ krb5_boolean is_fips;
|
||||
+};
|
||||
+
|
||||
/* Validate constraints of an attribute. */
|
||||
krb5_error_code
|
||||
kr_attr_valid(krad_attr type, const krb5_data *data);
|
||||
@@ -57,7 +66,8 @@ kr_attr_valid(krad_attr type, const krb5_data *data);
|
||||
krb5_error_code
|
||||
kr_attr_encode(krb5_context ctx, const char *secret, const unsigned char *auth,
|
||||
krad_attr type, const krb5_data *in,
|
||||
- unsigned char outbuf[MAX_ATTRSIZE], size_t *outlen);
|
||||
+ unsigned char outbuf[MAX_ATTRSIZE], size_t *outlen,
|
||||
+ krb5_boolean *is_fips);
|
||||
|
||||
/* Decode an attribute. */
|
||||
krb5_error_code
|
||||
@@ -69,7 +79,8 @@ kr_attr_decode(krb5_context ctx, const char *secret, const unsigned char *auth,
|
||||
krb5_error_code
|
||||
kr_attrset_encode(const krad_attrset *set, const char *secret,
|
||||
const unsigned char *auth,
|
||||
- unsigned char outbuf[MAX_ATTRSETSIZE], size_t *outlen);
|
||||
+ unsigned char outbuf[MAX_ATTRSETSIZE], size_t *outlen,
|
||||
+ krb5_boolean *is_fips);
|
||||
|
||||
/* Decode attributes from a buffer. */
|
||||
krb5_error_code
|
||||
@@ -156,4 +167,17 @@ gai_error_code(int err)
|
||||
}
|
||||
}
|
||||
|
||||
+static inline krb5_boolean
|
||||
+kr_use_fips(krb5_context ctx)
|
||||
+{
|
||||
+ int val = 0;
|
||||
+
|
||||
+ if (!FIPS_mode())
|
||||
+ return 0;
|
||||
+
|
||||
+ (void)profile_get_boolean(ctx->profile, "libdefaults",
|
||||
+ "radius_md5_fips_override", NULL, 0, &val);
|
||||
+ return !val;
|
||||
+}
|
||||
+
|
||||
#endif /* INTERNAL_H_ */
|
||||
diff --git a/src/lib/krad/packet.c b/src/lib/krad/packet.c
|
||||
index c597174b65..fc2d248001 100644
|
||||
--- a/src/lib/krad/packet.c
|
||||
+++ b/src/lib/krad/packet.c
|
||||
@@ -53,12 +53,6 @@ typedef unsigned char uchar;
|
||||
#define pkt_auth(p) ((uchar *)offset(&(p)->pkt, OFFSET_AUTH))
|
||||
#define pkt_attr(p) ((unsigned char *)offset(&(p)->pkt, OFFSET_ATTR))
|
||||
|
||||
-struct krad_packet_st {
|
||||
- char buffer[KRAD_PACKET_SIZE_MAX];
|
||||
- krad_attrset *attrset;
|
||||
- krb5_data pkt;
|
||||
-};
|
||||
-
|
||||
typedef struct {
|
||||
uchar x[(UCHAR_MAX + 1) / 8];
|
||||
} idmap;
|
||||
@@ -187,8 +181,14 @@ auth_generate_response(krb5_context ctx, const char *secret,
|
||||
memcpy(data.data + response->pkt.length, secret, strlen(secret));
|
||||
|
||||
/* Hash it. */
|
||||
- retval = krb5_c_make_checksum(ctx, CKSUMTYPE_RSA_MD5, NULL, 0, &data,
|
||||
- &hash);
|
||||
+ if (kr_use_fips(ctx)) {
|
||||
+ /* This checksum does very little security-wise anyway, so don't
|
||||
+ * taint. */
|
||||
+ hash.contents = calloc(1, AUTH_FIELD_SIZE);
|
||||
+ } else {
|
||||
+ retval = krb5_c_make_checksum(ctx, CKSUMTYPE_RSA_MD5, NULL, 0, &data,
|
||||
+ &hash);
|
||||
+ }
|
||||
free(data.data);
|
||||
if (retval != 0)
|
||||
return retval;
|
||||
@@ -276,7 +276,7 @@ krad_packet_new_request(krb5_context ctx, const char *secret, krad_code code,
|
||||
|
||||
/* Encode the attributes. */
|
||||
retval = kr_attrset_encode(set, secret, pkt_auth(pkt), pkt_attr(pkt),
|
||||
- &attrset_len);
|
||||
+ &attrset_len, &pkt->is_fips);
|
||||
if (retval != 0)
|
||||
goto error;
|
||||
|
||||
@@ -314,7 +314,7 @@ krad_packet_new_response(krb5_context ctx, const char *secret, krad_code code,
|
||||
|
||||
/* Encode the attributes. */
|
||||
retval = kr_attrset_encode(set, secret, pkt_auth(request), pkt_attr(pkt),
|
||||
- &attrset_len);
|
||||
+ &attrset_len, &pkt->is_fips);
|
||||
if (retval != 0)
|
||||
goto error;
|
||||
|
||||
@@ -451,6 +451,8 @@ krad_packet_decode_response(krb5_context ctx, const char *secret,
|
||||
const krb5_data *
|
||||
krad_packet_encode(const krad_packet *pkt)
|
||||
{
|
||||
+ if (pkt->is_fips)
|
||||
+ return NULL;
|
||||
return &pkt->pkt;
|
||||
}
|
||||
|
||||
diff --git a/src/lib/krad/remote.c b/src/lib/krad/remote.c
|
||||
index 06ae751bc8..929f1cef67 100644
|
||||
--- a/src/lib/krad/remote.c
|
||||
+++ b/src/lib/krad/remote.c
|
||||
@@ -263,7 +263,7 @@ on_io_write(krad_remote *rr)
|
||||
request *r;
|
||||
|
||||
K5_TAILQ_FOREACH(r, &rr->list, list) {
|
||||
- tmp = krad_packet_encode(r->request);
|
||||
+ tmp = &r->request->pkt;
|
||||
|
||||
/* If the packet has already been sent, do nothing. */
|
||||
if (r->sent == tmp->length)
|
||||
@@ -359,7 +359,7 @@ on_io_read(krad_remote *rr)
|
||||
if (req != NULL) {
|
||||
K5_TAILQ_FOREACH(r, &rr->list, list) {
|
||||
if (r->request == req &&
|
||||
- r->sent == krad_packet_encode(req)->length) {
|
||||
+ r->sent == req->pkt.length) {
|
||||
request_finish(r, 0, rsp);
|
||||
break;
|
||||
}
|
||||
@@ -460,6 +460,12 @@ kr_remote_send(krad_remote *rr, krad_code code, krad_attrset *attrs,
|
||||
(krad_packet_iter_cb)iterator, &r, &tmp);
|
||||
if (retval != 0)
|
||||
goto error;
|
||||
+ else if (tmp->is_fips && rr->info->ai_family != AF_LOCAL &&
|
||||
+ rr->info->ai_family != AF_UNIX) {
|
||||
+ /* This would expose cleartext passwords, so abort. */
|
||||
+ retval = ESOCKTNOSUPPORT;
|
||||
+ goto error;
|
||||
+ }
|
||||
|
||||
K5_TAILQ_FOREACH(r, &rr->list, list) {
|
||||
if (r->request == tmp) {
|
||||
diff --git a/src/lib/krad/t_attr.c b/src/lib/krad/t_attr.c
|
||||
index eb2a780c89..4d285ad9de 100644
|
||||
--- a/src/lib/krad/t_attr.c
|
||||
+++ b/src/lib/krad/t_attr.c
|
||||
@@ -50,6 +50,7 @@ main()
|
||||
const char *tmp;
|
||||
krb5_data in;
|
||||
size_t len;
|
||||
+ krb5_boolean is_fips = FALSE;
|
||||
|
||||
noerror(krb5_init_context(&ctx));
|
||||
|
||||
@@ -73,7 +74,7 @@ main()
|
||||
in = string2data((char *)decoded);
|
||||
retval = kr_attr_encode(ctx, secret, auth,
|
||||
krad_attr_name2num("User-Password"),
|
||||
- &in, outbuf, &len);
|
||||
+ &in, outbuf, &len, &is_fips);
|
||||
insist(retval == 0);
|
||||
insist(len == sizeof(encoded));
|
||||
insist(memcmp(outbuf, encoded, len) == 0);
|
||||
diff --git a/src/lib/krad/t_attrset.c b/src/lib/krad/t_attrset.c
|
||||
index 7928335ca4..0f95762534 100644
|
||||
--- a/src/lib/krad/t_attrset.c
|
||||
+++ b/src/lib/krad/t_attrset.c
|
||||
@@ -49,6 +49,7 @@ main()
|
||||
krb5_context ctx;
|
||||
size_t len = 0, encode_len;
|
||||
krb5_data tmp;
|
||||
+ krb5_boolean is_fips = FALSE;
|
||||
|
||||
noerror(krb5_init_context(&ctx));
|
||||
noerror(krad_attrset_new(ctx, &set));
|
||||
@@ -62,7 +63,8 @@ main()
|
||||
noerror(krad_attrset_add(set, krad_attr_name2num("User-Password"), &tmp));
|
||||
|
||||
/* Encode attrset. */
|
||||
- noerror(kr_attrset_encode(set, "foo", auth, buffer, &encode_len));
|
||||
+ noerror(kr_attrset_encode(set, "foo", auth, buffer, &encode_len,
|
||||
+ &is_fips));
|
||||
krad_attrset_free(set);
|
||||
|
||||
/* Manually encode User-Name. */
|
||||
diff --git a/src/plugins/preauth/spake/spake_client.c b/src/plugins/preauth/spake/spake_client.c
|
||||
index 00734a13b5..a3ce22b70f 100644
|
||||
--- a/src/plugins/preauth/spake/spake_client.c
|
||||
+++ b/src/plugins/preauth/spake/spake_client.c
|
||||
@@ -38,6 +38,8 @@
|
||||
#include "groups.h"
|
||||
#include <krb5/clpreauth_plugin.h>
|
||||
|
||||
+#include <openssl/crypto.h>
|
||||
+
|
||||
typedef struct reqstate_st {
|
||||
krb5_pa_spake *msg; /* set in prep_questions, used in process */
|
||||
krb5_keyblock *initial_key;
|
||||
@@ -375,6 +377,10 @@ clpreauth_spake_initvt(krb5_context context, int maj_ver, int min_ver,
|
||||
|
||||
if (maj_ver != 1)
|
||||
return KRB5_PLUGIN_VER_NOTSUPP;
|
||||
+
|
||||
+ if (FIPS_mode())
|
||||
+ return KRB5_CRYPTO_INTERNAL;
|
||||
+
|
||||
vt = (krb5_clpreauth_vtable)vtable;
|
||||
vt->name = "spake";
|
||||
vt->pa_type_list = pa_types;
|
||||
diff --git a/src/plugins/preauth/spake/spake_kdc.c b/src/plugins/preauth/spake/spake_kdc.c
|
||||
index 1a772d450f..232e78bc05 100644
|
||||
--- a/src/plugins/preauth/spake/spake_kdc.c
|
||||
+++ b/src/plugins/preauth/spake/spake_kdc.c
|
||||
@@ -41,6 +41,8 @@
|
||||
|
||||
#include <krb5/kdcpreauth_plugin.h>
|
||||
|
||||
+#include <openssl/crypto.h>
|
||||
+
|
||||
/*
|
||||
* The SPAKE kdcpreauth module uses a secure cookie containing the following
|
||||
* concatenated fields (all integer fields are big-endian):
|
||||
@@ -551,6 +553,10 @@ kdcpreauth_spake_initvt(krb5_context context, int maj_ver, int min_ver,
|
||||
|
||||
if (maj_ver != 1)
|
||||
return KRB5_PLUGIN_VER_NOTSUPP;
|
||||
+
|
||||
+ if (FIPS_mode())
|
||||
+ return KRB5_CRYPTO_INTERNAL;
|
||||
+
|
||||
vt = (krb5_kdcpreauth_vtable)vtable;
|
||||
vt->name = "spake";
|
||||
vt->pa_type_list = pa_types;
|
||||
--
|
||||
2.45.1
|
||||
|
||||
|
|
@ -1,82 +0,0 @@
|
|||
From 707fa7bd2be6327343dc8fc5c20dc77645524518 Mon Sep 17 00:00:00 2001
|
||||
From: Julien Rische <jrische@redhat.com>
|
||||
Date: Thu, 5 May 2022 17:15:12 +0200
|
||||
Subject: [PATCH] [downstream] Allow krad UDP/TCP localhost connection
|
||||
with FIPS
|
||||
|
||||
libkrad allows to establish connections only to UNIX socket in FIPS
|
||||
mode, because MD5 digest is not considered safe enough to be used for
|
||||
network communication. However, FreeRadius requires connection on TCP or
|
||||
UDP ports.
|
||||
|
||||
This commit allows TCP or UDP connections in FIPS mode if destination is
|
||||
localhost.
|
||||
|
||||
Resolves: rhbz#2082189
|
||||
---
|
||||
src/lib/krad/remote.c | 35 +++++++++++++++++++++++++++++++++--
|
||||
1 file changed, 33 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/src/lib/krad/remote.c b/src/lib/krad/remote.c
|
||||
index 929f1cef67..063f17a613 100644
|
||||
--- a/src/lib/krad/remote.c
|
||||
+++ b/src/lib/krad/remote.c
|
||||
@@ -33,6 +33,7 @@
|
||||
|
||||
#include <string.h>
|
||||
#include <unistd.h>
|
||||
+#include <stdbool.h>
|
||||
|
||||
#include <sys/un.h>
|
||||
|
||||
@@ -74,6 +75,35 @@ on_io(verto_ctx *ctx, verto_ev *ev);
|
||||
static void
|
||||
on_timeout(verto_ctx *ctx, verto_ev *ev);
|
||||
|
||||
+static in_addr_t get_in_addr(struct addrinfo *info)
|
||||
+{ return ((struct sockaddr_in *)(info->ai_addr))->sin_addr.s_addr; }
|
||||
+
|
||||
+static struct in6_addr *get_in6_addr(struct addrinfo *info)
|
||||
+{ return &(((struct sockaddr_in6 *)(info->ai_addr))->sin6_addr); }
|
||||
+
|
||||
+static bool is_inet_localhost(struct addrinfo *info)
|
||||
+{
|
||||
+ struct addrinfo *p;
|
||||
+
|
||||
+ for (p = info; p; p = p->ai_next) {
|
||||
+ switch (p->ai_family) {
|
||||
+ case AF_INET:
|
||||
+ if (IN_LOOPBACKNET != (get_in_addr(p) & IN_CLASSA_NET
|
||||
+ >> IN_CLASSA_NSHIFT))
|
||||
+ return false;
|
||||
+ break;
|
||||
+ case AF_INET6:
|
||||
+ if (!IN6_IS_ADDR_LOOPBACK(get_in6_addr(p)))
|
||||
+ return false;
|
||||
+ break;
|
||||
+ default:
|
||||
+ return false;
|
||||
+ }
|
||||
+ }
|
||||
+
|
||||
+ return true;
|
||||
+}
|
||||
+
|
||||
/* Iterate over the set of outstanding packets. */
|
||||
static const krad_packet *
|
||||
iterator(request **out)
|
||||
@@ -460,8 +490,9 @@ kr_remote_send(krad_remote *rr, krad_code code, krad_attrset *attrs,
|
||||
(krad_packet_iter_cb)iterator, &r, &tmp);
|
||||
if (retval != 0)
|
||||
goto error;
|
||||
- else if (tmp->is_fips && rr->info->ai_family != AF_LOCAL &&
|
||||
- rr->info->ai_family != AF_UNIX) {
|
||||
+ else if (tmp->is_fips && rr->info->ai_family != AF_LOCAL
|
||||
+ && rr->info->ai_family != AF_UNIX
|
||||
+ && !is_inet_localhost(rr->info)) {
|
||||
/* This would expose cleartext passwords, so abort. */
|
||||
retval = ESOCKTNOSUPPORT;
|
||||
goto error;
|
||||
--
|
||||
2.45.1
|
||||
|
||||
|
|
@ -1,41 +0,0 @@
|
|||
From 1da88bea558348be2974470774aa688f8be634c0 Mon Sep 17 00:00:00 2001
|
||||
From: Julien Rische <jrische@redhat.com>
|
||||
Date: Wed, 7 Dec 2022 13:22:42 +0100
|
||||
Subject: [PATCH] [downstream] Make tests compatible with
|
||||
sssd_krb5_locator_plugin.so
|
||||
|
||||
The sssd_krb5_locator_plugin.so plugin provided by sssd-client conflicts
|
||||
with the upstream test t_discover_uri.py. The test has to be modified in
|
||||
order to avoid false positive.
|
||||
---
|
||||
src/lib/krb5/os/t_discover_uri.py | 9 ++++++++-
|
||||
1 file changed, 8 insertions(+), 1 deletion(-)
|
||||
|
||||
diff --git a/src/lib/krb5/os/t_discover_uri.py b/src/lib/krb5/os/t_discover_uri.py
|
||||
index 87bac17929..26bc95a8dc 100644
|
||||
--- a/src/lib/krb5/os/t_discover_uri.py
|
||||
+++ b/src/lib/krb5/os/t_discover_uri.py
|
||||
@@ -1,3 +1,4 @@
|
||||
+from os.path import exists
|
||||
from k5test import *
|
||||
|
||||
entries = ('URI _kerberos.TEST krb5srv::kkdcp:https://kdc1 1 1\n',
|
||||
@@ -37,8 +38,14 @@ realm.env['RESOLV_WRAPPER_HOSTS'] = hosts_filename
|
||||
out = realm.run(['./t_locate_kdc', 'TEST'], env=realm.env)
|
||||
l = out.splitlines()
|
||||
|
||||
+if (exists('/usr/lib/krb5/plugins/libkrb5/sssd_krb5_locator_plugin.so')
|
||||
+ or exists('/usr/lib64/krb5/plugins/libkrb5/sssd_krb5_locator_plugin.so')):
|
||||
+ line_range = range(6, 14)
|
||||
+else:
|
||||
+ line_range = range(4, 12)
|
||||
+
|
||||
j = 0
|
||||
-for i in range(4, 12):
|
||||
+for i in line_range:
|
||||
if l[i].strip() != expected[j]:
|
||||
fail('URI answers do not match')
|
||||
j += 1
|
||||
--
|
||||
2.45.1
|
||||
|
||||
|
|
@ -1,120 +0,0 @@
|
|||
From 775ed8588cc21385fb16a4cec4a861f0d578ce04 Mon Sep 17 00:00:00 2001
|
||||
From: Julien Rische <jrische@redhat.com>
|
||||
Date: Thu, 5 Jan 2023 20:06:47 +0100
|
||||
Subject: [PATCH] [downstream] Include missing OpenSSL FIPS header
|
||||
|
||||
The inclusion of openssl/fips.h, which provides the declaration of
|
||||
FIPS_mode(), was removed from openssl/crypto.h. As a consequence, this
|
||||
header file has to be included explicitly in krb5 code.
|
||||
---
|
||||
src/lib/crypto/krb/prng.c | 4 +++-
|
||||
src/lib/crypto/openssl/enc_provider/camellia.c | 1 +
|
||||
src/lib/crypto/openssl/enc_provider/rc4.c | 4 ++++
|
||||
src/lib/crypto/openssl/hmac.c | 1 +
|
||||
src/lib/krad/internal.h | 4 ++++
|
||||
src/plugins/preauth/spake/spake_client.c | 4 ++++
|
||||
src/plugins/preauth/spake/spake_kdc.c | 4 ++++
|
||||
7 files changed, 21 insertions(+), 1 deletion(-)
|
||||
|
||||
diff --git a/src/lib/crypto/krb/prng.c b/src/lib/crypto/krb/prng.c
|
||||
index 9e80a03d21..ae37c77518 100644
|
||||
--- a/src/lib/crypto/krb/prng.c
|
||||
+++ b/src/lib/crypto/krb/prng.c
|
||||
@@ -28,7 +28,9 @@
|
||||
|
||||
#include <openssl/rand.h>
|
||||
|
||||
-#if OPENSSL_VERSION_NUMBER < 0x30000000L
|
||||
+#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||
+#include <openssl/fips.h>
|
||||
+#else
|
||||
#include <openssl/crypto.h>
|
||||
#endif
|
||||
|
||||
diff --git a/src/lib/crypto/openssl/enc_provider/camellia.c b/src/lib/crypto/openssl/enc_provider/camellia.c
|
||||
index d9f327add6..3dd3b0624f 100644
|
||||
--- a/src/lib/crypto/openssl/enc_provider/camellia.c
|
||||
+++ b/src/lib/crypto/openssl/enc_provider/camellia.c
|
||||
@@ -32,6 +32,7 @@
|
||||
#include <openssl/camellia.h>
|
||||
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||
#include <openssl/core_names.h>
|
||||
+#include <openssl/fips.h>
|
||||
#else
|
||||
#include <openssl/modes.h>
|
||||
#endif
|
||||
diff --git a/src/lib/crypto/openssl/enc_provider/rc4.c b/src/lib/crypto/openssl/enc_provider/rc4.c
|
||||
index ce63cb5f1b..6a83f10d27 100644
|
||||
--- a/src/lib/crypto/openssl/enc_provider/rc4.c
|
||||
+++ b/src/lib/crypto/openssl/enc_provider/rc4.c
|
||||
@@ -38,6 +38,10 @@
|
||||
|
||||
#include <openssl/evp.h>
|
||||
|
||||
+#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||
+#include <openssl/fips.h>
|
||||
+#endif
|
||||
+
|
||||
/*
|
||||
* The loopback field is a pointer to the structure. If the application copies
|
||||
* the state (not a valid operation, but one which happens to works with some
|
||||
diff --git a/src/lib/crypto/openssl/hmac.c b/src/lib/crypto/openssl/hmac.c
|
||||
index f21e268f7f..25a419d73a 100644
|
||||
--- a/src/lib/crypto/openssl/hmac.c
|
||||
+++ b/src/lib/crypto/openssl/hmac.c
|
||||
@@ -59,6 +59,7 @@
|
||||
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||
#include <openssl/params.h>
|
||||
#include <openssl/core_names.h>
|
||||
+#include <openssl/fips.h>
|
||||
#else
|
||||
#include <openssl/hmac.h>
|
||||
#endif
|
||||
diff --git a/src/lib/krad/internal.h b/src/lib/krad/internal.h
|
||||
index e123763954..a17b6f39b1 100644
|
||||
--- a/src/lib/krad/internal.h
|
||||
+++ b/src/lib/krad/internal.h
|
||||
@@ -41,6 +41,10 @@
|
||||
|
||||
#include <openssl/crypto.h>
|
||||
|
||||
+#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||
+#include <openssl/fips.h>
|
||||
+#endif
|
||||
+
|
||||
#ifndef UCHAR_MAX
|
||||
#define UCHAR_MAX 255
|
||||
#endif
|
||||
diff --git a/src/plugins/preauth/spake/spake_client.c b/src/plugins/preauth/spake/spake_client.c
|
||||
index a3ce22b70f..13c699071f 100644
|
||||
--- a/src/plugins/preauth/spake/spake_client.c
|
||||
+++ b/src/plugins/preauth/spake/spake_client.c
|
||||
@@ -40,6 +40,10 @@
|
||||
|
||||
#include <openssl/crypto.h>
|
||||
|
||||
+#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||
+#include <openssl/fips.h>
|
||||
+#endif
|
||||
+
|
||||
typedef struct reqstate_st {
|
||||
krb5_pa_spake *msg; /* set in prep_questions, used in process */
|
||||
krb5_keyblock *initial_key;
|
||||
diff --git a/src/plugins/preauth/spake/spake_kdc.c b/src/plugins/preauth/spake/spake_kdc.c
|
||||
index 232e78bc05..3394f8a58e 100644
|
||||
--- a/src/plugins/preauth/spake/spake_kdc.c
|
||||
+++ b/src/plugins/preauth/spake/spake_kdc.c
|
||||
@@ -43,6 +43,10 @@
|
||||
|
||||
#include <openssl/crypto.h>
|
||||
|
||||
+#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||
+#include <openssl/fips.h>
|
||||
+#endif
|
||||
+
|
||||
/*
|
||||
* The SPAKE kdcpreauth module uses a secure cookie containing the following
|
||||
* concatenated fields (all integer fields are big-endian):
|
||||
--
|
||||
2.45.1
|
||||
|
||||
|
|
@ -1,31 +0,0 @@
|
|||
From 4fd20741afcf76085ea62eb015cd589bb9392a7b Mon Sep 17 00:00:00 2001
|
||||
From: Julien Rische <jrische@redhat.com>
|
||||
Date: Mon, 9 Jan 2023 22:39:52 +0100
|
||||
Subject: [PATCH] [downstream] Do not set root as ksu file owner
|
||||
|
||||
Upstream Makefile uses the install command to set root as owner of the
|
||||
ksu executable file. However, this is no longer supported on latest
|
||||
versions of the Mock build environment.
|
||||
|
||||
In case of ksu, the owner, group, and mode are already set using %attr()
|
||||
in the specfile.
|
||||
---
|
||||
src/config/pre.in | 2 +-
|
||||
1 file changed, 1 insertion(+), 1 deletion(-)
|
||||
|
||||
diff --git a/src/config/pre.in b/src/config/pre.in
|
||||
index 7eaa2f351c..e9ae71471e 100644
|
||||
--- a/src/config/pre.in
|
||||
+++ b/src/config/pre.in
|
||||
@@ -185,7 +185,7 @@ INSTALL_PROGRAM=@INSTALL_PROGRAM@ $(INSTALL_STRIP)
|
||||
INSTALL_SCRIPT=@INSTALL_PROGRAM@
|
||||
INSTALL_DATA=@INSTALL_DATA@
|
||||
INSTALL_SHLIB=@INSTALL_SHLIB@
|
||||
-INSTALL_SETUID=$(INSTALL) $(INSTALL_STRIP) -m 4755 -o root
|
||||
+INSTALL_SETUID=$(INSTALL)
|
||||
## This is needed because autoconf will sometimes define @exec_prefix@ to be
|
||||
## ${prefix}.
|
||||
prefix=@prefix@
|
||||
--
|
||||
2.45.1
|
||||
|
||||
|
|
@ -1,165 +0,0 @@
|
|||
From 16f90c007036789d8d9343e8a0cbabfd21853b5a Mon Sep 17 00:00:00 2001
|
||||
From: Julien Rische <jrische@redhat.com>
|
||||
Date: Thu, 19 Jan 2023 19:22:27 +0100
|
||||
Subject: [PATCH] [downstream] Allow KRB5KDF, MD5, and MD4 in FIPS mode
|
||||
|
||||
OpenSSL's restrictions to use KRB5KDF, MD5, and MD4 in FIPS mode are
|
||||
bypassed in case AES SHA-1 HMAC or RC4 encryption types are allowed by
|
||||
the crypto policy.
|
||||
---
|
||||
.../crypto/openssl/hash_provider/hash_evp.c | 97 +++++++++++++++++--
|
||||
src/lib/crypto/openssl/kdf.c | 2 +-
|
||||
2 files changed, 89 insertions(+), 10 deletions(-)
|
||||
|
||||
diff --git a/src/lib/crypto/openssl/hash_provider/hash_evp.c b/src/lib/crypto/openssl/hash_provider/hash_evp.c
|
||||
index 11659908bb..eb2e693e9f 100644
|
||||
--- a/src/lib/crypto/openssl/hash_provider/hash_evp.c
|
||||
+++ b/src/lib/crypto/openssl/hash_provider/hash_evp.c
|
||||
@@ -44,6 +44,49 @@
|
||||
#define EVP_MD_CTX_free EVP_MD_CTX_destroy
|
||||
#endif
|
||||
|
||||
+#include <openssl/provider.h>
|
||||
+#include <openssl/fips.h>
|
||||
+#include <threads.h>
|
||||
+
|
||||
+typedef struct ossl_lib_md_context {
|
||||
+ OSSL_LIB_CTX *libctx;
|
||||
+ OSSL_PROVIDER *default_provider;
|
||||
+ OSSL_PROVIDER *legacy_provider;
|
||||
+} ossl_md_context_t;
|
||||
+
|
||||
+static thread_local ossl_md_context_t *ossl_md_ctx = NULL;
|
||||
+
|
||||
+static krb5_error_code
|
||||
+init_ossl_md_ctx(ossl_md_context_t *ctx, const char *algo)
|
||||
+{
|
||||
+ ctx->libctx = OSSL_LIB_CTX_new();
|
||||
+ if (!ctx->libctx)
|
||||
+ return KRB5_CRYPTO_INTERNAL;
|
||||
+
|
||||
+ /* Load both legacy and default provider as both may be needed. */
|
||||
+ ctx->default_provider = OSSL_PROVIDER_load(ctx->libctx, "default");
|
||||
+ ctx->legacy_provider = OSSL_PROVIDER_load(ctx->libctx, "legacy");
|
||||
+
|
||||
+ if (!(ctx->default_provider && ctx->legacy_provider))
|
||||
+ return KRB5_CRYPTO_INTERNAL;
|
||||
+
|
||||
+ return 0;
|
||||
+}
|
||||
+
|
||||
+static void
|
||||
+deinit_ossl_ctx(ossl_md_context_t *ctx)
|
||||
+{
|
||||
+ if (ctx->legacy_provider)
|
||||
+ OSSL_PROVIDER_unload(ctx->legacy_provider);
|
||||
+
|
||||
+ if (ctx->default_provider)
|
||||
+ OSSL_PROVIDER_unload(ctx->default_provider);
|
||||
+
|
||||
+ if (ctx->libctx)
|
||||
+ OSSL_LIB_CTX_free(ctx->libctx);
|
||||
+}
|
||||
+
|
||||
+
|
||||
static krb5_error_code
|
||||
hash_evp(const EVP_MD *type, const krb5_crypto_iov *data, size_t num_data,
|
||||
krb5_data *output)
|
||||
@@ -60,11 +103,6 @@ hash_evp(const EVP_MD *type, const krb5_crypto_iov *data, size_t num_data,
|
||||
if (ctx == NULL)
|
||||
return ENOMEM;
|
||||
|
||||
- if (type == EVP_md4() || type == EVP_md5()) {
|
||||
- /* See comments below in hash_md4() and hash_md5(). */
|
||||
- EVP_MD_CTX_set_flags(ctx, EVP_MD_CTX_FLAG_NON_FIPS_ALLOW);
|
||||
- }
|
||||
-
|
||||
ok = EVP_DigestInit_ex(ctx, type, NULL);
|
||||
for (i = 0; i < num_data; i++) {
|
||||
if (!SIGN_IOV(&data[i]))
|
||||
@@ -77,6 +115,43 @@ hash_evp(const EVP_MD *type, const krb5_crypto_iov *data, size_t num_data,
|
||||
return ok ? 0 : KRB5_CRYPTO_INTERNAL;
|
||||
}
|
||||
|
||||
+static krb5_error_code
|
||||
+hash_legacy_evp(const char *algo, const krb5_crypto_iov *data, size_t num_data,
|
||||
+ krb5_data *output)
|
||||
+{
|
||||
+ krb5_error_code err;
|
||||
+ EVP_MD *md = NULL;
|
||||
+
|
||||
+ if (!ossl_md_ctx) {
|
||||
+ ossl_md_ctx = malloc(sizeof(ossl_md_context_t));
|
||||
+ if (!ossl_md_ctx) {
|
||||
+ err = ENOMEM;
|
||||
+ goto end;
|
||||
+ }
|
||||
+
|
||||
+ err = init_ossl_md_ctx(ossl_md_ctx, algo);
|
||||
+ if (err) {
|
||||
+ deinit_ossl_ctx(ossl_md_ctx);
|
||||
+ free(ossl_md_ctx);
|
||||
+ ossl_md_ctx = NULL;
|
||||
+ goto end;
|
||||
+ }
|
||||
+ }
|
||||
+
|
||||
+ md = EVP_MD_fetch(ossl_md_ctx->libctx, algo, NULL);
|
||||
+ if (!md) {
|
||||
+ err = KRB5_CRYPTO_INTERNAL;
|
||||
+ goto end;
|
||||
+ }
|
||||
+
|
||||
+ err = hash_evp(md, data, num_data, output);
|
||||
+
|
||||
+end:
|
||||
+ if (md)
|
||||
+ EVP_MD_free(md);
|
||||
+
|
||||
+ return err;
|
||||
+}
|
||||
#endif
|
||||
|
||||
#ifdef K5_OPENSSL_MD4
|
||||
@@ -88,7 +163,8 @@ hash_md4(const krb5_crypto_iov *data, size_t num_data, krb5_data *output)
|
||||
* by IPA. These keys are only used along a (separately) secured channel
|
||||
* for legacy reasons when performing trusts to Active Directory.
|
||||
*/
|
||||
- return hash_evp(EVP_md4(), data, num_data, output);
|
||||
+ return FIPS_mode() ? hash_legacy_evp("MD4", data, num_data, output)
|
||||
+ : hash_evp(EVP_md4(), data, num_data, output);
|
||||
}
|
||||
|
||||
const struct krb5_hash_provider krb5int_hash_md4 = {
|
||||
@@ -100,9 +176,12 @@ const struct krb5_hash_provider krb5int_hash_md4 = {
|
||||
static krb5_error_code
|
||||
hash_md5(const krb5_crypto_iov *data, size_t num_data, krb5_data *output)
|
||||
{
|
||||
- /* MD5 is needed in FIPS mode for communication with RADIUS servers. This
|
||||
- * is gated in libkrad by libdefaults->radius_md5_fips_override. */
|
||||
- return hash_evp(EVP_md5(), data, num_data, output);
|
||||
+ /*
|
||||
+ * MD5 is needed in FIPS mode for communication with RADIUS servers. This
|
||||
+ * is gated in libkrad by libdefaults->radius_md5_fips_override.
|
||||
+ */
|
||||
+ return FIPS_mode() ? hash_legacy_evp("MD5", data, num_data, output)
|
||||
+ : hash_evp(EVP_md5(), data, num_data, output);
|
||||
}
|
||||
|
||||
const struct krb5_hash_provider krb5int_hash_md5 = {
|
||||
diff --git a/src/lib/crypto/openssl/kdf.c b/src/lib/crypto/openssl/kdf.c
|
||||
index 5a43c3d9eb..8528ddc4a9 100644
|
||||
--- a/src/lib/crypto/openssl/kdf.c
|
||||
+++ b/src/lib/crypto/openssl/kdf.c
|
||||
@@ -198,7 +198,7 @@ k5_derive_random_rfc3961(const struct krb5_enc_provider *enc, krb5_key key,
|
||||
goto done;
|
||||
}
|
||||
|
||||
- kdf = EVP_KDF_fetch(NULL, "KRB5KDF", NULL);
|
||||
+ kdf = EVP_KDF_fetch(NULL, "KRB5KDF", "-fips");
|
||||
if (kdf == NULL) {
|
||||
ret = KRB5_CRYPTO_INTERNAL;
|
||||
goto done;
|
||||
--
|
||||
2.45.1
|
||||
|
||||
|
|
@ -1,280 +0,0 @@
|
|||
From 23b58199db429603802e338db530677b61561335 Mon Sep 17 00:00:00 2001
|
||||
From: Julien Rische <jrische@redhat.com>
|
||||
Date: Wed, 15 Mar 2023 15:56:34 +0100
|
||||
Subject: [PATCH] [downstream] Allow to set PAC ticket signature as
|
||||
optional
|
||||
|
||||
MS-PAC states that "The ticket signature SHOULD be included in tickets
|
||||
that are not encrypted to the krbtgt account". However, the
|
||||
implementation of krb5_kdc_verify_ticket() will require the ticket
|
||||
signature to be present in case the target of the request is a service
|
||||
principal.
|
||||
|
||||
In gradual upgrade environments, it results in S4U2Proxy requests
|
||||
against a 1.20 KDC using a service ticket generated by an older version
|
||||
KDC to fail.
|
||||
|
||||
This commit adds a krb5_kdc_verify_ticket_ext() function with an extra
|
||||
switch parameter to tolerate the absence of ticket signature in this
|
||||
scenario. If the ticket signature is present, it has to be valid,
|
||||
regardless of this parameter.
|
||||
|
||||
This parameter is set based on the "optional_pac_tkt_chksum" string
|
||||
attribute of the TGT KDB entry.
|
||||
---
|
||||
doc/admin/admin_commands/kadmin_local.rst | 6 ++++
|
||||
doc/appdev/refs/api/index.rst | 1 +
|
||||
src/include/kdb.h | 1 +
|
||||
src/include/krb5/krb5.hin | 40 +++++++++++++++++++++++
|
||||
src/kdc/kdc_util.c | 32 ++++++++++++++----
|
||||
src/lib/krb5/krb/pac.c | 31 +++++++++++++++---
|
||||
src/lib/krb5/libkrb5.exports | 1 +
|
||||
src/man/kadmin.man | 6 ++++
|
||||
8 files changed, 108 insertions(+), 10 deletions(-)
|
||||
|
||||
diff --git a/doc/admin/admin_commands/kadmin_local.rst b/doc/admin/admin_commands/kadmin_local.rst
|
||||
index 2435b3c361..58ac79549f 100644
|
||||
--- a/doc/admin/admin_commands/kadmin_local.rst
|
||||
+++ b/doc/admin/admin_commands/kadmin_local.rst
|
||||
@@ -658,6 +658,12 @@ KDC:
|
||||
Directory realm when using aes-sha2 keys on the local krbtgt
|
||||
entry.
|
||||
|
||||
+**optional_pac_tkt_chksum**
|
||||
+ Boolean value defining the behavior of the KDC in case an expected
|
||||
+ ticket checksum signed with one of this principal keys is not
|
||||
+ present in the PAC. This is typically the case for TGS or
|
||||
+ cross-realm TGS principals when processing S4U2Proxy requests.
|
||||
+
|
||||
This command requires the **modify** privilege.
|
||||
|
||||
Alias: **setstr**
|
||||
diff --git a/doc/appdev/refs/api/index.rst b/doc/appdev/refs/api/index.rst
|
||||
index d12be47c3c..9b95ebd0f9 100644
|
||||
--- a/doc/appdev/refs/api/index.rst
|
||||
+++ b/doc/appdev/refs/api/index.rst
|
||||
@@ -225,6 +225,7 @@ Rarely used public interfaces
|
||||
krb5_is_referral_realm.rst
|
||||
krb5_kdc_sign_ticket.rst
|
||||
krb5_kdc_verify_ticket.rst
|
||||
+ krb5_kdc_verify_ticket_ext.rst
|
||||
krb5_kt_add_entry.rst
|
||||
krb5_kt_end_seq_get.rst
|
||||
krb5_kt_get_entry.rst
|
||||
diff --git a/src/include/kdb.h b/src/include/kdb.h
|
||||
index 745b24f351..6075349e5e 100644
|
||||
--- a/src/include/kdb.h
|
||||
+++ b/src/include/kdb.h
|
||||
@@ -136,6 +136,7 @@
|
||||
#define KRB5_KDB_SK_PAC_PRIVSVR_ENCTYPE "pac_privsvr_enctype"
|
||||
#define KRB5_KDB_SK_SESSION_ENCTYPES "session_enctypes"
|
||||
#define KRB5_KDB_SK_REQUIRE_AUTH "require_auth"
|
||||
+#define KRB5_KDB_SK_OPTIONAL_PAC_TKT_CHKSUM "optional_pac_tkt_chksum"
|
||||
|
||||
#if !defined(_WIN32)
|
||||
|
||||
diff --git a/src/include/krb5/krb5.hin b/src/include/krb5/krb5.hin
|
||||
index c5a625db8f..2d9b64dc85 100644
|
||||
--- a/src/include/krb5/krb5.hin
|
||||
+++ b/src/include/krb5/krb5.hin
|
||||
@@ -8329,6 +8329,46 @@ krb5_kdc_verify_ticket(krb5_context context, const krb5_enc_tkt_part *enc_tkt,
|
||||
const krb5_keyblock *server,
|
||||
const krb5_keyblock *privsvr, krb5_pac *pac_out);
|
||||
|
||||
+/**
|
||||
+ * Verify a PAC, possibly including ticket signature
|
||||
+ *
|
||||
+ * @param [in] context Library context
|
||||
+ * @param [in] enc_tkt Ticket enc-part, possibly containing a PAC
|
||||
+ * @param [in] server_princ Canonicalized name of ticket server
|
||||
+ * @param [in] server Key to validate server checksum (or NULL)
|
||||
+ * @param [in] privsvr Key to validate KDC checksum (or NULL)
|
||||
+ * @paran [in] optional_tkt_chksum Whether to require a ticket checksum
|
||||
+ * @param [out] pac_out Verified PAC (NULL if no PAC included)
|
||||
+ *
|
||||
+ * This function is an extension of krb5_kdc_verify_ticket(), adding the @a
|
||||
+ * optional_tkt_chksum parameter allowing to tolerate the absence of the PAC
|
||||
+ * ticket signature.
|
||||
+ *
|
||||
+ * If a PAC is present in @a enc_tkt, verify its signatures. If @a privsvr is
|
||||
+ * not NULL and @a server_princ is not a krbtgt or kadmin/changepw service and
|
||||
+ * @a optional_tkt_chksum is FALSE, require a ticket signature over @a enc_tkt
|
||||
+ * in addition to the KDC signature. Place the verified PAC in @a pac_out. If
|
||||
+ * an invalid PAC signature is found, return an error matching the Windows KDC
|
||||
+ * protocol code for that condition as closely as possible.
|
||||
+ *
|
||||
+ * If no PAC is present in @a enc_tkt, set @a pac_out to NULL and return
|
||||
+ * successfully.
|
||||
+ *
|
||||
+ * @note This function does not validate the PAC_CLIENT_INFO buffer. If a
|
||||
+ * specific value is expected, the caller can make a separate call to
|
||||
+ * krb5_pac_verify_ext() with a principal but no keys.
|
||||
+ *
|
||||
+ * @retval 0 Success; otherwise - Kerberos error codes
|
||||
+ */
|
||||
+krb5_error_code KRB5_CALLCONV
|
||||
+krb5_kdc_verify_ticket_ext(krb5_context context,
|
||||
+ const krb5_enc_tkt_part *enc_tkt,
|
||||
+ krb5_const_principal server_princ,
|
||||
+ const krb5_keyblock *server,
|
||||
+ const krb5_keyblock *privsvr,
|
||||
+ krb5_boolean optional_tkt_chksum,
|
||||
+ krb5_pac *pac_out);
|
||||
+
|
||||
/** @deprecated Use krb5_kdc_sign_ticket() instead. */
|
||||
krb5_error_code KRB5_CALLCONV
|
||||
krb5_pac_sign(krb5_context context, krb5_pac pac, krb5_timestamp authtime,
|
||||
diff --git a/src/kdc/kdc_util.c b/src/kdc/kdc_util.c
|
||||
index fe4e48209a..93415ba862 100644
|
||||
--- a/src/kdc/kdc_util.c
|
||||
+++ b/src/kdc/kdc_util.c
|
||||
@@ -560,16 +560,36 @@ cleanup:
|
||||
static krb5_error_code
|
||||
try_verify_pac(krb5_context context, const krb5_enc_tkt_part *enc_tkt,
|
||||
krb5_db_entry *server, krb5_keyblock *server_key,
|
||||
- const krb5_keyblock *tgt_key, krb5_pac *pac_out)
|
||||
+ krb5_db_entry *tgt, const krb5_keyblock *tgt_key,
|
||||
+ krb5_pac *pac_out)
|
||||
{
|
||||
krb5_error_code ret;
|
||||
+ krb5_boolean optional_tkt_chksum;
|
||||
+ char *str = NULL;
|
||||
krb5_keyblock *privsvr_key;
|
||||
|
||||
ret = pac_privsvr_key(context, server, tgt_key, &privsvr_key);
|
||||
if (ret)
|
||||
return ret;
|
||||
- ret = krb5_kdc_verify_ticket(context, enc_tkt, server->princ, server_key,
|
||||
- privsvr_key, pac_out);
|
||||
+
|
||||
+ /* Check if the absence of ticket signature is tolerated for this realm */
|
||||
+ ret = krb5_dbe_get_string(context, tgt,
|
||||
+ KRB5_KDB_SK_OPTIONAL_PAC_TKT_CHKSUM, &str);
|
||||
+ /* TODO: should be using _krb5_conf_boolean(), but os-proto.h is not
|
||||
+ * available here.
|
||||
+ */
|
||||
+ optional_tkt_chksum = !ret && str && (strncasecmp(str, "true", 4) == 0
|
||||
+ || strncasecmp(str, "t", 1) == 0
|
||||
+ || strncasecmp(str, "yes", 3) == 0
|
||||
+ || strncasecmp(str, "y", 1) == 0
|
||||
+ || strncasecmp(str, "1", 1) == 0
|
||||
+ || strncasecmp(str, "on", 2) == 0);
|
||||
+
|
||||
+ krb5_dbe_free_string(context, str);
|
||||
+
|
||||
+ ret = krb5_kdc_verify_ticket_ext(context, enc_tkt, server->princ,
|
||||
+ server_key, privsvr_key,
|
||||
+ optional_tkt_chksum, pac_out);
|
||||
krb5_free_keyblock(context, privsvr_key);
|
||||
return ret;
|
||||
}
|
||||
@@ -599,7 +619,7 @@ get_verified_pac(krb5_context context, const krb5_enc_tkt_part *enc_tkt,
|
||||
server_key, NULL, pac_out);
|
||||
}
|
||||
|
||||
- ret = try_verify_pac(context, enc_tkt, server, server_key, tgt_key,
|
||||
+ ret = try_verify_pac(context, enc_tkt, server, server_key, tgt, tgt_key,
|
||||
pac_out);
|
||||
if (ret != KRB5KRB_AP_ERR_MODIFIED && ret != KRB5_BAD_ENCTYPE)
|
||||
return ret;
|
||||
@@ -613,8 +633,8 @@ get_verified_pac(krb5_context context, const krb5_enc_tkt_part *enc_tkt,
|
||||
ret = krb5_dbe_decrypt_key_data(context, NULL, kd, &old_key, NULL);
|
||||
if (ret)
|
||||
return ret;
|
||||
- ret = try_verify_pac(context, enc_tkt, server, server_key, &old_key,
|
||||
- pac_out);
|
||||
+ ret = try_verify_pac(context, enc_tkt, server, server_key, tgt,
|
||||
+ &old_key, pac_out);
|
||||
krb5_free_keyblock_contents(context, &old_key);
|
||||
if (!ret)
|
||||
return 0;
|
||||
diff --git a/src/lib/krb5/krb/pac.c b/src/lib/krb5/krb/pac.c
|
||||
index 5d1fdf1ba0..0c0e2ada68 100644
|
||||
--- a/src/lib/krb5/krb/pac.c
|
||||
+++ b/src/lib/krb5/krb/pac.c
|
||||
@@ -594,6 +594,19 @@ krb5_kdc_verify_ticket(krb5_context context, const krb5_enc_tkt_part *enc_tkt,
|
||||
krb5_const_principal server_princ,
|
||||
const krb5_keyblock *server,
|
||||
const krb5_keyblock *privsvr, krb5_pac *pac_out)
|
||||
+{
|
||||
+ return krb5_kdc_verify_ticket_ext(context, enc_tkt, server_princ, server,
|
||||
+ privsvr, FALSE, pac_out);
|
||||
+}
|
||||
+
|
||||
+krb5_error_code KRB5_CALLCONV
|
||||
+krb5_kdc_verify_ticket_ext(krb5_context context,
|
||||
+ const krb5_enc_tkt_part *enc_tkt,
|
||||
+ krb5_const_principal server_princ,
|
||||
+ const krb5_keyblock *server,
|
||||
+ const krb5_keyblock *privsvr,
|
||||
+ krb5_boolean optional_tkt_chksum,
|
||||
+ krb5_pac *pac_out)
|
||||
{
|
||||
krb5_error_code ret;
|
||||
krb5_pac pac = NULL;
|
||||
@@ -602,7 +615,7 @@ krb5_kdc_verify_ticket(krb5_context context, const krb5_enc_tkt_part *enc_tkt,
|
||||
krb5_authdata *orig, **ifrel = NULL, **recoded_ifrel = NULL;
|
||||
uint8_t z = 0;
|
||||
krb5_authdata zpac = { KV5M_AUTHDATA, KRB5_AUTHDATA_WIN2K_PAC, 1, &z };
|
||||
- krb5_boolean is_service_tkt;
|
||||
+ krb5_boolean is_service_tkt, has_tkt_chksum = FALSE;
|
||||
size_t i, j;
|
||||
|
||||
*pac_out = NULL;
|
||||
@@ -667,11 +680,21 @@ krb5_kdc_verify_ticket(krb5_context context, const krb5_enc_tkt_part *enc_tkt,
|
||||
|
||||
ret = verify_checksum(context, pac, KRB5_PAC_TICKET_CHECKSUM, privsvr,
|
||||
KRB5_KEYUSAGE_APP_DATA_CKSUM, recoded_tkt);
|
||||
- if (ret)
|
||||
- goto cleanup;
|
||||
+ if (ret) {
|
||||
+ if (!optional_tkt_chksum)
|
||||
+ goto cleanup;
|
||||
+ else if (ret != ENOENT)
|
||||
+ goto cleanup;
|
||||
+ /* Otherwise ticket signature is absent but optional. Proceed... */
|
||||
+ } else {
|
||||
+ has_tkt_chksum = TRUE;
|
||||
+ }
|
||||
}
|
||||
+ /* Else, we make the assumption the ticket signature is absent in case this
|
||||
+ * is not a service ticket.
|
||||
+ */
|
||||
|
||||
- ret = verify_pac_checksums(context, pac, is_service_tkt, server, privsvr);
|
||||
+ ret = verify_pac_checksums(context, pac, has_tkt_chksum, server, privsvr);
|
||||
if (ret)
|
||||
goto cleanup;
|
||||
|
||||
diff --git a/src/lib/krb5/libkrb5.exports b/src/lib/krb5/libkrb5.exports
|
||||
index 4c50e935a2..d4b0455c8c 100644
|
||||
--- a/src/lib/krb5/libkrb5.exports
|
||||
+++ b/src/lib/krb5/libkrb5.exports
|
||||
@@ -463,6 +463,7 @@ krb5_is_thread_safe
|
||||
krb5_kdc_rep_decrypt_proc
|
||||
krb5_kdc_sign_ticket
|
||||
krb5_kdc_verify_ticket
|
||||
+krb5_kdc_verify_ticket_ext
|
||||
krb5_kt_add_entry
|
||||
krb5_kt_client_default
|
||||
krb5_kt_close
|
||||
diff --git a/src/man/kadmin.man b/src/man/kadmin.man
|
||||
index 8413e70ccd..f68eb0569d 100644
|
||||
--- a/src/man/kadmin.man
|
||||
+++ b/src/man/kadmin.man
|
||||
@@ -724,6 +724,12 @@ encryption type. It may be necessary to set this value to
|
||||
"aes256\-sha1" on the cross\-realm krbtgt entry for an Active
|
||||
Directory realm when using aes\-sha2 keys on the local krbtgt
|
||||
entry.
|
||||
+.TP
|
||||
+\fBoptional_pac_tkt_chksum\fP
|
||||
+Boolean value defining the behavior of the KDC in case an expected ticket
|
||||
+checksum signed with one of this principal keys is not present in the PAC. This
|
||||
+is typically the case for TGS or cross-realm TGS principals when processing
|
||||
+S4U2Proxy requests.
|
||||
.UNINDENT
|
||||
.sp
|
||||
This command requires the \fBmodify\fP privilege.
|
||||
--
|
||||
2.45.1
|
||||
|
||||
|
|
@ -1,47 +0,0 @@
|
|||
From 31b9debcf2cbd558f8f315fefb69fc8206b115b4 Mon Sep 17 00:00:00 2001
|
||||
From: Julien Rische <jrische@redhat.com>
|
||||
Date: Tue, 23 May 2023 12:19:54 +0200
|
||||
Subject: [PATCH] [downstream] Make PKINIT CMS SHA-1 signature
|
||||
verification available in FIPS mode
|
||||
|
||||
We recommend using the SHA1 crypto-module in order to allow the
|
||||
verification of SHA-1 signature for CMS messages. However, this module
|
||||
does not work in FIPS mode, because the SHA-1 algorithm is absent from
|
||||
the OpenSSL FIPS provider.
|
||||
|
||||
This commit enables the signature verification process to fetch the
|
||||
algorithm from a non-FIPS OpenSSL provider.
|
||||
|
||||
Support for SHA-1 CMS signature is still required, especially in order
|
||||
to interoperate with Active Directory. At least it is until elliptic
|
||||
curve cryptography is implemented for PKINIT in MIT krb5.
|
||||
---
|
||||
src/plugins/preauth/pkinit/pkinit_crypto_openssl.c | 11 ++++++++++-
|
||||
1 file changed, 10 insertions(+), 1 deletion(-)
|
||||
|
||||
diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c
|
||||
index cb9c79626c..17dd18e37d 100644
|
||||
--- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c
|
||||
+++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c
|
||||
@@ -1844,8 +1844,17 @@ cms_signeddata_verify(krb5_context context,
|
||||
if (oid == NULL)
|
||||
goto cleanup;
|
||||
|
||||
+#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||
+ /* Do not use FIPS provider (even in FIPS mode) because it keeps from
|
||||
+ * allowing SHA-1 signature verification using the SHA1 crypto-module
|
||||
+ */
|
||||
+ cms = CMS_ContentInfo_new_ex(NULL, "-fips");
|
||||
+ if (!cms)
|
||||
+ goto cleanup;
|
||||
+#endif
|
||||
+
|
||||
/* decode received CMS message */
|
||||
- if ((cms = d2i_CMS_ContentInfo(NULL, &p, (int)signed_data_len)) == NULL) {
|
||||
+ if (!d2i_CMS_ContentInfo(&cms, &p, (int)signed_data_len)) {
|
||||
retval = oerr(context, 0, _("Failed to decode CMS message"));
|
||||
goto cleanup;
|
||||
}
|
||||
--
|
||||
2.45.1
|
||||
|
||||
|
|
@ -1,218 +0,0 @@
|
|||
From c24c9faf859ddc04910a6bc591d8ddb2ada93e80 Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Tue, 30 May 2023 01:21:48 -0400
|
||||
Subject: [PATCH] Enable PKINIT if at least one group is available
|
||||
|
||||
OpenSSL may no longer allow decoding of non-well-known Diffie-Hellman
|
||||
group parameters as EVP_PKEY objects in FIPS mode. However, OpenSSL
|
||||
does not know about MODP group 2 (1024-bit), which is considered as a
|
||||
custom group. As a consequence, the PKINIT kdcpreauth module fails to
|
||||
load in FIPS mode.
|
||||
|
||||
Allow initialization of PKINIT plugin if at least one of the MODP
|
||||
well-known group parameters successfully decodes.
|
||||
|
||||
[ghudson@mit.edu: minor commit message and code edits]
|
||||
|
||||
ticket: 9096 (new)
|
||||
(cherry picked from commit 509d8db922e9ad6f108883838473b6178f89874a)
|
||||
---
|
||||
src/plugins/preauth/pkinit/pkinit_clnt.c | 2 +-
|
||||
src/plugins/preauth/pkinit/pkinit_crypto.h | 3 +-
|
||||
.../preauth/pkinit/pkinit_crypto_openssl.c | 76 +++++++++++--------
|
||||
src/plugins/preauth/pkinit/pkinit_srv.c | 2 +-
|
||||
src/plugins/preauth/pkinit/pkinit_trace.h | 3 +
|
||||
5 files changed, 51 insertions(+), 35 deletions(-)
|
||||
|
||||
diff --git a/src/plugins/preauth/pkinit/pkinit_clnt.c b/src/plugins/preauth/pkinit/pkinit_clnt.c
|
||||
index 725d5bc438..ea9ba454df 100644
|
||||
--- a/src/plugins/preauth/pkinit/pkinit_clnt.c
|
||||
+++ b/src/plugins/preauth/pkinit/pkinit_clnt.c
|
||||
@@ -1378,7 +1378,7 @@ pkinit_client_plugin_init(krb5_context context,
|
||||
if (retval)
|
||||
goto errout;
|
||||
|
||||
- retval = pkinit_init_plg_crypto(&ctx->cryptoctx);
|
||||
+ retval = pkinit_init_plg_crypto(context, &ctx->cryptoctx);
|
||||
if (retval)
|
||||
goto errout;
|
||||
|
||||
diff --git a/src/plugins/preauth/pkinit/pkinit_crypto.h b/src/plugins/preauth/pkinit/pkinit_crypto.h
|
||||
index 9fa315d7a0..8bdbea8e95 100644
|
||||
--- a/src/plugins/preauth/pkinit/pkinit_crypto.h
|
||||
+++ b/src/plugins/preauth/pkinit/pkinit_crypto.h
|
||||
@@ -103,7 +103,8 @@ typedef struct _pkinit_cert_matching_data {
|
||||
/*
|
||||
* Functions to initialize and cleanup crypto contexts
|
||||
*/
|
||||
-krb5_error_code pkinit_init_plg_crypto(pkinit_plg_crypto_context *);
|
||||
+krb5_error_code pkinit_init_plg_crypto(krb5_context,
|
||||
+ pkinit_plg_crypto_context *);
|
||||
void pkinit_fini_plg_crypto(pkinit_plg_crypto_context);
|
||||
|
||||
krb5_error_code pkinit_init_req_crypto(pkinit_req_crypto_context *);
|
||||
diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c
|
||||
index 17dd18e37d..8cdc40bfb4 100644
|
||||
--- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c
|
||||
+++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c
|
||||
@@ -47,7 +47,8 @@
|
||||
static krb5_error_code pkinit_init_pkinit_oids(pkinit_plg_crypto_context );
|
||||
static void pkinit_fini_pkinit_oids(pkinit_plg_crypto_context );
|
||||
|
||||
-static krb5_error_code pkinit_init_dh_params(pkinit_plg_crypto_context );
|
||||
+static krb5_error_code pkinit_init_dh_params(krb5_context,
|
||||
+ pkinit_plg_crypto_context);
|
||||
static void pkinit_fini_dh_params(pkinit_plg_crypto_context );
|
||||
|
||||
static krb5_error_code pkinit_init_certs(pkinit_identity_crypto_context ctx);
|
||||
@@ -951,7 +952,8 @@ oerr_cert(krb5_context context, krb5_error_code code, X509_STORE_CTX *certctx,
|
||||
}
|
||||
|
||||
krb5_error_code
|
||||
-pkinit_init_plg_crypto(pkinit_plg_crypto_context *cryptoctx)
|
||||
+pkinit_init_plg_crypto(krb5_context context,
|
||||
+ pkinit_plg_crypto_context *cryptoctx)
|
||||
{
|
||||
krb5_error_code retval = ENOMEM;
|
||||
pkinit_plg_crypto_context ctx = NULL;
|
||||
@@ -969,7 +971,7 @@ pkinit_init_plg_crypto(pkinit_plg_crypto_context *cryptoctx)
|
||||
if (retval)
|
||||
goto out;
|
||||
|
||||
- retval = pkinit_init_dh_params(ctx);
|
||||
+ retval = pkinit_init_dh_params(context, ctx);
|
||||
if (retval)
|
||||
goto out;
|
||||
|
||||
@@ -1278,30 +1280,36 @@ pkinit_fini_pkinit_oids(pkinit_plg_crypto_context ctx)
|
||||
ASN1_OBJECT_free(ctx->id_kp_serverAuth);
|
||||
}
|
||||
|
||||
-static krb5_error_code
|
||||
-pkinit_init_dh_params(pkinit_plg_crypto_context plgctx)
|
||||
+static int
|
||||
+try_import_group(krb5_context context, const krb5_data *params,
|
||||
+ const char *name, EVP_PKEY **pkey_out)
|
||||
{
|
||||
- krb5_error_code retval = ENOMEM;
|
||||
-
|
||||
- plgctx->dh_1024 = decode_dh_params(&oakley_1024);
|
||||
- if (plgctx->dh_1024 == NULL)
|
||||
- goto cleanup;
|
||||
-
|
||||
- plgctx->dh_2048 = decode_dh_params(&oakley_2048);
|
||||
- if (plgctx->dh_2048 == NULL)
|
||||
- goto cleanup;
|
||||
+ *pkey_out = decode_dh_params(params);
|
||||
+ if (*pkey_out == NULL)
|
||||
+ TRACE_PKINIT_DH_GROUP_UNAVAILABLE(context, name);
|
||||
+ return (*pkey_out != NULL) ? 1 : 0;
|
||||
+}
|
||||
|
||||
- plgctx->dh_4096 = decode_dh_params(&oakley_4096);
|
||||
- if (plgctx->dh_4096 == NULL)
|
||||
- goto cleanup;
|
||||
+static krb5_error_code
|
||||
+pkinit_init_dh_params(krb5_context context, pkinit_plg_crypto_context plgctx)
|
||||
+{
|
||||
+ int n = 0;
|
||||
|
||||
- retval = 0;
|
||||
+ n += try_import_group(context, &oakley_1024, "MODP 2 (1024-bit)",
|
||||
+ &plgctx->dh_1024);
|
||||
+ n += try_import_group(context, &oakley_2048, "MODP 14 (2048-bit)",
|
||||
+ &plgctx->dh_2048);
|
||||
+ n += try_import_group(context, &oakley_4096, "MODP 16 (4096-bit)",
|
||||
+ &plgctx->dh_4096);
|
||||
|
||||
-cleanup:
|
||||
- if (retval)
|
||||
+ if (n == 0) {
|
||||
pkinit_fini_dh_params(plgctx);
|
||||
+ k5_setmsg(context, ENOMEM,
|
||||
+ _("PKINIT cannot initialize any key exchange groups"));
|
||||
+ return ENOMEM;
|
||||
+ }
|
||||
|
||||
- return retval;
|
||||
+ return 0;
|
||||
}
|
||||
|
||||
static void
|
||||
@@ -2912,11 +2920,11 @@ client_create_dh(krb5_context context,
|
||||
|
||||
if (cryptoctx->received_params != NULL)
|
||||
params = cryptoctx->received_params;
|
||||
- else if (dh_size == 1024)
|
||||
+ else if (plg_cryptoctx->dh_1024 != NULL && dh_size == 1024)
|
||||
params = plg_cryptoctx->dh_1024;
|
||||
- else if (dh_size == 2048)
|
||||
+ else if (plg_cryptoctx->dh_2048 != NULL && dh_size == 2048)
|
||||
params = plg_cryptoctx->dh_2048;
|
||||
- else if (dh_size == 4096)
|
||||
+ else if (plg_cryptoctx->dh_4096 != NULL && dh_size == 4096)
|
||||
params = plg_cryptoctx->dh_4096;
|
||||
else
|
||||
goto cleanup;
|
||||
@@ -3212,19 +3220,23 @@ pkinit_create_td_dh_parameters(krb5_context context,
|
||||
krb5_algorithm_identifier alg_4096 = { dh_oid, oakley_4096 };
|
||||
krb5_algorithm_identifier *alglist[4];
|
||||
|
||||
- if (opts->dh_min_bits > 4096) {
|
||||
- ret = KRB5KRB_ERR_GENERIC;
|
||||
- goto cleanup;
|
||||
- }
|
||||
-
|
||||
i = 0;
|
||||
- if (opts->dh_min_bits <= 2048)
|
||||
+ if (plg_cryptoctx->dh_2048 != NULL && opts->dh_min_bits <= 2048)
|
||||
alglist[i++] = &alg_2048;
|
||||
- alglist[i++] = &alg_4096;
|
||||
- if (opts->dh_min_bits <= 1024)
|
||||
+ if (plg_cryptoctx->dh_4096 != NULL && opts->dh_min_bits <= 4096)
|
||||
+ alglist[i++] = &alg_4096;
|
||||
+ if (plg_cryptoctx->dh_1024 != NULL && opts->dh_min_bits <= 1024)
|
||||
alglist[i++] = &alg_1024;
|
||||
alglist[i] = NULL;
|
||||
|
||||
+ if (i == 0) {
|
||||
+ ret = KRB5KRB_ERR_GENERIC;
|
||||
+ k5_setmsg(context, ret,
|
||||
+ _("OpenSSL has no supported key exchange groups for "
|
||||
+ "pkinit_dh_min_bits=%d"), opts->dh_min_bits);
|
||||
+ goto cleanup;
|
||||
+ }
|
||||
+
|
||||
ret = k5int_encode_krb5_td_dh_parameters(alglist, &der_alglist);
|
||||
if (ret)
|
||||
goto cleanup;
|
||||
diff --git a/src/plugins/preauth/pkinit/pkinit_srv.c b/src/plugins/preauth/pkinit/pkinit_srv.c
|
||||
index 1b3bf6d4d0..768a4e559f 100644
|
||||
--- a/src/plugins/preauth/pkinit/pkinit_srv.c
|
||||
+++ b/src/plugins/preauth/pkinit/pkinit_srv.c
|
||||
@@ -1222,7 +1222,7 @@ pkinit_server_plugin_init_realm(krb5_context context, const char *realmname,
|
||||
goto errout;
|
||||
plgctx->realmname_len = strlen(plgctx->realmname);
|
||||
|
||||
- retval = pkinit_init_plg_crypto(&plgctx->cryptoctx);
|
||||
+ retval = pkinit_init_plg_crypto(context, &plgctx->cryptoctx);
|
||||
if (retval)
|
||||
goto errout;
|
||||
|
||||
diff --git a/src/plugins/preauth/pkinit/pkinit_trace.h b/src/plugins/preauth/pkinit/pkinit_trace.h
|
||||
index 259e95c6c2..5ee39c085c 100644
|
||||
--- a/src/plugins/preauth/pkinit/pkinit_trace.h
|
||||
+++ b/src/plugins/preauth/pkinit/pkinit_trace.h
|
||||
@@ -90,6 +90,9 @@
|
||||
#define TRACE_PKINIT_CLIENT_TRYAGAIN(c) \
|
||||
TRACE(c, "PKINIT client trying again with KDC-provided parameters")
|
||||
|
||||
+#define TRACE_PKINIT_DH_GROUP_UNAVAILABLE(c, name) \
|
||||
+ TRACE(c, "PKINIT key exchange group {str} unsupported", name)
|
||||
+
|
||||
#define TRACE_PKINIT_OPENSSL_ERROR(c, msg) \
|
||||
TRACE(c, "PKINIT OpenSSL error: {str}", msg)
|
||||
|
||||
--
|
||||
2.45.1
|
||||
|
||||
|
|
@ -1,64 +0,0 @@
|
|||
From e92365b510a2407eaceaec90836f5c713403d75f Mon Sep 17 00:00:00 2001
|
||||
From: Julien Rische <jrische@redhat.com>
|
||||
Date: Wed, 19 Jul 2023 13:43:17 +0200
|
||||
Subject: [PATCH] Replace ssl.wrap_socket() for tests
|
||||
|
||||
The ssl.wrap_socket() function was deprecated in Python 3.7 and is
|
||||
removed in Python 3.12. The ssl.SSLContext.wrap_socket() method
|
||||
replaces it.
|
||||
|
||||
Bump the required Python version for tests to 3.4 for
|
||||
ssl.create_default_context().
|
||||
|
||||
[ghudson@mit.edu: changed minimum Python version]
|
||||
|
||||
(cherry picked from commit 0ceab6c363e65fb21d3312a663f2b9b569ecc415)
|
||||
---
|
||||
src/configure.ac | 9 ++++-----
|
||||
src/util/wsgiref-kdcproxy.py | 4 +++-
|
||||
2 files changed, 7 insertions(+), 6 deletions(-)
|
||||
|
||||
diff --git a/src/configure.ac b/src/configure.ac
|
||||
index 2561e917a2..487f393146 100644
|
||||
--- a/src/configure.ac
|
||||
+++ b/src/configure.ac
|
||||
@@ -1157,10 +1157,9 @@ AC_SUBST(PKINIT)
|
||||
# for lib/apputils
|
||||
AC_REPLACE_FUNCS(daemon)
|
||||
|
||||
-# For Python tests. Python version 3.2.4 is required as prior
|
||||
-# versions do not accept string input to subprocess.Popen.communicate
|
||||
-# when universal_newlines is set.
|
||||
-PYTHON_MINVERSION=3.2.4
|
||||
+# For Python tests. Python version 3.4 is required for
|
||||
+# ssl.create_default_context().
|
||||
+PYTHON_MINVERSION=3.4
|
||||
AC_SUBST(PYTHON_MINVERSION)
|
||||
AC_CHECK_PROG(PYTHON,python3,python3)
|
||||
if test x"$PYTHON" = x; then
|
||||
@@ -1168,7 +1167,7 @@ if test x"$PYTHON" = x; then
|
||||
fi
|
||||
HAVE_PYTHON=no
|
||||
if test x"$PYTHON" != x; then
|
||||
- wantver="(sys.hexversion >= 0x30204F0)"
|
||||
+ wantver="(sys.hexversion >= 0x30400F0)"
|
||||
if "$PYTHON" -c "import sys; sys.exit(not $wantver and 1 or 0)"; then
|
||||
HAVE_PYTHON=yes
|
||||
fi
|
||||
diff --git a/src/util/wsgiref-kdcproxy.py b/src/util/wsgiref-kdcproxy.py
|
||||
index 58759696b6..d1d10d733c 100755
|
||||
--- a/src/util/wsgiref-kdcproxy.py
|
||||
+++ b/src/util/wsgiref-kdcproxy.py
|
||||
@@ -14,6 +14,8 @@ else:
|
||||
pem = '*'
|
||||
|
||||
server = make_server('localhost', port, kdcproxy.Application())
|
||||
-server.socket = ssl.wrap_socket(server.socket, certfile=pem, server_side=True)
|
||||
+sslctx = ssl.create_default_context(purpose=ssl.Purpose.CLIENT_AUTH)
|
||||
+sslctx.load_cert_chain(certfile=pem)
|
||||
+server.socket = sslctx.wrap_socket(server.socket, server_side=True)
|
||||
os.write(sys.stdout.fileno(), b'proxy server ready\n')
|
||||
server.serve_forever()
|
||||
--
|
||||
2.45.1
|
||||
|
||||
File diff suppressed because it is too large
Load diff
|
|
@ -1,206 +0,0 @@
|
|||
From ee66c1feedb57ce06ce51aaa823f9a61f564c58e Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Tue, 5 Mar 2024 19:53:07 -0500
|
||||
Subject: [PATCH] Fix two unlikely memory leaks
|
||||
|
||||
In gss_krb5int_make_seal_token_v3(), one of the bounds checks (which
|
||||
could probably never be triggered) leaks plain.data. Fix this leak
|
||||
and use current practices for cleanup throughout the function.
|
||||
|
||||
In xmt_rmtcallres() (unused within the tree and likely elsewhere),
|
||||
store port_ptr into crp->port_ptr as soon as it is allocated;
|
||||
otherwise it could leak if the subsequent xdr_u_int32() operation
|
||||
fails.
|
||||
|
||||
(cherry picked from commit c5f9c816107f70139de11b38aa02db2f1774ee0d)
|
||||
---
|
||||
src/lib/gssapi/krb5/k5sealv3.c | 56 +++++++++++++++-------------------
|
||||
src/lib/rpc/pmap_rmt.c | 10 +++---
|
||||
2 files changed, 29 insertions(+), 37 deletions(-)
|
||||
|
||||
diff --git a/src/lib/gssapi/krb5/k5sealv3.c b/src/lib/gssapi/krb5/k5sealv3.c
|
||||
index 1fcbdfbb87..d3210c1107 100644
|
||||
--- a/src/lib/gssapi/krb5/k5sealv3.c
|
||||
+++ b/src/lib/gssapi/krb5/k5sealv3.c
|
||||
@@ -65,7 +65,7 @@ gss_krb5int_make_seal_token_v3 (krb5_context context,
|
||||
int conf_req_flag, int toktype)
|
||||
{
|
||||
size_t bufsize = 16;
|
||||
- unsigned char *outbuf = 0;
|
||||
+ unsigned char *outbuf = NULL;
|
||||
krb5_error_code err;
|
||||
int key_usage;
|
||||
unsigned char acceptor_flag;
|
||||
@@ -75,9 +75,13 @@ gss_krb5int_make_seal_token_v3 (krb5_context context,
|
||||
#endif
|
||||
size_t ec;
|
||||
unsigned short tok_id;
|
||||
- krb5_checksum sum;
|
||||
+ krb5_checksum sum = { 0 };
|
||||
krb5_key key;
|
||||
krb5_cksumtype cksumtype;
|
||||
+ krb5_data plain = empty_data();
|
||||
+
|
||||
+ token->value = NULL;
|
||||
+ token->length = 0;
|
||||
|
||||
acceptor_flag = ctx->initiate ? 0 : FLAG_SENDER_IS_ACCEPTOR;
|
||||
key_usage = (toktype == KG_TOK_WRAP_MSG
|
||||
@@ -107,14 +111,15 @@ gss_krb5int_make_seal_token_v3 (krb5_context context,
|
||||
#endif
|
||||
|
||||
if (toktype == KG_TOK_WRAP_MSG && conf_req_flag) {
|
||||
- krb5_data plain;
|
||||
krb5_enc_data cipher;
|
||||
size_t ec_max;
|
||||
size_t encrypt_size;
|
||||
|
||||
/* 300: Adds some slop. */
|
||||
- if (SIZE_MAX - 300 < message->length)
|
||||
- return ENOMEM;
|
||||
+ if (SIZE_MAX - 300 < message->length) {
|
||||
+ err = ENOMEM;
|
||||
+ goto cleanup;
|
||||
+ }
|
||||
ec_max = SIZE_MAX - message->length - 300;
|
||||
if (ec_max > 0xffff)
|
||||
ec_max = 0xffff;
|
||||
@@ -126,20 +131,20 @@ gss_krb5int_make_seal_token_v3 (krb5_context context,
|
||||
#endif
|
||||
err = alloc_data(&plain, message->length + 16 + ec);
|
||||
if (err)
|
||||
- return err;
|
||||
+ goto cleanup;
|
||||
|
||||
/* Get size of ciphertext. */
|
||||
encrypt_size = krb5_encrypt_size(plain.length, key->keyblock.enctype);
|
||||
if (encrypt_size > SIZE_MAX / 2) {
|
||||
err = ENOMEM;
|
||||
- goto error;
|
||||
+ goto cleanup;
|
||||
}
|
||||
bufsize = 16 + encrypt_size;
|
||||
/* Allocate space for header plus encrypted data. */
|
||||
outbuf = gssalloc_malloc(bufsize);
|
||||
if (outbuf == NULL) {
|
||||
- free(plain.data);
|
||||
- return ENOMEM;
|
||||
+ err = ENOMEM;
|
||||
+ goto cleanup;
|
||||
}
|
||||
|
||||
/* TOK_ID */
|
||||
@@ -164,11 +169,8 @@ gss_krb5int_make_seal_token_v3 (krb5_context context,
|
||||
cipher.ciphertext.length = bufsize - 16;
|
||||
cipher.enctype = key->keyblock.enctype;
|
||||
err = krb5_k_encrypt(context, key, key_usage, 0, &plain, &cipher);
|
||||
- zap(plain.data, plain.length);
|
||||
- free(plain.data);
|
||||
- plain.data = 0;
|
||||
if (err)
|
||||
- goto error;
|
||||
+ goto cleanup;
|
||||
|
||||
/* Now that we know we're returning a valid token.... */
|
||||
ctx->seq_send++;
|
||||
@@ -181,7 +183,6 @@ gss_krb5int_make_seal_token_v3 (krb5_context context,
|
||||
/* If the rotate fails, don't worry about it. */
|
||||
#endif
|
||||
} else if (toktype == KG_TOK_WRAP_MSG && !conf_req_flag) {
|
||||
- krb5_data plain;
|
||||
size_t cksumsize;
|
||||
|
||||
/* Here, message is the application-supplied data; message2 is
|
||||
@@ -193,21 +194,19 @@ gss_krb5int_make_seal_token_v3 (krb5_context context,
|
||||
wrap_with_checksum:
|
||||
err = alloc_data(&plain, message->length + 16);
|
||||
if (err)
|
||||
- return err;
|
||||
+ goto cleanup;
|
||||
|
||||
err = krb5_c_checksum_length(context, cksumtype, &cksumsize);
|
||||
if (err)
|
||||
- goto error;
|
||||
+ goto cleanup;
|
||||
|
||||
assert(cksumsize <= 0xffff);
|
||||
|
||||
bufsize = 16 + message2->length + cksumsize;
|
||||
outbuf = gssalloc_malloc(bufsize);
|
||||
if (outbuf == NULL) {
|
||||
- free(plain.data);
|
||||
- plain.data = 0;
|
||||
err = ENOMEM;
|
||||
- goto error;
|
||||
+ goto cleanup;
|
||||
}
|
||||
|
||||
/* TOK_ID */
|
||||
@@ -239,23 +238,15 @@ gss_krb5int_make_seal_token_v3 (krb5_context context,
|
||||
if (message2->length)
|
||||
memcpy(outbuf + 16, message2->value, message2->length);
|
||||
|
||||
- sum.contents = outbuf + 16 + message2->length;
|
||||
- sum.length = cksumsize;
|
||||
-
|
||||
err = krb5_k_make_checksum(context, cksumtype, key,
|
||||
key_usage, &plain, &sum);
|
||||
- zap(plain.data, plain.length);
|
||||
- free(plain.data);
|
||||
- plain.data = 0;
|
||||
if (err) {
|
||||
zap(outbuf,bufsize);
|
||||
- goto error;
|
||||
+ goto cleanup;
|
||||
}
|
||||
if (sum.length != cksumsize)
|
||||
abort();
|
||||
memcpy(outbuf + 16 + message2->length, sum.contents, cksumsize);
|
||||
- krb5_free_checksum_contents(context, &sum);
|
||||
- sum.contents = 0;
|
||||
/* Now that we know we're actually generating the token... */
|
||||
ctx->seq_send++;
|
||||
|
||||
@@ -285,12 +276,13 @@ gss_krb5int_make_seal_token_v3 (krb5_context context,
|
||||
|
||||
token->value = outbuf;
|
||||
token->length = bufsize;
|
||||
- return 0;
|
||||
+ outbuf = NULL;
|
||||
+ err = 0;
|
||||
|
||||
-error:
|
||||
+cleanup:
|
||||
+ krb5_free_checksum_contents(context, &sum);
|
||||
+ zapfree(plain.data, plain.length);
|
||||
gssalloc_free(outbuf);
|
||||
- token->value = NULL;
|
||||
- token->length = 0;
|
||||
return err;
|
||||
}
|
||||
|
||||
diff --git a/src/lib/rpc/pmap_rmt.c b/src/lib/rpc/pmap_rmt.c
|
||||
index 434e4eea65..f55ca46c60 100644
|
||||
--- a/src/lib/rpc/pmap_rmt.c
|
||||
+++ b/src/lib/rpc/pmap_rmt.c
|
||||
@@ -161,12 +161,12 @@ xdr_rmtcallres(
|
||||
caddr_t port_ptr;
|
||||
|
||||
port_ptr = (caddr_t)(void *)crp->port_ptr;
|
||||
- if (xdr_reference(xdrs, &port_ptr, sizeof (uint32_t),
|
||||
- (xdrproc_t)xdr_u_int32) &&
|
||||
- xdr_u_int32(xdrs, &crp->resultslen)) {
|
||||
- crp->port_ptr = (uint32_t *)(void *)port_ptr;
|
||||
+ if (!xdr_reference(xdrs, &port_ptr, sizeof (uint32_t),
|
||||
+ (xdrproc_t)xdr_u_int32))
|
||||
+ return (FALSE);
|
||||
+ crp->port_ptr = (uint32_t *)(void *)port_ptr;
|
||||
+ if (xdr_u_int32(xdrs, &crp->resultslen))
|
||||
return ((*(crp->xdr_results))(xdrs, crp->results_ptr));
|
||||
- }
|
||||
return (FALSE);
|
||||
}
|
||||
|
||||
--
|
||||
2.45.1
|
||||
|
||||
File diff suppressed because it is too large
Load diff
|
|
@ -1,71 +0,0 @@
|
|||
From 05bb6d9c729a3c6a4ba35270368bc0f6e1875ad0 Mon Sep 17 00:00:00 2001
|
||||
From: Julien Rische <jrische@redhat.com>
|
||||
Date: Mon, 8 Jan 2024 16:52:27 +0100
|
||||
Subject: [PATCH] Remove klist's defname global variable
|
||||
|
||||
Addition of a "cleanup" section in kinit's show_ccache() function as
|
||||
part of commit 6c5471176f5266564fbc8a7e02f03b4b042202f8 introduced a
|
||||
double-free bug, because defname is a global variable. After the
|
||||
first call, successive calls may take place with a dangling pointer in
|
||||
defname, which will be freed if krb5_cc_get_principal() fails.
|
||||
|
||||
Convert "defname" to a local variable initialized at the beginning of
|
||||
show_ccache().
|
||||
|
||||
[ghudson@mit.edu: edited commit message]
|
||||
|
||||
(cherry picked from commit 5b00197227231943bd2305328c8260dd0b0dbcf0)
|
||||
---
|
||||
src/clients/klist/klist.c | 8 ++++----
|
||||
1 file changed, 4 insertions(+), 4 deletions(-)
|
||||
|
||||
diff --git a/src/clients/klist/klist.c b/src/clients/klist/klist.c
|
||||
index b5ae96a843..b5808e5c93 100644
|
||||
--- a/src/clients/klist/klist.c
|
||||
+++ b/src/clients/klist/klist.c
|
||||
@@ -53,7 +53,6 @@ int show_flags = 0, show_time = 0, status_only = 0, show_keys = 0;
|
||||
int show_etype = 0, show_addresses = 0, no_resolve = 0, print_version = 0;
|
||||
int show_adtype = 0, show_all = 0, list_all = 0, use_client_keytab = 0;
|
||||
int show_config = 0;
|
||||
-char *defname;
|
||||
char *progname;
|
||||
krb5_timestamp now;
|
||||
unsigned int timestamp_width;
|
||||
@@ -62,7 +61,7 @@ krb5_context context;
|
||||
|
||||
static krb5_boolean is_local_tgt(krb5_principal princ, krb5_data *realm);
|
||||
static char *etype_string(krb5_enctype );
|
||||
-static void show_credential(krb5_creds *);
|
||||
+static void show_credential(krb5_creds *, const char *);
|
||||
|
||||
static void list_all_ccaches(void);
|
||||
static int list_ccache(krb5_ccache);
|
||||
@@ -473,6 +472,7 @@ show_ccache(krb5_ccache cache)
|
||||
krb5_creds creds;
|
||||
krb5_principal princ = NULL;
|
||||
krb5_error_code ret;
|
||||
+ char *defname = NULL;
|
||||
int status = 1;
|
||||
|
||||
ret = krb5_cc_get_principal(context, cache, &princ);
|
||||
@@ -503,7 +503,7 @@ show_ccache(krb5_ccache cache)
|
||||
}
|
||||
while ((ret = krb5_cc_next_cred(context, cache, &cur, &creds)) == 0) {
|
||||
if (show_config || !krb5_is_config_principal(context, creds.server))
|
||||
- show_credential(&creds);
|
||||
+ show_credential(&creds, defname);
|
||||
krb5_free_cred_contents(context, &creds);
|
||||
}
|
||||
if (ret == KRB5_CC_END) {
|
||||
@@ -676,7 +676,7 @@ print_config_data(int col, krb5_data *data)
|
||||
}
|
||||
|
||||
static void
|
||||
-show_credential(krb5_creds *cred)
|
||||
+show_credential(krb5_creds *cred, const char *defname)
|
||||
{
|
||||
krb5_error_code ret;
|
||||
krb5_ticket *tkt = NULL;
|
||||
--
|
||||
2.45.1
|
||||
|
||||
|
|
@ -1,34 +0,0 @@
|
|||
From d7bcca2a215de880f4419afc450a96a747d48560 Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Fri, 27 Oct 2023 00:44:53 -0400
|
||||
Subject: [PATCH] End connection on KDC_ERR_SVC_UNAVAILABLE
|
||||
|
||||
In sendto_kdc.c:service_fds(), if a message handler indicates that a
|
||||
message should be discarded, kill the connection so we don't continue
|
||||
waiting on it for more data.
|
||||
|
||||
ticket: 7899
|
||||
(cherry picked from commit ca80f64c786341d5871ae1de18142e62af64f7b9)
|
||||
---
|
||||
src/lib/krb5/os/sendto_kdc.c | 5 ++++-
|
||||
1 file changed, 4 insertions(+), 1 deletion(-)
|
||||
|
||||
diff --git a/src/lib/krb5/os/sendto_kdc.c b/src/lib/krb5/os/sendto_kdc.c
|
||||
index 0f4bf23a95..262edf09b4 100644
|
||||
--- a/src/lib/krb5/os/sendto_kdc.c
|
||||
+++ b/src/lib/krb5/os/sendto_kdc.c
|
||||
@@ -1440,7 +1440,10 @@ service_fds(krb5_context context, struct select_state *selstate,
|
||||
if (msg_handler != NULL) {
|
||||
krb5_data reply = make_data(state->in.buf, state->in.pos);
|
||||
|
||||
- stop = (msg_handler(context, &reply, msg_handler_data) != 0);
|
||||
+ if (!msg_handler(context, &reply, msg_handler_data)) {
|
||||
+ kill_conn(context, state, selstate);
|
||||
+ stop = 0;
|
||||
+ }
|
||||
}
|
||||
|
||||
if (stop) {
|
||||
--
|
||||
2.46.0
|
||||
|
||||
|
|
@ -1,226 +0,0 @@
|
|||
From a07b3ae29fd972c40e30b95f6bcc8fb3ed4d9991 Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Thu, 26 Oct 2023 14:20:34 -0400
|
||||
Subject: [PATCH] Add request_timeout configuration parameter
|
||||
|
||||
Add a parameter to limit the total amount of time taken for a KDC or
|
||||
password change request.
|
||||
|
||||
ticket: 9106 (new)
|
||||
(cherry picked from commit 802318cda963456b3ed7856c836e89da891483be)
|
||||
---
|
||||
doc/admin/conf_files/krb5_conf.rst | 9 ++++++
|
||||
src/include/k5-int.h | 2 ++
|
||||
src/lib/krb5/krb/init_ctx.c | 14 +++++++-
|
||||
src/lib/krb5/os/sendto_kdc.c | 51 ++++++++++++++++++++----------
|
||||
4 files changed, 58 insertions(+), 18 deletions(-)
|
||||
|
||||
diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst
|
||||
index a33711d918..65fb592d98 100644
|
||||
--- a/doc/admin/conf_files/krb5_conf.rst
|
||||
+++ b/doc/admin/conf_files/krb5_conf.rst
|
||||
@@ -356,6 +356,15 @@ The libdefaults section may contain any of the following relations:
|
||||
(:ref:`duration` string.) Sets the default renewable lifetime
|
||||
for initial ticket requests. The default value is 0.
|
||||
|
||||
+**request_timeout**
|
||||
+ (:ref:`duration` string.) Sets the maximum total time for KDC or
|
||||
+ password change requests. This timeout does not affect the
|
||||
+ intervals between requests, so setting a low timeout may result in
|
||||
+ fewer requests being attempted and/or some servers not being
|
||||
+ contacted. A value of 0 indicates no specific maximum, in which
|
||||
+ case requests will time out if no server responds after several
|
||||
+ tries. The default value is 0. (New in release 1.22.)
|
||||
+
|
||||
**spake_preauth_groups**
|
||||
A whitespace or comma-separated list of words which specifies the
|
||||
groups allowed for SPAKE preauthentication. The possible values
|
||||
diff --git a/src/include/k5-int.h b/src/include/k5-int.h
|
||||
index b3e07945c1..69d6a6f569 100644
|
||||
--- a/src/include/k5-int.h
|
||||
+++ b/src/include/k5-int.h
|
||||
@@ -296,6 +296,7 @@ typedef unsigned char u_char;
|
||||
#define KRB5_CONF_SPAKE_PREAUTH_INDICATOR "spake_preauth_indicator"
|
||||
#define KRB5_CONF_SPAKE_PREAUTH_KDC_CHALLENGE "spake_preauth_kdc_challenge"
|
||||
#define KRB5_CONF_SPAKE_PREAUTH_GROUPS "spake_preauth_groups"
|
||||
+#define KRB5_CONF_REQUEST_TIMEOUT "request_timeout"
|
||||
#define KRB5_CONF_TICKET_LIFETIME "ticket_lifetime"
|
||||
#define KRB5_CONF_UDP_PREFERENCE_LIMIT "udp_preference_limit"
|
||||
#define KRB5_CONF_UNLOCKITER "unlockiter"
|
||||
@@ -1200,6 +1201,7 @@ struct _krb5_context {
|
||||
kdb5_dal_handle *dal_handle;
|
||||
/* allowable clock skew */
|
||||
krb5_deltat clockskew;
|
||||
+ krb5_deltat req_timeout;
|
||||
krb5_flags kdc_default_options;
|
||||
krb5_flags library_options;
|
||||
krb5_boolean profile_secure;
|
||||
diff --git a/src/lib/krb5/krb/init_ctx.c b/src/lib/krb5/krb/init_ctx.c
|
||||
index 2b5abcd817..582a2945ff 100644
|
||||
--- a/src/lib/krb5/krb/init_ctx.c
|
||||
+++ b/src/lib/krb5/krb/init_ctx.c
|
||||
@@ -157,7 +157,7 @@ krb5_init_context_profile(profile_t profile, krb5_flags flags,
|
||||
krb5_context ctx = 0;
|
||||
krb5_error_code retval;
|
||||
int tmp;
|
||||
- char *plugin_dir = NULL;
|
||||
+ char *plugin_dir = NULL, *timeout_str = NULL;
|
||||
|
||||
/* Verify some assumptions. If the assumptions hold and the
|
||||
compiler is optimizing, this should result in no code being
|
||||
@@ -240,6 +240,17 @@ krb5_init_context_profile(profile_t profile, krb5_flags flags,
|
||||
get_integer(ctx, KRB5_CONF_CLOCKSKEW, DEFAULT_CLOCKSKEW, &tmp);
|
||||
ctx->clockskew = tmp;
|
||||
|
||||
+ retval = profile_get_string(ctx->profile, KRB5_CONF_LIBDEFAULTS,
|
||||
+ KRB5_CONF_REQUEST_TIMEOUT, NULL, NULL,
|
||||
+ &timeout_str);
|
||||
+ if (retval)
|
||||
+ goto cleanup;
|
||||
+ if (timeout_str != NULL) {
|
||||
+ retval = krb5_string_to_deltat(timeout_str, &ctx->req_timeout);
|
||||
+ if (retval)
|
||||
+ goto cleanup;
|
||||
+ }
|
||||
+
|
||||
get_integer(ctx, KRB5_CONF_KDC_DEFAULT_OPTIONS, KDC_OPT_RENEWABLE_OK,
|
||||
&tmp);
|
||||
ctx->kdc_default_options = tmp;
|
||||
@@ -281,6 +292,7 @@ krb5_init_context_profile(profile_t profile, krb5_flags flags,
|
||||
|
||||
cleanup:
|
||||
profile_release_string(plugin_dir);
|
||||
+ profile_release_string(timeout_str);
|
||||
krb5_free_context(ctx);
|
||||
return retval;
|
||||
}
|
||||
diff --git a/src/lib/krb5/os/sendto_kdc.c b/src/lib/krb5/os/sendto_kdc.c
|
||||
index 262edf09b4..98247a1089 100644
|
||||
--- a/src/lib/krb5/os/sendto_kdc.c
|
||||
+++ b/src/lib/krb5/os/sendto_kdc.c
|
||||
@@ -1395,34 +1395,41 @@ get_endtime(time_ms endtime, struct conn_state *conns)
|
||||
|
||||
static krb5_boolean
|
||||
service_fds(krb5_context context, struct select_state *selstate,
|
||||
- time_ms interval, struct conn_state *conns,
|
||||
+ time_ms interval, time_ms timeout, struct conn_state *conns,
|
||||
struct select_state *seltemp, const krb5_data *realm,
|
||||
int (*msg_handler)(krb5_context, const krb5_data *, void *),
|
||||
void *msg_handler_data, struct conn_state **winner_out)
|
||||
{
|
||||
int e, selret = 0;
|
||||
- time_ms endtime;
|
||||
+ time_ms curtime, interval_end, endtime;
|
||||
struct conn_state *state;
|
||||
|
||||
*winner_out = NULL;
|
||||
|
||||
- e = get_curtime_ms(&endtime);
|
||||
+ e = get_curtime_ms(&curtime);
|
||||
if (e)
|
||||
return TRUE;
|
||||
- endtime += interval;
|
||||
+ interval_end = curtime + interval;
|
||||
|
||||
e = 0;
|
||||
while (selstate->nfds > 0) {
|
||||
- e = cm_select_or_poll(selstate, get_endtime(endtime, conns),
|
||||
- seltemp, &selret);
|
||||
+ endtime = get_endtime(interval_end, conns);
|
||||
+ /* Don't wait longer than the whole request should last. */
|
||||
+ if (timeout && endtime > timeout)
|
||||
+ endtime = timeout;
|
||||
+ e = cm_select_or_poll(selstate, endtime, seltemp, &selret);
|
||||
if (e == EINTR)
|
||||
continue;
|
||||
if (e != 0)
|
||||
break;
|
||||
|
||||
- if (selret == 0)
|
||||
- /* Timeout, return to caller. */
|
||||
+ if (selret == 0) {
|
||||
+ /* We timed out. Stop if we hit the overall request timeout. */
|
||||
+ if (timeout && (get_curtime_ms(&curtime) || curtime >= timeout))
|
||||
+ return TRUE;
|
||||
+ /* Otherwise return to the caller to send the next request. */
|
||||
return FALSE;
|
||||
+ }
|
||||
|
||||
/* Got something on a socket, process it. */
|
||||
for (state = conns; state != NULL; state = state->next) {
|
||||
@@ -1495,7 +1502,7 @@ k5_sendto(krb5_context context, const krb5_data *message,
|
||||
void *msg_handler_data)
|
||||
{
|
||||
int pass;
|
||||
- time_ms delay;
|
||||
+ time_ms delay, timeout = 0;
|
||||
krb5_error_code retval;
|
||||
struct conn_state *conns = NULL, *state, **tailptr, *next, *winner;
|
||||
size_t s;
|
||||
@@ -1505,6 +1512,13 @@ k5_sendto(krb5_context context, const krb5_data *message,
|
||||
|
||||
*reply = empty_data();
|
||||
|
||||
+ if (context->req_timeout) {
|
||||
+ retval = get_curtime_ms(&timeout);
|
||||
+ if (retval)
|
||||
+ return retval;
|
||||
+ timeout += 1000 * context->req_timeout;
|
||||
+ }
|
||||
+
|
||||
/* One for use here, listing all our fds in use, and one for
|
||||
* temporary use in service_fds, for the fds of interest. */
|
||||
sel_state = malloc(2 * sizeof(*sel_state));
|
||||
@@ -1532,8 +1546,9 @@ k5_sendto(krb5_context context, const krb5_data *message,
|
||||
if (maybe_send(context, state, message, sel_state, realm,
|
||||
callback_info))
|
||||
continue;
|
||||
- done = service_fds(context, sel_state, 1000, conns, seltemp,
|
||||
- realm, msg_handler, msg_handler_data, &winner);
|
||||
+ done = service_fds(context, sel_state, 1000, timeout, conns,
|
||||
+ seltemp, realm, msg_handler, msg_handler_data,
|
||||
+ &winner);
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1545,13 +1560,13 @@ k5_sendto(krb5_context context, const krb5_data *message,
|
||||
if (maybe_send(context, state, message, sel_state, realm,
|
||||
callback_info))
|
||||
continue;
|
||||
- done = service_fds(context, sel_state, 1000, conns, seltemp,
|
||||
+ done = service_fds(context, sel_state, 1000, timeout, conns, seltemp,
|
||||
realm, msg_handler, msg_handler_data, &winner);
|
||||
}
|
||||
|
||||
/* Wait for two seconds at the end of the first pass. */
|
||||
if (!done) {
|
||||
- done = service_fds(context, sel_state, 2000, conns, seltemp,
|
||||
+ done = service_fds(context, sel_state, 2000, timeout, conns, seltemp,
|
||||
realm, msg_handler, msg_handler_data, &winner);
|
||||
}
|
||||
|
||||
@@ -1562,15 +1577,17 @@ k5_sendto(krb5_context context, const krb5_data *message,
|
||||
if (maybe_send(context, state, message, sel_state, realm,
|
||||
callback_info))
|
||||
continue;
|
||||
- done = service_fds(context, sel_state, 1000, conns, seltemp,
|
||||
- realm, msg_handler, msg_handler_data, &winner);
|
||||
+ done = service_fds(context, sel_state, 1000, timeout, conns,
|
||||
+ seltemp, realm, msg_handler, msg_handler_data,
|
||||
+ &winner);
|
||||
if (sel_state->nfds == 0)
|
||||
break;
|
||||
}
|
||||
/* Wait for the delay backoff at the end of this pass. */
|
||||
if (!done) {
|
||||
- done = service_fds(context, sel_state, delay, conns, seltemp,
|
||||
- realm, msg_handler, msg_handler_data, &winner);
|
||||
+ done = service_fds(context, sel_state, delay, timeout, conns,
|
||||
+ seltemp, realm, msg_handler, msg_handler_data,
|
||||
+ &winner);
|
||||
}
|
||||
if (sel_state->nfds == 0)
|
||||
break;
|
||||
--
|
||||
2.46.0
|
||||
|
||||
|
|
@ -1,138 +0,0 @@
|
|||
From 1da153d97d7fb30a44fca35f9b71b8f4ed5385b9 Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Thu, 26 Oct 2023 16:26:42 -0400
|
||||
Subject: [PATCH] Wait indefinitely on KDC TCP connections
|
||||
|
||||
When making a KDC or password change request, wait indefinitely
|
||||
(limited only by request_timeout if set) once a KDC has accepted a TCP
|
||||
connection.
|
||||
|
||||
ticket: 9105 (new)
|
||||
(cherry picked from commit 6436a3808061da787a43c6810f5f0370cdfb6e36)
|
||||
---
|
||||
doc/admin/conf_files/krb5_conf.rst | 2 +-
|
||||
src/lib/krb5/os/sendto_kdc.c | 50 ++++++++++++++++--------------
|
||||
2 files changed, 27 insertions(+), 25 deletions(-)
|
||||
|
||||
diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst
|
||||
index 65fb592d98..b7284c47df 100644
|
||||
--- a/doc/admin/conf_files/krb5_conf.rst
|
||||
+++ b/doc/admin/conf_files/krb5_conf.rst
|
||||
@@ -357,7 +357,7 @@ The libdefaults section may contain any of the following relations:
|
||||
for initial ticket requests. The default value is 0.
|
||||
|
||||
**request_timeout**
|
||||
- (:ref:`duration` string.) Sets the maximum total time for KDC or
|
||||
+ (:ref:`duration` string.) Sets the maximum total time for KDC and
|
||||
password change requests. This timeout does not affect the
|
||||
intervals between requests, so setting a low timeout may result in
|
||||
fewer requests being attempted and/or some servers not being
|
||||
diff --git a/src/lib/krb5/os/sendto_kdc.c b/src/lib/krb5/os/sendto_kdc.c
|
||||
index 98247a1089..924f5b2d26 100644
|
||||
--- a/src/lib/krb5/os/sendto_kdc.c
|
||||
+++ b/src/lib/krb5/os/sendto_kdc.c
|
||||
@@ -134,7 +134,6 @@ struct conn_state {
|
||||
krb5_data callback_buffer;
|
||||
size_t server_index;
|
||||
struct conn_state *next;
|
||||
- time_ms endtime;
|
||||
krb5_boolean defer;
|
||||
struct {
|
||||
const char *uri_path;
|
||||
@@ -344,15 +343,19 @@ cm_select_or_poll(const struct select_state *in, time_ms endtime,
|
||||
struct select_state *out, int *sret)
|
||||
{
|
||||
#ifndef USE_POLL
|
||||
- struct timeval tv;
|
||||
+ struct timeval tv, *tvp;
|
||||
#endif
|
||||
krb5_error_code retval;
|
||||
time_ms curtime, interval;
|
||||
|
||||
- retval = get_curtime_ms(&curtime);
|
||||
- if (retval != 0)
|
||||
- return retval;
|
||||
- interval = (curtime < endtime) ? endtime - curtime : 0;
|
||||
+ if (endtime != 0) {
|
||||
+ retval = get_curtime_ms(&curtime);
|
||||
+ if (retval != 0)
|
||||
+ return retval;
|
||||
+ interval = (curtime < endtime) ? endtime - curtime : 0;
|
||||
+ } else {
|
||||
+ interval = -1;
|
||||
+ }
|
||||
|
||||
/* We don't need a separate copy of the selstate for poll, but use one for
|
||||
* consistency with how we use select. */
|
||||
@@ -361,9 +364,14 @@ cm_select_or_poll(const struct select_state *in, time_ms endtime,
|
||||
#ifdef USE_POLL
|
||||
*sret = poll(out->fds, out->nfds, interval);
|
||||
#else
|
||||
- tv.tv_sec = interval / 1000;
|
||||
- tv.tv_usec = interval % 1000 * 1000;
|
||||
- *sret = select(out->max, &out->rfds, &out->wfds, &out->xfds, &tv);
|
||||
+ if (interval != -1) {
|
||||
+ tv.tv_sec = interval / 1000;
|
||||
+ tv.tv_usec = interval % 1000 * 1000;
|
||||
+ tvp = &tv;
|
||||
+ } else {
|
||||
+ tvp = NULL;
|
||||
+ }
|
||||
+ *sret = select(out->max, &out->rfds, &out->wfds, &out->xfds, tvp);
|
||||
#endif
|
||||
|
||||
return (*sret < 0) ? SOCKET_ERRNO : 0;
|
||||
@@ -1099,11 +1107,6 @@ service_tcp_connect(krb5_context context, const krb5_data *realm,
|
||||
}
|
||||
|
||||
conn->state = WRITING;
|
||||
-
|
||||
- /* Record this connection's timeout for service_fds. */
|
||||
- if (get_curtime_ms(&conn->endtime) == 0)
|
||||
- conn->endtime += 10000;
|
||||
-
|
||||
return conn->service_write(context, realm, conn, selstate);
|
||||
}
|
||||
|
||||
@@ -1378,19 +1381,18 @@ kill_conn:
|
||||
return FALSE;
|
||||
}
|
||||
|
||||
-/* Return the maximum of endtime and the endtime fields of all currently active
|
||||
- * TCP connections. */
|
||||
-static time_ms
|
||||
-get_endtime(time_ms endtime, struct conn_state *conns)
|
||||
+/* Return true if conns contains any states with connected TCP sockets. */
|
||||
+static krb5_boolean
|
||||
+any_tcp_connections(struct conn_state *conns)
|
||||
{
|
||||
struct conn_state *state;
|
||||
|
||||
for (state = conns; state != NULL; state = state->next) {
|
||||
- if ((state->state == READING || state->state == WRITING) &&
|
||||
- state->endtime > endtime)
|
||||
- endtime = state->endtime;
|
||||
+ if (state->addr.transport != UDP &&
|
||||
+ (state->state == READING || state->state == WRITING))
|
||||
+ return TRUE;
|
||||
}
|
||||
- return endtime;
|
||||
+ return FALSE;
|
||||
}
|
||||
|
||||
static krb5_boolean
|
||||
@@ -1413,9 +1415,9 @@ service_fds(krb5_context context, struct select_state *selstate,
|
||||
|
||||
e = 0;
|
||||
while (selstate->nfds > 0) {
|
||||
- endtime = get_endtime(interval_end, conns);
|
||||
+ endtime = any_tcp_connections(conns) ? 0 : interval_end;
|
||||
/* Don't wait longer than the whole request should last. */
|
||||
- if (timeout && endtime > timeout)
|
||||
+ if (timeout && (!endtime || endtime > timeout))
|
||||
endtime = timeout;
|
||||
e = cm_select_or_poll(selstate, endtime, seltemp, &selret);
|
||||
if (e == EINTR)
|
||||
--
|
||||
2.46.0
|
||||
|
||||
File diff suppressed because it is too large
Load diff
|
|
@ -1,265 +0,0 @@
|
|||
From 3999883b9745bfd7065d41ff05b19e56bcb2e791 Mon Sep 17 00:00:00 2001
|
||||
From: Julien Rische <jrische@redhat.com>
|
||||
Date: Fri, 6 Sep 2024 17:18:11 +0200
|
||||
Subject: [PATCH] Fix various issues detected by static analysis
|
||||
|
||||
In klists's show_credential(), ensure that the column counter doesn't
|
||||
decrease if printf() fails.
|
||||
|
||||
In process_k5beta7_princ(), bounds-check the e_length field.
|
||||
|
||||
In ndr_enc_delegation_info(), initialize b so it is always valid for
|
||||
the cleanup handler.
|
||||
|
||||
In krb5_dbe_def_decrypt_key_data(), change the flow control so ret is
|
||||
always set by the end of the function. Return KRB5_KDB_INVALIDKEYSIZE
|
||||
if there isn't enough data in the first key_data_contents field or if
|
||||
the serialized key length is invalid.
|
||||
|
||||
In svcauth_gss_validate(), expand rpchdr to accomodate the header plus
|
||||
MAX_AUTH_BYTES.
|
||||
|
||||
In svcudp_reply(), change slen to unsigned to match the return type of
|
||||
XDR_GETPOS() and eliminate an unnecessary check for slen >= 0.
|
||||
|
||||
In krb5int_pthread_loaded()(), remove pthread_equal() from the weak
|
||||
symbol checks. It is implemented as an inline function in some glibc
|
||||
versions, which makes the comparison "&pthread_equal == 0" always
|
||||
false.
|
||||
|
||||
[ghudson@mit.edu: further modified krb5_dbe_def_decrypt_key_data() for
|
||||
clarity; added detail to commit message]
|
||||
|
||||
(cherry picked from commit a96541981ee34c8642ddeb6101b98e883e41c6e5)
|
||||
---
|
||||
src/clients/klist/klist.c | 12 ++++-----
|
||||
src/kadmin/dbutil/dump.c | 5 ++++
|
||||
src/kdc/ndr.c | 2 +-
|
||||
src/lib/kdb/decrypt_key.c | 54 ++++++++++++++++++++------------------
|
||||
src/lib/rpc/svc_auth_gss.c | 5 +++-
|
||||
src/lib/rpc/svc_udp.c | 13 ++++-----
|
||||
src/util/support/threads.c | 2 --
|
||||
7 files changed, 51 insertions(+), 42 deletions(-)
|
||||
|
||||
diff --git a/src/clients/klist/klist.c b/src/clients/klist/klist.c
|
||||
index b5808e5c93..ba9539fd23 100644
|
||||
--- a/src/clients/klist/klist.c
|
||||
+++ b/src/clients/klist/klist.c
|
||||
@@ -681,7 +681,7 @@ show_credential(krb5_creds *cred, const char *defname)
|
||||
krb5_error_code ret;
|
||||
krb5_ticket *tkt = NULL;
|
||||
char *name = NULL, *sname = NULL, *tktsname, *flags;
|
||||
- int extra_field = 0, ccol = 0, i;
|
||||
+ int extra_field = 0, ccol = 0, i, r;
|
||||
krb5_boolean is_config = krb5_is_config_principal(context, cred->server);
|
||||
|
||||
ret = krb5_unparse_name(context, cred->client, &name);
|
||||
@@ -711,11 +711,11 @@ show_credential(krb5_creds *cred, const char *defname)
|
||||
fputs("config: ", stdout);
|
||||
ccol = 8;
|
||||
for (i = 1; i < cred->server->length; i++) {
|
||||
- ccol += printf("%s%.*s%s",
|
||||
- i > 1 ? "(" : "",
|
||||
- (int)cred->server->data[i].length,
|
||||
- cred->server->data[i].data,
|
||||
- i > 1 ? ")" : "");
|
||||
+ r = printf("%s%.*s%s", i > 1 ? "(" : "",
|
||||
+ (int)cred->server->data[i].length,
|
||||
+ cred->server->data[i].data, i > 1 ? ")" : "");
|
||||
+ if (r >= 0)
|
||||
+ ccol += r;
|
||||
}
|
||||
fputs(" = ", stdout);
|
||||
ccol += 3;
|
||||
diff --git a/src/kadmin/dbutil/dump.c b/src/kadmin/dbutil/dump.c
|
||||
index 4d6cc0bdf9..feb053d834 100644
|
||||
--- a/src/kadmin/dbutil/dump.c
|
||||
+++ b/src/kadmin/dbutil/dump.c
|
||||
@@ -704,6 +704,11 @@ process_k5beta7_princ(krb5_context context, const char *fname, FILE *filep,
|
||||
|
||||
dbentry->len = u1;
|
||||
dbentry->n_key_data = u4;
|
||||
+
|
||||
+ if (u5 > UINT16_MAX) {
|
||||
+ load_err(fname, *linenop, _("invalid principal extra data size"));
|
||||
+ goto fail;
|
||||
+ }
|
||||
dbentry->e_length = u5;
|
||||
|
||||
if (kp != NULL) {
|
||||
diff --git a/src/kdc/ndr.c b/src/kdc/ndr.c
|
||||
index d438408ee2..38be9fe42a 100644
|
||||
--- a/src/kdc/ndr.c
|
||||
+++ b/src/kdc/ndr.c
|
||||
@@ -242,7 +242,7 @@ ndr_enc_delegation_info(struct pac_s4u_delegation_info *in, krb5_data *out)
|
||||
{
|
||||
krb5_error_code ret;
|
||||
size_t i;
|
||||
- struct k5buf b;
|
||||
+ struct k5buf b = EMPTY_K5BUF;
|
||||
struct encoded_wchars pt_encoded = { 0 }, *tss_encoded = NULL;
|
||||
uint32_t pointer = 0;
|
||||
|
||||
diff --git a/src/lib/kdb/decrypt_key.c b/src/lib/kdb/decrypt_key.c
|
||||
index 82bbed6312..21aa3742b1 100644
|
||||
--- a/src/lib/kdb/decrypt_key.c
|
||||
+++ b/src/lib/kdb/decrypt_key.c
|
||||
@@ -60,7 +60,7 @@ krb5_dbe_def_decrypt_key_data(krb5_context context, const krb5_keyblock *mkey,
|
||||
krb5_keyblock *dbkey_out,
|
||||
krb5_keysalt *keysalt_out)
|
||||
{
|
||||
- krb5_error_code ret;
|
||||
+ krb5_error_code ret = KRB5_CRYPTO_INTERNAL;
|
||||
int16_t keylen;
|
||||
krb5_enc_data cipher;
|
||||
krb5_data plain = empty_data();
|
||||
@@ -74,36 +74,38 @@ krb5_dbe_def_decrypt_key_data(krb5_context context, const krb5_keyblock *mkey,
|
||||
if (mkey == NULL)
|
||||
return KRB5_KDB_BADSTORED_MKEY;
|
||||
|
||||
- if (kd->key_data_contents[0] != NULL && kd->key_data_length[0] >= 2) {
|
||||
- keylen = load_16_le(kd->key_data_contents[0]);
|
||||
- if (keylen < 0)
|
||||
- return EINVAL;
|
||||
- cipher.enctype = ENCTYPE_UNKNOWN;
|
||||
- cipher.ciphertext = make_data(kd->key_data_contents[0] + 2,
|
||||
- kd->key_data_length[0] - 2);
|
||||
- ret = alloc_data(&plain, kd->key_data_length[0] - 2);
|
||||
- if (ret)
|
||||
- goto cleanup;
|
||||
+ if (kd->key_data_contents[0] == NULL || kd->key_data_length[0] < 2)
|
||||
+ return KRB5_KDB_INVALIDKEYSIZE;
|
||||
|
||||
- ret = krb5_c_decrypt(context, mkey, 0, 0, &cipher, &plain);
|
||||
- if (ret)
|
||||
- goto cleanup;
|
||||
+ keylen = load_16_le(kd->key_data_contents[0]);
|
||||
+ if (keylen < 0)
|
||||
+ return KRB5_KDB_INVALIDKEYSIZE;
|
||||
|
||||
- /* Make sure the plaintext has at least as many bytes as the true ke
|
||||
- * length (it may have more due to padding). */
|
||||
- if ((unsigned int)keylen > plain.length) {
|
||||
- ret = KRB5_CRYPTO_INTERNAL;
|
||||
- if (ret)
|
||||
- goto cleanup;
|
||||
- }
|
||||
+ cipher.enctype = ENCTYPE_UNKNOWN;
|
||||
+ cipher.ciphertext = make_data(kd->key_data_contents[0] + 2,
|
||||
+ kd->key_data_length[0] - 2);
|
||||
+ ret = alloc_data(&plain, kd->key_data_length[0] - 2);
|
||||
+ if (ret)
|
||||
+ goto cleanup;
|
||||
|
||||
- kb.magic = KV5M_KEYBLOCK;
|
||||
- kb.enctype = kd->key_data_type[0];
|
||||
- kb.length = keylen;
|
||||
- kb.contents = (uint8_t *)plain.data;
|
||||
- plain = empty_data();
|
||||
+ ret = krb5_c_decrypt(context, mkey, 0, 0, &cipher, &plain);
|
||||
+ if (ret)
|
||||
+ goto cleanup;
|
||||
+
|
||||
+ /* Make sure the plaintext has at least as many bytes as the true key
|
||||
+ * length (it may have more due to padding). */
|
||||
+ if ((unsigned int)keylen > plain.length) {
|
||||
+ ret = KRB5_CRYPTO_INTERNAL;
|
||||
+ if (ret)
|
||||
+ goto cleanup;
|
||||
}
|
||||
|
||||
+ kb.magic = KV5M_KEYBLOCK;
|
||||
+ kb.enctype = kd->key_data_type[0];
|
||||
+ kb.length = keylen;
|
||||
+ kb.contents = (uint8_t *)plain.data;
|
||||
+ plain = empty_data();
|
||||
+
|
||||
/* Decode salt data. */
|
||||
if (keysalt_out != NULL) {
|
||||
if (kd->key_data_ver == 2) {
|
||||
diff --git a/src/lib/rpc/svc_auth_gss.c b/src/lib/rpc/svc_auth_gss.c
|
||||
index 98d601c8ab..4f1d2911b0 100644
|
||||
--- a/src/lib/rpc/svc_auth_gss.c
|
||||
+++ b/src/lib/rpc/svc_auth_gss.c
|
||||
@@ -297,7 +297,7 @@ svcauth_gss_validate(struct svc_req *rqst, struct svc_rpc_gss_data *gd, struct r
|
||||
struct opaque_auth *oa;
|
||||
gss_buffer_desc rpcbuf, checksum;
|
||||
OM_uint32 maj_stat, min_stat, qop_state;
|
||||
- u_char rpchdr[128];
|
||||
+ u_char rpchdr[32 + MAX_AUTH_BYTES];
|
||||
int32_t *buf;
|
||||
|
||||
log_debug("in svcauth_gss_validate()");
|
||||
@@ -315,6 +315,8 @@ svcauth_gss_validate(struct svc_req *rqst, struct svc_rpc_gss_data *gd, struct r
|
||||
return (FALSE);
|
||||
|
||||
buf = (int32_t *)(void *)rpchdr;
|
||||
+
|
||||
+ /* Write the 32 first bytes of the header. */
|
||||
IXDR_PUT_LONG(buf, msg->rm_xid);
|
||||
IXDR_PUT_ENUM(buf, msg->rm_direction);
|
||||
IXDR_PUT_LONG(buf, msg->rm_call.cb_rpcvers);
|
||||
@@ -323,6 +325,7 @@ svcauth_gss_validate(struct svc_req *rqst, struct svc_rpc_gss_data *gd, struct r
|
||||
IXDR_PUT_LONG(buf, msg->rm_call.cb_proc);
|
||||
IXDR_PUT_ENUM(buf, oa->oa_flavor);
|
||||
IXDR_PUT_LONG(buf, oa->oa_length);
|
||||
+
|
||||
if (oa->oa_length) {
|
||||
memcpy((caddr_t)buf, oa->oa_base, oa->oa_length);
|
||||
buf += RNDUP(oa->oa_length) / sizeof(int32_t);
|
||||
diff --git a/src/lib/rpc/svc_udp.c b/src/lib/rpc/svc_udp.c
|
||||
index 8ecbdf2b33..3aff277eb7 100644
|
||||
--- a/src/lib/rpc/svc_udp.c
|
||||
+++ b/src/lib/rpc/svc_udp.c
|
||||
@@ -248,8 +248,9 @@ static bool_t svcudp_reply(
|
||||
{
|
||||
struct svcudp_data *su = su_data(xprt);
|
||||
XDR *xdrs = &su->su_xdrs;
|
||||
- int slen;
|
||||
+ u_int slen;
|
||||
bool_t stat = FALSE;
|
||||
+ ssize_t r;
|
||||
|
||||
xdrproc_t xdr_results = NULL;
|
||||
caddr_t xdr_location = 0;
|
||||
@@ -272,12 +273,12 @@ static bool_t svcudp_reply(
|
||||
if (xdr_replymsg(xdrs, msg) &&
|
||||
(!has_args ||
|
||||
(SVCAUTH_WRAP(xprt->xp_auth, xdrs, xdr_results, xdr_location)))) {
|
||||
- slen = (int)XDR_GETPOS(xdrs);
|
||||
- if (sendto(xprt->xp_sock, rpc_buffer(xprt), slen, 0,
|
||||
- (struct sockaddr *)&(xprt->xp_raddr), xprt->xp_addrlen)
|
||||
- == slen) {
|
||||
+ slen = XDR_GETPOS(xdrs);
|
||||
+ r = sendto(xprt->xp_sock, rpc_buffer(xprt), slen, 0,
|
||||
+ (struct sockaddr *)&(xprt->xp_raddr), xprt->xp_addrlen);
|
||||
+ if (r >= 0 && (u_int)r == slen) {
|
||||
stat = TRUE;
|
||||
- if (su->su_cache && slen >= 0) {
|
||||
+ if (su->su_cache) {
|
||||
cache_set(xprt, (uint32_t) slen);
|
||||
}
|
||||
}
|
||||
diff --git a/src/util/support/threads.c b/src/util/support/threads.c
|
||||
index be7e4c2e3f..4ded805b79 100644
|
||||
--- a/src/util/support/threads.c
|
||||
+++ b/src/util/support/threads.c
|
||||
@@ -118,7 +118,6 @@ struct tsd_block {
|
||||
# pragma weak pthread_mutex_destroy
|
||||
# pragma weak pthread_mutex_init
|
||||
# pragma weak pthread_self
|
||||
-# pragma weak pthread_equal
|
||||
# pragma weak pthread_getspecific
|
||||
# pragma weak pthread_setspecific
|
||||
# pragma weak pthread_key_create
|
||||
@@ -151,7 +150,6 @@ int krb5int_pthread_loaded (void)
|
||||
|| &pthread_mutex_destroy == 0
|
||||
|| &pthread_mutex_init == 0
|
||||
|| &pthread_self == 0
|
||||
- || &pthread_equal == 0
|
||||
/* Any program that's really multithreaded will have to be
|
||||
able to create threads. */
|
||||
|| &pthread_create == 0
|
||||
--
|
||||
2.46.0
|
||||
|
||||
|
|
@ -1,629 +0,0 @@
|
|||
From ea02fd7bb79861b8e36517c7c95af821a16657c4 Mon Sep 17 00:00:00 2001
|
||||
From: Julien Rische <jrische@redhat.com>
|
||||
Date: Thu, 22 Aug 2024 17:15:50 +0200
|
||||
Subject: [PATCH] Generate and verify message MACs in libkrad
|
||||
|
||||
Implement some of the measures specified in
|
||||
draft-ietf-radext-deprecating-radius-03 for mitigating the BlastRADIUS
|
||||
attack (CVE-2024-3596):
|
||||
|
||||
* Include a Message-Authenticator MAC as the first attribute when
|
||||
generating a packet of type Access-Request, Access-Reject,
|
||||
Access-Accept, or Access-Challenge (sections 5.2.1 and 5.2.4), if
|
||||
the secret is non-empty. (An empty secret indicates the use of Unix
|
||||
domain socket transport.)
|
||||
|
||||
* Validate the Message-Authenticator MAC in received packets, if
|
||||
present.
|
||||
|
||||
FreeRADIUS enforces Message-Authenticator as of versions 3.2.5 and
|
||||
3.0.27. libkrad must generate Message-Authenticator attributes in
|
||||
order to remain compatible with these implementations.
|
||||
|
||||
[ghudson@mit.edu: adjusted style and naming; simplified some
|
||||
functions; edited commit message]
|
||||
|
||||
ticket: 9142 (new)
|
||||
tags: pullup
|
||||
target_version: 1.21-next
|
||||
|
||||
(cherry picked from commit 871125fea8ce0370a972bf65f7d1de63f619b06c)
|
||||
---
|
||||
src/include/k5-int.h | 5 +
|
||||
src/lib/crypto/krb/checksum_hmac_md5.c | 28 ++++
|
||||
src/lib/crypto/libk5crypto.exports | 1 +
|
||||
src/lib/krad/attr.c | 17 ++
|
||||
src/lib/krad/attrset.c | 59 +++++--
|
||||
src/lib/krad/internal.h | 7 +-
|
||||
src/lib/krad/packet.c | 206 +++++++++++++++++++++++--
|
||||
src/lib/krad/t_attrset.c | 2 +-
|
||||
src/lib/krad/t_daemon.py | 3 +-
|
||||
src/lib/krad/t_packet.c | 11 ++
|
||||
src/tests/t_otp.py | 3 +
|
||||
11 files changed, 311 insertions(+), 31 deletions(-)
|
||||
|
||||
diff --git a/src/include/k5-int.h b/src/include/k5-int.h
|
||||
index 69d6a6f569..b7789a2dd8 100644
|
||||
--- a/src/include/k5-int.h
|
||||
+++ b/src/include/k5-int.h
|
||||
@@ -2403,4 +2403,9 @@ krb5_boolean
|
||||
k5_sname_compare(krb5_context context, krb5_const_principal sname,
|
||||
krb5_const_principal princ);
|
||||
|
||||
+/* Generate an HMAC-MD5 keyed checksum as specified by RFC 2104. */
|
||||
+krb5_error_code
|
||||
+k5_hmac_md5(const krb5_data *key, const krb5_crypto_iov *data, size_t num_data,
|
||||
+ krb5_data *output);
|
||||
+
|
||||
#endif /* _KRB5_INT_H */
|
||||
diff --git a/src/lib/crypto/krb/checksum_hmac_md5.c b/src/lib/crypto/krb/checksum_hmac_md5.c
|
||||
index ec024f3966..a809388549 100644
|
||||
--- a/src/lib/crypto/krb/checksum_hmac_md5.c
|
||||
+++ b/src/lib/crypto/krb/checksum_hmac_md5.c
|
||||
@@ -92,3 +92,31 @@ cleanup:
|
||||
free(hash_iov);
|
||||
return ret;
|
||||
}
|
||||
+
|
||||
+krb5_error_code
|
||||
+k5_hmac_md5(const krb5_data *key, const krb5_crypto_iov *data, size_t num_data,
|
||||
+ krb5_data *output)
|
||||
+{
|
||||
+ krb5_error_code ret;
|
||||
+ const struct krb5_hash_provider *hash = &krb5int_hash_md5;
|
||||
+ krb5_keyblock keyblock = { 0 };
|
||||
+ krb5_data hashed_key;
|
||||
+ uint8_t hkeybuf[16];
|
||||
+ krb5_crypto_iov iov;
|
||||
+
|
||||
+ /* Hash the key if it is longer than the block size. */
|
||||
+ if (key->length > hash->blocksize) {
|
||||
+ hashed_key = make_data(hkeybuf, sizeof(hkeybuf));
|
||||
+ iov.flags = KRB5_CRYPTO_TYPE_DATA;
|
||||
+ iov.data = *key;
|
||||
+ ret = hash->hash(&iov, 1, &hashed_key);
|
||||
+ if (ret)
|
||||
+ return ret;
|
||||
+ key = &hashed_key;
|
||||
+ }
|
||||
+
|
||||
+ keyblock.magic = KV5M_KEYBLOCK;
|
||||
+ keyblock.length = key->length;
|
||||
+ keyblock.contents = (uint8_t *)key->data;
|
||||
+ return krb5int_hmac_keyblock(hash, &keyblock, data, num_data, output);
|
||||
+}
|
||||
diff --git a/src/lib/crypto/libk5crypto.exports b/src/lib/crypto/libk5crypto.exports
|
||||
index d8ffa63304..00e0ce1812 100644
|
||||
--- a/src/lib/crypto/libk5crypto.exports
|
||||
+++ b/src/lib/crypto/libk5crypto.exports
|
||||
@@ -102,3 +102,4 @@ krb5_c_prfplus
|
||||
krb5_c_derive_prfplus
|
||||
k5_enctype_to_ssf
|
||||
krb5int_c_deprecated_enctype
|
||||
+k5_hmac_md5
|
||||
diff --git a/src/lib/krad/attr.c b/src/lib/krad/attr.c
|
||||
index 42d354a3b5..65ed1d35e7 100644
|
||||
--- a/src/lib/krad/attr.c
|
||||
+++ b/src/lib/krad/attr.c
|
||||
@@ -125,6 +125,23 @@ static const attribute_record attributes[UCHAR_MAX] = {
|
||||
{"NAS-Port-Type", 4, 4, NULL, NULL},
|
||||
{"Port-Limit", 4, 4, NULL, NULL},
|
||||
{"Login-LAT-Port", 1, MAX_ATTRSIZE, NULL, NULL},
|
||||
+ {NULL, 0, 0, NULL, NULL}, /* Reserved for tunnelling */
|
||||
+ {NULL, 0, 0, NULL, NULL}, /* Reserved for tunnelling */
|
||||
+ {NULL, 0, 0, NULL, NULL}, /* Reserved for tunnelling */
|
||||
+ {NULL, 0, 0, NULL, NULL}, /* Reserved for tunnelling */
|
||||
+ {NULL, 0, 0, NULL, NULL}, /* Reserved for tunnelling */
|
||||
+ {NULL, 0, 0, NULL, NULL}, /* Reserved for tunnelling */
|
||||
+ {NULL, 0, 0, NULL, NULL}, /* Reserved for Apple Remote Access Protocol */
|
||||
+ {NULL, 0, 0, NULL, NULL}, /* Reserved for Apple Remote Access Protocol */
|
||||
+ {NULL, 0, 0, NULL, NULL}, /* Reserved for Apple Remote Access Protocol */
|
||||
+ {NULL, 0, 0, NULL, NULL}, /* Reserved for Apple Remote Access Protocol */
|
||||
+ {NULL, 0, 0, NULL, NULL}, /* Reserved for Apple Remote Access Protocol */
|
||||
+ {NULL, 0, 0, NULL, NULL}, /* Password-Retry */
|
||||
+ {NULL, 0, 0, NULL, NULL}, /* Prompt */
|
||||
+ {NULL, 0, 0, NULL, NULL}, /* Connect-Info */
|
||||
+ {NULL, 0, 0, NULL, NULL}, /* Configuration-Token */
|
||||
+ {NULL, 0, 0, NULL, NULL}, /* EAP-Message */
|
||||
+ {"Message-Authenticator", MD5_DIGEST_SIZE, MD5_DIGEST_SIZE, NULL, NULL},
|
||||
};
|
||||
|
||||
/* Encode User-Password attribute. */
|
||||
diff --git a/src/lib/krad/attrset.c b/src/lib/krad/attrset.c
|
||||
index 6ec031e320..e5457ebfd7 100644
|
||||
--- a/src/lib/krad/attrset.c
|
||||
+++ b/src/lib/krad/attrset.c
|
||||
@@ -164,15 +164,44 @@ krad_attrset_copy(const krad_attrset *set, krad_attrset **copy)
|
||||
return 0;
|
||||
}
|
||||
|
||||
+/* Place an encoded attributes into outbuf at position *i. Increment *i by the
|
||||
+ * length of the encoding. */
|
||||
+static krb5_error_code
|
||||
+append_attr(krb5_context ctx, const char *secret,
|
||||
+ const uint8_t *auth, krad_attr type, const krb5_data *data,
|
||||
+ uint8_t outbuf[MAX_ATTRSETSIZE], size_t *i, krb5_boolean *is_fips)
|
||||
+{
|
||||
+ uint8_t buffer[MAX_ATTRSIZE];
|
||||
+ size_t attrlen;
|
||||
+ krb5_error_code retval;
|
||||
+
|
||||
+ retval = kr_attr_encode(ctx, secret, auth, type, data, buffer, &attrlen,
|
||||
+ is_fips);
|
||||
+ if (retval)
|
||||
+ return retval;
|
||||
+
|
||||
+ if (attrlen > MAX_ATTRSETSIZE - *i - 2)
|
||||
+ return EMSGSIZE;
|
||||
+
|
||||
+ outbuf[(*i)++] = type;
|
||||
+ outbuf[(*i)++] = attrlen + 2;
|
||||
+ memcpy(outbuf + *i, buffer, attrlen);
|
||||
+ *i += attrlen;
|
||||
+
|
||||
+ return 0;
|
||||
+}
|
||||
+
|
||||
krb5_error_code
|
||||
kr_attrset_encode(const krad_attrset *set, const char *secret,
|
||||
- const unsigned char *auth,
|
||||
+ const uint8_t *auth, krb5_boolean add_msgauth,
|
||||
unsigned char outbuf[MAX_ATTRSETSIZE], size_t *outlen,
|
||||
krb5_boolean *is_fips)
|
||||
{
|
||||
- unsigned char buffer[MAX_ATTRSIZE];
|
||||
krb5_error_code retval;
|
||||
- size_t i = 0, attrlen;
|
||||
+ krad_attr msgauth_type = krad_attr_name2num("Message-Authenticator");
|
||||
+ const uint8_t zeroes[MD5_DIGEST_SIZE] = { 0 };
|
||||
+ krb5_data zerodata;
|
||||
+ size_t i = 0;
|
||||
attr *a;
|
||||
|
||||
if (set == NULL) {
|
||||
@@ -180,19 +209,21 @@ kr_attrset_encode(const krad_attrset *set, const char *secret,
|
||||
return 0;
|
||||
}
|
||||
|
||||
- K5_TAILQ_FOREACH(a, &set->list, list) {
|
||||
- retval = kr_attr_encode(set->ctx, secret, auth, a->type, &a->attr,
|
||||
- buffer, &attrlen, is_fips);
|
||||
- if (retval != 0)
|
||||
+ if (add_msgauth) {
|
||||
+ /* Encode Message-Authenticator as the first attribute, per
|
||||
+ * draft-ietf-radext-deprecating-radius-03 section 5.2. */
|
||||
+ zerodata = make_data((uint8_t *)zeroes, MD5_DIGEST_SIZE);
|
||||
+ retval = append_attr(set->ctx, secret, auth, msgauth_type, &zerodata,
|
||||
+ outbuf, &i, is_fips);
|
||||
+ if (retval)
|
||||
return retval;
|
||||
+ }
|
||||
|
||||
- if (i + attrlen + 2 > MAX_ATTRSETSIZE)
|
||||
- return EMSGSIZE;
|
||||
-
|
||||
- outbuf[i++] = a->type;
|
||||
- outbuf[i++] = attrlen + 2;
|
||||
- memcpy(&outbuf[i], buffer, attrlen);
|
||||
- i += attrlen;
|
||||
+ K5_TAILQ_FOREACH(a, &set->list, list) {
|
||||
+ retval = append_attr(set->ctx, secret, auth, a->type, &a->attr,
|
||||
+ outbuf, &i, is_fips);
|
||||
+ if (retval)
|
||||
+ return retval;
|
||||
}
|
||||
|
||||
*outlen = i;
|
||||
diff --git a/src/lib/krad/internal.h b/src/lib/krad/internal.h
|
||||
index a17b6f39b1..ca66f3ec68 100644
|
||||
--- a/src/lib/krad/internal.h
|
||||
+++ b/src/lib/krad/internal.h
|
||||
@@ -49,6 +49,8 @@
|
||||
#define UCHAR_MAX 255
|
||||
#endif
|
||||
|
||||
+#define MD5_DIGEST_SIZE 16
|
||||
+
|
||||
/* RFC 2865 */
|
||||
#define MAX_ATTRSIZE (UCHAR_MAX - 2)
|
||||
#define MAX_ATTRSETSIZE (KRAD_PACKET_SIZE_MAX - 20)
|
||||
@@ -79,10 +81,11 @@ kr_attr_decode(krb5_context ctx, const char *secret, const unsigned char *auth,
|
||||
krad_attr type, const krb5_data *in,
|
||||
unsigned char outbuf[MAX_ATTRSIZE], size_t *outlen);
|
||||
|
||||
-/* Encode the attributes into the buffer. */
|
||||
+/* Encode set into outbuf. If add_msgauth is true, include a zeroed
|
||||
+ * Message-Authenticator as the first attribute. */
|
||||
krb5_error_code
|
||||
kr_attrset_encode(const krad_attrset *set, const char *secret,
|
||||
- const unsigned char *auth,
|
||||
+ const uint8_t *auth, krb5_boolean add_msgauth,
|
||||
unsigned char outbuf[MAX_ATTRSETSIZE], size_t *outlen,
|
||||
krb5_boolean *is_fips);
|
||||
|
||||
diff --git a/src/lib/krad/packet.c b/src/lib/krad/packet.c
|
||||
index c5446b890c..3c1a4d507e 100644
|
||||
--- a/src/lib/krad/packet.c
|
||||
+++ b/src/lib/krad/packet.c
|
||||
@@ -36,6 +36,7 @@
|
||||
typedef unsigned char uchar;
|
||||
|
||||
/* RFC 2865 */
|
||||
+#define MSGAUTH_SIZE (2 + MD5_DIGEST_SIZE)
|
||||
#define OFFSET_CODE 0
|
||||
#define OFFSET_ID 1
|
||||
#define OFFSET_LENGTH 2
|
||||
@@ -222,6 +223,106 @@ packet_set_attrset(krb5_context ctx, const char *secret, krad_packet *pkt)
|
||||
return kr_attrset_decode(ctx, &tmp, secret, pkt_auth(pkt), &pkt->attrset);
|
||||
}
|
||||
|
||||
+/* Determine if a packet requires a Message-Authenticator attribute. */
|
||||
+static inline krb5_boolean
|
||||
+requires_msgauth(const char *secret, krad_code code)
|
||||
+{
|
||||
+ /* If no secret is provided, assume that the transport is a UNIX socket.
|
||||
+ * Message-Authenticator is required only on UDP and TCP connections. */
|
||||
+ if (*secret == '\0')
|
||||
+ return FALSE;
|
||||
+
|
||||
+ /*
|
||||
+ * Per draft-ietf-radext-deprecating-radius-03 sections 5.2.1 and 5.2.4,
|
||||
+ * Message-Authenticator is required in Access-Request packets and all
|
||||
+ * potential responses when UDP or TCP transport is used.
|
||||
+ */
|
||||
+ return code == krad_code_name2num("Access-Request") ||
|
||||
+ code == krad_code_name2num("Access-Reject") ||
|
||||
+ code == krad_code_name2num("Access-Accept") ||
|
||||
+ code == krad_code_name2num("Access-Challenge");
|
||||
+}
|
||||
+
|
||||
+/* Check if the packet has a Message-Authenticator attribute. */
|
||||
+static inline krb5_boolean
|
||||
+has_pkt_msgauth(const krad_packet *pkt)
|
||||
+{
|
||||
+ krad_attr msgauth_type = krad_attr_name2num("Message-Authenticator");
|
||||
+
|
||||
+ return krad_attrset_get(pkt->attrset, msgauth_type, 0) != NULL;
|
||||
+}
|
||||
+
|
||||
+/* Return the beginning of the Message-Authenticator attribute in pkt, or NULL
|
||||
+ * if no such attribute is present. */
|
||||
+static const uint8_t *
|
||||
+lookup_msgauth_addr(const krad_packet *pkt)
|
||||
+{
|
||||
+ krad_attr msgauth_type = krad_attr_name2num("Message-Authenticator");
|
||||
+ size_t i;
|
||||
+ uint8_t *p;
|
||||
+
|
||||
+ i = OFFSET_ATTR;
|
||||
+ while (i + 2 < pkt->pkt.length) {
|
||||
+ p = (uint8_t *)offset(&pkt->pkt, i);
|
||||
+ if (msgauth_type == *p)
|
||||
+ return p;
|
||||
+ i += p[1];
|
||||
+ }
|
||||
+
|
||||
+ return NULL;
|
||||
+}
|
||||
+
|
||||
+/*
|
||||
+ * Calculate the message authenticator MAC for pkt as specified in RFC 2869
|
||||
+ * section 5.14, placing the result in mac_out. Use the provided authenticator
|
||||
+ * auth, which may be from pkt or from a corresponding request.
|
||||
+ */
|
||||
+static krb5_error_code
|
||||
+calculate_mac(const char *secret, const krad_packet *pkt,
|
||||
+ const uint8_t auth[AUTH_FIELD_SIZE],
|
||||
+ uint8_t mac_out[MD5_DIGEST_SIZE])
|
||||
+{
|
||||
+ uint8_t zeroed_msgauth[MSGAUTH_SIZE];
|
||||
+ krad_attr msgauth_type = krad_attr_name2num("Message-Authenticator");
|
||||
+ const uint8_t *msgauth_attr, *msgauth_end, *pkt_end;
|
||||
+ krb5_crypto_iov input[5];
|
||||
+ krb5_data ksecr, mac;
|
||||
+
|
||||
+ msgauth_attr = lookup_msgauth_addr(pkt);
|
||||
+ if (msgauth_attr == NULL)
|
||||
+ return EINVAL;
|
||||
+ msgauth_end = msgauth_attr + MSGAUTH_SIZE;
|
||||
+ pkt_end = (const uint8_t *)pkt->pkt.data + pkt->pkt.length;
|
||||
+
|
||||
+ /* Read code, id, and length from the packet. */
|
||||
+ input[0].flags = KRB5_CRYPTO_TYPE_DATA;
|
||||
+ input[0].data = make_data(pkt->pkt.data, OFFSET_AUTH);
|
||||
+
|
||||
+ /* Read the provided authenticator. */
|
||||
+ input[1].flags = KRB5_CRYPTO_TYPE_DATA;
|
||||
+ input[1].data = make_data((uint8_t *)auth, AUTH_FIELD_SIZE);
|
||||
+
|
||||
+ /* Read any attributes before Message-Authenticator. */
|
||||
+ input[2].flags = KRB5_CRYPTO_TYPE_DATA;
|
||||
+ input[2].data = make_data(pkt_attr(pkt), msgauth_attr - pkt_attr(pkt));
|
||||
+
|
||||
+ /* Read Message-Authenticator with the data bytes all set to zero, per RFC
|
||||
+ * 2869 section 5.14. */
|
||||
+ zeroed_msgauth[0] = msgauth_type;
|
||||
+ zeroed_msgauth[1] = MSGAUTH_SIZE;
|
||||
+ memset(zeroed_msgauth + 2, 0, MD5_DIGEST_SIZE);
|
||||
+ input[3].flags = KRB5_CRYPTO_TYPE_DATA;
|
||||
+ input[3].data = make_data(zeroed_msgauth, MSGAUTH_SIZE);
|
||||
+
|
||||
+ /* Read any attributes after Message-Authenticator. */
|
||||
+ input[4].flags = KRB5_CRYPTO_TYPE_DATA;
|
||||
+ input[4].data = make_data((uint8_t *)msgauth_end, pkt_end - msgauth_end);
|
||||
+
|
||||
+ mac = make_data(mac_out, MD5_DIGEST_SIZE);
|
||||
+ ksecr = string2data((char *)secret);
|
||||
+ return k5_hmac_md5(&ksecr, input, 5, &mac);
|
||||
+}
|
||||
+
|
||||
ssize_t
|
||||
krad_packet_bytes_needed(const krb5_data *buffer)
|
||||
{
|
||||
@@ -255,6 +356,7 @@ krad_packet_new_request(krb5_context ctx, const char *secret, krad_code code,
|
||||
krad_packet *pkt;
|
||||
uchar id;
|
||||
size_t attrset_len;
|
||||
+ krb5_boolean msgauth_required;
|
||||
|
||||
pkt = packet_new();
|
||||
if (pkt == NULL) {
|
||||
@@ -274,9 +376,13 @@ krad_packet_new_request(krb5_context ctx, const char *secret, krad_code code,
|
||||
if (retval != 0)
|
||||
goto error;
|
||||
|
||||
+ /* Determine if Message-Authenticator is required. */
|
||||
+ msgauth_required = (*secret != '\0' &&
|
||||
+ code == krad_code_name2num("Access-Request"));
|
||||
+
|
||||
/* Encode the attributes. */
|
||||
- retval = kr_attrset_encode(set, secret, pkt_auth(pkt), pkt_attr(pkt),
|
||||
- &attrset_len, &pkt->is_fips);
|
||||
+ retval = kr_attrset_encode(set, secret, pkt_auth(pkt), msgauth_required,
|
||||
+ pkt_attr(pkt), &attrset_len, &pkt->is_fips);
|
||||
if (retval != 0)
|
||||
goto error;
|
||||
|
||||
@@ -285,6 +391,13 @@ krad_packet_new_request(krb5_context ctx, const char *secret, krad_code code,
|
||||
pkt_code_set(pkt, code);
|
||||
pkt_len_set(pkt, pkt->pkt.length);
|
||||
|
||||
+ if (msgauth_required) {
|
||||
+ /* Calculate and set the Message-Authenticator MAC. */
|
||||
+ retval = calculate_mac(secret, pkt, pkt_auth(pkt), pkt_attr(pkt) + 2);
|
||||
+ if (retval != 0)
|
||||
+ goto error;
|
||||
+ }
|
||||
+
|
||||
/* Copy the attrset for future use. */
|
||||
retval = packet_set_attrset(ctx, secret, pkt);
|
||||
if (retval != 0)
|
||||
@@ -307,14 +420,19 @@ krad_packet_new_response(krb5_context ctx, const char *secret, krad_code code,
|
||||
krb5_error_code retval;
|
||||
krad_packet *pkt;
|
||||
size_t attrset_len;
|
||||
+ krb5_boolean msgauth_required;
|
||||
|
||||
pkt = packet_new();
|
||||
if (pkt == NULL)
|
||||
return ENOMEM;
|
||||
|
||||
+ /* Determine if Message-Authenticator is required. */
|
||||
+ msgauth_required = requires_msgauth(secret, code);
|
||||
+
|
||||
/* Encode the attributes. */
|
||||
- retval = kr_attrset_encode(set, secret, pkt_auth(request), pkt_attr(pkt),
|
||||
- &attrset_len, &pkt->is_fips);
|
||||
+ retval = kr_attrset_encode(set, secret, pkt_auth(request),
|
||||
+ msgauth_required, pkt_attr(pkt), &attrset_len,
|
||||
+ &pkt->is_fips);
|
||||
if (retval != 0)
|
||||
goto error;
|
||||
|
||||
@@ -330,6 +448,18 @@ krad_packet_new_response(krb5_context ctx, const char *secret, krad_code code,
|
||||
if (retval != 0)
|
||||
goto error;
|
||||
|
||||
+ if (msgauth_required) {
|
||||
+ /*
|
||||
+ * Calculate and replace the Message-Authenticator MAC. Per RFC 2869
|
||||
+ * section 5.14, use the authenticator from the request, not from the
|
||||
+ * response.
|
||||
+ */
|
||||
+ retval = calculate_mac(secret, pkt, pkt_auth(request),
|
||||
+ pkt_attr(pkt) + 2);
|
||||
+ if (retval != 0)
|
||||
+ goto error;
|
||||
+ }
|
||||
+
|
||||
/* Copy the attrset for future use. */
|
||||
retval = packet_set_attrset(ctx, secret, pkt);
|
||||
if (retval != 0)
|
||||
@@ -343,6 +473,34 @@ error:
|
||||
return retval;
|
||||
}
|
||||
|
||||
+/* Verify the Message-Authenticator value in pkt, using the provided
|
||||
+ * authenticator (which may be from pkt or from a corresponding request). */
|
||||
+static krb5_error_code
|
||||
+verify_msgauth(const char *secret, const krad_packet *pkt,
|
||||
+ const uint8_t auth[AUTH_FIELD_SIZE])
|
||||
+{
|
||||
+ uint8_t mac[MD5_DIGEST_SIZE];
|
||||
+ krad_attr msgauth_type = krad_attr_name2num("Message-Authenticator");
|
||||
+ const krb5_data *msgauth;
|
||||
+ krb5_error_code retval;
|
||||
+
|
||||
+ msgauth = krad_packet_get_attr(pkt, msgauth_type, 0);
|
||||
+ if (msgauth == NULL)
|
||||
+ return ENODATA;
|
||||
+
|
||||
+ retval = calculate_mac(secret, pkt, auth, mac);
|
||||
+ if (retval)
|
||||
+ return retval;
|
||||
+
|
||||
+ if (msgauth->length != MD5_DIGEST_SIZE)
|
||||
+ return EMSGSIZE;
|
||||
+
|
||||
+ if (k5_bcmp(mac, msgauth->data, MD5_DIGEST_SIZE) != 0)
|
||||
+ return EBADMSG;
|
||||
+
|
||||
+ return 0;
|
||||
+}
|
||||
+
|
||||
/* Decode a packet. */
|
||||
static krb5_error_code
|
||||
decode_packet(krb5_context ctx, const char *secret, const krb5_data *buffer,
|
||||
@@ -394,21 +552,35 @@ krad_packet_decode_request(krb5_context ctx, const char *secret,
|
||||
krad_packet **reqpkt)
|
||||
{
|
||||
const krad_packet *tmp = NULL;
|
||||
+ krad_packet *req;
|
||||
krb5_error_code retval;
|
||||
|
||||
- retval = decode_packet(ctx, secret, buffer, reqpkt);
|
||||
- if (cb != NULL && retval == 0) {
|
||||
+ retval = decode_packet(ctx, secret, buffer, &req);
|
||||
+ if (retval)
|
||||
+ return retval;
|
||||
+
|
||||
+ /* Verify Message-Authenticator if present. */
|
||||
+ if (has_pkt_msgauth(req)) {
|
||||
+ retval = verify_msgauth(secret, req, pkt_auth(req));
|
||||
+ if (retval) {
|
||||
+ krad_packet_free(req);
|
||||
+ return retval;
|
||||
+ }
|
||||
+ }
|
||||
+
|
||||
+ if (cb != NULL) {
|
||||
for (tmp = (*cb)(data, FALSE); tmp != NULL; tmp = (*cb)(data, FALSE)) {
|
||||
if (pkt_id_get(*reqpkt) == pkt_id_get(tmp))
|
||||
break;
|
||||
}
|
||||
- }
|
||||
|
||||
- if (cb != NULL && (retval != 0 || tmp != NULL))
|
||||
- (*cb)(data, TRUE);
|
||||
+ if (tmp != NULL)
|
||||
+ (*cb)(data, TRUE);
|
||||
+ }
|
||||
|
||||
+ *reqpkt = req;
|
||||
*duppkt = tmp;
|
||||
- return retval;
|
||||
+ return 0;
|
||||
}
|
||||
|
||||
krb5_error_code
|
||||
@@ -435,9 +607,17 @@ krad_packet_decode_response(krb5_context ctx, const char *secret,
|
||||
break;
|
||||
}
|
||||
|
||||
- /* If the authenticator matches, then the response is valid. */
|
||||
- if (memcmp(pkt_auth(*rsppkt), auth, sizeof(auth)) == 0)
|
||||
- break;
|
||||
+ /* Verify the response authenticator. */
|
||||
+ if (k5_bcmp(pkt_auth(*rsppkt), auth, sizeof(auth)) != 0)
|
||||
+ continue;
|
||||
+
|
||||
+ /* Verify Message-Authenticator if present. */
|
||||
+ if (has_pkt_msgauth(*rsppkt)) {
|
||||
+ if (verify_msgauth(secret, *rsppkt, pkt_auth(tmp)) != 0)
|
||||
+ continue;
|
||||
+ }
|
||||
+
|
||||
+ break;
|
||||
}
|
||||
}
|
||||
|
||||
diff --git a/src/lib/krad/t_attrset.c b/src/lib/krad/t_attrset.c
|
||||
index 4cdb8b7d8e..f9c66509bd 100644
|
||||
--- a/src/lib/krad/t_attrset.c
|
||||
+++ b/src/lib/krad/t_attrset.c
|
||||
@@ -63,7 +63,7 @@ main(void)
|
||||
noerror(krad_attrset_add(set, krad_attr_name2num("User-Password"), &tmp));
|
||||
|
||||
/* Encode attrset. */
|
||||
- noerror(kr_attrset_encode(set, "foo", auth, buffer, &encode_len,
|
||||
+ noerror(kr_attrset_encode(set, "foo", auth, FALSE, buffer, &encode_len,
|
||||
&is_fips));
|
||||
krad_attrset_free(set);
|
||||
|
||||
diff --git a/src/lib/krad/t_daemon.py b/src/lib/krad/t_daemon.py
|
||||
index 4a3de079c7..647d4894eb 100755
|
||||
--- a/src/lib/krad/t_daemon.py
|
||||
+++ b/src/lib/krad/t_daemon.py
|
||||
@@ -40,6 +40,7 @@ DICTIONARY = """
|
||||
ATTRIBUTE\tUser-Name\t1\tstring
|
||||
ATTRIBUTE\tUser-Password\t2\toctets
|
||||
ATTRIBUTE\tNAS-Identifier\t32\tstring
|
||||
+ATTRIBUTE\tMessage-Authenticator\t80\toctets
|
||||
"""
|
||||
|
||||
class TestServer(server.Server):
|
||||
@@ -52,7 +53,7 @@ class TestServer(server.Server):
|
||||
if key == "User-Password":
|
||||
passwd = [pkt.PwDecrypt(x) for x in pkt[key]]
|
||||
|
||||
- reply = self.CreateReplyPacket(pkt)
|
||||
+ reply = self.CreateReplyPacket(pkt, message_authenticator=True)
|
||||
if passwd == ['accept']:
|
||||
reply.code = packet.AccessAccept
|
||||
else:
|
||||
diff --git a/src/lib/krad/t_packet.c b/src/lib/krad/t_packet.c
|
||||
index c22489144f..104b6507a2 100644
|
||||
--- a/src/lib/krad/t_packet.c
|
||||
+++ b/src/lib/krad/t_packet.c
|
||||
@@ -172,6 +172,9 @@ main(int argc, const char **argv)
|
||||
krb5_data username, password;
|
||||
krb5_boolean auth = FALSE;
|
||||
krb5_context ctx;
|
||||
+ const krad_packet *dupreq;
|
||||
+ const krb5_data *encpkt;
|
||||
+ krad_packet *decreq;
|
||||
|
||||
username = string2data("testUser");
|
||||
|
||||
@@ -184,9 +187,17 @@ main(int argc, const char **argv)
|
||||
|
||||
password = string2data("accept");
|
||||
noerror(make_packet(ctx, &username, &password, &packets[ACCEPT_PACKET]));
|
||||
+ encpkt = krad_packet_encode(packets[ACCEPT_PACKET]);
|
||||
+ noerror(krad_packet_decode_request(ctx, "foo", encpkt, NULL, NULL,
|
||||
+ &dupreq, &decreq));
|
||||
+ krad_packet_free(decreq);
|
||||
|
||||
password = string2data("reject");
|
||||
noerror(make_packet(ctx, &username, &password, &packets[REJECT_PACKET]));
|
||||
+ encpkt = krad_packet_encode(packets[REJECT_PACKET]);
|
||||
+ noerror(krad_packet_decode_request(ctx, "foo", encpkt, NULL, NULL,
|
||||
+ &dupreq, &decreq));
|
||||
+ krad_packet_free(decreq);
|
||||
|
||||
memset(&hints, 0, sizeof(hints));
|
||||
hints.ai_family = AF_INET;
|
||||
diff --git a/src/tests/t_otp.py b/src/tests/t_otp.py
|
||||
index c3b820a411..dd5cdc5c26 100755
|
||||
--- a/src/tests/t_otp.py
|
||||
+++ b/src/tests/t_otp.py
|
||||
@@ -49,6 +49,7 @@ ATTRIBUTE User-Name 1 string
|
||||
ATTRIBUTE User-Password 2 octets
|
||||
ATTRIBUTE Service-Type 6 integer
|
||||
ATTRIBUTE NAS-Identifier 32 string
|
||||
+ATTRIBUTE Message-Authenticator 80 octets
|
||||
'''
|
||||
|
||||
class RadiusDaemon(Process):
|
||||
@@ -97,6 +98,8 @@ class RadiusDaemon(Process):
|
||||
reply.code = packet.AccessReject
|
||||
replyq['reply'] = False
|
||||
|
||||
+ reply.add_message_authenticator()
|
||||
+
|
||||
outq.put(replyq)
|
||||
if addr is None:
|
||||
sock.send(reply.ReplyPacket())
|
||||
--
|
||||
2.46.0
|
||||
|
||||
File diff suppressed because it is too large
Load diff
|
|
@ -1,78 +0,0 @@
|
|||
From 43d10f1580c033fe706470e7588c720ac7854918 Mon Sep 17 00:00:00 2001
|
||||
From: Julien Rische <jrische@redhat.com>
|
||||
Date: Wed, 21 Jun 2023 18:27:11 +0200
|
||||
Subject: [PATCH] Add ecdsa-with-sha512/256 to supportedCMSTypes
|
||||
|
||||
Elliptic curve certificates are already supported for PKINIT
|
||||
pre-authentication, but their associated signature types aren't
|
||||
advertized. Add ecdsa-with-sha512 and ecdsa-with-sha256 OIDs to the
|
||||
supportedCMSTypes list sent by the client.
|
||||
|
||||
[ghudson@mit.edu: edited commit message]
|
||||
|
||||
ticket: 9100 (new)
|
||||
(cherry picked from commit 9913e5c92c4e5cb76d6ae58386f744766d2e6454)
|
||||
---
|
||||
src/plugins/preauth/pkinit/pkinit_constants.c | 38 +++++++++++++++++++
|
||||
1 file changed, 38 insertions(+)
|
||||
|
||||
diff --git a/src/plugins/preauth/pkinit/pkinit_constants.c b/src/plugins/preauth/pkinit/pkinit_constants.c
|
||||
index 10f8688ec2..905e90d29c 100644
|
||||
--- a/src/plugins/preauth/pkinit/pkinit_constants.c
|
||||
+++ b/src/plugins/preauth/pkinit/pkinit_constants.c
|
||||
@@ -64,14 +64,52 @@ static char sha512WithRSAEncr_oid[9] = {
|
||||
0x2a, 0x86, 0x48, 0x86, 0xf7, 0x0d, 0x01, 0x01, 0x0d
|
||||
};
|
||||
|
||||
+/* RFC 3279 ecdsa-with-SHA1: iso(1) member-body(2) us(840) ansi-X9-62(10045)
|
||||
+ * signatures(4) 1 */
|
||||
+static char ecdsaWithSha1_oid[] = {
|
||||
+ 0x2a, 0x86, 0x48, 0xce, 0x3d, 0x04, 0x01
|
||||
+};
|
||||
+
|
||||
+/* RFC 5758 ecdsa-with-SHA256: iso(1) member-body(2) us(840) ansi-X9-62(10045)
|
||||
+ * signatures(4) ecdsa-with-SHA2(3) 2 */
|
||||
+static char ecdsaWithSha256_oid[] = {
|
||||
+ 0x2a, 0x86, 0x48, 0xce, 0x3d, 0x04, 0x03, 0x02
|
||||
+};
|
||||
+
|
||||
+/* RFC 5758 ecdsa-with-SHA384: iso(1) member-body(2) us(840) ansi-X9-62(10045)
|
||||
+ * signatures(4) ecdsa-with-SHA2(3) 3 */
|
||||
+static char ecdsaWithSha384_oid[] = {
|
||||
+ 0x2a, 0x86, 0x48, 0xce, 0x3d, 0x04, 0x03, 0x03
|
||||
+};
|
||||
+
|
||||
+/* RFC 5758 ecdsa-with-SHA512: iso(1) member-body(2) us(840) ansi-X9-62(10045)
|
||||
+ * signatures(4) ecdsa-with-SHA2(3) 4 */
|
||||
+static char ecdsaWithSha512_oid[] = {
|
||||
+ 0x2a, 0x86, 0x48, 0xce, 0x3d, 0x04, 0x03, 0x04
|
||||
+};
|
||||
+
|
||||
const krb5_data sha256WithRSAEncr_id = {
|
||||
KV5M_DATA, sizeof(sha256WithRSAEncr_oid), sha256WithRSAEncr_oid
|
||||
};
|
||||
const krb5_data sha512WithRSAEncr_id = {
|
||||
KV5M_DATA, sizeof(sha512WithRSAEncr_oid), sha512WithRSAEncr_oid
|
||||
};
|
||||
+const krb5_data ecdsaWithSha1_id = {
|
||||
+ KV5M_DATA, sizeof(ecdsaWithSha1_oid), ecdsaWithSha1_oid
|
||||
+};
|
||||
+const krb5_data ecdsaWithSha256_id = {
|
||||
+ KV5M_DATA, sizeof(ecdsaWithSha256_oid), ecdsaWithSha256_oid
|
||||
+};
|
||||
+const krb5_data ecdsaWithSha384_id = {
|
||||
+ KV5M_DATA, sizeof(ecdsaWithSha384_oid), ecdsaWithSha384_oid
|
||||
+};
|
||||
+const krb5_data ecdsaWithSha512_id = {
|
||||
+ KV5M_DATA, sizeof(ecdsaWithSha512_oid), ecdsaWithSha512_oid
|
||||
+};
|
||||
|
||||
krb5_data const * const supported_cms_algs[] = {
|
||||
+ &ecdsaWithSha512_id,
|
||||
+ &ecdsaWithSha256_id,
|
||||
&sha512WithRSAEncr_id,
|
||||
&sha256WithRSAEncr_id,
|
||||
NULL
|
||||
--
|
||||
2.47.1
|
||||
|
||||
|
|
@ -1,264 +0,0 @@
|
|||
From fba4cbf0bc50569b8ea6d1e1c3303eaab84935e1 Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Sun, 30 Jul 2023 01:07:38 -0400
|
||||
Subject: [PATCH] Get rid of pkinit_crypto_openssl.h
|
||||
|
||||
Fold pkinit_crypto_openssl.h into the one source file where it was
|
||||
used. Also clean up the include of <arpa/inet.h>, as htonl() is no
|
||||
longer used after commit 1c87ce6c44a9de0824580a2d72a8a202237e01f4.
|
||||
|
||||
(cherry picked from commit b3352945fb8836f8b4095e0b8aad04b54aca3152)
|
||||
---
|
||||
src/plugins/preauth/pkinit/deps | 2 +-
|
||||
.../preauth/pkinit/pkinit_crypto_openssl.c | 85 +++++++++++-
|
||||
.../preauth/pkinit/pkinit_crypto_openssl.h | 121 ------------------
|
||||
3 files changed, 83 insertions(+), 125 deletions(-)
|
||||
delete mode 100644 src/plugins/preauth/pkinit/pkinit_crypto_openssl.h
|
||||
|
||||
diff --git a/src/plugins/preauth/pkinit/deps b/src/plugins/preauth/pkinit/deps
|
||||
index 58320aa801..b6f4476fe8 100644
|
||||
--- a/src/plugins/preauth/pkinit/deps
|
||||
+++ b/src/plugins/preauth/pkinit/deps
|
||||
@@ -112,4 +112,4 @@ pkinit_crypto_openssl.so pkinit_crypto_openssl.po $(OUTPRE)pkinit_crypto_openssl
|
||||
$(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/krb5/preauth_plugin.h \
|
||||
$(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \
|
||||
pkcs11.h pkinit.h pkinit_accessor.h pkinit_crypto.h \
|
||||
- pkinit_crypto_openssl.c pkinit_crypto_openssl.h pkinit_trace.h
|
||||
+ pkinit_crypto_openssl.c pkinit_trace.h
|
||||
diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c
|
||||
index f6d494bd11..ae8599d5a2 100644
|
||||
--- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c
|
||||
+++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c
|
||||
@@ -30,20 +30,99 @@
|
||||
*/
|
||||
|
||||
#include "k5-int.h"
|
||||
-#include "pkinit_crypto_openssl.h"
|
||||
#include "k5-buf.h"
|
||||
#include "k5-err.h"
|
||||
#include "k5-hex.h"
|
||||
-#include <unistd.h>
|
||||
+#include "pkinit.h"
|
||||
#include <dirent.h>
|
||||
-#include <arpa/inet.h>
|
||||
|
||||
+#include <openssl/bn.h>
|
||||
+#include <openssl/dh.h>
|
||||
+#include <openssl/x509.h>
|
||||
+#include <openssl/pkcs7.h>
|
||||
+#include <openssl/pkcs12.h>
|
||||
+#include <openssl/obj_mac.h>
|
||||
+#include <openssl/x509v3.h>
|
||||
+#include <openssl/err.h>
|
||||
+#include <openssl/evp.h>
|
||||
+#include <openssl/sha.h>
|
||||
+#include <openssl/asn1.h>
|
||||
+#include <openssl/pem.h>
|
||||
+#include <openssl/asn1t.h>
|
||||
+#include <openssl/cms.h>
|
||||
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||
#include <openssl/core_names.h>
|
||||
#include <openssl/kdf.h>
|
||||
+#include <openssl/decoder.h>
|
||||
#include <openssl/params.h>
|
||||
#endif
|
||||
|
||||
+#define DN_BUF_LEN 256
|
||||
+#define MAX_CREDS_ALLOWED 20
|
||||
+
|
||||
+struct _pkinit_cred_info {
|
||||
+ char *name;
|
||||
+ X509 *cert;
|
||||
+ EVP_PKEY *key;
|
||||
+#ifndef WITHOUT_PKCS11
|
||||
+ CK_BYTE_PTR cert_id;
|
||||
+ int cert_id_len;
|
||||
+#endif
|
||||
+};
|
||||
+typedef struct _pkinit_cred_info *pkinit_cred_info;
|
||||
+
|
||||
+struct _pkinit_identity_crypto_context {
|
||||
+ pkinit_cred_info creds[MAX_CREDS_ALLOWED+1];
|
||||
+ STACK_OF(X509) *my_certs; /* available user certs */
|
||||
+ char *identity; /* identity name for user cert */
|
||||
+ int cert_index; /* cert to use out of available certs*/
|
||||
+ EVP_PKEY *my_key; /* available user keys if in filesystem */
|
||||
+ STACK_OF(X509) *trustedCAs; /* available trusted ca certs */
|
||||
+ STACK_OF(X509) *intermediateCAs; /* available intermediate ca certs */
|
||||
+ STACK_OF(X509_CRL) *revoked; /* available crls */
|
||||
+ int pkcs11_method;
|
||||
+ krb5_prompter_fct prompter;
|
||||
+ void *prompter_data;
|
||||
+#ifndef WITHOUT_PKCS11
|
||||
+ char *p11_module_name;
|
||||
+ CK_SLOT_ID slotid;
|
||||
+ char *token_label;
|
||||
+ char *cert_label;
|
||||
+ /* These are crypto-specific. */
|
||||
+ struct plugin_file_handle *p11_module;
|
||||
+ CK_SESSION_HANDLE session;
|
||||
+ CK_FUNCTION_LIST_PTR p11;
|
||||
+ uint8_t *cert_id;
|
||||
+ size_t cert_id_len;
|
||||
+ CK_MECHANISM_TYPE mech;
|
||||
+#endif
|
||||
+ krb5_boolean defer_id_prompt;
|
||||
+ pkinit_deferred_id *deferred_ids;
|
||||
+};
|
||||
+
|
||||
+struct _pkinit_plg_crypto_context {
|
||||
+ EVP_PKEY *dh_1024;
|
||||
+ EVP_PKEY *dh_2048;
|
||||
+ EVP_PKEY *dh_4096;
|
||||
+ EVP_PKEY *ec_p256;
|
||||
+ EVP_PKEY *ec_p384;
|
||||
+ EVP_PKEY *ec_p521;
|
||||
+ ASN1_OBJECT *id_pkinit_authData;
|
||||
+ ASN1_OBJECT *id_pkinit_DHKeyData;
|
||||
+ ASN1_OBJECT *id_pkinit_rkeyData;
|
||||
+ ASN1_OBJECT *id_pkinit_san;
|
||||
+ ASN1_OBJECT *id_ms_san_upn;
|
||||
+ ASN1_OBJECT *id_pkinit_KPClientAuth;
|
||||
+ ASN1_OBJECT *id_pkinit_KPKdc;
|
||||
+ ASN1_OBJECT *id_ms_kp_sc_logon;
|
||||
+ ASN1_OBJECT *id_kp_serverAuth;
|
||||
+};
|
||||
+
|
||||
+struct _pkinit_req_crypto_context {
|
||||
+ X509 *received_cert;
|
||||
+ EVP_PKEY *client_pkey;
|
||||
+};
|
||||
+
|
||||
static krb5_error_code pkinit_init_pkinit_oids(pkinit_plg_crypto_context );
|
||||
static void pkinit_fini_pkinit_oids(pkinit_plg_crypto_context );
|
||||
|
||||
diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.h b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.h
|
||||
deleted file mode 100644
|
||||
index b7a3358800..0000000000
|
||||
--- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.h
|
||||
+++ /dev/null
|
||||
@@ -1,121 +0,0 @@
|
||||
-/*
|
||||
- * COPYRIGHT (C) 2006,2007
|
||||
- * THE REGENTS OF THE UNIVERSITY OF MICHIGAN
|
||||
- * ALL RIGHTS RESERVED
|
||||
- *
|
||||
- * Permission is granted to use, copy, create derivative works
|
||||
- * and redistribute this software and such derivative works
|
||||
- * for any purpose, so long as the name of The University of
|
||||
- * Michigan is not used in any advertising or publicity
|
||||
- * pertaining to the use of distribution of this software
|
||||
- * without specific, written prior authorization. If the
|
||||
- * above copyright notice or any other identification of the
|
||||
- * University of Michigan is included in any copy of any
|
||||
- * portion of this software, then the disclaimer below must
|
||||
- * also be included.
|
||||
- *
|
||||
- * THIS SOFTWARE IS PROVIDED AS IS, WITHOUT REPRESENTATION
|
||||
- * FROM THE UNIVERSITY OF MICHIGAN AS TO ITS FITNESS FOR ANY
|
||||
- * PURPOSE, AND WITHOUT WARRANTY BY THE UNIVERSITY OF
|
||||
- * MICHIGAN OF ANY KIND, EITHER EXPRESS OR IMPLIED, INCLUDING
|
||||
- * WITHOUT LIMITATION THE IMPLIED WARRANTIES OF
|
||||
- * MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. THE
|
||||
- * REGENTS OF THE UNIVERSITY OF MICHIGAN SHALL NOT BE LIABLE
|
||||
- * FOR ANY DAMAGES, INCLUDING SPECIAL, INDIRECT, INCIDENTAL, OR
|
||||
- * CONSEQUENTIAL DAMAGES, WITH RESPECT TO ANY CLAIM ARISING
|
||||
- * OUT OF OR IN CONNECTION WITH THE USE OF THE SOFTWARE, EVEN
|
||||
- * IF IT HAS BEEN OR IS HEREAFTER ADVISED OF THE POSSIBILITY OF
|
||||
- * SUCH DAMAGES.
|
||||
- */
|
||||
-
|
||||
-#ifndef _PKINIT_CRYPTO_OPENSSL_H
|
||||
-#define _PKINIT_CRYPTO_OPENSSL_H
|
||||
-
|
||||
-#include "pkinit.h"
|
||||
-
|
||||
-#include <openssl/bn.h>
|
||||
-#include <openssl/dh.h>
|
||||
-#include <openssl/x509.h>
|
||||
-#include <openssl/pkcs7.h>
|
||||
-#include <openssl/pkcs12.h>
|
||||
-#include <openssl/obj_mac.h>
|
||||
-#include <openssl/x509v3.h>
|
||||
-#include <openssl/err.h>
|
||||
-#include <openssl/evp.h>
|
||||
-#include <openssl/sha.h>
|
||||
-#include <openssl/asn1.h>
|
||||
-#include <openssl/pem.h>
|
||||
-#include <openssl/asn1t.h>
|
||||
-#include <openssl/cms.h>
|
||||
-#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||
-#include <openssl/core_names.h>
|
||||
-#include <openssl/decoder.h>
|
||||
-#endif
|
||||
-
|
||||
-#define DN_BUF_LEN 256
|
||||
-#define MAX_CREDS_ALLOWED 20
|
||||
-
|
||||
-struct _pkinit_cred_info {
|
||||
- char *name;
|
||||
- X509 *cert;
|
||||
- EVP_PKEY *key;
|
||||
-#ifndef WITHOUT_PKCS11
|
||||
- CK_BYTE_PTR cert_id;
|
||||
- int cert_id_len;
|
||||
-#endif
|
||||
-};
|
||||
-typedef struct _pkinit_cred_info * pkinit_cred_info;
|
||||
-
|
||||
-struct _pkinit_identity_crypto_context {
|
||||
- pkinit_cred_info creds[MAX_CREDS_ALLOWED+1];
|
||||
- STACK_OF(X509) *my_certs; /* available user certs */
|
||||
- char *identity; /* identity name for user cert */
|
||||
- int cert_index; /* cert to use out of available certs*/
|
||||
- EVP_PKEY *my_key; /* available user keys if in filesystem */
|
||||
- STACK_OF(X509) *trustedCAs; /* available trusted ca certs */
|
||||
- STACK_OF(X509) *intermediateCAs; /* available intermediate ca certs */
|
||||
- STACK_OF(X509_CRL) *revoked; /* available crls */
|
||||
- int pkcs11_method;
|
||||
- krb5_prompter_fct prompter;
|
||||
- void *prompter_data;
|
||||
-#ifndef WITHOUT_PKCS11
|
||||
- char *p11_module_name;
|
||||
- CK_SLOT_ID slotid;
|
||||
- char *token_label;
|
||||
- char *cert_label;
|
||||
- /* These are crypto-specific */
|
||||
- struct plugin_file_handle *p11_module;
|
||||
- CK_SESSION_HANDLE session;
|
||||
- CK_FUNCTION_LIST_PTR p11;
|
||||
- uint8_t *cert_id;
|
||||
- size_t cert_id_len;
|
||||
- CK_MECHANISM_TYPE mech;
|
||||
-#endif
|
||||
- krb5_boolean defer_id_prompt;
|
||||
- pkinit_deferred_id *deferred_ids;
|
||||
-};
|
||||
-
|
||||
-struct _pkinit_plg_crypto_context {
|
||||
- EVP_PKEY *dh_1024;
|
||||
- EVP_PKEY *dh_2048;
|
||||
- EVP_PKEY *dh_4096;
|
||||
- EVP_PKEY *ec_p256;
|
||||
- EVP_PKEY *ec_p384;
|
||||
- EVP_PKEY *ec_p521;
|
||||
- ASN1_OBJECT *id_pkinit_authData;
|
||||
- ASN1_OBJECT *id_pkinit_DHKeyData;
|
||||
- ASN1_OBJECT *id_pkinit_rkeyData;
|
||||
- ASN1_OBJECT *id_pkinit_san;
|
||||
- ASN1_OBJECT *id_ms_san_upn;
|
||||
- ASN1_OBJECT *id_pkinit_KPClientAuth;
|
||||
- ASN1_OBJECT *id_pkinit_KPKdc;
|
||||
- ASN1_OBJECT *id_ms_kp_sc_logon;
|
||||
- ASN1_OBJECT *id_kp_serverAuth;
|
||||
-};
|
||||
-
|
||||
-struct _pkinit_req_crypto_context {
|
||||
- X509 *received_cert;
|
||||
- EVP_PKEY *client_pkey;
|
||||
-};
|
||||
-
|
||||
-#endif /* _PKINIT_CRYPTO_OPENSSL_H */
|
||||
--
|
||||
2.47.1
|
||||
|
||||
|
|
@ -1,157 +0,0 @@
|
|||
From 1b01057df4c2223fbf92be44f1e764207208ef03 Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Mon, 26 Feb 2024 19:03:38 -0500
|
||||
Subject: [PATCH] Use SoftHSMv2 for PKCS11 PKINIT tests
|
||||
|
||||
Instead of softpkcs11, use SoftHSMv2 to mock the PKCS11 token for
|
||||
PKINIT tests. Use pkcs11-tool from OpenSC to initialize the token and
|
||||
import a certificate and key. SoftHSM does not support PIN-less
|
||||
tokens (see https://github.com/opendnssec/SoftHSMv2/issues/480) so
|
||||
remove that test for now.
|
||||
|
||||
(cherry picked from commit 8ab61608236883fdc5c2d43f4bd1ff2094401d19)
|
||||
---
|
||||
.github/workflows/build.yml | 2 +-
|
||||
src/tests/t_pkinit.py | 82 ++++++++++++++++++++-----------------
|
||||
2 files changed, 45 insertions(+), 39 deletions(-)
|
||||
|
||||
diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml
|
||||
index 68a4788adb..d7ae86b150 100644
|
||||
--- a/.github/workflows/build.yml
|
||||
+++ b/.github/workflows/build.yml
|
||||
@@ -33,7 +33,7 @@ jobs:
|
||||
if: startsWith(matrix.os, 'ubuntu')
|
||||
run: |
|
||||
sudo apt-get update -qq
|
||||
- sudo apt-get install -y bison gettext keyutils ldap-utils libcmocka-dev libldap2-dev libkeyutils-dev libsasl2-dev libssl-dev python3-kdcproxy python3-pip slapd tcsh
|
||||
+ sudo apt-get install -y bison gettext keyutils ldap-utils libcmocka-dev libldap2-dev libkeyutils-dev libsasl2-dev libssl-dev python3-kdcproxy python3-pip slapd tcsh softhsm2 opensc
|
||||
pip3 install pyrad
|
||||
- name: Build
|
||||
env:
|
||||
diff --git a/src/tests/t_pkinit.py b/src/tests/t_pkinit.py
|
||||
index f8f2debc1b..4435746429 100755
|
||||
--- a/src/tests/t_pkinit.py
|
||||
+++ b/src/tests/t_pkinit.py
|
||||
@@ -1,11 +1,10 @@
|
||||
from k5test import *
|
||||
+import re
|
||||
|
||||
# Skip this test if pkinit wasn't built.
|
||||
if not pkinit_enabled:
|
||||
skip_rest('PKINIT tests', 'PKINIT module not built')
|
||||
|
||||
-soft_pkcs11 = os.path.join(buildtop, 'tests', 'softpkcs11', 'softpkcs11.so')
|
||||
-
|
||||
# Construct a krb5.conf fragment configuring pkinit.
|
||||
user_pem = os.path.join(pkinit_certs, 'user.pem')
|
||||
privkey_pem = os.path.join(pkinit_certs, 'privkey.pem')
|
||||
@@ -55,9 +54,6 @@ p12_upn2_identity = 'PKCS12:%s' % user_upn2_p12
|
||||
p12_upn3_identity = 'PKCS12:%s' % user_upn3_p12
|
||||
p12_generic_identity = 'PKCS12:%s' % generic_p12
|
||||
p12_enc_identity = 'PKCS12:%s' % user_enc_p12
|
||||
-p11_identity = 'PKCS11:' + soft_pkcs11
|
||||
-p11_token_identity = ('PKCS11:module_name=' + soft_pkcs11 +
|
||||
- ':slotid=1:token=SoftToken (token)')
|
||||
|
||||
# Start a realm with the test kdb module for the following UPN SAN tests.
|
||||
realm = K5Realm(kdc_conf=alias_kdc_conf, create_kdb=False, pkinit=True)
|
||||
@@ -389,53 +385,63 @@ realm.klist(realm.user_princ)
|
||||
realm.kinit(realm.user_princ, flags=['-X', 'X509_user_identity=,'],
|
||||
expected_code=1, expected_msg='Preauthentication failed while')
|
||||
|
||||
-softpkcs11rc = os.path.join(os.getcwd(), 'testdir', 'soft-pkcs11.rc')
|
||||
-realm.env['SOFTPKCS11RC'] = softpkcs11rc
|
||||
+softhsm2 = '/usr/lib/softhsm/libsofthsm2.so'
|
||||
+if not os.path.exists(softhsm2):
|
||||
+ skip_rest('PKCS11 tests', 'SoftHSMv2 required')
|
||||
+pkcs11_tool = which('pkcs11-tool')
|
||||
+if not pkcs11_tool:
|
||||
+ skip_rest('PKCS11 tests', 'pkcs11-tool from OpenSC required')
|
||||
+tool_cmd = [pkcs11_tool, '--module', softhsm2]
|
||||
+
|
||||
+# Prepare a SoftHSM token.
|
||||
+softhsm2_conf = os.path.join(realm.testdir, 'softhsm2.conf')
|
||||
+softhsm2_tokens = os.path.join(realm.testdir, 'tokens')
|
||||
+os.mkdir(softhsm2_tokens)
|
||||
+realm.env['SOFTHSM2_CONF'] = softhsm2_conf
|
||||
+with open(softhsm2_conf, 'w') as f:
|
||||
+ f.write('directories.tokendir = %s\n' % softhsm2_tokens)
|
||||
+realm.run(tool_cmd + ['--init-token', '--label', 'user',
|
||||
+ '--so-pin', 'sopin', '--init-pin', '--pin', 'userpin'])
|
||||
+realm.run(tool_cmd + ['-w', user_pem, '-y', 'cert'])
|
||||
+realm.run(tool_cmd + ['-w', privkey_pem, '-y', 'privkey',
|
||||
+ '-l', '--pin', 'userpin'])
|
||||
+
|
||||
+# Extract the slot ID generated by SoftHSM.
|
||||
+out = realm.run(tool_cmd + ['-L'])
|
||||
+m = re.search(r'slot ID 0x([0-9a-f]+)\n', out)
|
||||
+if not m:
|
||||
+ fail('could not extract slot ID from SoftHSM token')
|
||||
+slot_id = int(m.group(1), 16)
|
||||
+
|
||||
+p11_attr = 'X509_user_identity=PKCS11:' + softhsm2
|
||||
+p11_token_identity = ('PKCS11:module_name=%s:slotid=%d:token=user' %
|
||||
+ (softhsm2, slot_id))
|
||||
|
||||
-# PKINIT with PKCS11: identity, with no need for a PIN.
|
||||
-mark('PKCS11 identity, no PIN')
|
||||
-conf = open(softpkcs11rc, 'w')
|
||||
-conf.write("%s\t%s\t%s\t%s\n" % ('user', 'user token', user_pem, privkey_pem))
|
||||
-conf.close()
|
||||
-# Expect to succeed without having to supply any more information.
|
||||
-realm.kinit(realm.user_princ,
|
||||
- flags=['-X', 'X509_user_identity=%s' % p11_identity])
|
||||
+mark('PKCS11 identity, with PIN (prompter)')
|
||||
+realm.kinit(realm.user_princ, flags=['-X', p11_attr], password='userpin')
|
||||
realm.klist(realm.user_princ)
|
||||
realm.run([kvno, realm.host_princ])
|
||||
|
||||
-# PKINIT with PKCS11: identity, with a PIN supplied by the prompter.
|
||||
-mark('PKCS11 identity, with PIN (prompter)')
|
||||
-os.remove(softpkcs11rc)
|
||||
-conf = open(softpkcs11rc, 'w')
|
||||
-conf.write("%s\t%s\t%s\t%s\n" % ('user', 'user token', user_pem,
|
||||
- privkey_enc_pem))
|
||||
-conf.close()
|
||||
-# Expect failure if the responder does nothing, and there's no prompter
|
||||
+mark('PKCS11 identity, unavailable PIN')
|
||||
realm.run(['./responder', '-x', 'pkinit={"%s": 0}' % p11_token_identity,
|
||||
- '-X', 'X509_user_identity=%s' % p11_identity, realm.user_princ],
|
||||
- expected_code=2)
|
||||
-realm.kinit(realm.user_princ,
|
||||
- flags=['-X', 'X509_user_identity=%s' % p11_identity],
|
||||
- password='encrypted')
|
||||
-realm.klist(realm.user_princ)
|
||||
-realm.run([kvno, realm.host_princ])
|
||||
+ '-X', p11_attr, realm.user_princ], expected_code=2)
|
||||
|
||||
-# Supply the wrong PIN.
|
||||
mark('PKCS11 identity, wrong PIN')
|
||||
expected_trace = ('PKINIT client has no configured identity; giving up',)
|
||||
realm.kinit(realm.user_princ,
|
||||
- flags=['-X', 'X509_user_identity=%s' % p11_identity],
|
||||
+ flags=['-X', p11_attr],
|
||||
password='wrong', expected_code=1, expected_trace=expected_trace)
|
||||
|
||||
# PKINIT with PKCS11: identity, with a PIN supplied by the responder.
|
||||
-# Supply the response in raw form.
|
||||
+# Supply the response in raw form. Expect the PIN_COUNT_LOW flag (1)
|
||||
+# to be set due to the previous test.
|
||||
mark('PKCS11 identity, with PIN (responder)')
|
||||
-realm.run(['./responder', '-x', 'pkinit={"%s": 0}' % p11_token_identity,
|
||||
- '-r', 'pkinit={"%s": "encrypted"}' % p11_token_identity,
|
||||
- '-X', 'X509_user_identity=%s' % p11_identity, realm.user_princ])
|
||||
+realm.run(['./responder', '-x', 'pkinit={"%s": 1}' % p11_token_identity,
|
||||
+ '-r', 'pkinit={"%s": "userpin"}' % p11_token_identity,
|
||||
+ '-X', p11_attr, realm.user_princ])
|
||||
# Supply the response through the convenience API.
|
||||
-realm.run(['./responder', '-X', 'X509_user_identity=%s' % p11_identity,
|
||||
- '-p', '%s=%s' % (p11_token_identity, 'encrypted'),
|
||||
+realm.run(['./responder', '-X', p11_attr,
|
||||
+ '-p', '%s=%s' % (p11_token_identity, 'userpin'),
|
||||
realm.user_princ])
|
||||
realm.klist(realm.user_princ)
|
||||
realm.run([kvno, realm.host_princ])
|
||||
--
|
||||
2.47.1
|
||||
|
||||
|
|
@ -1,202 +0,0 @@
|
|||
From b0315d30f066c4241fcecc33dd9e4d1c7c28b9d8 Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Fri, 9 Feb 2024 17:32:40 -0500
|
||||
Subject: [PATCH] Simplify PKINIT cert representation
|
||||
|
||||
In the _pkinit_identity_crypto_context structure, the my_certs field
|
||||
is a stack which only ever contains one cert and is only ever used to
|
||||
retrieve that one cert. The cert_index field is always 0. Replace
|
||||
these fields with a my_cert field pointing directly to the X509
|
||||
certificate.
|
||||
|
||||
Simplify crypto_cert_select_default() by making it call
|
||||
crypto_cert_select() with index 0 after verifying the certificate
|
||||
count.
|
||||
|
||||
(cherry picked from commit f95dfb7908456f9563cee66706216a21df8d791f)
|
||||
---
|
||||
.../preauth/pkinit/pkinit_crypto_openssl.c | 74 +++++--------------
|
||||
1 file changed, 20 insertions(+), 54 deletions(-)
|
||||
|
||||
diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c
|
||||
index ae8599d5a2..da59cb1e02 100644
|
||||
--- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c
|
||||
+++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c
|
||||
@@ -73,10 +73,9 @@ typedef struct _pkinit_cred_info *pkinit_cred_info;
|
||||
|
||||
struct _pkinit_identity_crypto_context {
|
||||
pkinit_cred_info creds[MAX_CREDS_ALLOWED+1];
|
||||
- STACK_OF(X509) *my_certs; /* available user certs */
|
||||
+ X509 *my_cert; /* selected user or KDC cert */
|
||||
char *identity; /* identity name for user cert */
|
||||
- int cert_index; /* cert to use out of available certs*/
|
||||
- EVP_PKEY *my_key; /* available user keys if in filesystem */
|
||||
+ EVP_PKEY *my_key; /* selected cert key if in filesystem */
|
||||
STACK_OF(X509) *trustedCAs; /* available trusted ca certs */
|
||||
STACK_OF(X509) *intermediateCAs; /* available intermediate ca certs */
|
||||
STACK_OF(X509_CRL) *revoked; /* available crls */
|
||||
@@ -1489,8 +1488,7 @@ pkinit_init_certs(pkinit_identity_crypto_context ctx)
|
||||
|
||||
for (i = 0; i < MAX_CREDS_ALLOWED; i++)
|
||||
ctx->creds[i] = NULL;
|
||||
- ctx->my_certs = NULL;
|
||||
- ctx->cert_index = 0;
|
||||
+ ctx->my_cert = NULL;
|
||||
ctx->my_key = NULL;
|
||||
ctx->trustedCAs = NULL;
|
||||
ctx->intermediateCAs = NULL;
|
||||
@@ -1506,8 +1504,8 @@ pkinit_fini_certs(pkinit_identity_crypto_context ctx)
|
||||
if (ctx == NULL)
|
||||
return;
|
||||
|
||||
- if (ctx->my_certs != NULL)
|
||||
- sk_X509_pop_free(ctx->my_certs, X509_free);
|
||||
+ if (ctx->my_cert != NULL)
|
||||
+ X509_free(ctx->my_cert);
|
||||
|
||||
if (ctx->my_key != NULL)
|
||||
EVP_PKEY_free(ctx->my_key);
|
||||
@@ -1696,7 +1694,6 @@ cms_signeddata_create(krb5_context context,
|
||||
ASN1_OCTET_STRING *digest = NULL;
|
||||
unsigned int alg_len = 0, digest_len = 0;
|
||||
unsigned char *y = NULL;
|
||||
- X509 *cert = NULL;
|
||||
ASN1_OBJECT *oid = NULL, *oid_copy;
|
||||
|
||||
/* Start creating PKCS7 data. */
|
||||
@@ -1715,7 +1712,7 @@ cms_signeddata_create(krb5_context context,
|
||||
if (oid == NULL)
|
||||
goto cleanup;
|
||||
|
||||
- if (id_cryptoctx->my_certs != NULL) {
|
||||
+ if (id_cryptoctx->my_cert != NULL) {
|
||||
X509_STORE *certstore = NULL;
|
||||
X509_STORE_CTX *certctx;
|
||||
STACK_OF(X509) *certstack = NULL;
|
||||
@@ -1726,8 +1723,6 @@ cms_signeddata_create(krb5_context context,
|
||||
if ((cert_stack = sk_X509_new_null()) == NULL)
|
||||
goto cleanup;
|
||||
|
||||
- cert = sk_X509_value(id_cryptoctx->my_certs, id_cryptoctx->cert_index);
|
||||
-
|
||||
certstore = X509_STORE_new();
|
||||
if (certstore == NULL)
|
||||
goto cleanup;
|
||||
@@ -1736,7 +1731,7 @@ cms_signeddata_create(krb5_context context,
|
||||
certctx = X509_STORE_CTX_new();
|
||||
if (certctx == NULL)
|
||||
goto cleanup;
|
||||
- X509_STORE_CTX_init(certctx, certstore, cert,
|
||||
+ X509_STORE_CTX_init(certctx, certstore, id_cryptoctx->my_cert,
|
||||
id_cryptoctx->intermediateCAs);
|
||||
X509_STORE_CTX_trusted_stack(certctx, id_cryptoctx->trustedCAs);
|
||||
if (!X509_verify_cert(certctx)) {
|
||||
@@ -1764,13 +1759,13 @@ cms_signeddata_create(krb5_context context,
|
||||
if (!ASN1_INTEGER_set(p7si->version, 1))
|
||||
goto cleanup;
|
||||
if (!X509_NAME_set(&p7si->issuer_and_serial->issuer,
|
||||
- X509_get_issuer_name(cert)))
|
||||
+ X509_get_issuer_name(id_cryptoctx->my_cert)))
|
||||
goto cleanup;
|
||||
/* because ASN1_INTEGER_set is used to set a 'long' we will do
|
||||
* things the ugly way. */
|
||||
ASN1_INTEGER_free(p7si->issuer_and_serial->serial);
|
||||
if (!(p7si->issuer_and_serial->serial =
|
||||
- ASN1_INTEGER_dup(X509_get_serialNumber(cert))))
|
||||
+ ASN1_INTEGER_dup(X509_get_serialNumber(id_cryptoctx->my_cert))))
|
||||
goto cleanup;
|
||||
|
||||
/* will not fill-out EVP_PKEY because it's on the smartcard */
|
||||
@@ -3311,7 +3306,7 @@ pkinit_check_kdc_pkid(krb5_context context,
|
||||
PKCS7_ISSUER_AND_SERIAL *is = NULL;
|
||||
const unsigned char *p = pdid_buf;
|
||||
int status = 1;
|
||||
- X509 *kdc_cert = sk_X509_value(id_cryptoctx->my_certs, id_cryptoctx->cert_index);
|
||||
+ X509 *kdc_cert = id_cryptoctx->my_cert;
|
||||
|
||||
*valid_kdcPkId = 0;
|
||||
pkiDebug("found kdcPkId in AS REQ\n");
|
||||
@@ -4783,7 +4778,8 @@ cleanup:
|
||||
}
|
||||
|
||||
/*
|
||||
- * Set the certificate in idctx->creds[cred_index] as the selected certificate.
|
||||
+ * Set the certificate in idctx->creds[cred_index] as the selected certificate,
|
||||
+ * stealing pointers from it.
|
||||
*/
|
||||
krb5_error_code
|
||||
crypto_cert_select(krb5_context context, pkinit_identity_crypto_context idctx,
|
||||
@@ -4795,20 +4791,17 @@ crypto_cert_select(krb5_context context, pkinit_identity_crypto_context idctx,
|
||||
return ENOENT;
|
||||
|
||||
ci = idctx->creds[cred_index];
|
||||
- /* copy the selected cert into our id_cryptoctx */
|
||||
- if (idctx->my_certs != NULL)
|
||||
- sk_X509_pop_free(idctx->my_certs, X509_free);
|
||||
- idctx->my_certs = sk_X509_new_null();
|
||||
- sk_X509_push(idctx->my_certs, ci->cert);
|
||||
- free(idctx->identity);
|
||||
+
|
||||
+ idctx->my_cert = ci->cert;
|
||||
+ ci->cert = NULL;
|
||||
+
|
||||
/* hang on to the selected credential name */
|
||||
+ free(idctx->identity);
|
||||
if (ci->name != NULL)
|
||||
idctx->identity = strdup(ci->name);
|
||||
else
|
||||
idctx->identity = NULL;
|
||||
|
||||
- ci->cert = NULL; /* Don't free it twice */
|
||||
- idctx->cert_index = 0;
|
||||
if (idctx->pkcs11_method != 1) {
|
||||
idctx->my_key = ci->key;
|
||||
ci->key = NULL; /* Don't free it twice */
|
||||
@@ -4837,41 +4830,14 @@ crypto_cert_select_default(krb5_context context,
|
||||
|
||||
retval = crypto_cert_get_count(id_cryptoctx, &cert_count);
|
||||
if (retval)
|
||||
- goto errout;
|
||||
+ return retval;
|
||||
|
||||
if (cert_count != 1) {
|
||||
TRACE_PKINIT_NO_DEFAULT_CERT(context, cert_count);
|
||||
- retval = EINVAL;
|
||||
- goto errout;
|
||||
- }
|
||||
- /* copy the selected cert into our id_cryptoctx */
|
||||
- if (id_cryptoctx->my_certs != NULL) {
|
||||
- sk_X509_pop_free(id_cryptoctx->my_certs, X509_free);
|
||||
+ return EINVAL;
|
||||
}
|
||||
- id_cryptoctx->my_certs = sk_X509_new_null();
|
||||
- sk_X509_push(id_cryptoctx->my_certs, id_cryptoctx->creds[0]->cert);
|
||||
- id_cryptoctx->creds[0]->cert = NULL; /* Don't free it twice */
|
||||
- id_cryptoctx->cert_index = 0;
|
||||
- /* hang on to the selected credential name */
|
||||
- if (id_cryptoctx->creds[0]->name != NULL)
|
||||
- id_cryptoctx->identity = strdup(id_cryptoctx->creds[0]->name);
|
||||
- else
|
||||
- id_cryptoctx->identity = NULL;
|
||||
|
||||
- if (id_cryptoctx->pkcs11_method != 1) {
|
||||
- id_cryptoctx->my_key = id_cryptoctx->creds[0]->key;
|
||||
- id_cryptoctx->creds[0]->key = NULL; /* Don't free it twice */
|
||||
- }
|
||||
-#ifndef WITHOUT_PKCS11
|
||||
- else {
|
||||
- id_cryptoctx->cert_id = id_cryptoctx->creds[0]->cert_id;
|
||||
- id_cryptoctx->creds[0]->cert_id = NULL; /* Don't free it twice */
|
||||
- id_cryptoctx->cert_id_len = id_cryptoctx->creds[0]->cert_id_len;
|
||||
- }
|
||||
-#endif
|
||||
- retval = 0;
|
||||
-errout:
|
||||
- return retval;
|
||||
+ return crypto_cert_select(context, id_cryptoctx, 0);
|
||||
}
|
||||
|
||||
|
||||
--
|
||||
2.47.1
|
||||
|
||||
File diff suppressed because it is too large
Load diff
|
|
@ -1,599 +0,0 @@
|
|||
From e43c05e7b0b93401dd68fc3ec3186c3a455b04ea Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Fri, 23 Feb 2024 13:51:26 -0500
|
||||
Subject: [PATCH] Improve PKCS11 error reporting in PKINIT
|
||||
|
||||
Create a helper p11err() to set extended error message for failed
|
||||
PKCS11 operations, and use it instead of pkiDebug() and pkcs11error().
|
||||
|
||||
ticket: 9113 (new)
|
||||
(cherry picked from commit 98afb314d13939cbee19c69885dcb655db8460da)
|
||||
---
|
||||
.../preauth/pkinit/pkinit_crypto_openssl.c | 262 ++++++++++--------
|
||||
src/plugins/preauth/pkinit/pkinit_trace.h | 9 -
|
||||
2 files changed, 142 insertions(+), 129 deletions(-)
|
||||
|
||||
diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c
|
||||
index 4accfc2664..402bf1b9b3 100644
|
||||
--- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c
|
||||
+++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c
|
||||
@@ -161,9 +161,11 @@ static krb5_error_code pkinit_create_sequence_of_principal_identifiers
|
||||
int type, krb5_pa_data ***e_data_out);
|
||||
|
||||
#ifndef WITHOUT_PKCS11
|
||||
-static krb5_error_code pkinit_find_private_key
|
||||
-(pkinit_identity_crypto_context, CK_ATTRIBUTE_TYPE usage,
|
||||
- CK_OBJECT_HANDLE *objp);
|
||||
+static krb5_error_code
|
||||
+pkinit_find_private_key(krb5_context context,
|
||||
+ pkinit_identity_crypto_context id_cryptoctx,
|
||||
+ CK_ATTRIBUTE_TYPE usage,
|
||||
+ CK_OBJECT_HANDLE *objp);
|
||||
static krb5_error_code pkinit_login
|
||||
(krb5_context context, pkinit_identity_crypto_context id_cryptoctx,
|
||||
CK_TOKEN_INFO *tip, const char *password);
|
||||
@@ -180,6 +182,8 @@ static krb5_error_code pkinit_sign_data_pkcs11
|
||||
(krb5_context context, pkinit_identity_crypto_context id_cryptoctx,
|
||||
unsigned char *data, unsigned int data_len,
|
||||
unsigned char **sig, unsigned int *sig_len);
|
||||
+
|
||||
+static krb5_error_code p11err(krb5_context context, CK_RV rv, const char *op);
|
||||
#endif /* WITHOUT_PKCS11 */
|
||||
|
||||
static krb5_error_code pkinit_sign_data_fs
|
||||
@@ -197,9 +201,6 @@ create_krb5_invalidCertificates(krb5_context context,
|
||||
static krb5_error_code
|
||||
create_identifiers_from_stack(STACK_OF(X509) *sk,
|
||||
krb5_external_principal_identifier *** ids);
|
||||
-static const char *
|
||||
-pkcs11err(int err);
|
||||
-
|
||||
|
||||
#if OPENSSL_VERSION_NUMBER < 0x10100000L
|
||||
|
||||
@@ -944,8 +945,9 @@ cleanup:
|
||||
|
||||
#endif /* OPENSSL_VERSION_NUMBER < 0x30000000L */
|
||||
|
||||
+#ifndef WITHOUT_PKC11
|
||||
static struct pkcs11_errstrings {
|
||||
- short code;
|
||||
+ CK_RV code;
|
||||
char *text;
|
||||
} pkcs11_errstrings[] = {
|
||||
{ 0x0, "ok" },
|
||||
@@ -1035,6 +1037,7 @@ static struct pkcs11_errstrings {
|
||||
{ 0x200, "function rejected" },
|
||||
{ -1, NULL }
|
||||
};
|
||||
+#endif
|
||||
|
||||
MAKE_INIT_FUNCTION(pkinit_openssl_init);
|
||||
|
||||
@@ -1563,6 +1566,8 @@ pkinit_fini_pkcs11(pkinit_identity_crypto_context ctx)
|
||||
free(ctx->token_label);
|
||||
free(ctx->cert_id);
|
||||
free(ctx->cert_label);
|
||||
+ ctx->p11_module_name = ctx->token_label = ctx->cert_label = NULL;
|
||||
+ ctx->cert_id = NULL;
|
||||
#endif
|
||||
}
|
||||
|
||||
@@ -3344,48 +3349,53 @@ pkinit_pkcs7type2oid(pkinit_plg_crypto_context cryptoctx, int pkcs7_type)
|
||||
}
|
||||
|
||||
#ifndef WITHOUT_PKCS11
|
||||
-static struct plugin_file_handle *
|
||||
+static krb5_error_code
|
||||
load_pkcs11_module(krb5_context context, const char *modname,
|
||||
- CK_FUNCTION_LIST_PTR_PTR p11p)
|
||||
+ struct plugin_file_handle **handle_out,
|
||||
+ CK_FUNCTION_LIST_PTR_PTR p11_out)
|
||||
{
|
||||
struct plugin_file_handle *handle = NULL;
|
||||
- CK_RV (*getflist)(CK_FUNCTION_LIST_PTR_PTR);
|
||||
+ CK_RV rv, (*getflist)(CK_FUNCTION_LIST_PTR_PTR);
|
||||
struct errinfo einfo = EMPTY_ERRINFO;
|
||||
- const char *errmsg = NULL;
|
||||
+ const char *errmsg = NULL, *failure;
|
||||
void (*sym)(void);
|
||||
long err;
|
||||
- CK_RV rv;
|
||||
|
||||
TRACE_PKINIT_PKCS11_OPEN(context, modname);
|
||||
err = krb5int_open_plugin(modname, &handle, &einfo);
|
||||
if (err) {
|
||||
- errmsg = k5_get_error(&einfo, err);
|
||||
- TRACE_PKINIT_PKCS11_OPEN_FAILED(context, errmsg);
|
||||
+ failure = _("Cannot load PKCS11 module");
|
||||
goto error;
|
||||
}
|
||||
|
||||
err = krb5int_get_plugin_func(handle, "C_GetFunctionList", &sym, &einfo);
|
||||
if (err) {
|
||||
- errmsg = k5_get_error(&einfo, err);
|
||||
- TRACE_PKINIT_PKCS11_GETSYM_FAILED(context, errmsg);
|
||||
+ failure = _("Cannot find C_GetFunctionList in PKCS11 module");
|
||||
goto error;
|
||||
}
|
||||
|
||||
getflist = (CK_RV (*)(CK_FUNCTION_LIST_PTR_PTR))sym;
|
||||
- rv = (*getflist)(p11p);
|
||||
+ rv = (*getflist)(p11_out);
|
||||
if (rv != CKR_OK) {
|
||||
- TRACE_PKINIT_PKCS11_GETFLIST_FAILED(context, pkcs11err(rv));
|
||||
+ failure = _("Cannot retrieve function list in PKCS11 module");
|
||||
goto error;
|
||||
}
|
||||
|
||||
- return handle;
|
||||
+ *handle_out = handle;
|
||||
+ return 0;
|
||||
|
||||
error:
|
||||
- k5_free_error(&einfo, errmsg);
|
||||
+ if (err) {
|
||||
+ errmsg = k5_get_error(&einfo, err);
|
||||
+ k5_setmsg(context, err, _("%s: %s"), failure, errmsg);
|
||||
+ } else {
|
||||
+ err = KRB5KDC_ERR_PREAUTH_FAILED;
|
||||
+ k5_setmsg(context, err, "%s", failure);
|
||||
+ }
|
||||
k5_clear_error(&einfo);
|
||||
if (handle != NULL)
|
||||
krb5int_close_plugin(handle);
|
||||
- return NULL;
|
||||
+ return err;
|
||||
}
|
||||
|
||||
static krb5_error_code
|
||||
@@ -3393,12 +3403,13 @@ pkinit_login(krb5_context context,
|
||||
pkinit_identity_crypto_context id_cryptoctx,
|
||||
CK_TOKEN_INFO *tip, const char *password)
|
||||
{
|
||||
+ krb5_error_code ret = 0;
|
||||
+ CK_RV rv;
|
||||
krb5_data rdat;
|
||||
char *prompt;
|
||||
const char *warning;
|
||||
krb5_prompt kprompt;
|
||||
krb5_prompt_type prompt_type;
|
||||
- int r = 0;
|
||||
|
||||
if (tip->flags & CKF_PROTECTED_AUTHENTICATION_PATH) {
|
||||
rdat.data = NULL;
|
||||
@@ -3407,7 +3418,7 @@ pkinit_login(krb5_context context,
|
||||
rdat.data = strdup(password);
|
||||
rdat.length = strlen(password);
|
||||
} else if (id_cryptoctx->prompter == NULL) {
|
||||
- r = KRB5_LIBOS_CANTREADPWD;
|
||||
+ ret = KRB5_LIBOS_CANTREADPWD;
|
||||
rdat.data = NULL;
|
||||
} else {
|
||||
if (tip->flags & CKF_USER_PIN_LOCKED)
|
||||
@@ -3431,31 +3442,28 @@ pkinit_login(krb5_context context,
|
||||
|
||||
/* PROMPTER_INVOCATION */
|
||||
k5int_set_prompt_types(context, &prompt_type);
|
||||
- r = (*id_cryptoctx->prompter)(context, id_cryptoctx->prompter_data,
|
||||
- NULL, NULL, 1, &kprompt);
|
||||
+ ret = (*id_cryptoctx->prompter)(context, id_cryptoctx->prompter_data,
|
||||
+ NULL, NULL, 1, &kprompt);
|
||||
k5int_set_prompt_types(context, 0);
|
||||
free(prompt);
|
||||
}
|
||||
|
||||
- if (r == 0) {
|
||||
- r = id_cryptoctx->p11->C_Login(id_cryptoctx->session, CKU_USER,
|
||||
- (u_char *) rdat.data, rdat.length);
|
||||
-
|
||||
- if (r != CKR_OK) {
|
||||
- TRACE_PKINIT_PKCS11_LOGIN_FAILED(context, pkcs11err(r));
|
||||
- r = KRB5KDC_ERR_PREAUTH_FAILED;
|
||||
- }
|
||||
+ if (!ret) {
|
||||
+ rv = id_cryptoctx->p11->C_Login(id_cryptoctx->session, CKU_USER,
|
||||
+ (uint8_t *)rdat.data, rdat.length);
|
||||
+ if (rv != CKR_OK)
|
||||
+ ret = p11err(context, rv, "C_Login");
|
||||
}
|
||||
free(rdat.data);
|
||||
|
||||
- return r;
|
||||
+ return ret;
|
||||
}
|
||||
|
||||
static krb5_error_code
|
||||
pkinit_open_session(krb5_context context,
|
||||
pkinit_identity_crypto_context cctx)
|
||||
{
|
||||
- CK_ULONG i, pret;
|
||||
+ CK_ULONG i, rv;
|
||||
unsigned char *cp;
|
||||
size_t label_len;
|
||||
CK_ULONG count = 0;
|
||||
@@ -3469,30 +3477,35 @@ pkinit_open_session(krb5_context context,
|
||||
return 0; /* session already open */
|
||||
|
||||
/* Load module */
|
||||
- cctx->p11_module = load_pkcs11_module(context, cctx->p11_module_name,
|
||||
- &cctx->p11);
|
||||
- if (cctx->p11_module == NULL)
|
||||
- return KRB5KDC_ERR_PREAUTH_FAILED;
|
||||
+ ret = load_pkcs11_module(context, cctx->p11_module_name, &cctx->p11_module,
|
||||
+ &cctx->p11);
|
||||
+ if (ret)
|
||||
+ goto cleanup;
|
||||
|
||||
/* Init */
|
||||
- pret = cctx->p11->C_Initialize(NULL);
|
||||
- if (pret != CKR_OK) {
|
||||
- pkiDebug("C_Initialize: %s\n", pkcs11err(pret));
|
||||
- return KRB5KDC_ERR_PREAUTH_FAILED;
|
||||
+ rv = cctx->p11->C_Initialize(NULL);
|
||||
+ if (rv != CKR_OK) {
|
||||
+ ret = p11err(context, rv, "C_Initialize");
|
||||
+ goto cleanup;
|
||||
}
|
||||
|
||||
/* Get the list of available slots */
|
||||
- if (cctx->p11->C_GetSlotList(TRUE, NULL, &count) != CKR_OK)
|
||||
- return KRB5KDC_ERR_PREAUTH_FAILED;
|
||||
+ rv = cctx->p11->C_GetSlotList(TRUE, NULL, &count);
|
||||
+ if (rv != CKR_OK) {
|
||||
+ ret = p11err(context, rv, "C_GetSlotList");
|
||||
+ goto cleanup;
|
||||
+ }
|
||||
if (count == 0) {
|
||||
TRACE_PKINIT_PKCS11_NO_TOKEN(context);
|
||||
- return KRB5KDC_ERR_PREAUTH_FAILED;
|
||||
+ ret = KRB5KDC_ERR_PREAUTH_FAILED;
|
||||
+ goto cleanup;
|
||||
}
|
||||
- slotlist = calloc(count, sizeof(CK_SLOT_ID));
|
||||
+ slotlist = k5calloc(count, sizeof(CK_SLOT_ID), &ret);
|
||||
if (slotlist == NULL)
|
||||
- return ENOMEM;
|
||||
- if (cctx->p11->C_GetSlotList(TRUE, slotlist, &count) != CKR_OK) {
|
||||
- ret = KRB5KDC_ERR_PREAUTH_FAILED;
|
||||
+ goto cleanup;
|
||||
+ rv = cctx->p11->C_GetSlotList(TRUE, slotlist, &count);
|
||||
+ if (rv != CKR_OK) {
|
||||
+ ret = p11err(context, rv, "C_GetSlotList");
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
@@ -3503,19 +3516,17 @@ pkinit_open_session(krb5_context context,
|
||||
continue;
|
||||
|
||||
/* Open session */
|
||||
- pret = cctx->p11->C_OpenSession(slotlist[i], CKF_SERIAL_SESSION,
|
||||
- NULL, NULL, &cctx->session);
|
||||
- if (pret != CKR_OK) {
|
||||
- pkiDebug("C_OpenSession: %s\n", pkcs11err(pret));
|
||||
- ret = KRB5KDC_ERR_PREAUTH_FAILED;
|
||||
+ rv = cctx->p11->C_OpenSession(slotlist[i], CKF_SERIAL_SESSION,
|
||||
+ NULL, NULL, &cctx->session);
|
||||
+ if (rv != CKR_OK) {
|
||||
+ ret = p11err(context, rv, "C_OpenSession");
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
/* Get token info */
|
||||
- pret = cctx->p11->C_GetTokenInfo(slotlist[i], &tinfo);
|
||||
- if (pret != CKR_OK) {
|
||||
- pkiDebug("C_GetTokenInfo: %s\n", pkcs11err(pret));
|
||||
- ret = KRB5KDC_ERR_PREAUTH_FAILED;
|
||||
+ rv = cctx->p11->C_GetTokenInfo(slotlist[i], &tinfo);
|
||||
+ if (rv != CKR_OK) {
|
||||
+ ret = p11err(context, rv, "C_GetTokenInfo");
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
@@ -3577,6 +3588,10 @@ pkinit_open_session(krb5_context context,
|
||||
|
||||
ret = 0;
|
||||
cleanup:
|
||||
+ /* On error, finalize the PKCS11 fields to ensure that we don't mistakenly
|
||||
+ * short-circuit with success on the next call. */
|
||||
+ if (ret)
|
||||
+ pkinit_fini_pkcs11(cctx);
|
||||
free(slotlist);
|
||||
free(p11name);
|
||||
return ret;
|
||||
@@ -3598,16 +3613,17 @@ cleanup:
|
||||
* If there are more than one, we just take the first one.
|
||||
*/
|
||||
|
||||
-krb5_error_code
|
||||
-pkinit_find_private_key(pkinit_identity_crypto_context id_cryptoctx,
|
||||
+static krb5_error_code
|
||||
+pkinit_find_private_key(krb5_context context,
|
||||
+ pkinit_identity_crypto_context id_cryptoctx,
|
||||
CK_ATTRIBUTE_TYPE usage,
|
||||
CK_OBJECT_HANDLE *objp)
|
||||
{
|
||||
CK_OBJECT_CLASS cls;
|
||||
CK_ATTRIBUTE attrs[4];
|
||||
CK_ULONG count;
|
||||
+ CK_RV rv;
|
||||
unsigned int nattrs = 0;
|
||||
- int r;
|
||||
#ifdef PKINIT_USE_KEY_USAGE
|
||||
CK_BBOOL true_false;
|
||||
#endif
|
||||
@@ -3637,18 +3653,21 @@ pkinit_find_private_key(pkinit_identity_crypto_context id_cryptoctx,
|
||||
attrs[nattrs].ulValueLen = id_cryptoctx->cert_id_len;
|
||||
nattrs++;
|
||||
|
||||
- r = id_cryptoctx->p11->C_FindObjectsInit(id_cryptoctx->session, attrs, nattrs);
|
||||
- if (r != CKR_OK) {
|
||||
- pkiDebug("krb5_pkinit_sign_data: C_FindObjectsInit: %s\n",
|
||||
- pkcs11err(r));
|
||||
- return KRB5KDC_ERR_PREAUTH_FAILED;
|
||||
- }
|
||||
+ rv = id_cryptoctx->p11->C_FindObjectsInit(id_cryptoctx->session, attrs,
|
||||
+ nattrs);
|
||||
+ if (rv != CKR_OK)
|
||||
+ return p11err(context, rv, _("C_FindObjectsInit"));
|
||||
|
||||
- r = id_cryptoctx->p11->C_FindObjects(id_cryptoctx->session, objp, 1, &count);
|
||||
+ rv = id_cryptoctx->p11->C_FindObjects(id_cryptoctx->session, objp, 1,
|
||||
+ &count);
|
||||
id_cryptoctx->p11->C_FindObjectsFinal(id_cryptoctx->session);
|
||||
- pkiDebug("found %d private keys (%s)\n", (int)count, pkcs11err(r));
|
||||
- if (r != CKR_OK || count < 1)
|
||||
+ if (rv != CKR_OK)
|
||||
+ return p11err(context, rv, _("C_FindObjects"));
|
||||
+ if (count < 1) {
|
||||
+ k5_setmsg(context, KRB5KDC_ERR_PREAUTH_FAILED,
|
||||
+ _("Found no private keys in PKCS11 token"));
|
||||
return KRB5KDC_ERR_PREAUTH_FAILED;
|
||||
+ }
|
||||
return 0;
|
||||
}
|
||||
#endif
|
||||
@@ -3796,34 +3815,32 @@ pkinit_sign_data_pkcs11(krb5_context context,
|
||||
CK_FUNCTION_LIST_PTR p11;
|
||||
CK_ATTRIBUTE attr;
|
||||
CK_KEY_TYPE keytype;
|
||||
+ CK_RV rv;
|
||||
EVP_MD_CTX *ctx;
|
||||
const EVP_MD *md = EVP_sha256();
|
||||
unsigned int mdlen;
|
||||
uint8_t mdbuf[EVP_MAX_MD_SIZE], *dinfo = NULL, *sigbuf = NULL, *input;
|
||||
size_t dinfo_len, input_len;
|
||||
- int r;
|
||||
|
||||
*sig = NULL;
|
||||
*sig_len = 0;
|
||||
|
||||
- if (pkinit_open_session(context, id_cryptoctx)) {
|
||||
- pkiDebug("can't open pkcs11 session\n");
|
||||
- return KRB5KDC_ERR_PREAUTH_FAILED;
|
||||
- }
|
||||
+ ret = pkinit_open_session(context, id_cryptoctx);
|
||||
+ if (ret)
|
||||
+ return ret;
|
||||
p11 = id_cryptoctx->p11;
|
||||
session = id_cryptoctx->session;
|
||||
|
||||
- ret = pkinit_find_private_key(id_cryptoctx, CKA_SIGN, &obj);
|
||||
+ ret = pkinit_find_private_key(context, id_cryptoctx, CKA_SIGN, &obj);
|
||||
if (ret)
|
||||
return ret;
|
||||
|
||||
attr.type = CKA_KEY_TYPE;
|
||||
attr.pValue = &keytype;
|
||||
attr.ulValueLen = sizeof(keytype);
|
||||
- r = p11->C_GetAttributeValue(session, obj, &attr, 1);
|
||||
- if (r) {
|
||||
- pkiDebug("C_GetAttributeValue: %s\n", pkcs11err(r));
|
||||
- ret = KRB5KDC_ERR_PREAUTH_FAILED;
|
||||
+ rv = p11->C_GetAttributeValue(session, obj, &attr, 1);
|
||||
+ if (rv != CKR_OK) {
|
||||
+ ret = p11err(context, rv, "C_GetAttributeValue");
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
@@ -3865,10 +3882,9 @@ pkinit_sign_data_pkcs11(krb5_context context,
|
||||
mech.pParameter = NULL;
|
||||
mech.ulParameterLen = 0;
|
||||
|
||||
- r = p11->C_SignInit(session, &mech, obj);
|
||||
- if (r != CKR_OK) {
|
||||
- pkiDebug("C_SignInit: %s\n", pkcs11err(r));
|
||||
- ret = KRB5KDC_ERR_PREAUTH_FAILED;
|
||||
+ rv = p11->C_SignInit(session, &mech, obj);
|
||||
+ if (rv != CKR_OK) {
|
||||
+ ret = p11err(context, rv, "C_SignInit");
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
@@ -3881,18 +3897,17 @@ pkinit_sign_data_pkcs11(krb5_context context,
|
||||
if (sigbuf == NULL)
|
||||
goto cleanup;
|
||||
|
||||
- r = p11->C_Sign(session, input, input_len, sigbuf, &len);
|
||||
- if (r == CKR_BUFFER_TOO_SMALL || (r == CKR_OK && len >= PK_SIGLEN_GUESS)) {
|
||||
+ rv = p11->C_Sign(session, input, input_len, sigbuf, &len);
|
||||
+ if (rv == CKR_BUFFER_TOO_SMALL ||
|
||||
+ (rv == CKR_OK && len >= PK_SIGLEN_GUESS)) {
|
||||
free(sigbuf);
|
||||
- pkiDebug("C_Sign realloc %d\n", (int) len);
|
||||
sigbuf = k5alloc(len, &ret);
|
||||
if (sigbuf == NULL)
|
||||
goto cleanup;
|
||||
- r = p11->C_Sign(session, input, input_len, sigbuf, &len);
|
||||
+ rv = p11->C_Sign(session, input, input_len, sigbuf, &len);
|
||||
}
|
||||
- if (r != CKR_OK) {
|
||||
- pkiDebug("C_Sign: %s\n", pkcs11err(r));
|
||||
- ret = KRB5KDC_ERR_PREAUTH_FAILED;
|
||||
+ if (rv != CKR_OK) {
|
||||
+ ret = p11err(context, rv, "C_Sign");
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
@@ -4348,13 +4363,14 @@ reassemble_pkcs11_name(pkinit_identity_opts *idopts)
|
||||
}
|
||||
|
||||
static krb5_error_code
|
||||
-load_one_cert(CK_FUNCTION_LIST_PTR p11, CK_SESSION_HANDLE session,
|
||||
- pkinit_identity_opts *idopts, pkinit_cred_info *cred_out)
|
||||
+load_one_cert(krb5_context context, CK_FUNCTION_LIST_PTR p11,
|
||||
+ CK_SESSION_HANDLE session, pkinit_identity_opts *idopts,
|
||||
+ pkinit_cred_info *cred_out)
|
||||
{
|
||||
krb5_error_code ret;
|
||||
CK_ATTRIBUTE attrs[2];
|
||||
CK_BYTE_PTR cert = NULL, cert_id = NULL;
|
||||
- CK_RV pret;
|
||||
+ CK_RV rv;
|
||||
const unsigned char *cp;
|
||||
CK_OBJECT_HANDLE obj;
|
||||
CK_ULONG count;
|
||||
@@ -4364,8 +4380,8 @@ load_one_cert(CK_FUNCTION_LIST_PTR p11, CK_SESSION_HANDLE session,
|
||||
*cred_out = NULL;
|
||||
|
||||
/* Look for X.509 cert. */
|
||||
- pret = p11->C_FindObjects(session, &obj, 1, &count);
|
||||
- if (pret != CKR_OK || count <= 0)
|
||||
+ rv = p11->C_FindObjects(session, &obj, 1, &count);
|
||||
+ if (rv != CKR_OK || count <= 0)
|
||||
return 0;
|
||||
|
||||
/* Get cert and id len. */
|
||||
@@ -4375,10 +4391,9 @@ load_one_cert(CK_FUNCTION_LIST_PTR p11, CK_SESSION_HANDLE session,
|
||||
attrs[1].type = CKA_ID;
|
||||
attrs[1].pValue = NULL;
|
||||
attrs[1].ulValueLen = 0;
|
||||
- pret = p11->C_GetAttributeValue(session, obj, attrs, 2);
|
||||
- if (pret != CKR_OK && pret != CKR_BUFFER_TOO_SMALL) {
|
||||
- pkiDebug("C_GetAttributeValue: %s\n", pkcs11err(pret));
|
||||
- ret = KRB5KDC_ERR_PREAUTH_FAILED;
|
||||
+ rv = p11->C_GetAttributeValue(session, obj, attrs, 2);
|
||||
+ if (rv != CKR_OK && rv != CKR_BUFFER_TOO_SMALL) {
|
||||
+ ret = p11err(context, rv, "C_GetAttributeValue");
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
@@ -4393,10 +4408,9 @@ load_one_cert(CK_FUNCTION_LIST_PTR p11, CK_SESSION_HANDLE session,
|
||||
attrs[0].pValue = cert;
|
||||
attrs[1].type = CKA_ID;
|
||||
attrs[1].pValue = cert_id;
|
||||
- pret = p11->C_GetAttributeValue(session, obj, attrs, 2);
|
||||
- if (pret != CKR_OK) {
|
||||
- pkiDebug("C_GetAttributeValue: %s\n", pkcs11err(pret));
|
||||
- ret = KRB5KDC_ERR_PREAUTH_FAILED;
|
||||
+ rv = p11->C_GetAttributeValue(session, obj, attrs, 2);
|
||||
+ if (rv != CKR_OK) {
|
||||
+ ret = p11err(context, rv, "C_GetAttributeValue");
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
@@ -4406,7 +4420,8 @@ load_one_cert(CK_FUNCTION_LIST_PTR p11, CK_SESSION_HANDLE session,
|
||||
cp = (unsigned char *)cert;
|
||||
x = d2i_X509(NULL, &cp, (int)attrs[0].ulValueLen);
|
||||
if (x == NULL) {
|
||||
- ret = KRB5KDC_ERR_PREAUTH_FAILED;
|
||||
+ ret = oerr(context, 0,
|
||||
+ _("Failed to decode X509 certificate from PKCS11 token"));
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
@@ -4444,7 +4459,7 @@ pkinit_get_certs_pkcs11(krb5_context context,
|
||||
int i;
|
||||
unsigned int nattrs;
|
||||
krb5_error_code ret;
|
||||
- CK_RV pret;
|
||||
+ CK_RV rv;
|
||||
|
||||
/* Copy stuff from idopts -> id_cryptoctx */
|
||||
if (idopts->p11_module_name != NULL) {
|
||||
@@ -4516,16 +4531,16 @@ pkinit_get_certs_pkcs11(krb5_context context,
|
||||
nattrs++;
|
||||
}
|
||||
|
||||
- pret = id_cryptoctx->p11->C_FindObjectsInit(id_cryptoctx->session, attrs,
|
||||
- nattrs);
|
||||
- if (pret != CKR_OK) {
|
||||
- pkiDebug("C_FindObjectsInit: %s\n", pkcs11err(pret));
|
||||
+ rv = id_cryptoctx->p11->C_FindObjectsInit(id_cryptoctx->session, attrs,
|
||||
+ nattrs);
|
||||
+ if (rv != CKR_OK) {
|
||||
+ ret = p11err(context, rv, "C_FindObjectsInit");
|
||||
return KRB5KDC_ERR_PREAUTH_FAILED;
|
||||
}
|
||||
|
||||
for (i = 0; i < MAX_CREDS_ALLOWED; i++) {
|
||||
- ret = load_one_cert(id_cryptoctx->p11, id_cryptoctx->session, idopts,
|
||||
- &id_cryptoctx->creds[i]);
|
||||
+ ret = load_one_cert(context, id_cryptoctx->p11, id_cryptoctx->session,
|
||||
+ idopts, &id_cryptoctx->creds[i]);
|
||||
if (ret)
|
||||
return ret;
|
||||
if (id_cryptoctx->creds[i] == NULL)
|
||||
@@ -5510,19 +5525,26 @@ print_pubkey(BIGNUM * key, char *msg)
|
||||
}
|
||||
#endif
|
||||
|
||||
-static const char *
|
||||
-pkcs11err(int err)
|
||||
+#ifndef WITHOUT_PKCS11
|
||||
+static krb5_error_code
|
||||
+p11err(krb5_context context, CK_RV rv, const char *op)
|
||||
{
|
||||
+ krb5_error_code code = KRB5KDC_ERR_PREAUTH_FAILED;
|
||||
int i;
|
||||
+ const char *msg;
|
||||
|
||||
- for (i = 0; pkcs11_errstrings[i].text != NULL; i++)
|
||||
- if (pkcs11_errstrings[i].code == err)
|
||||
+ for (i = 0; pkcs11_errstrings[i].text != NULL; i++) {
|
||||
+ if (pkcs11_errstrings[i].code == rv)
|
||||
break;
|
||||
- if (pkcs11_errstrings[i].text != NULL)
|
||||
- return (pkcs11_errstrings[i].text);
|
||||
+ }
|
||||
+ msg = pkcs11_errstrings[i].text;
|
||||
+ if (msg == NULL)
|
||||
+ msg = "unknown PKCS11 error";
|
||||
|
||||
- return "unknown PKCS11 error";
|
||||
+ krb5_set_error_message(context, code, _("PKCS11 error (%s): %s"), op, msg);
|
||||
+ return code;
|
||||
}
|
||||
+#endif
|
||||
|
||||
/*
|
||||
* Add an item to the pkinit_identity_crypto_context's list of deferred
|
||||
diff --git a/src/plugins/preauth/pkinit/pkinit_trace.h b/src/plugins/preauth/pkinit/pkinit_trace.h
|
||||
index 1c1ceb5a41..1faa6816d7 100644
|
||||
--- a/src/plugins/preauth/pkinit/pkinit_trace.h
|
||||
+++ b/src/plugins/preauth/pkinit/pkinit_trace.h
|
||||
@@ -98,21 +98,12 @@
|
||||
#define TRACE_PKINIT_OPENSSL_ERROR(c, msg) \
|
||||
TRACE(c, "PKINIT OpenSSL error: {str}", msg)
|
||||
|
||||
-#define TRACE_PKINIT_PKCS11_GETFLIST_FAILED(c, errstr) \
|
||||
- TRACE(c, "PKINIT PKCS11 C_GetFunctionList failed: {str}", errstr)
|
||||
-#define TRACE_PKINIT_PKCS11_GETSYM_FAILED(c, errstr) \
|
||||
- TRACE(c, "PKINIT unable to find PKCS11 plugin symbol " \
|
||||
- "C_GetFunctionList: {str}", errstr)
|
||||
-#define TRACE_PKINIT_PKCS11_LOGIN_FAILED(c, errstr) \
|
||||
- TRACE(c, "PKINIT PKCS11 C_Login failed: {str}", errstr)
|
||||
#define TRACE_PKINIT_PKCS11_NO_MATCH_TOKEN(c) \
|
||||
TRACE(c, "PKINIT PKCS#11 module has no matching tokens")
|
||||
#define TRACE_PKINIT_PKCS11_NO_TOKEN(c) \
|
||||
TRACE(c, "PKINIT PKCS#11 module shows no slots with tokens")
|
||||
#define TRACE_PKINIT_PKCS11_OPEN(c, name) \
|
||||
TRACE(c, "PKINIT opening PKCS#11 module \"{str}\"", name)
|
||||
-#define TRACE_PKINIT_PKCS11_OPEN_FAILED(c, errstr) \
|
||||
- TRACE(c, "PKINIT PKCS#11 module open failed: {str}", errstr)
|
||||
#define TRACE_PKINIT_PKCS11_SLOT(c, slot, len, label) \
|
||||
TRACE(c, "PKINIT PKCS#11 slotid {int} token {lenstr}", \
|
||||
slot, len, label)
|
||||
--
|
||||
2.47.1
|
||||
|
||||
|
|
@ -1,61 +0,0 @@
|
|||
From 946f7dba8cea3d2ed0e68c5e7594cbd7e1364609 Mon Sep 17 00:00:00 2001
|
||||
From: Julien Rische <jrische@redhat.com>
|
||||
Date: Thu, 1 Aug 2024 10:56:07 +0200
|
||||
Subject: [PATCH] Set missing mask flags for kdb5_util operations
|
||||
|
||||
Set KADM5_TL_DATA for the use_mkey and update_princ_encryption
|
||||
commands. (Commit c877f13c8985d820583b0d7ac1bb4c5dc36e677e did this
|
||||
for the add_new_mkey and purge_mkeys commands.) Set appropriate flags
|
||||
for the add_random_key command.
|
||||
|
||||
[ghudson@mit.edu: combined two commits; pruned out proposed mask flag
|
||||
additions for values represented within key data or tl-data (like
|
||||
KADM5_MKVNO), as those flags are currently only used in the kadm5
|
||||
protocol, not to communicate with the KDB module]
|
||||
|
||||
ticket: 9158 (new)
|
||||
(cherry picked from commit 4ed7da378940198cf4415f86d4eb013de6ac6455)
|
||||
---
|
||||
src/kadmin/dbutil/kdb5_mkey.c | 4 +++-
|
||||
src/kadmin/dbutil/kdb5_util.c | 3 +++
|
||||
2 files changed, 6 insertions(+), 1 deletion(-)
|
||||
|
||||
diff --git a/src/kadmin/dbutil/kdb5_mkey.c b/src/kadmin/dbutil/kdb5_mkey.c
|
||||
index aceb0a9b80..ac5c51d05e 100644
|
||||
--- a/src/kadmin/dbutil/kdb5_mkey.c
|
||||
+++ b/src/kadmin/dbutil/kdb5_mkey.c
|
||||
@@ -525,6 +525,8 @@ kdb5_use_mkey(int argc, char *argv[])
|
||||
goto cleanup_return;
|
||||
}
|
||||
|
||||
+ master_entry->mask |= KADM5_TL_DATA;
|
||||
+
|
||||
if ((retval = krb5_db_put_principal(util_context, master_entry))) {
|
||||
com_err(progname, retval,
|
||||
_("while adding master key entry to the database"));
|
||||
@@ -814,7 +816,7 @@ update_princ_encryption_1(void *cb, krb5_db_entry *ent)
|
||||
goto fail;
|
||||
}
|
||||
|
||||
- ent->mask |= KADM5_KEY_DATA;
|
||||
+ ent->mask |= KADM5_KEY_DATA | KADM5_TL_DATA;
|
||||
|
||||
if ((retval = krb5_db_put_principal(util_context, ent))) {
|
||||
com_err(progname, retval, _("while updating principal '%s' key data "
|
||||
diff --git a/src/kadmin/dbutil/kdb5_util.c b/src/kadmin/dbutil/kdb5_util.c
|
||||
index 55d529fa4c..afc817891b 100644
|
||||
--- a/src/kadmin/dbutil/kdb5_util.c
|
||||
+++ b/src/kadmin/dbutil/kdb5_util.c
|
||||
@@ -600,6 +600,9 @@ add_random_key(int argc, char **argv)
|
||||
exit_status++;
|
||||
return;
|
||||
}
|
||||
+
|
||||
+ dbent->mask |= KADM5_ATTRIBUTES | KADM5_KEY_DATA | KADM5_TL_DATA;
|
||||
+
|
||||
ret = krb5_db_put_principal(util_context, dbent);
|
||||
krb5_db_free_principal(util_context, dbent);
|
||||
if (ret) {
|
||||
--
|
||||
2.47.1
|
||||
|
||||
|
|
@ -1,64 +0,0 @@
|
|||
From 9b669dd42b28e7900f5ccac2816204e7d04ea23c Mon Sep 17 00:00:00 2001
|
||||
From: Zoltan Borbely <Zoltan.Borbely@morganstanley.com>
|
||||
Date: Tue, 28 Jan 2025 16:39:25 -0500
|
||||
Subject: [PATCH] Prevent overflow when calculating ulog block size
|
||||
|
||||
In kdb_log.c:resize(), log an error and fail if the update size is
|
||||
larger than the largest possible block size (2^16-1).
|
||||
|
||||
CVE-2025-24528:
|
||||
|
||||
In MIT krb5 release 1.7 and later with incremental propagation
|
||||
enabled, an authenticated attacker can cause kadmind to write beyond
|
||||
the end of the mapped region for the iprop log file, likely causing a
|
||||
process crash.
|
||||
|
||||
[ghudson@mit.edu: edited commit message and added CVE description]
|
||||
|
||||
ticket: 9159 (new)
|
||||
tags: pullup
|
||||
target_version: 1.21-next
|
||||
|
||||
(cherry picked from commit 78ceba024b64d49612375be4a12d1c066b0bfbd0)
|
||||
---
|
||||
src/lib/kdb/kdb_log.c | 10 ++++++++--
|
||||
1 file changed, 8 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/src/lib/kdb/kdb_log.c b/src/lib/kdb/kdb_log.c
|
||||
index e9b95fce59..c805ebd988 100644
|
||||
--- a/src/lib/kdb/kdb_log.c
|
||||
+++ b/src/lib/kdb/kdb_log.c
|
||||
@@ -183,7 +183,7 @@ extend_file_to(int fd, unsigned int new_size)
|
||||
*/
|
||||
static krb5_error_code
|
||||
resize(kdb_hlog_t *ulog, uint32_t ulogentries, int ulogfd,
|
||||
- unsigned int recsize)
|
||||
+ unsigned int recsize, const kdb_incr_update_t *upd)
|
||||
{
|
||||
unsigned int new_block, new_size;
|
||||
|
||||
@@ -195,6 +195,12 @@ resize(kdb_hlog_t *ulog, uint32_t ulogentries, int ulogfd,
|
||||
new_block *= ULOG_BLOCK;
|
||||
new_size += ulogentries * new_block;
|
||||
|
||||
+ if (new_block > UINT16_MAX) {
|
||||
+ syslog(LOG_ERR, _("ulog overflow caused by principal %.*s"),
|
||||
+ upd->kdb_princ_name.utf8str_t_len,
|
||||
+ upd->kdb_princ_name.utf8str_t_val);
|
||||
+ return KRB5_LOG_ERROR;
|
||||
+ }
|
||||
if (new_size > MAXLOGLEN)
|
||||
return KRB5_LOG_ERROR;
|
||||
|
||||
@@ -291,7 +297,7 @@ store_update(kdb_log_context *log_ctx, kdb_incr_update_t *upd)
|
||||
recsize = sizeof(kdb_ent_header_t) + upd_size;
|
||||
|
||||
if (recsize > ulog->kdb_block) {
|
||||
- retval = resize(ulog, ulogentries, log_ctx->ulogfd, recsize);
|
||||
+ retval = resize(ulog, ulogentries, log_ctx->ulogfd, recsize, upd);
|
||||
if (retval)
|
||||
return retval;
|
||||
}
|
||||
--
|
||||
2.48.1
|
||||
|
||||
|
|
@ -1,327 +0,0 @@
|
|||
From c617915958a5cb05463713adcf03b6a0e0512ac3 Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Fri, 16 Dec 2022 18:31:07 -0500
|
||||
Subject: [PATCH] Don't issue session keys with deprecated enctypes
|
||||
|
||||
A paper by Tom Tervoort noted that rc4-hmac pre-hashes the input for
|
||||
its checksum and GSS operations before applying HMAC, and is therefore
|
||||
potentially vulnerable to hash collision attacks if a protocol
|
||||
contains a restricted signing oracle.
|
||||
|
||||
In light of these potential attacks, begin the functional deprecation
|
||||
of DES3 and RC4 by disallowing their use as session key enctypes by
|
||||
default. Add the variables allow_des3 and allow_rc4 in case
|
||||
negotiability of these enctypes for session keys needs to be turned
|
||||
back on, with the expectation that in future releases the enctypes
|
||||
will be more comprehensively deprecated.
|
||||
|
||||
ticket: 9081
|
||||
(cherry picked from commit 1b57a4d134bbd0e7c52d5885a92eccc815726463)
|
||||
---
|
||||
doc/admin/conf_files/krb5_conf.rst | 12 ++++++++++++
|
||||
doc/admin/enctypes.rst | 23 +++++++++++++++++++---
|
||||
src/include/k5-int.h | 4 ++++
|
||||
src/kdc/kdc_util.c | 10 ++++++++++
|
||||
src/lib/krb5/krb/get_in_tkt.c | 31 +++++++++++++++++++-----------
|
||||
src/lib/krb5/krb/init_ctx.c | 10 ++++++++++
|
||||
src/tests/gssapi/t_enctypes.py | 5 +++--
|
||||
src/tests/t_etype_info.py | 5 +++--
|
||||
src/tests/t_sesskeynego.py | 28 +++++++++++++++++++++++++--
|
||||
src/util/k5test.py | 9 ++++++++-
|
||||
10 files changed, 116 insertions(+), 21 deletions(-)
|
||||
|
||||
diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst
|
||||
index dca52e1426..d51fd3ce7e 100644
|
||||
--- a/doc/admin/conf_files/krb5_conf.rst
|
||||
+++ b/doc/admin/conf_files/krb5_conf.rst
|
||||
@@ -95,6 +95,18 @@ Additionally, krb5.conf may include any of the relations described in
|
||||
|
||||
The libdefaults section may contain any of the following relations:
|
||||
|
||||
+**allow_des3**
|
||||
+ Permit the KDC to issue tickets with des3-cbc-sha1 session keys.
|
||||
+ In future releases, this flag will allow des3-cbc-sha1 to be used
|
||||
+ at all. The default value for this tag is false. (Added in
|
||||
+ release 1.21.)
|
||||
+
|
||||
+**allow_rc4**
|
||||
+ Permit the KDC to issue tickets with arcfour-hmac session keys.
|
||||
+ In future releases, this flag will allow arcfour-hmac to be used
|
||||
+ at all. The default value for this tag is false. (Added in
|
||||
+ release 1.21.)
|
||||
+
|
||||
**allow_weak_crypto**
|
||||
If this flag is set to false, then weak encryption types (as noted
|
||||
in :ref:`Encryption_types` in :ref:`kdc.conf(5)`) will be filtered
|
||||
diff --git a/doc/admin/enctypes.rst b/doc/admin/enctypes.rst
|
||||
index c4d5499d3b..2b4ed7da0b 100644
|
||||
--- a/doc/admin/enctypes.rst
|
||||
+++ b/doc/admin/enctypes.rst
|
||||
@@ -48,12 +48,15 @@ Session key selection
|
||||
The KDC chooses the session key enctype by taking the intersection of
|
||||
its **permitted_enctypes** list, the list of long-term keys for the
|
||||
most recent kvno of the service, and the client's requested list of
|
||||
-enctypes.
|
||||
+enctypes. Starting in krb5-1.21, all services are assumed to support
|
||||
+aes256-cts-hmac-sha1-96; also, des3-cbc-sha1 and arcfour-hmac session
|
||||
+keys will not be issued by default.
|
||||
|
||||
Starting in krb5-1.11, it is possible to set a string attribute on a
|
||||
service principal to control what session key enctypes the KDC may
|
||||
-issue for service tickets for that principal. See :ref:`set_string`
|
||||
-in :ref:`kadmin(1)` for details.
|
||||
+issue for service tickets for that principal, overriding the service's
|
||||
+long-term keys and the assumption of aes256-cts-hmac-sha1-96 support.
|
||||
+See :ref:`set_string` in :ref:`kadmin(1)` for details.
|
||||
|
||||
|
||||
Choosing enctypes for a service
|
||||
@@ -87,6 +90,20 @@ affect how enctypes are chosen.
|
||||
acceptable risk for your environment and the weak enctypes are
|
||||
required for backward compatibility.
|
||||
|
||||
+**allow_des3**
|
||||
+ was added in release 1.21 and defaults to *false*. Unless this
|
||||
+ flag is set to *true*, the KDC will not issue tickets with
|
||||
+ des3-cbc-sha1 session keys. In a future release, this flag will
|
||||
+ control whether des3-cbc-sha1 is permitted in similar fashion to
|
||||
+ weak enctypes.
|
||||
+
|
||||
+**allow_rc4**
|
||||
+ was added in release 1.21 and defaults to *false*. Unless this
|
||||
+ flag is set to *true*, the KDC will not issue tickets with
|
||||
+ arcfour-hmac session keys. In a future release, this flag will
|
||||
+ control whether arcfour-hmac is permitted in similar fashion to
|
||||
+ weak enctypes.
|
||||
+
|
||||
**permitted_enctypes**
|
||||
controls the set of enctypes that a service will permit for
|
||||
session keys and for ticket and authenticator encryption. The KDC
|
||||
diff --git a/src/include/k5-int.h b/src/include/k5-int.h
|
||||
index b7789a2dd8..d0a263aa7d 100644
|
||||
--- a/src/include/k5-int.h
|
||||
+++ b/src/include/k5-int.h
|
||||
@@ -181,6 +181,8 @@ typedef unsigned char u_char;
|
||||
* matches the variable name. Keep these alphabetized. */
|
||||
#define KRB5_CONF_ACL_FILE "acl_file"
|
||||
#define KRB5_CONF_ADMIN_SERVER "admin_server"
|
||||
+#define KRB5_CONF_ALLOW_DES3 "allow_des3"
|
||||
+#define KRB5_CONF_ALLOW_RC4 "allow_rc4"
|
||||
#define KRB5_CONF_ALLOW_WEAK_CRYPTO "allow_weak_crypto"
|
||||
#define KRB5_CONF_AUTH_TO_LOCAL "auth_to_local"
|
||||
#define KRB5_CONF_AUTH_TO_LOCAL_NAMES "auth_to_local_names"
|
||||
@@ -1241,6 +1243,8 @@ struct _krb5_context {
|
||||
struct _kdb_log_context *kdblog_context;
|
||||
|
||||
krb5_boolean allow_weak_crypto;
|
||||
+ krb5_boolean allow_des3;
|
||||
+ krb5_boolean allow_rc4;
|
||||
krb5_boolean ignore_acceptor_hostname;
|
||||
krb5_boolean enforce_ok_as_delegate;
|
||||
enum dns_canonhost dns_canonicalize_hostname;
|
||||
diff --git a/src/kdc/kdc_util.c b/src/kdc/kdc_util.c
|
||||
index 93415ba862..c7b6e4090d 100644
|
||||
--- a/src/kdc/kdc_util.c
|
||||
+++ b/src/kdc/kdc_util.c
|
||||
@@ -1108,6 +1108,16 @@ select_session_keytype(krb5_context context, krb5_db_entry *server,
|
||||
if (!krb5_is_permitted_enctype(context, ktype[i]))
|
||||
continue;
|
||||
|
||||
+ /*
|
||||
+ * Prevent these deprecated enctypes from being used as session keys
|
||||
+ * unless they are explicitly allowed. In the future they will be more
|
||||
+ * comprehensively disabled and eventually removed.
|
||||
+ */
|
||||
+ if (ktype[i] == ENCTYPE_DES3_CBC_SHA1 && !context->allow_des3)
|
||||
+ continue;
|
||||
+ if (ktype[i] == ENCTYPE_ARCFOUR_HMAC && !context->allow_rc4)
|
||||
+ continue;
|
||||
+
|
||||
if (dbentry_supports_enctype(context, server, ktype[i]))
|
||||
return ktype[i];
|
||||
}
|
||||
diff --git a/src/lib/krb5/krb/get_in_tkt.c b/src/lib/krb5/krb/get_in_tkt.c
|
||||
index 1b420a3ac2..ea089f0fcc 100644
|
||||
--- a/src/lib/krb5/krb/get_in_tkt.c
|
||||
+++ b/src/lib/krb5/krb/get_in_tkt.c
|
||||
@@ -1582,22 +1582,31 @@ warn_pw_expiry(krb5_context context, krb5_get_init_creds_opt *options,
|
||||
(*prompter)(context, data, 0, banner, 0, 0);
|
||||
}
|
||||
|
||||
-/* Display a warning via the prompter if des3-cbc-sha1 was used for either the
|
||||
- * reply key or the session key. */
|
||||
+/* Display a warning via the prompter if a deprecated enctype was used for
|
||||
+ * either the reply key or the session key. */
|
||||
static void
|
||||
-warn_des3(krb5_context context, krb5_init_creds_context ctx,
|
||||
- krb5_enctype as_key_enctype)
|
||||
+warn_deprecated(krb5_context context, krb5_init_creds_context ctx,
|
||||
+ krb5_enctype as_key_enctype)
|
||||
{
|
||||
- const char *banner;
|
||||
+ krb5_enctype etype;
|
||||
+ char encbuf[128], banner[256];
|
||||
|
||||
- if (as_key_enctype != ENCTYPE_DES3_CBC_SHA1 &&
|
||||
- ctx->cred.keyblock.enctype != ENCTYPE_DES3_CBC_SHA1)
|
||||
- return;
|
||||
if (ctx->prompter == NULL)
|
||||
return;
|
||||
|
||||
- banner = _("Warning: encryption type des3-cbc-sha1 used for "
|
||||
- "authentication is weak and will be disabled");
|
||||
+ if (krb5int_c_deprecated_enctype(as_key_enctype))
|
||||
+ etype = as_key_enctype;
|
||||
+ else if (krb5int_c_deprecated_enctype(ctx->cred.keyblock.enctype))
|
||||
+ etype = ctx->cred.keyblock.enctype;
|
||||
+ else
|
||||
+ return;
|
||||
+
|
||||
+ if (krb5_enctype_to_name(etype, FALSE, encbuf, sizeof(encbuf)) != 0)
|
||||
+ return;
|
||||
+ snprintf(banner, sizeof(banner),
|
||||
+ _("Warning: encryption type %s used for authentication is "
|
||||
+ "deprecated and will be disabled"), encbuf);
|
||||
+
|
||||
/* PROMPTER_INVOCATION */
|
||||
(*ctx->prompter)(context, ctx->prompter_data, NULL, banner, 0, NULL);
|
||||
}
|
||||
@@ -1848,7 +1857,7 @@ init_creds_step_reply(krb5_context context,
|
||||
ctx->complete = TRUE;
|
||||
warn_pw_expiry(context, ctx->opt, ctx->prompter, ctx->prompter_data,
|
||||
ctx->in_tkt_service, ctx->reply);
|
||||
- warn_des3(context, ctx, encrypting_key.enctype);
|
||||
+ warn_deprecated(context, ctx, encrypting_key.enctype);
|
||||
|
||||
cleanup:
|
||||
krb5_free_pa_data(context, kdc_padata);
|
||||
diff --git a/src/lib/krb5/krb/init_ctx.c b/src/lib/krb5/krb/init_ctx.c
|
||||
index 582a2945ff..a32f8dbf03 100644
|
||||
--- a/src/lib/krb5/krb/init_ctx.c
|
||||
+++ b/src/lib/krb5/krb/init_ctx.c
|
||||
@@ -220,6 +220,16 @@ krb5_init_context_profile(profile_t profile, krb5_flags flags,
|
||||
goto cleanup;
|
||||
ctx->allow_weak_crypto = tmp;
|
||||
|
||||
+ retval = get_boolean(ctx, KRB5_CONF_ALLOW_DES3, 0, &tmp);
|
||||
+ if (retval)
|
||||
+ goto cleanup;
|
||||
+ ctx->allow_des3 = tmp;
|
||||
+
|
||||
+ retval = get_boolean(ctx, KRB5_CONF_ALLOW_RC4, 0, &tmp);
|
||||
+ if (retval)
|
||||
+ goto cleanup;
|
||||
+ ctx->allow_rc4 = tmp;
|
||||
+
|
||||
retval = get_boolean(ctx, KRB5_CONF_IGNORE_ACCEPTOR_HOSTNAME, 0, &tmp);
|
||||
if (retval)
|
||||
goto cleanup;
|
||||
diff --git a/src/tests/gssapi/t_enctypes.py b/src/tests/gssapi/t_enctypes.py
|
||||
index 2f95d89967..e6bde47afc 100755
|
||||
--- a/src/tests/gssapi/t_enctypes.py
|
||||
+++ b/src/tests/gssapi/t_enctypes.py
|
||||
@@ -10,8 +10,9 @@ d_rc4 = 'DEPRECATED:arcfour-hmac'
|
||||
|
||||
# These tests make assumptions about the default enctype lists, so set
|
||||
# them explicitly rather than relying on the library defaults.
|
||||
-supp='aes256-cts:normal aes128-cts:normal rc4-hmac:normal'
|
||||
-conf = {'libdefaults': {'permitted_enctypes': 'aes rc4'},
|
||||
+supp='aes256-cts:normal aes128-cts:normal des3-cbc-sha1:normal rc4-hmac:normal'
|
||||
+conf = {'libdefaults': {'permitted_enctypes': 'aes des3 rc4',
|
||||
+ 'allow_des3': 'true', 'allow_rc4': 'true'},
|
||||
'realms': {'$realm': {'supported_enctypes': supp}}}
|
||||
realm = K5Realm(krb5_conf=conf)
|
||||
shutil.copyfile(realm.ccache, os.path.join(realm.testdir, 'save'))
|
||||
diff --git a/src/tests/t_etype_info.py b/src/tests/t_etype_info.py
|
||||
index a6f538b66d..75d9621dd6 100644
|
||||
--- a/src/tests/t_etype_info.py
|
||||
+++ b/src/tests/t_etype_info.py
|
||||
@@ -1,7 +1,8 @@
|
||||
from k5test import *
|
||||
|
||||
-supported_enctypes = 'aes128-cts rc4-hmac'
|
||||
-conf = {'realms': {'$realm': {'supported_enctypes': supported_enctypes}}}
|
||||
+supported_enctypes = 'aes128-cts des3-cbc-sha1 rc4-hmac'
|
||||
+conf = {'libdefaults': {'allow_des3': 'true', 'allow_rc4': 'true'},
|
||||
+ 'realms': {'$realm': {'supported_enctypes': supported_enctypes}}}
|
||||
realm = K5Realm(create_host=False, get_creds=False, krb5_conf=conf)
|
||||
|
||||
realm.run([kadminl, 'addprinc', '-pw', 'pw', '+requires_preauth',
|
||||
diff --git a/src/tests/t_sesskeynego.py b/src/tests/t_sesskeynego.py
|
||||
index 9024aee838..5a213617b5 100755
|
||||
--- a/src/tests/t_sesskeynego.py
|
||||
+++ b/src/tests/t_sesskeynego.py
|
||||
@@ -25,6 +25,8 @@ conf3 = {'libdefaults': {
|
||||
'default_tkt_enctypes': 'aes128-cts',
|
||||
'default_tgs_enctypes': 'rc4-hmac,aes128-cts'}}
|
||||
conf4 = {'libdefaults': {'permitted_enctypes': 'aes256-cts'}}
|
||||
+conf5 = {'libdefaults': {'allow_rc4': 'true'}}
|
||||
+conf6 = {'libdefaults': {'allow_des3': 'true'}}
|
||||
# Test with client request and session_enctypes preferring aes128, but
|
||||
# aes256 long-term key.
|
||||
realm = K5Realm(krb5_conf=conf1, create_host=False, get_creds=False)
|
||||
@@ -54,10 +56,12 @@ realm.run([kadminl, 'setstr', 'server', 'session_enctypes',
|
||||
'aes128-cts,aes256-cts'])
|
||||
test_kvno(realm, 'aes128-cts-hmac-sha1-96', 'aes256-cts-hmac-sha1-96')
|
||||
|
||||
-# 3b: Negotiate rc4-hmac session key when principal only has aes256 long-term.
|
||||
+# 3b: Skip RC4 (as the KDC does not allow it for session keys by
|
||||
+# default) and negotiate aes128-cts session key, with only an aes256
|
||||
+# long-term service key.
|
||||
realm.run([kadminl, 'setstr', 'server', 'session_enctypes',
|
||||
'rc4-hmac,aes128-cts,aes256-cts'])
|
||||
-test_kvno(realm, 'DEPRECATED:arcfour-hmac', 'aes256-cts-hmac-sha1-96')
|
||||
+test_kvno(realm, 'aes128-cts-hmac-sha1-96', 'aes256-cts-hmac-sha1-96')
|
||||
realm.stop()
|
||||
|
||||
# 4: Check that permitted_enctypes is a default for session key enctypes.
|
||||
@@ -67,4 +71,24 @@ realm.run([kvno, 'user'],
|
||||
expected_trace=('etypes requested in TGS request: aes256-cts',))
|
||||
realm.stop()
|
||||
|
||||
+# 5: allow_rc4 permits negotiation of rc4-hmac session key.
|
||||
+realm = K5Realm(krb5_conf=conf5, create_host=False, get_creds=False)
|
||||
+realm.run([kadminl, 'addprinc', '-randkey', '-e', 'aes256-cts', 'server'])
|
||||
+realm.run([kadminl, 'setstr', 'server', 'session_enctypes', 'rc4-hmac'])
|
||||
+test_kvno(realm, 'DEPRECATED:arcfour-hmac', 'aes256-cts-hmac-sha1-96')
|
||||
+realm.stop()
|
||||
+
|
||||
+# 6: allow_des3 permits negotiation of des3-cbc-sha1 session key.
|
||||
+realm = K5Realm(krb5_conf=conf6, create_host=False, get_creds=False)
|
||||
+realm.run([kadminl, 'addprinc', '-randkey', '-e', 'aes256-cts', 'server'])
|
||||
+realm.run([kadminl, 'setstr', 'server', 'session_enctypes', 'des3-cbc-sha1'])
|
||||
+test_kvno(realm, 'DEPRECATED:des3-cbc-sha1', 'aes256-cts-hmac-sha1-96')
|
||||
+realm.stop()
|
||||
+
|
||||
+# 7: default config negotiates aes256-sha1 session key for RC4-only service.
|
||||
+realm = K5Realm(create_host=False, get_creds=False)
|
||||
+realm.run([kadminl, 'addprinc', '-randkey', '-e', 'rc4-hmac', 'server'])
|
||||
+test_kvno(realm, 'aes256-cts-hmac-sha1-96', 'DEPRECATED:arcfour-hmac')
|
||||
+realm.stop()
|
||||
+
|
||||
success('sesskeynego')
|
||||
diff --git a/src/util/k5test.py b/src/util/k5test.py
|
||||
index d823653aa0..8e5f5ba8e9 100644
|
||||
--- a/src/util/k5test.py
|
||||
+++ b/src/util/k5test.py
|
||||
@@ -1338,9 +1338,16 @@ _passes = [
|
||||
# No special settings; exercises AES256.
|
||||
('default', None, None, None),
|
||||
|
||||
+ # Exercise the DES3 enctype.
|
||||
+ ('des3', None,
|
||||
+ {'libdefaults': {'permitted_enctypes': 'des3 aes256-sha1'}},
|
||||
+ {'realms': {'$realm': {
|
||||
+ 'supported_enctypes': 'des3-cbc-sha1:normal',
|
||||
+ 'master_key_type': 'des3-cbc-sha1'}}}),
|
||||
+
|
||||
# Exercise the arcfour enctype.
|
||||
('arcfour', None,
|
||||
- {'libdefaults': {'permitted_enctypes': 'rc4'}},
|
||||
+ {'libdefaults': {'permitted_enctypes': 'rc4 aes256-sha1'}},
|
||||
{'realms': {'$realm': {
|
||||
'supported_enctypes': 'arcfour-hmac:normal',
|
||||
'master_key_type': 'arcfour-hmac'}}}),
|
||||
--
|
||||
2.49.0
|
||||
|
||||
|
|
@ -1,260 +0,0 @@
|
|||
From b0993b57dbe584f9308cc7773b930efe76e19ba3 Mon Sep 17 00:00:00 2001
|
||||
From: Julien Rische <jrische@redhat.com>
|
||||
Date: Fri, 4 Apr 2025 15:08:36 +0200
|
||||
Subject: [PATCH] [downstream] Remove 3des support (cumulative 1)
|
||||
|
||||
Remove mentions for the triple-DES encryption type which were added
|
||||
since the previous downstream patch.
|
||||
---
|
||||
README | 15 +++++++--------
|
||||
doc/admin/conf_files/krb5_conf.rst | 6 ------
|
||||
doc/admin/enctypes.rst | 11 ++---------
|
||||
doc/mitK5features.rst | 5 ++---
|
||||
src/include/k5-int.h | 2 --
|
||||
src/kdc/kdc_util.c | 2 --
|
||||
src/lib/krb5/krb/init_ctx.c | 5 -----
|
||||
src/man/krb5.conf.man | 6 ------
|
||||
src/tests/gssapi/t_enctypes.py | 5 ++---
|
||||
src/tests/t_etype_info.py | 4 ++--
|
||||
src/tests/t_sesskeynego.py | 8 --------
|
||||
src/util/k5test.py | 7 -------
|
||||
12 files changed, 15 insertions(+), 61 deletions(-)
|
||||
|
||||
diff --git a/README b/README
|
||||
index 6d6f7f16e3..9341bd3dd8 100644
|
||||
--- a/README
|
||||
+++ b/README
|
||||
@@ -81,11 +81,11 @@ Triple-DES and RC4 transitions
|
||||
------------------------------
|
||||
|
||||
Beginning with the krb5-1.21 release, the KDC will not issue tickets
|
||||
-with triple-DES or RC4 session keys unless explicitly configured using
|
||||
-the new allow_des3 and allow_rc4 variables in [libdefaults]. To
|
||||
-facilitate the negotiation of session keys, the KDC will assume that
|
||||
-all services can handle aes256-sha1 session keys unless the service
|
||||
-principal has a session_enctypes string attribute.
|
||||
+with RC4 session keys unless explicitly configured using the new
|
||||
+allow_rc4 variable in [libdefaults]. To facilitate the negotiation of
|
||||
+session keys, the KDC will assume that all services can handle
|
||||
+aes256-sha1 session keys unless the service principal has a
|
||||
+session_enctypes string attribute.
|
||||
|
||||
Beginning with the krb5-1.19 release, a warning will be issued if
|
||||
initial credentials are acquired using the des3-cbc-sha1 encryption
|
||||
@@ -164,9 +164,8 @@ Developer experience:
|
||||
|
||||
Protocol evolution:
|
||||
|
||||
-* The KDC will no longer issue tickets with RC4 or triple-DES session
|
||||
- keys unless explicitly configured with the new allow_rc4 or
|
||||
- allow_des3 variables respectively.
|
||||
+* The KDC will no longer issue tickets with RC4 session keys unless
|
||||
+ explicitly configured with the new allow_rc4 variable.
|
||||
|
||||
* The KDC will assume that all services can handle aes256-sha1 session
|
||||
keys unless the service principal has a session_enctypes string
|
||||
diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst
|
||||
index d51fd3ce7e..d20dcf18e3 100644
|
||||
--- a/doc/admin/conf_files/krb5_conf.rst
|
||||
+++ b/doc/admin/conf_files/krb5_conf.rst
|
||||
@@ -95,12 +95,6 @@ Additionally, krb5.conf may include any of the relations described in
|
||||
|
||||
The libdefaults section may contain any of the following relations:
|
||||
|
||||
-**allow_des3**
|
||||
- Permit the KDC to issue tickets with des3-cbc-sha1 session keys.
|
||||
- In future releases, this flag will allow des3-cbc-sha1 to be used
|
||||
- at all. The default value for this tag is false. (Added in
|
||||
- release 1.21.)
|
||||
-
|
||||
**allow_rc4**
|
||||
Permit the KDC to issue tickets with arcfour-hmac session keys.
|
||||
In future releases, this flag will allow arcfour-hmac to be used
|
||||
diff --git a/doc/admin/enctypes.rst b/doc/admin/enctypes.rst
|
||||
index 2b4ed7da0b..6ce4638d5e 100644
|
||||
--- a/doc/admin/enctypes.rst
|
||||
+++ b/doc/admin/enctypes.rst
|
||||
@@ -49,8 +49,8 @@ The KDC chooses the session key enctype by taking the intersection of
|
||||
its **permitted_enctypes** list, the list of long-term keys for the
|
||||
most recent kvno of the service, and the client's requested list of
|
||||
enctypes. Starting in krb5-1.21, all services are assumed to support
|
||||
-aes256-cts-hmac-sha1-96; also, des3-cbc-sha1 and arcfour-hmac session
|
||||
-keys will not be issued by default.
|
||||
+aes256-cts-hmac-sha1-96; also, arcfour-hmac session keys will not be
|
||||
+issued by default.
|
||||
|
||||
Starting in krb5-1.11, it is possible to set a string attribute on a
|
||||
service principal to control what session key enctypes the KDC may
|
||||
@@ -90,13 +90,6 @@ affect how enctypes are chosen.
|
||||
acceptable risk for your environment and the weak enctypes are
|
||||
required for backward compatibility.
|
||||
|
||||
-**allow_des3**
|
||||
- was added in release 1.21 and defaults to *false*. Unless this
|
||||
- flag is set to *true*, the KDC will not issue tickets with
|
||||
- des3-cbc-sha1 session keys. In a future release, this flag will
|
||||
- control whether des3-cbc-sha1 is permitted in similar fashion to
|
||||
- weak enctypes.
|
||||
-
|
||||
**allow_rc4**
|
||||
was added in release 1.21 and defaults to *false*. Unless this
|
||||
flag is set to *true*, the KDC will not issue tickets with
|
||||
diff --git a/doc/mitK5features.rst b/doc/mitK5features.rst
|
||||
index cad0855724..64d746b0af 100644
|
||||
--- a/doc/mitK5features.rst
|
||||
+++ b/doc/mitK5features.rst
|
||||
@@ -659,9 +659,8 @@ Release 1.21
|
||||
|
||||
* Protocol evolution:
|
||||
|
||||
- - The KDC will no longer issue tickets with RC4 or triple-DES
|
||||
- session keys unless explicitly configured with the new allow_rc4
|
||||
- or allow_des3 variables respectively.
|
||||
+ - The KDC will no longer issue tickets with RC4 session keys unless
|
||||
+ explicitly configured with the new allow_rc4 variable.
|
||||
|
||||
- The KDC will assume that all services can handle aes256-sha1
|
||||
session keys unless the service principal has a session_enctypes
|
||||
diff --git a/src/include/k5-int.h b/src/include/k5-int.h
|
||||
index d0a263aa7d..82a763298d 100644
|
||||
--- a/src/include/k5-int.h
|
||||
+++ b/src/include/k5-int.h
|
||||
@@ -181,7 +181,6 @@ typedef unsigned char u_char;
|
||||
* matches the variable name. Keep these alphabetized. */
|
||||
#define KRB5_CONF_ACL_FILE "acl_file"
|
||||
#define KRB5_CONF_ADMIN_SERVER "admin_server"
|
||||
-#define KRB5_CONF_ALLOW_DES3 "allow_des3"
|
||||
#define KRB5_CONF_ALLOW_RC4 "allow_rc4"
|
||||
#define KRB5_CONF_ALLOW_WEAK_CRYPTO "allow_weak_crypto"
|
||||
#define KRB5_CONF_AUTH_TO_LOCAL "auth_to_local"
|
||||
@@ -1243,7 +1242,6 @@ struct _krb5_context {
|
||||
struct _kdb_log_context *kdblog_context;
|
||||
|
||||
krb5_boolean allow_weak_crypto;
|
||||
- krb5_boolean allow_des3;
|
||||
krb5_boolean allow_rc4;
|
||||
krb5_boolean ignore_acceptor_hostname;
|
||||
krb5_boolean enforce_ok_as_delegate;
|
||||
diff --git a/src/kdc/kdc_util.c b/src/kdc/kdc_util.c
|
||||
index c7b6e4090d..bafcf5f728 100644
|
||||
--- a/src/kdc/kdc_util.c
|
||||
+++ b/src/kdc/kdc_util.c
|
||||
@@ -1113,8 +1113,6 @@ select_session_keytype(krb5_context context, krb5_db_entry *server,
|
||||
* unless they are explicitly allowed. In the future they will be more
|
||||
* comprehensively disabled and eventually removed.
|
||||
*/
|
||||
- if (ktype[i] == ENCTYPE_DES3_CBC_SHA1 && !context->allow_des3)
|
||||
- continue;
|
||||
if (ktype[i] == ENCTYPE_ARCFOUR_HMAC && !context->allow_rc4)
|
||||
continue;
|
||||
|
||||
diff --git a/src/lib/krb5/krb/init_ctx.c b/src/lib/krb5/krb/init_ctx.c
|
||||
index a32f8dbf03..82aba64c5e 100644
|
||||
--- a/src/lib/krb5/krb/init_ctx.c
|
||||
+++ b/src/lib/krb5/krb/init_ctx.c
|
||||
@@ -220,11 +220,6 @@ krb5_init_context_profile(profile_t profile, krb5_flags flags,
|
||||
goto cleanup;
|
||||
ctx->allow_weak_crypto = tmp;
|
||||
|
||||
- retval = get_boolean(ctx, KRB5_CONF_ALLOW_DES3, 0, &tmp);
|
||||
- if (retval)
|
||||
- goto cleanup;
|
||||
- ctx->allow_des3 = tmp;
|
||||
-
|
||||
retval = get_boolean(ctx, KRB5_CONF_ALLOW_RC4, 0, &tmp);
|
||||
if (retval)
|
||||
goto cleanup;
|
||||
diff --git a/src/man/krb5.conf.man b/src/man/krb5.conf.man
|
||||
index 6c0e9aff8c..4b53988712 100644
|
||||
--- a/src/man/krb5.conf.man
|
||||
+++ b/src/man/krb5.conf.man
|
||||
@@ -178,12 +178,6 @@ kdc.conf(5), but it is not a recommended practice.
|
||||
The libdefaults section may contain any of the following relations:
|
||||
.INDENT 0.0
|
||||
.TP
|
||||
-\fBallow_des3\fP
|
||||
-Permit the KDC to issue tickets with des3\-cbc\-sha1 session keys.
|
||||
-In future releases, this flag will allow des3\-cbc\-sha1 to be used
|
||||
-at all. The default value for this tag is false. (Added in
|
||||
-release 1.21.)
|
||||
-.TP
|
||||
\fBallow_rc4\fP
|
||||
Permit the KDC to issue tickets with arcfour\-hmac session keys.
|
||||
In future releases, this flag will allow arcfour\-hmac to be used
|
||||
diff --git a/src/tests/gssapi/t_enctypes.py b/src/tests/gssapi/t_enctypes.py
|
||||
index e6bde47afc..1bb8c40b6b 100755
|
||||
--- a/src/tests/gssapi/t_enctypes.py
|
||||
+++ b/src/tests/gssapi/t_enctypes.py
|
||||
@@ -10,9 +10,8 @@ d_rc4 = 'DEPRECATED:arcfour-hmac'
|
||||
|
||||
# These tests make assumptions about the default enctype lists, so set
|
||||
# them explicitly rather than relying on the library defaults.
|
||||
-supp='aes256-cts:normal aes128-cts:normal des3-cbc-sha1:normal rc4-hmac:normal'
|
||||
-conf = {'libdefaults': {'permitted_enctypes': 'aes des3 rc4',
|
||||
- 'allow_des3': 'true', 'allow_rc4': 'true'},
|
||||
+supp='aes256-cts:normal aes128-cts:normal rc4-hmac:normal'
|
||||
+conf = {'libdefaults': {'permitted_enctypes': 'aes rc4', 'allow_rc4': 'true'},
|
||||
'realms': {'$realm': {'supported_enctypes': supp}}}
|
||||
realm = K5Realm(krb5_conf=conf)
|
||||
shutil.copyfile(realm.ccache, os.path.join(realm.testdir, 'save'))
|
||||
diff --git a/src/tests/t_etype_info.py b/src/tests/t_etype_info.py
|
||||
index 75d9621dd6..e82ff7ff07 100644
|
||||
--- a/src/tests/t_etype_info.py
|
||||
+++ b/src/tests/t_etype_info.py
|
||||
@@ -1,7 +1,7 @@
|
||||
from k5test import *
|
||||
|
||||
-supported_enctypes = 'aes128-cts des3-cbc-sha1 rc4-hmac'
|
||||
-conf = {'libdefaults': {'allow_des3': 'true', 'allow_rc4': 'true'},
|
||||
+supported_enctypes = 'aes128-cts rc4-hmac'
|
||||
+conf = {'libdefaults': {'allow_rc4': 'true'},
|
||||
'realms': {'$realm': {'supported_enctypes': supported_enctypes}}}
|
||||
realm = K5Realm(create_host=False, get_creds=False, krb5_conf=conf)
|
||||
|
||||
diff --git a/src/tests/t_sesskeynego.py b/src/tests/t_sesskeynego.py
|
||||
index 5a213617b5..c7dba0ff5b 100755
|
||||
--- a/src/tests/t_sesskeynego.py
|
||||
+++ b/src/tests/t_sesskeynego.py
|
||||
@@ -26,7 +26,6 @@ conf3 = {'libdefaults': {
|
||||
'default_tgs_enctypes': 'rc4-hmac,aes128-cts'}}
|
||||
conf4 = {'libdefaults': {'permitted_enctypes': 'aes256-cts'}}
|
||||
conf5 = {'libdefaults': {'allow_rc4': 'true'}}
|
||||
-conf6 = {'libdefaults': {'allow_des3': 'true'}}
|
||||
# Test with client request and session_enctypes preferring aes128, but
|
||||
# aes256 long-term key.
|
||||
realm = K5Realm(krb5_conf=conf1, create_host=False, get_creds=False)
|
||||
@@ -78,13 +77,6 @@ realm.run([kadminl, 'setstr', 'server', 'session_enctypes', 'rc4-hmac'])
|
||||
test_kvno(realm, 'DEPRECATED:arcfour-hmac', 'aes256-cts-hmac-sha1-96')
|
||||
realm.stop()
|
||||
|
||||
-# 6: allow_des3 permits negotiation of des3-cbc-sha1 session key.
|
||||
-realm = K5Realm(krb5_conf=conf6, create_host=False, get_creds=False)
|
||||
-realm.run([kadminl, 'addprinc', '-randkey', '-e', 'aes256-cts', 'server'])
|
||||
-realm.run([kadminl, 'setstr', 'server', 'session_enctypes', 'des3-cbc-sha1'])
|
||||
-test_kvno(realm, 'DEPRECATED:des3-cbc-sha1', 'aes256-cts-hmac-sha1-96')
|
||||
-realm.stop()
|
||||
-
|
||||
# 7: default config negotiates aes256-sha1 session key for RC4-only service.
|
||||
realm = K5Realm(create_host=False, get_creds=False)
|
||||
realm.run([kadminl, 'addprinc', '-randkey', '-e', 'rc4-hmac', 'server'])
|
||||
diff --git a/src/util/k5test.py b/src/util/k5test.py
|
||||
index 8e5f5ba8e9..b953827018 100644
|
||||
--- a/src/util/k5test.py
|
||||
+++ b/src/util/k5test.py
|
||||
@@ -1338,13 +1338,6 @@ _passes = [
|
||||
# No special settings; exercises AES256.
|
||||
('default', None, None, None),
|
||||
|
||||
- # Exercise the DES3 enctype.
|
||||
- ('des3', None,
|
||||
- {'libdefaults': {'permitted_enctypes': 'des3 aes256-sha1'}},
|
||||
- {'realms': {'$realm': {
|
||||
- 'supported_enctypes': 'des3-cbc-sha1:normal',
|
||||
- 'master_key_type': 'des3-cbc-sha1'}}}),
|
||||
-
|
||||
# Exercise the arcfour enctype.
|
||||
('arcfour', None,
|
||||
{'libdefaults': {'permitted_enctypes': 'rc4 aes256-sha1'}},
|
||||
--
|
||||
2.49.0
|
||||
|
||||
|
|
@ -1,692 +0,0 @@
|
|||
From 9d03713af124c2096d071ba36893018da8d71655 Mon Sep 17 00:00:00 2001
|
||||
From: Julien Rische <jrische@redhat.com>
|
||||
Date: Tue, 14 Jan 2025 13:31:11 +0100
|
||||
Subject: [PATCH] Add PKINIT paChecksum2 from MS-PKCA v20230920
|
||||
|
||||
In 2023, Microsoft updated MS-PKCA to add the optional paChecksum2
|
||||
element in the PKAuthenticator sequence. This checksum accepts SHA-1,
|
||||
SHA-256, SHA-384, and SHA-512 digests.
|
||||
|
||||
In Windows Server 2025, this checksum becomes mandatory when using
|
||||
PKINIT with FFDH (but strangely not with ECDH if SHA-1 is configured as
|
||||
allowed).
|
||||
|
||||
[ghudson@mit.edu: refactored crypto interfaces to reduce complexity of
|
||||
calling code]
|
||||
|
||||
ticket: 9166 (new)
|
||||
(cherry picked from commit 310793ba63782af5ffa3a95d20e41f8f03ca7e00)
|
||||
---
|
||||
src/include/k5-int-pkinit.h | 25 ++--
|
||||
src/lib/krb5/asn.1/asn1_k_encode.c | 18 ++-
|
||||
src/plugins/preauth/pkinit/pkinit.h | 1 +
|
||||
src/plugins/preauth/pkinit/pkinit_clnt.c | 41 +++----
|
||||
src/plugins/preauth/pkinit/pkinit_constants.c | 42 +++++--
|
||||
src/plugins/preauth/pkinit/pkinit_crypto.h | 24 +++-
|
||||
.../preauth/pkinit/pkinit_crypto_openssl.c | 116 +++++++++++++++++-
|
||||
src/plugins/preauth/pkinit/pkinit_kdf_test.c | 4 +-
|
||||
src/plugins/preauth/pkinit/pkinit_lib.c | 16 ++-
|
||||
src/plugins/preauth/pkinit/pkinit_srv.c | 38 ++----
|
||||
src/plugins/preauth/pkinit/pkinit_trace.h | 5 +-
|
||||
src/tests/asn.1/krb5_decode_test.c | 2 +-
|
||||
src/tests/asn.1/ktest.c | 7 +-
|
||||
src/tests/asn.1/ktest_equal.c | 2 +-
|
||||
src/tests/asn.1/pkinit_encode.out | 2 +-
|
||||
src/tests/asn.1/pkinit_trval.out | 2 +-
|
||||
16 files changed, 250 insertions(+), 95 deletions(-)
|
||||
|
||||
diff --git a/src/include/k5-int-pkinit.h b/src/include/k5-int-pkinit.h
|
||||
index 915904e518..cf6b1f99c5 100644
|
||||
--- a/src/include/k5-int-pkinit.h
|
||||
+++ b/src/include/k5-int-pkinit.h
|
||||
@@ -36,21 +36,28 @@
|
||||
* pkinit structures
|
||||
*/
|
||||
|
||||
-/* PKAuthenticator */
|
||||
-typedef struct _krb5_pk_authenticator {
|
||||
- krb5_int32 cusec; /* (0..999999) */
|
||||
- krb5_timestamp ctime;
|
||||
- krb5_int32 nonce; /* (0..4294967295) */
|
||||
- krb5_checksum paChecksum;
|
||||
- krb5_data *freshnessToken;
|
||||
-} krb5_pk_authenticator;
|
||||
-
|
||||
/* AlgorithmIdentifier */
|
||||
typedef struct _krb5_algorithm_identifier {
|
||||
krb5_data algorithm; /* OID */
|
||||
krb5_data parameters; /* Optional */
|
||||
} krb5_algorithm_identifier;
|
||||
|
||||
+/* PAChecksum2 */
|
||||
+typedef struct _krb5_pachecksum2 {
|
||||
+ krb5_data checksum;
|
||||
+ krb5_algorithm_identifier algorithmIdentifier;
|
||||
+} krb5_pachecksum2;
|
||||
+
|
||||
+/* PKAuthenticator */
|
||||
+typedef struct _krb5_pk_authenticator {
|
||||
+ krb5_int32 cusec; /* (0..999999) */
|
||||
+ krb5_timestamp ctime;
|
||||
+ krb5_int32 nonce; /* (0..4294967295) */
|
||||
+ krb5_data paChecksum;
|
||||
+ krb5_data *freshnessToken; /* Optional */
|
||||
+ krb5_pachecksum2 *paChecksum2; /* Optional */
|
||||
+} krb5_pk_authenticator;
|
||||
+
|
||||
/** AuthPack from RFC 4556*/
|
||||
typedef struct _krb5_auth_pack {
|
||||
krb5_pk_authenticator pkAuthenticator;
|
||||
diff --git a/src/lib/krb5/asn.1/asn1_k_encode.c b/src/lib/krb5/asn.1/asn1_k_encode.c
|
||||
index 5378b5c23b..cf7b500837 100644
|
||||
--- a/src/lib/krb5/asn.1/asn1_k_encode.c
|
||||
+++ b/src/lib/krb5/asn.1/asn1_k_encode.c
|
||||
@@ -1394,20 +1394,30 @@ DEFSEQTYPE(pkinit_supp_pub_info, krb5_pkinit_supp_pub_info,
|
||||
MAKE_ENCODER(encode_krb5_pkinit_supp_pub_info, pkinit_supp_pub_info);
|
||||
MAKE_ENCODER(encode_krb5_sp80056a_other_info, sp80056a_other_info);
|
||||
|
||||
-/* A krb5_checksum encoded as an OCTET STRING, for PKAuthenticator. */
|
||||
-DEFCOUNTEDTYPE(ostring_checksum, krb5_checksum, contents, length, octetstring);
|
||||
+DEFFIELD(pachecksum2_0, krb5_pachecksum2, checksum, 0, ostring_data);
|
||||
+DEFFIELD(pachecksum2_1, krb5_pachecksum2, algorithmIdentifier, 1,
|
||||
+ algorithm_identifier);
|
||||
+static const struct atype_info *pachecksum2_fields[] = {
|
||||
+ &k5_atype_pachecksum2_0, &k5_atype_pachecksum2_1
|
||||
+};
|
||||
+DEFSEQTYPE(pachecksum2, krb5_pachecksum2, pachecksum2_fields);
|
||||
+
|
||||
+DEFPTRTYPE(pachecksum2_ptr, pachecksum2);
|
||||
+DEFOPTIONALZEROTYPE(opt_pachecksum2_ptr, pachecksum2_ptr);
|
||||
|
||||
DEFFIELD(pk_authenticator_0, krb5_pk_authenticator, cusec, 0, int32);
|
||||
DEFFIELD(pk_authenticator_1, krb5_pk_authenticator, ctime, 1, kerberos_time);
|
||||
DEFFIELD(pk_authenticator_2, krb5_pk_authenticator, nonce, 2, int32);
|
||||
DEFFIELD(pk_authenticator_3, krb5_pk_authenticator, paChecksum, 3,
|
||||
- ostring_checksum);
|
||||
+ ostring_data);
|
||||
DEFFIELD(pk_authenticator_4, krb5_pk_authenticator, freshnessToken, 4,
|
||||
opt_ostring_data_ptr);
|
||||
+DEFFIELD(pk_authenticator_5, krb5_pk_authenticator, paChecksum2, 5,
|
||||
+ opt_pachecksum2_ptr);
|
||||
static const struct atype_info *pk_authenticator_fields[] = {
|
||||
&k5_atype_pk_authenticator_0, &k5_atype_pk_authenticator_1,
|
||||
&k5_atype_pk_authenticator_2, &k5_atype_pk_authenticator_3,
|
||||
- &k5_atype_pk_authenticator_4
|
||||
+ &k5_atype_pk_authenticator_4, &k5_atype_pk_authenticator_5
|
||||
};
|
||||
DEFSEQTYPE(pk_authenticator, krb5_pk_authenticator, pk_authenticator_fields);
|
||||
|
||||
diff --git a/src/plugins/preauth/pkinit/pkinit.h b/src/plugins/preauth/pkinit/pkinit.h
|
||||
index 7ba7155bb4..a1564b6df2 100644
|
||||
--- a/src/plugins/preauth/pkinit/pkinit.h
|
||||
+++ b/src/plugins/preauth/pkinit/pkinit.h
|
||||
@@ -338,6 +338,7 @@ void free_krb5_external_principal_identifier(krb5_external_principal_identifier
|
||||
void free_krb5_algorithm_identifiers(krb5_algorithm_identifier ***in);
|
||||
void free_krb5_algorithm_identifier(krb5_algorithm_identifier *in);
|
||||
void free_krb5_kdc_dh_key_info(krb5_kdc_dh_key_info **in);
|
||||
+void free_pachecksum2(krb5_context context, krb5_pachecksum2 **in);
|
||||
krb5_error_code pkinit_copy_krb5_data(krb5_data *dst, const krb5_data *src);
|
||||
|
||||
|
||||
diff --git a/src/plugins/preauth/pkinit/pkinit_clnt.c b/src/plugins/preauth/pkinit/pkinit_clnt.c
|
||||
index b08022a214..433f477538 100644
|
||||
--- a/src/plugins/preauth/pkinit/pkinit_clnt.c
|
||||
+++ b/src/plugins/preauth/pkinit/pkinit_clnt.c
|
||||
@@ -56,10 +56,9 @@ use_content_info(krb5_context context, pkinit_req_context req,
|
||||
static krb5_error_code
|
||||
pkinit_as_req_create(krb5_context context, pkinit_context plgctx,
|
||||
pkinit_req_context reqctx, krb5_timestamp ctsec,
|
||||
- krb5_int32 cusec, krb5_ui_4 nonce,
|
||||
- const krb5_checksum *cksum,
|
||||
- krb5_principal client, krb5_principal server,
|
||||
- krb5_data **as_req);
|
||||
+ krb5_int32 cusec, krb5_ui_4 nonce, const krb5_data *cksum,
|
||||
+ const krb5_pachecksum2 *cksum2, krb5_principal client,
|
||||
+ krb5_principal server, krb5_data **as_req);
|
||||
|
||||
static krb5_error_code
|
||||
pkinit_as_rep_parse(krb5_context context, pkinit_context plgctx,
|
||||
@@ -89,7 +88,8 @@ pa_pkinit_gen_req(krb5_context context,
|
||||
krb5_timestamp ctsec = 0;
|
||||
krb5_int32 cusec = 0;
|
||||
krb5_ui_4 nonce = 0;
|
||||
- krb5_checksum cksum;
|
||||
+ krb5_data cksum = empty_data();
|
||||
+ krb5_pachecksum2 *cksum2 = NULL;
|
||||
krb5_data *der_req = NULL;
|
||||
krb5_pa_data **return_pa_data = NULL;
|
||||
|
||||
@@ -118,15 +118,10 @@ pa_pkinit_gen_req(krb5_context context,
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
- retval = krb5_c_make_checksum(context, CKSUMTYPE_SHA1, NULL, 0, der_req,
|
||||
- &cksum);
|
||||
+ retval = crypto_generate_checksums(context, der_req, &cksum, &cksum2);
|
||||
if (retval)
|
||||
goto cleanup;
|
||||
- TRACE_PKINIT_CLIENT_REQ_CHECKSUM(context, &cksum);
|
||||
-#ifdef DEBUG_CKSUM
|
||||
- pkiDebug("calculating checksum on buf size (%d)\n", der_req->length);
|
||||
- print_buffer(der_req->data, der_req->length);
|
||||
-#endif
|
||||
+ TRACE_PKINIT_CLIENT_REQ_CHECKSUMS(context, &cksum, cksum2);
|
||||
|
||||
retval = cb->get_preauth_time(context, rock, TRUE, &ctsec, &cusec);
|
||||
if (retval)
|
||||
@@ -140,7 +135,8 @@ pa_pkinit_gen_req(krb5_context context,
|
||||
nonce = request->nonce;
|
||||
|
||||
retval = pkinit_as_req_create(context, plgctx, reqctx, ctsec, cusec,
|
||||
- nonce, &cksum, request->client, request->server, &out_data);
|
||||
+ nonce, &cksum, cksum2, request->client,
|
||||
+ request->server, &out_data);
|
||||
if (retval) {
|
||||
pkiDebug("error %d on pkinit_as_req_create; aborting PKINIT\n",
|
||||
(int) retval);
|
||||
@@ -168,23 +164,19 @@ pa_pkinit_gen_req(krb5_context context,
|
||||
|
||||
cleanup:
|
||||
krb5_free_data(context, der_req);
|
||||
- krb5_free_checksum_contents(context, &cksum);
|
||||
+ krb5_free_data_contents(context, &cksum);
|
||||
+ free_pachecksum2(context, &cksum2);
|
||||
krb5_free_data(context, out_data);
|
||||
krb5_free_pa_data(context, return_pa_data);
|
||||
return retval;
|
||||
}
|
||||
|
||||
static krb5_error_code
|
||||
-pkinit_as_req_create(krb5_context context,
|
||||
- pkinit_context plgctx,
|
||||
- pkinit_req_context reqctx,
|
||||
- krb5_timestamp ctsec,
|
||||
- krb5_int32 cusec,
|
||||
- krb5_ui_4 nonce,
|
||||
- const krb5_checksum * cksum,
|
||||
- krb5_principal client,
|
||||
- krb5_principal server,
|
||||
- krb5_data ** as_req)
|
||||
+pkinit_as_req_create(krb5_context context, pkinit_context plgctx,
|
||||
+ pkinit_req_context reqctx, krb5_timestamp ctsec,
|
||||
+ krb5_int32 cusec, krb5_ui_4 nonce, const krb5_data *cksum,
|
||||
+ const krb5_pachecksum2 *cksum2, krb5_principal client,
|
||||
+ krb5_principal server, krb5_data **as_req)
|
||||
{
|
||||
krb5_error_code retval = ENOMEM;
|
||||
krb5_data spki = empty_data(), *coded_auth_pack = NULL;
|
||||
@@ -202,6 +194,7 @@ pkinit_as_req_create(krb5_context context,
|
||||
auth_pack.pkAuthenticator.paChecksum = *cksum;
|
||||
if (!reqctx->opts->disable_freshness)
|
||||
auth_pack.pkAuthenticator.freshnessToken = reqctx->freshness_token;
|
||||
+ auth_pack.pkAuthenticator.paChecksum2 = (krb5_pachecksum2 *)cksum2;
|
||||
auth_pack.clientDHNonce.length = 0;
|
||||
auth_pack.supportedKDFs = (krb5_data **)supported_kdf_alg_ids;
|
||||
|
||||
diff --git a/src/plugins/preauth/pkinit/pkinit_constants.c b/src/plugins/preauth/pkinit/pkinit_constants.c
|
||||
index 905e90d29c..a32b373c32 100644
|
||||
--- a/src/plugins/preauth/pkinit/pkinit_constants.c
|
||||
+++ b/src/plugins/preauth/pkinit/pkinit_constants.c
|
||||
@@ -34,25 +34,49 @@
|
||||
|
||||
/* RFC 8636 id-pkinit-kdf-ah-sha1: iso(1) identified-organization(3) dod(6)
|
||||
* internet(1) security(5) kerberosv5(2) pkinit(3) kdf(6) sha1(1) */
|
||||
-static char sha1_oid[8] = { 0x2B, 0x06, 0x01, 0x05, 0x02, 0x03, 0x06, 0x01 };
|
||||
+static char kdf_sha1[8] = { 0x2B, 0x06, 0x01, 0x05, 0x02, 0x03, 0x06, 0x01 };
|
||||
/* RFC 8636 id-pkinit-kdf-ah-sha256: iso(1) identified-organization(3) dod(6)
|
||||
* internet(1) security(5) kerberosv5(2) pkinit(3) kdf(6) sha256(2) */
|
||||
-static char sha256_oid[8] = { 0x2B, 0x06, 0x01, 0x05, 0x02, 0x03, 0x06, 0x02 };
|
||||
+static char kdf_sha256[8] = { 0x2B, 0x06, 0x01, 0x05, 0x02, 0x03, 0x06, 0x02 };
|
||||
/* RFC 8636 id-pkinit-kdf-ah-sha512: iso(1) identified-organization(3) dod(6)
|
||||
* internet(1) security(5) kerberosv5(2) pkinit(3) kdf(6) sha512(3) */
|
||||
-static char sha512_oid[8] = { 0x2B, 0x06, 0x01, 0x05, 0x02, 0x03, 0x06, 0x03 };
|
||||
+static char kdf_sha512[8] = { 0x2B, 0x06, 0x01, 0x05, 0x02, 0x03, 0x06, 0x03 };
|
||||
|
||||
-const krb5_data sha1_id = { KV5M_DATA, sizeof(sha1_oid), sha1_oid };
|
||||
-const krb5_data sha256_id = { KV5M_DATA, sizeof(sha256_oid), sha256_oid };
|
||||
-const krb5_data sha512_id = { KV5M_DATA, sizeof(sha512_oid), sha512_oid };
|
||||
+const krb5_data kdf_sha1_id = { KV5M_DATA, sizeof(kdf_sha1), kdf_sha1 };
|
||||
+const krb5_data kdf_sha256_id = { KV5M_DATA, sizeof(kdf_sha256), kdf_sha256 };
|
||||
+const krb5_data kdf_sha512_id = { KV5M_DATA, sizeof(kdf_sha512), kdf_sha512 };
|
||||
|
||||
krb5_data const * const supported_kdf_alg_ids[] = {
|
||||
- &sha256_id,
|
||||
- &sha1_id,
|
||||
- &sha512_id,
|
||||
+ &kdf_sha256_id,
|
||||
+ &kdf_sha1_id,
|
||||
+ &kdf_sha512_id,
|
||||
NULL
|
||||
};
|
||||
|
||||
+/* RFC 3370 sha-1: iso(1) identified-organization(3) oiw(14) secsig(3)
|
||||
+ * algorithm(2) 26 */
|
||||
+static char cms_sha1[] = { 0x2b, 0x0e, 0x03, 0x02, 0x1a };
|
||||
+/* RFC 5754 id-sha256: joint-iso-itu-t(2) country(16) us(840) organization(1)
|
||||
+ * gov(101) csor(3) nistalgorithm(4) hashalgs(2) 1 */
|
||||
+static char cms_sha256[] = {
|
||||
+ 0x60, 0x86, 0x48, 0x01, 0x65, 0x03, 0x04, 0x02, 0x01
|
||||
+};
|
||||
+/* RFC 5754 id-sha384: joint-iso-itu-t(2) country(16) us(840) organization(1)
|
||||
+ * gov(101) csor(3) nistalgorithm(4) hashalgs(2) 2 */
|
||||
+static char cms_sha384[] = {
|
||||
+ 0x60, 0x86, 0x48, 0x01, 0x65, 0x03, 0x04, 0x02, 0x02
|
||||
+};
|
||||
+/* RFC 5754 id-sha512: joint-iso-itu-t(2) country(16) us(840) organization(1)
|
||||
+ * gov(101) csor(3) nistalgorithm(4) hashalgs(2) 3 */
|
||||
+static char cms_sha512[] = {
|
||||
+ 0x60, 0x86, 0x48, 0x01, 0x65, 0x03, 0x04, 0x02, 0x03
|
||||
+};
|
||||
+
|
||||
+const krb5_data cms_sha1_id = { KV5M_DATA, sizeof(cms_sha1), cms_sha1 };
|
||||
+const krb5_data cms_sha256_id = { KV5M_DATA, sizeof(cms_sha256), cms_sha256 };
|
||||
+const krb5_data cms_sha384_id = { KV5M_DATA, sizeof(cms_sha384), cms_sha384 };
|
||||
+const krb5_data cms_sha512_id = { KV5M_DATA, sizeof(cms_sha512), cms_sha512 };
|
||||
+
|
||||
/* RFC 4055 sha256WithRSAEncryption: iso(1) member-body(2) us(840)
|
||||
* rsadsi(113549) pkcs(1) 1 11 */
|
||||
static char sha256WithRSAEncr_oid[9] = {
|
||||
diff --git a/src/plugins/preauth/pkinit/pkinit_crypto.h b/src/plugins/preauth/pkinit/pkinit_crypto.h
|
||||
index fd876e4850..3b12e904b1 100644
|
||||
--- a/src/plugins/preauth/pkinit/pkinit_crypto.h
|
||||
+++ b/src/plugins/preauth/pkinit/pkinit_crypto.h
|
||||
@@ -562,9 +562,13 @@ pkinit_alg_agility_kdf(krb5_context context,
|
||||
krb5_data *pk_as_rep,
|
||||
krb5_keyblock *key_block);
|
||||
|
||||
-extern const krb5_data sha1_id;
|
||||
-extern const krb5_data sha256_id;
|
||||
-extern const krb5_data sha512_id;
|
||||
+extern const krb5_data kdf_sha1_id;
|
||||
+extern const krb5_data kdf_sha256_id;
|
||||
+extern const krb5_data kdf_sha512_id;
|
||||
+extern const krb5_data cms_sha1_id;
|
||||
+extern const krb5_data cms_sha256_id;
|
||||
+extern const krb5_data cms_sha384_id;
|
||||
+extern const krb5_data cms_sha512_id;
|
||||
extern const krb5_data oakley_1024;
|
||||
extern const krb5_data oakley_2048;
|
||||
extern const krb5_data oakley_4096;
|
||||
@@ -597,4 +601,18 @@ crypto_req_cert_matching_data(krb5_context context,
|
||||
|
||||
int parse_dh_min_bits(krb5_context context, const char *str);
|
||||
|
||||
+/* Generate a SHA-1 checksum over body in *cksum1_out and a SHA-256 checksum
|
||||
+ * over body in *cksum2_out with appropriate metadata. */
|
||||
+krb5_error_code
|
||||
+crypto_generate_checksums(krb5_context context, const krb5_data *body,
|
||||
+ krb5_data *cksum1_out,
|
||||
+ krb5_pachecksum2 **cksum2_out);
|
||||
+
|
||||
+/* Verify the SHA-1 checksum in cksum1 and the tagged checksum in cksum2.
|
||||
+ * cksum2 may be NULL, in which case only cksum1 is verified. */
|
||||
+krb5_error_code
|
||||
+crypto_verify_checksums(krb5_context context, krb5_data *body,
|
||||
+ const krb5_data *cksum1,
|
||||
+ const krb5_pachecksum2 *cksum2);
|
||||
+
|
||||
#endif /* _PKINIT_CRYPTO_H */
|
||||
diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c
|
||||
index 402bf1b9b3..429b7d202c 100644
|
||||
--- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c
|
||||
+++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c
|
||||
@@ -2616,11 +2616,11 @@ cleanup:
|
||||
static const EVP_MD *
|
||||
algid_to_md(const krb5_data *alg_id)
|
||||
{
|
||||
- if (data_eq(*alg_id, sha1_id))
|
||||
+ if (data_eq(*alg_id, kdf_sha1_id))
|
||||
return EVP_sha1();
|
||||
- if (data_eq(*alg_id, sha256_id))
|
||||
+ if (data_eq(*alg_id, kdf_sha256_id))
|
||||
return EVP_sha256();
|
||||
- if (data_eq(*alg_id, sha512_id))
|
||||
+ if (data_eq(*alg_id, kdf_sha512_id))
|
||||
return EVP_sha512();
|
||||
return NULL;
|
||||
}
|
||||
@@ -5663,3 +5663,113 @@ parse_dh_min_bits(krb5_context context, const char *str)
|
||||
TRACE_PKINIT_DH_INVALID_MIN_BITS(context, str);
|
||||
return PKINIT_DEFAULT_DH_MIN_BITS;
|
||||
}
|
||||
+
|
||||
+/* Return the OpenSSL message digest type matching the given CMS OID, or NULL
|
||||
+ * if it doesn't match any of the CMS OIDs we know about. */
|
||||
+static const EVP_MD *
|
||||
+md_from_cms_oid(const krb5_data *alg_id)
|
||||
+{
|
||||
+ if (data_eq(*alg_id, cms_sha1_id))
|
||||
+ return EVP_sha1();
|
||||
+ if (data_eq(*alg_id, cms_sha256_id))
|
||||
+ return EVP_sha256();
|
||||
+ if (data_eq(*alg_id, cms_sha384_id))
|
||||
+ return EVP_sha384();
|
||||
+ if (data_eq(*alg_id, cms_sha512_id))
|
||||
+ return EVP_sha512();
|
||||
+ return NULL;
|
||||
+}
|
||||
+
|
||||
+/* Compute a message digest of the given type over body, placing the result in
|
||||
+ * *digest_out in allocated storage. Return true on success. */
|
||||
+static krb5_boolean
|
||||
+make_digest(const krb5_data *body, const EVP_MD *md, krb5_data *digest_out)
|
||||
+{
|
||||
+ krb5_error_code ret;
|
||||
+ krb5_data d;
|
||||
+
|
||||
+ if (md == NULL)
|
||||
+ return FALSE;
|
||||
+ ret = alloc_data(&d, EVP_MD_size(md));
|
||||
+ if (ret)
|
||||
+ return FALSE;
|
||||
+ if (!EVP_Digest(body->data, body->length, (uint8_t *)d.data, &d.length, md,
|
||||
+ NULL)) {
|
||||
+ free(d.data);
|
||||
+ return FALSE;
|
||||
+ }
|
||||
+ *digest_out = d;
|
||||
+ return TRUE;
|
||||
+}
|
||||
+
|
||||
+/* Return true if digest verifies for the given body and message digest
|
||||
+ * type. */
|
||||
+static krb5_boolean
|
||||
+check_digest(const krb5_data *body, const EVP_MD *md, const krb5_data *digest)
|
||||
+{
|
||||
+ unsigned int digest_len;
|
||||
+ uint8_t buf[EVP_MAX_MD_SIZE];
|
||||
+
|
||||
+ if (md == NULL)
|
||||
+ return FALSE;
|
||||
+ if (!EVP_Digest(body->data, body->length, buf, &digest_len, md, NULL))
|
||||
+ return FALSE;
|
||||
+ return (digest->length == digest_len &&
|
||||
+ CRYPTO_memcmp(digest->data, buf, digest_len) == 0);
|
||||
+}
|
||||
+
|
||||
+krb5_error_code
|
||||
+crypto_generate_checksums(krb5_context context, const krb5_data *body,
|
||||
+ krb5_data *cksum1_out, krb5_pachecksum2 **cksum2_out)
|
||||
+{
|
||||
+ krb5_data cksum1 = empty_data();
|
||||
+ krb5_pachecksum2 *cksum2 = NULL;
|
||||
+ krb5_error_code ret;
|
||||
+
|
||||
+ if (!make_digest(body, EVP_sha1(), &cksum1))
|
||||
+ goto fail;
|
||||
+
|
||||
+ cksum2 = k5alloc(sizeof(*cksum2), &ret);
|
||||
+ if (cksum2 == NULL)
|
||||
+ goto fail;
|
||||
+
|
||||
+ if (!make_digest(body, EVP_sha256(), &cksum2->checksum))
|
||||
+ goto fail;
|
||||
+
|
||||
+ if (krb5int_copy_data_contents(context, &cms_sha256_id,
|
||||
+ &cksum2->algorithmIdentifier.algorithm))
|
||||
+ goto fail;
|
||||
+
|
||||
+ cksum2->algorithmIdentifier.parameters = empty_data();
|
||||
+
|
||||
+ *cksum1_out = cksum1;
|
||||
+ *cksum2_out = cksum2;
|
||||
+ return 0;
|
||||
+
|
||||
+fail:
|
||||
+ krb5_free_data_contents(context, &cksum1);
|
||||
+ free_pachecksum2(context, &cksum2);
|
||||
+ return KRB5_CRYPTO_INTERNAL;
|
||||
+}
|
||||
+
|
||||
+krb5_error_code
|
||||
+crypto_verify_checksums(krb5_context context, krb5_data *body,
|
||||
+ const krb5_data *cksum1,
|
||||
+ const krb5_pachecksum2 *cksum2)
|
||||
+{
|
||||
+ const EVP_MD *md;
|
||||
+
|
||||
+ /* RFC 4556 doesn't say what error to return if the checksum doesn't match.
|
||||
+ * Windows returns this one. */
|
||||
+ if (!check_digest(body, EVP_sha1(), cksum1))
|
||||
+ return KRB5KRB_AP_ERR_MODIFIED;
|
||||
+
|
||||
+ if (cksum2 == NULL)
|
||||
+ return 0;
|
||||
+
|
||||
+ md = md_from_cms_oid(&cksum2->algorithmIdentifier.algorithm);
|
||||
+ if (!check_digest(body, md, &cksum2->checksum))
|
||||
+ return KRB5KRB_AP_ERR_MODIFIED;
|
||||
+
|
||||
+ return 0;
|
||||
+}
|
||||
diff --git a/src/plugins/preauth/pkinit/pkinit_kdf_test.c b/src/plugins/preauth/pkinit/pkinit_kdf_test.c
|
||||
index 99c93ac128..dd6e8d7503 100644
|
||||
--- a/src/plugins/preauth/pkinit/pkinit_kdf_test.c
|
||||
+++ b/src/plugins/preauth/pkinit/pkinit_kdf_test.c
|
||||
@@ -126,7 +126,7 @@ main(int argc, char **argv)
|
||||
|
||||
/* TEST 1: SHA-1/AES */
|
||||
/* set up algorithm id */
|
||||
- alg_id.algorithm = sha1_id;
|
||||
+ alg_id.algorithm = kdf_sha1_id;
|
||||
|
||||
enctype = enctype_aes;
|
||||
|
||||
@@ -157,7 +157,7 @@ main(int argc, char **argv)
|
||||
|
||||
/* TEST 2: SHA-256/AES */
|
||||
/* set up algorithm id */
|
||||
- alg_id.algorithm = sha256_id;
|
||||
+ alg_id.algorithm = kdf_sha256_id;
|
||||
|
||||
enctype = enctype_aes;
|
||||
|
||||
diff --git a/src/plugins/preauth/pkinit/pkinit_lib.c b/src/plugins/preauth/pkinit/pkinit_lib.c
|
||||
index 25965eb5d2..891f47fd26 100644
|
||||
--- a/src/plugins/preauth/pkinit/pkinit_lib.c
|
||||
+++ b/src/plugins/preauth/pkinit/pkinit_lib.c
|
||||
@@ -29,6 +29,7 @@
|
||||
* SUCH DAMAGES.
|
||||
*/
|
||||
|
||||
+#include "k5-int.h"
|
||||
#include "pkinit.h"
|
||||
|
||||
#define FAKECERT
|
||||
@@ -119,8 +120,9 @@ free_krb5_auth_pack(krb5_auth_pack **in)
|
||||
{
|
||||
if ((*in) == NULL) return;
|
||||
krb5_free_data_contents(NULL, &(*in)->clientPublicValue);
|
||||
- free((*in)->pkAuthenticator.paChecksum.contents);
|
||||
+ free((*in)->pkAuthenticator.paChecksum.data);
|
||||
krb5_free_data(NULL, (*in)->pkAuthenticator.freshnessToken);
|
||||
+ free_pachecksum2(NULL, &(*in)->pkAuthenticator.paChecksum2);
|
||||
if ((*in)->supportedCMSTypes != NULL)
|
||||
free_krb5_algorithm_identifiers(&((*in)->supportedCMSTypes));
|
||||
if ((*in)->supportedKDFs) {
|
||||
@@ -196,6 +198,18 @@ free_krb5_kdc_dh_key_info(krb5_kdc_dh_key_info **in)
|
||||
free(*in);
|
||||
}
|
||||
|
||||
+void
|
||||
+free_pachecksum2(krb5_context context, krb5_pachecksum2 **in)
|
||||
+{
|
||||
+ if (*in == NULL)
|
||||
+ return;
|
||||
+ krb5_free_data_contents(context, &(*in)->checksum);
|
||||
+ krb5_free_data_contents(context, &(*in)->algorithmIdentifier.algorithm);
|
||||
+ krb5_free_data_contents(context, &(*in)->algorithmIdentifier.parameters);
|
||||
+ free(*in);
|
||||
+ *in = NULL;
|
||||
+}
|
||||
+
|
||||
void
|
||||
init_krb5_pa_pk_as_req(krb5_pa_pk_as_req **in)
|
||||
{
|
||||
diff --git a/src/plugins/preauth/pkinit/pkinit_srv.c b/src/plugins/preauth/pkinit/pkinit_srv.c
|
||||
index e22bcb195b..f558308483 100644
|
||||
--- a/src/plugins/preauth/pkinit/pkinit_srv.c
|
||||
+++ b/src/plugins/preauth/pkinit/pkinit_srv.c
|
||||
@@ -428,11 +428,12 @@ pkinit_server_verify_padata(krb5_context context,
|
||||
krb5_data authp_data = {0, 0, NULL}, krb5_authz = {0, 0, NULL};
|
||||
krb5_pa_pk_as_req *reqp = NULL;
|
||||
krb5_auth_pack *auth_pack = NULL;
|
||||
+ krb5_pk_authenticator *pka;
|
||||
pkinit_kdc_context plgctx = NULL;
|
||||
pkinit_kdc_req_context reqctx = NULL;
|
||||
krb5_checksum cksum = {0, 0, 0, NULL};
|
||||
krb5_data *der_req = NULL;
|
||||
- krb5_data k5data, *ftoken;
|
||||
+ krb5_data k5data;
|
||||
int is_signed = 1;
|
||||
krb5_pa_data **e_data = NULL;
|
||||
krb5_kdcpreauth_modreq modreq = NULL;
|
||||
@@ -524,8 +525,9 @@ pkinit_server_verify_padata(krb5_context context,
|
||||
pkiDebug("failed to decode krb5_auth_pack\n");
|
||||
goto cleanup;
|
||||
}
|
||||
+ pka = &auth_pack->pkAuthenticator;
|
||||
|
||||
- retval = krb5_check_clockskew(context, auth_pack->pkAuthenticator.ctime);
|
||||
+ retval = krb5_check_clockskew(context, pka->ctime);
|
||||
if (retval)
|
||||
goto cleanup;
|
||||
|
||||
@@ -548,36 +550,14 @@ pkinit_server_verify_padata(krb5_context context,
|
||||
goto cleanup;
|
||||
}
|
||||
der_req = cb->request_body(context, rock);
|
||||
- retval = krb5_c_make_checksum(context, CKSUMTYPE_SHA1, NULL, 0, der_req,
|
||||
- &cksum);
|
||||
- if (retval) {
|
||||
- pkiDebug("unable to calculate AS REQ checksum\n");
|
||||
- goto cleanup;
|
||||
- }
|
||||
- if (cksum.length != auth_pack->pkAuthenticator.paChecksum.length ||
|
||||
- k5_bcmp(cksum.contents, auth_pack->pkAuthenticator.paChecksum.contents,
|
||||
- cksum.length) != 0) {
|
||||
- pkiDebug("failed to match the checksum\n");
|
||||
-#ifdef DEBUG_CKSUM
|
||||
- pkiDebug("calculating checksum on buf size (%d)\n", req_pkt->length);
|
||||
- print_buffer(req_pkt->data, req_pkt->length);
|
||||
- pkiDebug("received checksum type=%d size=%d ",
|
||||
- auth_pack->pkAuthenticator.paChecksum.checksum_type,
|
||||
- auth_pack->pkAuthenticator.paChecksum.length);
|
||||
- print_buffer(auth_pack->pkAuthenticator.paChecksum.contents,
|
||||
- auth_pack->pkAuthenticator.paChecksum.length);
|
||||
- pkiDebug("expected checksum type=%d size=%d ",
|
||||
- cksum.checksum_type, cksum.length);
|
||||
- print_buffer(cksum.contents, cksum.length);
|
||||
-#endif
|
||||
|
||||
- retval = KRB5KDC_ERR_PA_CHECKSUM_MUST_BE_INCLUDED;
|
||||
+ retval = crypto_verify_checksums(context, der_req, &pka->paChecksum,
|
||||
+ pka->paChecksum2);
|
||||
+ if (retval)
|
||||
goto cleanup;
|
||||
- }
|
||||
|
||||
- ftoken = auth_pack->pkAuthenticator.freshnessToken;
|
||||
- if (ftoken != NULL) {
|
||||
- retval = cb->check_freshness_token(context, rock, ftoken);
|
||||
+ if (pka->freshnessToken != NULL) {
|
||||
+ retval = cb->check_freshness_token(context, rock, pka->freshnessToken);
|
||||
if (retval)
|
||||
goto cleanup;
|
||||
valid_freshness_token = TRUE;
|
||||
diff --git a/src/plugins/preauth/pkinit/pkinit_trace.h b/src/plugins/preauth/pkinit/pkinit_trace.h
|
||||
index 1faa6816d7..7b68d4b3b1 100644
|
||||
--- a/src/plugins/preauth/pkinit/pkinit_trace.h
|
||||
+++ b/src/plugins/preauth/pkinit/pkinit_trace.h
|
||||
@@ -58,8 +58,9 @@
|
||||
TRACE(c, "PKINIT client verified DH reply")
|
||||
#define TRACE_PKINIT_CLIENT_REP_DH_FAIL(c) \
|
||||
TRACE(c, "PKINIT client could not verify DH reply")
|
||||
-#define TRACE_PKINIT_CLIENT_REQ_CHECKSUM(c, cksum) \
|
||||
- TRACE(c, "PKINIT client computed kdc-req-body checksum {cksum}", cksum)
|
||||
+#define TRACE_PKINIT_CLIENT_REQ_CHECKSUMS(c, ck1, ck2) \
|
||||
+ TRACE(c, "PKINIT client computed checksums: {hexdata} {hexdata}", \
|
||||
+ ck1, &(ck2)->checksum)
|
||||
#define TRACE_PKINIT_CLIENT_REQ_DH(c) \
|
||||
TRACE(c, "PKINIT client making DH request")
|
||||
#define TRACE_PKINIT_CLIENT_SAN_CONFIG_DNSNAME(c, host) \
|
||||
diff --git a/src/tests/asn.1/krb5_decode_test.c b/src/tests/asn.1/krb5_decode_test.c
|
||||
index 2fa6dce8eb..f47849abad 100644
|
||||
--- a/src/tests/asn.1/krb5_decode_test.c
|
||||
+++ b/src/tests/asn.1/krb5_decode_test.c
|
||||
@@ -1174,7 +1174,7 @@ main(int argc, char **argv)
|
||||
/* decode_krb5_auth_pack */
|
||||
{
|
||||
setup(krb5_auth_pack,ktest_make_sample_auth_pack);
|
||||
- decode_run("krb5_auth_pack","","30 81 85 A0 35 30 33 A0 05 02 03 01 E2 40 A1 11 18 0F 31 39 39 34 30 36 31 30 30 36 30 33 31 37 5A A2 03 02 01 2A A3 06 04 04 31 32 33 34 A4 0A 04 08 6B 72 62 35 64 61 74 61 A1 08 04 06 70 76 61 6C 75 65 A2 24 30 22 30 13 06 09 2A 86 48 86 F7 12 01 02 02 04 06 70 61 72 61 6D 73 30 0B 06 09 2A 86 48 86 F7 12 01 02 02 A3 0A 04 08 6B 72 62 35 64 61 74 61 A4 10 30 0E 30 0C A0 0A 06 08 6B 72 62 35 64 61 74 61",
|
||||
+ decode_run("krb5_auth_pack","","30 81 89 A0 39 30 37 A0 05 02 03 01 E2 40 A1 11 18 0F 31 39 39 34 30 36 31 30 30 36 30 33 31 37 5A A2 03 02 01 2A A3 0A 04 08 6B 72 62 35 64 61 74 61 A4 0A 04 08 6B 72 62 35 64 61 74 61 A1 08 04 06 70 76 61 6C 75 65 A2 24 30 22 30 13 06 09 2A 86 48 86 F7 12 01 02 02 04 06 70 61 72 61 6D 73 30 0B 06 09 2A 86 48 86 F7 12 01 02 02 A3 0A 04 08 6B 72 62 35 64 61 74 61 A4 10 30 0E 30 0C A0 0A 06 08 6B 72 62 35 64 61 74 61",
|
||||
acc.decode_krb5_auth_pack,
|
||||
ktest_equal_auth_pack,ktest_free_auth_pack);
|
||||
ktest_empty_auth_pack(&ref);
|
||||
diff --git a/src/tests/asn.1/ktest.c b/src/tests/asn.1/ktest.c
|
||||
index d37e4fa7e6..7f54aa3184 100644
|
||||
--- a/src/tests/asn.1/ktest.c
|
||||
+++ b/src/tests/asn.1/ktest.c
|
||||
@@ -700,9 +700,7 @@ ktest_make_sample_pk_authenticator(krb5_pk_authenticator *p)
|
||||
p->cusec = SAMPLE_USEC;
|
||||
p->ctime = SAMPLE_TIME;
|
||||
p->nonce = SAMPLE_NONCE;
|
||||
- ktest_make_sample_checksum(&p->paChecksum);
|
||||
- /* We don't encode the checksum type, only the contents. */
|
||||
- p->paChecksum.checksum_type = 0;
|
||||
+ ktest_make_sample_data(&p->paChecksum);
|
||||
p->freshnessToken = ealloc(sizeof(krb5_data));
|
||||
ktest_make_sample_data(p->freshnessToken);
|
||||
}
|
||||
@@ -1604,8 +1602,7 @@ ktest_empty_pa_otp_req(krb5_pa_otp_req *p)
|
||||
static void
|
||||
ktest_empty_pk_authenticator(krb5_pk_authenticator *p)
|
||||
{
|
||||
- ktest_empty_checksum(&p->paChecksum);
|
||||
- p->paChecksum.contents = NULL;
|
||||
+ ktest_empty_data(&p->paChecksum);
|
||||
krb5_free_data(NULL, p->freshnessToken);
|
||||
p->freshnessToken = NULL;
|
||||
}
|
||||
diff --git a/src/tests/asn.1/ktest_equal.c b/src/tests/asn.1/ktest_equal.c
|
||||
index b48a0285d2..13786dd1e5 100644
|
||||
--- a/src/tests/asn.1/ktest_equal.c
|
||||
+++ b/src/tests/asn.1/ktest_equal.c
|
||||
@@ -844,7 +844,7 @@ ktest_equal_pk_authenticator(krb5_pk_authenticator *ref,
|
||||
p = p && scalar_equal(cusec);
|
||||
p = p && scalar_equal(ctime);
|
||||
p = p && scalar_equal(nonce);
|
||||
- p = p && struct_equal(paChecksum, ktest_equal_checksum);
|
||||
+ p = p && data_eq(ref->paChecksum, var->paChecksum);
|
||||
return p;
|
||||
}
|
||||
|
||||
diff --git a/src/tests/asn.1/pkinit_encode.out b/src/tests/asn.1/pkinit_encode.out
|
||||
index 6ec7aaa36a..a764182e15 100644
|
||||
--- a/src/tests/asn.1/pkinit_encode.out
|
||||
+++ b/src/tests/asn.1/pkinit_encode.out
|
||||
@@ -1,7 +1,7 @@
|
||||
encode_krb5_pa_pk_as_req: 30 38 80 08 6B 72 62 35 64 61 74 61 A1 22 30 20 30 1E 80 08 6B 72 62 35 64 61 74 61 81 08 6B 72 62 35 64 61 74 61 82 08 6B 72 62 35 64 61 74 61 82 08 6B 72 62 35 64 61 74 61
|
||||
encode_krb5_pa_pk_as_rep(dhInfo): A0 28 30 26 80 08 6B 72 62 35 64 61 74 61 A1 0A 04 08 6B 72 62 35 64 61 74 61 A2 0E 30 0C A0 0A 06 08 6B 72 62 35 64 61 74 61
|
||||
encode_krb5_pa_pk_as_rep(encKeyPack): 81 08 6B 72 62 35 64 61 74 61
|
||||
-encode_krb5_auth_pack: 30 81 85 A0 35 30 33 A0 05 02 03 01 E2 40 A1 11 18 0F 31 39 39 34 30 36 31 30 30 36 30 33 31 37 5A A2 03 02 01 2A A3 06 04 04 31 32 33 34 A4 0A 04 08 6B 72 62 35 64 61 74 61 A1 08 04 06 70 76 61 6C 75 65 A2 24 30 22 30 13 06 09 2A 86 48 86 F7 12 01 02 02 04 06 70 61 72 61 6D 73 30 0B 06 09 2A 86 48 86 F7 12 01 02 02 A3 0A 04 08 6B 72 62 35 64 61 74 61 A4 10 30 0E 30 0C A0 0A 06 08 6B 72 62 35 64 61 74 61
|
||||
+encode_krb5_auth_pack: 30 81 89 A0 39 30 37 A0 05 02 03 01 E2 40 A1 11 18 0F 31 39 39 34 30 36 31 30 30 36 30 33 31 37 5A A2 03 02 01 2A A3 0A 04 08 6B 72 62 35 64 61 74 61 A4 0A 04 08 6B 72 62 35 64 61 74 61 A1 08 04 06 70 76 61 6C 75 65 A2 24 30 22 30 13 06 09 2A 86 48 86 F7 12 01 02 02 04 06 70 61 72 61 6D 73 30 0B 06 09 2A 86 48 86 F7 12 01 02 02 A3 0A 04 08 6B 72 62 35 64 61 74 61 A4 10 30 0E 30 0C A0 0A 06 08 6B 72 62 35 64 61 74 61
|
||||
encode_krb5_kdc_dh_key_info: 30 25 A0 0B 03 09 00 6B 72 62 35 64 61 74 61 A1 03 02 01 2A A2 11 18 0F 31 39 39 34 30 36 31 30 30 36 30 33 31 37 5A
|
||||
encode_krb5_reply_key_pack: 30 26 A0 13 30 11 A0 03 02 01 01 A1 0A 04 08 31 32 33 34 35 36 37 38 A1 0F 30 0D A0 03 02 01 01 A1 06 04 04 31 32 33 34
|
||||
encode_krb5_sp80056a_other_info: 30 81 81 30 0B 06 09 2A 86 48 86 F7 12 01 02 02 A0 32 04 30 30 2E A0 10 1B 0E 41 54 48 45 4E 41 2E 4D 49 54 2E 45 44 55 A1 1A 30 18 A0 03 02 01 01 A1 11 30 0F 1B 06 68 66 74 73 61 69 1B 05 65 78 74 72 61 A1 32 04 30 30 2E A0 10 1B 0E 41 54 48 45 4E 41 2E 4D 49 54 2E 45 44 55 A1 1A 30 18 A0 03 02 01 01 A1 11 30 0F 1B 06 68 66 74 73 61 69 1B 05 65 78 74 72 61 A2 0A 04 08 6B 72 62 35 64 61 74 61
|
||||
diff --git a/src/tests/asn.1/pkinit_trval.out b/src/tests/asn.1/pkinit_trval.out
|
||||
index 46f4a34108..c47bd71f67 100644
|
||||
--- a/src/tests/asn.1/pkinit_trval.out
|
||||
+++ b/src/tests/asn.1/pkinit_trval.out
|
||||
@@ -38,7 +38,7 @@ encode_krb5_auth_pack:
|
||||
. . [0] [Integer] 123456
|
||||
. . [1] [Generalized Time] "19940610060317Z"
|
||||
. . [2] [Integer] 42
|
||||
-. . [3] [Octet String] "1234"
|
||||
+. . [3] [Octet String] "krb5data"
|
||||
. . [4] [Octet String] "krb5data"
|
||||
. [1] [Octet String] "pvalue"
|
||||
. [2] [Sequence/Sequence Of]
|
||||
--
|
||||
2.49.0
|
||||
|
||||
|
|
@ -1,381 +0,0 @@
|
|||
From 33afd2a6cfdf87d153170b41fbabfb92be49c422 Mon Sep 17 00:00:00 2001
|
||||
From: Julien Rische <jrische@redhat.com>
|
||||
Date: Thu, 10 Apr 2025 10:04:22 +0200
|
||||
Subject: [PATCH] [downstream] Do not block HMAC-MD4/5 in FIPS mode
|
||||
|
||||
To ensure RC4 HMAC-MD5 was not used in FIPS mode, access to HMAC-MD4/5
|
||||
was not allowed in this mode. However, since we provide the
|
||||
"radius_md5_fips_override" configuration parameter to allow using RADIUS
|
||||
regardless to the FIPS restrictions, we should allow HMAC-MD5 to be used
|
||||
too in this case, because it is required for the newly supported
|
||||
Message-Authenticator attribute.
|
||||
|
||||
A FIPS mode check is added in calculate_mac() which will fail if
|
||||
"radius_md5_fips_override" is not true. It will not affect interactions
|
||||
between krb5kdc and ipa-otpd, because the Message-Authenticator
|
||||
attribute is not generated in this case.
|
||||
---
|
||||
src/lib/crypto/krb/crypto_int.h | 9 +++
|
||||
src/lib/crypto/openssl/Makefile.in | 9 ++-
|
||||
src/lib/crypto/openssl/common.c | 80 +++++++++++++++++++
|
||||
.../crypto/openssl/hash_provider/hash_evp.c | 62 ++------------
|
||||
src/lib/crypto/openssl/hmac.c | 15 ++--
|
||||
src/lib/krad/packet.c | 19 +++--
|
||||
6 files changed, 120 insertions(+), 74 deletions(-)
|
||||
create mode 100644 src/lib/crypto/openssl/common.c
|
||||
|
||||
diff --git a/src/lib/crypto/krb/crypto_int.h b/src/lib/crypto/krb/crypto_int.h
|
||||
index 1ee4b30e02..ff67b6bd35 100644
|
||||
--- a/src/lib/crypto/krb/crypto_int.h
|
||||
+++ b/src/lib/crypto/krb/crypto_int.h
|
||||
@@ -36,6 +36,9 @@
|
||||
|
||||
#include <openssl/opensslv.h>
|
||||
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||
+
|
||||
+#include <openssl/provider.h>
|
||||
+
|
||||
/*
|
||||
* OpenSSL 3.0 relegates MD4 and RC4 to the legacy provider, which must be
|
||||
* explicitly loaded into a library context. Performing this loading within a
|
||||
@@ -660,4 +663,10 @@ iov_cursor_advance(struct iov_cursor *c, size_t nblocks)
|
||||
c->out_pos += nblocks * c->block_size;
|
||||
}
|
||||
|
||||
+#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||
+
|
||||
+krb5_error_code k5_get_ossl_legacy_libctx(OSSL_LIB_CTX **libctx);
|
||||
+
|
||||
+#endif /* OPENSSL_VERSION_NUMBER >= 0x30000000L */
|
||||
+
|
||||
#endif /* CRYPTO_INT_H */
|
||||
diff --git a/src/lib/crypto/openssl/Makefile.in b/src/lib/crypto/openssl/Makefile.in
|
||||
index 8e4cdb8bbf..cc131000bd 100644
|
||||
--- a/src/lib/crypto/openssl/Makefile.in
|
||||
+++ b/src/lib/crypto/openssl/Makefile.in
|
||||
@@ -8,21 +8,24 @@ STLIBOBJS=\
|
||||
hmac.o \
|
||||
kdf.o \
|
||||
pbkdf2.o \
|
||||
- sha256.o
|
||||
+ sha256.o \
|
||||
+ common.o
|
||||
|
||||
OBJS=\
|
||||
$(OUTPRE)cmac.$(OBJEXT) \
|
||||
$(OUTPRE)hmac.$(OBJEXT) \
|
||||
$(OUTPRE)kdf.$(OBJEXT) \
|
||||
$(OUTPRE)pbkdf2.$(OBJEXT) \
|
||||
- $(OUTPRE)sha256.$(OBJEXT)
|
||||
+ $(OUTPRE)sha256.$(OBJEXT) \
|
||||
+ $(OUTPRE)common.$(OBJEXT)
|
||||
|
||||
SRCS=\
|
||||
$(srcdir)/cmac.c \
|
||||
$(srcdir)/hmac.c \
|
||||
$(srcdir)/kdf.c \
|
||||
$(srcdir)/pbkdf2.c \
|
||||
- $(srcdir)/sha256.c
|
||||
+ $(srcdir)/sha256.c \
|
||||
+ $(srcdir)/common.c
|
||||
|
||||
SUBDIROBJLISTS= md4/OBJS.ST \
|
||||
md5/OBJS.ST sha1/OBJS.ST sha2/OBJS.ST \
|
||||
diff --git a/src/lib/crypto/openssl/common.c b/src/lib/crypto/openssl/common.c
|
||||
new file mode 100644
|
||||
index 0000000000..ced43fd54c
|
||||
--- /dev/null
|
||||
+++ b/src/lib/crypto/openssl/common.c
|
||||
@@ -0,0 +1,80 @@
|
||||
+#include "crypto_int.h"
|
||||
+
|
||||
+#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||
+
|
||||
+#include <openssl/provider.h>
|
||||
+#include <openssl/fips.h>
|
||||
+#include <threads.h>
|
||||
+#include <stdbool.h>
|
||||
+
|
||||
+typedef struct ossl_legacy_context {
|
||||
+ bool initialized;
|
||||
+ OSSL_LIB_CTX *libctx;
|
||||
+ OSSL_PROVIDER *default_provider;
|
||||
+ OSSL_PROVIDER *legacy_provider;
|
||||
+} ossl_legacy_context_t;
|
||||
+
|
||||
+static thread_local ossl_legacy_context_t g_ossl_legacy_ctx;
|
||||
+
|
||||
+static krb5_error_code
|
||||
+init_ossl_legacy_ctx(ossl_legacy_context_t *ctx)
|
||||
+{
|
||||
+ ctx->libctx = OSSL_LIB_CTX_new();
|
||||
+ if (!ctx->libctx)
|
||||
+ return KRB5_CRYPTO_INTERNAL;
|
||||
+
|
||||
+ /* Load both legacy and default provider as both may be needed. */
|
||||
+ ctx->default_provider = OSSL_PROVIDER_load(ctx->libctx, "default");
|
||||
+ ctx->legacy_provider = OSSL_PROVIDER_load(ctx->libctx, "legacy");
|
||||
+
|
||||
+ if (!(ctx->default_provider && ctx->legacy_provider))
|
||||
+ return KRB5_CRYPTO_INTERNAL;
|
||||
+
|
||||
+ ctx->initialized = true;
|
||||
+ return 0;
|
||||
+}
|
||||
+
|
||||
+static void
|
||||
+deinit_ossl_legacy_ctx(ossl_legacy_context_t *ctx)
|
||||
+{
|
||||
+ if (ctx->legacy_provider)
|
||||
+ OSSL_PROVIDER_unload(ctx->legacy_provider);
|
||||
+
|
||||
+ if (ctx->default_provider)
|
||||
+ OSSL_PROVIDER_unload(ctx->default_provider);
|
||||
+
|
||||
+ if (ctx->libctx)
|
||||
+ OSSL_LIB_CTX_free(ctx->libctx);
|
||||
+
|
||||
+ ctx->initialized = false;
|
||||
+}
|
||||
+
|
||||
+krb5_error_code
|
||||
+k5_get_ossl_legacy_libctx(OSSL_LIB_CTX **libctx)
|
||||
+{
|
||||
+ krb5_error_code err;
|
||||
+
|
||||
+ if (!FIPS_mode()) {
|
||||
+ if (libctx)
|
||||
+ *libctx = NULL;
|
||||
+ err = 0;
|
||||
+ goto end;
|
||||
+ }
|
||||
+
|
||||
+ if (!g_ossl_legacy_ctx.initialized) {
|
||||
+ err = init_ossl_legacy_ctx(&g_ossl_legacy_ctx);
|
||||
+ if (err) {
|
||||
+ deinit_ossl_legacy_ctx(&g_ossl_legacy_ctx);
|
||||
+ goto end;
|
||||
+ }
|
||||
+ }
|
||||
+
|
||||
+ if (libctx)
|
||||
+ *libctx = g_ossl_legacy_ctx.libctx;
|
||||
+ err = 0;
|
||||
+
|
||||
+end:
|
||||
+ return err;
|
||||
+}
|
||||
+
|
||||
+#endif /* OPENSSL_VERSION_NUMBER >= 0x30000000L */
|
||||
diff --git a/src/lib/crypto/openssl/hash_provider/hash_evp.c b/src/lib/crypto/openssl/hash_provider/hash_evp.c
|
||||
index eb2e693e9f..2fd5d383d6 100644
|
||||
--- a/src/lib/crypto/openssl/hash_provider/hash_evp.c
|
||||
+++ b/src/lib/crypto/openssl/hash_provider/hash_evp.c
|
||||
@@ -44,48 +44,7 @@
|
||||
#define EVP_MD_CTX_free EVP_MD_CTX_destroy
|
||||
#endif
|
||||
|
||||
-#include <openssl/provider.h>
|
||||
#include <openssl/fips.h>
|
||||
-#include <threads.h>
|
||||
-
|
||||
-typedef struct ossl_lib_md_context {
|
||||
- OSSL_LIB_CTX *libctx;
|
||||
- OSSL_PROVIDER *default_provider;
|
||||
- OSSL_PROVIDER *legacy_provider;
|
||||
-} ossl_md_context_t;
|
||||
-
|
||||
-static thread_local ossl_md_context_t *ossl_md_ctx = NULL;
|
||||
-
|
||||
-static krb5_error_code
|
||||
-init_ossl_md_ctx(ossl_md_context_t *ctx, const char *algo)
|
||||
-{
|
||||
- ctx->libctx = OSSL_LIB_CTX_new();
|
||||
- if (!ctx->libctx)
|
||||
- return KRB5_CRYPTO_INTERNAL;
|
||||
-
|
||||
- /* Load both legacy and default provider as both may be needed. */
|
||||
- ctx->default_provider = OSSL_PROVIDER_load(ctx->libctx, "default");
|
||||
- ctx->legacy_provider = OSSL_PROVIDER_load(ctx->libctx, "legacy");
|
||||
-
|
||||
- if (!(ctx->default_provider && ctx->legacy_provider))
|
||||
- return KRB5_CRYPTO_INTERNAL;
|
||||
-
|
||||
- return 0;
|
||||
-}
|
||||
-
|
||||
-static void
|
||||
-deinit_ossl_ctx(ossl_md_context_t *ctx)
|
||||
-{
|
||||
- if (ctx->legacy_provider)
|
||||
- OSSL_PROVIDER_unload(ctx->legacy_provider);
|
||||
-
|
||||
- if (ctx->default_provider)
|
||||
- OSSL_PROVIDER_unload(ctx->default_provider);
|
||||
-
|
||||
- if (ctx->libctx)
|
||||
- OSSL_LIB_CTX_free(ctx->libctx);
|
||||
-}
|
||||
-
|
||||
|
||||
static krb5_error_code
|
||||
hash_evp(const EVP_MD *type, const krb5_crypto_iov *data, size_t num_data,
|
||||
@@ -120,25 +79,14 @@ hash_legacy_evp(const char *algo, const krb5_crypto_iov *data, size_t num_data,
|
||||
krb5_data *output)
|
||||
{
|
||||
krb5_error_code err;
|
||||
+ OSSL_LIB_CTX *ossl_libctx;
|
||||
EVP_MD *md = NULL;
|
||||
|
||||
- if (!ossl_md_ctx) {
|
||||
- ossl_md_ctx = malloc(sizeof(ossl_md_context_t));
|
||||
- if (!ossl_md_ctx) {
|
||||
- err = ENOMEM;
|
||||
- goto end;
|
||||
- }
|
||||
-
|
||||
- err = init_ossl_md_ctx(ossl_md_ctx, algo);
|
||||
- if (err) {
|
||||
- deinit_ossl_ctx(ossl_md_ctx);
|
||||
- free(ossl_md_ctx);
|
||||
- ossl_md_ctx = NULL;
|
||||
- goto end;
|
||||
- }
|
||||
- }
|
||||
+ err = k5_get_ossl_legacy_libctx(&ossl_libctx);
|
||||
+ if (err)
|
||||
+ goto end;
|
||||
|
||||
- md = EVP_MD_fetch(ossl_md_ctx->libctx, algo, NULL);
|
||||
+ md = EVP_MD_fetch(ossl_libctx, algo, NULL);
|
||||
if (!md) {
|
||||
err = KRB5_CRYPTO_INTERNAL;
|
||||
goto end;
|
||||
diff --git a/src/lib/crypto/openssl/hmac.c b/src/lib/crypto/openssl/hmac.c
|
||||
index 25a419d73a..8f9e88fec9 100644
|
||||
--- a/src/lib/crypto/openssl/hmac.c
|
||||
+++ b/src/lib/crypto/openssl/hmac.c
|
||||
@@ -59,7 +59,6 @@
|
||||
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||
#include <openssl/params.h>
|
||||
#include <openssl/core_names.h>
|
||||
-#include <openssl/fips.h>
|
||||
#else
|
||||
#include <openssl/hmac.h>
|
||||
#endif
|
||||
@@ -112,11 +111,7 @@ map_digest(const struct krb5_hash_provider *hash)
|
||||
return EVP_sha256();
|
||||
else if (hash == &krb5int_hash_sha384)
|
||||
return EVP_sha384();
|
||||
-
|
||||
- if (FIPS_mode())
|
||||
- return NULL;
|
||||
-
|
||||
- if (hash == &krb5int_hash_md5)
|
||||
+ else if (hash == &krb5int_hash_md5)
|
||||
return EVP_md5();
|
||||
else if (hash == &krb5int_hash_md4)
|
||||
return EVP_md4();
|
||||
@@ -138,13 +133,19 @@ krb5int_hmac_keyblock(const struct krb5_hash_provider *hash,
|
||||
EVP_MAC_CTX *ctx = NULL;
|
||||
OSSL_PARAM params[2], *p = params;
|
||||
size_t i = 0, md_len;
|
||||
+ OSSL_LIB_CTX *ossl_libctx;
|
||||
+ krb5_error_code err;
|
||||
|
||||
if (md == NULL || keyblock->length > hash->blocksize)
|
||||
return KRB5_CRYPTO_INTERNAL;
|
||||
if (output->length < hash->hashsize)
|
||||
return KRB5_BAD_MSIZE;
|
||||
|
||||
- mac = EVP_MAC_fetch(NULL, "HMAC", NULL);
|
||||
+ err = k5_get_ossl_legacy_libctx(&ossl_libctx);
|
||||
+ if (err)
|
||||
+ return err;
|
||||
+
|
||||
+ mac = EVP_MAC_fetch(ossl_libctx, "HMAC", NULL);
|
||||
if (mac == NULL)
|
||||
return KRB5_CRYPTO_INTERNAL;
|
||||
|
||||
diff --git a/src/lib/krad/packet.c b/src/lib/krad/packet.c
|
||||
index 3c1a4d507e..b95c99df65 100644
|
||||
--- a/src/lib/krad/packet.c
|
||||
+++ b/src/lib/krad/packet.c
|
||||
@@ -278,7 +278,7 @@ lookup_msgauth_addr(const krad_packet *pkt)
|
||||
* auth, which may be from pkt or from a corresponding request.
|
||||
*/
|
||||
static krb5_error_code
|
||||
-calculate_mac(const char *secret, const krad_packet *pkt,
|
||||
+calculate_mac(krb5_context ctx, const char *secret, const krad_packet *pkt,
|
||||
const uint8_t auth[AUTH_FIELD_SIZE],
|
||||
uint8_t mac_out[MD5_DIGEST_SIZE])
|
||||
{
|
||||
@@ -288,6 +288,10 @@ calculate_mac(const char *secret, const krad_packet *pkt,
|
||||
krb5_crypto_iov input[5];
|
||||
krb5_data ksecr, mac;
|
||||
|
||||
+ /* Do not use HMAC-MD5 if not explicitly allowed */
|
||||
+ if (kr_use_fips(ctx))
|
||||
+ return KRB5_CRYPTO_INTERNAL;
|
||||
+
|
||||
msgauth_attr = lookup_msgauth_addr(pkt);
|
||||
if (msgauth_attr == NULL)
|
||||
return EINVAL;
|
||||
@@ -393,7 +397,8 @@ krad_packet_new_request(krb5_context ctx, const char *secret, krad_code code,
|
||||
|
||||
if (msgauth_required) {
|
||||
/* Calculate and set the Message-Authenticator MAC. */
|
||||
- retval = calculate_mac(secret, pkt, pkt_auth(pkt), pkt_attr(pkt) + 2);
|
||||
+ retval = calculate_mac(ctx, secret, pkt, pkt_auth(pkt),
|
||||
+ pkt_attr(pkt) + 2);
|
||||
if (retval != 0)
|
||||
goto error;
|
||||
}
|
||||
@@ -454,7 +459,7 @@ krad_packet_new_response(krb5_context ctx, const char *secret, krad_code code,
|
||||
* section 5.14, use the authenticator from the request, not from the
|
||||
* response.
|
||||
*/
|
||||
- retval = calculate_mac(secret, pkt, pkt_auth(request),
|
||||
+ retval = calculate_mac(ctx, secret, pkt, pkt_auth(request),
|
||||
pkt_attr(pkt) + 2);
|
||||
if (retval != 0)
|
||||
goto error;
|
||||
@@ -476,7 +481,7 @@ error:
|
||||
/* Verify the Message-Authenticator value in pkt, using the provided
|
||||
* authenticator (which may be from pkt or from a corresponding request). */
|
||||
static krb5_error_code
|
||||
-verify_msgauth(const char *secret, const krad_packet *pkt,
|
||||
+verify_msgauth(krb5_context ctx, const char *secret, const krad_packet *pkt,
|
||||
const uint8_t auth[AUTH_FIELD_SIZE])
|
||||
{
|
||||
uint8_t mac[MD5_DIGEST_SIZE];
|
||||
@@ -488,7 +493,7 @@ verify_msgauth(const char *secret, const krad_packet *pkt,
|
||||
if (msgauth == NULL)
|
||||
return ENODATA;
|
||||
|
||||
- retval = calculate_mac(secret, pkt, auth, mac);
|
||||
+ retval = calculate_mac(ctx, secret, pkt, auth, mac);
|
||||
if (retval)
|
||||
return retval;
|
||||
|
||||
@@ -561,7 +566,7 @@ krad_packet_decode_request(krb5_context ctx, const char *secret,
|
||||
|
||||
/* Verify Message-Authenticator if present. */
|
||||
if (has_pkt_msgauth(req)) {
|
||||
- retval = verify_msgauth(secret, req, pkt_auth(req));
|
||||
+ retval = verify_msgauth(ctx, secret, req, pkt_auth(req));
|
||||
if (retval) {
|
||||
krad_packet_free(req);
|
||||
return retval;
|
||||
@@ -613,7 +618,7 @@ krad_packet_decode_response(krb5_context ctx, const char *secret,
|
||||
|
||||
/* Verify Message-Authenticator if present. */
|
||||
if (has_pkt_msgauth(*rsppkt)) {
|
||||
- if (verify_msgauth(secret, *rsppkt, pkt_auth(tmp)) != 0)
|
||||
+ if (verify_msgauth(ctx, secret, *rsppkt, pkt_auth(tmp)) != 0)
|
||||
continue;
|
||||
}
|
||||
|
||||
--
|
||||
2.49.0
|
||||
|
||||
|
|
@ -1,189 +0,0 @@
|
|||
From 1761e06398e4f043e4f540f57131c37fcc53a1b9 Mon Sep 17 00:00:00 2001
|
||||
From: Alexander Bokovoy <abokovoy@redhat.com>
|
||||
Date: Wed, 10 Dec 2025 10:42:02 +0200
|
||||
Subject: [PATCH] Fix strchr() conformance to C23
|
||||
|
||||
C23 7.28.5.1 specifies search functions such as strchr() as generic,
|
||||
returning const char * if the first argument is of type const char *.
|
||||
Fix uses of strchr() to conform to this change.
|
||||
|
||||
[jrische@redhat.com: altered changes to avoid casts; fixed an
|
||||
additional case]
|
||||
[ghudson@mit.edu: condensed some declarations; rewrote commit message]
|
||||
|
||||
ticket: 9191 (new)
|
||||
(cherry picked from commit 6cd8580d823585d50ee4f30efd9f7e855823a369)
|
||||
---
|
||||
src/lib/krb5/ccache/ccbase.c | 4 ++--
|
||||
src/lib/krb5/os/expand_path.c | 3 ++-
|
||||
src/lib/krb5/os/locate_kdc.c | 15 +++++++--------
|
||||
src/plugins/preauth/pkinit/pkinit_crypto.h | 2 +-
|
||||
.../preauth/pkinit/pkinit_crypto_openssl.c | 6 +++---
|
||||
src/plugins/preauth/pkinit/pkinit_identity.c | 2 +-
|
||||
src/plugins/preauth/pkinit/pkinit_matching.c | 2 +-
|
||||
src/tests/responder.c | 3 +--
|
||||
8 files changed, 18 insertions(+), 19 deletions(-)
|
||||
|
||||
diff --git a/src/lib/krb5/ccache/ccbase.c b/src/lib/krb5/ccache/ccbase.c
|
||||
index 5a01320832..1aada91b5e 100644
|
||||
--- a/src/lib/krb5/ccache/ccbase.c
|
||||
+++ b/src/lib/krb5/ccache/ccbase.c
|
||||
@@ -201,8 +201,8 @@ krb5_cc_register(krb5_context context, const krb5_cc_ops *ops,
|
||||
krb5_error_code KRB5_CALLCONV
|
||||
krb5_cc_resolve (krb5_context context, const char *name, krb5_ccache *cache)
|
||||
{
|
||||
- char *pfx, *cp;
|
||||
- const char *resid;
|
||||
+ char *pfx;
|
||||
+ const char *cp, *resid;
|
||||
unsigned int pfxlen;
|
||||
krb5_error_code err;
|
||||
const krb5_cc_ops *ops;
|
||||
diff --git a/src/lib/krb5/os/expand_path.c b/src/lib/krb5/os/expand_path.c
|
||||
index 5cbccf08c8..6569b8820b 100644
|
||||
--- a/src/lib/krb5/os/expand_path.c
|
||||
+++ b/src/lib/krb5/os/expand_path.c
|
||||
@@ -454,7 +454,8 @@ k5_expand_path_tokens_extra(krb5_context context, const char *path_in,
|
||||
{
|
||||
krb5_error_code ret;
|
||||
struct k5buf buf;
|
||||
- char *tok_begin, *tok_end, *tok_val, **extra_tokens = NULL, *path;
|
||||
+ const char *tok_begin, *tok_end;
|
||||
+ char *tok_val, **extra_tokens = NULL, *path;
|
||||
const char *path_left;
|
||||
size_t nargs = 0, i;
|
||||
va_list ap;
|
||||
diff --git a/src/lib/krb5/os/locate_kdc.c b/src/lib/krb5/os/locate_kdc.c
|
||||
index edca5ac7eb..47e15c849f 100644
|
||||
--- a/src/lib/krb5/os/locate_kdc.c
|
||||
+++ b/src/lib/krb5/os/locate_kdc.c
|
||||
@@ -188,8 +188,8 @@ oom:
|
||||
}
|
||||
|
||||
static void
|
||||
-parse_uri_if_https(const char *host_or_uri, k5_transport *transport,
|
||||
- const char **host, const char **uri_path)
|
||||
+parse_uri_if_https(char *host_or_uri, k5_transport *transport,
|
||||
+ char **host, const char **uri_path)
|
||||
{
|
||||
char *cp;
|
||||
|
||||
@@ -229,8 +229,7 @@ locate_srv_conf_1(krb5_context context, const krb5_data *realm,
|
||||
k5_transport transport, int udpport)
|
||||
{
|
||||
const char *realm_srv_names[4];
|
||||
- char **hostlist = NULL, *realmstr = NULL, *host = NULL;
|
||||
- const char *hostspec;
|
||||
+ char **hostlist = NULL, *realmstr = NULL, *host = NULL, *hostspec;
|
||||
krb5_error_code code;
|
||||
int i, default_port;
|
||||
|
||||
@@ -535,8 +534,8 @@ prof_locate_server(krb5_context context, const krb5_data *realm,
|
||||
* Return a NULL *host_out if there are any problems parsing the URI.
|
||||
*/
|
||||
static void
|
||||
-parse_uri_fields(const char *uri, k5_transport *transport_out,
|
||||
- const char **host_out, int *primary_out)
|
||||
+parse_uri_fields(char *uri, k5_transport *transport_out,
|
||||
+ char **host_out, int *primary_out)
|
||||
|
||||
{
|
||||
k5_transport transport;
|
||||
@@ -604,8 +603,8 @@ locate_uri(krb5_context context, const krb5_data *realm,
|
||||
krb5_error_code ret;
|
||||
k5_transport transport, host_trans;
|
||||
struct srv_dns_entry *answers, *entry;
|
||||
- char *host;
|
||||
- const char *host_field, *path;
|
||||
+ char *host, *host_field;
|
||||
+ const char *path;
|
||||
int port, def_port, primary;
|
||||
|
||||
ret = k5_make_uri_query(context, realm, req_service, &answers);
|
||||
diff --git a/src/plugins/preauth/pkinit/pkinit_crypto.h b/src/plugins/preauth/pkinit/pkinit_crypto.h
|
||||
index 3b12e904b1..99e2394040 100644
|
||||
--- a/src/plugins/preauth/pkinit/pkinit_crypto.h
|
||||
+++ b/src/plugins/preauth/pkinit/pkinit_crypto.h
|
||||
@@ -456,7 +456,7 @@ krb5_error_code crypto_load_cas_and_crls
|
||||
defines the storage type (file, directory, etc) */
|
||||
int catype, /* IN
|
||||
defines the ca type (anchor, intermediate, crls) */
|
||||
- char *id); /* IN
|
||||
+ const char *id); /* IN
|
||||
defines the location (filename, directory name, etc) */
|
||||
|
||||
/*
|
||||
diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c
|
||||
index 429b7d202c..6013080afc 100644
|
||||
--- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c
|
||||
+++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c
|
||||
@@ -4956,7 +4956,7 @@ load_cas_and_crls(krb5_context context,
|
||||
pkinit_req_crypto_context req_cryptoctx,
|
||||
pkinit_identity_crypto_context id_cryptoctx,
|
||||
int catype,
|
||||
- char *filename)
|
||||
+ const char *filename)
|
||||
{
|
||||
STACK_OF(X509_INFO) *sk = NULL;
|
||||
STACK_OF(X509) *ca_certs = NULL;
|
||||
@@ -5114,7 +5114,7 @@ load_cas_and_crls_dir(krb5_context context,
|
||||
pkinit_req_crypto_context req_cryptoctx,
|
||||
pkinit_identity_crypto_context id_cryptoctx,
|
||||
int catype,
|
||||
- char *dirname)
|
||||
+ const char *dirname)
|
||||
{
|
||||
krb5_error_code retval = EINVAL;
|
||||
DIR *d = NULL;
|
||||
@@ -5166,7 +5166,7 @@ crypto_load_cas_and_crls(krb5_context context,
|
||||
pkinit_identity_crypto_context id_cryptoctx,
|
||||
int idtype,
|
||||
int catype,
|
||||
- char *id)
|
||||
+ const char *id)
|
||||
{
|
||||
switch (idtype) {
|
||||
case IDTYPE_FILE:
|
||||
diff --git a/src/plugins/preauth/pkinit/pkinit_identity.c b/src/plugins/preauth/pkinit/pkinit_identity.c
|
||||
index a5a979f279..b06d519c66 100644
|
||||
--- a/src/plugins/preauth/pkinit/pkinit_identity.c
|
||||
+++ b/src/plugins/preauth/pkinit/pkinit_identity.c
|
||||
@@ -474,7 +474,7 @@ process_option_ca_crl(krb5_context context,
|
||||
const char *value,
|
||||
int catype)
|
||||
{
|
||||
- char *residual;
|
||||
+ const char *residual;
|
||||
unsigned int typelen;
|
||||
int idtype;
|
||||
|
||||
diff --git a/src/plugins/preauth/pkinit/pkinit_matching.c b/src/plugins/preauth/pkinit/pkinit_matching.c
|
||||
index b42485a50a..5a7f2ba3fa 100644
|
||||
--- a/src/plugins/preauth/pkinit/pkinit_matching.c
|
||||
+++ b/src/plugins/preauth/pkinit/pkinit_matching.c
|
||||
@@ -263,7 +263,7 @@ parse_rule_component(krb5_context context,
|
||||
char err_buf[128];
|
||||
int ret;
|
||||
struct keyword_desc *kw, *nextkw;
|
||||
- char *nk;
|
||||
+ const char *nk;
|
||||
int found_next_kw = 0;
|
||||
char *value = NULL;
|
||||
size_t len;
|
||||
diff --git a/src/tests/responder.c b/src/tests/responder.c
|
||||
index 82f870ea5d..4221a20283 100644
|
||||
--- a/src/tests/responder.c
|
||||
+++ b/src/tests/responder.c
|
||||
@@ -282,8 +282,7 @@ responder(krb5_context ctx, void *rawdata, krb5_responder_context rctx)
|
||||
/* Provide a particular response for an OTP challenge. */
|
||||
if (data->otp_answer != NULL) {
|
||||
if (krb5_responder_otp_get_challenge(ctx, rctx, &ochl) == 0) {
|
||||
- key = strchr(data->otp_answer, '=');
|
||||
- if (key != NULL) {
|
||||
+ if (strchr(data->otp_answer, '=') != NULL) {
|
||||
/* Make a copy of the answer that we can chop up. */
|
||||
key = strdup(data->otp_answer);
|
||||
if (key == NULL)
|
||||
--
|
||||
2.51.1
|
||||
|
||||
|
|
@ -1,226 +0,0 @@
|
|||
From 3baf9b93dc1dfe38585722c71d7268304cb4a01a Mon Sep 17 00:00:00 2001
|
||||
From: Alexander Bokovoy <abokovoy@redhat.com>
|
||||
Date: Sun, 21 Sep 2025 11:14:51 +0300
|
||||
Subject: libkrb5: in case PKINIT is configured, attempt Anonymous
|
||||
PKINIT for FAST
|
||||
|
||||
If auto_fast_armor is configured for the realm or globally, optimistically
|
||||
assume that Anonymous PKINIT is supported as well and try to obtain it for
|
||||
FAST use in case no pre-made FAST channel was established by the caller.
|
||||
|
||||
This behavior will automatically enable use of passwordless pre-authentication
|
||||
methods which rely on FAST channel presence in deployments such as FreeIPA.
|
||||
|
||||
Notably, Microsoft Active Directory KDCs do not support Anonymous PKINIT. For
|
||||
these deployments only a machine account (host keytab) can be used to build a
|
||||
FAST channel. However, libkrb5 does not have access to /etc/krb5.keytab in a
|
||||
general case.
|
||||
|
||||
Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
|
||||
---
|
||||
src/lib/krb5/krb/fast.c | 118 ++++++++++++++++++++++++++++++++++++++++
|
||||
src/lib/krb5/krb/fast.h | 2 +
|
||||
src/man/krb5.conf.man | 13 +++++
|
||||
3 files changed, 133 insertions(+)
|
||||
|
||||
diff --git a/src/lib/krb5/krb/fast.c b/src/lib/krb5/krb/fast.c
|
||||
index 62c9f0841..ee2e08189 100644
|
||||
--- a/src/lib/krb5/krb/fast.c
|
||||
+++ b/src/lib/krb5/krb/fast.c
|
||||
@@ -168,6 +168,109 @@ krb5int_fast_prep_req_body(krb5_context context,
|
||||
return retval;
|
||||
}
|
||||
|
||||
+static krb5_boolean
|
||||
+fast_is_pkinit_allowed(krb5_context context, krb5_data *realm)
|
||||
+{
|
||||
+ int value;
|
||||
+ krb5_error_code retval = EINVAL;
|
||||
+ char realmstr[1024];
|
||||
+ const char *option = "auto_fast_armor";
|
||||
+ const int def_value = FALSE;
|
||||
+
|
||||
+ if (realm != NULL && realm->length > sizeof(realmstr)-1)
|
||||
+ return FALSE;
|
||||
+
|
||||
+ if (realm != NULL) {
|
||||
+ strncpy(realmstr, realm->data, realm->length);
|
||||
+ realmstr[realm->length] = '\0';
|
||||
+
|
||||
+ retval = profile_get_boolean(context->profile,
|
||||
+ KRB5_CONF_REALMS, realmstr,
|
||||
+ option, def_value, &value);
|
||||
+ }
|
||||
+
|
||||
+ return retval ? FALSE : value;
|
||||
+
|
||||
+}
|
||||
+
|
||||
+static krb5_error_code
|
||||
+fast_acquire_pkinit_armor(krb5_context context,
|
||||
+ struct krb5int_fast_request_state *state,
|
||||
+ krb5_get_init_creds_opt *opt, krb5_kdc_req *request)
|
||||
+{
|
||||
+ krb5_context ctx;
|
||||
+ krb5_get_init_creds_opt *options = NULL;
|
||||
+ krb5_error_code retval = 0;
|
||||
+ krb5_data *target_realm = &request->server->realm;
|
||||
+ krb5_creds creds;
|
||||
+ krb5_principal anon_princ = NULL;
|
||||
+ krb5_ccache out_cc;
|
||||
+
|
||||
+ /* short circuit, we are asked to perform Anonymous PKINIT already */
|
||||
+ if (opt->flags & KRB5_GET_INIT_CREDS_OPT_ANONYMOUS) {
|
||||
+ return EINVAL;
|
||||
+ }
|
||||
+
|
||||
+ /* skip realms which do not allow use of automated FAST armor */
|
||||
+ if (!fast_is_pkinit_allowed(context, target_realm)) {
|
||||
+ return EINVAL;
|
||||
+ }
|
||||
+
|
||||
+ retval = krb5_init_context(&ctx);
|
||||
+ if (retval != 0) {
|
||||
+ return retval;
|
||||
+ }
|
||||
+ retval = krb5_get_init_creds_opt_alloc(ctx, &options);
|
||||
+ if (retval != 0) {
|
||||
+ goto cleanup;
|
||||
+ }
|
||||
+ krb5_get_init_creds_opt_set_anonymous(options, 1);
|
||||
+ retval = krb5_cc_new_unique(ctx, "MEMORY", NULL, &out_cc);
|
||||
+ if (retval != 0) {
|
||||
+ goto cleanup;
|
||||
+ }
|
||||
+
|
||||
+ retval = krb5_get_init_creds_opt_set_out_ccache(ctx, options, out_cc);
|
||||
+ if (retval != 0) {
|
||||
+ goto cleanup;
|
||||
+ }
|
||||
+
|
||||
+ retval = krb5_build_principal_ext(ctx, &anon_princ,
|
||||
+ target_realm->length, target_realm->data,
|
||||
+ strlen(KRB5_WELLKNOWN_NAMESTR),
|
||||
+ KRB5_WELLKNOWN_NAMESTR,
|
||||
+ strlen(KRB5_ANONYMOUS_PRINCSTR),
|
||||
+ KRB5_ANONYMOUS_PRINCSTR, 0);
|
||||
+ if (retval != 0) {
|
||||
+ goto cleanup;
|
||||
+ }
|
||||
+
|
||||
+ retval = krb5_get_init_creds_password(ctx, &creds, anon_princ, 0,
|
||||
+ NULL /* no prompter */, NULL,
|
||||
+ 0, NULL /* service name */,
|
||||
+ options);
|
||||
+ if (retval == 0) {
|
||||
+ state->fast_state_flags |= KRB5INT_FAST_OWN_ARMOR;
|
||||
+ state->armor_ccache = out_cc;
|
||||
+ }
|
||||
+cleanup:
|
||||
+ if (retval != 0 && out_cc != NULL) {
|
||||
+ (void) krb5_cc_destroy(ctx, out_cc);
|
||||
+ }
|
||||
+ if (retval == 0) {
|
||||
+ krb5_free_cred_contents(ctx, &creds);
|
||||
+ }
|
||||
+ if (options != NULL) {
|
||||
+ krb5_get_init_creds_opt_free(ctx, options);
|
||||
+ }
|
||||
+ if (anon_princ != NULL) {
|
||||
+ krb5_free_principal(ctx, anon_princ);
|
||||
+ }
|
||||
+ krb5_free_context(ctx);
|
||||
+
|
||||
+ return retval;
|
||||
+}
|
||||
+
|
||||
krb5_error_code
|
||||
krb5int_fast_as_armor(krb5_context context,
|
||||
struct krb5int_fast_request_state *state,
|
||||
@@ -178,10 +281,20 @@ krb5int_fast_as_armor(krb5_context context,
|
||||
krb5_principal target_principal = NULL;
|
||||
krb5_data *target_realm;
|
||||
const char *ccname = k5_gic_opt_get_fast_ccache_name(opt);
|
||||
+ char *fast_ccname = NULL;
|
||||
krb5_flags fast_flags;
|
||||
|
||||
krb5_clear_error_message(context);
|
||||
target_realm = &request->server->realm;
|
||||
+ if (ccname == NULL) {
|
||||
+ retval = fast_acquire_pkinit_armor(context, state, opt, request);
|
||||
+ if (retval == 0) {
|
||||
+ retval = krb5_cc_get_full_name(context, state->armor_ccache, &fast_ccname);
|
||||
+ if (retval == 0 && fast_ccname != NULL)
|
||||
+ ccname = fast_ccname;
|
||||
+ }
|
||||
+ retval = 0;
|
||||
+ }
|
||||
if (ccname != NULL) {
|
||||
TRACE_FAST_ARMOR_CCACHE(context, ccname);
|
||||
state->fast_state_flags |= KRB5INT_FAST_ARMOR_AVAIL;
|
||||
@@ -220,6 +333,8 @@ krb5int_fast_as_armor(krb5_context context,
|
||||
krb5_cc_close(context, ccache);
|
||||
if (target_principal)
|
||||
krb5_free_principal(context, target_principal);
|
||||
+ if (fast_ccname)
|
||||
+ free(fast_ccname);
|
||||
return retval;
|
||||
}
|
||||
|
||||
@@ -615,6 +730,9 @@ krb5int_fast_free_state(krb5_context context,
|
||||
/*We are responsible for none of the store in the fast_outer_req*/
|
||||
krb5_free_keyblock(context, state->armor_key);
|
||||
krb5_free_fast_armor(context, state->armor);
|
||||
+ if (state->fast_state_flags & KRB5INT_FAST_OWN_ARMOR) {
|
||||
+ krb5_cc_destroy(context, state->armor_ccache);
|
||||
+ }
|
||||
free(state);
|
||||
}
|
||||
|
||||
diff --git a/src/lib/krb5/krb/fast.h b/src/lib/krb5/krb/fast.h
|
||||
index 7156ea203..e5fe8bd54 100644
|
||||
--- a/src/lib/krb5/krb/fast.h
|
||||
+++ b/src/lib/krb5/krb/fast.h
|
||||
@@ -34,6 +34,7 @@ struct krb5int_fast_request_state {
|
||||
krb5_kdc_req fast_outer_request;
|
||||
krb5_keyblock *armor_key; /*non-null means fast is in use*/
|
||||
krb5_fast_armor *armor;
|
||||
+ krb5_ccache armor_ccache;
|
||||
krb5_ui_4 fast_state_flags;
|
||||
krb5_ui_4 fast_options;
|
||||
krb5_int32 nonce;
|
||||
@@ -41,6 +42,7 @@ struct krb5int_fast_request_state {
|
||||
|
||||
#define KRB5INT_FAST_DO_FAST (1l<<0) /* Perform FAST */
|
||||
#define KRB5INT_FAST_ARMOR_AVAIL (1l<<1)
|
||||
+#define KRB5INT_FAST_OWN_ARMOR (1l<<2)
|
||||
|
||||
krb5_error_code
|
||||
krb5int_fast_prep_req_body(krb5_context context,
|
||||
diff --git a/src/man/krb5.conf.man b/src/man/krb5.conf.man
|
||||
index d4caa2bd3..ac7649647 100644
|
||||
--- a/src/man/krb5.conf.man
|
||||
+++ b/src/man/krb5.conf.man
|
||||
@@ -650,6 +650,19 @@ primary KDC, in case the user\(aqs password has just been changed, and
|
||||
the updated database has not been propagated to the replica
|
||||
servers yet. New in release 1.19.
|
||||
.TP
|
||||
+\fBauto_fast_armor\fP
|
||||
+If this flag is true, then initial ticket request will use Anonymous
|
||||
+PKINIT to protect the communication as a FAST channel in case an application
|
||||
+did not provide its own FAST channel. This is useful for deployments where
|
||||
+pre-authentication methods require use of the FAST channel, such as
|
||||
+passwordless methods provided by FreeIPA. Microsoft Active Directory
|
||||
+implementation of PKINIT does not support Anonymous PKINIT feature.
|
||||
+As a result, \fIauto_fast_armor\fP defaults to false.
|
||||
+.sp
|
||||
+Use of \fIauto_fast_armor = true\fP requires properly configured PKINIT and
|
||||
+WELLKNOWN/ANONYMOUS principal defined on the KDC side. Consult KDC documentation
|
||||
+for details.
|
||||
+.TP
|
||||
\fBv4_instance_convert\fP
|
||||
This subsection allows the administrator to configure exceptions
|
||||
to the \fBdefault_domain\fP mapping rule. It contains V4 instances
|
||||
--
|
||||
2.51.0
|
||||
|
||||
|
|
@ -1,40 +0,0 @@
|
|||
From ff580d9cf86202d45454a6b6f53accc22cb40b62 Mon Sep 17 00:00:00 2001
|
||||
From: Alexander Bokovoy <abokovoy@redhat.com>
|
||||
Date: Sun, 19 Oct 2025 18:14:29 +0300
|
||||
Subject: [PATCH] bail if prompter is not specified but required
|
||||
|
||||
GSSAPI gss_init_sec_context() may trigger credential re-initialization
|
||||
if the cred in ccache is expired. If automatic FAST armor is in use,
|
||||
we'd request Anonymous PKINIT and use it as an armor and this will
|
||||
enable seeing pre-authentication methods which require armor presence.
|
||||
|
||||
OTP is one of such methods and its use requires prompter to be set,
|
||||
but GSSAPI cannot specify a prompter and thus we should fail any
|
||||
pre-auth where a prompter wasn't passed.
|
||||
|
||||
PKINIT PKCS11 and SAM-2 preauth methods use KRB5_LIBOS_CANTREADPWD while PKINIT
|
||||
and gic_pwd.c use EIO. Use EIO here because we technically attempt to read a
|
||||
PIN rather than a password.
|
||||
|
||||
Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
|
||||
---
|
||||
src/lib/krb5/krb/preauth_otp.c | 3 +++
|
||||
1 file changed, 3 insertions(+)
|
||||
|
||||
diff --git a/src/lib/krb5/krb/preauth_otp.c b/src/lib/krb5/krb/preauth_otp.c
|
||||
index 07ffc15c2..48003da62 100644
|
||||
--- a/src/lib/krb5/krb/preauth_otp.c
|
||||
+++ b/src/lib/krb5/krb/preauth_otp.c
|
||||
@@ -479,6 +479,9 @@ doprompt(krb5_context context, krb5_prompter_fct prompter, void *prompter_data,
|
||||
krb5_error_code retval;
|
||||
krb5_prompt_type prompt_type = KRB5_PROMPT_TYPE_PREAUTH;
|
||||
|
||||
+ if (prompter == NULL)
|
||||
+ return EIO;
|
||||
+
|
||||
if (prompttxt == NULL || out == NULL)
|
||||
return EINVAL;
|
||||
|
||||
--
|
||||
2.51.0
|
||||
|
||||
202
2010-007-patch.txt
Normal file
202
2010-007-patch.txt
Normal file
|
|
@ -0,0 +1,202 @@
|
|||
Index: krb5-1.8/src/plugins/preauth/pkinit/pkinit_srv.c
|
||||
===================================================================
|
||||
--- krb5-1.8/src/plugins/preauth/pkinit/pkinit_srv.c (revision 24455)
|
||||
+++ krb5-1.8/src/plugins/preauth/pkinit/pkinit_srv.c (working copy)
|
||||
@@ -691,8 +691,7 @@
|
||||
krb5_reply_key_pack *key_pack = NULL;
|
||||
krb5_reply_key_pack_draft9 *key_pack9 = NULL;
|
||||
krb5_data *encoded_key_pack = NULL;
|
||||
- unsigned int num_types;
|
||||
- krb5_cksumtype *cksum_types = NULL;
|
||||
+ krb5_cksumtype cksum_type;
|
||||
|
||||
pkinit_kdc_context plgctx;
|
||||
pkinit_kdc_req_context reqctx;
|
||||
@@ -882,14 +881,25 @@
|
||||
retval = ENOMEM;
|
||||
goto cleanup;
|
||||
}
|
||||
- /* retrieve checksums for a given enctype of the reply key */
|
||||
- retval = krb5_c_keyed_checksum_types(context,
|
||||
- encrypting_key->enctype, &num_types, &cksum_types);
|
||||
- if (retval)
|
||||
- goto cleanup;
|
||||
|
||||
- /* pick the first of acceptable enctypes for the checksum */
|
||||
- retval = krb5_c_make_checksum(context, cksum_types[0],
|
||||
+ switch (encrypting_key->enctype) {
|
||||
+ case ENCTYPE_DES_CBC_MD4:
|
||||
+ cksum_type = CKSUMTYPE_RSA_MD4_DES;
|
||||
+ break;
|
||||
+ case ENCTYPE_DES_CBC_MD5:
|
||||
+ case ENCTYPE_DES_CBC_CRC:
|
||||
+ cksum_type = CKSUMTYPE_RSA_MD5_DES;
|
||||
+ break;
|
||||
+ default:
|
||||
+ retval = krb5int_c_mandatory_cksumtype(context,
|
||||
+ encrypting_key->enctype,
|
||||
+ &cksum_type);
|
||||
+ if (retval)
|
||||
+ goto cleanup;
|
||||
+ break;
|
||||
+ }
|
||||
+
|
||||
+ retval = krb5_c_make_checksum(context, cksum_type,
|
||||
encrypting_key, KRB5_KEYUSAGE_TGS_REQ_AUTH_CKSUM,
|
||||
req_pkt, &key_pack->asChecksum);
|
||||
if (retval) {
|
||||
@@ -1033,7 +1043,6 @@
|
||||
krb5_free_data(context, encoded_key_pack);
|
||||
free(dh_pubkey);
|
||||
free(server_key);
|
||||
- free(cksum_types);
|
||||
|
||||
switch ((int)padata->pa_type) {
|
||||
case KRB5_PADATA_PK_AS_REQ:
|
||||
Index: krb5-1.8/src/lib/crypto/krb/cksumtypes.c
|
||||
===================================================================
|
||||
--- krb5-1.8/src/lib/crypto/krb/cksumtypes.c (revision 24455)
|
||||
+++ krb5-1.8/src/lib/crypto/krb/cksumtypes.c (working copy)
|
||||
@@ -101,7 +101,7 @@
|
||||
|
||||
{ CKSUMTYPE_MD5_HMAC_ARCFOUR,
|
||||
"md5-hmac-rc4", { 0 }, "Microsoft MD5 HMAC",
|
||||
- NULL, &krb5int_hash_md5,
|
||||
+ &krb5int_enc_arcfour, &krb5int_hash_md5,
|
||||
krb5int_hmacmd5_checksum, NULL,
|
||||
16, 16, 0 },
|
||||
};
|
||||
Index: krb5-1.8/src/lib/crypto/krb/keyed_checksum_types.c
|
||||
===================================================================
|
||||
--- krb5-1.8/src/lib/crypto/krb/keyed_checksum_types.c (revision 24455)
|
||||
+++ krb5-1.8/src/lib/crypto/krb/keyed_checksum_types.c (working copy)
|
||||
@@ -35,6 +35,13 @@
|
||||
{
|
||||
if (ctp->flags & CKSUM_UNKEYED)
|
||||
return FALSE;
|
||||
+ /* Stream ciphers do not play well with RFC 3961 key derivation, so be
|
||||
+ * conservative with RC4. */
|
||||
+ if ((ktp->etype == ENCTYPE_ARCFOUR_HMAC ||
|
||||
+ ktp->etype == ENCTYPE_ARCFOUR_HMAC_EXP) &&
|
||||
+ ctp->ctype != CKSUMTYPE_HMAC_MD5_ARCFOUR &&
|
||||
+ ctp->ctype != CKSUMTYPE_MD5_HMAC_ARCFOUR)
|
||||
+ return FALSE;
|
||||
return (!ctp->enc || ktp->enc == ctp->enc);
|
||||
}
|
||||
|
||||
Index: krb5-1.8/src/lib/crypto/krb/dk/derive.c
|
||||
===================================================================
|
||||
--- krb5-1.8/src/lib/crypto/krb/dk/derive.c (revision 24455)
|
||||
+++ krb5-1.8/src/lib/crypto/krb/dk/derive.c (working copy)
|
||||
@@ -91,6 +91,8 @@
|
||||
blocksize = enc->block_size;
|
||||
keybytes = enc->keybytes;
|
||||
|
||||
+ if (blocksize == 1)
|
||||
+ return KRB5_BAD_ENCTYPE;
|
||||
if (inkey->keyblock.length != enc->keylength || outrnd->length != keybytes)
|
||||
return KRB5_CRYPTO_INTERNAL;
|
||||
|
||||
Index: krb5-1.8/src/lib/gssapi/krb5/util_crypt.c
|
||||
===================================================================
|
||||
--- krb5-1.8/src/lib/gssapi/krb5/util_crypt.c (revision 24455)
|
||||
+++ krb5-1.8/src/lib/gssapi/krb5/util_crypt.c (working copy)
|
||||
@@ -119,10 +119,22 @@
|
||||
if (code != 0)
|
||||
return code;
|
||||
|
||||
- code = (*kaccess.mandatory_cksumtype)(context, subkey->keyblock.enctype,
|
||||
- cksumtype);
|
||||
- if (code != 0)
|
||||
- return code;
|
||||
+ switch (subkey->keyblock.enctype) {
|
||||
+ case ENCTYPE_DES_CBC_MD4:
|
||||
+ *cksumtype = CKSUMTYPE_RSA_MD4_DES;
|
||||
+ break;
|
||||
+ case ENCTYPE_DES_CBC_MD5:
|
||||
+ case ENCTYPE_DES_CBC_CRC:
|
||||
+ *cksumtype = CKSUMTYPE_RSA_MD5_DES;
|
||||
+ break;
|
||||
+ default:
|
||||
+ code = (*kaccess.mandatory_cksumtype)(context,
|
||||
+ subkey->keyblock.enctype,
|
||||
+ cksumtype);
|
||||
+ if (code != 0)
|
||||
+ return code;
|
||||
+ break;
|
||||
+ }
|
||||
|
||||
switch (subkey->keyblock.enctype) {
|
||||
case ENCTYPE_DES_CBC_MD5:
|
||||
Index: krb5-1.8/src/lib/krb5/krb/pac.c
|
||||
===================================================================
|
||||
--- krb5-1.8/src/lib/krb5/krb/pac.c (revision 24455)
|
||||
+++ krb5-1.8/src/lib/krb5/krb/pac.c (working copy)
|
||||
@@ -582,6 +582,8 @@
|
||||
checksum.checksum_type = load_32_le(p);
|
||||
checksum.length = checksum_data.length - PAC_SIGNATURE_DATA_LENGTH;
|
||||
checksum.contents = p + PAC_SIGNATURE_DATA_LENGTH;
|
||||
+ if (!krb5_c_is_keyed_cksum(checksum.checksum_type))
|
||||
+ return KRB5KRB_AP_ERR_INAPP_CKSUM;
|
||||
|
||||
pac_data.length = pac->data.length;
|
||||
pac_data.data = malloc(pac->data.length);
|
||||
Index: krb5-1.8/src/lib/krb5/krb/preauth2.c
|
||||
===================================================================
|
||||
--- krb5-1.8/src/lib/krb5/krb/preauth2.c (revision 24455)
|
||||
+++ krb5-1.8/src/lib/krb5/krb/preauth2.c (working copy)
|
||||
@@ -1578,7 +1578,9 @@
|
||||
|
||||
cksum = sc2->sam_cksum;
|
||||
|
||||
- while (*cksum) {
|
||||
+ for (; *cksum; cksum++) {
|
||||
+ if (!krb5_c_is_keyed_cksum((*cksum)->checksum_type))
|
||||
+ continue;
|
||||
/* Check this cksum */
|
||||
retval = krb5_c_verify_checksum(context, as_key,
|
||||
KRB5_KEYUSAGE_PA_SAM_CHALLENGE_CKSUM,
|
||||
@@ -1592,7 +1594,6 @@
|
||||
}
|
||||
if (valid_cksum)
|
||||
break;
|
||||
- cksum++;
|
||||
}
|
||||
|
||||
if (!valid_cksum) {
|
||||
Index: krb5-1.8/src/lib/krb5/krb/mk_safe.c
|
||||
===================================================================
|
||||
--- krb5-1.8/src/lib/krb5/krb/mk_safe.c (revision 24455)
|
||||
+++ krb5-1.8/src/lib/krb5/krb/mk_safe.c (working copy)
|
||||
@@ -215,10 +215,28 @@
|
||||
for (i = 0; i < nsumtypes; i++)
|
||||
if (auth_context->safe_cksumtype == sumtypes[i])
|
||||
break;
|
||||
- if (i == nsumtypes)
|
||||
- i = 0;
|
||||
- sumtype = sumtypes[i];
|
||||
krb5_free_cksumtypes (context, sumtypes);
|
||||
+ if (i < nsumtypes)
|
||||
+ sumtype = auth_context->safe_cksumtype;
|
||||
+ else {
|
||||
+ switch (enctype) {
|
||||
+ case ENCTYPE_DES_CBC_MD4:
|
||||
+ sumtype = CKSUMTYPE_RSA_MD4_DES;
|
||||
+ break;
|
||||
+ case ENCTYPE_DES_CBC_MD5:
|
||||
+ case ENCTYPE_DES_CBC_CRC:
|
||||
+ sumtype = CKSUMTYPE_RSA_MD5_DES;
|
||||
+ break;
|
||||
+ default:
|
||||
+ retval = krb5int_c_mandatory_cksumtype(context, enctype,
|
||||
+ &sumtype);
|
||||
+ if (retval) {
|
||||
+ CLEANUP_DONE();
|
||||
+ goto error;
|
||||
+ }
|
||||
+ break;
|
||||
+ }
|
||||
+ }
|
||||
}
|
||||
if ((retval = krb5_mk_safe_basic(context, userdata, key, &replaydata,
|
||||
plocal_fulladdr, premote_fulladdr,
|
||||
866
Add-ASN.1-encoders-and-decoders-for-SPAKE-types.patch
Normal file
866
Add-ASN.1-encoders-and-decoders-for-SPAKE-types.patch
Normal file
|
|
@ -0,0 +1,866 @@
|
|||
From dff5177801444307d19071fc4fac7de864fda92a Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Sat, 13 Jun 2015 16:04:53 -0400
|
||||
Subject: [PATCH] Add ASN.1 encoders and decoders for SPAKE types
|
||||
|
||||
Add a new internal header k5-spake.h. Add ASN.1 encoder and decoder
|
||||
functions and an internal free function for SPAKE types. Add ASN.1
|
||||
tests and asn1c test vectors the new types.
|
||||
|
||||
The additions to to make-vectors.c use C99 designated initializers in
|
||||
order to initialize unions. This is okay since make-vectors.c is only
|
||||
compiled as part of "make test-vectors" and not as part of the regular
|
||||
build.
|
||||
|
||||
(cherry picked from commit 78a09d95dff6915da4079bc611f4bb95f6a95f70)
|
||||
---
|
||||
src/include/k5-spake.h | 107 +++++++++++++++++++++++++++
|
||||
src/lib/krb5/asn.1/asn1_k_encode.c | 52 ++++++++++++-
|
||||
src/lib/krb5/krb/kfree.c | 40 ++++++++++
|
||||
src/lib/krb5/libkrb5.exports | 6 ++
|
||||
src/tests/asn.1/Makefile.in | 2 +-
|
||||
src/tests/asn.1/krb5_decode_test.c | 37 +++++++++
|
||||
src/tests/asn.1/krb5_encode_test.c | 29 ++++++++
|
||||
src/tests/asn.1/ktest.c | 97 ++++++++++++++++++++++++
|
||||
src/tests/asn.1/ktest.h | 9 +++
|
||||
src/tests/asn.1/ktest_equal.c | 49 ++++++++++++
|
||||
src/tests/asn.1/ktest_equal.h | 6 ++
|
||||
src/tests/asn.1/make-vectors.c | 56 ++++++++++++++
|
||||
src/tests/asn.1/reference_encode.out | 6 ++
|
||||
src/tests/asn.1/spake.asn1 | 44 +++++++++++
|
||||
src/tests/asn.1/trval_reference.out | 50 +++++++++++++
|
||||
15 files changed, 588 insertions(+), 2 deletions(-)
|
||||
create mode 100644 src/include/k5-spake.h
|
||||
create mode 100644 src/tests/asn.1/spake.asn1
|
||||
|
||||
diff --git a/src/include/k5-spake.h b/src/include/k5-spake.h
|
||||
new file mode 100644
|
||||
index 000000000..ddb5d810d
|
||||
--- /dev/null
|
||||
+++ b/src/include/k5-spake.h
|
||||
@@ -0,0 +1,107 @@
|
||||
+/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */
|
||||
+/* include/k5-spake.h - SPAKE preauth mech declarations */
|
||||
+/*
|
||||
+ * Copyright (C) 2015 by the Massachusetts Institute of Technology.
|
||||
+ * All rights reserved.
|
||||
+ *
|
||||
+ * Redistribution and use in source and binary forms, with or without
|
||||
+ * modification, are permitted provided that the following conditions
|
||||
+ * are met:
|
||||
+ *
|
||||
+ * * Redistributions of source code must retain the above copyright
|
||||
+ * notice, this list of conditions and the following disclaimer.
|
||||
+ *
|
||||
+ * * Redistributions in binary form must reproduce the above copyright
|
||||
+ * notice, this list of conditions and the following disclaimer in
|
||||
+ * the documentation and/or other materials provided with the
|
||||
+ * distribution.
|
||||
+ *
|
||||
+ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
|
||||
+ * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
|
||||
+ * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS
|
||||
+ * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE
|
||||
+ * COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT,
|
||||
+ * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES
|
||||
+ * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR
|
||||
+ * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
|
||||
+ * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
|
||||
+ * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
|
||||
+ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED
|
||||
+ * OF THE POSSIBILITY OF SUCH DAMAGE.
|
||||
+ */
|
||||
+
|
||||
+/*
|
||||
+ * The SPAKE preauth mechanism allows long-term client keys to be used for
|
||||
+ * preauthentication without exposing them to offline dictionary attacks. The
|
||||
+ * negotiated key can also be used for second-factor authentication. This
|
||||
+ * header file declares structures and encoder/decoder functions for the
|
||||
+ * mechanism's padata messages.
|
||||
+ */
|
||||
+
|
||||
+#ifndef K5_SPAKE_H
|
||||
+#define K5_SPAKE_H
|
||||
+
|
||||
+#include "k5-int.h"
|
||||
+
|
||||
+/* SPAKESecondFactor is contained within a SPAKEChallenge, SPAKEResponse, or
|
||||
+ * EncryptedData message and contains a second-factor challenge or response. */
|
||||
+typedef struct krb5_spake_factor_st {
|
||||
+ int32_t type;
|
||||
+ krb5_data *data;
|
||||
+} krb5_spake_factor;
|
||||
+
|
||||
+/* SPAKESupport is sent from the client to the KDC to indicate which group the
|
||||
+ * client supports. */
|
||||
+typedef struct krb5_spake_support_st {
|
||||
+ int32_t ngroups;
|
||||
+ int32_t *groups;
|
||||
+} krb5_spake_support;
|
||||
+
|
||||
+/* SPAKEChallenge is sent from the KDC to the client to communicate its group
|
||||
+ * selection, public value, and second-factor challenge options. */
|
||||
+typedef struct krb5_spake_challenge_st {
|
||||
+ int32_t group;
|
||||
+ krb5_data pubkey;
|
||||
+ krb5_spake_factor **factors;
|
||||
+} krb5_spake_challenge;
|
||||
+
|
||||
+/* SPAKEResponse is sent from the client to the KDC to communicate its public
|
||||
+ * value and encrypted second-factor response. */
|
||||
+typedef struct krb5_spake_response_st {
|
||||
+ krb5_data pubkey;
|
||||
+ krb5_enc_data factor;
|
||||
+} krb5_spake_response;
|
||||
+
|
||||
+enum krb5_spake_msgtype {
|
||||
+ SPAKE_MSGTYPE_UNKNOWN = -1,
|
||||
+ SPAKE_MSGTYPE_SUPPORT = 0,
|
||||
+ SPAKE_MSGTYPE_CHALLENGE = 1,
|
||||
+ SPAKE_MSGTYPE_RESPONSE = 2,
|
||||
+ SPAKE_MSGTYPE_ENCDATA = 3
|
||||
+};
|
||||
+
|
||||
+/* PA-SPAKE is a choice among the message types which can appear in a PA-SPAKE
|
||||
+ * padata element. */
|
||||
+typedef struct krb5_pa_spake_st {
|
||||
+ enum krb5_spake_msgtype choice;
|
||||
+ union krb5_spake_message_choices {
|
||||
+ krb5_spake_support support;
|
||||
+ krb5_spake_challenge challenge;
|
||||
+ krb5_spake_response response;
|
||||
+ krb5_enc_data encdata;
|
||||
+ } u;
|
||||
+} krb5_pa_spake;
|
||||
+
|
||||
+krb5_error_code encode_krb5_spake_factor(const krb5_spake_factor *val,
|
||||
+ krb5_data **code_out);
|
||||
+krb5_error_code decode_krb5_spake_factor(const krb5_data *code,
|
||||
+ krb5_spake_factor **val_out);
|
||||
+void k5_free_spake_factor(krb5_context context, krb5_spake_factor *val);
|
||||
+
|
||||
+krb5_error_code encode_krb5_pa_spake(const krb5_pa_spake *val,
|
||||
+ krb5_data **code_out);
|
||||
+krb5_error_code decode_krb5_pa_spake(const krb5_data *code,
|
||||
+ krb5_pa_spake **val_out);
|
||||
+void k5_free_pa_spake(krb5_context context, krb5_pa_spake *val);
|
||||
+
|
||||
+#endif /* K5_SPAKE_H */
|
||||
diff --git a/src/lib/krb5/asn.1/asn1_k_encode.c b/src/lib/krb5/asn.1/asn1_k_encode.c
|
||||
index 3b23fe34a..29f6b903d 100644
|
||||
--- a/src/lib/krb5/asn.1/asn1_k_encode.c
|
||||
+++ b/src/lib/krb5/asn.1/asn1_k_encode.c
|
||||
@@ -25,7 +25,7 @@
|
||||
*/
|
||||
|
||||
#include "asn1_encode.h"
|
||||
-#include <assert.h>
|
||||
+#include "k5-spake.h"
|
||||
|
||||
DEFINT_IMMEDIATE(krb5_version, KVNO, KRB5KDC_ERR_BAD_PVNO);
|
||||
|
||||
@@ -1817,3 +1817,53 @@ static const struct atype_info *secure_cookie_fields[] = {
|
||||
DEFSEQTYPE(secure_cookie, krb5_secure_cookie, secure_cookie_fields);
|
||||
MAKE_ENCODER(encode_krb5_secure_cookie, secure_cookie);
|
||||
MAKE_DECODER(decode_krb5_secure_cookie, secure_cookie);
|
||||
+
|
||||
+DEFFIELD(spake_factor_0, krb5_spake_factor, type, 0, int32);
|
||||
+DEFFIELD(spake_factor_1, krb5_spake_factor, data, 1, opt_ostring_data_ptr);
|
||||
+static const struct atype_info *spake_factor_fields[] = {
|
||||
+ &k5_atype_spake_factor_0, &k5_atype_spake_factor_1
|
||||
+};
|
||||
+DEFSEQTYPE(spake_factor, krb5_spake_factor, spake_factor_fields);
|
||||
+DEFPTRTYPE(spake_factor_ptr, spake_factor);
|
||||
+DEFNULLTERMSEQOFTYPE(seqof_spake_factor, spake_factor_ptr);
|
||||
+DEFPTRTYPE(ptr_seqof_spake_factor, seqof_spake_factor);
|
||||
+MAKE_ENCODER(encode_krb5_spake_factor, spake_factor);
|
||||
+MAKE_DECODER(decode_krb5_spake_factor, spake_factor);
|
||||
+
|
||||
+DEFCNFIELD(spake_support_0, krb5_spake_support, groups, ngroups, 0,
|
||||
+ cseqof_int32);
|
||||
+static const struct atype_info *spake_support_fields[] = {
|
||||
+ &k5_atype_spake_support_0
|
||||
+};
|
||||
+DEFSEQTYPE(spake_support, krb5_spake_support, spake_support_fields);
|
||||
+
|
||||
+DEFFIELD(spake_challenge_0, krb5_spake_challenge, group, 0, int32);
|
||||
+DEFFIELD(spake_challenge_1, krb5_spake_challenge, pubkey, 1, ostring_data);
|
||||
+DEFFIELD(spake_challenge_2, krb5_spake_challenge, factors, 2,
|
||||
+ ptr_seqof_spake_factor);
|
||||
+static const struct atype_info *spake_challenge_fields[] = {
|
||||
+ &k5_atype_spake_challenge_0, &k5_atype_spake_challenge_1,
|
||||
+ &k5_atype_spake_challenge_2
|
||||
+};
|
||||
+DEFSEQTYPE(spake_challenge, krb5_spake_challenge, spake_challenge_fields);
|
||||
+
|
||||
+DEFFIELD(spake_response_0, krb5_spake_response, pubkey, 0, ostring_data);
|
||||
+DEFFIELD(spake_response_1, krb5_spake_response, factor, 1, encrypted_data);
|
||||
+static const struct atype_info *spake_response_fields[] = {
|
||||
+ &k5_atype_spake_response_0, &k5_atype_spake_response_1,
|
||||
+};
|
||||
+DEFSEQTYPE(spake_response, krb5_spake_response, spake_response_fields);
|
||||
+
|
||||
+DEFCTAGGEDTYPE(pa_spake_0, 0, spake_support);
|
||||
+DEFCTAGGEDTYPE(pa_spake_1, 1, spake_challenge);
|
||||
+DEFCTAGGEDTYPE(pa_spake_2, 2, spake_response);
|
||||
+DEFCTAGGEDTYPE(pa_spake_3, 3, encrypted_data);
|
||||
+static const struct atype_info *pa_spake_alternatives[] = {
|
||||
+ &k5_atype_pa_spake_0, &k5_atype_pa_spake_1, &k5_atype_pa_spake_2,
|
||||
+ &k5_atype_pa_spake_3
|
||||
+};
|
||||
+DEFCHOICETYPE(pa_spake_choice, union krb5_spake_message_choices,
|
||||
+ enum krb5_spake_msgtype, pa_spake_alternatives);
|
||||
+DEFCOUNTEDTYPE_SIGNED(pa_spake, krb5_pa_spake, u, choice, pa_spake_choice);
|
||||
+MAKE_ENCODER(encode_krb5_pa_spake, pa_spake);
|
||||
+MAKE_DECODER(decode_krb5_pa_spake, pa_spake);
|
||||
diff --git a/src/lib/krb5/krb/kfree.c b/src/lib/krb5/krb/kfree.c
|
||||
index a631807d3..e1ea1494a 100644
|
||||
--- a/src/lib/krb5/krb/kfree.c
|
||||
+++ b/src/lib/krb5/krb/kfree.c
|
||||
@@ -51,6 +51,7 @@
|
||||
*/
|
||||
|
||||
#include "k5-int.h"
|
||||
+#include "k5-spake.h"
|
||||
#include <assert.h>
|
||||
|
||||
void KRB5_CALLCONV
|
||||
@@ -890,3 +891,42 @@ k5_free_secure_cookie(krb5_context context, krb5_secure_cookie *val)
|
||||
k5_zapfree_pa_data(val->data);
|
||||
free(val);
|
||||
}
|
||||
+
|
||||
+void
|
||||
+k5_free_spake_factor(krb5_context context, krb5_spake_factor *val)
|
||||
+{
|
||||
+ if (val == NULL)
|
||||
+ return;
|
||||
+ krb5_free_data(context, val->data);
|
||||
+ free(val);
|
||||
+}
|
||||
+
|
||||
+void
|
||||
+k5_free_pa_spake(krb5_context context, krb5_pa_spake *val)
|
||||
+{
|
||||
+ krb5_spake_factor **f;
|
||||
+
|
||||
+ if (val == NULL)
|
||||
+ return;
|
||||
+ switch (val->choice) {
|
||||
+ case SPAKE_MSGTYPE_SUPPORT:
|
||||
+ free(val->u.support.groups);
|
||||
+ break;
|
||||
+ case SPAKE_MSGTYPE_CHALLENGE:
|
||||
+ krb5_free_data_contents(context, &val->u.challenge.pubkey);
|
||||
+ for (f = val->u.challenge.factors; f != NULL && *f != NULL; f++)
|
||||
+ k5_free_spake_factor(context, *f);
|
||||
+ free(val->u.challenge.factors);
|
||||
+ break;
|
||||
+ case SPAKE_MSGTYPE_RESPONSE:
|
||||
+ krb5_free_data_contents(context, &val->u.response.pubkey);
|
||||
+ krb5_free_data_contents(context, &val->u.response.factor.ciphertext);
|
||||
+ break;
|
||||
+ case SPAKE_MSGTYPE_ENCDATA:
|
||||
+ krb5_free_data_contents(context, &val->u.encdata.ciphertext);
|
||||
+ break;
|
||||
+ default:
|
||||
+ break;
|
||||
+ }
|
||||
+ free(val);
|
||||
+}
|
||||
diff --git a/src/lib/krb5/libkrb5.exports b/src/lib/krb5/libkrb5.exports
|
||||
index ed6cad6ad..622bc3673 100644
|
||||
--- a/src/lib/krb5/libkrb5.exports
|
||||
+++ b/src/lib/krb5/libkrb5.exports
|
||||
@@ -36,6 +36,7 @@ decode_krb5_pa_otp_req
|
||||
decode_krb5_pa_otp_enc_req
|
||||
decode_krb5_pa_pac_req
|
||||
decode_krb5_pa_s4u_x509_user
|
||||
+decode_krb5_pa_spake
|
||||
decode_krb5_padata_sequence
|
||||
decode_krb5_priv
|
||||
decode_krb5_safe
|
||||
@@ -44,6 +45,7 @@ decode_krb5_sam_challenge_2_body
|
||||
decode_krb5_sam_response_2
|
||||
decode_krb5_secure_cookie
|
||||
decode_krb5_setpw_req
|
||||
+decode_krb5_spake_factor
|
||||
decode_krb5_tgs_rep
|
||||
decode_krb5_tgs_req
|
||||
decode_krb5_ticket
|
||||
@@ -85,6 +87,7 @@ encode_krb5_pa_otp_challenge
|
||||
encode_krb5_pa_otp_req
|
||||
encode_krb5_pa_otp_enc_req
|
||||
encode_krb5_pa_s4u_x509_user
|
||||
+encode_krb5_pa_spake
|
||||
encode_krb5_padata_sequence
|
||||
encode_krb5_pkinit_supp_pub_info
|
||||
encode_krb5_priv
|
||||
@@ -95,6 +98,7 @@ encode_krb5_sam_challenge_2_body
|
||||
encode_krb5_sam_response_2
|
||||
encode_krb5_secure_cookie
|
||||
encode_krb5_sp80056a_other_info
|
||||
+encode_krb5_spake_factor
|
||||
encode_krb5_tgs_rep
|
||||
encode_krb5_tgs_req
|
||||
encode_krb5_ticket
|
||||
@@ -128,7 +132,9 @@ k5_free_kkdcp_message
|
||||
k5_free_pa_otp_challenge
|
||||
k5_free_pa_otp_req
|
||||
k5_free_secure_cookie
|
||||
+k5_free_pa_spake
|
||||
k5_free_serverlist
|
||||
+k5_free_spake_factor
|
||||
k5_hostrealm_free_context
|
||||
k5_init_trace
|
||||
k5_is_string_numeric
|
||||
diff --git a/src/tests/asn.1/Makefile.in b/src/tests/asn.1/Makefile.in
|
||||
index fec4e109e..ec9c67495 100644
|
||||
--- a/src/tests/asn.1/Makefile.in
|
||||
+++ b/src/tests/asn.1/Makefile.in
|
||||
@@ -9,7 +9,7 @@ SRCS= $(srcdir)/krb5_encode_test.c $(srcdir)/krb5_decode_test.c \
|
||||
|
||||
ASN1SRCS= $(srcdir)/krb5.asn1 $(srcdir)/pkix.asn1 $(srcdir)/otp.asn1 \
|
||||
$(srcdir)/pkinit.asn1 $(srcdir)/pkinit-agility.asn1 \
|
||||
- $(srcdir)/cammac.asn1
|
||||
+ $(srcdir)/cammac.asn1 $(srcdir)/spake.asn1
|
||||
|
||||
all: krb5_encode_test krb5_decode_test krb5_decode_leak t_trval
|
||||
|
||||
diff --git a/src/tests/asn.1/krb5_decode_test.c b/src/tests/asn.1/krb5_decode_test.c
|
||||
index f17f9b1f1..ee70fa4b9 100644
|
||||
--- a/src/tests/asn.1/krb5_decode_test.c
|
||||
+++ b/src/tests/asn.1/krb5_decode_test.c
|
||||
@@ -25,6 +25,7 @@
|
||||
*/
|
||||
|
||||
#include "k5-int.h"
|
||||
+#include "k5-spake.h"
|
||||
#include "ktest.h"
|
||||
#include "com_err.h"
|
||||
#include "utility.h"
|
||||
@@ -1107,6 +1108,42 @@ int main(argc, argv)
|
||||
ktest_empty_secure_cookie(&ref);
|
||||
}
|
||||
|
||||
+ /****************************************************************/
|
||||
+ /* decode_krb5_spake_factor */
|
||||
+ {
|
||||
+ setup(krb5_spake_factor,ktest_make_minimal_spake_factor);
|
||||
+ decode_run("spake_factor","(optionals NULL)","30 05 A0 03 02 01 01",decode_krb5_spake_factor,ktest_equal_spake_factor,k5_free_spake_factor);
|
||||
+ ktest_empty_spake_factor(&ref);
|
||||
+ }
|
||||
+ {
|
||||
+ setup(krb5_spake_factor,ktest_make_maximal_spake_factor);
|
||||
+ decode_run("spake_factor","","30 0E A0 03 02 01 02 A1 07 04 05 66 64 61 74 61",decode_krb5_spake_factor,ktest_equal_spake_factor,k5_free_spake_factor);
|
||||
+ ktest_empty_spake_factor(&ref);
|
||||
+ }
|
||||
+
|
||||
+ /****************************************************************/
|
||||
+ /* decode_krb5_pa_spake */
|
||||
+ {
|
||||
+ setup(krb5_pa_spake,ktest_make_support_pa_spake);
|
||||
+ decode_run("pa_spake","(support)","A0 0C 30 0A A0 08 30 06 02 01 01 02 01 02",decode_krb5_pa_spake,ktest_equal_pa_spake,k5_free_pa_spake);
|
||||
+ ktest_empty_pa_spake(&ref);
|
||||
+ }
|
||||
+ {
|
||||
+ setup(krb5_pa_spake,ktest_make_challenge_pa_spake);
|
||||
+ decode_run("pa_spake","(challenge)","A1 2D 30 2B A0 03 02 01 01 A1 09 04 07 54 20 76 61 6C 75 65 A2 19 30 17 30 05 A0 03 02 01 01 30 0E A0 03 02 01 02 A1 07 04 05 66 64 61 74 61",decode_krb5_pa_spake,ktest_equal_pa_spake,k5_free_pa_spake);
|
||||
+ ktest_empty_pa_spake(&ref);
|
||||
+ }
|
||||
+ {
|
||||
+ setup(krb5_pa_spake,ktest_make_response_pa_spake);
|
||||
+ decode_run("pa_spake","(response)","A2 34 30 32 A0 09 04 07 53 20 76 61 6C 75 65 A1 25 30 23 A0 03 02 01 00 A1 03 02 01 05 A2 17 04 15 6B 72 62 41 53 4E 2E 31 20 74 65 73 74 20 6D 65 73 73 61 67 65",decode_krb5_pa_spake,ktest_equal_pa_spake,k5_free_pa_spake);
|
||||
+ ktest_empty_pa_spake(&ref);
|
||||
+ }
|
||||
+ {
|
||||
+ setup(krb5_pa_spake,ktest_make_encdata_pa_spake);
|
||||
+ decode_run("pa_spake","(encdata)","A3 25 30 23 A0 03 02 01 00 A1 03 02 01 05 A2 17 04 15 6B 72 62 41 53 4E 2E 31 20 74 65 73 74 20 6D 65 73 73 61 67 65",decode_krb5_pa_spake,ktest_equal_pa_spake,k5_free_pa_spake);
|
||||
+ ktest_empty_pa_spake(&ref);
|
||||
+ }
|
||||
+
|
||||
#ifndef DISABLE_PKINIT
|
||||
|
||||
/****************************************************************/
|
||||
diff --git a/src/tests/asn.1/krb5_encode_test.c b/src/tests/asn.1/krb5_encode_test.c
|
||||
index f5710b68c..3efbfb4c0 100644
|
||||
--- a/src/tests/asn.1/krb5_encode_test.c
|
||||
+++ b/src/tests/asn.1/krb5_encode_test.c
|
||||
@@ -759,6 +759,35 @@ main(argc, argv)
|
||||
encode_run(cookie, "secure_cookie", "", encode_krb5_secure_cookie);
|
||||
ktest_empty_secure_cookie(&cookie);
|
||||
}
|
||||
+ /****************************************************************/
|
||||
+ /* encode_krb5_spake_factor */
|
||||
+ {
|
||||
+ krb5_spake_factor factor;
|
||||
+ ktest_make_minimal_spake_factor(&factor);
|
||||
+ encode_run(factor, "spake_factor", "(optionals NULL)",
|
||||
+ encode_krb5_spake_factor);
|
||||
+ ktest_empty_spake_factor(&factor);
|
||||
+ ktest_make_maximal_spake_factor(&factor);
|
||||
+ encode_run(factor, "spake_factor", "", encode_krb5_spake_factor);
|
||||
+ ktest_empty_spake_factor(&factor);
|
||||
+ }
|
||||
+ /****************************************************************/
|
||||
+ /* encode_krb5_pa_spake */
|
||||
+ {
|
||||
+ krb5_pa_spake pa_spake;
|
||||
+ ktest_make_support_pa_spake(&pa_spake);
|
||||
+ encode_run(pa_spake, "pa_spake", "(support)", encode_krb5_pa_spake);
|
||||
+ ktest_empty_pa_spake(&pa_spake);
|
||||
+ ktest_make_challenge_pa_spake(&pa_spake);
|
||||
+ encode_run(pa_spake, "pa_spake", "(challenge)", encode_krb5_pa_spake);
|
||||
+ ktest_empty_pa_spake(&pa_spake);
|
||||
+ ktest_make_response_pa_spake(&pa_spake);
|
||||
+ encode_run(pa_spake, "pa_spake", "(response)", encode_krb5_pa_spake);
|
||||
+ ktest_empty_pa_spake(&pa_spake);
|
||||
+ ktest_make_encdata_pa_spake(&pa_spake);
|
||||
+ encode_run(pa_spake, "pa_spake", "(encdata)", encode_krb5_pa_spake);
|
||||
+ ktest_empty_pa_spake(&pa_spake);
|
||||
+ }
|
||||
#ifndef DISABLE_PKINIT
|
||||
/****************************************************************/
|
||||
/* encode_krb5_pa_pk_as_req */
|
||||
diff --git a/src/tests/asn.1/ktest.c b/src/tests/asn.1/ktest.c
|
||||
index cf63f3f66..5bfdc5be2 100644
|
||||
--- a/src/tests/asn.1/ktest.c
|
||||
+++ b/src/tests/asn.1/ktest.c
|
||||
@@ -1018,6 +1018,66 @@ ktest_make_sample_secure_cookie(krb5_secure_cookie *p)
|
||||
p->time = SAMPLE_TIME;
|
||||
}
|
||||
|
||||
+void
|
||||
+ktest_make_minimal_spake_factor(krb5_spake_factor *p)
|
||||
+{
|
||||
+ p->type = 1;
|
||||
+ p->data = NULL;
|
||||
+}
|
||||
+
|
||||
+void
|
||||
+ktest_make_maximal_spake_factor(krb5_spake_factor *p)
|
||||
+{
|
||||
+ p->type = 2;
|
||||
+ p->data = ealloc(sizeof(*p->data));
|
||||
+ krb5_data_parse(p->data, "fdata");
|
||||
+}
|
||||
+
|
||||
+void
|
||||
+ktest_make_support_pa_spake(krb5_pa_spake *p)
|
||||
+{
|
||||
+ krb5_spake_support *s = &p->u.support;
|
||||
+
|
||||
+ s->ngroups = 2;
|
||||
+ s->groups = ealloc(s->ngroups * sizeof(*s->groups));
|
||||
+ s->groups[0] = 1;
|
||||
+ s->groups[1] = 2;
|
||||
+ p->choice = SPAKE_MSGTYPE_SUPPORT;
|
||||
+}
|
||||
+
|
||||
+void
|
||||
+ktest_make_challenge_pa_spake(krb5_pa_spake *p)
|
||||
+{
|
||||
+ krb5_spake_challenge *c = &p->u.challenge;
|
||||
+
|
||||
+ c->group = 1;
|
||||
+ krb5_data_parse(&c->pubkey, "T value");
|
||||
+ c->factors = ealloc(3 * sizeof(*c->factors));
|
||||
+ c->factors[0] = ealloc(sizeof(*c->factors[0]));
|
||||
+ ktest_make_minimal_spake_factor(c->factors[0]);
|
||||
+ c->factors[1] = ealloc(sizeof(*c->factors[1]));
|
||||
+ ktest_make_maximal_spake_factor(c->factors[1]);
|
||||
+ c->factors[2] = NULL;
|
||||
+ p->choice = SPAKE_MSGTYPE_CHALLENGE;
|
||||
+}
|
||||
+
|
||||
+void
|
||||
+ktest_make_response_pa_spake(krb5_pa_spake *p)
|
||||
+{
|
||||
+ krb5_spake_response *r = &p->u.response;
|
||||
+
|
||||
+ krb5_data_parse(&r->pubkey, "S value");
|
||||
+ ktest_make_sample_enc_data(&r->factor);
|
||||
+ p->choice = SPAKE_MSGTYPE_RESPONSE;
|
||||
+}
|
||||
+
|
||||
+void
|
||||
+ktest_make_encdata_pa_spake(krb5_pa_spake *p)
|
||||
+{
|
||||
+ ktest_make_sample_enc_data(&p->u.encdata);
|
||||
+ p->choice = SPAKE_MSGTYPE_ENCDATA;
|
||||
+}
|
||||
+
|
||||
/****************************************************************/
|
||||
/* destructors */
|
||||
|
||||
@@ -1858,3 +1918,40 @@ ktest_empty_secure_cookie(krb5_secure_cookie *p)
|
||||
{
|
||||
ktest_empty_pa_data_array(p->data);
|
||||
}
|
||||
+
|
||||
+void
|
||||
+ktest_empty_spake_factor(krb5_spake_factor *p)
|
||||
+{
|
||||
+ krb5_free_data(NULL, p->data);
|
||||
+ p->data = NULL;
|
||||
+}
|
||||
+
|
||||
+void
|
||||
+ktest_empty_pa_spake(krb5_pa_spake *p)
|
||||
+{
|
||||
+ krb5_spake_factor **f;
|
||||
+
|
||||
+ switch (p->choice) {
|
||||
+ case SPAKE_MSGTYPE_SUPPORT:
|
||||
+ free(p->u.support.groups);
|
||||
+ break;
|
||||
+ case SPAKE_MSGTYPE_CHALLENGE:
|
||||
+ ktest_empty_data(&p->u.challenge.pubkey);
|
||||
+ for (f = p->u.challenge.factors; *f != NULL; f++) {
|
||||
+ ktest_empty_spake_factor(*f);
|
||||
+ free(*f);
|
||||
+ }
|
||||
+ free(p->u.challenge.factors);
|
||||
+ break;
|
||||
+ case SPAKE_MSGTYPE_RESPONSE:
|
||||
+ ktest_empty_data(&p->u.response.pubkey);
|
||||
+ ktest_destroy_enc_data(&p->u.response.factor);
|
||||
+ break;
|
||||
+ case SPAKE_MSGTYPE_ENCDATA:
|
||||
+ ktest_destroy_enc_data(&p->u.encdata);
|
||||
+ break;
|
||||
+ default:
|
||||
+ break;
|
||||
+ }
|
||||
+ p->choice = SPAKE_MSGTYPE_UNKNOWN;
|
||||
+}
|
||||
diff --git a/src/tests/asn.1/ktest.h b/src/tests/asn.1/ktest.h
|
||||
index 493303cc8..1413cfae1 100644
|
||||
--- a/src/tests/asn.1/ktest.h
|
||||
+++ b/src/tests/asn.1/ktest.h
|
||||
@@ -28,6 +28,7 @@
|
||||
#define __KTEST_H__
|
||||
|
||||
#include "k5-int.h"
|
||||
+#include "k5-spake.h"
|
||||
#include "kdb.h"
|
||||
|
||||
#define SAMPLE_USEC 123456
|
||||
@@ -124,6 +125,12 @@ void ktest_make_sample_kkdcp_message(krb5_kkdcp_message *p);
|
||||
void ktest_make_minimal_cammac(krb5_cammac *p);
|
||||
void ktest_make_maximal_cammac(krb5_cammac *p);
|
||||
void ktest_make_sample_secure_cookie(krb5_secure_cookie *p);
|
||||
+void ktest_make_minimal_spake_factor(krb5_spake_factor *p);
|
||||
+void ktest_make_maximal_spake_factor(krb5_spake_factor *p);
|
||||
+void ktest_make_support_pa_spake(krb5_pa_spake *p);
|
||||
+void ktest_make_challenge_pa_spake(krb5_pa_spake *p);
|
||||
+void ktest_make_response_pa_spake(krb5_pa_spake *p);
|
||||
+void ktest_make_encdata_pa_spake(krb5_pa_spake *p);
|
||||
|
||||
/*----------------------------------------------------------------------*/
|
||||
|
||||
@@ -209,6 +216,8 @@ void ktest_empty_ldap_seqof_key_data(krb5_context, ldap_seqof_key_data *p);
|
||||
void ktest_empty_kkdcp_message(krb5_kkdcp_message *p);
|
||||
void ktest_empty_cammac(krb5_cammac *p);
|
||||
void ktest_empty_secure_cookie(krb5_secure_cookie *p);
|
||||
+void ktest_empty_spake_factor(krb5_spake_factor *p);
|
||||
+void ktest_empty_pa_spake(krb5_pa_spake *p);
|
||||
|
||||
extern krb5_context test_context;
|
||||
extern char *sample_principal_name;
|
||||
diff --git a/src/tests/asn.1/ktest_equal.c b/src/tests/asn.1/ktest_equal.c
|
||||
index e8bb88944..714cc4398 100644
|
||||
--- a/src/tests/asn.1/ktest_equal.c
|
||||
+++ b/src/tests/asn.1/ktest_equal.c
|
||||
@@ -853,6 +853,13 @@ ktest_equal_sequence_of_otp_tokeninfo(krb5_otp_tokeninfo **ref,
|
||||
array_compare(ktest_equal_otp_tokeninfo);
|
||||
}
|
||||
|
||||
+int
|
||||
+ktest_equal_sequence_of_spake_factor(krb5_spake_factor **ref,
|
||||
+ krb5_spake_factor **var)
|
||||
+{
|
||||
+ array_compare(ktest_equal_spake_factor);
|
||||
+}
|
||||
+
|
||||
#ifndef DISABLE_PKINIT
|
||||
|
||||
static int
|
||||
@@ -1094,3 +1101,45 @@ ktest_equal_secure_cookie(krb5_secure_cookie *ref, krb5_secure_cookie *var)
|
||||
p = p && ref->time == ref->time;
|
||||
return p;
|
||||
}
|
||||
+
|
||||
+int
|
||||
+ktest_equal_spake_factor(krb5_spake_factor *ref, krb5_spake_factor *var)
|
||||
+{
|
||||
+ int p = TRUE;
|
||||
+ if (ref == var) return TRUE;
|
||||
+ else if (ref == NULL || var == NULL) return FALSE;
|
||||
+ p = p && scalar_equal(type);
|
||||
+ p = p && ptr_equal(data,ktest_equal_data);
|
||||
+ return p;
|
||||
+}
|
||||
+
|
||||
+int
|
||||
+ktest_equal_pa_spake(krb5_pa_spake *ref, krb5_pa_spake *var)
|
||||
+{
|
||||
+ int p = TRUE;
|
||||
+ if (ref == var) return TRUE;
|
||||
+ else if (ref == NULL || var == NULL) return FALSE;
|
||||
+ else if (ref->choice != var->choice) return FALSE;
|
||||
+ switch (ref->choice) {
|
||||
+ case SPAKE_MSGTYPE_SUPPORT:
|
||||
+ p = p && scalar_equal(u.support.ngroups);
|
||||
+ p = p && (memcmp(ref->u.support.groups,var->u.support.groups,
|
||||
+ ref->u.support.ngroups * sizeof(int32_t)) == 0);
|
||||
+ break;
|
||||
+ case SPAKE_MSGTYPE_CHALLENGE:
|
||||
+ p = p && struct_equal(u.challenge.pubkey,ktest_equal_data);
|
||||
+ p = p && ptr_equal(u.challenge.factors,
|
||||
+ ktest_equal_sequence_of_spake_factor);
|
||||
+ break;
|
||||
+ case SPAKE_MSGTYPE_RESPONSE:
|
||||
+ p = p && struct_equal(u.response.pubkey,ktest_equal_data);
|
||||
+ p = p && struct_equal(u.response.factor,ktest_equal_enc_data);
|
||||
+ break;
|
||||
+ case SPAKE_MSGTYPE_ENCDATA:
|
||||
+ p = p && struct_equal(u.encdata,ktest_equal_enc_data);
|
||||
+ break;
|
||||
+ default:
|
||||
+ break;
|
||||
+ }
|
||||
+ return p;
|
||||
+}
|
||||
diff --git a/src/tests/asn.1/ktest_equal.h b/src/tests/asn.1/ktest_equal.h
|
||||
index c7b5d7467..cfa82ac6e 100644
|
||||
--- a/src/tests/asn.1/ktest_equal.h
|
||||
+++ b/src/tests/asn.1/ktest_equal.h
|
||||
@@ -28,6 +28,7 @@
|
||||
#define __KTEST_EQUAL_H__
|
||||
|
||||
#include "k5-int.h"
|
||||
+#include "k5-spake.h"
|
||||
#include "kdb.h"
|
||||
|
||||
/* int ktest_equal_structure(krb5_structure *ref, *var) */
|
||||
@@ -97,6 +98,8 @@ ktest_equal_sequence_of_algorithm_identifier(krb5_algorithm_identifier **ref,
|
||||
krb5_algorithm_identifier **var);
|
||||
int ktest_equal_sequence_of_otp_tokeninfo(krb5_otp_tokeninfo **ref,
|
||||
krb5_otp_tokeninfo **var);
|
||||
+int ktest_equal_sequence_of_spake_factor(krb5_spake_factor **ref,
|
||||
+ krb5_spake_factor **var);
|
||||
|
||||
len_array(ktest_equal_array_of_enctype,krb5_enctype);
|
||||
len_array(ktest_equal_array_of_data,krb5_data);
|
||||
@@ -152,4 +155,7 @@ int ktest_equal_cammac(krb5_cammac *ref, krb5_cammac *var);
|
||||
int ktest_equal_secure_cookie(krb5_secure_cookie *ref,
|
||||
krb5_secure_cookie *var);
|
||||
|
||||
+generic(ktest_equal_spake_factor, krb5_spake_factor);
|
||||
+generic(ktest_equal_pa_spake, krb5_pa_spake);
|
||||
+
|
||||
#endif
|
||||
diff --git a/src/tests/asn.1/make-vectors.c b/src/tests/asn.1/make-vectors.c
|
||||
index 3cb8a45ba..2fc85466b 100644
|
||||
--- a/src/tests/asn.1/make-vectors.c
|
||||
+++ b/src/tests/asn.1/make-vectors.c
|
||||
@@ -40,6 +40,8 @@
|
||||
#include <PA-OTP-REQUEST.h>
|
||||
#include <PA-OTP-ENC-REQUEST.h>
|
||||
#include <AD-CAMMAC.h>
|
||||
+#include <SPAKESecondFactor.h>
|
||||
+#include <PA-SPAKE.h>
|
||||
|
||||
static unsigned char buf[8192];
|
||||
static size_t buf_pos;
|
||||
@@ -168,6 +170,36 @@ static struct other_verifiers overfs = { { verifiers, 2, 2 } };
|
||||
static AD_CAMMAC_t cammac_2 = { { { (void *)adlist_2, 2, 2 } },
|
||||
&vmac_1, &vmac_2, &overfs };
|
||||
|
||||
+/* SPAKESecondFactor */
|
||||
+static SPAKESecondFactor_t factor_1 = { 1, NULL };
|
||||
+static OCTET_STRING_t factor_data = { "fdata", 5 };
|
||||
+static SPAKESecondFactor_t factor_2 = { 2, &factor_data };
|
||||
+
|
||||
+/* PA-SPAKE (support) */
|
||||
+static Int32_t group_1 = 1, group_2 = 2, *groups[] = { &group_1, &group_2 };
|
||||
+static PA_SPAKE_t pa_spake_1 = { PA_SPAKE_PR_support,
|
||||
+ { .support = { { groups, 2, 2 } } } };
|
||||
+
|
||||
+/* PA-SPAKE (challenge) */
|
||||
+static SPAKESecondFactor_t *factors[2] = { &factor_1, &factor_2 };
|
||||
+static PA_SPAKE_t pa_spake_2 = { PA_SPAKE_PR_challenge,
|
||||
+ { .challenge = { 1, { "T value", 7 },
|
||||
+ { factors, 2, 2 } } } };
|
||||
+
|
||||
+/* PA-SPAKE (response) */
|
||||
+UInt32_t enctype_5 = 5;
|
||||
+static PA_SPAKE_t pa_spake_3 = { PA_SPAKE_PR_response,
|
||||
+ { .response = { { "S value", 7 },
|
||||
+ { 0, &enctype_5,
|
||||
+ { "krbASN.1 test message",
|
||||
+ 21 } } } } };
|
||||
+
|
||||
+/* PA-SPAKE (encdata) */
|
||||
+static PA_SPAKE_t pa_spake_4 = { PA_SPAKE_PR_encdata,
|
||||
+ { .encdata = { 0, &enctype_5,
|
||||
+ { "krbASN.1 test message",
|
||||
+ 21 } } } };
|
||||
+
|
||||
static int
|
||||
consume(const void *data, size_t size, void *dummy)
|
||||
{
|
||||
@@ -272,6 +304,30 @@ main()
|
||||
der_encode(&asn_DEF_AD_CAMMAC, &cammac_2, consume, NULL);
|
||||
printbuf();
|
||||
|
||||
+ printf("\nMinimal SPAKESecondFactor:\n");
|
||||
+ der_encode(&asn_DEF_SPAKESecondFactor, &factor_1, consume, NULL);
|
||||
+ printbuf();
|
||||
+
|
||||
+ printf("\nMaximal SPAKESecondFactor:\n");
|
||||
+ der_encode(&asn_DEF_SPAKESecondFactor, &factor_2, consume, NULL);
|
||||
+ printbuf();
|
||||
+
|
||||
+ printf("\nPA-SPAKE (support):\n");
|
||||
+ der_encode(&asn_DEF_PA_SPAKE, &pa_spake_1, consume, NULL);
|
||||
+ printbuf();
|
||||
+
|
||||
+ printf("\nPA-SPAKE (challenge):\n");
|
||||
+ der_encode(&asn_DEF_PA_SPAKE, &pa_spake_2, consume, NULL);
|
||||
+ printbuf();
|
||||
+
|
||||
+ printf("\nPA-SPAKE (response):\n");
|
||||
+ der_encode(&asn_DEF_PA_SPAKE, &pa_spake_3, consume, NULL);
|
||||
+ printbuf();
|
||||
+
|
||||
+ printf("\nPA-SPAKE (encdata):\n");
|
||||
+ der_encode(&asn_DEF_PA_SPAKE, &pa_spake_4, consume, NULL);
|
||||
+ printbuf();
|
||||
+
|
||||
printf("\n");
|
||||
return 0;
|
||||
}
|
||||
diff --git a/src/tests/asn.1/reference_encode.out b/src/tests/asn.1/reference_encode.out
|
||||
index 824e0798b..a76deead2 100644
|
||||
--- a/src/tests/asn.1/reference_encode.out
|
||||
+++ b/src/tests/asn.1/reference_encode.out
|
||||
@@ -72,3 +72,9 @@ encode_krb5_kkdcp_message: 30 82 01 FC A0 82 01 EC 04 82 01 E8 6A 82 01 E4 30 82
|
||||
encode_krb5_cammac(optionals NULL): 30 12 A0 10 30 0E 30 0C A0 03 02 01 01 A1 05 04 03 61 64 31
|
||||
encode_krb5_cammac: 30 81 F2 A0 1E 30 1C 30 0C A0 03 02 01 01 A1 05 04 03 61 64 31 30 0C A0 03 02 01 02 A1 05 04 03 61 64 32 A1 3D 30 3B A0 1A 30 18 A0 03 02 01 01 A1 11 30 0F 1B 06 68 66 74 73 61 69 1B 05 65 78 74 72 61 A1 03 02 01 05 A2 03 02 01 10 A3 13 30 11 A0 03 02 01 01 A1 0A 04 08 63 6B 73 75 6D 6B 64 63 A2 3D 30 3B A0 1A 30 18 A0 03 02 01 01 A1 11 30 0F 1B 06 68 66 74 73 61 69 1B 05 65 78 74 72 61 A1 03 02 01 05 A2 03 02 01 10 A3 13 30 11 A0 03 02 01 01 A1 0A 04 08 63 6B 73 75 6D 73 76 63 A3 52 30 50 30 13 A3 11 30 0F A0 03 02 01 01 A1 08 04 06 63 6B 73 75 6D 31 30 39 A0 1A 30 18 A0 03 02 01 01 A1 11 30 0F 1B 06 68 66 74 73 61 69 1B 05 65 78 74 72 61 A1 03 02 01 05 A2 03 02 01 10 A3 11 30 0F A0 03 02 01 01 A1 08 04 06 63 6B 73 75 6D 32
|
||||
encode_krb5_secure_cookie: 30 2C 02 04 2D F8 02 25 30 24 30 10 A1 03 02 01 0D A2 09 04 07 70 61 2D 64 61 74 61 30 10 A1 03 02 01 0D A2 09 04 07 70 61 2D 64 61 74 61
|
||||
+encode_krb5_spake_factor(optionals NULL): 30 05 A0 03 02 01 01
|
||||
+encode_krb5_spake_factor: 30 0E A0 03 02 01 02 A1 07 04 05 66 64 61 74 61
|
||||
+encode_krb5_pa_spake(support): A0 0C 30 0A A0 08 30 06 02 01 01 02 01 02
|
||||
+encode_krb5_pa_spake(challenge): A1 2D 30 2B A0 03 02 01 01 A1 09 04 07 54 20 76 61 6C 75 65 A2 19 30 17 30 05 A0 03 02 01 01 30 0E A0 03 02 01 02 A1 07 04 05 66 64 61 74 61
|
||||
+encode_krb5_pa_spake(response): A2 34 30 32 A0 09 04 07 53 20 76 61 6C 75 65 A1 25 30 23 A0 03 02 01 00 A1 03 02 01 05 A2 17 04 15 6B 72 62 41 53 4E 2E 31 20 74 65 73 74 20 6D 65 73 73 61 67 65
|
||||
+encode_krb5_pa_spake(encdata): A3 25 30 23 A0 03 02 01 00 A1 03 02 01 05 A2 17 04 15 6B 72 62 41 53 4E 2E 31 20 74 65 73 74 20 6D 65 73 73 61 67 65
|
||||
diff --git a/src/tests/asn.1/spake.asn1 b/src/tests/asn.1/spake.asn1
|
||||
new file mode 100644
|
||||
index 000000000..50718d8ad
|
||||
--- /dev/null
|
||||
+++ b/src/tests/asn.1/spake.asn1
|
||||
@@ -0,0 +1,44 @@
|
||||
+KerberosV5SPAKE {
|
||||
+ iso(1) identified-organization(3) dod(6) internet(1)
|
||||
+ security(5) kerberosV5(2) modules(4) spake(8)
|
||||
+} DEFINITIONS EXPLICIT TAGS ::= BEGIN
|
||||
+
|
||||
+IMPORTS
|
||||
+ EncryptedData, Int32
|
||||
+ FROM KerberosV5Spec2 { iso(1) identified-organization(3)
|
||||
+ dod(6) internet(1) security(5) kerberosV5(2) modules(4)
|
||||
+ krb5spec2(2) };
|
||||
+ -- as defined in RFC 4120.
|
||||
+
|
||||
+SPAKESupport ::= SEQUENCE {
|
||||
+ groups [0] SEQUENCE (SIZE(1..MAX)) OF Int32,
|
||||
+ ...
|
||||
+}
|
||||
+
|
||||
+SPAKEChallenge ::= SEQUENCE {
|
||||
+ group [0] Int32,
|
||||
+ pubkey [1] OCTET STRING,
|
||||
+ factors [2] SEQUENCE (SIZE(1..MAX)) OF SPAKESecondFactor,
|
||||
+ ...
|
||||
+}
|
||||
+
|
||||
+SPAKESecondFactor ::= SEQUENCE {
|
||||
+ type [0] Int32,
|
||||
+ data [1] OCTET STRING OPTIONAL
|
||||
+}
|
||||
+
|
||||
+SPAKEResponse ::= SEQUENCE {
|
||||
+ pubkey [0] OCTET STRING,
|
||||
+ factor [1] EncryptedData, -- SPAKESecondFactor
|
||||
+ ...
|
||||
+}
|
||||
+
|
||||
+PA-SPAKE ::= CHOICE {
|
||||
+ support [0] SPAKESupport,
|
||||
+ challenge [1] SPAKEChallenge,
|
||||
+ response [2] SPAKEResponse,
|
||||
+ encdata [3] EncryptedData,
|
||||
+ ...
|
||||
+}
|
||||
+
|
||||
+END
|
||||
diff --git a/src/tests/asn.1/trval_reference.out b/src/tests/asn.1/trval_reference.out
|
||||
index c27a0425b..e5c715924 100644
|
||||
--- a/src/tests/asn.1/trval_reference.out
|
||||
+++ b/src/tests/asn.1/trval_reference.out
|
||||
@@ -1584,3 +1584,53 @@ encode_krb5_secure_cookie:
|
||||
. . [Sequence/Sequence Of]
|
||||
. . . [1] [Integer] 13
|
||||
. . . [2] [Octet String] "pa-data"
|
||||
+
|
||||
+encode_krb5_spake_factor(optionals NULL):
|
||||
+
|
||||
+[Sequence/Sequence Of]
|
||||
+. [0] [Integer] 1
|
||||
+
|
||||
+encode_krb5_spake_factor:
|
||||
+
|
||||
+[Sequence/Sequence Of]
|
||||
+. [0] [Integer] 2
|
||||
+. [1] [Octet String] "fdata"
|
||||
+
|
||||
+encode_krb5_pa_spake(support):
|
||||
+
|
||||
+[CONT 0]
|
||||
+. [Sequence/Sequence Of]
|
||||
+. . [0] [Sequence/Sequence Of]
|
||||
+. . . [Integer] 1
|
||||
+. . . [Integer] 2
|
||||
+
|
||||
+encode_krb5_pa_spake(challenge):
|
||||
+
|
||||
+[CONT 1]
|
||||
+. [Sequence/Sequence Of]
|
||||
+. . [0] [Integer] 1
|
||||
+. . [1] [Octet String] "T value"
|
||||
+. . [2] [Sequence/Sequence Of]
|
||||
+. . . [Sequence/Sequence Of]
|
||||
+. . . . [0] [Integer] 1
|
||||
+. . . [Sequence/Sequence Of]
|
||||
+. . . . [0] [Integer] 2
|
||||
+. . . . [1] [Octet String] "fdata"
|
||||
+
|
||||
+encode_krb5_pa_spake(response):
|
||||
+
|
||||
+[CONT 2]
|
||||
+. [Sequence/Sequence Of]
|
||||
+. . [0] [Octet String] "S value"
|
||||
+. . [1] [Sequence/Sequence Of]
|
||||
+. . . [0] [Integer] 0
|
||||
+. . . [1] [Integer] 5
|
||||
+. . . [2] [Octet String] "krbASN.1 test message"
|
||||
+
|
||||
+encode_krb5_pa_spake(encdata):
|
||||
+
|
||||
+[CONT 3]
|
||||
+. [Sequence/Sequence Of]
|
||||
+. . [0] [Integer] 0
|
||||
+. . [1] [Integer] 5
|
||||
+. . [2] [Octet String] "krbASN.1 test message"
|
||||
631
Add-PKINIT-KDC-support-for-freshness-token.patch
Normal file
631
Add-PKINIT-KDC-support-for-freshness-token.patch
Normal file
|
|
@ -0,0 +1,631 @@
|
|||
From c93112a19f73b9a984cabd320129ee8f70cb4823 Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Mon, 12 Mar 2018 11:31:46 -0400
|
||||
Subject: [PATCH] Add PKINIT KDC support for freshness token
|
||||
|
||||
Send a freshness token in the preauth hint list if PKINIT is
|
||||
configured and the request padata indicates support. Verify the
|
||||
freshness token if the client includes one in a PKINIT request, and
|
||||
log whether one was received. If pkinit_require_freshness is set to
|
||||
true in the realm config, reject non-anonymous requests which don't
|
||||
contain a freshness token.
|
||||
|
||||
Add freshness token tests to t_pkinit.py with some related changes.
|
||||
Remove client long-term keys after testing password preauth so we get
|
||||
better error reporting when pkinit_require_freshness is set and a
|
||||
token is not sent. Remove ./responder invocations for test cases
|
||||
which don't ask PKINIT responder questions, or else the responder
|
||||
would fail now that it isn't being asked for the password. Leave
|
||||
anonymous PKINIT enabled after the anonymous tests so that we can use
|
||||
it again when testing enforcement of pkinit_require_freshness. Add
|
||||
expected trace messages for the basic test, including one for
|
||||
receiving a freshness token. Add minimal expected trace messages for
|
||||
the RSA test.
|
||||
|
||||
ticket: 8648
|
||||
(cherry picked from commit 4a9050df0bc34bfb08ba24462d6e2514640f4b8e)
|
||||
---
|
||||
doc/admin/conf_files/kdc_conf.rst | 4 +
|
||||
doc/admin/pkinit.rst | 25 +++++
|
||||
doc/appdev/refs/macros/index.rst | 2 +
|
||||
doc/formats/freshness_token.rst | 19 ++++
|
||||
doc/formats/index.rst | 1 +
|
||||
src/include/krb5/kdcpreauth_plugin.h | 17 ++++
|
||||
src/include/krb5/krb5.hin | 3 +
|
||||
src/kdc/do_as_req.c | 2 +
|
||||
src/kdc/kdc_preauth.c | 130 +++++++++++++++++++++++-
|
||||
src/kdc/kdc_util.h | 2 +
|
||||
src/plugins/preauth/pkinit/pkinit.h | 2 +
|
||||
src/plugins/preauth/pkinit/pkinit_srv.c | 51 +++++++++-
|
||||
src/tests/t_pkinit.py | 50 ++++++---
|
||||
13 files changed, 292 insertions(+), 16 deletions(-)
|
||||
create mode 100644 doc/formats/freshness_token.rst
|
||||
|
||||
diff --git a/doc/admin/conf_files/kdc_conf.rst b/doc/admin/conf_files/kdc_conf.rst
|
||||
index 3af1c3796..1ac1a37c2 100644
|
||||
--- a/doc/admin/conf_files/kdc_conf.rst
|
||||
+++ b/doc/admin/conf_files/kdc_conf.rst
|
||||
@@ -798,6 +798,10 @@ For information about the syntax of some of these options, see
|
||||
**pkinit_require_crl_checking** should be set to true if the
|
||||
policy is such that up-to-date CRLs must be present for every CA.
|
||||
|
||||
+**pkinit_require_freshness**
|
||||
+ Specifies whether to require clients to include a freshness token
|
||||
+ in PKINIT requests. The default value is false. (New in release
|
||||
+ 1.17.)
|
||||
|
||||
.. _Encryption_types:
|
||||
|
||||
diff --git a/doc/admin/pkinit.rst b/doc/admin/pkinit.rst
|
||||
index c601c5c9e..bec4fc800 100644
|
||||
--- a/doc/admin/pkinit.rst
|
||||
+++ b/doc/admin/pkinit.rst
|
||||
@@ -327,3 +327,28 @@ appropriate :ref:`kdc_realms` subsection of the KDC's
|
||||
To obtain anonymous credentials on a client, run ``kinit -n``, or
|
||||
``kinit -n @REALMNAME`` to specify a realm. The resulting tickets
|
||||
will have the client name ``WELLKNOWN/ANONYMOUS@WELLKNOWN:ANONYMOUS``.
|
||||
+
|
||||
+
|
||||
+Freshness tokens
|
||||
+----------------
|
||||
+
|
||||
+Freshness tokens can ensure that the client has recently had access to
|
||||
+its certificate private key. If freshness tokens are not required by
|
||||
+the KDC, a client program with temporary possession of the private key
|
||||
+can compose requests for future timestamps and use them later.
|
||||
+
|
||||
+In release 1.17 and later, freshness tokens are supported by the
|
||||
+client and are sent by the KDC when the client indicates support for
|
||||
+them. Because not all clients support freshness tokens yet, they are
|
||||
+not required by default. To check if freshness tokens are supported
|
||||
+by a realm's clients, look in the KDC logs for the lines::
|
||||
+
|
||||
+ PKINIT: freshness token received from <client principal>
|
||||
+ PKINIT: no freshness token received from <client principal>
|
||||
+
|
||||
+To require freshness tokens for all clients in a realm (except for
|
||||
+clients authenticating anonymously), set the
|
||||
+**pkinit_require_freshness** variable to ``true`` in the appropriate
|
||||
+:ref:`kdc_realms` subsection of the KDC's :ref:`kdc.conf(5)` file. To
|
||||
+test that this option is in effect, run ``kinit -X disable_freshness``
|
||||
+and verify that authentication is unsuccessful.
|
||||
diff --git a/doc/appdev/refs/macros/index.rst b/doc/appdev/refs/macros/index.rst
|
||||
index e76747102..dba818b26 100644
|
||||
--- a/doc/appdev/refs/macros/index.rst
|
||||
+++ b/doc/appdev/refs/macros/index.rst
|
||||
@@ -181,6 +181,7 @@ Public
|
||||
KRB5_KEYUSAGE_KRB_ERROR_CKSUM.rst
|
||||
KRB5_KEYUSAGE_KRB_PRIV_ENCPART.rst
|
||||
KRB5_KEYUSAGE_KRB_SAFE_CKSUM.rst
|
||||
+ KRB5_KEYUSAGE_PA_AS_FRESHNESS.rst
|
||||
KRB5_KEYUSAGE_PA_FX_COOKIE.rst
|
||||
KRB5_KEYUSAGE_PA_OTP_REQUEST.rst
|
||||
KRB5_KEYUSAGE_PA_PKINIT_KX.rst
|
||||
@@ -241,6 +242,7 @@ Public
|
||||
KRB5_PADATA_AFS3_SALT.rst
|
||||
KRB5_PADATA_AP_REQ.rst
|
||||
KRB5_PADATA_AS_CHECKSUM.rst
|
||||
+ KRB5_PADATA_AS_FRESHNESS.rst
|
||||
KRB5_PADATA_ENCRYPTED_CHALLENGE.rst
|
||||
KRB5_PADATA_ENC_SANDIA_SECURID.rst
|
||||
KRB5_PADATA_ENC_TIMESTAMP.rst
|
||||
diff --git a/doc/formats/freshness_token.rst b/doc/formats/freshness_token.rst
|
||||
new file mode 100644
|
||||
index 000000000..3127621a9
|
||||
--- /dev/null
|
||||
+++ b/doc/formats/freshness_token.rst
|
||||
@@ -0,0 +1,19 @@
|
||||
+PKINIT freshness tokens
|
||||
+=======================
|
||||
+
|
||||
+:rfc:`8070` specifies a pa-data type PA_AS_FRESHNESS, which clients
|
||||
+should reflect within signed PKINIT data to prove recent access to the
|
||||
+client certificate private key. The contents of a freshness token are
|
||||
+left to the KDC implementation. The MIT krb5 KDC uses the following
|
||||
+format for freshness tokens (starting in release 1.17):
|
||||
+
|
||||
+* a four-byte big-endian POSIX timestamp
|
||||
+* a four-byte big-endian key version number
|
||||
+* an :rfc:`3961` checksum, with no ASN.1 wrapper
|
||||
+
|
||||
+The checksum is computed using the first key in the local krbtgt
|
||||
+principal entry for the realm (e.g. ``krbtgt/KRBTEST.COM@KRBTEST.COM``
|
||||
+if the request is to the ``KRBTEST.COM`` realm) of the indicated key
|
||||
+version. The checksum type must be the mandatory checksum type for
|
||||
+the encryption type of the krbtgt key. The key usage value for the
|
||||
+checksum is 514.
|
||||
diff --git a/doc/formats/index.rst b/doc/formats/index.rst
|
||||
index 8b30626d4..4ad534424 100644
|
||||
--- a/doc/formats/index.rst
|
||||
+++ b/doc/formats/index.rst
|
||||
@@ -7,3 +7,4 @@ Protocols and file formats
|
||||
ccache_file_format
|
||||
keytab_file_format
|
||||
cookie
|
||||
+ freshness_token
|
||||
diff --git a/src/include/krb5/kdcpreauth_plugin.h b/src/include/krb5/kdcpreauth_plugin.h
|
||||
index f38820099..3a4754234 100644
|
||||
--- a/src/include/krb5/kdcpreauth_plugin.h
|
||||
+++ b/src/include/krb5/kdcpreauth_plugin.h
|
||||
@@ -240,6 +240,23 @@ typedef struct krb5_kdcpreauth_callbacks_st {
|
||||
|
||||
/* End of version 4 kdcpreauth callbacks. */
|
||||
|
||||
+ /*
|
||||
+ * Instruct the KDC to send a freshness token in the method data
|
||||
+ * accompanying a PREAUTH_REQUIRED or PREAUTH_FAILED error, if the client
|
||||
+ * indicated support for freshness tokens. This callback should only be
|
||||
+ * invoked from the edata method.
|
||||
+ */
|
||||
+ void (*send_freshness_token)(krb5_context context,
|
||||
+ krb5_kdcpreauth_rock rock);
|
||||
+
|
||||
+ /* Validate a freshness token sent by the client. Return 0 on success,
|
||||
+ * KRB5KDC_ERR_PREAUTH_EXPIRED on error. */
|
||||
+ krb5_error_code (*check_freshness_token)(krb5_context context,
|
||||
+ krb5_kdcpreauth_rock rock,
|
||||
+ const krb5_data *token);
|
||||
+
|
||||
+ /* End of version 5 kdcpreauth callbacks. */
|
||||
+
|
||||
} *krb5_kdcpreauth_callbacks;
|
||||
|
||||
/* Optional: preauth plugin initialization function. */
|
||||
diff --git a/src/include/krb5/krb5.hin b/src/include/krb5/krb5.hin
|
||||
index 833e72335..a650ecece 100644
|
||||
--- a/src/include/krb5/krb5.hin
|
||||
+++ b/src/include/krb5/krb5.hin
|
||||
@@ -1035,7 +1035,10 @@ krb5_c_keyed_checksum_types(krb5_context context, krb5_enctype enctype,
|
||||
#define KRB5_KEYUSAGE_AS_REQ 56
|
||||
#define KRB5_KEYUSAGE_CAMMAC 64
|
||||
|
||||
+/* Key usage values 512-1023 are reserved for uses internal to a Kerberos
|
||||
+ * implementation. */
|
||||
#define KRB5_KEYUSAGE_PA_FX_COOKIE 513 /**< Used for encrypted FAST cookies */
|
||||
+#define KRB5_KEYUSAGE_PA_AS_FRESHNESS 514 /**< Used for freshness tokens */
|
||||
/** @} */ /* end of KRB5_KEYUSAGE group */
|
||||
|
||||
/**
|
||||
diff --git a/src/kdc/do_as_req.c b/src/kdc/do_as_req.c
|
||||
index 7c8da63e1..588c1375a 100644
|
||||
--- a/src/kdc/do_as_req.c
|
||||
+++ b/src/kdc/do_as_req.c
|
||||
@@ -563,6 +563,7 @@ process_as_req(krb5_kdc_req *request, krb5_data *req_pkt,
|
||||
state->rock.rstate = state->rstate;
|
||||
state->rock.vctx = vctx;
|
||||
state->rock.auth_indicators = &state->auth_indicators;
|
||||
+ state->rock.send_freshness_token = FALSE;
|
||||
if (!state->request->client) {
|
||||
state->status = "NULL_CLIENT";
|
||||
errcode = KRB5KDC_ERR_C_PRINCIPAL_UNKNOWN;
|
||||
@@ -659,6 +660,7 @@ process_as_req(krb5_kdc_req *request, krb5_data *req_pkt,
|
||||
state->status = "GET_LOCAL_TGT";
|
||||
goto errout;
|
||||
}
|
||||
+ state->rock.local_tgt = state->local_tgt;
|
||||
|
||||
au_state->stage = VALIDATE_POL;
|
||||
|
||||
diff --git a/src/kdc/kdc_preauth.c b/src/kdc/kdc_preauth.c
|
||||
index 6f34dc289..80b130222 100644
|
||||
--- a/src/kdc/kdc_preauth.c
|
||||
+++ b/src/kdc/kdc_preauth.c
|
||||
@@ -87,6 +87,9 @@
|
||||
#include <assert.h>
|
||||
#include <krb5/kdcpreauth_plugin.h>
|
||||
|
||||
+/* Let freshness tokens be valid for ten minutes. */
|
||||
+#define FRESHNESS_LIFETIME 600
|
||||
+
|
||||
typedef struct preauth_system_st {
|
||||
const char *name;
|
||||
int type;
|
||||
@@ -497,8 +500,68 @@ client_name(krb5_context context, krb5_kdcpreauth_rock rock)
|
||||
return rock->client->princ;
|
||||
}
|
||||
|
||||
+static void
|
||||
+send_freshness_token(krb5_context context, krb5_kdcpreauth_rock rock)
|
||||
+{
|
||||
+ rock->send_freshness_token = TRUE;
|
||||
+}
|
||||
+
|
||||
+static krb5_error_code
|
||||
+check_freshness_token(krb5_context context, krb5_kdcpreauth_rock rock,
|
||||
+ const krb5_data *token)
|
||||
+{
|
||||
+ krb5_timestamp token_ts, now;
|
||||
+ krb5_key_data *kd;
|
||||
+ krb5_keyblock kb;
|
||||
+ krb5_kvno token_kvno;
|
||||
+ krb5_checksum cksum;
|
||||
+ krb5_data d;
|
||||
+ uint8_t *token_cksum;
|
||||
+ size_t token_cksum_len;
|
||||
+ krb5_boolean valid = FALSE;
|
||||
+ char ckbuf[4];
|
||||
+
|
||||
+ memset(&kb, 0, sizeof(kb));
|
||||
+
|
||||
+ if (krb5_timeofday(context, &now) != 0)
|
||||
+ goto cleanup;
|
||||
+
|
||||
+ if (token->length <= 8)
|
||||
+ goto cleanup;
|
||||
+ token_ts = load_32_be(token->data);
|
||||
+ token_kvno = load_32_be(token->data + 4);
|
||||
+ token_cksum = (uint8_t *)token->data + 8;
|
||||
+ token_cksum_len = token->length - 8;
|
||||
+
|
||||
+ /* Check if the token timestamp is too old. */
|
||||
+ if (ts_after(now, ts_incr(token_ts, FRESHNESS_LIFETIME)))
|
||||
+ goto cleanup;
|
||||
+
|
||||
+ /* Fetch and decrypt the local krbtgt key of the token's kvno. */
|
||||
+ if (krb5_dbe_find_enctype(context, rock->local_tgt, -1, -1, token_kvno,
|
||||
+ &kd) != 0)
|
||||
+ goto cleanup;
|
||||
+ if (krb5_dbe_decrypt_key_data(context, NULL, kd, &kb, NULL) != 0)
|
||||
+ goto cleanup;
|
||||
+
|
||||
+ /* Verify the token checksum against the current KDC time. The checksum
|
||||
+ * must use the mandatory checksum type of the krbtgt key's enctype. */
|
||||
+ store_32_be(token_ts, ckbuf);
|
||||
+ d = make_data(ckbuf, sizeof(ckbuf));
|
||||
+ cksum.magic = KV5M_CHECKSUM;
|
||||
+ cksum.checksum_type = 0;
|
||||
+ cksum.length = token_cksum_len;
|
||||
+ cksum.contents = token_cksum;
|
||||
+ (void)krb5_c_verify_checksum(context, &kb, KRB5_KEYUSAGE_PA_AS_FRESHNESS,
|
||||
+ &d, &cksum, &valid);
|
||||
+
|
||||
+cleanup:
|
||||
+ krb5_free_keyblock_contents(context, &kb);
|
||||
+ return valid ? 0 : KRB5KDC_ERR_PREAUTH_EXPIRED;
|
||||
+}
|
||||
+
|
||||
static struct krb5_kdcpreauth_callbacks_st callbacks = {
|
||||
- 4,
|
||||
+ 5,
|
||||
max_time_skew,
|
||||
client_keys,
|
||||
free_keys,
|
||||
@@ -514,7 +577,9 @@ static struct krb5_kdcpreauth_callbacks_st callbacks = {
|
||||
get_cookie,
|
||||
set_cookie,
|
||||
match_client,
|
||||
- client_name
|
||||
+ client_name,
|
||||
+ send_freshness_token,
|
||||
+ check_freshness_token
|
||||
};
|
||||
|
||||
static krb5_error_code
|
||||
@@ -770,6 +835,62 @@ cleanup:
|
||||
return ret;
|
||||
}
|
||||
|
||||
+static krb5_error_code
|
||||
+add_freshness_token(krb5_context context, krb5_kdcpreauth_rock rock,
|
||||
+ krb5_pa_data ***pa_list)
|
||||
+{
|
||||
+ krb5_error_code ret;
|
||||
+ krb5_timestamp now;
|
||||
+ krb5_key_data *kd;
|
||||
+ krb5_keyblock kb;
|
||||
+ krb5_checksum cksum;
|
||||
+ krb5_data d;
|
||||
+ krb5_pa_data *pa;
|
||||
+ char ckbuf[4];
|
||||
+
|
||||
+ memset(&cksum, 0, sizeof(cksum));
|
||||
+ memset(&kb, 0, sizeof(kb));
|
||||
+
|
||||
+ if (!rock->send_freshness_token)
|
||||
+ return 0;
|
||||
+ if (krb5int_find_pa_data(context, rock->request->padata,
|
||||
+ KRB5_PADATA_AS_FRESHNESS) == NULL)
|
||||
+ return 0;
|
||||
+
|
||||
+ /* Fetch and decrypt the current local krbtgt key. */
|
||||
+ ret = krb5_dbe_find_enctype(context, rock->local_tgt, -1, -1, 0, &kd);
|
||||
+ if (ret)
|
||||
+ goto cleanup;
|
||||
+ ret = krb5_dbe_decrypt_key_data(context, NULL, kd, &kb, NULL);
|
||||
+ if (ret)
|
||||
+ goto cleanup;
|
||||
+
|
||||
+ /* Compute a checksum over the current KDC time. */
|
||||
+ ret = krb5_timeofday(context, &now);
|
||||
+ if (ret)
|
||||
+ goto cleanup;
|
||||
+ store_32_be(now, ckbuf);
|
||||
+ d = make_data(ckbuf, sizeof(ckbuf));
|
||||
+ ret = krb5_c_make_checksum(context, 0, &kb, KRB5_KEYUSAGE_PA_AS_FRESHNESS,
|
||||
+ &d, &cksum);
|
||||
+
|
||||
+ /* Compose a freshness token from the time, krbtgt kvno, and checksum. */
|
||||
+ ret = alloc_pa_data(KRB5_PADATA_AS_FRESHNESS, 8 + cksum.length, &pa);
|
||||
+ if (ret)
|
||||
+ goto cleanup;
|
||||
+ store_32_be(now, pa->contents);
|
||||
+ store_32_be(kd->key_data_kvno, pa->contents + 4);
|
||||
+ memcpy(pa->contents + 8, cksum.contents, cksum.length);
|
||||
+
|
||||
+ /* add_pa_data_element() claims pa on success or failure. */
|
||||
+ ret = add_pa_data_element(pa_list, pa);
|
||||
+
|
||||
+cleanup:
|
||||
+ krb5_free_keyblock_contents(context, &kb);
|
||||
+ krb5_free_checksum_contents(context, &cksum);
|
||||
+ return ret;
|
||||
+}
|
||||
+
|
||||
struct hint_state {
|
||||
kdc_hint_respond_fn respond;
|
||||
void *arg;
|
||||
@@ -792,6 +913,11 @@ hint_list_finish(struct hint_state *state, krb5_error_code code)
|
||||
void *oldarg = state->arg;
|
||||
kdc_realm_t *kdc_active_realm = state->realm;
|
||||
|
||||
+ /* Add a freshness token if a preauth module requested it and the client
|
||||
+ * request indicates support for it. */
|
||||
+ if (!code)
|
||||
+ code = add_freshness_token(kdc_context, state->rock, &state->pa_data);
|
||||
+
|
||||
if (!code) {
|
||||
if (state->pa_data == NULL) {
|
||||
krb5_klog_syslog(LOG_INFO,
|
||||
diff --git a/src/kdc/kdc_util.h b/src/kdc/kdc_util.h
|
||||
index 198eab9c4..1885c9f80 100644
|
||||
--- a/src/kdc/kdc_util.h
|
||||
+++ b/src/kdc/kdc_util.h
|
||||
@@ -426,11 +426,13 @@ struct krb5_kdcpreauth_rock_st {
|
||||
krb5_kdc_req *request;
|
||||
krb5_data *inner_body;
|
||||
krb5_db_entry *client;
|
||||
+ krb5_db_entry *local_tgt;
|
||||
krb5_key_data *client_key;
|
||||
krb5_keyblock *client_keyblock;
|
||||
struct kdc_request_state *rstate;
|
||||
verto_ctx *vctx;
|
||||
krb5_data ***auth_indicators;
|
||||
+ krb5_boolean send_freshness_token;
|
||||
};
|
||||
|
||||
#define isflagset(flagfield, flag) (flagfield & (flag))
|
||||
diff --git a/src/plugins/preauth/pkinit/pkinit.h b/src/plugins/preauth/pkinit/pkinit.h
|
||||
index 8489a3e23..fe2ec0d31 100644
|
||||
--- a/src/plugins/preauth/pkinit/pkinit.h
|
||||
+++ b/src/plugins/preauth/pkinit/pkinit.h
|
||||
@@ -77,6 +77,7 @@
|
||||
#define KRB5_CONF_PKINIT_KDC_OCSP "pkinit_kdc_ocsp"
|
||||
#define KRB5_CONF_PKINIT_POOL "pkinit_pool"
|
||||
#define KRB5_CONF_PKINIT_REQUIRE_CRL_CHECKING "pkinit_require_crl_checking"
|
||||
+#define KRB5_CONF_PKINIT_REQUIRE_FRESHNESS "pkinit_require_freshness"
|
||||
#define KRB5_CONF_PKINIT_REVOKE "pkinit_revoke"
|
||||
|
||||
/* Make pkiDebug(fmt,...) print, or not. */
|
||||
@@ -148,6 +149,7 @@ typedef struct _pkinit_plg_opts {
|
||||
int allow_upn; /* allow UPN-SAN instead of pkinit-SAN */
|
||||
int dh_or_rsa; /* selects DH or RSA based pkinit */
|
||||
int require_crl_checking; /* require CRL for a CA (default is false) */
|
||||
+ int require_freshness; /* require freshness token (default is false) */
|
||||
int disable_freshness; /* disable freshness token on client for testing */
|
||||
int dh_min_bits; /* minimum DH modulus size allowed */
|
||||
} pkinit_plg_opts;
|
||||
diff --git a/src/plugins/preauth/pkinit/pkinit_srv.c b/src/plugins/preauth/pkinit/pkinit_srv.c
|
||||
index 8aa4d8b49..76ad5bf19 100644
|
||||
--- a/src/plugins/preauth/pkinit/pkinit_srv.c
|
||||
+++ b/src/plugins/preauth/pkinit/pkinit_srv.c
|
||||
@@ -161,6 +161,10 @@ pkinit_server_get_edata(krb5_context context,
|
||||
if (plgctx == NULL)
|
||||
retval = EINVAL;
|
||||
|
||||
+ /* Send a freshness token if the client requested one. */
|
||||
+ if (!retval)
|
||||
+ cb->send_freshness_token(context, rock);
|
||||
+
|
||||
(*respond)(arg, retval, NULL);
|
||||
}
|
||||
|
||||
@@ -403,6 +407,31 @@ cleanup:
|
||||
return ret;
|
||||
}
|
||||
|
||||
+/* Return an error if freshness tokens are required and one was not received.
|
||||
+ * Log an appropriate message indicating whether a valid token was received. */
|
||||
+static krb5_error_code
|
||||
+check_log_freshness(krb5_context context, pkinit_kdc_context plgctx,
|
||||
+ krb5_kdc_req *request, krb5_boolean valid_freshness_token)
|
||||
+{
|
||||
+ krb5_error_code ret;
|
||||
+ char *name = NULL;
|
||||
+
|
||||
+ ret = krb5_unparse_name(context, request->client, &name);
|
||||
+ if (ret)
|
||||
+ return ret;
|
||||
+ if (plgctx->opts->require_freshness && !valid_freshness_token) {
|
||||
+ com_err("", 0, _("PKINIT: no freshness token, rejecting auth from %s"),
|
||||
+ name);
|
||||
+ ret = KRB5KDC_ERR_PREAUTH_FAILED;
|
||||
+ } else if (valid_freshness_token) {
|
||||
+ com_err("", 0, _("PKINIT: freshness token received from %s"), name);
|
||||
+ } else {
|
||||
+ com_err("", 0, _("PKINIT: no freshness token received from %s"), name);
|
||||
+ }
|
||||
+ krb5_free_unparsed_name(context, name);
|
||||
+ return ret;
|
||||
+}
|
||||
+
|
||||
static void
|
||||
pkinit_server_verify_padata(krb5_context context,
|
||||
krb5_data *req_pkt,
|
||||
@@ -425,10 +454,11 @@ pkinit_server_verify_padata(krb5_context context,
|
||||
pkinit_kdc_req_context reqctx = NULL;
|
||||
krb5_checksum cksum = {0, 0, 0, NULL};
|
||||
krb5_data *der_req = NULL;
|
||||
- krb5_data k5data;
|
||||
+ krb5_data k5data, *ftoken;
|
||||
int is_signed = 1;
|
||||
krb5_pa_data **e_data = NULL;
|
||||
krb5_kdcpreauth_modreq modreq = NULL;
|
||||
+ krb5_boolean valid_freshness_token = FALSE;
|
||||
char **sp;
|
||||
|
||||
pkiDebug("pkinit_verify_padata: entered!\n");
|
||||
@@ -599,6 +629,14 @@ pkinit_server_verify_padata(krb5_context context,
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
+ ftoken = auth_pack->pkAuthenticator.freshnessToken;
|
||||
+ if (ftoken != NULL) {
|
||||
+ retval = cb->check_freshness_token(context, rock, ftoken);
|
||||
+ if (retval)
|
||||
+ goto cleanup;
|
||||
+ valid_freshness_token = TRUE;
|
||||
+ }
|
||||
+
|
||||
/* check if kdcPkId present and match KDC's subjectIdentifier */
|
||||
if (reqp->kdcPkId.data != NULL) {
|
||||
int valid_kdcPkId = 0;
|
||||
@@ -641,6 +679,13 @@ pkinit_server_verify_padata(krb5_context context,
|
||||
break;
|
||||
}
|
||||
|
||||
+ if (is_signed) {
|
||||
+ retval = check_log_freshness(context, plgctx, request,
|
||||
+ valid_freshness_token);
|
||||
+ if (retval)
|
||||
+ goto cleanup;
|
||||
+ }
|
||||
+
|
||||
if (is_signed && plgctx->auth_indicators != NULL) {
|
||||
/* Assert configured authentication indicators. */
|
||||
for (sp = plgctx->auth_indicators; *sp != NULL; sp++) {
|
||||
@@ -1330,6 +1375,10 @@ pkinit_init_kdc_profile(krb5_context context, pkinit_kdc_context plgctx)
|
||||
KRB5_CONF_PKINIT_REQUIRE_CRL_CHECKING,
|
||||
0, &plgctx->opts->require_crl_checking);
|
||||
|
||||
+ pkinit_kdcdefault_boolean(context, plgctx->realmname,
|
||||
+ KRB5_CONF_PKINIT_REQUIRE_FRESHNESS,
|
||||
+ 0, &plgctx->opts->require_freshness);
|
||||
+
|
||||
pkinit_kdcdefault_string(context, plgctx->realmname,
|
||||
KRB5_CONF_PKINIT_EKU_CHECKING,
|
||||
&eku_string);
|
||||
diff --git a/src/tests/t_pkinit.py b/src/tests/t_pkinit.py
|
||||
index 86fe661a0..5bc60cb1e 100755
|
||||
--- a/src/tests/t_pkinit.py
|
||||
+++ b/src/tests/t_pkinit.py
|
||||
@@ -39,6 +39,8 @@ pkinit_kdc_conf = {'realms': {'$realm': {
|
||||
'pkinit_indicator': ['indpkinit1', 'indpkinit2']}}}
|
||||
restrictive_kdc_conf = {'realms': {'$realm': {
|
||||
'restrict_anonymous_to_tgt': 'true' }}}
|
||||
+freshness_kdc_conf = {'realms': {'$realm': {
|
||||
+ 'pkinit_require_freshness': 'true'}}}
|
||||
|
||||
testprincs = {'krbtgt/KRBTEST.COM': {'keys': 'aes128-cts'},
|
||||
'user': {'keys': 'aes128-cts', 'flags': '+preauth'},
|
||||
@@ -118,6 +120,10 @@ realm.kinit(realm.user_princ, password=password('user'))
|
||||
realm.klist(realm.user_princ)
|
||||
realm.run([kvno, realm.host_princ])
|
||||
|
||||
+# Having tested password preauth, remove the keys for better error
|
||||
+# reporting.
|
||||
+realm.run([kadminl, 'purgekeys', '-all', realm.user_princ])
|
||||
+
|
||||
# Test anonymous PKINIT.
|
||||
realm.kinit('@%s' % realm.realm, flags=['-n'], expected_code=1,
|
||||
expected_msg='not found in Kerberos database')
|
||||
@@ -153,23 +159,32 @@ realm.run([kvno, realm.host_princ], expected_code=1,
|
||||
realm.kinit(realm.host_princ, flags=['-k'])
|
||||
realm.run([kvno, '-U', 'user', realm.host_princ])
|
||||
|
||||
-# Go back to a normal KDC and disable anonymous PKINIT.
|
||||
+# Go back to the normal KDC environment.
|
||||
realm.stop_kdc()
|
||||
realm.start_kdc()
|
||||
-realm.run([kadminl, 'delprinc', 'WELLKNOWN/ANONYMOUS'])
|
||||
|
||||
# Run the basic test - PKINIT with FILE: identity, with no password on the key.
|
||||
-realm.run(['./responder', '-x', 'pkinit=',
|
||||
- '-X', 'X509_user_identity=%s' % file_identity, realm.user_princ])
|
||||
realm.kinit(realm.user_princ,
|
||||
- flags=['-X', 'X509_user_identity=%s' % file_identity])
|
||||
+ flags=['-X', 'X509_user_identity=%s' % file_identity],
|
||||
+ expected_trace=('Sending unauthenticated request',
|
||||
+ '/Additional pre-authentication required',
|
||||
+ 'Preauthenticating using KDC method data',
|
||||
+ 'PKINIT client received freshness token from KDC',
|
||||
+ 'PKINIT loading CA certs and CRLs from FILE',
|
||||
+ 'PKINIT client making DH request',
|
||||
+ 'Produced preauth for next request: 133, 16',
|
||||
+ 'PKINIT client verified DH reply',
|
||||
+ 'PKINIT client found id-pkinit-san in KDC cert',
|
||||
+ 'PKINIT client matched KDC principal krbtgt/'))
|
||||
realm.klist(realm.user_princ)
|
||||
realm.run([kvno, realm.host_princ])
|
||||
|
||||
# Try again using RSA instead of DH.
|
||||
realm.kinit(realm.user_princ,
|
||||
flags=['-X', 'X509_user_identity=%s' % file_identity,
|
||||
- '-X', 'flag_RSA_PROTOCOL=yes'])
|
||||
+ '-X', 'flag_RSA_PROTOCOL=yes'],
|
||||
+ expected_trace=('PKINIT client making RSA request',
|
||||
+ 'PKINIT client verified RSA reply'))
|
||||
realm.klist(realm.user_princ)
|
||||
|
||||
# Test a DH parameter renegotiation by temporarily setting a 4096-bit
|
||||
@@ -192,8 +207,23 @@ expected_trace = ('Sending unauthenticated request',
|
||||
realm.kinit(realm.user_princ,
|
||||
flags=['-X', 'X509_user_identity=%s' % file_identity],
|
||||
expected_trace=expected_trace)
|
||||
+
|
||||
+# Test enforcement of required freshness tokens. (We can leave
|
||||
+# freshness tokens required after this test.)
|
||||
+realm.kinit(realm.user_princ,
|
||||
+ flags=['-X', 'X509_user_identity=%s' % file_identity,
|
||||
+ '-X', 'disable_freshness=yes'])
|
||||
+f_env = realm.special_env('freshness', True, kdc_conf=freshness_kdc_conf)
|
||||
realm.stop_kdc()
|
||||
-realm.start_kdc()
|
||||
+realm.start_kdc(env=f_env)
|
||||
+realm.kinit(realm.user_princ,
|
||||
+ flags=['-X', 'X509_user_identity=%s' % file_identity])
|
||||
+realm.kinit(realm.user_princ,
|
||||
+ flags=['-X', 'X509_user_identity=%s' % file_identity,
|
||||
+ '-X', 'disable_freshness=yes'],
|
||||
+ expected_code=1, expected_msg='Preauthentication failed')
|
||||
+# Anonymous should never require a freshness token.
|
||||
+realm.kinit('@%s' % realm.realm, flags=['-n', '-X', 'disable_freshness=yes'])
|
||||
|
||||
# Run the basic test - PKINIT with FILE: identity, with a password on the key,
|
||||
# supplied by the prompter.
|
||||
@@ -229,8 +259,6 @@ shutil.copy(privkey_pem, os.path.join(path, 'user.key'))
|
||||
shutil.copy(privkey_enc_pem, os.path.join(path_enc, 'user.key'))
|
||||
shutil.copy(user_pem, os.path.join(path, 'user.crt'))
|
||||
shutil.copy(user_pem, os.path.join(path_enc, 'user.crt'))
|
||||
-realm.run(['./responder', '-x', 'pkinit=', '-X',
|
||||
- 'X509_user_identity=%s' % dir_identity, realm.user_princ])
|
||||
realm.kinit(realm.user_princ,
|
||||
flags=['-X', 'X509_user_identity=%s' % dir_identity])
|
||||
realm.klist(realm.user_princ)
|
||||
@@ -262,8 +290,6 @@ realm.klist(realm.user_princ)
|
||||
realm.run([kvno, realm.host_princ])
|
||||
|
||||
# PKINIT with PKCS12: identity, with no password on the bundle.
|
||||
-realm.run(['./responder', '-x', 'pkinit=',
|
||||
- '-X', 'X509_user_identity=%s' % p12_identity, realm.user_princ])
|
||||
realm.kinit(realm.user_princ,
|
||||
flags=['-X', 'X509_user_identity=%s' % p12_identity])
|
||||
realm.klist(realm.user_princ)
|
||||
@@ -357,8 +383,6 @@ conf = open(softpkcs11rc, 'w')
|
||||
conf.write("%s\t%s\t%s\t%s\n" % ('user', 'user token', user_pem, privkey_pem))
|
||||
conf.close()
|
||||
# Expect to succeed without having to supply any more information.
|
||||
-realm.run(['./responder', '-x', 'pkinit=',
|
||||
- '-X', 'X509_user_identity=%s' % p11_identity, realm.user_princ])
|
||||
realm.kinit(realm.user_princ,
|
||||
flags=['-X', 'X509_user_identity=%s' % p11_identity])
|
||||
realm.klist(realm.user_princ)
|
||||
336
Add-PKINIT-client-support-for-freshness-token.patch
Normal file
336
Add-PKINIT-client-support-for-freshness-token.patch
Normal file
|
|
@ -0,0 +1,336 @@
|
|||
From 5edc6de93196b4f07da6695a4b271a067000c84d Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Tue, 31 Jan 2017 17:02:34 -0500
|
||||
Subject: [PATCH] Add PKINIT client support for freshness token
|
||||
|
||||
Send an empty PA_AS_FRESHNESS padata item in unauthenticated AS
|
||||
requests to indicate support for RFC 8070. If the KDC includes a
|
||||
PA_AS_FRESHNESS value in its method data, echo it back in the new
|
||||
freshnessToken field of pkAuthenticator
|
||||
|
||||
ticket: 8648
|
||||
(cherry picked from commit 085785362e01467cb25c79a90dcebfba9ea019d8)
|
||||
---
|
||||
doc/user/user_commands/kinit.rst | 3 +++
|
||||
src/include/k5-int-pkinit.h | 1 +
|
||||
src/include/krb5/krb5.hin | 1 +
|
||||
src/lib/krb5/asn.1/asn1_k_encode.c | 5 ++++-
|
||||
src/lib/krb5/krb/get_in_tkt.c | 12 ++++++++----
|
||||
src/lib/krb5/krb/init_creds_ctx.h | 2 +-
|
||||
src/plugins/preauth/pkinit/pkinit.h | 3 +++
|
||||
src/plugins/preauth/pkinit/pkinit_clnt.c | 19 ++++++++++++++++++-
|
||||
src/plugins/preauth/pkinit/pkinit_lib.c | 3 +++
|
||||
src/plugins/preauth/pkinit/pkinit_trace.h | 2 ++
|
||||
src/tests/asn.1/ktest.c | 4 ++++
|
||||
src/tests/asn.1/pkinit_encode.out | 2 +-
|
||||
src/tests/asn.1/pkinit_trval.out | 1 +
|
||||
13 files changed, 50 insertions(+), 8 deletions(-)
|
||||
|
||||
diff --git a/doc/user/user_commands/kinit.rst b/doc/user/user_commands/kinit.rst
|
||||
index 3f9d5340f..1f696920f 100644
|
||||
--- a/doc/user/user_commands/kinit.rst
|
||||
+++ b/doc/user/user_commands/kinit.rst
|
||||
@@ -197,6 +197,9 @@ OPTIONS
|
||||
specify use of RSA, rather than the default Diffie-Hellman
|
||||
protocol
|
||||
|
||||
+ **disable_freshness**\ [**=yes**]
|
||||
+ disable sending freshness tokens (for testing purposes only)
|
||||
+
|
||||
|
||||
ENVIRONMENT
|
||||
-----------
|
||||
diff --git a/src/include/k5-int-pkinit.h b/src/include/k5-int-pkinit.h
|
||||
index 7b2f595cb..4622a629e 100644
|
||||
--- a/src/include/k5-int-pkinit.h
|
||||
+++ b/src/include/k5-int-pkinit.h
|
||||
@@ -42,6 +42,7 @@ typedef struct _krb5_pk_authenticator {
|
||||
krb5_timestamp ctime;
|
||||
krb5_int32 nonce; /* (0..4294967295) */
|
||||
krb5_checksum paChecksum;
|
||||
+ krb5_data *freshnessToken;
|
||||
} krb5_pk_authenticator;
|
||||
|
||||
/* PKAuthenticator draft9 */
|
||||
diff --git a/src/include/krb5/krb5.hin b/src/include/krb5/krb5.hin
|
||||
index e81bb0a6d..833e72335 100644
|
||||
--- a/src/include/krb5/krb5.hin
|
||||
+++ b/src/include/krb5/krb5.hin
|
||||
@@ -1879,6 +1879,7 @@ krb5_verify_checksum(krb5_context context, krb5_cksumtype ctype,
|
||||
#define KRB5_PADATA_OTP_PIN_CHANGE 144 /**< RFC 6560 section 4.3 */
|
||||
#define KRB5_PADATA_PKINIT_KX 147 /**< RFC 6112 */
|
||||
#define KRB5_ENCPADATA_REQ_ENC_PA_REP 149 /**< RFC 6806 */
|
||||
+#define KRB5_PADATA_AS_FRESHNESS 150 /**< RFC 8070 */
|
||||
|
||||
#define KRB5_SAM_USE_SAD_AS_KEY 0x80000000
|
||||
#define KRB5_SAM_SEND_ENCRYPTED_SAD 0x40000000
|
||||
diff --git a/src/lib/krb5/asn.1/asn1_k_encode.c b/src/lib/krb5/asn.1/asn1_k_encode.c
|
||||
index 889460989..3b23fe34a 100644
|
||||
--- a/src/lib/krb5/asn.1/asn1_k_encode.c
|
||||
+++ b/src/lib/krb5/asn.1/asn1_k_encode.c
|
||||
@@ -1442,9 +1442,12 @@ DEFFIELD(pk_authenticator_1, krb5_pk_authenticator, ctime, 1, kerberos_time);
|
||||
DEFFIELD(pk_authenticator_2, krb5_pk_authenticator, nonce, 2, int32);
|
||||
DEFFIELD(pk_authenticator_3, krb5_pk_authenticator, paChecksum, 3,
|
||||
ostring_checksum);
|
||||
+DEFFIELD(pk_authenticator_4, krb5_pk_authenticator, freshnessToken, 4,
|
||||
+ opt_ostring_data_ptr);
|
||||
static const struct atype_info *pk_authenticator_fields[] = {
|
||||
&k5_atype_pk_authenticator_0, &k5_atype_pk_authenticator_1,
|
||||
- &k5_atype_pk_authenticator_2, &k5_atype_pk_authenticator_3
|
||||
+ &k5_atype_pk_authenticator_2, &k5_atype_pk_authenticator_3,
|
||||
+ &k5_atype_pk_authenticator_4
|
||||
};
|
||||
DEFSEQTYPE(pk_authenticator, krb5_pk_authenticator, pk_authenticator_fields);
|
||||
|
||||
diff --git a/src/lib/krb5/krb/get_in_tkt.c b/src/lib/krb5/krb/get_in_tkt.c
|
||||
index 47a00bf2c..1d96ff163 100644
|
||||
--- a/src/lib/krb5/krb/get_in_tkt.c
|
||||
+++ b/src/lib/krb5/krb/get_in_tkt.c
|
||||
@@ -895,7 +895,7 @@ krb5_init_creds_init(krb5_context context,
|
||||
ctx->request = k5alloc(sizeof(krb5_kdc_req), &code);
|
||||
if (code != 0)
|
||||
goto cleanup;
|
||||
- ctx->enc_pa_rep_permitted = TRUE;
|
||||
+ ctx->info_pa_permitted = TRUE;
|
||||
code = krb5_copy_principal(context, client, &ctx->request->client);
|
||||
if (code != 0)
|
||||
goto cleanup;
|
||||
@@ -1389,7 +1389,11 @@ init_creds_step_request(krb5_context context,
|
||||
krb5_free_data(context, ctx->encoded_previous_request);
|
||||
ctx->encoded_previous_request = NULL;
|
||||
}
|
||||
- if (ctx->enc_pa_rep_permitted) {
|
||||
+ if (ctx->info_pa_permitted) {
|
||||
+ code = add_padata(&ctx->request->padata, KRB5_PADATA_AS_FRESHNESS,
|
||||
+ NULL, 0);
|
||||
+ if (code)
|
||||
+ goto cleanup;
|
||||
code = add_padata(&ctx->request->padata, KRB5_ENCPADATA_REQ_ENC_PA_REP,
|
||||
NULL, 0);
|
||||
}
|
||||
@@ -1530,7 +1534,7 @@ init_creds_step_reply(krb5_context context,
|
||||
ctx->selected_preauth_type == KRB5_PADATA_NONE) {
|
||||
/* The KDC didn't like our informational padata (probably a pre-1.7
|
||||
* MIT krb5 KDC). Retry without it. */
|
||||
- ctx->enc_pa_rep_permitted = FALSE;
|
||||
+ ctx->info_pa_permitted = FALSE;
|
||||
ctx->restarted = TRUE;
|
||||
code = restart_init_creds_loop(context, ctx, FALSE);
|
||||
} else if (reply_code == KDC_ERR_PREAUTH_EXPIRED) {
|
||||
@@ -1574,7 +1578,7 @@ init_creds_step_reply(krb5_context context,
|
||||
goto cleanup;
|
||||
/* Reset per-realm negotiation state. */
|
||||
ctx->restarted = FALSE;
|
||||
- ctx->enc_pa_rep_permitted = TRUE;
|
||||
+ ctx->info_pa_permitted = TRUE;
|
||||
code = restart_init_creds_loop(context, ctx, FALSE);
|
||||
} else {
|
||||
if (retry && ctx->selected_preauth_type != KRB5_PADATA_NONE) {
|
||||
diff --git a/src/lib/krb5/krb/init_creds_ctx.h b/src/lib/krb5/krb/init_creds_ctx.h
|
||||
index fe769685b..b19410a13 100644
|
||||
--- a/src/lib/krb5/krb/init_creds_ctx.h
|
||||
+++ b/src/lib/krb5/krb/init_creds_ctx.h
|
||||
@@ -58,7 +58,7 @@ struct _krb5_init_creds_context {
|
||||
krb5_data s2kparams;
|
||||
krb5_keyblock as_key;
|
||||
krb5_enctype etype;
|
||||
- krb5_boolean enc_pa_rep_permitted;
|
||||
+ krb5_boolean info_pa_permitted;
|
||||
krb5_boolean restarted;
|
||||
struct krb5_responder_context_st rctx;
|
||||
krb5_preauthtype selected_preauth_type;
|
||||
diff --git a/src/plugins/preauth/pkinit/pkinit.h b/src/plugins/preauth/pkinit/pkinit.h
|
||||
index f3de9ad7a..8489a3e23 100644
|
||||
--- a/src/plugins/preauth/pkinit/pkinit.h
|
||||
+++ b/src/plugins/preauth/pkinit/pkinit.h
|
||||
@@ -148,6 +148,7 @@ typedef struct _pkinit_plg_opts {
|
||||
int allow_upn; /* allow UPN-SAN instead of pkinit-SAN */
|
||||
int dh_or_rsa; /* selects DH or RSA based pkinit */
|
||||
int require_crl_checking; /* require CRL for a CA (default is false) */
|
||||
+ int disable_freshness; /* disable freshness token on client for testing */
|
||||
int dh_min_bits; /* minimum DH modulus size allowed */
|
||||
} pkinit_plg_opts;
|
||||
|
||||
@@ -162,6 +163,7 @@ typedef struct _pkinit_req_opts {
|
||||
int require_crl_checking;
|
||||
int dh_size; /* initial request DH modulus size (default=1024) */
|
||||
int require_hostname_match;
|
||||
+ int disable_freshness;
|
||||
} pkinit_req_opts;
|
||||
|
||||
/*
|
||||
@@ -214,6 +216,7 @@ struct _pkinit_req_context {
|
||||
int identity_initialized;
|
||||
int identity_prompted;
|
||||
krb5_error_code identity_prompt_retval;
|
||||
+ krb5_data *freshness_token;
|
||||
};
|
||||
typedef struct _pkinit_req_context *pkinit_req_context;
|
||||
|
||||
diff --git a/src/plugins/preauth/pkinit/pkinit_clnt.c b/src/plugins/preauth/pkinit/pkinit_clnt.c
|
||||
index f1bc6b21d..9483d69e5 100644
|
||||
--- a/src/plugins/preauth/pkinit/pkinit_clnt.c
|
||||
+++ b/src/plugins/preauth/pkinit/pkinit_clnt.c
|
||||
@@ -231,6 +231,8 @@ pkinit_as_req_create(krb5_context context,
|
||||
auth_pack.pkAuthenticator.cusec = cusec;
|
||||
auth_pack.pkAuthenticator.nonce = nonce;
|
||||
auth_pack.pkAuthenticator.paChecksum = *cksum;
|
||||
+ if (!reqctx->opts->disable_freshness)
|
||||
+ auth_pack.pkAuthenticator.freshnessToken = reqctx->freshness_token;
|
||||
auth_pack.clientDHNonce.length = 0;
|
||||
auth_pack.clientPublicValue = &info;
|
||||
auth_pack.supportedKDFs = (krb5_data **)supported_kdf_alg_ids;
|
||||
@@ -1162,6 +1164,7 @@ pkinit_client_process(krb5_context context, krb5_clpreauth_moddata moddata,
|
||||
pkinit_context plgctx = (pkinit_context)moddata;
|
||||
pkinit_req_context reqctx = (pkinit_req_context)modreq;
|
||||
krb5_keyblock as_key;
|
||||
+ krb5_data d;
|
||||
|
||||
pkiDebug("pkinit_client_process %p %p %p %p\n",
|
||||
context, plgctx, reqctx, request);
|
||||
@@ -1174,6 +1177,12 @@ pkinit_client_process(krb5_context context, krb5_clpreauth_moddata moddata,
|
||||
case KRB5_PADATA_PKINIT_KX:
|
||||
reqctx->rfc6112_kdc = 1;
|
||||
return 0;
|
||||
+ case KRB5_PADATA_AS_FRESHNESS:
|
||||
+ TRACE_PKINIT_CLIENT_FRESHNESS_TOKEN(context);
|
||||
+ krb5_free_data(context, reqctx->freshness_token);
|
||||
+ reqctx->freshness_token = NULL;
|
||||
+ d = make_data(in_padata->contents, in_padata->length);
|
||||
+ return krb5_copy_data(context, &d, &reqctx->freshness_token);
|
||||
case KRB5_PADATA_PK_AS_REQ:
|
||||
reqctx->rfc4556_kdc = 1;
|
||||
pkiDebug("processing KRB5_PADATA_PK_AS_REQ\n");
|
||||
@@ -1359,7 +1368,7 @@ cleanup:
|
||||
static int
|
||||
pkinit_client_get_flags(krb5_context kcontext, krb5_preauthtype patype)
|
||||
{
|
||||
- if (patype == KRB5_PADATA_PKINIT_KX)
|
||||
+ if (patype == KRB5_PADATA_PKINIT_KX || patype == KRB5_PADATA_AS_FRESHNESS)
|
||||
return PA_INFO;
|
||||
return PA_REAL;
|
||||
}
|
||||
@@ -1376,6 +1385,7 @@ static krb5_preauthtype supported_client_pa_types[] = {
|
||||
KRB5_PADATA_PK_AS_REP_OLD,
|
||||
KRB5_PADATA_PK_AS_REQ_OLD,
|
||||
KRB5_PADATA_PKINIT_KX,
|
||||
+ KRB5_PADATA_AS_FRESHNESS,
|
||||
0
|
||||
};
|
||||
|
||||
@@ -1400,6 +1410,7 @@ pkinit_client_req_init(krb5_context context,
|
||||
reqctx->opts = NULL;
|
||||
reqctx->idctx = NULL;
|
||||
reqctx->idopts = NULL;
|
||||
+ reqctx->freshness_token = NULL;
|
||||
|
||||
retval = pkinit_init_req_opts(&reqctx->opts);
|
||||
if (retval)
|
||||
@@ -1410,6 +1421,7 @@ pkinit_client_req_init(krb5_context context,
|
||||
reqctx->opts->dh_or_rsa = plgctx->opts->dh_or_rsa;
|
||||
reqctx->opts->allow_upn = plgctx->opts->allow_upn;
|
||||
reqctx->opts->require_crl_checking = plgctx->opts->require_crl_checking;
|
||||
+ reqctx->opts->disable_freshness = plgctx->opts->disable_freshness;
|
||||
|
||||
retval = pkinit_init_req_crypto(&reqctx->cryptoctx);
|
||||
if (retval)
|
||||
@@ -1468,6 +1480,8 @@ pkinit_client_req_fini(krb5_context context, krb5_clpreauth_moddata moddata,
|
||||
if (reqctx->idopts != NULL)
|
||||
pkinit_fini_identity_opts(reqctx->idopts);
|
||||
|
||||
+ krb5_free_data(context, reqctx->freshness_token);
|
||||
+
|
||||
free(reqctx);
|
||||
return;
|
||||
}
|
||||
@@ -1580,6 +1594,9 @@ handle_gic_opt(krb5_context context,
|
||||
pkiDebug("Setting flag to use RSA_PROTOCOL\n");
|
||||
plgctx->opts->dh_or_rsa = RSA_PROTOCOL;
|
||||
}
|
||||
+ } else if (strcmp(attr, "disable_freshness") == 0) {
|
||||
+ if (strcmp(value, "yes") == 0)
|
||||
+ plgctx->opts->disable_freshness = 1;
|
||||
}
|
||||
return 0;
|
||||
}
|
||||
diff --git a/src/plugins/preauth/pkinit/pkinit_lib.c b/src/plugins/preauth/pkinit/pkinit_lib.c
|
||||
index 2f88545da..d5858c424 100644
|
||||
--- a/src/plugins/preauth/pkinit/pkinit_lib.c
|
||||
+++ b/src/plugins/preauth/pkinit/pkinit_lib.c
|
||||
@@ -82,6 +82,8 @@ pkinit_init_plg_opts(pkinit_plg_opts **plgopts)
|
||||
opts->dh_or_rsa = DH_PROTOCOL;
|
||||
opts->allow_upn = 0;
|
||||
opts->require_crl_checking = 0;
|
||||
+ opts->require_freshness = 0;
|
||||
+ opts->disable_freshness = 0;
|
||||
|
||||
opts->dh_min_bits = PKINIT_DEFAULT_DH_MIN_BITS;
|
||||
|
||||
@@ -145,6 +147,7 @@ free_krb5_auth_pack(krb5_auth_pack **in)
|
||||
free((*in)->clientPublicValue);
|
||||
}
|
||||
free((*in)->pkAuthenticator.paChecksum.contents);
|
||||
+ krb5_free_data(NULL, (*in)->pkAuthenticator.freshnessToken);
|
||||
if ((*in)->supportedCMSTypes != NULL)
|
||||
free_krb5_algorithm_identifiers(&((*in)->supportedCMSTypes));
|
||||
if ((*in)->supportedKDFs) {
|
||||
diff --git a/src/plugins/preauth/pkinit/pkinit_trace.h b/src/plugins/preauth/pkinit/pkinit_trace.h
|
||||
index 2d95da94a..7f95206c0 100644
|
||||
--- a/src/plugins/preauth/pkinit/pkinit_trace.h
|
||||
+++ b/src/plugins/preauth/pkinit/pkinit_trace.h
|
||||
@@ -41,6 +41,8 @@
|
||||
TRACE(c, "PKINIT client found no acceptable EKU in KDC cert")
|
||||
#define TRACE_PKINIT_CLIENT_EKU_SKIP(c) \
|
||||
TRACE(c, "PKINIT client skipping EKU check due to configuration")
|
||||
+#define TRACE_PKINIT_CLIENT_FRESHNESS_TOKEN(c) \
|
||||
+ TRACE(c, "PKINIT client received freshness token from KDC")
|
||||
#define TRACE_PKINIT_CLIENT_KDF_ALG(c, kdf, keyblock) \
|
||||
TRACE(c, "PKINIT client used KDF {hexdata} to compute reply key " \
|
||||
"{keyblock}", kdf, keyblock)
|
||||
diff --git a/src/tests/asn.1/ktest.c b/src/tests/asn.1/ktest.c
|
||||
index 43084cbbd..cf63f3f66 100644
|
||||
--- a/src/tests/asn.1/ktest.c
|
||||
+++ b/src/tests/asn.1/ktest.c
|
||||
@@ -725,6 +725,8 @@ ktest_make_sample_pk_authenticator(krb5_pk_authenticator *p)
|
||||
ktest_make_sample_checksum(&p->paChecksum);
|
||||
/* We don't encode the checksum type, only the contents. */
|
||||
p->paChecksum.checksum_type = 0;
|
||||
+ p->freshnessToken = ealloc(sizeof(krb5_data));
|
||||
+ ktest_make_sample_data(p->freshnessToken);
|
||||
}
|
||||
|
||||
static void
|
||||
@@ -1651,6 +1653,8 @@ ktest_empty_pk_authenticator(krb5_pk_authenticator *p)
|
||||
{
|
||||
ktest_empty_checksum(&p->paChecksum);
|
||||
p->paChecksum.contents = NULL;
|
||||
+ krb5_free_data(NULL, p->freshnessToken);
|
||||
+ p->freshnessToken = NULL;
|
||||
}
|
||||
|
||||
static void
|
||||
diff --git a/src/tests/asn.1/pkinit_encode.out b/src/tests/asn.1/pkinit_encode.out
|
||||
index 463128de0..3b0f7190a 100644
|
||||
--- a/src/tests/asn.1/pkinit_encode.out
|
||||
+++ b/src/tests/asn.1/pkinit_encode.out
|
||||
@@ -4,7 +4,7 @@ encode_krb5_pa_pk_as_rep(dhInfo): A0 28 30 26 80 08 6B 72 62 35 64 61 74 61 A1 0
|
||||
encode_krb5_pa_pk_as_rep(encKeyPack): 81 08 6B 72 62 35 64 61 74 61
|
||||
encode_krb5_pa_pk_as_rep_draft9(dhSignedData): 80 08 6B 72 62 35 64 61 74 61
|
||||
encode_krb5_pa_pk_as_rep_draft9(encKeyPack): 81 08 6B 72 62 35 64 61 74 61
|
||||
-encode_krb5_auth_pack: 30 81 93 A0 29 30 27 A0 05 02 03 01 E2 40 A1 11 18 0F 31 39 39 34 30 36 31 30 30 36 30 33 31 37 5A A2 03 02 01 2A A3 06 04 04 31 32 33 34 A1 22 30 20 30 13 06 09 2A 86 48 86 F7 12 01 02 02 04 06 70 61 72 61 6D 73 03 09 00 6B 72 62 35 64 61 74 61 A2 24 30 22 30 13 06 09 2A 86 48 86 F7 12 01 02 02 04 06 70 61 72 61 6D 73 30 0B 06 09 2A 86 48 86 F7 12 01 02 02 A3 0A 04 08 6B 72 62 35 64 61 74 61 A4 10 30 0E 30 0C A0 0A 06 08 6B 72 62 35 64 61 74 61
|
||||
+encode_krb5_auth_pack: 30 81 9F A0 35 30 33 A0 05 02 03 01 E2 40 A1 11 18 0F 31 39 39 34 30 36 31 30 30 36 30 33 31 37 5A A2 03 02 01 2A A3 06 04 04 31 32 33 34 A4 0A 04 08 6B 72 62 35 64 61 74 61 A1 22 30 20 30 13 06 09 2A 86 48 86 F7 12 01 02 02 04 06 70 61 72 61 6D 73 03 09 00 6B 72 62 35 64 61 74 61 A2 24 30 22 30 13 06 09 2A 86 48 86 F7 12 01 02 02 04 06 70 61 72 61 6D 73 30 0B 06 09 2A 86 48 86 F7 12 01 02 02 A3 0A 04 08 6B 72 62 35 64 61 74 61 A4 10 30 0E 30 0C A0 0A 06 08 6B 72 62 35 64 61 74 61
|
||||
encode_krb5_auth_pack_draft9: 30 75 A0 4F 30 4D A0 1A 30 18 A0 03 02 01 01 A1 11 30 0F 1B 06 68 66 74 73 61 69 1B 05 65 78 74 72 61 A1 10 1B 0E 41 54 48 45 4E 41 2E 4D 49 54 2E 45 44 55 A2 05 02 03 01 E2 40 A3 11 18 0F 31 39 39 34 30 36 31 30 30 36 30 33 31 37 5A A4 03 02 01 2A A1 22 30 20 30 13 06 09 2A 86 48 86 F7 12 01 02 02 04 06 70 61 72 61 6D 73 03 09 00 6B 72 62 35 64 61 74 61
|
||||
encode_krb5_kdc_dh_key_info: 30 25 A0 0B 03 09 00 6B 72 62 35 64 61 74 61 A1 03 02 01 2A A2 11 18 0F 31 39 39 34 30 36 31 30 30 36 30 33 31 37 5A
|
||||
encode_krb5_reply_key_pack: 30 26 A0 13 30 11 A0 03 02 01 01 A1 0A 04 08 31 32 33 34 35 36 37 38 A1 0F 30 0D A0 03 02 01 01 A1 06 04 04 31 32 33 34
|
||||
diff --git a/src/tests/asn.1/pkinit_trval.out b/src/tests/asn.1/pkinit_trval.out
|
||||
index 58d870631..f9edbe154 100644
|
||||
--- a/src/tests/asn.1/pkinit_trval.out
|
||||
+++ b/src/tests/asn.1/pkinit_trval.out
|
||||
@@ -57,6 +57,7 @@ encode_krb5_auth_pack:
|
||||
. . [1] [Generalized Time] "19940610060317Z"
|
||||
. . [2] [Integer] 42
|
||||
. . [3] [Octet String] "1234"
|
||||
+. . [4] [Octet String] "krb5data"
|
||||
. [1] [Sequence/Sequence Of]
|
||||
. . [Sequence/Sequence Of]
|
||||
. . . [Object Identifier] <9>
|
||||
14349
Add-SPAKE-preauth-support.patch
Normal file
14349
Add-SPAKE-preauth-support.patch
Normal file
File diff suppressed because it is too large
Load diff
31
Add-doc-index-entries-for-SPAKE-constants.patch
Normal file
31
Add-doc-index-entries-for-SPAKE-constants.patch
Normal file
|
|
@ -0,0 +1,31 @@
|
|||
From c891e4bc54c8083a1af8d28aa9b12ab1177ebb9a Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Tue, 27 Mar 2018 00:49:43 -0400
|
||||
Subject: [PATCH] Add doc index entries for SPAKE constants
|
||||
|
||||
ticket: 8647
|
||||
(cherry picked from commit c010c9031753f356bb380e8a1324cc34721f8221)
|
||||
---
|
||||
doc/appdev/refs/macros/index.rst | 2 ++
|
||||
1 file changed, 2 insertions(+)
|
||||
|
||||
diff --git a/doc/appdev/refs/macros/index.rst b/doc/appdev/refs/macros/index.rst
|
||||
index dba818b26..47c6d4413 100644
|
||||
--- a/doc/appdev/refs/macros/index.rst
|
||||
+++ b/doc/appdev/refs/macros/index.rst
|
||||
@@ -190,6 +190,7 @@ Public
|
||||
KRB5_KEYUSAGE_PA_SAM_CHALLENGE_CKSUM.rst
|
||||
KRB5_KEYUSAGE_PA_SAM_CHALLENGE_TRACKID.rst
|
||||
KRB5_KEYUSAGE_PA_SAM_RESPONSE.rst
|
||||
+ KRB5_KEYUSAGE_SPAKE.rst
|
||||
KRB5_KEYUSAGE_TGS_REP_ENCPART_SESSKEY.rst
|
||||
KRB5_KEYUSAGE_TGS_REP_ENCPART_SUBKEY.rst
|
||||
KRB5_KEYUSAGE_TGS_REQ_AD_SESSKEY.rst
|
||||
@@ -274,6 +275,7 @@ Public
|
||||
KRB5_PADATA_SAM_RESPONSE.rst
|
||||
KRB5_PADATA_SAM_RESPONSE_2.rst
|
||||
KRB5_PADATA_SESAME.rst
|
||||
+ KRB5_PADATA_SPAKE.rst
|
||||
KRB5_PADATA_SVR_REFERRAL_INFO.rst
|
||||
KRB5_PADATA_TGS_REQ.rst
|
||||
KRB5_PADATA_USE_SPECIFIED_KVNO.rst
|
||||
204
Add-flag-to-disable-encrypted-timestamp-on-client.patch
Normal file
204
Add-flag-to-disable-encrypted-timestamp-on-client.patch
Normal file
|
|
@ -0,0 +1,204 @@
|
|||
From f44ef4893050e673f495444c27a19525813f75a8 Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Mon, 11 Jun 2018 13:53:27 -0400
|
||||
Subject: [PATCH] Add flag to disable encrypted timestamp on client
|
||||
|
||||
ticket: 8655
|
||||
(cherry picked from commit 4ad376134b8d456392edbac7a7d351e6c7a7f0e7)
|
||||
---
|
||||
doc/admin/conf_files/krb5_conf.rst | 10 ++++++++++
|
||||
doc/admin/spake.rst | 8 ++++++++
|
||||
src/include/k5-int.h | 1 +
|
||||
src/include/k5-trace.h | 2 ++
|
||||
src/lib/krb5/krb/get_in_tkt.c | 23 +++++++++++++++++++++++
|
||||
src/lib/krb5/krb/init_creds_ctx.h | 1 +
|
||||
src/lib/krb5/krb/preauth_encts.c | 14 +++++++++++++-
|
||||
src/tests/t_referral.py | 13 +++++++++++++
|
||||
8 files changed, 71 insertions(+), 1 deletion(-)
|
||||
|
||||
diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst
|
||||
index ce545492d..eb5c29e5d 100644
|
||||
--- a/doc/admin/conf_files/krb5_conf.rst
|
||||
+++ b/doc/admin/conf_files/krb5_conf.rst
|
||||
@@ -475,6 +475,16 @@ following tags may be specified in the realm's subsection:
|
||||
(for example, when converting ``rcmd.hostname`` to
|
||||
``host/hostname.domain``).
|
||||
|
||||
+**disable_encrypted_timestamp**
|
||||
+ If this flag is true, the client will not perform encrypted
|
||||
+ timestamp preauthentication if requested by the KDC. Setting this
|
||||
+ flag can help to prevent dictionary attacks by active attackers,
|
||||
+ if the realm's KDCs support SPAKE preauthentication or if initial
|
||||
+ authentication always uses another mechanism or always uses FAST.
|
||||
+ This flag persists across client referrals during initial
|
||||
+ authentication. This flag does not prevent the KDC from offering
|
||||
+ encrypted timestamp. New in release 1.17.
|
||||
+
|
||||
**http_anchors**
|
||||
When KDCs and kpasswd servers are accessed through HTTPS proxies, this tag
|
||||
can be used to specify the location of the CA certificate which should be
|
||||
diff --git a/doc/admin/spake.rst b/doc/admin/spake.rst
|
||||
index b65c694aa..4f6eeaf53 100644
|
||||
--- a/doc/admin/spake.rst
|
||||
+++ b/doc/admin/spake.rst
|
||||
@@ -30,6 +30,14 @@ principal entries, as you would for any preauthentication mechanism::
|
||||
Clients which do not implement SPAKE preauthentication will fall back
|
||||
to encrypted timestamp.
|
||||
|
||||
+An active attacker can force a fallback to encrypted timestamp by
|
||||
+modifying the initial KDC response, defeating the protection against
|
||||
+dictionary attacks. To prevent this fallback on clients which do
|
||||
+implement SPAKE preauthentication, set the
|
||||
+**disable_encrypted_timestamp** variable to ``true`` in the
|
||||
+:ref:`realms` subsection for realms whose KDCs offer SPAKE
|
||||
+preauthentication.
|
||||
+
|
||||
By default, SPAKE preauthentication requires an extra network round
|
||||
trip to the KDC during initial authentication. If most of the clients
|
||||
in a realm support SPAKE, this extra round trip can be eliminated
|
||||
diff --git a/src/include/k5-int.h b/src/include/k5-int.h
|
||||
index 86b53c76b..e4a9a1412 100644
|
||||
--- a/src/include/k5-int.h
|
||||
+++ b/src/include/k5-int.h
|
||||
@@ -204,6 +204,7 @@ typedef unsigned char u_char;
|
||||
#define KRB5_CONF_DES_CRC_SESSION_SUPPORTED "des_crc_session_supported"
|
||||
#define KRB5_CONF_DICT_FILE "dict_file"
|
||||
#define KRB5_CONF_DISABLE "disable"
|
||||
+#define KRB5_CONF_DISABLE_ENCRYPTED_TIMESTAMP "disable_encrypted_timestamp"
|
||||
#define KRB5_CONF_DISABLE_LAST_SUCCESS "disable_last_success"
|
||||
#define KRB5_CONF_DISABLE_LOCKOUT "disable_lockout"
|
||||
#define KRB5_CONF_DNS_CANONICALIZE_HOSTNAME "dns_canonicalize_hostname"
|
||||
diff --git a/src/include/k5-trace.h b/src/include/k5-trace.h
|
||||
index 5f7eb9517..0854974dc 100644
|
||||
--- a/src/include/k5-trace.h
|
||||
+++ b/src/include/k5-trace.h
|
||||
@@ -299,6 +299,8 @@ void krb5int_trace(krb5_context context, const char *fmt, ...);
|
||||
#define TRACE_PREAUTH_ENC_TS(c, sec, usec, plain, enc) \
|
||||
TRACE(c, "Encrypted timestamp (for {long}.{int}): plain {hexdata}, " \
|
||||
"encrypted {hexdata}", (long) sec, (int) usec, plain, enc)
|
||||
+#define TRACE_PREAUTH_ENC_TS_DISABLED(c) \
|
||||
+ TRACE(c, "Ignoring encrypted timestamp because it is disabled")
|
||||
#define TRACE_PREAUTH_ETYPE_INFO(c, etype, salt, s2kparams) \
|
||||
TRACE(c, "Selected etype info: etype {etype}, salt \"{data}\", " \
|
||||
"params \"{data}\"", etype, salt, s2kparams)
|
||||
diff --git a/src/lib/krb5/krb/get_in_tkt.c b/src/lib/krb5/krb/get_in_tkt.c
|
||||
index c026bbc6d..79dede2c6 100644
|
||||
--- a/src/lib/krb5/krb/get_in_tkt.c
|
||||
+++ b/src/lib/krb5/krb/get_in_tkt.c
|
||||
@@ -801,6 +801,24 @@ read_allowed_preauth_type(krb5_context context, krb5_init_creds_context ctx)
|
||||
free(tmp);
|
||||
}
|
||||
|
||||
+/* Return true if encrypted timestamp is disabled for realm. */
|
||||
+static krb5_boolean
|
||||
+encts_disabled(profile_t profile, const krb5_data *realm)
|
||||
+{
|
||||
+ krb5_error_code ret;
|
||||
+ char *realmstr;
|
||||
+ int bval;
|
||||
+
|
||||
+ realmstr = k5memdup0(realm->data, realm->length, &ret);
|
||||
+ if (realmstr == NULL)
|
||||
+ return FALSE;
|
||||
+ ret = profile_get_boolean(profile, KRB5_CONF_REALMS, realmstr,
|
||||
+ KRB5_CONF_DISABLE_ENCRYPTED_TIMESTAMP, FALSE,
|
||||
+ &bval);
|
||||
+ free(realmstr);
|
||||
+ return (ret == 0) ? bval : FALSE;
|
||||
+}
|
||||
+
|
||||
/**
|
||||
* Throw away any pre-authentication realm state and begin with a
|
||||
* unauthenticated or optimistically authenticated request. If fast_upgrade is
|
||||
@@ -842,6 +860,11 @@ restart_init_creds_loop(krb5_context context, krb5_init_creds_context ctx,
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
+ /* Never set encts_disabled back to false, so it can't be circumvented with
|
||||
+ * client realm referrals. */
|
||||
+ if (encts_disabled(context->profile, &ctx->request->client->realm))
|
||||
+ ctx->encts_disabled = TRUE;
|
||||
+
|
||||
krb5_free_principal(context, ctx->request->server);
|
||||
ctx->request->server = NULL;
|
||||
|
||||
diff --git a/src/lib/krb5/krb/init_creds_ctx.h b/src/lib/krb5/krb/init_creds_ctx.h
|
||||
index 7ba61e17c..7a6219b1c 100644
|
||||
--- a/src/lib/krb5/krb/init_creds_ctx.h
|
||||
+++ b/src/lib/krb5/krb/init_creds_ctx.h
|
||||
@@ -61,6 +61,7 @@ struct _krb5_init_creds_context {
|
||||
krb5_boolean info_pa_permitted;
|
||||
krb5_boolean restarted;
|
||||
krb5_boolean fallback_disabled;
|
||||
+ krb5_boolean encts_disabled;
|
||||
struct krb5_responder_context_st rctx;
|
||||
krb5_preauthtype selected_preauth_type;
|
||||
krb5_preauthtype allowed_preauth_type;
|
||||
diff --git a/src/lib/krb5/krb/preauth_encts.c b/src/lib/krb5/krb/preauth_encts.c
|
||||
index 45bf9da92..345701984 100644
|
||||
--- a/src/lib/krb5/krb/preauth_encts.c
|
||||
+++ b/src/lib/krb5/krb/preauth_encts.c
|
||||
@@ -28,6 +28,7 @@
|
||||
#include <k5-int.h>
|
||||
#include <krb5/clpreauth_plugin.h>
|
||||
#include "int-proto.h"
|
||||
+#include "init_creds_ctx.h"
|
||||
|
||||
static krb5_error_code
|
||||
encts_prep_questions(krb5_context context, krb5_clpreauth_moddata moddata,
|
||||
@@ -38,7 +39,10 @@ encts_prep_questions(krb5_context context, krb5_clpreauth_moddata moddata,
|
||||
krb5_data *encoded_previous_request,
|
||||
krb5_pa_data *pa_data)
|
||||
{
|
||||
- cb->need_as_key(context, rock);
|
||||
+ krb5_init_creds_context ctx = (krb5_init_creds_context)rock;
|
||||
+
|
||||
+ if (!ctx->encts_disabled)
|
||||
+ cb->need_as_key(context, rock);
|
||||
return 0;
|
||||
}
|
||||
|
||||
@@ -51,6 +55,7 @@ encts_process(krb5_context context, krb5_clpreauth_moddata moddata,
|
||||
krb5_prompter_fct prompter, void *prompter_data,
|
||||
krb5_pa_data ***out_padata)
|
||||
{
|
||||
+ krb5_init_creds_context ctx = (krb5_init_creds_context)rock;
|
||||
krb5_error_code ret;
|
||||
krb5_pa_enc_ts pa_enc;
|
||||
krb5_data *ts = NULL, *enc_ts = NULL;
|
||||
@@ -60,6 +65,13 @@ encts_process(krb5_context context, krb5_clpreauth_moddata moddata,
|
||||
|
||||
enc_data.ciphertext = empty_data();
|
||||
|
||||
+ if (ctx->encts_disabled) {
|
||||
+ TRACE_PREAUTH_ENC_TS_DISABLED(context);
|
||||
+ k5_setmsg(context, KRB5_PREAUTH_FAILED,
|
||||
+ _("Encrypted timestamp is disabled"));
|
||||
+ return KRB5_PREAUTH_FAILED;
|
||||
+ }
|
||||
+
|
||||
ret = cb->get_as_key(context, rock, &as_key);
|
||||
if (ret)
|
||||
goto cleanup;
|
||||
diff --git a/src/tests/t_referral.py b/src/tests/t_referral.py
|
||||
index 98fdf2925..e12fdc2e9 100755
|
||||
--- a/src/tests/t_referral.py
|
||||
+++ b/src/tests/t_referral.py
|
||||
@@ -126,4 +126,17 @@ r1.klist('user@KRBTEST2.COM', 'krbtgt/KRBTEST2.COM')
|
||||
r1.kinit('abc@XYZ', 'pw', ['-E'])
|
||||
r1.klist('abc\@XYZ@KRBTEST2.COM', 'krbtgt/KRBTEST2.COM')
|
||||
|
||||
+# Test that disable_encrypted_timestamp persists across client
|
||||
+# referrals. (This test relies on SPAKE not being enabled by default
|
||||
+# on the KDC.)
|
||||
+r2.run([kadminl, 'modprinc', '+preauth', 'user'])
|
||||
+msgs = ('Encrypted timestamp (for ')
|
||||
+r1.kinit('user', password('user'), ['-C'], expected_trace=msgs)
|
||||
+dconf = {'realms': {'$realm': {'disable_encrypted_timestamp': 'true'}}}
|
||||
+denv = r1.special_env('disable_encts', False, krb5_conf=dconf)
|
||||
+msgs = ('Ignoring encrypted timestamp because it is disabled',
|
||||
+ '/Encrypted timestamp is disabled')
|
||||
+r1.kinit('user', None, ['-C'], env=denv, expected_code=1, expected_trace=msgs,
|
||||
+ expected_msg='Encrypted timestamp is disabled')
|
||||
+
|
||||
success('KDC host referral tests')
|
||||
185
Add-function-and-enctype-flag-for-deprecations.patch
Normal file
185
Add-function-and-enctype-flag-for-deprecations.patch
Normal file
|
|
@ -0,0 +1,185 @@
|
|||
From 7b4e3ebc438ec0263b4b7b45a0ad39809699bbec Mon Sep 17 00:00:00 2001
|
||||
From: Robbie Harwood <rharwood@redhat.com>
|
||||
Date: Tue, 15 Jan 2019 16:16:57 -0500
|
||||
Subject: [PATCH] Add function and enctype flag for deprecations
|
||||
|
||||
krb5int_c_deprecated_enctype() checks for the ETYPE_DEPRECATED flag on
|
||||
enctypes. All ENCTYPE_WEAK enctypes are currently deprecated; not all
|
||||
deprecated enctypes are considered weak. Deprecations follow RFC 6649
|
||||
and RFC 8429.
|
||||
|
||||
(cherry picked from commit 484a6e7712f9b66e782b2520f07b0883889e116f)
|
||||
(cherry picked from commit e0c8eb1bf93e0591e363e414378c70c255a6e6b6)
|
||||
[rharwood@redhat.com: krb5_32.def conflict]
|
||||
---
|
||||
src/include/k5-int.h | 1 +
|
||||
src/lib/crypto/krb/crypto_int.h | 9 ++++++++-
|
||||
src/lib/crypto/krb/enctype_util.c | 7 +++++++
|
||||
src/lib/crypto/krb/etypes.c | 19 ++++++++++---------
|
||||
src/lib/crypto/libk5crypto.exports | 1 +
|
||||
src/lib/krb5_32.def | 3 +++
|
||||
6 files changed, 30 insertions(+), 10 deletions(-)
|
||||
|
||||
diff --git a/src/include/k5-int.h b/src/include/k5-int.h
|
||||
index e4a9a1412..c597f3b8a 100644
|
||||
--- a/src/include/k5-int.h
|
||||
+++ b/src/include/k5-int.h
|
||||
@@ -2076,6 +2076,7 @@ krb5_get_tgs_ktypes(krb5_context, krb5_const_principal, krb5_enctype **);
|
||||
krb5_boolean krb5_is_permitted_enctype(krb5_context, krb5_enctype);
|
||||
|
||||
krb5_boolean KRB5_CALLCONV krb5int_c_weak_enctype(krb5_enctype);
|
||||
+krb5_boolean KRB5_CALLCONV krb5int_c_deprecated_enctype(krb5_enctype);
|
||||
krb5_error_code k5_enctype_to_ssf(krb5_enctype enctype, unsigned int *ssf_out);
|
||||
|
||||
krb5_error_code krb5_kdc_rep_decrypt_proc(krb5_context, const krb5_keyblock *,
|
||||
diff --git a/src/lib/crypto/krb/crypto_int.h b/src/lib/crypto/krb/crypto_int.h
|
||||
index e5099291e..6c1c77cac 100644
|
||||
--- a/src/lib/crypto/krb/crypto_int.h
|
||||
+++ b/src/lib/crypto/krb/crypto_int.h
|
||||
@@ -114,7 +114,14 @@ struct krb5_keytypes {
|
||||
unsigned int ssf;
|
||||
};
|
||||
|
||||
-#define ETYPE_WEAK 1
|
||||
+/*
|
||||
+ * "Weak" means the enctype is believed to be vulnerable to practical attacks,
|
||||
+ * and will be disabled unless allow_weak_crypto is set to true. "Deprecated"
|
||||
+ * means the enctype has been deprecated by the IETF, and affects display and
|
||||
+ * logging.
|
||||
+ */
|
||||
+#define ETYPE_WEAK (1 << 0)
|
||||
+#define ETYPE_DEPRECATED (1 << 1)
|
||||
|
||||
extern const struct krb5_keytypes krb5int_enctypes_list[];
|
||||
extern const int krb5int_enctypes_length;
|
||||
diff --git a/src/lib/crypto/krb/enctype_util.c b/src/lib/crypto/krb/enctype_util.c
|
||||
index b1b40e7ec..e394f4e19 100644
|
||||
--- a/src/lib/crypto/krb/enctype_util.c
|
||||
+++ b/src/lib/crypto/krb/enctype_util.c
|
||||
@@ -51,6 +51,13 @@ krb5int_c_weak_enctype(krb5_enctype etype)
|
||||
return (ktp != NULL && (ktp->flags & ETYPE_WEAK) != 0);
|
||||
}
|
||||
|
||||
+krb5_boolean KRB5_CALLCONV
|
||||
+krb5int_c_deprecated_enctype(krb5_enctype etype)
|
||||
+{
|
||||
+ const struct krb5_keytypes *ktp = find_enctype(etype);
|
||||
+ return ktp != NULL && (ktp->flags & ETYPE_DEPRECATED) != 0;
|
||||
+}
|
||||
+
|
||||
krb5_error_code KRB5_CALLCONV
|
||||
krb5_c_enctype_compare(krb5_context context, krb5_enctype e1, krb5_enctype e2,
|
||||
krb5_boolean *similar)
|
||||
diff --git a/src/lib/crypto/krb/etypes.c b/src/lib/crypto/krb/etypes.c
|
||||
index 53d4a5c79..8f44c37e7 100644
|
||||
--- a/src/lib/crypto/krb/etypes.c
|
||||
+++ b/src/lib/crypto/krb/etypes.c
|
||||
@@ -33,6 +33,7 @@
|
||||
that the keytypes are all near each other. I'd rather not make
|
||||
that assumption. */
|
||||
|
||||
+/* Deprecations come from RFC 6649 and RFC 8249. */
|
||||
const struct krb5_keytypes krb5int_enctypes_list[] = {
|
||||
{ ENCTYPE_DES_CBC_CRC,
|
||||
"des-cbc-crc", { 0 }, "DES cbc mode with CRC-32",
|
||||
@@ -42,7 +43,7 @@ const struct krb5_keytypes krb5int_enctypes_list[] = {
|
||||
krb5int_des_string_to_key, k5_rand2key_des,
|
||||
krb5int_des_prf,
|
||||
CKSUMTYPE_RSA_MD5_DES,
|
||||
- ETYPE_WEAK, 56 },
|
||||
+ ETYPE_WEAK | ETYPE_DEPRECATED, 56 },
|
||||
{ ENCTYPE_DES_CBC_MD4,
|
||||
"des-cbc-md4", { 0 }, "DES cbc mode with RSA-MD4",
|
||||
&krb5int_enc_des, &krb5int_hash_md4,
|
||||
@@ -51,7 +52,7 @@ const struct krb5_keytypes krb5int_enctypes_list[] = {
|
||||
krb5int_des_string_to_key, k5_rand2key_des,
|
||||
krb5int_des_prf,
|
||||
CKSUMTYPE_RSA_MD4_DES,
|
||||
- ETYPE_WEAK, 56 },
|
||||
+ ETYPE_WEAK | ETYPE_DEPRECATED, 56 },
|
||||
{ ENCTYPE_DES_CBC_MD5,
|
||||
"des-cbc-md5", { "des" }, "DES cbc mode with RSA-MD5",
|
||||
&krb5int_enc_des, &krb5int_hash_md5,
|
||||
@@ -60,7 +61,7 @@ const struct krb5_keytypes krb5int_enctypes_list[] = {
|
||||
krb5int_des_string_to_key, k5_rand2key_des,
|
||||
krb5int_des_prf,
|
||||
CKSUMTYPE_RSA_MD5_DES,
|
||||
- ETYPE_WEAK, 56 },
|
||||
+ ETYPE_WEAK | ETYPE_DEPRECATED, 56 },
|
||||
{ ENCTYPE_DES_CBC_RAW,
|
||||
"des-cbc-raw", { 0 }, "DES cbc mode raw",
|
||||
&krb5int_enc_des, NULL,
|
||||
@@ -69,7 +70,7 @@ const struct krb5_keytypes krb5int_enctypes_list[] = {
|
||||
krb5int_des_string_to_key, k5_rand2key_des,
|
||||
krb5int_des_prf,
|
||||
0,
|
||||
- ETYPE_WEAK, 56 },
|
||||
+ ETYPE_WEAK | ETYPE_DEPRECATED, 56 },
|
||||
{ ENCTYPE_DES3_CBC_RAW,
|
||||
"des3-cbc-raw", { 0 }, "Triple DES cbc mode raw",
|
||||
&krb5int_enc_des3, NULL,
|
||||
@@ -78,7 +79,7 @@ const struct krb5_keytypes krb5int_enctypes_list[] = {
|
||||
krb5int_dk_string_to_key, k5_rand2key_des3,
|
||||
NULL, /*PRF*/
|
||||
0,
|
||||
- ETYPE_WEAK, 112 },
|
||||
+ ETYPE_WEAK | ETYPE_DEPRECATED, 112 },
|
||||
|
||||
{ ENCTYPE_DES3_CBC_SHA1,
|
||||
"des3-cbc-sha1", { "des3-hmac-sha1", "des3-cbc-sha1-kd" },
|
||||
@@ -89,7 +90,7 @@ const struct krb5_keytypes krb5int_enctypes_list[] = {
|
||||
krb5int_dk_string_to_key, k5_rand2key_des3,
|
||||
krb5int_dk_prf,
|
||||
CKSUMTYPE_HMAC_SHA1_DES3,
|
||||
- 0 /*flags*/, 112 },
|
||||
+ ETYPE_DEPRECATED, 112 },
|
||||
|
||||
{ ENCTYPE_DES_HMAC_SHA1,
|
||||
"des-hmac-sha1", { 0 }, "DES with HMAC/sha1",
|
||||
@@ -99,7 +100,7 @@ const struct krb5_keytypes krb5int_enctypes_list[] = {
|
||||
krb5int_dk_string_to_key, k5_rand2key_des,
|
||||
NULL, /*PRF*/
|
||||
0,
|
||||
- ETYPE_WEAK, 56 },
|
||||
+ ETYPE_WEAK | ETYPE_DEPRECATED, 56 },
|
||||
|
||||
/* rc4-hmac uses a 128-bit key, but due to weaknesses in the RC4 cipher, we
|
||||
* consider its strength degraded and assign it an SSF value of 64. */
|
||||
@@ -113,7 +114,7 @@ const struct krb5_keytypes krb5int_enctypes_list[] = {
|
||||
krb5int_arcfour_decrypt, krb5int_arcfour_string_to_key,
|
||||
k5_rand2key_direct, krb5int_arcfour_prf,
|
||||
CKSUMTYPE_HMAC_MD5_ARCFOUR,
|
||||
- 0 /*flags*/, 64 },
|
||||
+ ETYPE_DEPRECATED, 64 },
|
||||
{ ENCTYPE_ARCFOUR_HMAC_EXP,
|
||||
"arcfour-hmac-exp", { "rc4-hmac-exp", "arcfour-hmac-md5-exp" },
|
||||
"Exportable ArcFour with HMAC/md5",
|
||||
@@ -124,7 +125,7 @@ const struct krb5_keytypes krb5int_enctypes_list[] = {
|
||||
krb5int_arcfour_decrypt, krb5int_arcfour_string_to_key,
|
||||
k5_rand2key_direct, krb5int_arcfour_prf,
|
||||
CKSUMTYPE_HMAC_MD5_ARCFOUR,
|
||||
- ETYPE_WEAK, 40
|
||||
+ ETYPE_WEAK | ETYPE_DEPRECATED, 40
|
||||
},
|
||||
|
||||
{ ENCTYPE_AES128_CTS_HMAC_SHA1_96,
|
||||
diff --git a/src/lib/crypto/libk5crypto.exports b/src/lib/crypto/libk5crypto.exports
|
||||
index 82eb5f30c..90afdf5f7 100644
|
||||
--- a/src/lib/crypto/libk5crypto.exports
|
||||
+++ b/src/lib/crypto/libk5crypto.exports
|
||||
@@ -109,3 +109,4 @@ k5_allow_weak_pbkdf2iter
|
||||
krb5_c_prfplus
|
||||
krb5_c_derive_prfplus
|
||||
k5_enctype_to_ssf
|
||||
+krb5int_c_deprecated_enctype
|
||||
diff --git a/src/lib/krb5_32.def b/src/lib/krb5_32.def
|
||||
index f7b428e16..53fdbd916 100644
|
||||
--- a/src/lib/krb5_32.def
|
||||
+++ b/src/lib/krb5_32.def
|
||||
@@ -473,3 +473,6 @@ EXPORTS
|
||||
|
||||
; new in 1.16
|
||||
k5_enctype_to_ssf @438 ; PRIVATE GSSAPI
|
||||
+
|
||||
+; new in 1.18
|
||||
+ krb5int_c_deprecated_enctype @450 ; PRIVATE
|
||||
119
Add-k5_buf_add_vfmt-to-k5buf-interface.patch
Normal file
119
Add-k5_buf_add_vfmt-to-k5buf-interface.patch
Normal file
|
|
@ -0,0 +1,119 @@
|
|||
From 74e1079df0cc6e8932e487455177a69f782b863a Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Thu, 4 Jan 2018 14:35:12 -0500
|
||||
Subject: [PATCH] Add k5_buf_add_vfmt to k5buf interface
|
||||
|
||||
(cherry picked from commit f05766469efc2a055085c0bcf9d40c4cdf47fe36)
|
||||
---
|
||||
src/include/k5-buf.h | 8 ++++++
|
||||
src/util/support/k5buf.c | 26 +++++++++++--------
|
||||
src/util/support/libkrb5support-fixed.exports | 1 +
|
||||
3 files changed, 24 insertions(+), 11 deletions(-)
|
||||
|
||||
diff --git a/src/include/k5-buf.h b/src/include/k5-buf.h
|
||||
index f3207bd09..1223916a6 100644
|
||||
--- a/src/include/k5-buf.h
|
||||
+++ b/src/include/k5-buf.h
|
||||
@@ -76,6 +76,14 @@ void k5_buf_add_fmt(struct k5buf *buf, const char *fmt, ...)
|
||||
#endif
|
||||
;
|
||||
|
||||
+/* Add sprintf-style formatted data to BUF, with a va_list. The value of ap is
|
||||
+ * undefined after the call. */
|
||||
+void k5_buf_add_vfmt(struct k5buf *buf, const char *fmt, va_list ap)
|
||||
+#if !defined(__cplusplus) && (__GNUC__ > 2)
|
||||
+ __attribute__((__format__(__printf__, 2, 0)))
|
||||
+#endif
|
||||
+ ;
|
||||
+
|
||||
/* Extend the length of buf by len and return a pointer to the reserved space,
|
||||
* to be filled in by the caller. Return NULL on error. */
|
||||
void *k5_buf_get_space(struct k5buf *buf, size_t len);
|
||||
diff --git a/src/util/support/k5buf.c b/src/util/support/k5buf.c
|
||||
index f619f6a48..35978f238 100644
|
||||
--- a/src/util/support/k5buf.c
|
||||
+++ b/src/util/support/k5buf.c
|
||||
@@ -141,9 +141,9 @@ k5_buf_add_len(struct k5buf *buf, const void *data, size_t len)
|
||||
}
|
||||
|
||||
void
|
||||
-k5_buf_add_fmt(struct k5buf *buf, const char *fmt, ...)
|
||||
+k5_buf_add_vfmt(struct k5buf *buf, const char *fmt, va_list ap)
|
||||
{
|
||||
- va_list ap;
|
||||
+ va_list apcopy;
|
||||
int r;
|
||||
size_t remaining;
|
||||
char *tmp;
|
||||
@@ -154,9 +154,7 @@ k5_buf_add_fmt(struct k5buf *buf, const char *fmt, ...)
|
||||
|
||||
if (buf->buftype == K5BUF_FIXED) {
|
||||
/* Format the data directly into the fixed buffer. */
|
||||
- va_start(ap, fmt);
|
||||
r = vsnprintf(endptr(buf), remaining, fmt, ap);
|
||||
- va_end(ap);
|
||||
if (SNPRINTF_OVERFLOW(r, remaining))
|
||||
set_error(buf);
|
||||
else
|
||||
@@ -166,9 +164,9 @@ k5_buf_add_fmt(struct k5buf *buf, const char *fmt, ...)
|
||||
|
||||
/* Optimistically format the data directly into the dynamic buffer. */
|
||||
assert(buf->buftype == K5BUF_DYNAMIC);
|
||||
- va_start(ap, fmt);
|
||||
- r = vsnprintf(endptr(buf), remaining, fmt, ap);
|
||||
- va_end(ap);
|
||||
+ va_copy(apcopy, ap);
|
||||
+ r = vsnprintf(endptr(buf), remaining, fmt, apcopy);
|
||||
+ va_end(apcopy);
|
||||
if (!SNPRINTF_OVERFLOW(r, remaining)) {
|
||||
buf->len += (unsigned int) r;
|
||||
return;
|
||||
@@ -179,9 +177,7 @@ k5_buf_add_fmt(struct k5buf *buf, const char *fmt, ...)
|
||||
if (!ensure_space(buf, r))
|
||||
return;
|
||||
remaining = buf->space - buf->len;
|
||||
- va_start(ap, fmt);
|
||||
r = vsnprintf(endptr(buf), remaining, fmt, ap);
|
||||
- va_end(ap);
|
||||
if (SNPRINTF_OVERFLOW(r, remaining)) /* Shouldn't ever happen. */
|
||||
k5_buf_free(buf);
|
||||
else
|
||||
@@ -191,9 +187,7 @@ k5_buf_add_fmt(struct k5buf *buf, const char *fmt, ...)
|
||||
|
||||
/* It's a pre-C99 snprintf implementation, or something else went wrong.
|
||||
* Fall back to asprintf. */
|
||||
- va_start(ap, fmt);
|
||||
r = vasprintf(&tmp, fmt, ap);
|
||||
- va_end(ap);
|
||||
if (r < 0) {
|
||||
k5_buf_free(buf);
|
||||
return;
|
||||
@@ -206,6 +200,16 @@ k5_buf_add_fmt(struct k5buf *buf, const char *fmt, ...)
|
||||
free(tmp);
|
||||
}
|
||||
|
||||
+void
|
||||
+k5_buf_add_fmt(struct k5buf *buf, const char *fmt, ...)
|
||||
+{
|
||||
+ va_list ap;
|
||||
+
|
||||
+ va_start(ap, fmt);
|
||||
+ k5_buf_add_vfmt(buf, fmt, ap);
|
||||
+ va_end(ap);
|
||||
+}
|
||||
+
|
||||
void *
|
||||
k5_buf_get_space(struct k5buf *buf, size_t len)
|
||||
{
|
||||
diff --git a/src/util/support/libkrb5support-fixed.exports b/src/util/support/libkrb5support-fixed.exports
|
||||
index 30c946e7e..cb9bf0826 100644
|
||||
--- a/src/util/support/libkrb5support-fixed.exports
|
||||
+++ b/src/util/support/libkrb5support-fixed.exports
|
||||
@@ -6,6 +6,7 @@ k5_buf_init_dynamic
|
||||
k5_buf_add
|
||||
k5_buf_add_len
|
||||
k5_buf_add_fmt
|
||||
+k5_buf_add_vfmt
|
||||
k5_buf_get_space
|
||||
k5_buf_truncate
|
||||
k5_buf_status
|
||||
222
Add-k5_dir_filenames-to-libkrb5support.patch
Normal file
222
Add-k5_dir_filenames-to-libkrb5support.patch
Normal file
|
|
@ -0,0 +1,222 @@
|
|||
From 9010a0dbf59771cb0a9c1e6fd5a18a92a1200ca7 Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Tue, 5 Jun 2018 14:01:05 -0400
|
||||
Subject: [PATCH] Add k5_dir_filenames() to libkrb5support
|
||||
|
||||
Add a support function to get a list of filenames from a directory in
|
||||
sorted order.
|
||||
|
||||
(cherry picked from commit 27534121eb39089ff4335d8b465027e9ba783682)
|
||||
---
|
||||
src/include/k5-platform.h | 7 +
|
||||
src/util/support/Makefile.in | 3 +
|
||||
src/util/support/dir_filenames.c | 135 ++++++++++++++++++
|
||||
src/util/support/libkrb5support-fixed.exports | 2 +
|
||||
4 files changed, 147 insertions(+)
|
||||
create mode 100644 src/util/support/dir_filenames.c
|
||||
|
||||
diff --git a/src/include/k5-platform.h b/src/include/k5-platform.h
|
||||
index 07ef6a4ca..763408a09 100644
|
||||
--- a/src/include/k5-platform.h
|
||||
+++ b/src/include/k5-platform.h
|
||||
@@ -44,6 +44,8 @@
|
||||
* + constant time memory comparison
|
||||
* + path manipulation
|
||||
* + _, N_, dgettext, bindtextdomain (for localization)
|
||||
+ * + getopt_long
|
||||
+ * + fetching filenames from a directory
|
||||
*/
|
||||
|
||||
#ifndef K5_PLATFORM_H
|
||||
@@ -1148,4 +1150,9 @@ extern int k5_getopt_long(int nargc, char **nargv, char *options,
|
||||
#define getopt_long k5_getopt_long
|
||||
#endif /* HAVE_GETOPT_LONG */
|
||||
|
||||
+/* Set *fnames_out to a null-terminated list of filenames within dirname,
|
||||
+ * sorted according to strcmp(). Return 0 on success, or ENOENT/ENOMEM. */
|
||||
+int k5_dir_filenames(const char *dirname, char ***fnames_out);
|
||||
+void k5_free_filenames(char **fnames);
|
||||
+
|
||||
#endif /* K5_PLATFORM_H */
|
||||
diff --git a/src/util/support/Makefile.in b/src/util/support/Makefile.in
|
||||
index caaf15822..4715e0391 100644
|
||||
--- a/src/util/support/Makefile.in
|
||||
+++ b/src/util/support/Makefile.in
|
||||
@@ -85,6 +85,7 @@ STLIBOBJS= \
|
||||
hex.o \
|
||||
bcmp.o \
|
||||
strerror_r.o \
|
||||
+ dir_filenames.o \
|
||||
$(GETTIMEOFDAY_ST_OBJ) \
|
||||
$(IPC_ST_OBJ) \
|
||||
$(STRLCPY_ST_OBJ) \
|
||||
@@ -111,6 +112,7 @@ LIBOBJS= \
|
||||
$(OUTPRE)hex.$(OBJEXT) \
|
||||
$(OUTPRE)bcmp.$(OBJEXT) \
|
||||
$(OUTPRE)strerror_r.$(OBJEXT) \
|
||||
+ $(OUTPRE)dir_filenames.$(OBJEXT) \
|
||||
$(GETTIMEOFDAY_OBJ) \
|
||||
$(IPC_OBJ) \
|
||||
$(STRLCPY_OBJ) \
|
||||
@@ -147,6 +149,7 @@ SRCS=\
|
||||
$(srcdir)/hex.c \
|
||||
$(srcdir)/bcmp.c \
|
||||
$(srcdir)/strerror_r.c \
|
||||
+ $(srcdir)/dir_filenames.c \
|
||||
$(srcdir)/t_utf8.c \
|
||||
$(srcdir)/t_utf16.c \
|
||||
$(srcdir)/getopt.c \
|
||||
diff --git a/src/util/support/dir_filenames.c b/src/util/support/dir_filenames.c
|
||||
new file mode 100644
|
||||
index 000000000..9312b0238
|
||||
--- /dev/null
|
||||
+++ b/src/util/support/dir_filenames.c
|
||||
@@ -0,0 +1,135 @@
|
||||
+/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */
|
||||
+/* util/support/dir_filenames.c - fetch filenames in a directory */
|
||||
+/*
|
||||
+ * Copyright (C) 2018 by the Massachusetts Institute of Technology.
|
||||
+ * All rights reserved.
|
||||
+ *
|
||||
+ * Redistribution and use in source and binary forms, with or without
|
||||
+ * modification, are permitted provided that the following conditions
|
||||
+ * are met:
|
||||
+ *
|
||||
+ * * Redistributions of source code must retain the above copyright
|
||||
+ * notice, this list of conditions and the following disclaimer.
|
||||
+ *
|
||||
+ * * Redistributions in binary form must reproduce the above copyright
|
||||
+ * notice, this list of conditions and the following disclaimer in
|
||||
+ * the documentation and/or other materials provided with the
|
||||
+ * distribution.
|
||||
+ *
|
||||
+ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
|
||||
+ * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
|
||||
+ * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS
|
||||
+ * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE
|
||||
+ * COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT,
|
||||
+ * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES
|
||||
+ * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR
|
||||
+ * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
|
||||
+ * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
|
||||
+ * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
|
||||
+ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED
|
||||
+ * OF THE POSSIBILITY OF SUCH DAMAGE.
|
||||
+ */
|
||||
+
|
||||
+#include "k5-platform.h"
|
||||
+
|
||||
+void
|
||||
+k5_free_filenames(char **fnames)
|
||||
+{
|
||||
+ char **fn;
|
||||
+
|
||||
+ for (fn = fnames; fn != NULL && *fn != NULL; fn++)
|
||||
+ free(*fn);
|
||||
+ free(fnames);
|
||||
+}
|
||||
+
|
||||
+/* Resize the filename list and add a name. */
|
||||
+static int
|
||||
+add_filename(char ***fnames, int *n_fnames, const char *name)
|
||||
+{
|
||||
+ char **newlist;
|
||||
+
|
||||
+ newlist = realloc(*fnames, (*n_fnames + 2) * sizeof(*newlist));
|
||||
+ if (newlist == NULL)
|
||||
+ return ENOMEM;
|
||||
+ *fnames = newlist;
|
||||
+ newlist[*n_fnames] = strdup(name);
|
||||
+ if (newlist[*n_fnames] == NULL)
|
||||
+ return ENOMEM;
|
||||
+ (*n_fnames)++;
|
||||
+ newlist[*n_fnames] = NULL;
|
||||
+ return 0;
|
||||
+}
|
||||
+
|
||||
+static int
|
||||
+compare_with_strcmp(const void *a, const void *b)
|
||||
+{
|
||||
+ return strcmp(*(char **)a, *(char **)b);
|
||||
+}
|
||||
+
|
||||
+#ifdef _WIN32
|
||||
+
|
||||
+int
|
||||
+k5_dir_filenames(const char *dirname, char ***fnames_out)
|
||||
+{
|
||||
+ char *wildcard;
|
||||
+ WIN32_FIND_DATA ffd;
|
||||
+ HANDLE handle;
|
||||
+ char **fnames = NULL;
|
||||
+ int n_fnames = 0;
|
||||
+
|
||||
+ *fnames_out = NULL;
|
||||
+
|
||||
+ if (asprintf(&wildcard, "%s\\*", dirname) < 0)
|
||||
+ return ENOMEM;
|
||||
+ handle = FindFirstFile(wildcard, &ffd);
|
||||
+ free(wildcard);
|
||||
+ if (handle == INVALID_HANDLE_VALUE)
|
||||
+ return ENOENT;
|
||||
+
|
||||
+ do {
|
||||
+ if (add_filename(&fnames, &n_fnames, &ffd.cFileName) != 0) {
|
||||
+ k5_free_filenames(fnames);
|
||||
+ FindClose(handle);
|
||||
+ return ENOMEM;
|
||||
+ }
|
||||
+ } while (FindNextFile(handle, &ffd) != 0);
|
||||
+
|
||||
+ FindClose(handle);
|
||||
+ qsort(fnames, n_fnames, sizeof(*fnames), compare_with_strcmp);
|
||||
+ *fnames_out = fnames;
|
||||
+ return 0;
|
||||
+}
|
||||
+
|
||||
+#else /* _WIN32 */
|
||||
+
|
||||
+#include <dirent.h>
|
||||
+
|
||||
+int
|
||||
+k5_dir_filenames(const char *dirname, char ***fnames_out)
|
||||
+{
|
||||
+ DIR *dir;
|
||||
+ struct dirent *ent;
|
||||
+ char **fnames = NULL;
|
||||
+ int n_fnames = 0;
|
||||
+
|
||||
+ *fnames_out = NULL;
|
||||
+
|
||||
+ dir = opendir(dirname);
|
||||
+ if (dir == NULL)
|
||||
+ return ENOENT;
|
||||
+
|
||||
+ while ((ent = readdir(dir)) != NULL) {
|
||||
+ if (add_filename(&fnames, &n_fnames, ent->d_name) != 0) {
|
||||
+ k5_free_filenames(fnames);
|
||||
+ closedir(dir);
|
||||
+ return ENOMEM;
|
||||
+ }
|
||||
+ }
|
||||
+
|
||||
+ closedir(dir);
|
||||
+ qsort(fnames, n_fnames, sizeof(*fnames), compare_with_strcmp);
|
||||
+ *fnames_out = fnames;
|
||||
+ return 0;
|
||||
+}
|
||||
+
|
||||
+#endif /* not _WIN32 */
|
||||
diff --git a/src/util/support/libkrb5support-fixed.exports b/src/util/support/libkrb5support-fixed.exports
|
||||
index a5e2ade04..16ed5a6c1 100644
|
||||
--- a/src/util/support/libkrb5support-fixed.exports
|
||||
+++ b/src/util/support/libkrb5support-fixed.exports
|
||||
@@ -58,6 +58,8 @@ k5_path_split
|
||||
k5_strerror_r
|
||||
k5_utf8_to_utf16le
|
||||
k5_utf16le_to_utf8
|
||||
+k5_dir_filenames
|
||||
+k5_free_filenames
|
||||
krb5int_key_register
|
||||
krb5int_key_delete
|
||||
krb5int_getspecific
|
||||
60
Add-k5test-mark-function.patch
Normal file
60
Add-k5test-mark-function.patch
Normal file
|
|
@ -0,0 +1,60 @@
|
|||
From 68b61c6d6402c0ad57509705137c92ae814ace27 Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Wed, 18 Apr 2018 19:21:40 -0400
|
||||
Subject: [PATCH] Add k5test mark() function
|
||||
|
||||
Make it easier to locate a failing command in long Python test scripts
|
||||
by allowing the script to output marks, and displaying the most recent
|
||||
mark with command failures.
|
||||
|
||||
(cherry picked from commit 4e813204ac3dace93297f47d64dfc0aaecc370f8)
|
||||
---
|
||||
src/util/k5test.py | 14 ++++++++++++++
|
||||
1 file changed, 14 insertions(+)
|
||||
|
||||
diff --git a/src/util/k5test.py b/src/util/k5test.py
|
||||
index 4d30baf40..bc32877a7 100644
|
||||
--- a/src/util/k5test.py
|
||||
+++ b/src/util/k5test.py
|
||||
@@ -141,6 +141,11 @@ Scripts may use the following functions and variables:
|
||||
added newline) in testlog, and write it to stdout if running
|
||||
verbosely.
|
||||
|
||||
+* mark(message): Place a divider message in the test output, to make
|
||||
+ it easier to determine what part of the test script a command
|
||||
+ invocation belongs to. The last mark message will also be displayed
|
||||
+ if a command invocation fails. Do not include a newline in message.
|
||||
+
|
||||
* which(progname): Return the location of progname in the executable
|
||||
path, or None if it is not found.
|
||||
|
||||
@@ -376,6 +381,8 @@ def fail(msg):
|
||||
"""Print a message and exit with failure."""
|
||||
global _current_pass
|
||||
print "*** Failure:", msg
|
||||
+ if _last_mark:
|
||||
+ print "*** Last mark: %s" % _last_mark
|
||||
if _last_cmd:
|
||||
print "*** Last command (#%d): %s" % (_cmd_index - 1, _last_cmd)
|
||||
if _last_cmd_output:
|
||||
@@ -392,6 +399,12 @@ def success(msg):
|
||||
_success = True
|
||||
|
||||
|
||||
+def mark(msg):
|
||||
+ global _last_mark
|
||||
+ output('\n====== %s ======\n' % msg)
|
||||
+ _last_mark = msg
|
||||
+
|
||||
+
|
||||
def skipped(whatmsg, whymsg):
|
||||
output('*** Skipping: %s: %s\n' % (whatmsg, whymsg), force_verbose=True)
|
||||
f = open(os.path.join(buildtop, 'skiptests'), 'a')
|
||||
@@ -1275,6 +1288,7 @@ atexit.register(_onexit)
|
||||
signal.signal(signal.SIGINT, _onsigint)
|
||||
_outfile = open('testlog', 'w')
|
||||
_cmd_index = 1
|
||||
+_last_mark = None
|
||||
_last_cmd = None
|
||||
_last_cmd_output = None
|
||||
buildtop = _find_buildtop()
|
||||
484
Add-libkrb5support-hex-functions-and-tests.patch
Normal file
484
Add-libkrb5support-hex-functions-and-tests.patch
Normal file
|
|
@ -0,0 +1,484 @@
|
|||
From 507b1aff60fdadc91ca7c56d39711049aeeb1e58 Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Mon, 19 Feb 2018 00:51:44 -0500
|
||||
Subject: [PATCH] Add libkrb5support hex functions and tests
|
||||
|
||||
(cherry picked from commit 720dea558da0062d3cea4385327161e62cf09a5e)
|
||||
[rharwood@redhat.com Remove .gitignore]
|
||||
---
|
||||
src/include/k5-hex.h | 53 ++++++
|
||||
src/util/support/Makefile.in | 15 +-
|
||||
src/util/support/deps | 6 +
|
||||
src/util/support/hex.c | 116 ++++++++++++
|
||||
src/util/support/libkrb5support-fixed.exports | 2 +
|
||||
src/util/support/t_hex.c | 169 ++++++++++++++++++
|
||||
6 files changed, 358 insertions(+), 3 deletions(-)
|
||||
create mode 100644 src/include/k5-hex.h
|
||||
create mode 100644 src/util/support/hex.c
|
||||
create mode 100644 src/util/support/t_hex.c
|
||||
|
||||
diff --git a/src/include/k5-hex.h b/src/include/k5-hex.h
|
||||
new file mode 100644
|
||||
index 000000000..75bd2cb19
|
||||
--- /dev/null
|
||||
+++ b/src/include/k5-hex.h
|
||||
@@ -0,0 +1,53 @@
|
||||
+/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */
|
||||
+/* include/k5-hex.h - libkrb5support hex encoding/decoding declarations */
|
||||
+/*
|
||||
+ * Copyright (C) 2018 by the Massachusetts Institute of Technology.
|
||||
+ * All rights reserved.
|
||||
+ *
|
||||
+ * Redistribution and use in source and binary forms, with or without
|
||||
+ * modification, are permitted provided that the following conditions
|
||||
+ * are met:
|
||||
+ *
|
||||
+ * * Redistributions of source code must retain the above copyright
|
||||
+ * notice, this list of conditions and the following disclaimer.
|
||||
+ *
|
||||
+ * * Redistributions in binary form must reproduce the above copyright
|
||||
+ * notice, this list of conditions and the following disclaimer in
|
||||
+ * the documentation and/or other materials provided with the
|
||||
+ * distribution.
|
||||
+ *
|
||||
+ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
|
||||
+ * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
|
||||
+ * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS
|
||||
+ * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE
|
||||
+ * COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT,
|
||||
+ * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES
|
||||
+ * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR
|
||||
+ * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
|
||||
+ * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
|
||||
+ * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
|
||||
+ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED
|
||||
+ * OF THE POSSIBILITY OF SUCH DAMAGE.
|
||||
+ */
|
||||
+
|
||||
+#ifndef K5_HEX_H
|
||||
+#define K5_HEX_H
|
||||
+
|
||||
+#include "k5-platform.h"
|
||||
+
|
||||
+/*
|
||||
+ * Encode len bytes in hex, placing the result in allocated storage in
|
||||
+ * *hex_out. Use uppercase hex digits if uppercase is non-zero. Return 0 on
|
||||
+ * success, ENOMEM on error.
|
||||
+ */
|
||||
+int k5_hex_encode(const void *bytes, size_t len, int uppercase,
|
||||
+ char **hex_out);
|
||||
+
|
||||
+/*
|
||||
+ * Decode hex bytes, placing the result in allocated storage in *bytes_out and
|
||||
+ * *len_out. Null-terminate the result (primarily for decoding passwords in
|
||||
+ * libkdb_ldap). Return 0 on success, ENOMEM or EINVAL on error.
|
||||
+ */
|
||||
+int k5_hex_decode(const char *hex, uint8_t **bytes_out, size_t *len_out);
|
||||
+
|
||||
+#endif /* K5_HEX_H */
|
||||
diff --git a/src/util/support/Makefile.in b/src/util/support/Makefile.in
|
||||
index 58ac2e333..caaf15822 100644
|
||||
--- a/src/util/support/Makefile.in
|
||||
+++ b/src/util/support/Makefile.in
|
||||
@@ -82,6 +82,7 @@ STLIBOBJS= \
|
||||
path.o \
|
||||
base64.o \
|
||||
json.o \
|
||||
+ hex.o \
|
||||
bcmp.o \
|
||||
strerror_r.o \
|
||||
$(GETTIMEOFDAY_ST_OBJ) \
|
||||
@@ -107,6 +108,7 @@ LIBOBJS= \
|
||||
$(OUTPRE)path.$(OBJEXT) \
|
||||
$(OUTPRE)base64.$(OBJEXT) \
|
||||
$(OUTPRE)json.$(OBJEXT) \
|
||||
+ $(OUTPRE)hex.$(OBJEXT) \
|
||||
$(OUTPRE)bcmp.$(OBJEXT) \
|
||||
$(OUTPRE)strerror_r.$(OBJEXT) \
|
||||
$(GETTIMEOFDAY_OBJ) \
|
||||
@@ -137,10 +139,12 @@ SRCS=\
|
||||
$(srcdir)/t_unal.c \
|
||||
$(srcdir)/t_path.c \
|
||||
$(srcdir)/t_json.c \
|
||||
+ $(srcdir)/t_hex.c \
|
||||
$(srcdir)/zap.c \
|
||||
$(srcdir)/path.c \
|
||||
$(srcdir)/base64.c \
|
||||
$(srcdir)/json.c \
|
||||
+ $(srcdir)/hex.c \
|
||||
$(srcdir)/bcmp.c \
|
||||
$(srcdir)/strerror_r.c \
|
||||
$(srcdir)/t_utf8.c \
|
||||
@@ -216,6 +220,9 @@ T_JSON_OBJS= t_json.o json.o base64.o k5buf.o $(PRINTF_ST_OBJ)
|
||||
t_json: $(T_JSON_OBJS)
|
||||
$(CC_LINK) -o $@ $(T_JSON_OBJS)
|
||||
|
||||
+t_hex: t_hex.o hex.o
|
||||
+ $(CC_LINK) -o $@ t_hex.o hex.o
|
||||
+
|
||||
t_unal: t_unal.o
|
||||
$(CC_LINK) -o t_unal t_unal.o
|
||||
|
||||
@@ -227,7 +234,8 @@ T_UTF16_OBJS= t_utf16.o utf8_conv.o utf8.o k5buf.o $(PRINTF_ST_OBJ)
|
||||
t_utf16: $(T_UTF16_OBJS)
|
||||
$(CC_LINK) -o $@ $(T_UTF16_OBJS)
|
||||
|
||||
-TEST_PROGS= t_k5buf t_path t_path_win t_base64 t_json t_unal t_utf8 t_utf16
|
||||
+TEST_PROGS= t_k5buf t_path t_path_win t_base64 t_json t_hex t_unal t_utf8 \
|
||||
+ t_utf16
|
||||
|
||||
check-unix: $(TEST_PROGS)
|
||||
./t_k5buf
|
||||
@@ -235,6 +243,7 @@ check-unix: $(TEST_PROGS)
|
||||
./t_path_win
|
||||
./t_base64
|
||||
./t_json
|
||||
+ ./t_hex
|
||||
./t_unal
|
||||
./t_utf8
|
||||
./t_utf16
|
||||
@@ -242,8 +251,8 @@ check-unix: $(TEST_PROGS)
|
||||
clean:
|
||||
$(RM) t_k5buf.o t_k5buf t_unal.o t_unal path_win.o path_win
|
||||
$(RM) t_path_win.o t_path_win t_path.o t_path t_base64.o t_base64
|
||||
- $(RM) t_json.o t_json libkrb5support.exports t_utf8.o t_utf8
|
||||
- $(RM) t_utf16.o t_utf16
|
||||
+ $(RM) t_json.o t_json t_hex.o t_hex libkrb5support.exports
|
||||
+ $(RM) t_utf8.o t_utf8 t_utf16.o t_utf16
|
||||
|
||||
@lib_frag@
|
||||
@libobj_frag@
|
||||
diff --git a/src/util/support/deps b/src/util/support/deps
|
||||
index 34d8a884b..80e9a1c58 100644
|
||||
--- a/src/util/support/deps
|
||||
+++ b/src/util/support/deps
|
||||
@@ -63,6 +63,9 @@ t_path.so t_path.po $(OUTPRE)t_path.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \
|
||||
t_path.c
|
||||
t_json.so t_json.po $(OUTPRE)t_json.$(OBJEXT): $(top_srcdir)/include/k5-json.h \
|
||||
t_json.c
|
||||
+t_hex.so t_hex.po $(OUTPRE)t_hex.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \
|
||||
+ $(top_srcdir)/include/k5-hex.h $(top_srcdir)/include/k5-platform.h \
|
||||
+ $(top_srcdir)/include/k5-thread.h t_hex.c
|
||||
zap.so zap.po $(OUTPRE)zap.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \
|
||||
$(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-thread.h \
|
||||
zap.c
|
||||
@@ -76,6 +79,9 @@ json.so json.po $(OUTPRE)json.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \
|
||||
$(top_srcdir)/include/k5-base64.h $(top_srcdir)/include/k5-buf.h \
|
||||
$(top_srcdir)/include/k5-json.h $(top_srcdir)/include/k5-platform.h \
|
||||
$(top_srcdir)/include/k5-thread.h json.c
|
||||
+hex.so hex.po $(OUTPRE)hex.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \
|
||||
+ $(top_srcdir)/include/k5-hex.h $(top_srcdir)/include/k5-platform.h \
|
||||
+ $(top_srcdir)/include/k5-thread.h hex.c
|
||||
bcmp.so bcmp.po $(OUTPRE)bcmp.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \
|
||||
$(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-thread.h \
|
||||
bcmp.c
|
||||
diff --git a/src/util/support/hex.c b/src/util/support/hex.c
|
||||
new file mode 100644
|
||||
index 000000000..4407ff9ff
|
||||
--- /dev/null
|
||||
+++ b/src/util/support/hex.c
|
||||
@@ -0,0 +1,116 @@
|
||||
+/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */
|
||||
+/* util/support/hex.c - hex encoding/decoding implementation */
|
||||
+/*
|
||||
+ * Copyright (C) 2018 by the Massachusetts Institute of Technology.
|
||||
+ * All rights reserved.
|
||||
+ *
|
||||
+ * Redistribution and use in source and binary forms, with or without
|
||||
+ * modification, are permitted provided that the following conditions
|
||||
+ * are met:
|
||||
+ *
|
||||
+ * * Redistributions of source code must retain the above copyright
|
||||
+ * notice, this list of conditions and the following disclaimer.
|
||||
+ *
|
||||
+ * * Redistributions in binary form must reproduce the above copyright
|
||||
+ * notice, this list of conditions and the following disclaimer in
|
||||
+ * the documentation and/or other materials provided with the
|
||||
+ * distribution.
|
||||
+ *
|
||||
+ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
|
||||
+ * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
|
||||
+ * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS
|
||||
+ * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE
|
||||
+ * COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT,
|
||||
+ * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES
|
||||
+ * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR
|
||||
+ * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
|
||||
+ * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
|
||||
+ * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
|
||||
+ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED
|
||||
+ * OF THE POSSIBILITY OF SUCH DAMAGE.
|
||||
+ */
|
||||
+
|
||||
+#include <k5-platform.h>
|
||||
+#include <k5-hex.h>
|
||||
+#include <ctype.h>
|
||||
+
|
||||
+static inline char
|
||||
+hex_digit(uint8_t bval, int uppercase)
|
||||
+{
|
||||
+ assert(bval >= 0 && bval <= 0xF);
|
||||
+ if (bval < 10)
|
||||
+ return '0' + bval;
|
||||
+ else if (uppercase)
|
||||
+ return 'A' + (bval - 10);
|
||||
+ else
|
||||
+ return 'a' + (bval - 10);
|
||||
+}
|
||||
+
|
||||
+int
|
||||
+k5_hex_encode(const void *bytes, size_t len, int uppercase, char **hex_out)
|
||||
+{
|
||||
+ size_t i;
|
||||
+ const uint8_t *p = bytes;
|
||||
+ char *hex;
|
||||
+
|
||||
+ *hex_out = NULL;
|
||||
+
|
||||
+ hex = malloc(len * 2 + 1);
|
||||
+ if (hex == NULL)
|
||||
+ return ENOMEM;
|
||||
+
|
||||
+ for (i = 0; i < len; i++) {
|
||||
+ hex[i * 2] = hex_digit(p[i] >> 4, uppercase);
|
||||
+ hex[i * 2 + 1] = hex_digit(p[i] & 0xF, uppercase);
|
||||
+ }
|
||||
+ hex[len * 2] = '\0';
|
||||
+
|
||||
+ *hex_out = hex;
|
||||
+ return 0;
|
||||
+}
|
||||
+
|
||||
+/* Decode a hex digit. Return 0-15 on success, -1 on invalid input. */
|
||||
+static inline int
|
||||
+decode_hexchar(unsigned char c)
|
||||
+{
|
||||
+ if (isdigit(c))
|
||||
+ return c - '0';
|
||||
+ if (c >= 'A' && c <= 'F')
|
||||
+ return c - 'A' + 10;
|
||||
+ if (c >= 'a' && c <= 'f')
|
||||
+ return c - 'a' + 10;
|
||||
+ return -1;
|
||||
+}
|
||||
+
|
||||
+int
|
||||
+k5_hex_decode(const char *hex, uint8_t **bytes_out, size_t *len_out)
|
||||
+{
|
||||
+ size_t hexlen, i;
|
||||
+ int h1, h2;
|
||||
+ uint8_t *bytes;
|
||||
+
|
||||
+ *bytes_out = NULL;
|
||||
+ *len_out = 0;
|
||||
+
|
||||
+ hexlen = strlen(hex);
|
||||
+ if (hexlen % 2 != 0)
|
||||
+ return EINVAL;
|
||||
+ bytes = malloc(hexlen / 2 + 1);
|
||||
+ if (bytes == NULL)
|
||||
+ return ENOMEM;
|
||||
+
|
||||
+ for (i = 0; i < hexlen / 2; i++) {
|
||||
+ h1 = decode_hexchar(hex[i * 2]);
|
||||
+ h2 = decode_hexchar(hex[i * 2 + 1]);
|
||||
+ if (h1 == -1 || h2 == -1) {
|
||||
+ free(bytes);
|
||||
+ return EINVAL;
|
||||
+ }
|
||||
+ bytes[i] = h1 * 16 + h2;
|
||||
+ }
|
||||
+ bytes[i] = 0;
|
||||
+
|
||||
+ *bytes_out = bytes;
|
||||
+ *len_out = hexlen / 2;
|
||||
+ return 0;
|
||||
+}
|
||||
diff --git a/src/util/support/libkrb5support-fixed.exports b/src/util/support/libkrb5support-fixed.exports
|
||||
index fd74a1897..30c946e7e 100644
|
||||
--- a/src/util/support/libkrb5support-fixed.exports
|
||||
+++ b/src/util/support/libkrb5support-fixed.exports
|
||||
@@ -16,6 +16,8 @@ k5_get_error
|
||||
k5_free_error
|
||||
k5_clear_error
|
||||
k5_set_error_info_callout_fn
|
||||
+k5_hex_decode
|
||||
+k5_hex_encode
|
||||
k5_json_array_add
|
||||
k5_json_array_create
|
||||
k5_json_array_fmt
|
||||
diff --git a/src/util/support/t_hex.c b/src/util/support/t_hex.c
|
||||
new file mode 100644
|
||||
index 000000000..a586a1bc8
|
||||
--- /dev/null
|
||||
+++ b/src/util/support/t_hex.c
|
||||
@@ -0,0 +1,169 @@
|
||||
+/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */
|
||||
+/* util/support/t_hex.c - Test hex encoding and decoding */
|
||||
+/*
|
||||
+ * Copyright (C) 2018 by the Massachusetts Institute of Technology.
|
||||
+ * All rights reserved.
|
||||
+ *
|
||||
+ * Redistribution and use in source and binary forms, with or without
|
||||
+ * modification, are permitted provided that the following conditions
|
||||
+ * are met:
|
||||
+ *
|
||||
+ * * Redistributions of source code must retain the above copyright
|
||||
+ * notice, this list of conditions and the following disclaimer.
|
||||
+ *
|
||||
+ * * Redistributions in binary form must reproduce the above copyright
|
||||
+ * notice, this list of conditions and the following disclaimer in
|
||||
+ * the documentation and/or other materials provided with the
|
||||
+ * distribution.
|
||||
+ *
|
||||
+ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
|
||||
+ * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
|
||||
+ * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS
|
||||
+ * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE
|
||||
+ * COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT,
|
||||
+ * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES
|
||||
+ * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR
|
||||
+ * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
|
||||
+ * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
|
||||
+ * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
|
||||
+ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED
|
||||
+ * OF THE POSSIBILITY OF SUCH DAMAGE.
|
||||
+ */
|
||||
+
|
||||
+#include <k5-platform.h>
|
||||
+#include <k5-hex.h>
|
||||
+
|
||||
+struct {
|
||||
+ const char *hex;
|
||||
+ const char *binary;
|
||||
+ size_t binary_len;
|
||||
+ int uppercase;
|
||||
+} tests[] = {
|
||||
+ /* Invalid hex strings */
|
||||
+ { "1" },
|
||||
+ { "123" },
|
||||
+ { "0/" },
|
||||
+ { "/0" },
|
||||
+ { "0:" },
|
||||
+ { ":0" },
|
||||
+ { "0@" },
|
||||
+ { "@0" },
|
||||
+ { "0G" },
|
||||
+ { "G0" },
|
||||
+ { "0`" },
|
||||
+ { "`0" },
|
||||
+ { "0g" },
|
||||
+ { "g0" },
|
||||
+ { " 00 " },
|
||||
+ { "0\x01" },
|
||||
+
|
||||
+ { "", "", 0 },
|
||||
+ { "00", "\x00", 1 },
|
||||
+ { "01", "\x01", 1 },
|
||||
+ { "10", "\x10", 1 },
|
||||
+ { "01ff", "\x01\xFF", 2 },
|
||||
+ { "A0B0C0", "\xA0\xB0\xC0", 3, 1 },
|
||||
+ { "1a2b3c4d5e6f", "\x1A\x2B\x3C\x4D\x5E\x6F", 6 },
|
||||
+ { "ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff",
|
||||
+ "\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF"
|
||||
+ "\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF", 32 },
|
||||
+
|
||||
+ /* All byte values, lowercase */
|
||||
+ { "0001020304050607", "\x00\x01\x02\x03\x04\x05\x06\x07", 8 },
|
||||
+ { "08090a0b0c0d0e0f", "\x08\x09\x0A\x0B\x0C\x0D\x0E\x0F", 8 },
|
||||
+ { "1011121314151617", "\x10\x11\x12\x13\x14\x15\x16\x17", 8 },
|
||||
+ { "18191a1b1c1d1e1f", "\x18\x19\x1A\x1B\x1C\x1D\x1E\x1F", 8 },
|
||||
+ { "2021222324252627", "\x20\x21\x22\x23\x24\x25\x26\x27", 8 },
|
||||
+ { "28292a2b2c2d2e2f", "\x28\x29\x2A\x2B\x2C\x2D\x2E\x2F", 8 },
|
||||
+ { "3031323334353637", "\x30\x31\x32\x33\x34\x35\x36\x37", 8 },
|
||||
+ { "38393a3b3c3d3e3f", "\x38\x39\x3A\x3B\x3C\x3D\x3E\x3F", 8 },
|
||||
+ { "4041424344454647", "\x40\x41\x42\x43\x44\x45\x46\x47", 8 },
|
||||
+ { "48494a4b4c4d4e4f", "\x48\x49\x4A\x4B\x4C\x4D\x4E\x4F", 8 },
|
||||
+ { "5051525354555657", "\x50\x51\x52\x53\x54\x55\x56\x57", 8 },
|
||||
+ { "58595a5b5c5d5e5f", "\x58\x59\x5A\x5B\x5C\x5D\x5E\x5F", 8 },
|
||||
+ { "6061626364656667", "\x60\x61\x62\x63\x64\x65\x66\x67", 8 },
|
||||
+ { "68696a6b6c6d6e6f", "\x68\x69\x6A\x6B\x6C\x6D\x6E\x6F", 8 },
|
||||
+ { "7071727374757677", "\x70\x71\x72\x73\x74\x75\x76\x77", 8 },
|
||||
+ { "78797a7b7c7d7e7f", "\x78\x79\x7A\x7B\x7C\x7D\x7E\x7F", 8 },
|
||||
+ { "8081828384858687", "\x80\x81\x82\x83\x84\x85\x86\x87", 8 },
|
||||
+ { "88898a8b8c8d8e8f", "\x88\x89\x8A\x8B\x8C\x8D\x8E\x8F", 8 },
|
||||
+ { "9091929394959697", "\x90\x91\x92\x93\x94\x95\x96\x97", 8 },
|
||||
+ { "98999a9b9c9d9e9f", "\x98\x99\x9A\x9B\x9C\x9D\x9E\x9F", 8 },
|
||||
+ { "a0a1a2a3a4a5a6a7", "\xA0\xA1\xA2\xA3\xA4\xA5\xA6\xA7", 8 },
|
||||
+ { "a8a9aaabacadaeaf", "\xA8\xA9\xAA\xAB\xAC\xAD\xAE\xAF", 8 },
|
||||
+ { "b0b1b2b3b4b5b6b7", "\xB0\xB1\xB2\xB3\xB4\xB5\xB6\xB7", 8 },
|
||||
+ { "b8b9babbbcbdbebf", "\xB8\xB9\xBA\xBB\xBC\xBD\xBE\xBF", 8 },
|
||||
+ { "c0c1c2c3c4c5c6c7", "\xC0\xC1\xC2\xC3\xC4\xC5\xC6\xC7", 8 },
|
||||
+ { "c8c9cacbcccdcecf", "\xC8\xC9\xCA\xCB\xCC\xCD\xCE\xCF", 8 },
|
||||
+ { "d0d1d2d3d4d5d6d7", "\xD0\xD1\xD2\xD3\xD4\xD5\xD6\xD7", 8 },
|
||||
+ { "d8d9dadbdcdddedf", "\xD8\xD9\xDA\xDB\xDC\xDD\xDE\xDF", 8 },
|
||||
+ { "e0e1e2e3e4e5e6e7", "\xE0\xE1\xE2\xE3\xE4\xE5\xE6\xE7", 8 },
|
||||
+ { "e8e9eaebecedeeef", "\xE8\xE9\xEA\xEB\xEC\xED\xEE\xEF", 8 },
|
||||
+ { "f0f1f2f3f4f5f6f7", "\xF0\xF1\xF2\xF3\xF4\xF5\xF6\xF7", 8 },
|
||||
+ { "f8f9fafbfcfdfeff", "\xF8\xF9\xFA\xFB\xFC\xFD\xFE\xFF", 8 },
|
||||
+
|
||||
+ /* All byte values, uppercase */
|
||||
+ { "0001020304050607", "\x00\x01\x02\x03\x04\x05\x06\x07", 8, 1 },
|
||||
+ { "08090A0B0C0D0E0F", "\x08\x09\x0A\x0B\x0C\x0D\x0E\x0F", 8, 1 },
|
||||
+ { "1011121314151617", "\x10\x11\x12\x13\x14\x15\x16\x17", 8, 1 },
|
||||
+ { "18191A1B1C1D1E1F", "\x18\x19\x1A\x1B\x1C\x1D\x1E\x1F", 8, 1 },
|
||||
+ { "2021222324252627", "\x20\x21\x22\x23\x24\x25\x26\x27", 8, 1 },
|
||||
+ { "28292A2B2C2D2E2F", "\x28\x29\x2A\x2B\x2C\x2D\x2E\x2F", 8, 1 },
|
||||
+ { "3031323334353637", "\x30\x31\x32\x33\x34\x35\x36\x37", 8, 1 },
|
||||
+ { "38393A3B3C3D3E3F", "\x38\x39\x3A\x3B\x3C\x3D\x3E\x3F", 8, 1 },
|
||||
+ { "4041424344454647", "\x40\x41\x42\x43\x44\x45\x46\x47", 8, 1 },
|
||||
+ { "48494A4B4C4D4E4F", "\x48\x49\x4A\x4B\x4C\x4D\x4E\x4F", 8, 1 },
|
||||
+ { "5051525354555657", "\x50\x51\x52\x53\x54\x55\x56\x57", 8, 1 },
|
||||
+ { "58595A5B5C5D5E5F", "\x58\x59\x5A\x5B\x5C\x5D\x5E\x5F", 8, 1 },
|
||||
+ { "6061626364656667", "\x60\x61\x62\x63\x64\x65\x66\x67", 8, 1 },
|
||||
+ { "68696A6B6C6D6E6F", "\x68\x69\x6A\x6B\x6C\x6D\x6E\x6F", 8, 1 },
|
||||
+ { "7071727374757677", "\x70\x71\x72\x73\x74\x75\x76\x77", 8, 1 },
|
||||
+ { "78797A7B7C7D7E7F", "\x78\x79\x7A\x7B\x7C\x7D\x7E\x7F", 8, 1 },
|
||||
+ { "8081828384858687", "\x80\x81\x82\x83\x84\x85\x86\x87", 8, 1 },
|
||||
+ { "88898A8B8C8D8E8F", "\x88\x89\x8A\x8B\x8C\x8D\x8E\x8F", 8, 1 },
|
||||
+ { "9091929394959697", "\x90\x91\x92\x93\x94\x95\x96\x97", 8, 1 },
|
||||
+ { "98999A9B9C9D9E9F", "\x98\x99\x9A\x9B\x9C\x9D\x9E\x9F", 8, 1 },
|
||||
+ { "A0A1A2A3A4A5A6A7", "\xA0\xA1\xA2\xA3\xA4\xA5\xA6\xA7", 8, 1 },
|
||||
+ { "A8A9AAABACADAEAF", "\xA8\xA9\xAA\xAB\xAC\xAD\xAE\xAF", 8, 1 },
|
||||
+ { "B0B1B2B3B4B5B6B7", "\xB0\xB1\xB2\xB3\xB4\xB5\xB6\xB7", 8, 1 },
|
||||
+ { "B8B9BABBBCBDBEBF", "\xB8\xB9\xBA\xBB\xBC\xBD\xBE\xBF", 8, 1 },
|
||||
+ { "C0C1C2C3C4C5C6C7", "\xC0\xC1\xC2\xC3\xC4\xC5\xC6\xC7", 8, 1 },
|
||||
+ { "C8C9CACBCCCDCECF", "\xC8\xC9\xCA\xCB\xCC\xCD\xCE\xCF", 8, 1 },
|
||||
+ { "D0D1D2D3D4D5D6D7", "\xD0\xD1\xD2\xD3\xD4\xD5\xD6\xD7", 8, 1 },
|
||||
+ { "D8D9DADBDCDDDEDF", "\xD8\xD9\xDA\xDB\xDC\xDD\xDE\xDF", 8, 1 },
|
||||
+ { "E0E1E2E3E4E5E6E7", "\xE0\xE1\xE2\xE3\xE4\xE5\xE6\xE7", 8, 1 },
|
||||
+ { "E8E9EAEBECEDEEEF", "\xE8\xE9\xEA\xEB\xEC\xED\xEE\xEF", 8, 1 },
|
||||
+ { "F0F1F2F3F4F5F6F7", "\xF0\xF1\xF2\xF3\xF4\xF5\xF6\xF7", 8, 1 },
|
||||
+ { "F8F9FAFBFCFDFEFF", "\xF8\xF9\xFA\xFB\xFC\xFD\xFE\xFF", 8, 1 },
|
||||
+};
|
||||
+
|
||||
+int main()
|
||||
+{
|
||||
+ size_t i;
|
||||
+ char *hex;
|
||||
+ int ret;
|
||||
+ uint8_t *bytes;
|
||||
+ size_t len;
|
||||
+
|
||||
+ for (i = 0; i < sizeof(tests) / sizeof(*tests); i++) {
|
||||
+ if (tests[i].binary == NULL) {
|
||||
+ ret = k5_hex_decode(tests[i].hex, &bytes, &len);
|
||||
+ assert(ret == EINVAL && bytes == NULL && len == 0);
|
||||
+ continue;
|
||||
+ }
|
||||
+
|
||||
+ ret = k5_hex_decode(tests[i].hex, &bytes, &len);
|
||||
+ assert(ret == 0);
|
||||
+ assert(len == tests[i].binary_len);
|
||||
+ assert(memcmp(bytes, tests[i].binary, len) == 0);
|
||||
+ assert(bytes[len] == 0);
|
||||
+ free(bytes);
|
||||
+
|
||||
+ ret = k5_hex_encode((uint8_t *)tests[i].binary, tests[i].binary_len,
|
||||
+ tests[i].uppercase, &hex);
|
||||
+ assert(ret == 0);
|
||||
+ assert(strcmp(tests[i].hex, hex) == 0);
|
||||
+ free(hex);
|
||||
+ }
|
||||
+ return 0;
|
||||
+}
|
||||
106
Add-vector-support-to-k5_sha256.patch
Normal file
106
Add-vector-support-to-k5_sha256.patch
Normal file
|
|
@ -0,0 +1,106 @@
|
|||
From f8b14b92cc4c82578f8fc56dd1fddebe88120769 Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Sat, 3 Feb 2018 20:53:42 -0500
|
||||
Subject: [PATCH] Add vector support to k5_sha256()
|
||||
|
||||
Add a length argument so that multiple krb5_data values can be passed
|
||||
to k5_sha256(), for efficient computation of SHA-256 hashes over
|
||||
concatenations of data values.
|
||||
|
||||
(cherry picked from commit 4f3373e8c55b3e9bdfb5b065e07214c5816c85fa)
|
||||
---
|
||||
src/include/k5-int.h | 4 ++--
|
||||
src/lib/crypto/builtin/sha2/sha256.c | 6 ++++--
|
||||
src/lib/crypto/crypto_tests/t_sha2.c | 2 +-
|
||||
src/lib/crypto/openssl/sha256.c | 6 ++++--
|
||||
src/lib/krb5/rcache/rc_conv.c | 2 +-
|
||||
5 files changed, 12 insertions(+), 8 deletions(-)
|
||||
|
||||
diff --git a/src/include/k5-int.h b/src/include/k5-int.h
|
||||
index 9378ae047..1c1d9783b 100644
|
||||
--- a/src/include/k5-int.h
|
||||
+++ b/src/include/k5-int.h
|
||||
@@ -635,9 +635,9 @@ krb5int_arcfour_gsscrypt(const krb5_keyblock *keyblock, krb5_keyusage usage,
|
||||
|
||||
#define K5_SHA256_HASHLEN (256 / 8)
|
||||
|
||||
-/* Write the SHA-256 hash of in to out. */
|
||||
+/* Write the SHA-256 hash of in (containing n elements) to out. */
|
||||
krb5_error_code
|
||||
-k5_sha256(const krb5_data *in, uint8_t out[K5_SHA256_HASHLEN]);
|
||||
+k5_sha256(const krb5_data *in, size_t n, uint8_t out[K5_SHA256_HASHLEN]);
|
||||
|
||||
/*
|
||||
* Attempt to zero memory in a way that compilers won't optimize out.
|
||||
diff --git a/src/lib/crypto/builtin/sha2/sha256.c b/src/lib/crypto/builtin/sha2/sha256.c
|
||||
index 2b5cbe480..9a940b3f8 100644
|
||||
--- a/src/lib/crypto/builtin/sha2/sha256.c
|
||||
+++ b/src/lib/crypto/builtin/sha2/sha256.c
|
||||
@@ -257,12 +257,14 @@ k5_sha256_final(void *res, SHA256_CTX *m)
|
||||
}
|
||||
|
||||
krb5_error_code
|
||||
-k5_sha256(const krb5_data *in, uint8_t out[K5_SHA256_HASHLEN])
|
||||
+k5_sha256(const krb5_data *in, size_t n, uint8_t out[K5_SHA256_HASHLEN])
|
||||
{
|
||||
SHA256_CTX ctx;
|
||||
+ size_t i;
|
||||
|
||||
k5_sha256_init(&ctx);
|
||||
- k5_sha256_update(&ctx, in->data, in->length);
|
||||
+ for (i = 0; i < n; i++)
|
||||
+ k5_sha256_update(&ctx, in[i].data, in[i].length);
|
||||
k5_sha256_final(out, &ctx);
|
||||
return 0;
|
||||
}
|
||||
diff --git a/src/lib/crypto/crypto_tests/t_sha2.c b/src/lib/crypto/crypto_tests/t_sha2.c
|
||||
index 12f32869b..e6fa58498 100644
|
||||
--- a/src/lib/crypto/crypto_tests/t_sha2.c
|
||||
+++ b/src/lib/crypto/crypto_tests/t_sha2.c
|
||||
@@ -125,7 +125,7 @@ hash_test(const struct krb5_hash_provider *hash, struct test *tests)
|
||||
|
||||
if (hash == &krb5int_hash_sha256) {
|
||||
/* Try again using k5_sha256(). */
|
||||
- if (k5_sha256(&iov.data, (uint8_t *)hval.data) != 0)
|
||||
+ if (k5_sha256(&iov.data, 1, (uint8_t *)hval.data) != 0)
|
||||
abort();
|
||||
if (memcmp(hval.data, t->hash, hval.length) != 0)
|
||||
abort();
|
||||
diff --git a/src/lib/crypto/openssl/sha256.c b/src/lib/crypto/openssl/sha256.c
|
||||
index fa095d472..0edd8b7ba 100644
|
||||
--- a/src/lib/crypto/openssl/sha256.c
|
||||
+++ b/src/lib/crypto/openssl/sha256.c
|
||||
@@ -34,16 +34,18 @@
|
||||
#include <openssl/evp.h>
|
||||
|
||||
krb5_error_code
|
||||
-k5_sha256(const krb5_data *in, uint8_t out[K5_SHA256_HASHLEN])
|
||||
+k5_sha256(const krb5_data *in, size_t n, uint8_t out[K5_SHA256_HASHLEN])
|
||||
{
|
||||
EVP_MD_CTX *ctx;
|
||||
+ size_t i;
|
||||
int ok;
|
||||
|
||||
ctx = EVP_MD_CTX_new();
|
||||
if (ctx == NULL)
|
||||
return ENOMEM;
|
||||
ok = EVP_DigestInit_ex(ctx, EVP_sha256(), NULL);
|
||||
- ok = ok && EVP_DigestUpdate(ctx, in->data, in->length);
|
||||
+ for (i = 0; i < n; i++)
|
||||
+ ok = ok && EVP_DigestUpdate(ctx, in[i].data, in[i].length);
|
||||
ok = ok && EVP_DigestFinal_ex(ctx, out, NULL);
|
||||
EVP_MD_CTX_free(ctx);
|
||||
return ok ? 0 : ENOMEM;
|
||||
diff --git a/src/lib/krb5/rcache/rc_conv.c b/src/lib/krb5/rcache/rc_conv.c
|
||||
index 0e021f5d8..f2fe528ac 100644
|
||||
--- a/src/lib/krb5/rcache/rc_conv.c
|
||||
+++ b/src/lib/krb5/rcache/rc_conv.c
|
||||
@@ -58,7 +58,7 @@ krb5_rc_hash_message(krb5_context context, const krb5_data *message,
|
||||
*out = NULL;
|
||||
|
||||
/* Calculate the binary checksum. */
|
||||
- retval = k5_sha256(message, cksum);
|
||||
+ retval = k5_sha256(message, 1, cksum);
|
||||
if (retval)
|
||||
return retval;
|
||||
|
||||
95
Address-some-optimized-out-memset-calls.patch
Normal file
95
Address-some-optimized-out-memset-calls.patch
Normal file
|
|
@ -0,0 +1,95 @@
|
|||
From 772178a22bc43df83bfa74992d55f99a5153c03e Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Sun, 30 Dec 2018 16:40:28 -0500
|
||||
Subject: [PATCH] Address some optimized-out memset() calls
|
||||
|
||||
Ilja Van Sprundel reported a list of memset() calls which gcc
|
||||
optimizes out. In krb_auth_su.c, use zap() to clear the password, and
|
||||
remove two memset() calls when there is no password to clear. In
|
||||
iakerb.c, remove an unnecessary memset() before setting the only two
|
||||
fields of the IAKERB header structure. In svr_principal.c, use
|
||||
krb5_free_key_keyblock_contents() instead of hand-freeing key data.
|
||||
In asn1_k_encode.c, remove an unnecessary memset() of the kdc_req_hack
|
||||
shell before returning.
|
||||
|
||||
(cherry picked from commit 1057b0befec1f1c0e9d4da5521a58496e2dc0997)
|
||||
(cherry picked from commit 0d83197140d2040d47ca79f006126e503680f661)
|
||||
---
|
||||
src/clients/ksu/krb_auth_su.c | 4 +---
|
||||
src/lib/gssapi/krb5/iakerb.c | 1 -
|
||||
src/lib/kadm5/srv/svr_principal.c | 10 ++--------
|
||||
src/lib/krb5/asn.1/asn1_k_encode.c | 1 -
|
||||
4 files changed, 3 insertions(+), 13 deletions(-)
|
||||
|
||||
diff --git a/src/clients/ksu/krb_auth_su.c b/src/clients/ksu/krb_auth_su.c
|
||||
index 7af48195c..e39685fff 100644
|
||||
--- a/src/clients/ksu/krb_auth_su.c
|
||||
+++ b/src/clients/ksu/krb_auth_su.c
|
||||
@@ -183,21 +183,19 @@ krb5_boolean ksu_get_tgt_via_passwd(context, client, options, zero_password,
|
||||
if (code ) {
|
||||
com_err(prog_name, code, _("while reading password for '%s'\n"),
|
||||
client_name);
|
||||
- memset(password, 0, sizeof(password));
|
||||
return (FALSE);
|
||||
}
|
||||
|
||||
if ( pwsize == 0) {
|
||||
fprintf(stderr, _("No password given\n"));
|
||||
*zero_password = TRUE;
|
||||
- memset(password, 0, sizeof(password));
|
||||
return (FALSE);
|
||||
}
|
||||
|
||||
code = krb5_get_init_creds_password(context, &creds, client, password,
|
||||
krb5_prompter_posix, NULL, 0, NULL,
|
||||
options);
|
||||
- memset(password, 0, sizeof(password));
|
||||
+ zap(password, sizeof(password));
|
||||
|
||||
|
||||
if (code) {
|
||||
diff --git a/src/lib/gssapi/krb5/iakerb.c b/src/lib/gssapi/krb5/iakerb.c
|
||||
index bb1072fe4..47c161ec9 100644
|
||||
--- a/src/lib/gssapi/krb5/iakerb.c
|
||||
+++ b/src/lib/gssapi/krb5/iakerb.c
|
||||
@@ -262,7 +262,6 @@ iakerb_make_token(iakerb_ctx_id_t ctx,
|
||||
/*
|
||||
* Assemble the IAKERB-HEADER from the realm and cookie
|
||||
*/
|
||||
- memset(&iah, 0, sizeof(iah));
|
||||
iah.target_realm = *realm;
|
||||
iah.cookie = cookie;
|
||||
|
||||
diff --git a/src/lib/kadm5/srv/svr_principal.c b/src/lib/kadm5/srv/svr_principal.c
|
||||
index a59a65e8f..61ce60da7 100644
|
||||
--- a/src/lib/kadm5/srv/svr_principal.c
|
||||
+++ b/src/lib/kadm5/srv/svr_principal.c
|
||||
@@ -2091,14 +2091,8 @@ static int decrypt_key_data(krb5_context context,
|
||||
ret = krb5_dbe_decrypt_key_data(context, NULL, &key_data[i], &keys[i],
|
||||
NULL);
|
||||
if (ret) {
|
||||
- for (; i >= 0; i--) {
|
||||
- if (keys[i].contents) {
|
||||
- memset (keys[i].contents, 0, keys[i].length);
|
||||
- free( keys[i].contents );
|
||||
- }
|
||||
- }
|
||||
-
|
||||
- memset(keys, 0, n_key_data*sizeof(krb5_keyblock));
|
||||
+ for (; i >= 0; i--)
|
||||
+ krb5_free_keyblock_contents(context, &keys[i]);
|
||||
free(keys);
|
||||
return ret;
|
||||
}
|
||||
diff --git a/src/lib/krb5/asn.1/asn1_k_encode.c b/src/lib/krb5/asn.1/asn1_k_encode.c
|
||||
index 29f6b903d..716ceee59 100644
|
||||
--- a/src/lib/krb5/asn.1/asn1_k_encode.c
|
||||
+++ b/src/lib/krb5/asn.1/asn1_k_encode.c
|
||||
@@ -532,7 +532,6 @@ decode_kdc_req_body(const taginfo *t, const unsigned char *asn1, size_t len,
|
||||
if (ret) {
|
||||
free_kdc_req_body(b);
|
||||
free(h.server_realm.data);
|
||||
- memset(&h, 0, sizeof(h));
|
||||
return ret;
|
||||
}
|
||||
b->server->realm = h.server_realm;
|
||||
56
Avoid-allocating-a-register-in-zap-assembly.patch
Normal file
56
Avoid-allocating-a-register-in-zap-assembly.patch
Normal file
|
|
@ -0,0 +1,56 @@
|
|||
From 0326bf3250ea674f424d72cdec3672bcc9918d8f Mon Sep 17 00:00:00 2001
|
||||
From: Andreas Schneider <asn@samba.org>
|
||||
Date: Thu, 3 Jan 2019 17:19:32 +0100
|
||||
Subject: [PATCH] Avoid allocating a register in zap() assembly
|
||||
|
||||
See https://bugs.llvm.org/show_bug.cgi?id=15495
|
||||
|
||||
Also add explicit_bzero() (glibc, FreeBSD) and explicit_memset()
|
||||
(NetBSD) as alternatives.
|
||||
|
||||
[ghudson@mit.edu: added explicit_bzero() and explicit_memset()]
|
||||
|
||||
(cherry picked from commit 7391e8b541061d0f584193b4a53365b64364b0e8)
|
||||
(cherry picked from commit 77b1ce65e7777395cee5a79e4068ff4340fcc680)
|
||||
---
|
||||
src/configure.in | 2 +-
|
||||
src/include/k5-platform.h | 6 +++++-
|
||||
2 files changed, 6 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/src/configure.in b/src/configure.in
|
||||
index 00cb297b8..b6b7b1f21 100644
|
||||
--- a/src/configure.in
|
||||
+++ b/src/configure.in
|
||||
@@ -419,7 +419,7 @@ AC_PROG_LEX
|
||||
AC_C_CONST
|
||||
AC_HEADER_DIRENT
|
||||
AC_FUNC_STRERROR_R
|
||||
-AC_CHECK_FUNCS(strdup setvbuf seteuid setresuid setreuid setegid setresgid setregid setsid flock fchmod chmod strftime strptime geteuid setenv unsetenv getenv gmtime_r localtime_r bswap16 bswap64 mkstemp getusershell access getcwd srand48 srand srandom stat strchr strerror timegm)
|
||||
+AC_CHECK_FUNCS(strdup setvbuf seteuid setresuid setreuid setegid setresgid setregid setsid flock fchmod chmod strftime strptime geteuid setenv unsetenv getenv gmtime_r localtime_r bswap16 bswap64 mkstemp getusershell access getcwd srand48 srand srandom stat strchr strerror timegm explicit_bzero explicit_memset)
|
||||
|
||||
AC_CHECK_FUNC(mkstemp,
|
||||
[MKSTEMP_ST_OBJ=
|
||||
diff --git a/src/include/k5-platform.h b/src/include/k5-platform.h
|
||||
index 3368c7193..6e86129e8 100644
|
||||
--- a/src/include/k5-platform.h
|
||||
+++ b/src/include/k5-platform.h
|
||||
@@ -1023,6 +1023,10 @@ static inline void zap(void *ptr, size_t len)
|
||||
if (len > 0)
|
||||
memset_s(ptr, len, 0, len);
|
||||
}
|
||||
+#elif defined(HAVE_EXPLICIT_BZERO)
|
||||
+# define zap(ptr, len) explicit_bzero(ptr, len)
|
||||
+#elif defined(HAVE_EXPLICIT_MEMSET)
|
||||
+# define zap(ptr, len) explicit_memset(ptr, 0, len)
|
||||
#elif defined(__GNUC__) || defined(__clang__)
|
||||
/*
|
||||
* Use an asm statement which declares a memory clobber to force the memset to
|
||||
@@ -1032,7 +1036,7 @@ static inline void zap(void *ptr, size_t len)
|
||||
{
|
||||
if (len > 0)
|
||||
memset(ptr, 0, len);
|
||||
- __asm__ __volatile__("" : : "r" (ptr) : "memory");
|
||||
+ __asm__ __volatile__("" : : "g" (ptr) : "memory");
|
||||
}
|
||||
#else
|
||||
/*
|
||||
229
Be-more-careful-asking-for-AS-key-in-SPAKE-client.patch
Normal file
229
Be-more-careful-asking-for-AS-key-in-SPAKE-client.patch
Normal file
|
|
@ -0,0 +1,229 @@
|
|||
From 2b9e79d58b28196dba5f7d3ff2f32ca577444ddc Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Sat, 31 Mar 2018 10:43:49 -0400
|
||||
Subject: [PATCH] Be more careful asking for AS key in SPAKE client
|
||||
|
||||
Asking for the AS key too early can result in password prompts in
|
||||
situations where SPAKE won't proceed, such as when the KDC offers only
|
||||
second factor types not supported by the client.
|
||||
|
||||
In spake_prep_questions(), decode the received message and make sure
|
||||
it's a challenge with a supported group and second factor type
|
||||
(SF-NONE at the moment). Save the decoded message and use it in
|
||||
spake_process(). Do not retrieve the AS key at the beginning of
|
||||
spake_process(); instead do so in process_challenge() after checking
|
||||
the challenge group and factor types.
|
||||
|
||||
Move contains_sf_none() earlier in the file so that it can be used by
|
||||
spake_prep_questions() without a prototype.
|
||||
|
||||
ticket: 8659
|
||||
(cherry picked from commit f240f1b0d324312be8aa59ead7cfbe0c329ed064)
|
||||
---
|
||||
src/plugins/preauth/spake/spake_client.c | 111 ++++++++++++++---------
|
||||
1 file changed, 66 insertions(+), 45 deletions(-)
|
||||
|
||||
diff --git a/src/plugins/preauth/spake/spake_client.c b/src/plugins/preauth/spake/spake_client.c
|
||||
index d72bd64aa..47a6ba26c 100644
|
||||
--- a/src/plugins/preauth/spake/spake_client.c
|
||||
+++ b/src/plugins/preauth/spake/spake_client.c
|
||||
@@ -39,12 +39,26 @@
|
||||
#include <krb5/clpreauth_plugin.h>
|
||||
|
||||
typedef struct reqstate_st {
|
||||
+ krb5_pa_spake *msg; /* set in prep_questions, used in process */
|
||||
krb5_keyblock *initial_key;
|
||||
krb5_data *support;
|
||||
krb5_data thash;
|
||||
krb5_data spakeresult;
|
||||
} reqstate;
|
||||
|
||||
+/* Return true if SF-NONE is present in factors. */
|
||||
+static krb5_boolean
|
||||
+contains_sf_none(krb5_spake_factor **factors)
|
||||
+{
|
||||
+ int i;
|
||||
+
|
||||
+ for (i = 0; factors != NULL && factors[i] != NULL; i++) {
|
||||
+ if (factors[i]->type == SPAKE_SF_NONE)
|
||||
+ return TRUE;
|
||||
+ }
|
||||
+ return FALSE;
|
||||
+}
|
||||
+
|
||||
static krb5_error_code
|
||||
spake_init(krb5_context context, krb5_clpreauth_moddata *moddata_out)
|
||||
{
|
||||
@@ -77,6 +91,7 @@ spake_request_fini(krb5_context context, krb5_clpreauth_moddata moddata,
|
||||
{
|
||||
reqstate *st = (reqstate *)modreq;
|
||||
|
||||
+ k5_free_pa_spake(context, st->msg);
|
||||
krb5_free_keyblock(context, st->initial_key);
|
||||
krb5_free_data(context, st->support);
|
||||
krb5_free_data_contents(context, &st->thash);
|
||||
@@ -92,16 +107,42 @@ spake_prep_questions(krb5_context context, krb5_clpreauth_moddata moddata,
|
||||
krb5_data *enc_req, krb5_data *enc_prev_req,
|
||||
krb5_pa_data *pa_data)
|
||||
{
|
||||
+ krb5_error_code ret;
|
||||
+ groupstate *gstate = (groupstate *)moddata;
|
||||
reqstate *st = (reqstate *)modreq;
|
||||
+ krb5_data in_data;
|
||||
+ krb5_spake_challenge *ch;
|
||||
|
||||
if (st == NULL)
|
||||
return ENOMEM;
|
||||
- if (st->initial_key == NULL && pa_data->length > 0)
|
||||
+
|
||||
+ /* We don't need to ask any questions to send a support message. */
|
||||
+ if (pa_data->length == 0)
|
||||
+ return 0;
|
||||
+
|
||||
+ /* Decode the incoming message, replacing any previous one in the request
|
||||
+ * state. If we can't decode it, we have no questions to ask. */
|
||||
+ k5_free_pa_spake(context, st->msg);
|
||||
+ st->msg = NULL;
|
||||
+ in_data = make_data(pa_data->contents, pa_data->length);
|
||||
+ ret = decode_krb5_pa_spake(&in_data, &st->msg);
|
||||
+ if (ret)
|
||||
+ return (ret == ENOMEM) ? ENOMEM : 0;
|
||||
+
|
||||
+ if (st->msg->choice == SPAKE_MSGTYPE_CHALLENGE) {
|
||||
+ ch = &st->msg->u.challenge;
|
||||
+ if (!group_is_permitted(gstate, ch->group))
|
||||
+ return 0;
|
||||
+ /* When second factor support is implemented, we should ask questions
|
||||
+ * based on the factors in the challenge. */
|
||||
+ if (!contains_sf_none(ch->factors))
|
||||
+ return 0;
|
||||
+ /* We will need the AS key to respond to the challenge. */
|
||||
cb->need_as_key(context, rock);
|
||||
-
|
||||
- /* When second-factor is implemented, we should ask questions based on the
|
||||
- * factors in the challenge. */
|
||||
-
|
||||
+ } else if (st->msg->choice == SPAKE_MSGTYPE_ENCDATA) {
|
||||
+ /* When second factor support is implemented, we should decrypt the
|
||||
+ * encdata message and ask questions based on the factor data. */
|
||||
+ }
|
||||
return 0;
|
||||
}
|
||||
|
||||
@@ -136,19 +177,6 @@ send_support(krb5_context context, groupstate *gstate, reqstate *st,
|
||||
return convert_to_padata(support, pa_out);
|
||||
}
|
||||
|
||||
-/* Return true if SF-NONE is present in factors. */
|
||||
-static krb5_boolean
|
||||
-contains_sf_none(krb5_spake_factor **factors)
|
||||
-{
|
||||
- int i;
|
||||
-
|
||||
- for (i = 0; factors != NULL && factors[i] != NULL; i++) {
|
||||
- if (factors[i]->type == SPAKE_SF_NONE)
|
||||
- return TRUE;
|
||||
- }
|
||||
- return FALSE;
|
||||
-}
|
||||
-
|
||||
static krb5_error_code
|
||||
process_challenge(krb5_context context, groupstate *gstate, reqstate *st,
|
||||
krb5_spake_challenge *ch, const krb5_data *der_msg,
|
||||
@@ -157,7 +185,7 @@ process_challenge(krb5_context context, groupstate *gstate, reqstate *st,
|
||||
const krb5_data *der_req, krb5_pa_data ***pa_out)
|
||||
{
|
||||
krb5_error_code ret;
|
||||
- krb5_keyblock *k0 = NULL, *k1 = NULL;
|
||||
+ krb5_keyblock *k0 = NULL, *k1 = NULL, *as_key;
|
||||
krb5_spake_factor factor;
|
||||
krb5_pa_spake msg;
|
||||
krb5_data *der_factor = NULL, *response;
|
||||
@@ -167,8 +195,8 @@ process_challenge(krb5_context context, groupstate *gstate, reqstate *st,
|
||||
|
||||
enc_factor.ciphertext = empty_data();
|
||||
|
||||
- /* Not expected if we already computed the SPAKE result. */
|
||||
- if (st->spakeresult.length != 0)
|
||||
+ /* Not expected if we processed a challenge and didn't reject it. */
|
||||
+ if (st->initial_key != NULL)
|
||||
return KRB5KDC_ERR_PREAUTH_FAILED;
|
||||
|
||||
if (!group_is_permitted(gstate, ch->group)) {
|
||||
@@ -193,6 +221,12 @@ process_challenge(krb5_context context, groupstate *gstate, reqstate *st,
|
||||
if (!contains_sf_none(ch->factors))
|
||||
return KRB5KDC_ERR_PREAUTH_FAILED;
|
||||
|
||||
+ ret = cb->get_as_key(context, rock, &as_key);
|
||||
+ if (ret)
|
||||
+ goto cleanup;
|
||||
+ ret = krb5_copy_keyblock(context, as_key, &st->initial_key);
|
||||
+ if (ret)
|
||||
+ goto cleanup;
|
||||
ret = derive_wbytes(context, ch->group, st->initial_key, &wbytes);
|
||||
if (ret)
|
||||
goto cleanup;
|
||||
@@ -267,7 +301,7 @@ process_encdata(krb5_context context, reqstate *st, krb5_enc_data *enc,
|
||||
krb5_pa_data ***pa_out)
|
||||
{
|
||||
/* Not expected if we haven't sent a response yet. */
|
||||
- if (st->spakeresult.length == 0)
|
||||
+ if (st->initial_key == NULL || st->spakeresult.length == 0)
|
||||
return KRB5KDC_ERR_PREAUTH_FAILED;
|
||||
|
||||
/*
|
||||
@@ -292,9 +326,7 @@ spake_process(krb5_context context, krb5_clpreauth_moddata moddata,
|
||||
krb5_error_code ret;
|
||||
groupstate *gstate = (groupstate *)moddata;
|
||||
reqstate *st = (reqstate *)modreq;
|
||||
- krb5_pa_spake *msg;
|
||||
krb5_data in_data;
|
||||
- krb5_keyblock *as_key;
|
||||
|
||||
if (st == NULL)
|
||||
return ENOMEM;
|
||||
@@ -306,34 +338,23 @@ spake_process(krb5_context context, krb5_clpreauth_moddata moddata,
|
||||
return send_support(context, gstate, st, pa_out);
|
||||
}
|
||||
|
||||
- /* We need the initial reply key to process any non-trivial message. */
|
||||
- if (st->initial_key == NULL) {
|
||||
- ret = cb->get_as_key(context, rock, &as_key);
|
||||
- if (ret)
|
||||
- return ret;
|
||||
- ret = krb5_copy_keyblock(context, as_key, &st->initial_key);
|
||||
- if (ret)
|
||||
- return ret;
|
||||
- }
|
||||
-
|
||||
- in_data = make_data(pa_in->contents, pa_in->length);
|
||||
- ret = decode_krb5_pa_spake(&in_data, &msg);
|
||||
- if (ret)
|
||||
- return ret;
|
||||
-
|
||||
- if (msg->choice == SPAKE_MSGTYPE_CHALLENGE) {
|
||||
- ret = process_challenge(context, gstate, st, &msg->u.challenge,
|
||||
+ if (st->msg == NULL) {
|
||||
+ /* The message failed to decode in spake_prep_questions(). */
|
||||
+ ret = KRB5KDC_ERR_PREAUTH_FAILED;
|
||||
+ } else if (st->msg->choice == SPAKE_MSGTYPE_CHALLENGE) {
|
||||
+ in_data = make_data(pa_in->contents, pa_in->length);
|
||||
+ ret = process_challenge(context, gstate, st, &st->msg->u.challenge,
|
||||
&in_data, cb, rock, prompter, prompter_data,
|
||||
der_req, pa_out);
|
||||
- } else if (msg->choice == SPAKE_MSGTYPE_ENCDATA) {
|
||||
- ret = process_encdata(context, st, &msg->u.encdata, cb, rock, prompter,
|
||||
- prompter_data, der_prev_req, der_req, pa_out);
|
||||
+ } else if (st->msg->choice == SPAKE_MSGTYPE_ENCDATA) {
|
||||
+ ret = process_encdata(context, st, &st->msg->u.encdata, cb, rock,
|
||||
+ prompter, prompter_data, der_prev_req, der_req,
|
||||
+ pa_out);
|
||||
} else {
|
||||
/* Unexpected message type */
|
||||
ret = KRB5KDC_ERR_PREAUTH_FAILED;
|
||||
}
|
||||
|
||||
- k5_free_pa_spake(context, msg);
|
||||
return ret;
|
||||
}
|
||||
|
||||
536
Convert-Python-tests-to-Python-3.patch
Normal file
536
Convert-Python-tests-to-Python-3.patch
Normal file
|
|
@ -0,0 +1,536 @@
|
|||
From 2bc365f12282cdd83a191478b97f4ea0d9aa60dd Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Mon, 19 Feb 2018 21:10:09 -0500
|
||||
Subject: [PATCH] Convert Python tests to Python 3
|
||||
|
||||
Look for python3 in configure.in and verify that we got it. Convert
|
||||
test code to conform to Python 3.
|
||||
|
||||
ticket: 8710 (new)
|
||||
(cherry picked from commit e23d24beacb73581bbf4351250f3955e6fd44361)
|
||||
[rharwood@redhat.com: Context skew due to not having LMDB in tests]
|
||||
---
|
||||
src/Makefile.in | 1 +
|
||||
src/configure.in | 6 ++--
|
||||
src/kadmin/dbutil/t_tdumputil.py | 4 +--
|
||||
src/tests/jsonwalker.py | 16 +++++------
|
||||
src/tests/t_cve-2012-1014.py | 2 +-
|
||||
src/tests/t_cve-2012-1015.py | 2 +-
|
||||
src/tests/t_hostrealm.py | 4 ++-
|
||||
src/tests/t_kdb.py | 11 ++++---
|
||||
src/tests/t_keytab.py | 34 +++++++++++-----------
|
||||
src/tests/t_mkey.py | 6 ++--
|
||||
src/tests/t_otp.py | 7 +++--
|
||||
src/tests/t_tabdump.py | 4 +--
|
||||
src/util/Makefile.in | 1 +
|
||||
src/util/k5test.py | 49 +++++++++++++++++---------------
|
||||
src/util/princflags.py | 25 ++++++++--------
|
||||
15 files changed, 88 insertions(+), 84 deletions(-)
|
||||
|
||||
diff --git a/src/Makefile.in b/src/Makefile.in
|
||||
index 77beff8bc..79b8d5f98 100644
|
||||
--- a/src/Makefile.in
|
||||
+++ b/src/Makefile.in
|
||||
@@ -533,6 +533,7 @@ runenv.py: pyrunenv.vals
|
||||
|
||||
clean-unix::
|
||||
$(RM) runenv.py runenv.pyc pyrunenv.vals
|
||||
+ $(RM) -r __pycache__
|
||||
|
||||
COV_BUILD= cov-build
|
||||
COV_ANALYZE= cov-analyze
|
||||
diff --git a/src/configure.in b/src/configure.in
|
||||
index 3f45784b5..00cb297b8 100644
|
||||
--- a/src/configure.in
|
||||
+++ b/src/configure.in
|
||||
@@ -1098,15 +1098,13 @@ fi
|
||||
AC_SUBST(HAVE_RUNTEST)
|
||||
|
||||
# For Python tests.
|
||||
-AC_CHECK_PROG(PYTHON,python2,python2)
|
||||
+AC_CHECK_PROG(PYTHON,python3,python3)
|
||||
if text x"$PYTHON" = x; then
|
||||
AC_CHECK_PROG(PYTHON,python,python)
|
||||
fi
|
||||
HAVE_PYTHON=no
|
||||
if test x"$PYTHON" != x; then
|
||||
- # k5test.py requires python 2.4 (for the subprocess module).
|
||||
- # Some code needs python 2.5 (for syntax like conditional expressions).
|
||||
- wantver="(sys.hexversion >= 0x2050000 and sys.hexversion < 0x3000000)"
|
||||
+ wantver="(sys.hexversion >= 0x3000000)"
|
||||
if "$PYTHON" -c "import sys; sys.exit(not $wantver and 1 or 0)"; then
|
||||
HAVE_PYTHON=yes
|
||||
fi
|
||||
diff --git a/src/kadmin/dbutil/t_tdumputil.py b/src/kadmin/dbutil/t_tdumputil.py
|
||||
index 52e356533..47b2aa7a3 100755
|
||||
--- a/src/kadmin/dbutil/t_tdumputil.py
|
||||
+++ b/src/kadmin/dbutil/t_tdumputil.py
|
||||
@@ -6,8 +6,8 @@ realm = K5Realm(create_kdb=False)
|
||||
def compare(s, expected, msg):
|
||||
if s == expected:
|
||||
return
|
||||
- print 'expected:', repr(expected)
|
||||
- print 'got:', repr(s)
|
||||
+ print('expected:', repr(expected))
|
||||
+ print('got:', repr(s))
|
||||
fail(msg)
|
||||
|
||||
out = realm.run(['./t_tdumputil', '2', 'field1', 'field2',
|
||||
diff --git a/src/tests/jsonwalker.py b/src/tests/jsonwalker.py
|
||||
index 942ca2db7..7a0675e08 100644
|
||||
--- a/src/tests/jsonwalker.py
|
||||
+++ b/src/tests/jsonwalker.py
|
||||
@@ -2,8 +2,8 @@ import sys
|
||||
try:
|
||||
import cjson
|
||||
except ImportError:
|
||||
- print "Warning: skipping audit log verification because the cjson module" \
|
||||
- " is unavailable"
|
||||
+ print("Warning: skipping audit log verification because the cjson module" \
|
||||
+ " is unavailable")
|
||||
sys.exit(0)
|
||||
from collections import defaultdict
|
||||
from optparse import OptionParser
|
||||
@@ -22,10 +22,10 @@ class Parser(object):
|
||||
result = self.parse(logs)
|
||||
if len(result) != len(self.defaults):
|
||||
diff = set(self.defaults.keys()).difference(result.keys())
|
||||
- print 'Test failed.'
|
||||
- print 'The following attributes were not set:'
|
||||
+ print('Test failed.')
|
||||
+ print('The following attributes were not set:')
|
||||
for it in diff:
|
||||
- print it
|
||||
+ print(it)
|
||||
sys.exit(1)
|
||||
|
||||
def flatten(self, defaults):
|
||||
@@ -42,7 +42,7 @@ class Parser(object):
|
||||
result = dict()
|
||||
for path,value in self._walk(defaults):
|
||||
if path in result:
|
||||
- print 'Warning: attribute path %s already exists' % path
|
||||
+ print('Warning: attribute path %s already exists' % path)
|
||||
result[path] = value
|
||||
|
||||
return result
|
||||
@@ -60,7 +60,7 @@ class Parser(object):
|
||||
if v is not None:
|
||||
dv = self.DEFAULTS[type(v)]
|
||||
else:
|
||||
- print 'Warning: attribute %s is set to None' % a
|
||||
+ print('Warning: attribute %s is set to None' % a)
|
||||
continue
|
||||
# by now we have default value
|
||||
if v != dv:
|
||||
@@ -96,7 +96,7 @@ if __name__ == '__main__':
|
||||
content.append(cjson.decode(l.rstrip()))
|
||||
f.close()
|
||||
else:
|
||||
- print 'Input file in jason format is required'
|
||||
+ print('Input file in jason format is required')
|
||||
exit()
|
||||
|
||||
defaults = None
|
||||
diff --git a/src/tests/t_cve-2012-1014.py b/src/tests/t_cve-2012-1014.py
|
||||
index dcff95f6e..8447e0ee7 100755
|
||||
--- a/src/tests/t_cve-2012-1014.py
|
||||
+++ b/src/tests/t_cve-2012-1014.py
|
||||
@@ -20,7 +20,7 @@ x2 = base64.b16decode('A44F304DA007030500FEDCBA90A10E30' +
|
||||
'01')
|
||||
|
||||
for x in range(11, 128):
|
||||
- s.sendto(''.join([x1, chr(x), x2]), a)
|
||||
+ s.sendto(x1 + bytes([x]) + x2, a)
|
||||
|
||||
# Make sure kinit still works.
|
||||
|
||||
diff --git a/src/tests/t_cve-2012-1015.py b/src/tests/t_cve-2012-1015.py
|
||||
index 28b1e619b..ae5678cac 100755
|
||||
--- a/src/tests/t_cve-2012-1015.py
|
||||
+++ b/src/tests/t_cve-2012-1015.py
|
||||
@@ -27,7 +27,7 @@ x1 = base64.b16decode('6A81A030819DA103020105A20302010A' +
|
||||
x2 = base64.b16decode('A8083006020106020112')
|
||||
|
||||
for x in range(0, 128):
|
||||
- s.sendto(''.join([x1, chr(x), x2]), a)
|
||||
+ s.sendto(x1 + bytes([x]) + x2, a)
|
||||
|
||||
# Make sure kinit still works.
|
||||
|
||||
diff --git a/src/tests/t_hostrealm.py b/src/tests/t_hostrealm.py
|
||||
index 256ba2a38..beea6f3bc 100755
|
||||
--- a/src/tests/t_hostrealm.py
|
||||
+++ b/src/tests/t_hostrealm.py
|
||||
@@ -119,7 +119,9 @@ testd(realm, 'KRBTEST.COM', 'default_realm profile', env=notest2)
|
||||
# see the first. Remove the profile default_realm setting to expose
|
||||
# this behavior.
|
||||
remove_default = {'libdefaults': {'default_realm': None}}
|
||||
-nodefault_conf = dict(disable_conf.items() + remove_default.items())
|
||||
+# Python 3.5+: nodefault_conf = {**disable_conf, **remove_default}
|
||||
+nodefault_conf = dict(list(disable_conf.items()) +
|
||||
+ list(remove_default.items()))
|
||||
nodefault = realm.special_env('nodefault', False, krb5_conf=nodefault_conf)
|
||||
testd(realm, 'one', 'default_realm test1', env=nodefault)
|
||||
|
||||
diff --git a/src/tests/t_kdb.py b/src/tests/t_kdb.py
|
||||
index 983cd93c8..42237f7a1 100755
|
||||
--- a/src/tests/t_kdb.py
|
||||
+++ b/src/tests/t_kdb.py
|
||||
@@ -1,6 +1,5 @@
|
||||
from k5test import *
|
||||
import time
|
||||
-from itertools import imap
|
||||
|
||||
# Run kdbtest against the BDB module.
|
||||
realm = K5Realm(create_kdb=False)
|
||||
@@ -51,7 +50,7 @@ else:
|
||||
def slap_add(ldif):
|
||||
proc = subprocess.Popen([slapadd, '-b', 'cn=config', '-F', slapd_conf],
|
||||
stdin=subprocess.PIPE, stdout=subprocess.PIPE,
|
||||
- stderr=subprocess.STDOUT)
|
||||
+ stderr=subprocess.STDOUT, universal_newlines=True)
|
||||
(out, dummy) = proc.communicate(ldif)
|
||||
output(out)
|
||||
return proc.wait()
|
||||
@@ -98,7 +97,7 @@ if slap_add('include: file://%s\n' % schema) != 0:
|
||||
ldap_homes = ['/etc/ldap', '/etc/openldap', '/usr/local/etc/openldap',
|
||||
'/usr/local/etc/ldap']
|
||||
local_schema_path = '/schema/core.ldif'
|
||||
-core_schema = next((i for i in imap(lambda x:x+local_schema_path, ldap_homes)
|
||||
+core_schema = next((i for i in map(lambda x:x+local_schema_path, ldap_homes)
|
||||
if os.path.isfile(i)), None)
|
||||
if core_schema:
|
||||
if slap_add('include: file://%s\n' % core_schema) != 0:
|
||||
@@ -114,7 +113,7 @@ atexit.register(kill_slapd)
|
||||
|
||||
out = open(slapd_out, 'w')
|
||||
subprocess.call([slapd, '-h', ldap_uri, '-F', slapd_conf], stdout=out,
|
||||
- stderr=out)
|
||||
+ stderr=out, universal_newlines=True)
|
||||
out.close()
|
||||
pidf = open(slapd_pidfile, 'r')
|
||||
slapd_pid = int(pidf.read())
|
||||
@@ -158,7 +157,7 @@ def ldap_search(args):
|
||||
proc = subprocess.Popen([ldapsearch, '-H', ldap_uri, '-b', top_dn,
|
||||
'-D', admin_dn, '-w', admin_pw, args],
|
||||
stdin=subprocess.PIPE, stdout=subprocess.PIPE,
|
||||
- stderr=subprocess.STDOUT)
|
||||
+ stderr=subprocess.STDOUT, universal_newlines=True)
|
||||
(out, dummy) = proc.communicate()
|
||||
return out
|
||||
|
||||
@@ -166,7 +165,7 @@ def ldap_modify(ldif, args=[]):
|
||||
proc = subprocess.Popen([ldapmodify, '-H', ldap_uri, '-D', admin_dn,
|
||||
'-x', '-w', admin_pw] + args,
|
||||
stdin=subprocess.PIPE, stdout=subprocess.PIPE,
|
||||
- stderr=subprocess.STDOUT)
|
||||
+ stderr=subprocess.STDOUT, universal_newlines=True)
|
||||
(out, dummy) = proc.communicate(ldif)
|
||||
output(out)
|
||||
|
||||
diff --git a/src/tests/t_keytab.py b/src/tests/t_keytab.py
|
||||
index 228c36334..8a17ae2eb 100755
|
||||
--- a/src/tests/t_keytab.py
|
||||
+++ b/src/tests/t_keytab.py
|
||||
@@ -90,36 +90,36 @@ test_key_rotate(realm, princ, 2)
|
||||
|
||||
# Test that klist -k can read a keytab entry without a 32-bit kvno and
|
||||
# reports the 8-bit key version.
|
||||
-record = '\x00\x01' # principal component count
|
||||
-record += '\x00\x0bKRBTEST.COM' # realm
|
||||
-record += '\x00\x04user' # principal component
|
||||
-record += '\x00\x00\x00\x01' # name type (NT-PRINCIPAL)
|
||||
-record += '\x54\xf7\x4d\x35' # timestamp
|
||||
-record += '\x02' # key version
|
||||
-record += '\x00\x12' # enctype
|
||||
-record += '\x00\x20' # key length
|
||||
-record += '\x00' * 32 # key bytes
|
||||
-f = open(realm.keytab, 'w')
|
||||
-f.write('\x05\x02\x00\x00\x00' + chr(len(record)))
|
||||
+record = b'\x00\x01' # principal component count
|
||||
+record += b'\x00\x0bKRBTEST.COM' # realm
|
||||
+record += b'\x00\x04user' # principal component
|
||||
+record += b'\x00\x00\x00\x01' # name type (NT-PRINCIPAL)
|
||||
+record += b'\x54\xf7\x4d\x35' # timestamp
|
||||
+record += b'\x02' # key version
|
||||
+record += b'\x00\x12' # enctype
|
||||
+record += b'\x00\x20' # key length
|
||||
+record += b'\x00' * 32 # key bytes
|
||||
+f = open(realm.keytab, 'wb')
|
||||
+f.write(b'\x05\x02\x00\x00\x00' + bytes([len(record)]))
|
||||
f.write(record)
|
||||
f.close()
|
||||
msg = ' 2 %s' % realm.user_princ
|
||||
out = realm.run([klist, '-k'], expected_msg=msg)
|
||||
|
||||
# Make sure zero-fill isn't treated as a 32-bit kvno.
|
||||
-f = open(realm.keytab, 'w')
|
||||
-f.write('\x05\x02\x00\x00\x00' + chr(len(record) + 4))
|
||||
+f = open(realm.keytab, 'wb')
|
||||
+f.write(b'\x05\x02\x00\x00\x00' + bytes([len(record) + 4]))
|
||||
f.write(record)
|
||||
-f.write('\x00\x00\x00\x00')
|
||||
+f.write(b'\x00\x00\x00\x00')
|
||||
f.close()
|
||||
msg = ' 2 %s' % realm.user_princ
|
||||
out = realm.run([klist, '-k'], expected_msg=msg)
|
||||
|
||||
# Make sure a hand-crafted 32-bit kvno is recognized.
|
||||
-f = open(realm.keytab, 'w')
|
||||
-f.write('\x05\x02\x00\x00\x00' + chr(len(record) + 4))
|
||||
+f = open(realm.keytab, 'wb')
|
||||
+f.write(b'\x05\x02\x00\x00\x00' + bytes([len(record) + 4]))
|
||||
f.write(record)
|
||||
-f.write('\x00\x00\x00\x03')
|
||||
+f.write(b'\x00\x00\x00\x03')
|
||||
f.close()
|
||||
msg = ' 3 %s' % realm.user_princ
|
||||
out = realm.run([klist, '-k'], expected_msg=msg)
|
||||
diff --git a/src/tests/t_mkey.py b/src/tests/t_mkey.py
|
||||
index 48a533059..cbc830235 100755
|
||||
--- a/src/tests/t_mkey.py
|
||||
+++ b/src/tests/t_mkey.py
|
||||
@@ -296,10 +296,10 @@ realm.stop()
|
||||
# 2. list_mkeys displays the same list as for a post-1.7 KDB.
|
||||
dumpfile = os.path.join(srctop, 'tests', 'dumpfiles', 'dump.16')
|
||||
os.remove(stash_file)
|
||||
-f = open(stash_file, 'w')
|
||||
+f = open(stash_file, 'wb')
|
||||
f.write(struct.pack('=HL24s', 16, 24,
|
||||
- '\xF8\x3E\xFB\xBA\x6D\x80\xD9\x54\xE5\x5D\xF2\xE0'
|
||||
- '\x94\xAD\x6D\x86\xB5\x16\x37\xEC\x7C\x8A\xBC\x86'))
|
||||
+ b'\xF8\x3E\xFB\xBA\x6D\x80\xD9\x54\xE5\x5D\xF2\xE0'
|
||||
+ b'\x94\xAD\x6D\x86\xB5\x16\x37\xEC\x7C\x8A\xBC\x86'))
|
||||
f.close()
|
||||
realm.run([kdb5_util, 'load', dumpfile])
|
||||
nprincs = len(realm.run([kadminl, 'listprincs']).splitlines())
|
||||
diff --git a/src/tests/t_otp.py b/src/tests/t_otp.py
|
||||
index 0fd35d576..617a8ecf5 100755
|
||||
--- a/src/tests/t_otp.py
|
||||
+++ b/src/tests/t_otp.py
|
||||
@@ -29,8 +29,8 @@
|
||||
#
|
||||
|
||||
from k5test import *
|
||||
-from Queue import Empty
|
||||
-import StringIO
|
||||
+from queue import Empty
|
||||
+from io import StringIO
|
||||
import struct
|
||||
|
||||
try:
|
||||
@@ -120,7 +120,8 @@ class UnixRadiusDaemon(RadiusDaemon):
|
||||
sock.listen(1)
|
||||
return (sock, addr)
|
||||
|
||||
- def recvRequest(self, (sock, addr)):
|
||||
+ def recvRequest(self, sock_and_addr):
|
||||
+ sock, addr = sock_and_addr
|
||||
conn = sock.accept()[0]
|
||||
sock.close()
|
||||
os.remove(addr)
|
||||
diff --git a/src/tests/t_tabdump.py b/src/tests/t_tabdump.py
|
||||
index 2a86136dd..49531bf49 100755
|
||||
--- a/src/tests/t_tabdump.py
|
||||
+++ b/src/tests/t_tabdump.py
|
||||
@@ -1,10 +1,10 @@
|
||||
from k5test import *
|
||||
|
||||
import csv
|
||||
-import StringIO
|
||||
+from io import StringIO
|
||||
|
||||
def tab_csv(s):
|
||||
- io = StringIO.StringIO(s)
|
||||
+ io = StringIO(s)
|
||||
return list(csv.DictReader(io, dialect=csv.excel_tab))
|
||||
|
||||
|
||||
diff --git a/src/util/Makefile.in b/src/util/Makefile.in
|
||||
index 2611581c1..19a6bd312 100644
|
||||
--- a/src/util/Makefile.in
|
||||
+++ b/src/util/Makefile.in
|
||||
@@ -26,3 +26,4 @@ install:
|
||||
|
||||
clean-unix::
|
||||
$(RM) *.pyc
|
||||
+ $(RM) -r __pycache__
|
||||
diff --git a/src/util/k5test.py b/src/util/k5test.py
|
||||
index bc32877a7..81fac3063 100644
|
||||
--- a/src/util/k5test.py
|
||||
+++ b/src/util/k5test.py
|
||||
@@ -380,16 +380,16 @@ import imp
|
||||
def fail(msg):
|
||||
"""Print a message and exit with failure."""
|
||||
global _current_pass
|
||||
- print "*** Failure:", msg
|
||||
+ print("*** Failure:", msg)
|
||||
if _last_mark:
|
||||
- print "*** Last mark: %s" % _last_mark
|
||||
+ print("*** Last mark: %s" % _last_mark)
|
||||
if _last_cmd:
|
||||
- print "*** Last command (#%d): %s" % (_cmd_index - 1, _last_cmd)
|
||||
+ print("*** Last command (#%d): %s" % (_cmd_index - 1, _last_cmd))
|
||||
if _last_cmd_output:
|
||||
- print "*** Output of last command:"
|
||||
+ print("*** Output of last command:")
|
||||
sys.stdout.write(_last_cmd_output)
|
||||
if _current_pass:
|
||||
- print "*** Failed in test pass:", _current_pass
|
||||
+ print("*** Failed in test pass:", _current_pass)
|
||||
sys.exit(1)
|
||||
|
||||
|
||||
@@ -465,15 +465,16 @@ def _onexit():
|
||||
if not verbose:
|
||||
testlogfile = os.path.join(os.getcwd(), 'testlog')
|
||||
utildir = os.path.join(srctop, 'util')
|
||||
- print 'For details, see: %s' % testlogfile
|
||||
- print 'Or re-run this test script with the -v flag:'
|
||||
- print ' cd %s' % os.getcwd()
|
||||
- print ' PYTHONPATH=%s %s %s -v' % \
|
||||
- (utildir, sys.executable, sys.argv[0])
|
||||
- print
|
||||
- print 'Use --debug=NUM to run a command under a debugger. Use'
|
||||
- print '--stop-after=NUM to stop after a daemon is started in order to'
|
||||
- print 'attach to it with a debugger. Use --help to see other options.'
|
||||
+ print('For details, see: %s' % testlogfile)
|
||||
+ print('Or re-run this test script with the -v flag:')
|
||||
+ print(' cd %s' % os.getcwd())
|
||||
+ print(' PYTHONPATH=%s %s %s -v' %
|
||||
+ (utildir, sys.executable, sys.argv[0]))
|
||||
+ print()
|
||||
+ print('Use --debug=NUM to run a command under a debugger. Use')
|
||||
+ print('--stop-after=NUM to stop after a daemon is started in order to')
|
||||
+ print('attach to it with a debugger. Use --help to see other')
|
||||
+ print('options.')
|
||||
|
||||
|
||||
def _onsigint(signum, frame):
|
||||
@@ -523,8 +524,8 @@ def _get_hostname():
|
||||
hostname = socket.gethostname()
|
||||
try:
|
||||
ai = socket.getaddrinfo(hostname, None, 0, 0, 0, socket.AI_CANONNAME)
|
||||
- except socket.gaierror, (error, errstr):
|
||||
- fail('Local hostname "%s" does not resolve: %s.' % (hostname, errstr))
|
||||
+ except socket.gaierror as e:
|
||||
+ fail('Local hostname "%s" does not resolve: %s.' % (hostname, e[1]))
|
||||
(family, socktype, proto, canonname, sockaddr) = ai[0]
|
||||
try:
|
||||
name = socket.getnameinfo(sockaddr, socket.NI_NAMEREQD)
|
||||
@@ -594,7 +595,7 @@ def _match_cmdnum(cmdnum, ind):
|
||||
def _build_env():
|
||||
global buildtop, runenv
|
||||
env = os.environ.copy()
|
||||
- for (k, v) in runenv.env.iteritems():
|
||||
+ for (k, v) in runenv.env.items():
|
||||
if v.find('./') == 0:
|
||||
env[k] = os.path.join(buildtop, v)
|
||||
else:
|
||||
@@ -704,7 +705,8 @@ def _run_cmd(args, env, input=None, expected_code=0, expected_msg=None,
|
||||
|
||||
# Run the command and log the result, folding stderr into stdout.
|
||||
proc = subprocess.Popen(args, stdin=infile, stdout=subprocess.PIPE,
|
||||
- stderr=subprocess.STDOUT, env=env)
|
||||
+ stderr=subprocess.STDOUT, env=env,
|
||||
+ universal_newlines=True)
|
||||
(outdata, dummy_errdata) = proc.communicate(input)
|
||||
_last_cmd_output = outdata
|
||||
code = proc.returncode
|
||||
@@ -734,10 +736,10 @@ def _debug_cmd(args, env, input):
|
||||
(_cmd_index, _shell_equiv(args)), True)
|
||||
if input:
|
||||
print
|
||||
- print '*** Enter the following input when appropriate:'
|
||||
- print
|
||||
- print input
|
||||
- print
|
||||
+ print('*** Enter the following input when appropriate:')
|
||||
+ print()
|
||||
+ print(input)
|
||||
+ print()
|
||||
code = subprocess.call(args, env=env)
|
||||
output('*** [%d] Completed in debugger with return code %d\n' %
|
||||
(_cmd_index, code))
|
||||
@@ -765,7 +767,8 @@ def _start_daemon(args, env, sentinel):
|
||||
|
||||
# Start the daemon and look for the sentinel in stdout or stderr.
|
||||
proc = subprocess.Popen(args, stdin=null_input, stdout=subprocess.PIPE,
|
||||
- stderr=subprocess.STDOUT, env=env)
|
||||
+ stderr=subprocess.STDOUT, env=env,
|
||||
+ universal_newlines=True)
|
||||
_last_cmd_output = ''
|
||||
while True:
|
||||
line = proc.stdout.readline()
|
||||
diff --git a/src/util/princflags.py b/src/util/princflags.py
|
||||
index f568dd2f1..f645e86e4 100644
|
||||
--- a/src/util/princflags.py
|
||||
+++ b/src/util/princflags.py
|
||||
@@ -1,5 +1,4 @@
|
||||
import re
|
||||
-import string
|
||||
|
||||
# Module for translating KDB principal flags between string and
|
||||
# integer forms.
|
||||
@@ -81,7 +80,7 @@ _prefixlen = len(_prefix)
|
||||
_flagnames = {}
|
||||
|
||||
# Translation table to map hyphens to underscores
|
||||
-_squash = string.maketrans('-', '_')
|
||||
+_squash = str.maketrans('-', '_')
|
||||
|
||||
# Combined input-to-flag lookup table, to be filled in by
|
||||
# _setup_tables()
|
||||
@@ -176,7 +175,7 @@ def flagnum2str(n):
|
||||
# Return a list of flag names from a flag word.
|
||||
def flags2namelist(flags):
|
||||
a = []
|
||||
- for n in xrange(32):
|
||||
+ for n in range(32):
|
||||
if flags & (1 << n):
|
||||
a.append(flagnum2str(n))
|
||||
return a
|
||||
@@ -225,21 +224,21 @@ def speclist2mask(s):
|
||||
|
||||
# Print C table of input flag specifiers for lib/kadm5/str_conv.c.
|
||||
def _print_ftbl():
|
||||
- print 'static const struct flag_table_row ftbl[] = {'
|
||||
- a = sorted(pflags.items(), key=lambda (k, v): (v.flag, -v.invert, k))
|
||||
+ print('static const struct flag_table_row ftbl[] = {')
|
||||
+ a = sorted(pflags.items(), key=lambda k, v: (v.flag, -v.invert, k))
|
||||
for k, v in a:
|
||||
s1 = ' {"%s",' % k
|
||||
s2 = '%-31s KRB5_KDB_%s,' % (s1, v.flagname())
|
||||
- print '%-63s %d},' % (s2, 1 if v.invert else 0)
|
||||
+ print('%-63s %d},' % (s2, 1 if v.invert else 0))
|
||||
|
||||
- print '};'
|
||||
- print '#define NFTBL (sizeof(ftbl) / sizeof(ftbl[0]))'
|
||||
+ print('};')
|
||||
+ print('#define NFTBL (sizeof(ftbl) / sizeof(ftbl[0]))')
|
||||
|
||||
|
||||
# Print C table of output flag names for lib/kadm5/str_conv.c.
|
||||
def _print_outflags():
|
||||
- print 'static const char *outflags[] = {'
|
||||
- for i in xrange(32):
|
||||
+ print('static const char *outflags[] = {')
|
||||
+ for i in range(32):
|
||||
flag = 1 << i
|
||||
if flag > max(_flagnames.keys()):
|
||||
break
|
||||
@@ -247,10 +246,10 @@ def _print_outflags():
|
||||
s = ' "%s",' % _flagnames[flag]
|
||||
except KeyError:
|
||||
s = ' NULL,'
|
||||
- print '%-32s/* 0x%08x */' % (s, flag)
|
||||
+ print('%-32s/* 0x%08x */' % (s, flag))
|
||||
|
||||
- print '};'
|
||||
- print '#define NOUTFLAGS (sizeof(outflags) / sizeof(outflags[0]))'
|
||||
+ print('};')
|
||||
+ print('#define NOUTFLAGS (sizeof(outflags) / sizeof(outflags[0]))')
|
||||
|
||||
|
||||
# Print out C tables to insert into lib/kadm5/str_conv.c.
|
||||
2950
Eliminate-preprocessor-disabled-dead-code.patch
Normal file
2950
Eliminate-preprocessor-disabled-dead-code.patch
Normal file
File diff suppressed because it is too large
Load diff
31
Exit-with-status-0-from-kadmind.patch
Normal file
31
Exit-with-status-0-from-kadmind.patch
Normal file
|
|
@ -0,0 +1,31 @@
|
|||
From 3bfe632c7011c335362d78356232507d9ee26f73 Mon Sep 17 00:00:00 2001
|
||||
From: Robbie Harwood <rharwood@redhat.com>
|
||||
Date: Wed, 14 Mar 2018 14:31:22 -0400
|
||||
Subject: [PATCH] Exit with status 0 from kadmind
|
||||
|
||||
Typically, 0 denotes successful exit. In particular, init systems
|
||||
will complain if another different value is returned. This presents a
|
||||
problem for automated installation jobs which want to restart kadmind.
|
||||
|
||||
`service kadmin stop` typically sends SIGTERM, which is caught by
|
||||
verto and passed to our handler. Besides cleanup, we then call
|
||||
verto_break(), which causes the verto_run() event loop to return. The
|
||||
weird return code has been present since the addition of the kadmin
|
||||
code, which used a similar event model for signals.
|
||||
|
||||
(cherry picked from commit f970ad412aca36f8a7d3addb1cd4026ed22e5592)
|
||||
---
|
||||
src/kadmin/server/ovsec_kadmd.c | 2 +-
|
||||
1 file changed, 1 insertion(+), 1 deletion(-)
|
||||
|
||||
diff --git a/src/kadmin/server/ovsec_kadmd.c b/src/kadmin/server/ovsec_kadmd.c
|
||||
index aac4d4ffd..0a28b2384 100644
|
||||
--- a/src/kadmin/server/ovsec_kadmd.c
|
||||
+++ b/src/kadmin/server/ovsec_kadmd.c
|
||||
@@ -559,5 +559,5 @@ main(int argc, char *argv[])
|
||||
|
||||
krb5_klog_close(context);
|
||||
krb5_free_context(context);
|
||||
- exit(2);
|
||||
+ exit(0);
|
||||
}
|
||||
816
Explicitly-look-for-python2-in-configure.in.patch
Normal file
816
Explicitly-look-for-python2-in-configure.in.patch
Normal file
|
|
@ -0,0 +1,816 @@
|
|||
From 1d0c0db7755076834519fd02c271a78bbf26bb19 Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Tue, 3 Jul 2018 01:20:50 -0400
|
||||
Subject: [PATCH] Explicitly look for python2 in configure.in
|
||||
|
||||
The executable "python" has traditionally been Python 2, but is
|
||||
becoming more ambiguous as operating systems transition towards Python
|
||||
3. Look for "python2" in the path in preference to "python", and
|
||||
check that what we found isn't Python 3.
|
||||
|
||||
Remove the "#!/usr/bin/python" headers at the start of Python test
|
||||
scripts since we run them explicitly under python, not as executables.
|
||||
Execute paste-kdcproxy.py via sys.executable in t_proxy.py so that it
|
||||
doesn't need a #!/usr/bin/python header.
|
||||
|
||||
ticket: 8709 (new)
|
||||
(cherry picked from commit 2bd410ecdb366083fe9b4e5f6ac4b741b624230b)
|
||||
---
|
||||
src/appl/gss-sample/t_gss_sample.py | 2 --
|
||||
src/appl/user_user/t_user2user.py | 1 -
|
||||
src/configure.in | 9 ++++++---
|
||||
src/kadmin/dbutil/t_tdumputil.py | 2 --
|
||||
src/kdc/t_bigreply.py | 1 -
|
||||
src/kdc/t_emptytgt.py | 1 -
|
||||
src/kdc/t_workers.py | 1 -
|
||||
src/lib/kdb/t_stringattr.py | 1 -
|
||||
src/lib/krad/t_daemon.py | 2 --
|
||||
src/lib/krb5/ccache/t_cccol.py | 1 -
|
||||
src/lib/krb5/krb/t_expire_warn.py | 2 --
|
||||
src/lib/krb5/krb/t_in_ccache_patypes.py | 2 --
|
||||
src/lib/krb5/krb/t_vfy_increds.py | 2 --
|
||||
src/lib/krb5/os/t_discover_uri.py | 1 -
|
||||
src/tests/gssapi/t_authind.py | 1 -
|
||||
src/tests/gssapi/t_ccselect.py | 2 --
|
||||
src/tests/gssapi/t_client_keytab.py | 1 -
|
||||
src/tests/gssapi/t_enctypes.py | 1 -
|
||||
src/tests/gssapi/t_export_cred.py | 1 -
|
||||
src/tests/gssapi/t_gssapi.py | 1 -
|
||||
src/tests/gssapi/t_s4u.py | 1 -
|
||||
src/tests/jsonwalker.py | 2 --
|
||||
src/tests/t_audit.py | 1 -
|
||||
src/tests/t_authdata.py | 1 -
|
||||
src/tests/t_bogus_kdc_req.py | 2 --
|
||||
src/tests/t_ccache.py | 2 --
|
||||
src/tests/t_certauth.py | 1 -
|
||||
src/tests/t_changepw.py | 1 -
|
||||
src/tests/t_crossrealm.py | 2 --
|
||||
src/tests/t_cve-2012-1014.py | 2 --
|
||||
src/tests/t_cve-2012-1015.py | 2 --
|
||||
src/tests/t_cve-2013-1416.py | 2 --
|
||||
src/tests/t_cve-2013-1417.py | 2 --
|
||||
src/tests/t_dump.py | 1 -
|
||||
src/tests/t_errmsg.py | 1 -
|
||||
src/tests/t_etype_info.py | 1 -
|
||||
src/tests/t_general.py | 1 -
|
||||
src/tests/t_hooks.py | 1 -
|
||||
src/tests/t_hostrealm.py | 1 -
|
||||
src/tests/t_iprop.py | 2 --
|
||||
src/tests/t_kadm5_auth.py | 1 -
|
||||
src/tests/t_kadm5_hook.py | 1 -
|
||||
src/tests/t_kadmin_acl.py | 1 -
|
||||
src/tests/t_kadmin_parsing.py | 1 -
|
||||
src/tests/t_kdb.py | 1 -
|
||||
src/tests/t_kdb_locking.py | 2 --
|
||||
src/tests/t_kdc_log.py | 2 --
|
||||
src/tests/t_kdcpolicy.py | 1 -
|
||||
src/tests/t_keydata.py | 1 -
|
||||
src/tests/t_keyrollover.py | 1 -
|
||||
src/tests/t_keytab.py | 1 -
|
||||
src/tests/t_kprop.py | 1 -
|
||||
src/tests/t_localauth.py | 1 -
|
||||
src/tests/t_mkey.py | 1 -
|
||||
src/tests/t_otp.py | 2 --
|
||||
src/tests/t_pkinit.py | 1 -
|
||||
src/tests/t_policy.py | 1 -
|
||||
src/tests/t_preauth.py | 1 -
|
||||
src/tests/t_princflags.py | 1 -
|
||||
src/tests/t_proxy.py | 4 ++--
|
||||
src/tests/t_pwqual.py | 1 -
|
||||
src/tests/t_rdreq.py | 1 -
|
||||
src/tests/t_referral.py | 1 -
|
||||
src/tests/t_renew.py | 1 -
|
||||
src/tests/t_renprinc.py | 2 --
|
||||
src/tests/t_salt.py | 1 -
|
||||
src/tests/t_sesskeynego.py | 1 -
|
||||
src/tests/t_skew.py | 1 -
|
||||
src/tests/t_sn2princ.py | 1 -
|
||||
src/tests/t_spake.py | 1 -
|
||||
src/tests/t_stringattr.py | 2 --
|
||||
src/tests/t_tabdump.py | 1 -
|
||||
src/tests/t_unlockiter.py | 1 -
|
||||
src/tests/t_y2038.py | 1 -
|
||||
src/util/paste-kdcproxy.py | 1 -
|
||||
75 files changed, 8 insertions(+), 99 deletions(-)
|
||||
|
||||
diff --git a/src/appl/gss-sample/t_gss_sample.py b/src/appl/gss-sample/t_gss_sample.py
|
||||
index 0299e4590..2f537823a 100755
|
||||
--- a/src/appl/gss-sample/t_gss_sample.py
|
||||
+++ b/src/appl/gss-sample/t_gss_sample.py
|
||||
@@ -1,5 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
-
|
||||
# Copyright (C) 2010 by the Massachusetts Institute of Technology.
|
||||
# All rights reserved.
|
||||
#
|
||||
diff --git a/src/appl/user_user/t_user2user.py b/src/appl/user_user/t_user2user.py
|
||||
index 2a7d03f8d..2c054f181 100755
|
||||
--- a/src/appl/user_user/t_user2user.py
|
||||
+++ b/src/appl/user_user/t_user2user.py
|
||||
@@ -1,4 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
from k5test import *
|
||||
|
||||
# If uuserver is not compiled under -DDEBUG, then set to 0
|
||||
diff --git a/src/configure.in b/src/configure.in
|
||||
index 08c63beca..3f45784b5 100644
|
||||
--- a/src/configure.in
|
||||
+++ b/src/configure.in
|
||||
@@ -1098,13 +1098,16 @@ fi
|
||||
AC_SUBST(HAVE_RUNTEST)
|
||||
|
||||
# For Python tests.
|
||||
-AC_CHECK_PROG(PYTHON,python,python)
|
||||
+AC_CHECK_PROG(PYTHON,python2,python2)
|
||||
+if text x"$PYTHON" = x; then
|
||||
+ AC_CHECK_PROG(PYTHON,python,python)
|
||||
+fi
|
||||
HAVE_PYTHON=no
|
||||
if test x"$PYTHON" != x; then
|
||||
# k5test.py requires python 2.4 (for the subprocess module).
|
||||
# Some code needs python 2.5 (for syntax like conditional expressions).
|
||||
- vercheck="import sys;sys.exit((sys.hexversion < 0x2050000) and 1 or 0)"
|
||||
- if python -c "$vercheck"; then
|
||||
+ wantver="(sys.hexversion >= 0x2050000 and sys.hexversion < 0x3000000)"
|
||||
+ if "$PYTHON" -c "import sys; sys.exit(not $wantver and 1 or 0)"; then
|
||||
HAVE_PYTHON=yes
|
||||
fi
|
||||
fi
|
||||
diff --git a/src/kadmin/dbutil/t_tdumputil.py b/src/kadmin/dbutil/t_tdumputil.py
|
||||
index 5d7ac38d2..52e356533 100755
|
||||
--- a/src/kadmin/dbutil/t_tdumputil.py
|
||||
+++ b/src/kadmin/dbutil/t_tdumputil.py
|
||||
@@ -1,5 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
-
|
||||
from k5test import *
|
||||
from subprocess import *
|
||||
|
||||
diff --git a/src/kdc/t_bigreply.py b/src/kdc/t_bigreply.py
|
||||
index 6bc9a8fe0..b6300154f 100644
|
||||
--- a/src/kdc/t_bigreply.py
|
||||
+++ b/src/kdc/t_bigreply.py
|
||||
@@ -1,4 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
from k5test import *
|
||||
|
||||
# Set the maximum UDP reply size very low, so that all replies go
|
||||
diff --git a/src/kdc/t_emptytgt.py b/src/kdc/t_emptytgt.py
|
||||
index 2d0432e33..c601c010c 100755
|
||||
--- a/src/kdc/t_emptytgt.py
|
||||
+++ b/src/kdc/t_emptytgt.py
|
||||
@@ -1,4 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
from k5test import *
|
||||
|
||||
realm = K5Realm(create_host=False)
|
||||
diff --git a/src/kdc/t_workers.py b/src/kdc/t_workers.py
|
||||
index 6dd4f6805..8de3f34d9 100755
|
||||
--- a/src/kdc/t_workers.py
|
||||
+++ b/src/kdc/t_workers.py
|
||||
@@ -1,4 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
from k5test import *
|
||||
|
||||
realm = K5Realm(start_kdc=False, create_host=False)
|
||||
diff --git a/src/lib/kdb/t_stringattr.py b/src/lib/kdb/t_stringattr.py
|
||||
index 085e179e4..93e2b0c01 100755
|
||||
--- a/src/lib/kdb/t_stringattr.py
|
||||
+++ b/src/lib/kdb/t_stringattr.py
|
||||
@@ -1,4 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
from k5test import *
|
||||
|
||||
realm = K5Realm(create_kdb=False)
|
||||
diff --git a/src/lib/krad/t_daemon.py b/src/lib/krad/t_daemon.py
|
||||
index dcda0050b..7d7a5d0c8 100755
|
||||
--- a/src/lib/krad/t_daemon.py
|
||||
+++ b/src/lib/krad/t_daemon.py
|
||||
@@ -1,5 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
-#
|
||||
# Copyright 2013 Red Hat, Inc. All rights reserved.
|
||||
#
|
||||
# Redistribution and use in source and binary forms, with or without
|
||||
diff --git a/src/lib/krb5/ccache/t_cccol.py b/src/lib/krb5/ccache/t_cccol.py
|
||||
index f7f178564..1467512e2 100755
|
||||
--- a/src/lib/krb5/ccache/t_cccol.py
|
||||
+++ b/src/lib/krb5/ccache/t_cccol.py
|
||||
@@ -1,4 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
from k5test import *
|
||||
|
||||
realm = K5Realm(create_kdb=False)
|
||||
diff --git a/src/lib/krb5/krb/t_expire_warn.py b/src/lib/krb5/krb/t_expire_warn.py
|
||||
index aed39e399..781f2728a 100755
|
||||
--- a/src/lib/krb5/krb/t_expire_warn.py
|
||||
+++ b/src/lib/krb5/krb/t_expire_warn.py
|
||||
@@ -1,5 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
-
|
||||
# Copyright (C) 2010 by the Massachusetts Institute of Technology.
|
||||
# All rights reserved.
|
||||
#
|
||||
diff --git a/src/lib/krb5/krb/t_in_ccache_patypes.py b/src/lib/krb5/krb/t_in_ccache_patypes.py
|
||||
index c04234064..b2812688c 100755
|
||||
--- a/src/lib/krb5/krb/t_in_ccache_patypes.py
|
||||
+++ b/src/lib/krb5/krb/t_in_ccache_patypes.py
|
||||
@@ -1,5 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
-
|
||||
# Copyright (C) 2010,2012 by the Massachusetts Institute of Technology.
|
||||
# All rights reserved.
|
||||
#
|
||||
diff --git a/src/lib/krb5/krb/t_vfy_increds.py b/src/lib/krb5/krb/t_vfy_increds.py
|
||||
index c820cc690..b899308a8 100755
|
||||
--- a/src/lib/krb5/krb/t_vfy_increds.py
|
||||
+++ b/src/lib/krb5/krb/t_vfy_increds.py
|
||||
@@ -1,5 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
-
|
||||
# Copyright (C) 2011 by the Massachusetts Institute of Technology.
|
||||
# All rights reserved.
|
||||
#
|
||||
diff --git a/src/lib/krb5/os/t_discover_uri.py b/src/lib/krb5/os/t_discover_uri.py
|
||||
index 278f98371..87bac1792 100644
|
||||
--- a/src/lib/krb5/os/t_discover_uri.py
|
||||
+++ b/src/lib/krb5/os/t_discover_uri.py
|
||||
@@ -1,4 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
from k5test import *
|
||||
|
||||
entries = ('URI _kerberos.TEST krb5srv::kkdcp:https://kdc1 1 1\n',
|
||||
diff --git a/src/tests/gssapi/t_authind.py b/src/tests/gssapi/t_authind.py
|
||||
index 84793beb6..af1741a23 100644
|
||||
--- a/src/tests/gssapi/t_authind.py
|
||||
+++ b/src/tests/gssapi/t_authind.py
|
||||
@@ -1,4 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
from k5test import *
|
||||
|
||||
# Test authentication indicators. Load the test preauth module so we
|
||||
diff --git a/src/tests/gssapi/t_ccselect.py b/src/tests/gssapi/t_ccselect.py
|
||||
index 3503f9269..cd62da231 100755
|
||||
--- a/src/tests/gssapi/t_ccselect.py
|
||||
+++ b/src/tests/gssapi/t_ccselect.py
|
||||
@@ -1,5 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
-
|
||||
# Copyright (C) 2011 by the Massachusetts Institute of Technology.
|
||||
# All rights reserved.
|
||||
|
||||
diff --git a/src/tests/gssapi/t_client_keytab.py b/src/tests/gssapi/t_client_keytab.py
|
||||
index 2da87f45b..e474a27c7 100755
|
||||
--- a/src/tests/gssapi/t_client_keytab.py
|
||||
+++ b/src/tests/gssapi/t_client_keytab.py
|
||||
@@ -1,4 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
from k5test import *
|
||||
|
||||
# Set up a basic realm and a client keytab containing two user principals.
|
||||
diff --git a/src/tests/gssapi/t_enctypes.py b/src/tests/gssapi/t_enctypes.py
|
||||
index f513db2b5..ee43ff028 100755
|
||||
--- a/src/tests/gssapi/t_enctypes.py
|
||||
+++ b/src/tests/gssapi/t_enctypes.py
|
||||
@@ -1,4 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
from k5test import *
|
||||
|
||||
# Define some convenience abbreviations for enctypes we will see in
|
||||
diff --git a/src/tests/gssapi/t_export_cred.py b/src/tests/gssapi/t_export_cred.py
|
||||
index b98962788..89167bcc5 100755
|
||||
--- a/src/tests/gssapi/t_export_cred.py
|
||||
+++ b/src/tests/gssapi/t_export_cred.py
|
||||
@@ -1,4 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
from k5test import *
|
||||
|
||||
# Test gss_export_cred and gss_import_cred for initiator creds,
|
||||
diff --git a/src/tests/gssapi/t_gssapi.py b/src/tests/gssapi/t_gssapi.py
|
||||
index 6da5fceff..a7dda20fb 100755
|
||||
--- a/src/tests/gssapi/t_gssapi.py
|
||||
+++ b/src/tests/gssapi/t_gssapi.py
|
||||
@@ -1,4 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
from k5test import *
|
||||
|
||||
# Test krb5 negotiation under SPNEGO for all enctype configurations. Also
|
||||
diff --git a/src/tests/gssapi/t_s4u.py b/src/tests/gssapi/t_s4u.py
|
||||
index e4cd68469..fc9d9e8a4 100755
|
||||
--- a/src/tests/gssapi/t_s4u.py
|
||||
+++ b/src/tests/gssapi/t_s4u.py
|
||||
@@ -1,4 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
from k5test import *
|
||||
|
||||
realm = K5Realm(create_host=False, get_creds=False)
|
||||
diff --git a/src/tests/jsonwalker.py b/src/tests/jsonwalker.py
|
||||
index 265c69c70..942ca2db7 100644
|
||||
--- a/src/tests/jsonwalker.py
|
||||
+++ b/src/tests/jsonwalker.py
|
||||
@@ -1,5 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
-
|
||||
import sys
|
||||
try:
|
||||
import cjson
|
||||
diff --git a/src/tests/t_audit.py b/src/tests/t_audit.py
|
||||
index 00e96bfea..0f880edb2 100755
|
||||
--- a/src/tests/t_audit.py
|
||||
+++ b/src/tests/t_audit.py
|
||||
@@ -1,4 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
from k5test import *
|
||||
|
||||
conf = {'plugins': {'audit': {
|
||||
diff --git a/src/tests/t_authdata.py b/src/tests/t_authdata.py
|
||||
index 8a577b4b1..5cff80348 100644
|
||||
--- a/src/tests/t_authdata.py
|
||||
+++ b/src/tests/t_authdata.py
|
||||
@@ -1,4 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
from k5test import *
|
||||
|
||||
# Load the sample KDC authdata module.
|
||||
diff --git a/src/tests/t_bogus_kdc_req.py b/src/tests/t_bogus_kdc_req.py
|
||||
index b6208ca68..a101c0e10 100755
|
||||
--- a/src/tests/t_bogus_kdc_req.py
|
||||
+++ b/src/tests/t_bogus_kdc_req.py
|
||||
@@ -1,5 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
-
|
||||
import base64
|
||||
import socket
|
||||
from k5test import *
|
||||
diff --git a/src/tests/t_ccache.py b/src/tests/t_ccache.py
|
||||
index 61d549b7b..a913eb025 100755
|
||||
--- a/src/tests/t_ccache.py
|
||||
+++ b/src/tests/t_ccache.py
|
||||
@@ -1,5 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
-
|
||||
# Copyright (C) 2011 by the Massachusetts Institute of Technology.
|
||||
# All rights reserved.
|
||||
|
||||
diff --git a/src/tests/t_certauth.py b/src/tests/t_certauth.py
|
||||
index e64a57b0d..9c7094525 100644
|
||||
--- a/src/tests/t_certauth.py
|
||||
+++ b/src/tests/t_certauth.py
|
||||
@@ -1,4 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
from k5test import *
|
||||
|
||||
# Skip this test if pkinit wasn't built.
|
||||
diff --git a/src/tests/t_changepw.py b/src/tests/t_changepw.py
|
||||
index 37fe4fce1..211cda6c3 100755
|
||||
--- a/src/tests/t_changepw.py
|
||||
+++ b/src/tests/t_changepw.py
|
||||
@@ -1,4 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
from k5test import *
|
||||
|
||||
# This file is intended to cover any password-changing mechanism. For
|
||||
diff --git a/src/tests/t_crossrealm.py b/src/tests/t_crossrealm.py
|
||||
index 4d595dca6..09028bfa7 100755
|
||||
--- a/src/tests/t_crossrealm.py
|
||||
+++ b/src/tests/t_crossrealm.py
|
||||
@@ -1,5 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
-
|
||||
# Copyright (C) 2011 by the Massachusetts Institute of Technology.
|
||||
# All rights reserved.
|
||||
#
|
||||
diff --git a/src/tests/t_cve-2012-1014.py b/src/tests/t_cve-2012-1014.py
|
||||
index e02162d6c..dcff95f6e 100755
|
||||
--- a/src/tests/t_cve-2012-1014.py
|
||||
+++ b/src/tests/t_cve-2012-1014.py
|
||||
@@ -1,5 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
-
|
||||
import base64
|
||||
import socket
|
||||
from k5test import *
|
||||
diff --git a/src/tests/t_cve-2012-1015.py b/src/tests/t_cve-2012-1015.py
|
||||
index e00c4dc90..28b1e619b 100755
|
||||
--- a/src/tests/t_cve-2012-1015.py
|
||||
+++ b/src/tests/t_cve-2012-1015.py
|
||||
@@ -1,5 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
-
|
||||
import base64
|
||||
import socket
|
||||
from k5test import *
|
||||
diff --git a/src/tests/t_cve-2013-1416.py b/src/tests/t_cve-2013-1416.py
|
||||
index 94fb6d5ef..8c4391a86 100755
|
||||
--- a/src/tests/t_cve-2013-1416.py
|
||||
+++ b/src/tests/t_cve-2013-1416.py
|
||||
@@ -1,5 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
-
|
||||
from k5test import *
|
||||
|
||||
realm = K5Realm()
|
||||
diff --git a/src/tests/t_cve-2013-1417.py b/src/tests/t_cve-2013-1417.py
|
||||
index c26930a30..ce47d21ca 100755
|
||||
--- a/src/tests/t_cve-2013-1417.py
|
||||
+++ b/src/tests/t_cve-2013-1417.py
|
||||
@@ -1,5 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
-
|
||||
from k5test import *
|
||||
|
||||
realm = K5Realm(realm='TEST')
|
||||
diff --git a/src/tests/t_dump.py b/src/tests/t_dump.py
|
||||
index 8a9462bd8..2cfeada6c 100755
|
||||
--- a/src/tests/t_dump.py
|
||||
+++ b/src/tests/t_dump.py
|
||||
@@ -1,4 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
from k5test import *
|
||||
from filecmp import cmp
|
||||
|
||||
diff --git a/src/tests/t_errmsg.py b/src/tests/t_errmsg.py
|
||||
index c9ae6637f..4aacf4e0a 100755
|
||||
--- a/src/tests/t_errmsg.py
|
||||
+++ b/src/tests/t_errmsg.py
|
||||
@@ -1,4 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
from k5test import *
|
||||
|
||||
realm = K5Realm(create_kdb=False)
|
||||
diff --git a/src/tests/t_etype_info.py b/src/tests/t_etype_info.py
|
||||
index b2eb0f7af..b12fb53c8 100644
|
||||
--- a/src/tests/t_etype_info.py
|
||||
+++ b/src/tests/t_etype_info.py
|
||||
@@ -1,4 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
from k5test import *
|
||||
|
||||
supported_enctypes = 'aes128-cts des3-cbc-sha1 rc4-hmac des-cbc-crc:afs3'
|
||||
diff --git a/src/tests/t_general.py b/src/tests/t_general.py
|
||||
index 91ad0cb8a..96ba8a4b0 100755
|
||||
--- a/src/tests/t_general.py
|
||||
+++ b/src/tests/t_general.py
|
||||
@@ -1,4 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
from k5test import *
|
||||
|
||||
for realm in multipass_realms(create_host=False):
|
||||
diff --git a/src/tests/t_hooks.py b/src/tests/t_hooks.py
|
||||
index 58dff3ae7..4fd3822e8 100755
|
||||
--- a/src/tests/t_hooks.py
|
||||
+++ b/src/tests/t_hooks.py
|
||||
@@ -1,4 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
from k5test import *
|
||||
|
||||
# Test that KDC send and recv hooks work correctly.
|
||||
diff --git a/src/tests/t_hostrealm.py b/src/tests/t_hostrealm.py
|
||||
index 224c067ef..256ba2a38 100755
|
||||
--- a/src/tests/t_hostrealm.py
|
||||
+++ b/src/tests/t_hostrealm.py
|
||||
@@ -1,4 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
from k5test import *
|
||||
|
||||
plugin = os.path.join(buildtop, "plugins", "hostrealm", "test",
|
||||
diff --git a/src/tests/t_iprop.py b/src/tests/t_iprop.py
|
||||
index 8e23cd5de..9cbeb3e68 100755
|
||||
--- a/src/tests/t_iprop.py
|
||||
+++ b/src/tests/t_iprop.py
|
||||
@@ -1,5 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
-
|
||||
import os
|
||||
import re
|
||||
|
||||
diff --git a/src/tests/t_kadm5_auth.py b/src/tests/t_kadm5_auth.py
|
||||
index ba4ab8ef1..6e0f42b08 100644
|
||||
--- a/src/tests/t_kadm5_auth.py
|
||||
+++ b/src/tests/t_kadm5_auth.py
|
||||
@@ -1,4 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
from k5test import *
|
||||
|
||||
# Create a realm with the welcomer and bouncer kadm5_auth test modules
|
||||
diff --git a/src/tests/t_kadm5_hook.py b/src/tests/t_kadm5_hook.py
|
||||
index c1c8c9419..32fab781d 100755
|
||||
--- a/src/tests/t_kadm5_hook.py
|
||||
+++ b/src/tests/t_kadm5_hook.py
|
||||
@@ -1,4 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
from k5test import *
|
||||
|
||||
plugin = os.path.join(buildtop, "plugins", "kadm5_hook", "test",
|
||||
diff --git a/src/tests/t_kadmin_acl.py b/src/tests/t_kadmin_acl.py
|
||||
index 42bdf423c..01a3eda29 100755
|
||||
--- a/src/tests/t_kadmin_acl.py
|
||||
+++ b/src/tests/t_kadmin_acl.py
|
||||
@@ -1,4 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
from k5test import *
|
||||
import os
|
||||
|
||||
diff --git a/src/tests/t_kadmin_parsing.py b/src/tests/t_kadmin_parsing.py
|
||||
index 8de387c64..bebb01488 100644
|
||||
--- a/src/tests/t_kadmin_parsing.py
|
||||
+++ b/src/tests/t_kadmin_parsing.py
|
||||
@@ -1,4 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
from k5test import *
|
||||
|
||||
# This file contains tests for kadmin command parsing. Principal
|
||||
diff --git a/src/tests/t_kdb.py b/src/tests/t_kdb.py
|
||||
index 6e563b103..983cd93c8 100755
|
||||
--- a/src/tests/t_kdb.py
|
||||
+++ b/src/tests/t_kdb.py
|
||||
@@ -1,4 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
from k5test import *
|
||||
import time
|
||||
from itertools import imap
|
||||
diff --git a/src/tests/t_kdb_locking.py b/src/tests/t_kdb_locking.py
|
||||
index aac0a220f..b5afd6d23 100755
|
||||
--- a/src/tests/t_kdb_locking.py
|
||||
+++ b/src/tests/t_kdb_locking.py
|
||||
@@ -1,5 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
-
|
||||
# This is a regression test for
|
||||
# https://bugzilla.redhat.com/show_bug.cgi?id=586032 .
|
||||
#
|
||||
diff --git a/src/tests/t_kdc_log.py b/src/tests/t_kdc_log.py
|
||||
index 8ddb7691b..1b14828de 100755
|
||||
--- a/src/tests/t_kdc_log.py
|
||||
+++ b/src/tests/t_kdc_log.py
|
||||
@@ -1,5 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
-
|
||||
from k5test import *
|
||||
|
||||
# Make a TGS request with an expired ticket.
|
||||
diff --git a/src/tests/t_kdcpolicy.py b/src/tests/t_kdcpolicy.py
|
||||
index 5b198bb43..a44adfdb5 100644
|
||||
--- a/src/tests/t_kdcpolicy.py
|
||||
+++ b/src/tests/t_kdcpolicy.py
|
||||
@@ -1,4 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
from k5test import *
|
||||
from datetime import datetime
|
||||
import re
|
||||
diff --git a/src/tests/t_keydata.py b/src/tests/t_keydata.py
|
||||
index 5c04a8523..b37233b21 100755
|
||||
--- a/src/tests/t_keydata.py
|
||||
+++ b/src/tests/t_keydata.py
|
||||
@@ -1,4 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
from k5test import *
|
||||
|
||||
realm = K5Realm(create_user=False, create_host=False)
|
||||
diff --git a/src/tests/t_keyrollover.py b/src/tests/t_keyrollover.py
|
||||
index bfd38914b..7c8d828f0 100755
|
||||
--- a/src/tests/t_keyrollover.py
|
||||
+++ b/src/tests/t_keyrollover.py
|
||||
@@ -1,4 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
from k5test import *
|
||||
|
||||
rollover_krb5_conf = {'libdefaults': {'allow_weak_crypto': 'true'}}
|
||||
diff --git a/src/tests/t_keytab.py b/src/tests/t_keytab.py
|
||||
index a48740ba5..228c36334 100755
|
||||
--- a/src/tests/t_keytab.py
|
||||
+++ b/src/tests/t_keytab.py
|
||||
@@ -1,4 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
from k5test import *
|
||||
|
||||
for realm in multipass_realms(create_user=False):
|
||||
diff --git a/src/tests/t_kprop.py b/src/tests/t_kprop.py
|
||||
index 39169675d..f352ec8d7 100755
|
||||
--- a/src/tests/t_kprop.py
|
||||
+++ b/src/tests/t_kprop.py
|
||||
@@ -1,4 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
from k5test import *
|
||||
|
||||
conf_slave = {'dbmodules': {'db': {'database_name': '$testdir/db.slave'}}}
|
||||
diff --git a/src/tests/t_localauth.py b/src/tests/t_localauth.py
|
||||
index aa625d038..ebc9cdfde 100755
|
||||
--- a/src/tests/t_localauth.py
|
||||
+++ b/src/tests/t_localauth.py
|
||||
@@ -1,4 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
from k5test import *
|
||||
|
||||
# Unfortunately, we can't reliably test the k5login module. We can control
|
||||
diff --git a/src/tests/t_mkey.py b/src/tests/t_mkey.py
|
||||
index 615cd91ca..48a533059 100755
|
||||
--- a/src/tests/t_mkey.py
|
||||
+++ b/src/tests/t_mkey.py
|
||||
@@ -1,4 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
from k5test import *
|
||||
import random
|
||||
import re
|
||||
diff --git a/src/tests/t_otp.py b/src/tests/t_otp.py
|
||||
index 9b18ff94b..0fd35d576 100755
|
||||
--- a/src/tests/t_otp.py
|
||||
+++ b/src/tests/t_otp.py
|
||||
@@ -1,5 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
-#
|
||||
# Author: Nathaniel McCallum <npmccallum@redhat.com>
|
||||
#
|
||||
# Copyright (c) 2013 Red Hat, Inc.
|
||||
diff --git a/src/tests/t_pkinit.py b/src/tests/t_pkinit.py
|
||||
index 0e964c689..850db4fdd 100755
|
||||
--- a/src/tests/t_pkinit.py
|
||||
+++ b/src/tests/t_pkinit.py
|
||||
@@ -1,4 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
from k5test import *
|
||||
|
||||
# Skip this test if pkinit wasn't built.
|
||||
diff --git a/src/tests/t_policy.py b/src/tests/t_policy.py
|
||||
index 26c4e466e..eb3865d7c 100755
|
||||
--- a/src/tests/t_policy.py
|
||||
+++ b/src/tests/t_policy.py
|
||||
@@ -1,4 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
from k5test import *
|
||||
import re
|
||||
|
||||
diff --git a/src/tests/t_preauth.py b/src/tests/t_preauth.py
|
||||
index 32e35b08b..f597c3d08 100644
|
||||
--- a/src/tests/t_preauth.py
|
||||
+++ b/src/tests/t_preauth.py
|
||||
@@ -1,4 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
from k5test import *
|
||||
|
||||
# Test that the kdcpreauth client_keyblock() callback matches the key
|
||||
diff --git a/src/tests/t_princflags.py b/src/tests/t_princflags.py
|
||||
index 6378ef94f..aa3660217 100755
|
||||
--- a/src/tests/t_princflags.py
|
||||
+++ b/src/tests/t_princflags.py
|
||||
@@ -1,4 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
from k5test import *
|
||||
from princflags import *
|
||||
import re
|
||||
diff --git a/src/tests/t_proxy.py b/src/tests/t_proxy.py
|
||||
index 4e86fce8f..ff1929bef 100755
|
||||
--- a/src/tests/t_proxy.py
|
||||
+++ b/src/tests/t_proxy.py
|
||||
@@ -1,4 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
from k5test import *
|
||||
|
||||
# Skip this test if we're missing proxy functionality or parts of the proxy.
|
||||
@@ -62,7 +61,8 @@ def start_proxy(realm, keycertpem):
|
||||
conf.write('kpasswd = kpasswd://localhost:%d\n' % (realm.portbase + 2))
|
||||
conf.close()
|
||||
realm.env['KDCPROXY_CONFIG'] = proxy_conf_path
|
||||
- cmd = [proxy_exec_path, str(realm.server_port()), keycertpem]
|
||||
+ cmd = [sys.executable, proxy_exec_path, str(realm.server_port()),
|
||||
+ keycertpem]
|
||||
return realm.start_server(cmd, sentinel='proxy server ready')
|
||||
|
||||
# Fail: untrusted issuer and hostname doesn't match.
|
||||
diff --git a/src/tests/t_pwqual.py b/src/tests/t_pwqual.py
|
||||
index 011110bd1..171805697 100755
|
||||
--- a/src/tests/t_pwqual.py
|
||||
+++ b/src/tests/t_pwqual.py
|
||||
@@ -1,4 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
from k5test import *
|
||||
|
||||
plugin = os.path.join(buildtop, "plugins", "pwqual", "test", "pwqual_test.so")
|
||||
diff --git a/src/tests/t_rdreq.py b/src/tests/t_rdreq.py
|
||||
index f67c34866..00cd5cbb4 100755
|
||||
--- a/src/tests/t_rdreq.py
|
||||
+++ b/src/tests/t_rdreq.py
|
||||
@@ -1,4 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
from k5test import *
|
||||
|
||||
conf = {'realms': {'$realm': {'supported_enctypes': 'aes256-cts aes128-cts'}}}
|
||||
diff --git a/src/tests/t_referral.py b/src/tests/t_referral.py
|
||||
index e12fdc2e9..2f29d5712 100755
|
||||
--- a/src/tests/t_referral.py
|
||||
+++ b/src/tests/t_referral.py
|
||||
@@ -1,4 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
from k5test import *
|
||||
|
||||
# Create a pair of realms, where KRBTEST1.COM can authenticate to
|
||||
diff --git a/src/tests/t_renew.py b/src/tests/t_renew.py
|
||||
index 034190c80..67b4182fd 100755
|
||||
--- a/src/tests/t_renew.py
|
||||
+++ b/src/tests/t_renew.py
|
||||
@@ -1,4 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
from k5test import *
|
||||
from datetime import datetime
|
||||
import re
|
||||
diff --git a/src/tests/t_renprinc.py b/src/tests/t_renprinc.py
|
||||
index cc780839a..46cbed441 100755
|
||||
--- a/src/tests/t_renprinc.py
|
||||
+++ b/src/tests/t_renprinc.py
|
||||
@@ -1,5 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
-
|
||||
# Copyright (C) 2011 by the Massachusetts Institute of Technology.
|
||||
# All rights reserved.
|
||||
|
||||
diff --git a/src/tests/t_salt.py b/src/tests/t_salt.py
|
||||
index ddb1905ed..278911a22 100755
|
||||
--- a/src/tests/t_salt.py
|
||||
+++ b/src/tests/t_salt.py
|
||||
@@ -1,4 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
from k5test import *
|
||||
import re
|
||||
|
||||
diff --git a/src/tests/t_sesskeynego.py b/src/tests/t_sesskeynego.py
|
||||
index 732c306ea..448092387 100755
|
||||
--- a/src/tests/t_sesskeynego.py
|
||||
+++ b/src/tests/t_sesskeynego.py
|
||||
@@ -1,4 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
from k5test import *
|
||||
import re
|
||||
|
||||
diff --git a/src/tests/t_skew.py b/src/tests/t_skew.py
|
||||
index f2ae06695..36d5a95c5 100755
|
||||
--- a/src/tests/t_skew.py
|
||||
+++ b/src/tests/t_skew.py
|
||||
@@ -1,4 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
from k5test import *
|
||||
|
||||
# Create a realm with the KDC one hour in the past.
|
||||
diff --git a/src/tests/t_sn2princ.py b/src/tests/t_sn2princ.py
|
||||
index 19a0d2fa7..e2c85e665 100755
|
||||
--- a/src/tests/t_sn2princ.py
|
||||
+++ b/src/tests/t_sn2princ.py
|
||||
@@ -1,4 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
from k5test import *
|
||||
|
||||
offline = (len(args) > 0 and args[0] != "no")
|
||||
diff --git a/src/tests/t_spake.py b/src/tests/t_spake.py
|
||||
index 5b47e62d3..65af46d18 100644
|
||||
--- a/src/tests/t_spake.py
|
||||
+++ b/src/tests/t_spake.py
|
||||
@@ -1,4 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
from k5test import *
|
||||
|
||||
# The name and number of each supported SPAKE group.
|
||||
diff --git a/src/tests/t_stringattr.py b/src/tests/t_stringattr.py
|
||||
index 5672a0f20..c2dc348e9 100755
|
||||
--- a/src/tests/t_stringattr.py
|
||||
+++ b/src/tests/t_stringattr.py
|
||||
@@ -1,5 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
-
|
||||
# Copyright (C) 2011 by the Massachusetts Institute of Technology.
|
||||
# All rights reserved.
|
||||
|
||||
diff --git a/src/tests/t_tabdump.py b/src/tests/t_tabdump.py
|
||||
index 066e48418..2a86136dd 100755
|
||||
--- a/src/tests/t_tabdump.py
|
||||
+++ b/src/tests/t_tabdump.py
|
||||
@@ -1,4 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
from k5test import *
|
||||
|
||||
import csv
|
||||
diff --git a/src/tests/t_unlockiter.py b/src/tests/t_unlockiter.py
|
||||
index 2a438e99a..603cf721d 100755
|
||||
--- a/src/tests/t_unlockiter.py
|
||||
+++ b/src/tests/t_unlockiter.py
|
||||
@@ -1,4 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
from k5test import *
|
||||
|
||||
# Default KDB iteration is locked. Expect write lock failure unless
|
||||
diff --git a/src/tests/t_y2038.py b/src/tests/t_y2038.py
|
||||
index 02e946df4..42a4ff7ed 100644
|
||||
--- a/src/tests/t_y2038.py
|
||||
+++ b/src/tests/t_y2038.py
|
||||
@@ -1,4 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
from k5test import *
|
||||
|
||||
# These tests will become much less important after the y2038 boundary
|
||||
diff --git a/src/util/paste-kdcproxy.py b/src/util/paste-kdcproxy.py
|
||||
index 1e56b8954..30467fd74 100755
|
||||
--- a/src/util/paste-kdcproxy.py
|
||||
+++ b/src/util/paste-kdcproxy.py
|
||||
@@ -1,4 +1,3 @@
|
||||
-#!/usr/bin/python
|
||||
import kdcproxy
|
||||
from paste import httpserver
|
||||
import os
|
||||
41
Fix-SPAKE-memory-leak.patch
Normal file
41
Fix-SPAKE-memory-leak.patch
Normal file
|
|
@ -0,0 +1,41 @@
|
|||
From 390c515e13dffc8c00b44623cba47e27c2f20cf7 Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Tue, 27 Mar 2018 10:36:05 -0400
|
||||
Subject: [PATCH] Fix SPAKE memory leak
|
||||
|
||||
In the NIST group implementations, ossl_fini() needs to free the
|
||||
groupdata container as well as its fields. Also in
|
||||
spake_kdc.c:parse_data(), initialize the magic field of the resulting
|
||||
data object to avoid a harmless uninitialized memory copy.
|
||||
|
||||
ticket: 8647
|
||||
(cherry picked from commit 70b88b8018658e052d6eabf06f8fdad17fbe993c)
|
||||
---
|
||||
src/plugins/preauth/spake/openssl.c | 1 +
|
||||
src/plugins/preauth/spake/spake_kdc.c | 1 +
|
||||
2 files changed, 2 insertions(+)
|
||||
|
||||
diff --git a/src/plugins/preauth/spake/openssl.c b/src/plugins/preauth/spake/openssl.c
|
||||
index b821a9158..f2e4b53ec 100644
|
||||
--- a/src/plugins/preauth/spake/openssl.c
|
||||
+++ b/src/plugins/preauth/spake/openssl.c
|
||||
@@ -69,6 +69,7 @@ ossl_fini(groupdata *gd)
|
||||
EC_POINT_free(gd->N);
|
||||
BN_CTX_free(gd->ctx);
|
||||
BN_free(gd->order);
|
||||
+ free(gd);
|
||||
}
|
||||
|
||||
static krb5_error_code
|
||||
diff --git a/src/plugins/preauth/spake/spake_kdc.c b/src/plugins/preauth/spake/spake_kdc.c
|
||||
index c1723ebaf..59e88409e 100644
|
||||
--- a/src/plugins/preauth/spake/spake_kdc.c
|
||||
+++ b/src/plugins/preauth/spake/spake_kdc.c
|
||||
@@ -75,6 +75,7 @@ parse_data(struct k5input *in, krb5_data *out)
|
||||
{
|
||||
out->length = k5_input_get_uint32_be(in);
|
||||
out->data = (char *)k5_input_get_bytes(in, out->length);
|
||||
+ out->magic = KV5M_DATA;
|
||||
}
|
||||
|
||||
/* Parse a received cookie into its components. The pointers stored in the
|
||||
92
Fix-hex-conversion-of-PKINIT-certid-strings.patch
Normal file
92
Fix-hex-conversion-of-PKINIT-certid-strings.patch
Normal file
|
|
@ -0,0 +1,92 @@
|
|||
From 8b898badbe8051270c6da96f5c15f3bc8b6d974e Mon Sep 17 00:00:00 2001
|
||||
From: Sumit Bose <sbose@redhat.com>
|
||||
Date: Fri, 26 Jan 2018 11:47:50 -0500
|
||||
Subject: [PATCH] Fix hex conversion of PKINIT certid strings
|
||||
|
||||
When parsing a PKCS11 token specification, correctly convert from hex
|
||||
to binary instead of using OpenSSL bignum functions (which would strip
|
||||
leading zeros).
|
||||
|
||||
[ghudson@mit.edu: made hex_string_to_bin() a bit less verbose; wrote
|
||||
commit message]
|
||||
|
||||
ticket: 8636
|
||||
(cherry picked from commit 63e8b8142fd7b3931a7bf2d6448978ca536bafc0)
|
||||
---
|
||||
.../preauth/pkinit/pkinit_crypto_openssl.c | 55 +++++++++++++++----
|
||||
1 file changed, 44 insertions(+), 11 deletions(-)
|
||||
|
||||
diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c
|
||||
index 2064eb7bd..eb2953fe1 100644
|
||||
--- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c
|
||||
+++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c
|
||||
@@ -4616,6 +4616,43 @@ reassemble_pkcs11_name(pkinit_identity_opts *idopts)
|
||||
return ret;
|
||||
}
|
||||
|
||||
+static int
|
||||
+hex_string_to_bin(const char *str, int *bin_len_out, CK_BYTE **bin_out)
|
||||
+{
|
||||
+ size_t str_len, i;
|
||||
+ CK_BYTE *bin;
|
||||
+ char *endptr, tmp[3] = { '\0', '\0', '\0' };
|
||||
+ long val;
|
||||
+
|
||||
+ *bin_len_out = 0;
|
||||
+ *bin_out = NULL;
|
||||
+
|
||||
+ str_len = strlen(str);
|
||||
+ if (str_len % 2 != 0)
|
||||
+ return EINVAL;
|
||||
+ bin = malloc(str_len / 2);
|
||||
+ if (bin == NULL)
|
||||
+ return ENOMEM;
|
||||
+
|
||||
+ errno = 0;
|
||||
+ for (i = 0; i < str_len / 2; i++) {
|
||||
+ tmp[0] = str[i * 2];
|
||||
+ tmp[1] = str[i * 2 + 1];
|
||||
+
|
||||
+ val = strtol(tmp, &endptr, 16);
|
||||
+ if (val < 0 || val > 255 || errno != 0 || endptr != &tmp[2]) {
|
||||
+ free(bin);
|
||||
+ return EINVAL;
|
||||
+ }
|
||||
+
|
||||
+ bin[i] = (CK_BYTE)val;
|
||||
+ }
|
||||
+
|
||||
+ *bin_len_out = str_len / 2;
|
||||
+ *bin_out = bin;
|
||||
+ return 0;
|
||||
+}
|
||||
+
|
||||
static krb5_error_code
|
||||
pkinit_get_certs_pkcs11(krb5_context context,
|
||||
pkinit_plg_crypto_context plg_cryptoctx,
|
||||
@@ -4658,18 +4695,14 @@ pkinit_get_certs_pkcs11(krb5_context context,
|
||||
}
|
||||
/* Convert the ascii cert_id string into a binary blob */
|
||||
if (idopts->cert_id_string != NULL) {
|
||||
- BIGNUM *bn = NULL;
|
||||
- BN_hex2bn(&bn, idopts->cert_id_string);
|
||||
- if (bn == NULL)
|
||||
- return ENOMEM;
|
||||
- id_cryptoctx->cert_id_len = BN_num_bytes(bn);
|
||||
- id_cryptoctx->cert_id = malloc((size_t) id_cryptoctx->cert_id_len);
|
||||
- if (id_cryptoctx->cert_id == NULL) {
|
||||
- BN_free(bn);
|
||||
- return ENOMEM;
|
||||
+ r = hex_string_to_bin(idopts->cert_id_string,
|
||||
+ &id_cryptoctx->cert_id_len,
|
||||
+ &id_cryptoctx->cert_id);
|
||||
+ if (r != 0) {
|
||||
+ pkiDebug("Failed to convert certid string [%s]\n",
|
||||
+ idopts->cert_id_string);
|
||||
+ return r;
|
||||
}
|
||||
- BN_bn2bin(bn, id_cryptoctx->cert_id);
|
||||
- BN_free(bn);
|
||||
}
|
||||
id_cryptoctx->slotid = idopts->slotid;
|
||||
id_cryptoctx->pkcs11_method = 1;
|
||||
35
Fix-k5test-prompts-for-Python-3.patch
Normal file
35
Fix-k5test-prompts-for-Python-3.patch
Normal file
|
|
@ -0,0 +1,35 @@
|
|||
From 43cf653d21d931b792b36c7e6e4cfab3a6236bef Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Wed, 25 Jul 2018 11:50:02 -0400
|
||||
Subject: [PATCH] Fix k5test prompts for Python 3
|
||||
|
||||
With Python 3, sys.stdout.write() of a partial line followed by
|
||||
sys.stdin.readline() does not display the partial line. Add explicit
|
||||
flushes to make prompts visible in k5test.py.
|
||||
|
||||
ticket: 8710
|
||||
(cherry picked from commit 297535b72177dcced036b78107e9d0e37781c7a3)
|
||||
---
|
||||
src/util/k5test.py | 2 ++
|
||||
1 file changed, 2 insertions(+)
|
||||
|
||||
diff --git a/src/util/k5test.py b/src/util/k5test.py
|
||||
index 81fac3063..e4f99b211 100644
|
||||
--- a/src/util/k5test.py
|
||||
+++ b/src/util/k5test.py
|
||||
@@ -457,6 +457,7 @@ def _onexit():
|
||||
if _debug or _stop_before or _stop_after or _shell_before or _shell_after:
|
||||
# Wait before killing daemons in case one is being debugged.
|
||||
sys.stdout.write('*** Press return to kill daemons and exit script: ')
|
||||
+ sys.stdout.flush()
|
||||
sys.stdin.readline()
|
||||
for proc in _daemons:
|
||||
os.kill(proc.pid, signal.SIGTERM)
|
||||
@@ -658,6 +659,7 @@ def _valgrind(args):
|
||||
def _stop_or_shell(stop, shell, env, ind):
|
||||
if (_match_cmdnum(stop, ind)):
|
||||
sys.stdout.write('*** [%d] Waiting for return: ' % ind)
|
||||
+ sys.stdout.flush()
|
||||
sys.stdin.readline()
|
||||
if (_match_cmdnum(shell, ind)):
|
||||
output('*** [%d] Spawning shell\n' % ind, True)
|
||||
48
Fix-read-overflow-in-KDC-sort_pa_data.patch
Normal file
48
Fix-read-overflow-in-KDC-sort_pa_data.patch
Normal file
|
|
@ -0,0 +1,48 @@
|
|||
From 59a28991e15496e6f9cf867c32dc18e7e1062f59 Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Thu, 15 Mar 2018 20:27:30 -0400
|
||||
Subject: [PATCH] Fix read overflow in KDC sort_pa_data()
|
||||
|
||||
sort_pa_data() could read past the end of pa_order if all preauth
|
||||
systems in the table have the PA_REPLACES_KEY flag, causing a
|
||||
dereference of preauth_systems[-1]. This situation became possible
|
||||
after commit fea1a488924faa3938ef723feaa1ff12d22a91ff with the
|
||||
elimination of static_preauth_systems; before that there were always
|
||||
table entries which did not have PA_REPLACES_KEY set.
|
||||
|
||||
Fix this bug by removing the loop to count n_key_replacers, and
|
||||
instead get the count from the prior loop by stopping once we move all
|
||||
of the key-replacing modules to the front.
|
||||
|
||||
(cherry picked from commit b38e318cea18fd65647189eed64aef83bf1cb772)
|
||||
---
|
||||
src/kdc/kdc_preauth.c | 9 +++++----
|
||||
1 file changed, 5 insertions(+), 4 deletions(-)
|
||||
|
||||
diff --git a/src/kdc/kdc_preauth.c b/src/kdc/kdc_preauth.c
|
||||
index 80b130222..62ff9a8a7 100644
|
||||
--- a/src/kdc/kdc_preauth.c
|
||||
+++ b/src/kdc/kdc_preauth.c
|
||||
@@ -663,17 +663,18 @@ sort_pa_order(krb5_context context, krb5_kdc_req *request, int *pa_order)
|
||||
break;
|
||||
}
|
||||
}
|
||||
+ /* If we didn't find one, we have moved all of the key-replacing
|
||||
+ * modules, and i is the count of those modules. */
|
||||
+ if (j == n_repliers)
|
||||
+ break;
|
||||
}
|
||||
+ n_key_replacers = i;
|
||||
|
||||
if (request->padata != NULL) {
|
||||
/* Now reorder the subset of modules which replace the key,
|
||||
* bubbling those which handle pa_data types provided by the
|
||||
* client ahead of the others.
|
||||
*/
|
||||
- for (i = 0; preauth_systems[pa_order[i]].flags & PA_REPLACES_KEY; i++) {
|
||||
- continue;
|
||||
- }
|
||||
- n_key_replacers = i;
|
||||
for (i = 0; i < n_key_replacers; i++) {
|
||||
if (pa_list_includes(request->padata,
|
||||
preauth_systems[pa_order[i]].type))
|
||||
43
Fix-securid_sam2-preauth-for-non-default-salt.patch
Normal file
43
Fix-securid_sam2-preauth-for-non-default-salt.patch
Normal file
|
|
@ -0,0 +1,43 @@
|
|||
From e405f42b532e377e7e3d654313a07f8c11f48f9a Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Wed, 3 Jan 2018 12:06:08 -0500
|
||||
Subject: [PATCH] Fix securid_sam2 preauth for non-default salt
|
||||
|
||||
When looking up the client long-term key, look for any salt type, not
|
||||
just the default salt type.
|
||||
|
||||
ticket: 8629
|
||||
(cherry picked from commit a2339099ad13c84de0843fd04d0ba612fc194a1e)
|
||||
---
|
||||
src/plugins/preauth/securid_sam2/grail.c | 3 +--
|
||||
src/plugins/preauth/securid_sam2/securid2.c | 3 +--
|
||||
2 files changed, 2 insertions(+), 4 deletions(-)
|
||||
|
||||
diff --git a/src/plugins/preauth/securid_sam2/grail.c b/src/plugins/preauth/securid_sam2/grail.c
|
||||
index 18d48f924..48b61b0d1 100644
|
||||
--- a/src/plugins/preauth/securid_sam2/grail.c
|
||||
+++ b/src/plugins/preauth/securid_sam2/grail.c
|
||||
@@ -213,8 +213,7 @@ verify_grail_data(krb5_context context, krb5_db_entry *client,
|
||||
return KRB5KDC_ERR_PREAUTH_FAILED;
|
||||
|
||||
ret = krb5_dbe_find_enctype(context, client,
|
||||
- sr2->sam_enc_nonce_or_sad.enctype,
|
||||
- KRB5_KDB_SALTTYPE_NORMAL,
|
||||
+ sr2->sam_enc_nonce_or_sad.enctype, -1,
|
||||
sr2->sam_enc_nonce_or_sad.kvno,
|
||||
&client_key_data);
|
||||
if (ret)
|
||||
diff --git a/src/plugins/preauth/securid_sam2/securid2.c b/src/plugins/preauth/securid_sam2/securid2.c
|
||||
index ca99ce3ef..363e17a10 100644
|
||||
--- a/src/plugins/preauth/securid_sam2/securid2.c
|
||||
+++ b/src/plugins/preauth/securid_sam2/securid2.c
|
||||
@@ -313,8 +313,7 @@ verify_securid_data_2(krb5_context context, krb5_db_entry *client,
|
||||
}
|
||||
|
||||
retval = krb5_dbe_find_enctype(context, client,
|
||||
- sr2->sam_enc_nonce_or_sad.enctype,
|
||||
- KRB5_KDB_SALTTYPE_NORMAL,
|
||||
+ sr2->sam_enc_nonce_or_sad.enctype, -1,
|
||||
sr2->sam_enc_nonce_or_sad.kvno,
|
||||
&client_key_data);
|
||||
if (retval) {
|
||||
133
Fix-segfault-in-finish_dispatch.patch
Normal file
133
Fix-segfault-in-finish_dispatch.patch
Normal file
|
|
@ -0,0 +1,133 @@
|
|||
From 617d153bb32d0bd7db33ccec21043d1113651f3a Mon Sep 17 00:00:00 2001
|
||||
From: Robbie Harwood <rharwood@redhat.com>
|
||||
Date: Wed, 18 Apr 2018 14:13:28 -0400
|
||||
Subject: [PATCH] Fix segfault in finish_dispatch()
|
||||
|
||||
dispatch() doesn't necessarily initialize state->active_realm which
|
||||
led to an explicit NULL dereference in finish_dispatch().
|
||||
|
||||
Additionally, fix make_too_big_error() so that it won't subsequently
|
||||
dereference state->active_realm.
|
||||
|
||||
tags: pullup
|
||||
target_version: 1.16-next
|
||||
target_version: 1.15-next
|
||||
---
|
||||
src/kdc/dispatch.c | 79 ++++++++++++++++++++++++----------------------
|
||||
1 file changed, 42 insertions(+), 37 deletions(-)
|
||||
|
||||
diff --git a/src/kdc/dispatch.c b/src/kdc/dispatch.c
|
||||
index 3ed5176a8..fb3686c98 100644
|
||||
--- a/src/kdc/dispatch.c
|
||||
+++ b/src/kdc/dispatch.c
|
||||
@@ -35,9 +35,6 @@
|
||||
|
||||
static krb5_int32 last_usec = 0, last_os_random = 0;
|
||||
|
||||
-static krb5_error_code make_too_big_error(kdc_realm_t *kdc_active_realm,
|
||||
- krb5_data **out);
|
||||
-
|
||||
struct dispatch_state {
|
||||
loop_respond_fn respond;
|
||||
void *arg;
|
||||
@@ -47,6 +44,41 @@ struct dispatch_state {
|
||||
krb5_context kdc_err_context;
|
||||
};
|
||||
|
||||
+
|
||||
+static krb5_error_code
|
||||
+make_too_big_error(krb5_context context, krb5_principal tgsprinc,
|
||||
+ krb5_data **out)
|
||||
+{
|
||||
+ krb5_error errpkt;
|
||||
+ krb5_error_code retval;
|
||||
+ krb5_data *scratch;
|
||||
+
|
||||
+ *out = NULL;
|
||||
+ memset(&errpkt, 0, sizeof(errpkt));
|
||||
+
|
||||
+ retval = krb5_us_timeofday(context, &errpkt.stime, &errpkt.susec);
|
||||
+ if (retval)
|
||||
+ return retval;
|
||||
+ errpkt.error = KRB_ERR_RESPONSE_TOO_BIG;
|
||||
+ errpkt.server = tgsprinc;
|
||||
+ errpkt.client = NULL;
|
||||
+ errpkt.text.length = 0;
|
||||
+ errpkt.text.data = 0;
|
||||
+ errpkt.e_data.length = 0;
|
||||
+ errpkt.e_data.data = 0;
|
||||
+ scratch = malloc(sizeof(*scratch));
|
||||
+ if (scratch == NULL)
|
||||
+ return ENOMEM;
|
||||
+ retval = krb5_mk_error(context, &errpkt, scratch);
|
||||
+ if (retval) {
|
||||
+ free(scratch);
|
||||
+ return retval;
|
||||
+ }
|
||||
+
|
||||
+ *out = scratch;
|
||||
+ return 0;
|
||||
+}
|
||||
+
|
||||
static void
|
||||
finish_dispatch(struct dispatch_state *state, krb5_error_code code,
|
||||
krb5_data *response)
|
||||
@@ -54,12 +86,17 @@ finish_dispatch(struct dispatch_state *state, krb5_error_code code,
|
||||
loop_respond_fn oldrespond = state->respond;
|
||||
void *oldarg = state->arg;
|
||||
kdc_realm_t *kdc_active_realm = state->active_realm;
|
||||
+ krb5_principal tgsprinc = NULL;
|
||||
+
|
||||
+ if (kdc_active_realm != NULL)
|
||||
+ tgsprinc = kdc_active_realm->realm_tgsprinc;
|
||||
|
||||
if (state->is_tcp == 0 && response &&
|
||||
response->length > (unsigned int)max_dgram_reply_size) {
|
||||
- krb5_free_data(kdc_context, response);
|
||||
+ krb5_free_data(state->kdc_err_context, response);
|
||||
response = NULL;
|
||||
- code = make_too_big_error(kdc_active_realm, &response);
|
||||
+ code = make_too_big_error(state->kdc_err_context, tgsprinc,
|
||||
+ &response);
|
||||
if (code)
|
||||
krb5_klog_syslog(LOG_ERR, "error constructing "
|
||||
"KRB_ERR_RESPONSE_TOO_BIG error: %s",
|
||||
@@ -208,38 +245,6 @@ done:
|
||||
finish_dispatch_cache(state, retval, response);
|
||||
}
|
||||
|
||||
-static krb5_error_code
|
||||
-make_too_big_error(kdc_realm_t *kdc_active_realm, krb5_data **out)
|
||||
-{
|
||||
- krb5_error errpkt;
|
||||
- krb5_error_code retval;
|
||||
- krb5_data *scratch;
|
||||
-
|
||||
- *out = NULL;
|
||||
- memset(&errpkt, 0, sizeof(errpkt));
|
||||
-
|
||||
- retval = krb5_us_timeofday(kdc_context, &errpkt.stime, &errpkt.susec);
|
||||
- if (retval)
|
||||
- return retval;
|
||||
- errpkt.error = KRB_ERR_RESPONSE_TOO_BIG;
|
||||
- errpkt.server = tgs_server;
|
||||
- errpkt.client = NULL;
|
||||
- errpkt.text.length = 0;
|
||||
- errpkt.text.data = 0;
|
||||
- errpkt.e_data.length = 0;
|
||||
- errpkt.e_data.data = 0;
|
||||
- scratch = malloc(sizeof(*scratch));
|
||||
- if (scratch == NULL)
|
||||
- return ENOMEM;
|
||||
- retval = krb5_mk_error(kdc_context, &errpkt, scratch);
|
||||
- if (retval) {
|
||||
- free(scratch);
|
||||
- return retval;
|
||||
- }
|
||||
-
|
||||
- *out = scratch;
|
||||
- return 0;
|
||||
-}
|
||||
|
||||
krb5_context get_context(void *handle)
|
||||
{
|
||||
81
Fix-some-broken-tests-for-Python-3.patch
Normal file
81
Fix-some-broken-tests-for-Python-3.patch
Normal file
|
|
@ -0,0 +1,81 @@
|
|||
From eb60404564852a262d4082c3e38086742afb1bd9 Mon Sep 17 00:00:00 2001
|
||||
From: Robbie Harwood <rharwood@redhat.com>
|
||||
Date: Mon, 16 Jul 2018 16:44:01 -0400
|
||||
Subject: [PATCH] Fix some broken tests for Python 3
|
||||
|
||||
Remove python2 dependencies in .travis.yml and add python3-paste.
|
||||
Convert t_daemon.py and jsonwalker.py to python3. csjon has no
|
||||
python3 version, so replace it with python's built-in JSON module.
|
||||
|
||||
python3-pyrad isn't available for Trusty, so krad and OTP tests are
|
||||
currently not exercised by Travis.
|
||||
|
||||
[ghudson@mit.edu: squashed commits; edited commit message]
|
||||
|
||||
ticket: 8710
|
||||
(cherry picked from commit d1fb3551c0dff5c3e6555b31fcbf04ff04d577fe)
|
||||
[rharwood@redhat.com: .travis.yml]
|
||||
---
|
||||
src/lib/krad/t_daemon.py | 2 +-
|
||||
src/tests/jsonwalker.py | 16 +++++-----------
|
||||
2 files changed, 6 insertions(+), 12 deletions(-)
|
||||
|
||||
diff --git a/src/lib/krad/t_daemon.py b/src/lib/krad/t_daemon.py
|
||||
index 7d7a5d0c8..7668cd7f8 100755
|
||||
--- a/src/lib/krad/t_daemon.py
|
||||
+++ b/src/lib/krad/t_daemon.py
|
||||
@@ -23,7 +23,7 @@
|
||||
# NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS
|
||||
# SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
|
||||
|
||||
-import StringIO
|
||||
+from io import StringIO
|
||||
import os
|
||||
import sys
|
||||
import signal
|
||||
diff --git a/src/tests/jsonwalker.py b/src/tests/jsonwalker.py
|
||||
index 7a0675e08..1880363d2 100644
|
||||
--- a/src/tests/jsonwalker.py
|
||||
+++ b/src/tests/jsonwalker.py
|
||||
@@ -1,10 +1,5 @@
|
||||
import sys
|
||||
-try:
|
||||
- import cjson
|
||||
-except ImportError:
|
||||
- print("Warning: skipping audit log verification because the cjson module" \
|
||||
- " is unavailable")
|
||||
- sys.exit(0)
|
||||
+import json
|
||||
from collections import defaultdict
|
||||
from optparse import OptionParser
|
||||
|
||||
@@ -72,7 +67,7 @@ class Parser(object):
|
||||
"""
|
||||
Generator that works through dictionary.
|
||||
"""
|
||||
- for a,v in adict.iteritems():
|
||||
+ for a,v in adict.items():
|
||||
if isinstance(v,dict):
|
||||
for (attrpath,u) in self._walk(v):
|
||||
yield (a+'.'+attrpath,u)
|
||||
@@ -93,17 +88,16 @@ if __name__ == '__main__':
|
||||
with open(options.filename, 'r') as f:
|
||||
content = list()
|
||||
for l in f:
|
||||
- content.append(cjson.decode(l.rstrip()))
|
||||
+ content.append(json.loads(l.rstrip()))
|
||||
f.close()
|
||||
else:
|
||||
- print('Input file in jason format is required')
|
||||
+ print('Input file in JSON format is required')
|
||||
exit()
|
||||
|
||||
defaults = None
|
||||
if options.defaults is not None:
|
||||
with open(options.defaults, 'r') as f:
|
||||
- defaults = cjson.decode(f.read())
|
||||
- f.close()
|
||||
+ defaults = json.load(f)
|
||||
|
||||
# run test
|
||||
p = Parser(defaults)
|
||||
149
Implement-k5_buf_init_dynamic_zap.patch
Normal file
149
Implement-k5_buf_init_dynamic_zap.patch
Normal file
|
|
@ -0,0 +1,149 @@
|
|||
From 3d651a6e234bed4c4d4865a56c5fa47dab89a5a6 Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Mon, 26 Mar 2018 11:12:39 -0400
|
||||
Subject: [PATCH] Implement k5_buf_init_dynamic_zap
|
||||
|
||||
Add a variant of dynamic k5buf objects which zeroes memory when
|
||||
reallocating or freeing the buffer.
|
||||
|
||||
(cherry picked from commit 8ee8246c14702dc03b02e31b9fb5b7c2bb674bfb)
|
||||
---
|
||||
src/include/k5-buf.h | 6 ++-
|
||||
src/util/support/k5buf.c | 41 +++++++++++++++----
|
||||
src/util/support/libkrb5support-fixed.exports | 1 +
|
||||
3 files changed, 39 insertions(+), 9 deletions(-)
|
||||
|
||||
diff --git a/src/include/k5-buf.h b/src/include/k5-buf.h
|
||||
index 1223916a6..48e2a7d53 100644
|
||||
--- a/src/include/k5-buf.h
|
||||
+++ b/src/include/k5-buf.h
|
||||
@@ -45,7 +45,7 @@
|
||||
*/
|
||||
|
||||
/* Buffer type values */
|
||||
-enum k5buftype { K5BUF_ERROR, K5BUF_FIXED, K5BUF_DYNAMIC };
|
||||
+enum k5buftype { K5BUF_ERROR, K5BUF_FIXED, K5BUF_DYNAMIC, K5BUF_DYNAMIC_ZAP };
|
||||
|
||||
struct k5buf {
|
||||
enum k5buftype buftype;
|
||||
@@ -63,6 +63,10 @@ void k5_buf_init_fixed(struct k5buf *buf, char *data, size_t space);
|
||||
/* Initialize a k5buf using an internally allocated dynamic buffer. */
|
||||
void k5_buf_init_dynamic(struct k5buf *buf);
|
||||
|
||||
+/* Initialize a k5buf using an internally allocated dynamic buffer, zeroing
|
||||
+ * memory when reallocating or freeing. */
|
||||
+void k5_buf_init_dynamic_zap(struct k5buf *buf);
|
||||
+
|
||||
/* Add a C string to BUF. */
|
||||
void k5_buf_add(struct k5buf *buf, const char *data);
|
||||
|
||||
diff --git a/src/util/support/k5buf.c b/src/util/support/k5buf.c
|
||||
index 35978f238..b2b5e5b67 100644
|
||||
--- a/src/util/support/k5buf.c
|
||||
+++ b/src/util/support/k5buf.c
|
||||
@@ -37,7 +37,7 @@
|
||||
/*
|
||||
* Structure invariants:
|
||||
*
|
||||
- * buftype is K5BUF_FIXED, K5BUF_DYNAMIC, or K5BUF_ERROR
|
||||
+ * buftype is K5BUF_FIXED, K5BUF_DYNAMIC, K5BUF_DYNAMIC_ZAP, or K5BUF_ERROR
|
||||
* if buftype is K5BUF_ERROR, the other fields are NULL or 0
|
||||
* if buftype is not K5BUF_ERROR:
|
||||
* space > 0
|
||||
@@ -77,22 +77,35 @@ ensure_space(struct k5buf *buf, size_t len)
|
||||
return 1;
|
||||
if (buf->buftype == K5BUF_FIXED) /* Can't resize a fixed buffer. */
|
||||
goto error_exit;
|
||||
- assert(buf->buftype == K5BUF_DYNAMIC);
|
||||
+ assert(buf->buftype == K5BUF_DYNAMIC || buf->buftype == K5BUF_DYNAMIC_ZAP);
|
||||
new_space = buf->space * 2;
|
||||
while (new_space - buf->len - 1 < len) {
|
||||
if (new_space > SIZE_MAX / 2)
|
||||
goto error_exit;
|
||||
new_space *= 2;
|
||||
}
|
||||
- new_data = realloc(buf->data, new_space);
|
||||
- if (new_data == NULL)
|
||||
- goto error_exit;
|
||||
+ if (buf->buftype == K5BUF_DYNAMIC_ZAP) {
|
||||
+ /* realloc() could leave behind a partial copy of sensitive data. */
|
||||
+ new_data = malloc(new_space);
|
||||
+ if (new_data == NULL)
|
||||
+ goto error_exit;
|
||||
+ memcpy(new_data, buf->data, buf->len);
|
||||
+ new_data[buf->len] = '\0';
|
||||
+ zap(buf->data, buf->len);
|
||||
+ free(buf->data);
|
||||
+ } else {
|
||||
+ new_data = realloc(buf->data, new_space);
|
||||
+ if (new_data == NULL)
|
||||
+ goto error_exit;
|
||||
+ }
|
||||
buf->data = new_data;
|
||||
buf->space = new_space;
|
||||
return 1;
|
||||
|
||||
error_exit:
|
||||
- if (buf->buftype == K5BUF_DYNAMIC)
|
||||
+ if (buf->buftype == K5BUF_DYNAMIC_ZAP)
|
||||
+ zap(buf->data, buf->len);
|
||||
+ if (buf->buftype == K5BUF_DYNAMIC_ZAP || buf->buftype == K5BUF_DYNAMIC)
|
||||
free(buf->data);
|
||||
set_error(buf);
|
||||
return 0;
|
||||
@@ -123,6 +136,14 @@ k5_buf_init_dynamic(struct k5buf *buf)
|
||||
*endptr(buf) = '\0';
|
||||
}
|
||||
|
||||
+void
|
||||
+k5_buf_init_dynamic_zap(struct k5buf *buf)
|
||||
+{
|
||||
+ k5_buf_init_dynamic(buf);
|
||||
+ if (buf->buftype == K5BUF_DYNAMIC)
|
||||
+ buf->buftype = K5BUF_DYNAMIC_ZAP;
|
||||
+}
|
||||
+
|
||||
void
|
||||
k5_buf_add(struct k5buf *buf, const char *data)
|
||||
{
|
||||
@@ -163,7 +184,7 @@ k5_buf_add_vfmt(struct k5buf *buf, const char *fmt, va_list ap)
|
||||
}
|
||||
|
||||
/* Optimistically format the data directly into the dynamic buffer. */
|
||||
- assert(buf->buftype == K5BUF_DYNAMIC);
|
||||
+ assert(buf->buftype == K5BUF_DYNAMIC || buf->buftype == K5BUF_DYNAMIC_ZAP);
|
||||
va_copy(apcopy, ap);
|
||||
r = vsnprintf(endptr(buf), remaining, fmt, apcopy);
|
||||
va_end(apcopy);
|
||||
@@ -197,6 +218,8 @@ k5_buf_add_vfmt(struct k5buf *buf, const char *fmt, va_list ap)
|
||||
memcpy(endptr(buf), tmp, r + 1);
|
||||
buf->len += r;
|
||||
}
|
||||
+ if (buf->buftype == K5BUF_DYNAMIC_ZAP)
|
||||
+ zap(tmp, strlen(tmp));
|
||||
free(tmp);
|
||||
}
|
||||
|
||||
@@ -241,7 +264,9 @@ k5_buf_free(struct k5buf *buf)
|
||||
{
|
||||
if (buf->buftype == K5BUF_ERROR)
|
||||
return;
|
||||
- assert(buf->buftype == K5BUF_DYNAMIC);
|
||||
+ assert(buf->buftype == K5BUF_DYNAMIC || buf->buftype == K5BUF_DYNAMIC_ZAP);
|
||||
+ if (buf->buftype == K5BUF_DYNAMIC_ZAP)
|
||||
+ zap(buf->data, buf->len);
|
||||
free(buf->data);
|
||||
set_error(buf);
|
||||
}
|
||||
diff --git a/src/util/support/libkrb5support-fixed.exports b/src/util/support/libkrb5support-fixed.exports
|
||||
index cb9bf0826..a5e2ade04 100644
|
||||
--- a/src/util/support/libkrb5support-fixed.exports
|
||||
+++ b/src/util/support/libkrb5support-fixed.exports
|
||||
@@ -3,6 +3,7 @@ k5_base64_encode
|
||||
k5_bcmp
|
||||
k5_buf_init_fixed
|
||||
k5_buf_init_dynamic
|
||||
+k5_buf_init_dynamic_zap
|
||||
k5_buf_add
|
||||
k5_buf_add_len
|
||||
k5_buf_add_fmt
|
||||
327
In-FIPS-mode-add-plaintext-fallback-for-RC4-usages-a.patch
Normal file
327
In-FIPS-mode-add-plaintext-fallback-for-RC4-usages-a.patch
Normal file
|
|
@ -0,0 +1,327 @@
|
|||
From a9f547544ae43c2a71f21cab4fa61388c2f67553 Mon Sep 17 00:00:00 2001
|
||||
From: Robbie Harwood <rharwood@redhat.com>
|
||||
Date: Tue, 31 Jul 2018 13:47:26 -0400
|
||||
Subject: [PATCH] In FIPS mode, add plaintext fallback for RC4 usages and taint
|
||||
|
||||
---
|
||||
src/lib/krad/attr.c | 38 ++++++++++++++++++++++++++++----------
|
||||
src/lib/krad/attrset.c | 5 +++--
|
||||
src/lib/krad/internal.h | 13 +++++++++++--
|
||||
src/lib/krad/packet.c | 18 +++++++++---------
|
||||
src/lib/krad/remote.c | 10 ++++++++--
|
||||
src/lib/krad/t_attr.c | 3 ++-
|
||||
src/lib/krad/t_attrset.c | 4 +++-
|
||||
7 files changed, 64 insertions(+), 27 deletions(-)
|
||||
|
||||
diff --git a/src/lib/krad/attr.c b/src/lib/krad/attr.c
|
||||
index 9c13d9d75..3a2d0243b 100644
|
||||
--- a/src/lib/krad/attr.c
|
||||
+++ b/src/lib/krad/attr.c
|
||||
@@ -38,7 +38,8 @@
|
||||
typedef krb5_error_code
|
||||
(*attribute_transform_fn)(krb5_context ctx, const char *secret,
|
||||
const unsigned char *auth, const krb5_data *in,
|
||||
- unsigned char outbuf[MAX_ATTRSIZE], size_t *outlen);
|
||||
+ unsigned char outbuf[MAX_ATTRSIZE], size_t *outlen,
|
||||
+ krb5_boolean *is_fips);
|
||||
|
||||
typedef struct {
|
||||
const char *name;
|
||||
@@ -51,12 +52,14 @@ typedef struct {
|
||||
static krb5_error_code
|
||||
user_password_encode(krb5_context ctx, const char *secret,
|
||||
const unsigned char *auth, const krb5_data *in,
|
||||
- unsigned char outbuf[MAX_ATTRSIZE], size_t *outlen);
|
||||
+ unsigned char outbuf[MAX_ATTRSIZE], size_t *outlen,
|
||||
+ krb5_boolean *is_fips);
|
||||
|
||||
static krb5_error_code
|
||||
user_password_decode(krb5_context ctx, const char *secret,
|
||||
const unsigned char *auth, const krb5_data *in,
|
||||
- unsigned char outbuf[MAX_ATTRSIZE], size_t *outlen);
|
||||
+ unsigned char outbuf[MAX_ATTRSIZE], size_t *outlen,
|
||||
+ krb5_boolean *ignored);
|
||||
|
||||
static const attribute_record attributes[UCHAR_MAX] = {
|
||||
{"User-Name", 1, MAX_ATTRSIZE, NULL, NULL},
|
||||
@@ -128,7 +131,8 @@ static const attribute_record attributes[UCHAR_MAX] = {
|
||||
static krb5_error_code
|
||||
user_password_encode(krb5_context ctx, const char *secret,
|
||||
const unsigned char *auth, const krb5_data *in,
|
||||
- unsigned char outbuf[MAX_ATTRSIZE], size_t *outlen)
|
||||
+ unsigned char outbuf[MAX_ATTRSIZE], size_t *outlen,
|
||||
+ krb5_boolean *is_fips)
|
||||
{
|
||||
const unsigned char *indx;
|
||||
krb5_error_code retval;
|
||||
@@ -156,7 +160,12 @@ user_password_encode(krb5_context ctx, const char *secret,
|
||||
|
||||
retval = krb5_c_make_checksum(ctx, CKSUMTYPE_RSA_MD5, NULL, 0, &tmp,
|
||||
&sum);
|
||||
- if (retval != 0) {
|
||||
+ if (retval == ENOMEM) {
|
||||
+ /* I'm Linux, so we know this is a FIPS failure. Taint so we
|
||||
+ * don't send it later. */
|
||||
+ *is_fips = TRUE;
|
||||
+ sum.contents = calloc(1, BLOCKSIZE);
|
||||
+ } else if (retval != 0) {
|
||||
zap(tmp.data, tmp.length);
|
||||
zap(outbuf, len);
|
||||
krb5_free_data_contents(ctx, &tmp);
|
||||
@@ -180,7 +189,8 @@ user_password_encode(krb5_context ctx, const char *secret,
|
||||
static krb5_error_code
|
||||
user_password_decode(krb5_context ctx, const char *secret,
|
||||
const unsigned char *auth, const krb5_data *in,
|
||||
- unsigned char outbuf[MAX_ATTRSIZE], size_t *outlen)
|
||||
+ unsigned char outbuf[MAX_ATTRSIZE], size_t *outlen,
|
||||
+ krb5_boolean *is_fips)
|
||||
{
|
||||
const unsigned char *indx;
|
||||
krb5_error_code retval;
|
||||
@@ -206,7 +216,12 @@ user_password_decode(krb5_context ctx, const char *secret,
|
||||
|
||||
retval = krb5_c_make_checksum(ctx, CKSUMTYPE_RSA_MD5, NULL, 0,
|
||||
&tmp, &sum);
|
||||
- if (retval != 0) {
|
||||
+ if (retval == ENOMEM) {
|
||||
+ /* I'm Linux, so we know this is a FIPS failure. Assume the
|
||||
+ * other side is running locally and move on. */
|
||||
+ *is_fips = TRUE;
|
||||
+ sum.contents = calloc(1, BLOCKSIZE);
|
||||
+ } else if (retval != 0) {
|
||||
zap(tmp.data, tmp.length);
|
||||
zap(outbuf, in->length);
|
||||
krb5_free_data_contents(ctx, &tmp);
|
||||
@@ -248,7 +263,7 @@ krb5_error_code
|
||||
kr_attr_encode(krb5_context ctx, const char *secret,
|
||||
const unsigned char *auth, krad_attr type,
|
||||
const krb5_data *in, unsigned char outbuf[MAX_ATTRSIZE],
|
||||
- size_t *outlen)
|
||||
+ size_t *outlen, krb5_boolean *is_fips)
|
||||
{
|
||||
krb5_error_code retval;
|
||||
|
||||
@@ -265,7 +280,8 @@ kr_attr_encode(krb5_context ctx, const char *secret,
|
||||
return 0;
|
||||
}
|
||||
|
||||
- return attributes[type - 1].encode(ctx, secret, auth, in, outbuf, outlen);
|
||||
+ return attributes[type - 1].encode(ctx, secret, auth, in, outbuf, outlen,
|
||||
+ is_fips);
|
||||
}
|
||||
|
||||
krb5_error_code
|
||||
@@ -274,6 +290,7 @@ kr_attr_decode(krb5_context ctx, const char *secret, const unsigned char *auth,
|
||||
unsigned char outbuf[MAX_ATTRSIZE], size_t *outlen)
|
||||
{
|
||||
krb5_error_code retval;
|
||||
+ krb5_boolean ignored;
|
||||
|
||||
retval = kr_attr_valid(type, in);
|
||||
if (retval != 0)
|
||||
@@ -288,7 +305,8 @@ kr_attr_decode(krb5_context ctx, const char *secret, const unsigned char *auth,
|
||||
return 0;
|
||||
}
|
||||
|
||||
- return attributes[type - 1].decode(ctx, secret, auth, in, outbuf, outlen);
|
||||
+ return attributes[type - 1].decode(ctx, secret, auth, in, outbuf, outlen,
|
||||
+ &ignored);
|
||||
}
|
||||
|
||||
krad_attr
|
||||
diff --git a/src/lib/krad/attrset.c b/src/lib/krad/attrset.c
|
||||
index 03c613716..d89982a13 100644
|
||||
--- a/src/lib/krad/attrset.c
|
||||
+++ b/src/lib/krad/attrset.c
|
||||
@@ -167,7 +167,8 @@ krad_attrset_copy(const krad_attrset *set, krad_attrset **copy)
|
||||
krb5_error_code
|
||||
kr_attrset_encode(const krad_attrset *set, const char *secret,
|
||||
const unsigned char *auth,
|
||||
- unsigned char outbuf[MAX_ATTRSETSIZE], size_t *outlen)
|
||||
+ unsigned char outbuf[MAX_ATTRSETSIZE], size_t *outlen,
|
||||
+ krb5_boolean *is_fips)
|
||||
{
|
||||
unsigned char buffer[MAX_ATTRSIZE];
|
||||
krb5_error_code retval;
|
||||
@@ -181,7 +182,7 @@ kr_attrset_encode(const krad_attrset *set, const char *secret,
|
||||
|
||||
K5_TAILQ_FOREACH(a, &set->list, list) {
|
||||
retval = kr_attr_encode(set->ctx, secret, auth, a->type, &a->attr,
|
||||
- buffer, &attrlen);
|
||||
+ buffer, &attrlen, is_fips);
|
||||
if (retval != 0)
|
||||
return retval;
|
||||
|
||||
diff --git a/src/lib/krad/internal.h b/src/lib/krad/internal.h
|
||||
index 996a89372..a53ce31ce 100644
|
||||
--- a/src/lib/krad/internal.h
|
||||
+++ b/src/lib/krad/internal.h
|
||||
@@ -49,6 +49,13 @@
|
||||
|
||||
typedef struct krad_remote_st krad_remote;
|
||||
|
||||
+struct krad_packet_st {
|
||||
+ char buffer[KRAD_PACKET_SIZE_MAX];
|
||||
+ krad_attrset *attrset;
|
||||
+ krb5_data pkt;
|
||||
+ krb5_boolean is_fips;
|
||||
+};
|
||||
+
|
||||
/* Validate constraints of an attribute. */
|
||||
krb5_error_code
|
||||
kr_attr_valid(krad_attr type, const krb5_data *data);
|
||||
@@ -57,7 +64,8 @@ kr_attr_valid(krad_attr type, const krb5_data *data);
|
||||
krb5_error_code
|
||||
kr_attr_encode(krb5_context ctx, const char *secret, const unsigned char *auth,
|
||||
krad_attr type, const krb5_data *in,
|
||||
- unsigned char outbuf[MAX_ATTRSIZE], size_t *outlen);
|
||||
+ unsigned char outbuf[MAX_ATTRSIZE], size_t *outlen,
|
||||
+ krb5_boolean *is_fips);
|
||||
|
||||
/* Decode an attribute. */
|
||||
krb5_error_code
|
||||
@@ -69,7 +77,8 @@ kr_attr_decode(krb5_context ctx, const char *secret, const unsigned char *auth,
|
||||
krb5_error_code
|
||||
kr_attrset_encode(const krad_attrset *set, const char *secret,
|
||||
const unsigned char *auth,
|
||||
- unsigned char outbuf[MAX_ATTRSETSIZE], size_t *outlen);
|
||||
+ unsigned char outbuf[MAX_ATTRSETSIZE], size_t *outlen,
|
||||
+ krb5_boolean *is_fips);
|
||||
|
||||
/* Decode attributes from a buffer. */
|
||||
krb5_error_code
|
||||
diff --git a/src/lib/krad/packet.c b/src/lib/krad/packet.c
|
||||
index c597174b6..2fbf0ee1e 100644
|
||||
--- a/src/lib/krad/packet.c
|
||||
+++ b/src/lib/krad/packet.c
|
||||
@@ -53,12 +53,6 @@ typedef unsigned char uchar;
|
||||
#define pkt_auth(p) ((uchar *)offset(&(p)->pkt, OFFSET_AUTH))
|
||||
#define pkt_attr(p) ((unsigned char *)offset(&(p)->pkt, OFFSET_ATTR))
|
||||
|
||||
-struct krad_packet_st {
|
||||
- char buffer[KRAD_PACKET_SIZE_MAX];
|
||||
- krad_attrset *attrset;
|
||||
- krb5_data pkt;
|
||||
-};
|
||||
-
|
||||
typedef struct {
|
||||
uchar x[(UCHAR_MAX + 1) / 8];
|
||||
} idmap;
|
||||
@@ -190,7 +184,11 @@ auth_generate_response(krb5_context ctx, const char *secret,
|
||||
retval = krb5_c_make_checksum(ctx, CKSUMTYPE_RSA_MD5, NULL, 0, &data,
|
||||
&hash);
|
||||
free(data.data);
|
||||
- if (retval != 0)
|
||||
+ if (retval == ENOMEM) {
|
||||
+ /* We're on Linux, so this is a FIPS failure, and this checksum
|
||||
+ * does very little security-wise anyway, so don't taint. */
|
||||
+ hash.contents = calloc(1, AUTH_FIELD_SIZE);
|
||||
+ } else if (retval != 0)
|
||||
return retval;
|
||||
|
||||
memcpy(rauth, hash.contents, AUTH_FIELD_SIZE);
|
||||
@@ -276,7 +274,7 @@ krad_packet_new_request(krb5_context ctx, const char *secret, krad_code code,
|
||||
|
||||
/* Encode the attributes. */
|
||||
retval = kr_attrset_encode(set, secret, pkt_auth(pkt), pkt_attr(pkt),
|
||||
- &attrset_len);
|
||||
+ &attrset_len, &pkt->is_fips);
|
||||
if (retval != 0)
|
||||
goto error;
|
||||
|
||||
@@ -314,7 +312,7 @@ krad_packet_new_response(krb5_context ctx, const char *secret, krad_code code,
|
||||
|
||||
/* Encode the attributes. */
|
||||
retval = kr_attrset_encode(set, secret, pkt_auth(request), pkt_attr(pkt),
|
||||
- &attrset_len);
|
||||
+ &attrset_len, &pkt->is_fips);
|
||||
if (retval != 0)
|
||||
goto error;
|
||||
|
||||
@@ -451,6 +449,8 @@ krad_packet_decode_response(krb5_context ctx, const char *secret,
|
||||
const krb5_data *
|
||||
krad_packet_encode(const krad_packet *pkt)
|
||||
{
|
||||
+ if (pkt->is_fips)
|
||||
+ return NULL;
|
||||
return &pkt->pkt;
|
||||
}
|
||||
|
||||
diff --git a/src/lib/krad/remote.c b/src/lib/krad/remote.c
|
||||
index 437f7e91a..0f90443ce 100644
|
||||
--- a/src/lib/krad/remote.c
|
||||
+++ b/src/lib/krad/remote.c
|
||||
@@ -263,7 +263,7 @@ on_io_write(krad_remote *rr)
|
||||
request *r;
|
||||
|
||||
K5_TAILQ_FOREACH(r, &rr->list, list) {
|
||||
- tmp = krad_packet_encode(r->request);
|
||||
+ tmp = &r->request->pkt;
|
||||
|
||||
/* If the packet has already been sent, do nothing. */
|
||||
if (r->sent == tmp->length)
|
||||
@@ -359,7 +359,7 @@ on_io_read(krad_remote *rr)
|
||||
if (req != NULL) {
|
||||
K5_TAILQ_FOREACH(r, &rr->list, list) {
|
||||
if (r->request == req &&
|
||||
- r->sent == krad_packet_encode(req)->length) {
|
||||
+ r->sent == req->pkt.length) {
|
||||
request_finish(r, 0, rsp);
|
||||
break;
|
||||
}
|
||||
@@ -455,6 +455,12 @@ kr_remote_send(krad_remote *rr, krad_code code, krad_attrset *attrs,
|
||||
(krad_packet_iter_cb)iterator, &r, &tmp);
|
||||
if (retval != 0)
|
||||
goto error;
|
||||
+ else if (tmp->is_fips && rr->info->ai_family != AF_LOCAL &&
|
||||
+ rr->info->ai_family != AF_UNIX) {
|
||||
+ /* This would expose cleartext passwords, so abort. */
|
||||
+ retval = ESOCKTNOSUPPORT;
|
||||
+ goto error;
|
||||
+ }
|
||||
|
||||
K5_TAILQ_FOREACH(r, &rr->list, list) {
|
||||
if (r->request == tmp) {
|
||||
diff --git a/src/lib/krad/t_attr.c b/src/lib/krad/t_attr.c
|
||||
index eb2a780c8..4d285ad9d 100644
|
||||
--- a/src/lib/krad/t_attr.c
|
||||
+++ b/src/lib/krad/t_attr.c
|
||||
@@ -50,6 +50,7 @@ main()
|
||||
const char *tmp;
|
||||
krb5_data in;
|
||||
size_t len;
|
||||
+ krb5_boolean is_fips = FALSE;
|
||||
|
||||
noerror(krb5_init_context(&ctx));
|
||||
|
||||
@@ -73,7 +74,7 @@ main()
|
||||
in = string2data((char *)decoded);
|
||||
retval = kr_attr_encode(ctx, secret, auth,
|
||||
krad_attr_name2num("User-Password"),
|
||||
- &in, outbuf, &len);
|
||||
+ &in, outbuf, &len, &is_fips);
|
||||
insist(retval == 0);
|
||||
insist(len == sizeof(encoded));
|
||||
insist(memcmp(outbuf, encoded, len) == 0);
|
||||
diff --git a/src/lib/krad/t_attrset.c b/src/lib/krad/t_attrset.c
|
||||
index 7928335ca..0f9576253 100644
|
||||
--- a/src/lib/krad/t_attrset.c
|
||||
+++ b/src/lib/krad/t_attrset.c
|
||||
@@ -49,6 +49,7 @@ main()
|
||||
krb5_context ctx;
|
||||
size_t len = 0, encode_len;
|
||||
krb5_data tmp;
|
||||
+ krb5_boolean is_fips = FALSE;
|
||||
|
||||
noerror(krb5_init_context(&ctx));
|
||||
noerror(krad_attrset_new(ctx, &set));
|
||||
@@ -62,7 +63,8 @@ main()
|
||||
noerror(krad_attrset_add(set, krad_attr_name2num("User-Password"), &tmp));
|
||||
|
||||
/* Encode attrset. */
|
||||
- noerror(kr_attrset_encode(set, "foo", auth, buffer, &encode_len));
|
||||
+ noerror(kr_attrset_encode(set, "foo", auth, buffer, &encode_len,
|
||||
+ &is_fips));
|
||||
krad_attrset_free(set);
|
||||
|
||||
/* Manually encode User-Name. */
|
||||
29
In-kpropd-debug-log-proper-ticket-enctype-names.patch
Normal file
29
In-kpropd-debug-log-proper-ticket-enctype-names.patch
Normal file
|
|
@ -0,0 +1,29 @@
|
|||
From 35fd91ee49ecba137a7f5b5da5f9c56ddef461af Mon Sep 17 00:00:00 2001
|
||||
From: Robbie Harwood <rharwood@redhat.com>
|
||||
Date: Tue, 15 Jan 2019 13:41:16 -0500
|
||||
Subject: [PATCH] In kpropd, debug-log proper ticket enctype names
|
||||
|
||||
This change replaces the last call of krb5_enctype_to_string() in our
|
||||
sources with krb5_enctype_to_name(), ensuring that we log consistently
|
||||
to users using readily discoverable strings.
|
||||
|
||||
(cherry picked from commit 30e12a2ecdf7e2a034a91626a03b5c9909e4c68d)
|
||||
(cherry picked from commit d2990ce023e000e1628007a5d24aad5a5abdb0a3)
|
||||
---
|
||||
src/slave/kpropd.c | 3 ++-
|
||||
1 file changed, 2 insertions(+), 1 deletion(-)
|
||||
|
||||
diff --git a/src/slave/kpropd.c b/src/slave/kpropd.c
|
||||
index 99676cc97..e1e21f631 100644
|
||||
--- a/src/slave/kpropd.c
|
||||
+++ b/src/slave/kpropd.c
|
||||
@@ -1279,7 +1279,8 @@ kerberos_authenticate(krb5_context context, int fd, krb5_principal *clientp,
|
||||
exit(1);
|
||||
}
|
||||
|
||||
- retval = krb5_enctype_to_string(*etype, etypebuf, sizeof(etypebuf));
|
||||
+ retval = krb5_enctype_to_name(*etype, FALSE, etypebuf,
|
||||
+ sizeof(etypebuf));
|
||||
if (retval) {
|
||||
com_err(progname, retval, _("while unparsing ticket etype"));
|
||||
exit(1);
|
||||
55
In-rd_req_dec-always-log-non-permitted-enctypes.patch
Normal file
55
In-rd_req_dec-always-log-non-permitted-enctypes.patch
Normal file
|
|
@ -0,0 +1,55 @@
|
|||
From 1bc74278b3393aeb559b0bcd3c7e2bd476f2754b Mon Sep 17 00:00:00 2001
|
||||
From: Robbie Harwood <rharwood@redhat.com>
|
||||
Date: Mon, 14 Jan 2019 17:14:42 -0500
|
||||
Subject: [PATCH] In rd_req_dec, always log non-permitted enctypes
|
||||
|
||||
The buffer specified in negotiate_etype() is too small for use with
|
||||
the AES enctypes when used with krb5_enctype_to_string(), so switch to
|
||||
using krb5_enctype_to_name().
|
||||
|
||||
(cherry picked from commit bf75ebf583a51bf00005a96d17924818d19377be)
|
||||
(cherry picked from commit e595f7a4c1c95aadcb1bc3ea2bb88fce66fb826b)
|
||||
---
|
||||
src/lib/krb5/krb/rd_req_dec.c | 5 ++---
|
||||
src/tests/gssapi/t_enctypes.py | 5 +++--
|
||||
2 files changed, 5 insertions(+), 5 deletions(-)
|
||||
|
||||
diff --git a/src/lib/krb5/krb/rd_req_dec.c b/src/lib/krb5/krb/rd_req_dec.c
|
||||
index 4cd429a11..e75192fee 100644
|
||||
--- a/src/lib/krb5/krb/rd_req_dec.c
|
||||
+++ b/src/lib/krb5/krb/rd_req_dec.c
|
||||
@@ -864,9 +864,8 @@ negotiate_etype(krb5_context context,
|
||||
if (permitted == FALSE) {
|
||||
char enctype_name[30];
|
||||
|
||||
- if (krb5_enctype_to_string(desired_etypes[i],
|
||||
- enctype_name,
|
||||
- sizeof(enctype_name)) == 0)
|
||||
+ if (krb5_enctype_to_name(desired_etypes[i], FALSE, enctype_name,
|
||||
+ sizeof(enctype_name)) == 0)
|
||||
k5_setmsg(context, KRB5_NOPERM_ETYPE,
|
||||
_("Encryption type %s not permitted"), enctype_name);
|
||||
return KRB5_NOPERM_ETYPE;
|
||||
diff --git a/src/tests/gssapi/t_enctypes.py b/src/tests/gssapi/t_enctypes.py
|
||||
index ee43ff028..5d9f80e04 100755
|
||||
--- a/src/tests/gssapi/t_enctypes.py
|
||||
+++ b/src/tests/gssapi/t_enctypes.py
|
||||
@@ -85,7 +85,8 @@ test('both aes128', 'aes128-cts', 'aes128-cts',
|
||||
# If only the acceptor constrains the permitted session enctypes to
|
||||
# aes128, subkey negotiation fails because the acceptor considers the
|
||||
# aes256 session key to be non-permitted.
|
||||
-test_err('acc aes128', None, 'aes128-cts', 'Encryption type not permitted')
|
||||
+test_err('acc aes128', None, 'aes128-cts',
|
||||
+ 'Encryption type aes256-cts-hmac-sha1-96 not permitted')
|
||||
|
||||
# If the initiator constrains the permitted session enctypes to des3,
|
||||
# no acceptor subkey will be generated because we can't upgrade to a
|
||||
@@ -128,7 +129,7 @@ test('upgrade init des3+rc4', 'des3 rc4', None,
|
||||
# is only for the sake of the kernel, since we could upgrade to an
|
||||
# aes128 subkey, but it's the current semantics.)
|
||||
test_err('upgrade acc aes128', None, 'aes128-cts',
|
||||
- 'Encryption type ArcFour with HMAC/md5 not permitted')
|
||||
+ 'Encryption type arcfour-hmac not permitted')
|
||||
|
||||
# If the acceptor permits rc4 but prefers aes128, it will negotiate an
|
||||
# upgrade to aes128.
|
||||
38
Include-etype-info-in-for-hardware-preauth-hints.patch
Normal file
38
Include-etype-info-in-for-hardware-preauth-hints.patch
Normal file
|
|
@ -0,0 +1,38 @@
|
|||
From bbc68d1657306a61a7646dd7b9690f67705e24be Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Wed, 3 Jan 2018 11:59:14 -0500
|
||||
Subject: [PATCH] Include etype-info in for hardware preauth hints
|
||||
|
||||
If a principal has the requires_hwauth bit set, include PA-ETYPE-INFO
|
||||
or PA-ETYPE-INFO2 padata in the PREAUTH_REQUIRED error, as preauth
|
||||
mechs involving hardware tokens may also use the principal's Kerberos
|
||||
password.
|
||||
|
||||
ticket: 8629
|
||||
(cherry picked from commit ba92da05accc524b8037453b63ced1a6c65fd2a1)
|
||||
---
|
||||
src/kdc/kdc_preauth.c | 4 ++--
|
||||
1 file changed, 2 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/src/kdc/kdc_preauth.c b/src/kdc/kdc_preauth.c
|
||||
index 81d0b8cff..739c5e776 100644
|
||||
--- a/src/kdc/kdc_preauth.c
|
||||
+++ b/src/kdc/kdc_preauth.c
|
||||
@@ -144,7 +144,7 @@ static preauth_system static_preauth_systems[] = {
|
||||
{
|
||||
"etype-info",
|
||||
KRB5_PADATA_ETYPE_INFO,
|
||||
- 0,
|
||||
+ PA_HARDWARE,
|
||||
NULL,
|
||||
NULL,
|
||||
NULL,
|
||||
@@ -155,7 +155,7 @@ static preauth_system static_preauth_systems[] = {
|
||||
{
|
||||
"etype-info2",
|
||||
KRB5_PADATA_ETYPE_INFO2,
|
||||
- 0,
|
||||
+ PA_HARDWARE,
|
||||
NULL,
|
||||
NULL,
|
||||
NULL,
|
||||
514
Include-preauth-name-in-trace-output-if-possible.patch
Normal file
514
Include-preauth-name-in-trace-output-if-possible.patch
Normal file
|
|
@ -0,0 +1,514 @@
|
|||
From b623881ec039bffc758f53906f7e4f9b884f1cf4 Mon Sep 17 00:00:00 2001
|
||||
From: Robbie Harwood <rharwood@redhat.com>
|
||||
Date: Thu, 15 Mar 2018 14:37:28 -0400
|
||||
Subject: [PATCH] Include preauth name in trace output if possible
|
||||
|
||||
Add a {patype} trace format specifier for a single pa-type value. Add
|
||||
a krb5_preauthtype to string conversion function to trace machinery
|
||||
and use it when formatting {patype} or {patypes}.
|
||||
|
||||
[ghudson@mit.edu: wrote conversion function; edited commit message]
|
||||
|
||||
ticket: 8653 (new)
|
||||
(cherry picked from commit 9c68fe39b018666eabe033b639c1f35d03ba51c7)
|
||||
---
|
||||
src/include/k5-trace.h | 17 +--
|
||||
src/lib/krb5/os/t_trace.ref | 2 +-
|
||||
src/lib/krb5/os/trace.c | 61 +++++++++-
|
||||
src/tests/t_pkinit.py | 43 +++----
|
||||
src/tests/t_preauth.py | 216 ++++++++++++++++++------------------
|
||||
5 files changed, 200 insertions(+), 139 deletions(-)
|
||||
|
||||
diff --git a/src/include/k5-trace.h b/src/include/k5-trace.h
|
||||
index 390a8b7d6..5f7eb9517 100644
|
||||
--- a/src/include/k5-trace.h
|
||||
+++ b/src/include/k5-trace.h
|
||||
@@ -75,6 +75,7 @@
|
||||
* {cksum} const krb5_checksum *, display cksumtype and hex checksum
|
||||
* {princ} krb5_principal, unparse and display
|
||||
* {ptype} krb5_int32, krb5_principal type, display name
|
||||
+ * {patype} krb5_preauthtype, a single padata type number
|
||||
* {patypes} krb5_pa_data **, display list of padata type numbers
|
||||
* {etype} krb5_enctype, display shortest name of enctype
|
||||
* {etypes} krb5_enctype *, display list of enctypes
|
||||
@@ -232,14 +233,14 @@ void krb5int_trace(krb5_context context, const char *fmt, ...);
|
||||
#define TRACE_INIT_CREDS_PREAUTH_DECRYPT_FAIL(c, code) \
|
||||
TRACE(c, "Decrypt with preauth AS key failed: {kerr}", code)
|
||||
#define TRACE_INIT_CREDS_PREAUTH_MORE(c, patype) \
|
||||
- TRACE(c, "Continuing preauth mech {int}", (int)patype)
|
||||
+ TRACE(c, "Continuing preauth mech {patype}", patype)
|
||||
#define TRACE_INIT_CREDS_PREAUTH_NONE(c) \
|
||||
TRACE(c, "Sending unauthenticated request")
|
||||
#define TRACE_INIT_CREDS_PREAUTH_OPTIMISTIC(c) \
|
||||
TRACE(c, "Attempting optimistic preauth")
|
||||
#define TRACE_INIT_CREDS_PREAUTH_TRYAGAIN(c, patype, code) \
|
||||
- TRACE(c, "Recovering from KDC error {int} using preauth mech {int}", \
|
||||
- (int)patype, (int)code)
|
||||
+ TRACE(c, "Recovering from KDC error {int} using preauth mech {patype}", \
|
||||
+ patype, (int)code)
|
||||
#define TRACE_INIT_CREDS_RESTART_FAST(c) \
|
||||
TRACE(c, "Restarting to upgrade to FAST")
|
||||
#define TRACE_INIT_CREDS_RESTART_PREAUTH_FAILED(c) \
|
||||
@@ -290,7 +291,7 @@ void krb5int_trace(krb5_context context, const char *fmt, ...);
|
||||
|
||||
#define TRACE_PREAUTH_CONFLICT(c, name1, name2, patype) \
|
||||
TRACE(c, "Preauth module {str} conflicts with module {str} for pa " \
|
||||
- "type {int}", name1, name2, (int) patype)
|
||||
+ "type {patype}", name1, name2, patype)
|
||||
#define TRACE_PREAUTH_COOKIE(c, len, data) \
|
||||
TRACE(c, "Received cookie: {lenstr}", (size_t) len, data)
|
||||
#define TRACE_PREAUTH_ENC_TS_KEY_GAK(c, keyblock) \
|
||||
@@ -302,8 +303,8 @@ void krb5int_trace(krb5_context context, const char *fmt, ...);
|
||||
TRACE(c, "Selected etype info: etype {etype}, salt \"{data}\", " \
|
||||
"params \"{data}\"", etype, salt, s2kparams)
|
||||
#define TRACE_PREAUTH_INFO_FAIL(c, patype, code) \
|
||||
- TRACE(c, "Preauth builtin info function failure, type={int}: {kerr}", \
|
||||
- (int) patype, code)
|
||||
+ TRACE(c, "Preauth builtin info function failure, type={patype}: {kerr}", \
|
||||
+ patype, code)
|
||||
#define TRACE_PREAUTH_INPUT(c, padata) \
|
||||
TRACE(c, "Processing preauth types: {patypes}", padata)
|
||||
#define TRACE_PREAUTH_OUTPUT(c, padata) \
|
||||
@@ -314,8 +315,8 @@ void krb5int_trace(krb5_context context, const char *fmt, ...);
|
||||
#define TRACE_PREAUTH_SAM_KEY_GAK(c, keyblock) \
|
||||
TRACE(c, "AS key obtained for SAM: {keyblock}", keyblock)
|
||||
#define TRACE_PREAUTH_SALT(c, salt, patype) \
|
||||
- TRACE(c, "Received salt \"{data}\" via padata type {int}", salt, \
|
||||
- (int) patype)
|
||||
+ TRACE(c, "Received salt \"{data}\" via padata type {patype}", salt, \
|
||||
+ patype)
|
||||
#define TRACE_PREAUTH_SKIP(c, name, patype) \
|
||||
TRACE(c, "Skipping previously used preauth module {str} ({int})", \
|
||||
name, (int) patype)
|
||||
diff --git a/src/lib/krb5/os/t_trace.ref b/src/lib/krb5/os/t_trace.ref
|
||||
index ca5818a1e..bd5d9b6b6 100644
|
||||
--- a/src/lib/krb5/os/t_trace.ref
|
||||
+++ b/src/lib/krb5/os/t_trace.ref
|
||||
@@ -38,7 +38,7 @@ int, krb5_principal type: Windows 2000 UPN and SID
|
||||
int, krb5_principal type: NT 4 style name
|
||||
int, krb5_principal type: NT 4 style name and SID
|
||||
int, krb5_principal type: ?
|
||||
-krb5_pa_data **, display list of padata type numbers: 3, 0
|
||||
+krb5_pa_data **, display list of padata type numbers: PA-PW-SALT (3), 0
|
||||
krb5_pa_data **, display list of padata type numbers: (empty)
|
||||
krb5_enctype, display shortest name of enctype: des-cbc-crc
|
||||
krb5_enctype *, display list of enctypes: 5, rc4-hmac-exp, 511
|
||||
diff --git a/src/lib/krb5/os/trace.c b/src/lib/krb5/os/trace.c
|
||||
index 779f184cb..10b4f0c14 100644
|
||||
--- a/src/lib/krb5/os/trace.c
|
||||
+++ b/src/lib/krb5/os/trace.c
|
||||
@@ -123,6 +123,50 @@ principal_type_string(krb5_int32 type)
|
||||
}
|
||||
}
|
||||
|
||||
+static char *
|
||||
+padata_type_string(krb5_preauthtype type)
|
||||
+{
|
||||
+ switch (type) {
|
||||
+ case KRB5_PADATA_TGS_REQ: return "PA-TGS-REQ";
|
||||
+ case KRB5_PADATA_ENC_TIMESTAMP: return "PA-ENC-TIMESTAMP";
|
||||
+ case KRB5_PADATA_PW_SALT: return "PA-PW-SALT";
|
||||
+ case KRB5_PADATA_ENC_UNIX_TIME: return "PA-ENC-UNIX-TIME";
|
||||
+ case KRB5_PADATA_ENC_SANDIA_SECURID: return "PA-SANDIA-SECUREID";
|
||||
+ case KRB5_PADATA_SESAME: return "PA-SESAME";
|
||||
+ case KRB5_PADATA_OSF_DCE: return "PA-OSF-DCE";
|
||||
+ case KRB5_CYBERSAFE_SECUREID: return "PA-CYBERSAFE-SECUREID";
|
||||
+ case KRB5_PADATA_AFS3_SALT: return "PA-AFS3-SALT";
|
||||
+ case KRB5_PADATA_ETYPE_INFO: return "PA-ETYPE-INFO";
|
||||
+ case KRB5_PADATA_SAM_CHALLENGE: return "PA-SAM-CHALLENGE";
|
||||
+ case KRB5_PADATA_SAM_RESPONSE: return "PA-SAM-RESPONSE";
|
||||
+ case KRB5_PADATA_PK_AS_REQ_OLD: return "PA-PK-AS-REQ_OLD";
|
||||
+ case KRB5_PADATA_PK_AS_REP_OLD: return "PA-PK-AS-REP_OLD";
|
||||
+ case KRB5_PADATA_PK_AS_REQ: return "PA-PK-AS-REQ";
|
||||
+ case KRB5_PADATA_PK_AS_REP: return "PA-PK-AS-REP";
|
||||
+ case KRB5_PADATA_ETYPE_INFO2: return "PA-ETYPE-INFO2";
|
||||
+ case KRB5_PADATA_SVR_REFERRAL_INFO: return "PA-SVR-REFERRAL-INFO";
|
||||
+ case KRB5_PADATA_SAM_REDIRECT: return "PA-SAM-REDIRECT";
|
||||
+ case KRB5_PADATA_GET_FROM_TYPED_DATA: return "PA-GET-FROM-TYPED-DATA";
|
||||
+ case KRB5_PADATA_SAM_CHALLENGE_2: return "PA-SAM-CHALLENGE2";
|
||||
+ case KRB5_PADATA_SAM_RESPONSE_2: return "PA-SAM-RESPONSE2";
|
||||
+ case KRB5_PADATA_PAC_REQUEST: return "PA-PAC-REQUEST";
|
||||
+ case KRB5_PADATA_FOR_USER: return "PA-FOR_USER";
|
||||
+ case KRB5_PADATA_S4U_X509_USER: return "PA-FOR-X509-USER";
|
||||
+ case KRB5_PADATA_AS_CHECKSUM: return "PA-AS-CHECKSUM";
|
||||
+ case KRB5_PADATA_FX_COOKIE: return "PA-FX-COOKIE";
|
||||
+ case KRB5_PADATA_FX_FAST: return "PA-FX-FAST";
|
||||
+ case KRB5_PADATA_FX_ERROR: return "PA-FX-ERROR";
|
||||
+ case KRB5_PADATA_ENCRYPTED_CHALLENGE: return "PA-ENCRYPTED-CHALLENGE";
|
||||
+ case KRB5_PADATA_OTP_CHALLENGE: return "PA-OTP-CHALLENGE";
|
||||
+ case KRB5_PADATA_OTP_REQUEST: return "PA-OTP-REQUEST";
|
||||
+ case KRB5_PADATA_OTP_PIN_CHANGE: return "PA-OTP-PIN-CHANGE";
|
||||
+ case KRB5_PADATA_PKINIT_KX: return "PA-PKINIT-KX";
|
||||
+ case KRB5_ENCPADATA_REQ_ENC_PA_REP: return "PA-REQ-ENC-PA-REP";
|
||||
+ case KRB5_PADATA_AS_FRESHNESS: return "PA_AS_FRESHNESS";
|
||||
+ default: return NULL;
|
||||
+ }
|
||||
+}
|
||||
+
|
||||
static char *
|
||||
trace_format(krb5_context context, const char *fmt, va_list ap)
|
||||
{
|
||||
@@ -140,6 +184,8 @@ trace_format(krb5_context context, const char *fmt, va_list ap)
|
||||
krb5_key key;
|
||||
const krb5_checksum *cksum;
|
||||
krb5_pa_data **padata;
|
||||
+ krb5_preauthtype pa_type;
|
||||
+ const char *name;
|
||||
krb5_ccache ccache;
|
||||
krb5_keytab keytab;
|
||||
krb5_creds *creds;
|
||||
@@ -271,10 +317,23 @@ trace_format(krb5_context context, const char *fmt, va_list ap)
|
||||
if (padata == NULL || *padata == NULL)
|
||||
k5_buf_add(&buf, "(empty)");
|
||||
for (; padata != NULL && *padata != NULL; padata++) {
|
||||
- k5_buf_add_fmt(&buf, "%d", (int)(*padata)->pa_type);
|
||||
+ pa_type = (*padata)->pa_type;
|
||||
+ name = padata_type_string(pa_type);
|
||||
+ if (name != NULL)
|
||||
+ k5_buf_add_fmt(&buf, "%s (%d)", name, (int)pa_type);
|
||||
+ else
|
||||
+ k5_buf_add_fmt(&buf, "%d", (int)pa_type);
|
||||
+
|
||||
if (*(padata + 1) != NULL)
|
||||
k5_buf_add(&buf, ", ");
|
||||
}
|
||||
+ } else if (strcmp(tmpbuf, "patype") == 0) {
|
||||
+ pa_type = va_arg(ap, krb5_preauthtype);
|
||||
+ name = padata_type_string(pa_type);
|
||||
+ if (name != NULL)
|
||||
+ k5_buf_add_fmt(&buf, "%s (%d)", name, (int)pa_type);
|
||||
+ else
|
||||
+ k5_buf_add_fmt(&buf, "%d", (int)pa_type);
|
||||
} else if (strcmp(tmpbuf, "etype") == 0) {
|
||||
etype = va_arg(ap, krb5_enctype);
|
||||
if (krb5_enctype_to_name(etype, TRUE, tmpbuf, sizeof(tmpbuf)) == 0)
|
||||
diff --git a/src/tests/t_pkinit.py b/src/tests/t_pkinit.py
|
||||
index 5bc60cb1e..0e964c689 100755
|
||||
--- a/src/tests/t_pkinit.py
|
||||
+++ b/src/tests/t_pkinit.py
|
||||
@@ -164,18 +164,19 @@ realm.stop_kdc()
|
||||
realm.start_kdc()
|
||||
|
||||
# Run the basic test - PKINIT with FILE: identity, with no password on the key.
|
||||
+msgs = ('Sending unauthenticated request',
|
||||
+ '/Additional pre-authentication required',
|
||||
+ 'Preauthenticating using KDC method data',
|
||||
+ 'PKINIT client received freshness token from KDC',
|
||||
+ 'PKINIT loading CA certs and CRLs from FILE',
|
||||
+ 'PKINIT client making DH request',
|
||||
+ ' preauth for next request: PA-FX-COOKIE (133), PA-PK-AS-REQ (16)',
|
||||
+ 'PKINIT client verified DH reply',
|
||||
+ 'PKINIT client found id-pkinit-san in KDC cert',
|
||||
+ 'PKINIT client matched KDC principal krbtgt/')
|
||||
realm.kinit(realm.user_princ,
|
||||
flags=['-X', 'X509_user_identity=%s' % file_identity],
|
||||
- expected_trace=('Sending unauthenticated request',
|
||||
- '/Additional pre-authentication required',
|
||||
- 'Preauthenticating using KDC method data',
|
||||
- 'PKINIT client received freshness token from KDC',
|
||||
- 'PKINIT loading CA certs and CRLs from FILE',
|
||||
- 'PKINIT client making DH request',
|
||||
- 'Produced preauth for next request: 133, 16',
|
||||
- 'PKINIT client verified DH reply',
|
||||
- 'PKINIT client found id-pkinit-san in KDC cert',
|
||||
- 'PKINIT client matched KDC principal krbtgt/'))
|
||||
+ expected_trace=msgs)
|
||||
realm.klist(realm.user_princ)
|
||||
realm.run([kvno, realm.host_princ])
|
||||
|
||||
@@ -194,19 +195,19 @@ minbits_kdc_conf = {'realms': {'$realm': {'pkinit_dh_min_bits': '4096'}}}
|
||||
minbits_env = realm.special_env('restrict', True, kdc_conf=minbits_kdc_conf)
|
||||
realm.stop_kdc()
|
||||
realm.start_kdc(env=minbits_env)
|
||||
-expected_trace = ('Sending unauthenticated request',
|
||||
- '/Additional pre-authentication required',
|
||||
- 'Preauthenticating using KDC method data',
|
||||
- 'Preauth module pkinit (16) (real) returned: 0/Success',
|
||||
- 'Produced preauth for next request: 133, 16',
|
||||
- '/Key parameters not accepted',
|
||||
- 'Preauth tryagain input types (16): 109, 133',
|
||||
- 'trying again with KDC-provided parameters',
|
||||
- 'Preauth module pkinit (16) tryagain returned: 0/Success',
|
||||
- 'Followup preauth for next request: 16, 133')
|
||||
+msgs = ('Sending unauthenticated request',
|
||||
+ '/Additional pre-authentication required',
|
||||
+ 'Preauthenticating using KDC method data',
|
||||
+ 'Preauth module pkinit (16) (real) returned: 0/Success',
|
||||
+ ' preauth for next request: PA-FX-COOKIE (133), PA-PK-AS-REQ (16)',
|
||||
+ '/Key parameters not accepted',
|
||||
+ 'Preauth tryagain input types (16): 109, PA-FX-COOKIE (133)',
|
||||
+ 'trying again with KDC-provided parameters',
|
||||
+ 'Preauth module pkinit (16) tryagain returned: 0/Success',
|
||||
+ ' preauth for next request: PA-PK-AS-REQ (16), PA-FX-COOKIE (133)')
|
||||
realm.kinit(realm.user_princ,
|
||||
flags=['-X', 'X509_user_identity=%s' % file_identity],
|
||||
- expected_trace=expected_trace)
|
||||
+ expected_trace=msgs)
|
||||
|
||||
# Test enforcement of required freshness tokens. (We can leave
|
||||
# freshness tokens required after this test.)
|
||||
diff --git a/src/tests/t_preauth.py b/src/tests/t_preauth.py
|
||||
index fec0bf619..efb3ea20d 100644
|
||||
--- a/src/tests/t_preauth.py
|
||||
+++ b/src/tests/t_preauth.py
|
||||
@@ -18,15 +18,15 @@ realm.kinit('nokeyuser', password('user'), expected_code=1,
|
||||
# PA-FX-COOKIE; 2 is encrypted timestamp.
|
||||
|
||||
# Test normal preauth flow.
|
||||
-expected_trace = ('Sending unauthenticated request',
|
||||
- '/Additional pre-authentication required',
|
||||
- 'Preauthenticating using KDC method data',
|
||||
- 'Processing preauth types:',
|
||||
- 'Preauth module test (-123) (real) returned: 0/Success',
|
||||
- 'Produced preauth for next request: 133, -123',
|
||||
- 'Decrypted AS reply')
|
||||
+msgs = ('Sending unauthenticated request',
|
||||
+ '/Additional pre-authentication required',
|
||||
+ 'Preauthenticating using KDC method data',
|
||||
+ 'Processing preauth types:',
|
||||
+ 'Preauth module test (-123) (real) returned: 0/Success',
|
||||
+ 'Produced preauth for next request: PA-FX-COOKIE (133), -123',
|
||||
+ 'Decrypted AS reply')
|
||||
realm.run(['./icred', realm.user_princ, password('user')],
|
||||
- expected_msg='testval', expected_trace=expected_trace)
|
||||
+ expected_msg='testval', expected_trace=msgs)
|
||||
|
||||
# Test successful optimistic preauth.
|
||||
expected_trace = ('Attempting optimistic preauth',
|
||||
@@ -39,136 +39,136 @@ realm.run(['./icred', '-o', '-123', realm.user_princ, password('user')],
|
||||
|
||||
# Test optimistic preauth failing on client, followed by successful
|
||||
# preauth using the same module.
|
||||
-expected_trace = ('Attempting optimistic preauth',
|
||||
- 'Processing preauth types: -123',
|
||||
- '/induced optimistic fail',
|
||||
- 'Sending unauthenticated request',
|
||||
- '/Additional pre-authentication required',
|
||||
- 'Preauthenticating using KDC method data',
|
||||
- 'Processing preauth types:',
|
||||
- 'Preauth module test (-123) (real) returned: 0/Success',
|
||||
- 'Produced preauth for next request: 133, -123',
|
||||
- 'Decrypted AS reply')
|
||||
+msgs = ('Attempting optimistic preauth',
|
||||
+ 'Processing preauth types: -123',
|
||||
+ '/induced optimistic fail',
|
||||
+ 'Sending unauthenticated request',
|
||||
+ '/Additional pre-authentication required',
|
||||
+ 'Preauthenticating using KDC method data',
|
||||
+ 'Processing preauth types:',
|
||||
+ 'Preauth module test (-123) (real) returned: 0/Success',
|
||||
+ 'Produced preauth for next request: PA-FX-COOKIE (133), -123',
|
||||
+ 'Decrypted AS reply')
|
||||
realm.run(['./icred', '-o', '-123', '-X', 'fail_optimistic', realm.user_princ,
|
||||
password('user')], expected_msg='testval',
|
||||
- expected_trace=expected_trace)
|
||||
+ expected_trace=msgs)
|
||||
|
||||
# Test optimistic preauth failing on KDC, followed by successful preauth
|
||||
# using the same module.
|
||||
realm.run([kadminl, 'setstr', realm.user_princ, 'failopt', 'yes'])
|
||||
-expected_trace = ('Attempting optimistic preauth',
|
||||
- 'Processing preauth types: -123',
|
||||
- 'Preauth module test (-123) (real) returned: 0/Success',
|
||||
- 'Produced preauth for next request: -123',
|
||||
- '/Preauthentication failed',
|
||||
- 'Preauthenticating using KDC method data',
|
||||
- 'Processing preauth types:',
|
||||
- 'Preauth module test (-123) (real) returned: 0/Success',
|
||||
- 'Produced preauth for next request: 133, -123',
|
||||
- 'Decrypted AS reply')
|
||||
+msgs = ('Attempting optimistic preauth',
|
||||
+ 'Processing preauth types: -123',
|
||||
+ 'Preauth module test (-123) (real) returned: 0/Success',
|
||||
+ 'Produced preauth for next request: -123',
|
||||
+ '/Preauthentication failed',
|
||||
+ 'Preauthenticating using KDC method data',
|
||||
+ 'Processing preauth types:',
|
||||
+ 'Preauth module test (-123) (real) returned: 0/Success',
|
||||
+ 'Produced preauth for next request: PA-FX-COOKIE (133), -123',
|
||||
+ 'Decrypted AS reply')
|
||||
realm.run(['./icred', '-o', '-123', realm.user_princ, password('user')],
|
||||
- expected_msg='testval', expected_trace=expected_trace)
|
||||
+ expected_msg='testval', expected_trace=msgs)
|
||||
realm.run([kadminl, 'delstr', realm.user_princ, 'failopt'])
|
||||
|
||||
# Test KDC_ERR_MORE_PREAUTH_DATA_REQUIRED and secure cookies.
|
||||
realm.run([kadminl, 'setstr', realm.user_princ, '2rt', 'secondtrip'])
|
||||
-expected_trace = ('Sending unauthenticated request',
|
||||
- '/Additional pre-authentication required',
|
||||
- 'Preauthenticating using KDC method data',
|
||||
- 'Processing preauth types:',
|
||||
- 'Preauth module test (-123) (real) returned: 0/Success',
|
||||
- 'Produced preauth for next request: 133, -123',
|
||||
- '/More preauthentication data is required',
|
||||
- 'Continuing preauth mech -123',
|
||||
- 'Processing preauth types: -123, 133',
|
||||
- 'Produced preauth for next request: 133, -123',
|
||||
- 'Decrypted AS reply')
|
||||
+msgs = ('Sending unauthenticated request',
|
||||
+ '/Additional pre-authentication required',
|
||||
+ 'Preauthenticating using KDC method data',
|
||||
+ 'Processing preauth types:',
|
||||
+ 'Preauth module test (-123) (real) returned: 0/Success',
|
||||
+ 'Produced preauth for next request: PA-FX-COOKIE (133), -123',
|
||||
+ '/More preauthentication data is required',
|
||||
+ 'Continuing preauth mech -123',
|
||||
+ 'Processing preauth types: -123, PA-FX-COOKIE (133)',
|
||||
+ 'Produced preauth for next request: PA-FX-COOKIE (133), -123',
|
||||
+ 'Decrypted AS reply')
|
||||
realm.run(['./icred', realm.user_princ, password('user')],
|
||||
- expected_msg='2rt: secondtrip', expected_trace=expected_trace)
|
||||
+ expected_msg='2rt: secondtrip', expected_trace=msgs)
|
||||
|
||||
# Test client-side failure after KDC_ERR_MORE_PREAUTH_DATA_REQUIRED,
|
||||
# falling back to encrypted timestamp.
|
||||
-expected_trace = ('Sending unauthenticated request',
|
||||
- '/Additional pre-authentication required',
|
||||
- 'Preauthenticating using KDC method data',
|
||||
- 'Processing preauth types:',
|
||||
- 'Preauth module test (-123) (real) returned: 0/Success',
|
||||
- 'Produced preauth for next request: 133, -123',
|
||||
- '/More preauthentication data is required',
|
||||
- 'Continuing preauth mech -123',
|
||||
- 'Processing preauth types: -123, 133',
|
||||
- '/induced 2rt fail',
|
||||
- 'Preauthenticating using KDC method data',
|
||||
- 'Processing preauth types:',
|
||||
- 'Encrypted timestamp (for ',
|
||||
- 'module encrypted_timestamp (2) (real) returned: 0/Success',
|
||||
- 'Produced preauth for next request: 133, 2',
|
||||
- 'Decrypted AS reply')
|
||||
+msgs = ('Sending unauthenticated request',
|
||||
+ '/Additional pre-authentication required',
|
||||
+ 'Preauthenticating using KDC method data',
|
||||
+ 'Processing preauth types:',
|
||||
+ 'Preauth module test (-123) (real) returned: 0/Success',
|
||||
+ 'Produced preauth for next request: PA-FX-COOKIE (133), -123',
|
||||
+ '/More preauthentication data is required',
|
||||
+ 'Continuing preauth mech -123',
|
||||
+ 'Processing preauth types: -123, PA-FX-COOKIE (133)',
|
||||
+ '/induced 2rt fail',
|
||||
+ 'Preauthenticating using KDC method data',
|
||||
+ 'Processing preauth types:',
|
||||
+ 'Encrypted timestamp (for ',
|
||||
+ 'module encrypted_timestamp (2) (real) returned: 0/Success',
|
||||
+ 'preauth for next request: PA-FX-COOKIE (133), PA-ENC-TIMESTAMP (2)',
|
||||
+ 'Decrypted AS reply')
|
||||
realm.run(['./icred', '-X', 'fail_2rt', realm.user_princ, password('user')],
|
||||
- expected_msg='2rt: secondtrip', expected_trace=expected_trace)
|
||||
+ expected_msg='2rt: secondtrip', expected_trace=msgs)
|
||||
|
||||
# Test KDC-side failure after KDC_ERR_MORE_PREAUTH_DATA_REQUIRED,
|
||||
# falling back to encrypted timestamp.
|
||||
realm.run([kadminl, 'setstr', realm.user_princ, 'fail2rt', 'yes'])
|
||||
-expected_trace = ('Sending unauthenticated request',
|
||||
- '/Additional pre-authentication required',
|
||||
- 'Preauthenticating using KDC method data',
|
||||
- 'Processing preauth types:',
|
||||
- 'Preauth module test (-123) (real) returned: 0/Success',
|
||||
- 'Produced preauth for next request: 133, -123',
|
||||
- '/More preauthentication data is required',
|
||||
- 'Continuing preauth mech -123',
|
||||
- 'Processing preauth types: -123, 133',
|
||||
- 'Preauth module test (-123) (real) returned: 0/Success',
|
||||
- 'Produced preauth for next request: 133, -123',
|
||||
- '/Preauthentication failed',
|
||||
- 'Preauthenticating using KDC method data',
|
||||
- 'Processing preauth types:',
|
||||
- 'Encrypted timestamp (for ',
|
||||
- 'module encrypted_timestamp (2) (real) returned: 0/Success',
|
||||
- 'Produced preauth for next request: 133, 2',
|
||||
- 'Decrypted AS reply')
|
||||
+msgs = ('Sending unauthenticated request',
|
||||
+ '/Additional pre-authentication required',
|
||||
+ 'Preauthenticating using KDC method data',
|
||||
+ 'Processing preauth types:',
|
||||
+ 'Preauth module test (-123) (real) returned: 0/Success',
|
||||
+ 'Produced preauth for next request: PA-FX-COOKIE (133), -123',
|
||||
+ '/More preauthentication data is required',
|
||||
+ 'Continuing preauth mech -123',
|
||||
+ 'Processing preauth types: -123, PA-FX-COOKIE (133)',
|
||||
+ 'Preauth module test (-123) (real) returned: 0/Success',
|
||||
+ 'Produced preauth for next request: PA-FX-COOKIE (133), -123',
|
||||
+ '/Preauthentication failed',
|
||||
+ 'Preauthenticating using KDC method data',
|
||||
+ 'Processing preauth types:',
|
||||
+ 'Encrypted timestamp (for ',
|
||||
+ 'module encrypted_timestamp (2) (real) returned: 0/Success',
|
||||
+ 'preauth for next request: PA-FX-COOKIE (133), PA-ENC-TIMESTAMP (2)',
|
||||
+ 'Decrypted AS reply')
|
||||
realm.run(['./icred', realm.user_princ, password('user')],
|
||||
- expected_msg='2rt: secondtrip', expected_trace=expected_trace)
|
||||
+ expected_msg='2rt: secondtrip', expected_trace=msgs)
|
||||
realm.run([kadminl, 'delstr', realm.user_princ, 'fail2rt'])
|
||||
|
||||
# Test tryagain flow by inducing a KDC_ERR_ENCTYPE_NOSUPP error on the KDC.
|
||||
realm.run([kadminl, 'setstr', realm.user_princ, 'err', 'testagain'])
|
||||
-expected_trace = ('Sending unauthenticated request',
|
||||
- '/Additional pre-authentication required',
|
||||
- 'Preauthenticating using KDC method data',
|
||||
- 'Processing preauth types:',
|
||||
- 'Preauth module test (-123) (real) returned: 0/Success',
|
||||
- 'Produced preauth for next request: 133, -123',
|
||||
- '/KDC has no support for encryption type',
|
||||
- 'Recovering from KDC error 14 using preauth mech -123',
|
||||
- 'Preauth tryagain input types (-123): -123, 133',
|
||||
- 'Preauth module test (-123) tryagain returned: 0/Success',
|
||||
- 'Followup preauth for next request: -123, 133',
|
||||
- 'Decrypted AS reply')
|
||||
+msgs = ('Sending unauthenticated request',
|
||||
+ '/Additional pre-authentication required',
|
||||
+ 'Preauthenticating using KDC method data',
|
||||
+ 'Processing preauth types:',
|
||||
+ 'Preauth module test (-123) (real) returned: 0/Success',
|
||||
+ 'Produced preauth for next request: PA-FX-COOKIE (133), -123',
|
||||
+ '/KDC has no support for encryption type',
|
||||
+ 'Recovering from KDC error 14 using preauth mech -123',
|
||||
+ 'Preauth tryagain input types (-123): -123, PA-FX-COOKIE (133)',
|
||||
+ 'Preauth module test (-123) tryagain returned: 0/Success',
|
||||
+ 'Followup preauth for next request: -123, PA-FX-COOKIE (133)',
|
||||
+ 'Decrypted AS reply')
|
||||
realm.run(['./icred', realm.user_princ, password('user')],
|
||||
- expected_msg='tryagain: testagain', expected_trace=expected_trace)
|
||||
+ expected_msg='tryagain: testagain', expected_trace=msgs)
|
||||
|
||||
# Test a client-side tryagain failure, falling back to encrypted
|
||||
# timestamp.
|
||||
-expected_trace = ('Sending unauthenticated request',
|
||||
- '/Additional pre-authentication required',
|
||||
- 'Preauthenticating using KDC method data',
|
||||
- 'Processing preauth types:',
|
||||
- 'Preauth module test (-123) (real) returned: 0/Success',
|
||||
- 'Produced preauth for next request: 133, -123',
|
||||
- '/KDC has no support for encryption type',
|
||||
- 'Recovering from KDC error 14 using preauth mech -123',
|
||||
- 'Preauth tryagain input types (-123): -123, 133',
|
||||
- '/induced tryagain fail',
|
||||
- 'Preauthenticating using KDC method data',
|
||||
- 'Processing preauth types:',
|
||||
- 'Encrypted timestamp (for ',
|
||||
- 'module encrypted_timestamp (2) (real) returned: 0/Success',
|
||||
- 'Produced preauth for next request: 133, 2',
|
||||
- 'Decrypted AS reply')
|
||||
+msgs = ('Sending unauthenticated request',
|
||||
+ '/Additional pre-authentication required',
|
||||
+ 'Preauthenticating using KDC method data',
|
||||
+ 'Processing preauth types:',
|
||||
+ 'Preauth module test (-123) (real) returned: 0/Success',
|
||||
+ 'Produced preauth for next request: PA-FX-COOKIE (133), -123',
|
||||
+ '/KDC has no support for encryption type',
|
||||
+ 'Recovering from KDC error 14 using preauth mech -123',
|
||||
+ 'Preauth tryagain input types (-123): -123, PA-FX-COOKIE (133)',
|
||||
+ '/induced tryagain fail',
|
||||
+ 'Preauthenticating using KDC method data',
|
||||
+ 'Processing preauth types:',
|
||||
+ 'Encrypted timestamp (for ',
|
||||
+ 'module encrypted_timestamp (2) (real) returned: 0/Success',
|
||||
+ 'preauth for next request: PA-FX-COOKIE (133), PA-ENC-TIMESTAMP (2)',
|
||||
+ 'Decrypted AS reply')
|
||||
realm.run(['./icred', '-X', 'fail_tryagain', realm.user_princ,
|
||||
- password('user')], expected_trace=expected_trace)
|
||||
+ password('user')], expected_trace=msgs)
|
||||
|
||||
# Test that multiple stepwise initial creds operations can be
|
||||
# performed with the same krb5_context, with proper tracking of
|
||||
35
Log-when-non-root-ksu-authorization-fails.patch
Normal file
35
Log-when-non-root-ksu-authorization-fails.patch
Normal file
|
|
@ -0,0 +1,35 @@
|
|||
From 9dd3a84f324979c29e8ab4b472e98dfa73e6b290 Mon Sep 17 00:00:00 2001
|
||||
From: Robbie Harwood <rharwood@redhat.com>
|
||||
Date: Mon, 7 May 2018 16:42:59 -0400
|
||||
Subject: [PATCH] Log when non-root ksu authorization fails
|
||||
|
||||
If non-root user attempts to ksu but is denied by policy, log to
|
||||
syslog at LOG_WARNING in keeping with other failure messages.
|
||||
|
||||
ticket: 8270
|
||||
(cherry picked from commit 6cfa5c113e981f14f70ccafa20abfa5c46b665ba)
|
||||
---
|
||||
src/clients/ksu/main.c | 10 ++++++++++
|
||||
1 file changed, 10 insertions(+)
|
||||
|
||||
diff --git a/src/clients/ksu/main.c b/src/clients/ksu/main.c
|
||||
index c6321c01b..35ff8978f 100644
|
||||
--- a/src/clients/ksu/main.c
|
||||
+++ b/src/clients/ksu/main.c
|
||||
@@ -417,6 +417,16 @@ main (argc, argv)
|
||||
if (hp){
|
||||
if (gb_err) fprintf(stderr, "%s", gb_err);
|
||||
fprintf(stderr, _("account %s: authorization failed\n"), target_user);
|
||||
+
|
||||
+ if (cmd != NULL) {
|
||||
+ syslog(LOG_WARNING,
|
||||
+ "Account %s: authorization for %s for execution of %s failed",
|
||||
+ target_user, source_user, cmd);
|
||||
+ } else {
|
||||
+ syslog(LOG_WARNING, "Account %s: authorization of %s failed",
|
||||
+ target_user, source_user);
|
||||
+ }
|
||||
+
|
||||
exit(1);
|
||||
}
|
||||
|
||||
36
Make-docs-build-python3-compatible.patch
Normal file
36
Make-docs-build-python3-compatible.patch
Normal file
|
|
@ -0,0 +1,36 @@
|
|||
From 16c745b7e9e239535a8c71dc7022b477a5165e01 Mon Sep 17 00:00:00 2001
|
||||
From: Robbie Harwood <rharwood@redhat.com>
|
||||
Date: Wed, 13 Jun 2018 15:07:48 -0400
|
||||
Subject: [PATCH] Make docs build python3-compatible
|
||||
|
||||
python3 removed execfile(), which we use for loading version data and
|
||||
paths information in docs. Call exec() directly instead.
|
||||
|
||||
ticket: 8692 (new)
|
||||
(cherry picked from commit a7c6d98480f1e33454173f88381921472d72f80a)
|
||||
---
|
||||
doc/conf.py | 4 ++--
|
||||
1 file changed, 2 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/doc/conf.py b/doc/conf.py
|
||||
index 25ba214a8..0555808e6 100644
|
||||
--- a/doc/conf.py
|
||||
+++ b/doc/conf.py
|
||||
@@ -50,7 +50,7 @@ copyright = u'1985-2018, MIT'
|
||||
# The version info for the project you're documenting, acts as replacement for
|
||||
# |version| and |release|, also used in various other places throughout the
|
||||
# built documents.
|
||||
-execfile("version.py")
|
||||
+exec(open("version.py").read())
|
||||
# The short X.Y version.
|
||||
r_list = [r_major, r_minor]
|
||||
if r_patch:
|
||||
@@ -238,7 +238,7 @@ if 'mansubs' in tags:
|
||||
ckeytab = '``@CKTNAME@``'
|
||||
elif 'pathsubs' in tags:
|
||||
# Read configured paths from a file produced by the build system.
|
||||
- execfile('paths.py')
|
||||
+ exec(open("paths.py").read())
|
||||
else:
|
||||
bindir = ':ref:`BINDIR <paths>`'
|
||||
sbindir = ':ref:`SBINDIR <paths>`'
|
||||
297
Make-etype-names-in-KDC-logs-human-readable.patch
Normal file
297
Make-etype-names-in-KDC-logs-human-readable.patch
Normal file
|
|
@ -0,0 +1,297 @@
|
|||
From 3a17abda20fbb92ed20c1466a82fb2c7a656a6ab Mon Sep 17 00:00:00 2001
|
||||
From: Robbie Harwood <rharwood@redhat.com>
|
||||
Date: Tue, 8 Jan 2019 17:42:35 -0500
|
||||
Subject: [PATCH] Make etype names in KDC logs human-readable
|
||||
|
||||
Introduce enctype_name() as a wrapper over krb5_enctype_to_name for
|
||||
converting between registered constants and names. Adjust signatures
|
||||
and rewrite ktypes2str() and rep_etypes2str() to operate on dynamic
|
||||
buffers.
|
||||
|
||||
ticket: 8772 (new)
|
||||
(cherry picked from commit a649279727490687d54becad91fde8cf7429d951)
|
||||
(cherry picked from commit b999ade3996817ccb9c9362e4c06dd236e4a854b)
|
||||
---
|
||||
src/kdc/kdc_log.c | 42 +++++++--------
|
||||
src/kdc/kdc_util.c | 131 +++++++++++++++++++++++----------------------
|
||||
src/kdc/kdc_util.h | 6 +--
|
||||
3 files changed, 90 insertions(+), 89 deletions(-)
|
||||
|
||||
diff --git a/src/kdc/kdc_log.c b/src/kdc/kdc_log.c
|
||||
index 4eec50373..b160ba21a 100644
|
||||
--- a/src/kdc/kdc_log.c
|
||||
+++ b/src/kdc/kdc_log.c
|
||||
@@ -65,7 +65,7 @@ log_as_req(krb5_context context,
|
||||
{
|
||||
const char *fromstring = 0;
|
||||
char fromstringbuf[70];
|
||||
- char ktypestr[128];
|
||||
+ char *ktypestr = NULL;
|
||||
const char *cname2 = cname ? cname : "<unknown client>";
|
||||
const char *sname2 = sname ? sname : "<unknown server>";
|
||||
|
||||
@@ -74,26 +74,29 @@ log_as_req(krb5_context context,
|
||||
fromstringbuf, sizeof(fromstringbuf));
|
||||
if (!fromstring)
|
||||
fromstring = "<unknown>";
|
||||
- ktypes2str(ktypestr, sizeof(ktypestr),
|
||||
- request->nktypes, request->ktype);
|
||||
+
|
||||
+ ktypestr = ktypes2str(request->ktype, request->nktypes);
|
||||
|
||||
if (status == NULL) {
|
||||
/* success */
|
||||
- char rep_etypestr[128];
|
||||
- rep_etypes2str(rep_etypestr, sizeof(rep_etypestr), reply);
|
||||
+ char *rep_etypestr = rep_etypes2str(reply);
|
||||
krb5_klog_syslog(LOG_INFO, _("AS_REQ (%s) %s: ISSUE: authtime %u, %s, "
|
||||
"%s for %s"),
|
||||
- ktypestr, fromstring, (unsigned int)authtime,
|
||||
- rep_etypestr, cname2, sname2);
|
||||
+ ktypestr ? ktypestr : "", fromstring,
|
||||
+ (unsigned int)authtime,
|
||||
+ rep_etypestr ? rep_etypestr : "", cname2, sname2);
|
||||
+ free(rep_etypestr);
|
||||
} else {
|
||||
/* fail */
|
||||
krb5_klog_syslog(LOG_INFO, _("AS_REQ (%s) %s: %s: %s for %s%s%s"),
|
||||
- ktypestr, fromstring, status,
|
||||
- cname2, sname2, emsg ? ", " : "", emsg ? emsg : "");
|
||||
+ ktypestr ? ktypestr : "", fromstring, status, cname2,
|
||||
+ sname2, emsg ? ", " : "", emsg ? emsg : "");
|
||||
}
|
||||
krb5_db_audit_as_req(context, request,
|
||||
local_addr->address, remote_addr->address,
|
||||
client, server, authtime, errcode);
|
||||
+
|
||||
+ free(ktypestr);
|
||||
}
|
||||
|
||||
/*
|
||||
@@ -122,10 +125,9 @@ log_tgs_req(krb5_context ctx, const krb5_fulladdr *from,
|
||||
unsigned int c_flags,
|
||||
const char *status, krb5_error_code errcode, const char *emsg)
|
||||
{
|
||||
- char ktypestr[128];
|
||||
+ char *ktypestr = NULL, *rep_etypestr = NULL;
|
||||
const char *fromstring = 0;
|
||||
char fromstringbuf[70];
|
||||
- char rep_etypestr[128];
|
||||
char *cname = NULL, *sname = NULL, *altcname = NULL;
|
||||
char *logcname = NULL, *logsname = NULL, *logaltcname = NULL;
|
||||
|
||||
@@ -134,11 +136,6 @@ log_tgs_req(krb5_context ctx, const krb5_fulladdr *from,
|
||||
fromstringbuf, sizeof(fromstringbuf));
|
||||
if (!fromstring)
|
||||
fromstring = "<unknown>";
|
||||
- ktypes2str(ktypestr, sizeof(ktypestr), request->nktypes, request->ktype);
|
||||
- if (!errcode)
|
||||
- rep_etypes2str(rep_etypestr, sizeof(rep_etypestr), reply);
|
||||
- else
|
||||
- rep_etypestr[0] = 0;
|
||||
|
||||
unparse_and_limit(ctx, cprinc, &cname);
|
||||
logcname = (cname != NULL) ? cname : "<unknown client>";
|
||||
@@ -151,10 +148,14 @@ log_tgs_req(krb5_context ctx, const krb5_fulladdr *from,
|
||||
name (useful), and doesn't log ktypestr (probably not
|
||||
important). */
|
||||
if (errcode != KRB5KDC_ERR_SERVER_NOMATCH) {
|
||||
+ ktypestr = ktypes2str(request->ktype, request->nktypes);
|
||||
+ rep_etypestr = rep_etypes2str(reply);
|
||||
krb5_klog_syslog(LOG_INFO, _("TGS_REQ (%s) %s: %s: authtime %u, %s%s "
|
||||
"%s for %s%s%s"),
|
||||
- ktypestr, fromstring, status, (unsigned int)authtime,
|
||||
- rep_etypestr, !errcode ? "," : "", logcname, logsname,
|
||||
+ ktypestr ? ktypestr : "", fromstring, status,
|
||||
+ (unsigned int)authtime,
|
||||
+ rep_etypestr ? rep_etypestr : "",
|
||||
+ !errcode ? "," : "", logcname, logsname,
|
||||
errcode ? ", " : "", errcode ? emsg : "");
|
||||
if (isflagset(c_flags, KRB5_KDB_FLAG_PROTOCOL_TRANSITION))
|
||||
krb5_klog_syslog(LOG_INFO,
|
||||
@@ -171,9 +172,8 @@ log_tgs_req(krb5_context ctx, const krb5_fulladdr *from,
|
||||
fromstring, status, (unsigned int)authtime,
|
||||
logcname, logsname, logaltcname);
|
||||
|
||||
- /* OpenSolaris: audit_krb5kdc_tgs_req(...) or
|
||||
- audit_krb5kdc_tgs_req_2ndtktmm(...) */
|
||||
-
|
||||
+ free(rep_etypestr);
|
||||
+ free(ktypestr);
|
||||
krb5_free_unparsed_name(ctx, cname);
|
||||
krb5_free_unparsed_name(ctx, sname);
|
||||
krb5_free_unparsed_name(ctx, altcname);
|
||||
diff --git a/src/kdc/kdc_util.c b/src/kdc/kdc_util.c
|
||||
index 13111215d..6f83be9db 100644
|
||||
--- a/src/kdc/kdc_util.c
|
||||
+++ b/src/kdc/kdc_util.c
|
||||
@@ -1043,84 +1043,87 @@ void limit_string(char *name)
|
||||
return;
|
||||
}
|
||||
|
||||
-/*
|
||||
- * L10_2 = log10(2**x), rounded up; log10(2) ~= 0.301.
|
||||
- */
|
||||
-#define L10_2(x) ((int)(((x * 301) + 999) / 1000))
|
||||
-
|
||||
-/*
|
||||
- * Max length of sprintf("%ld") for an int of type T; includes leading
|
||||
- * minus sign and terminating NUL.
|
||||
- */
|
||||
-#define D_LEN(t) (L10_2(sizeof(t) * CHAR_BIT) + 2)
|
||||
-
|
||||
-void
|
||||
-ktypes2str(char *s, size_t len, int nktypes, krb5_enctype *ktype)
|
||||
+/* Wrapper of krb5_enctype_to_name() to include the PKINIT types. */
|
||||
+static krb5_error_code
|
||||
+enctype_name(krb5_enctype ktype, char *buf, size_t buflen)
|
||||
{
|
||||
- int i;
|
||||
- char stmp[D_LEN(krb5_enctype) + 1];
|
||||
- char *p;
|
||||
+ char *name;
|
||||
|
||||
- if (nktypes < 0
|
||||
- || len < (sizeof(" etypes {...}") + D_LEN(int))) {
|
||||
- *s = '\0';
|
||||
- return;
|
||||
- }
|
||||
+ if (buflen == 0)
|
||||
+ return EINVAL;
|
||||
+ *buf = '\0'; /* ensure these are always valid C-strings */
|
||||
|
||||
- snprintf(s, len, "%d etypes {", nktypes);
|
||||
- for (i = 0; i < nktypes; i++) {
|
||||
- snprintf(stmp, sizeof(stmp), "%s%ld", i ? " " : "", (long)ktype[i]);
|
||||
- if (strlen(s) + strlen(stmp) + sizeof("}") > len)
|
||||
- break;
|
||||
- strlcat(s, stmp, len);
|
||||
- }
|
||||
- if (i < nktypes) {
|
||||
- /*
|
||||
- * We broke out of the loop. Try to truncate the list.
|
||||
- */
|
||||
- p = s + strlen(s);
|
||||
- while (p - s + sizeof("...}") > len) {
|
||||
- while (p > s && *p != ' ' && *p != '{')
|
||||
- *p-- = '\0';
|
||||
- if (p > s && *p == ' ') {
|
||||
- *p-- = '\0';
|
||||
- continue;
|
||||
- }
|
||||
- }
|
||||
- strlcat(s, "...", len);
|
||||
- }
|
||||
- strlcat(s, "}", len);
|
||||
- return;
|
||||
+ /* rfc4556 recommends that clients wishing to indicate support for these
|
||||
+ * pkinit algorithms include them in the etype field of the AS-REQ. */
|
||||
+ if (ktype == ENCTYPE_DSA_SHA1_CMS)
|
||||
+ name = "id-dsa-with-sha1-CmsOID";
|
||||
+ else if (ktype == ENCTYPE_MD5_RSA_CMS)
|
||||
+ name = "md5WithRSAEncryption-CmsOID";
|
||||
+ else if (ktype == ENCTYPE_SHA1_RSA_CMS)
|
||||
+ name = "sha-1WithRSAEncryption-CmsOID";
|
||||
+ else if (ktype == ENCTYPE_RC2_CBC_ENV)
|
||||
+ name = "rc2-cbc-EnvOID";
|
||||
+ else if (ktype == ENCTYPE_RSA_ENV)
|
||||
+ name = "rsaEncryption-EnvOID";
|
||||
+ else if (ktype == ENCTYPE_RSA_ES_OAEP_ENV)
|
||||
+ name = "id-RSAES-OAEP-EnvOID";
|
||||
+ else if (ktype == ENCTYPE_DES3_CBC_ENV)
|
||||
+ name = "des-ede3-cbc-EnvOID";
|
||||
+ else
|
||||
+ return krb5_enctype_to_name(ktype, FALSE, buf, buflen);
|
||||
+
|
||||
+ if (strlcpy(name, buf, buflen) >= buflen)
|
||||
+ return ENOMEM;
|
||||
+ return 0;
|
||||
}
|
||||
|
||||
-void
|
||||
-rep_etypes2str(char *s, size_t len, krb5_kdc_rep *rep)
|
||||
+char *
|
||||
+ktypes2str(krb5_enctype *ktype, int nktypes)
|
||||
{
|
||||
- char stmp[sizeof("ses=") + D_LEN(krb5_enctype)];
|
||||
+ struct k5buf buf;
|
||||
+ int i;
|
||||
+ char name[64];
|
||||
|
||||
- if (len < (3 * D_LEN(krb5_enctype)
|
||||
- + sizeof("etypes {rep= tkt= ses=}"))) {
|
||||
- *s = '\0';
|
||||
- return;
|
||||
+ if (nktypes < 0)
|
||||
+ return NULL;
|
||||
+
|
||||
+ k5_buf_init_dynamic(&buf);
|
||||
+ k5_buf_add_fmt(&buf, "%d etypes {", nktypes);
|
||||
+ for (i = 0; i < nktypes; i++) {
|
||||
+ enctype_name(ktype[i], name, sizeof(name));
|
||||
+ k5_buf_add_fmt(&buf, "%s%s(%ld)", i ? ", " : "", name, (long)ktype[i]);
|
||||
}
|
||||
+ k5_buf_add(&buf, "}");
|
||||
+ return buf.data;
|
||||
+}
|
||||
|
||||
- snprintf(s, len, "etypes {rep=%ld", (long)rep->enc_part.enctype);
|
||||
+char *
|
||||
+rep_etypes2str(krb5_kdc_rep *rep)
|
||||
+{
|
||||
+ struct k5buf buf;
|
||||
+ char name[64];
|
||||
+ krb5_enctype etype;
|
||||
+
|
||||
+ k5_buf_init_dynamic(&buf);
|
||||
+ k5_buf_add(&buf, "etypes {rep=");
|
||||
+ enctype_name(rep->enc_part.enctype, name, sizeof(name));
|
||||
+ k5_buf_add_fmt(&buf, "%s(%ld)", name, (long)rep->enc_part.enctype);
|
||||
|
||||
if (rep->ticket != NULL) {
|
||||
- snprintf(stmp, sizeof(stmp),
|
||||
- " tkt=%ld", (long)rep->ticket->enc_part.enctype);
|
||||
- strlcat(s, stmp, len);
|
||||
+ etype = rep->ticket->enc_part.enctype;
|
||||
+ enctype_name(etype, name, sizeof(name));
|
||||
+ k5_buf_add_fmt(&buf, ", tkt=%s(%ld)", name, (long)etype);
|
||||
}
|
||||
|
||||
- if (rep->ticket != NULL
|
||||
- && rep->ticket->enc_part2 != NULL
|
||||
- && rep->ticket->enc_part2->session != NULL) {
|
||||
- snprintf(stmp, sizeof(stmp), " ses=%ld",
|
||||
- (long)rep->ticket->enc_part2->session->enctype);
|
||||
- strlcat(s, stmp, len);
|
||||
+ if (rep->ticket != NULL && rep->ticket->enc_part2 != NULL &&
|
||||
+ rep->ticket->enc_part2->session != NULL) {
|
||||
+ etype = rep->ticket->enc_part2->session->enctype;
|
||||
+ enctype_name(etype, name, sizeof(name));
|
||||
+ k5_buf_add_fmt(&buf, ", ses=%s(%ld)", name, (long)etype);
|
||||
}
|
||||
- strlcat(s, "}", len);
|
||||
- return;
|
||||
+
|
||||
+ k5_buf_add(&buf, "}");
|
||||
+ return buf.data;
|
||||
}
|
||||
|
||||
static krb5_error_code
|
||||
diff --git a/src/kdc/kdc_util.h b/src/kdc/kdc_util.h
|
||||
index 1885c9f80..8085e625a 100644
|
||||
--- a/src/kdc/kdc_util.h
|
||||
+++ b/src/kdc/kdc_util.h
|
||||
@@ -110,11 +110,9 @@ select_session_keytype (kdc_realm_t *kdc_active_realm,
|
||||
|
||||
void limit_string (char *name);
|
||||
|
||||
-void
|
||||
-ktypes2str(char *s, size_t len, int nktypes, krb5_enctype *ktype);
|
||||
+char *ktypes2str(krb5_enctype *ktype, int nktypes);
|
||||
|
||||
-void
|
||||
-rep_etypes2str(char *s, size_t len, krb5_kdc_rep *rep);
|
||||
+char *rep_etypes2str(krb5_kdc_rep *rep);
|
||||
|
||||
/* authind.c */
|
||||
krb5_boolean
|
||||
67
Make-krb5kdc-p-affect-TCP-ports.patch
Normal file
67
Make-krb5kdc-p-affect-TCP-ports.patch
Normal file
|
|
@ -0,0 +1,67 @@
|
|||
From 5587c1de938324faa1871e08ccfc835415acb443 Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Tue, 17 Jul 2018 11:29:19 -0400
|
||||
Subject: [PATCH] Make krb5kdc -p affect TCP ports
|
||||
|
||||
Now that the KDC listens for TCP connections by default (ticket 6731),
|
||||
the "-p" option should affect both UDP and TCP default listening
|
||||
ports.
|
||||
|
||||
ticket: 8715 (new)
|
||||
(cherry picked from commit eb514587acc5c357bf0f554199bf0489b5515f8b)
|
||||
---
|
||||
doc/admin/admin_commands/krb5kdc.rst | 12 ++++++------
|
||||
src/kdc/main.c | 12 ++++--------
|
||||
2 files changed, 10 insertions(+), 14 deletions(-)
|
||||
|
||||
diff --git a/doc/admin/admin_commands/krb5kdc.rst b/doc/admin/admin_commands/krb5kdc.rst
|
||||
index 7ec4ee4d3..bda2c015c 100644
|
||||
--- a/doc/admin/admin_commands/krb5kdc.rst
|
||||
+++ b/doc/admin/admin_commands/krb5kdc.rst
|
||||
@@ -57,12 +57,12 @@ The **-P** *pid_file* option tells the KDC to write its PID into
|
||||
the KDC is still running and to allow init scripts to stop the correct
|
||||
process.
|
||||
|
||||
-The **-p** *portnum* option specifies the default UDP port numbers
|
||||
-which the KDC should listen on for Kerberos version 5 requests, as a
|
||||
-comma-separated list. This value overrides the UDP port numbers
|
||||
-specified in the :ref:`kdcdefaults` section of :ref:`kdc.conf(5)`, but
|
||||
-may be overridden by realm-specific values. If no value is given from
|
||||
-any source, the default port is 88.
|
||||
+The **-p** *portnum* option specifies the default UDP and TCP port
|
||||
+numbers which the KDC should listen on for Kerberos version 5
|
||||
+requests, as a comma-separated list. This value overrides the port
|
||||
+numbers specified in the :ref:`kdcdefaults` section of
|
||||
+:ref:`kdc.conf(5)`, but may be overridden by realm-specific values.
|
||||
+If no value is given from any source, the default port is 88.
|
||||
|
||||
The **-w** *numworkers* option tells the KDC to fork *numworkers*
|
||||
processes to listen to the KDC ports and process requests in parallel.
|
||||
diff --git a/src/kdc/main.c b/src/kdc/main.c
|
||||
index ccac3a759..89dac23ae 100644
|
||||
--- a/src/kdc/main.c
|
||||
+++ b/src/kdc/main.c
|
||||
@@ -793,19 +793,15 @@ initialize_realms(krb5_context kcontext, int argc, char **argv,
|
||||
pid_file = optarg;
|
||||
break;
|
||||
case 'p':
|
||||
- if (def_udp_listen)
|
||||
- free(def_udp_listen);
|
||||
+ free(def_udp_listen);
|
||||
+ free(def_tcp_listen);
|
||||
def_udp_listen = strdup(optarg);
|
||||
- if (!def_udp_listen) {
|
||||
+ def_tcp_listen = strdup(optarg);
|
||||
+ if (def_udp_listen == NULL || def_tcp_listen == NULL) {
|
||||
fprintf(stderr, _(" KDC cannot initialize. Not enough "
|
||||
"memory\n"));
|
||||
exit(1);
|
||||
}
|
||||
-#if 0 /* not yet */
|
||||
- if (default_tcp_ports)
|
||||
- free(default_tcp_ports);
|
||||
- default_tcp_ports = strdup(optarg);
|
||||
-#endif
|
||||
break;
|
||||
case 'T':
|
||||
time_offset = atoi(optarg);
|
||||
251
Mark-deprecated-enctypes-when-used.patch
Normal file
251
Mark-deprecated-enctypes-when-used.patch
Normal file
|
|
@ -0,0 +1,251 @@
|
|||
From 378f2ade14ec9bd2f5ab7b0e69d5437e51066584 Mon Sep 17 00:00:00 2001
|
||||
From: Robbie Harwood <rharwood@redhat.com>
|
||||
Date: Thu, 10 Jan 2019 16:34:54 -0500
|
||||
Subject: [PATCH] Mark deprecated enctypes when used
|
||||
|
||||
Preface ETYPE_DEPRECATED enctypes with "DEPRECATED:" in klist output,
|
||||
KDC logs, and kadmin interactions. Also complain in krb5kdc when the
|
||||
stash file has a deprecated enctype or a deprecated enctype is
|
||||
requested with -k.
|
||||
|
||||
ticket: 8773 (new)
|
||||
(cherry picked from commit 8d8e68283b599e680f9fe45eff8af397e827bd6c)
|
||||
(cherry picked from commit 1d1db003481768092410dc36a41e240c48a136e0)
|
||||
---
|
||||
src/clients/klist/klist.c | 14 ++++++++++----
|
||||
src/kadmin/cli/kadmin.c | 6 +++++-
|
||||
src/kdc/kdc_util.c | 9 +++++++++
|
||||
src/kdc/main.c | 19 +++++++++++++++++++
|
||||
src/tests/gssapi/t_enctypes.py | 15 +++++++++------
|
||||
src/tests/t_keyrollover.py | 8 +++++---
|
||||
src/tests/t_sesskeynego.py | 4 ++--
|
||||
7 files changed, 59 insertions(+), 16 deletions(-)
|
||||
|
||||
diff --git a/src/clients/klist/klist.c b/src/clients/klist/klist.c
|
||||
index e9e76d8f3..8b24b30bc 100644
|
||||
--- a/src/clients/klist/klist.c
|
||||
+++ b/src/clients/klist/klist.c
|
||||
@@ -573,11 +573,17 @@ static char *
|
||||
etype_string(krb5_enctype enctype)
|
||||
{
|
||||
static char buf[100];
|
||||
- krb5_error_code ret;
|
||||
+ char *bp = buf;
|
||||
+ size_t deplen, buflen = sizeof(buf);
|
||||
|
||||
- ret = krb5_enctype_to_name(enctype, FALSE, buf, sizeof(buf));
|
||||
- if (ret)
|
||||
- snprintf(buf, sizeof(buf), "etype %d", enctype);
|
||||
+ if (krb5int_c_deprecated_enctype(enctype)) {
|
||||
+ deplen = strlcpy(bp, "DEPRECATED:", buflen);
|
||||
+ buflen -= deplen;
|
||||
+ bp += deplen;
|
||||
+ }
|
||||
+
|
||||
+ if (krb5_enctype_to_name(enctype, FALSE, bp, buflen))
|
||||
+ snprintf(bp, buflen, "etype %d", enctype);
|
||||
return buf;
|
||||
}
|
||||
|
||||
diff --git a/src/kadmin/cli/kadmin.c b/src/kadmin/cli/kadmin.c
|
||||
index aee5c83b9..a1db55026 100644
|
||||
--- a/src/kadmin/cli/kadmin.c
|
||||
+++ b/src/kadmin/cli/kadmin.c
|
||||
@@ -1449,12 +1449,16 @@ kadmin_getprinc(int argc, char *argv[])
|
||||
for (i = 0; i < dprinc.n_key_data; i++) {
|
||||
krb5_key_data *key_data = &dprinc.key_data[i];
|
||||
char enctype[BUFSIZ], salttype[BUFSIZ];
|
||||
+ char *deprecated = "";
|
||||
|
||||
if (krb5_enctype_to_name(key_data->key_data_type[0], FALSE,
|
||||
enctype, sizeof(enctype)))
|
||||
snprintf(enctype, sizeof(enctype), _("<Encryption type 0x%x>"),
|
||||
key_data->key_data_type[0]);
|
||||
- printf("Key: vno %d, %s", key_data->key_data_kvno, enctype);
|
||||
+ if (krb5int_c_deprecated_enctype(key_data->key_data_type[0]))
|
||||
+ deprecated = "DEPRECATED:";
|
||||
+ printf("Key: vno %d, %s%s", key_data->key_data_kvno, deprecated,
|
||||
+ enctype);
|
||||
if (key_data->key_data_ver > 1 &&
|
||||
key_data->key_data_type[1] != KRB5_KDB_SALTTYPE_NORMAL) {
|
||||
if (krb5_salttype_to_string(key_data->key_data_type[1],
|
||||
diff --git a/src/kdc/kdc_util.c b/src/kdc/kdc_util.c
|
||||
index 6f83be9db..e98efd3df 100644
|
||||
--- a/src/kdc/kdc_util.c
|
||||
+++ b/src/kdc/kdc_util.c
|
||||
@@ -1048,11 +1048,20 @@ static krb5_error_code
|
||||
enctype_name(krb5_enctype ktype, char *buf, size_t buflen)
|
||||
{
|
||||
char *name;
|
||||
+ size_t len;
|
||||
|
||||
if (buflen == 0)
|
||||
return EINVAL;
|
||||
*buf = '\0'; /* ensure these are always valid C-strings */
|
||||
|
||||
+ if (krb5int_c_deprecated_enctype(ktype)) {
|
||||
+ len = strlcpy(buf, "DEPRECATED:", buflen);
|
||||
+ if (len >= buflen)
|
||||
+ return ENOMEM;
|
||||
+ buflen -= len;
|
||||
+ buf += len;
|
||||
+ }
|
||||
+
|
||||
/* rfc4556 recommends that clients wishing to indicate support for these
|
||||
* pkinit algorithms include them in the etype field of the AS-REQ. */
|
||||
if (ktype == ENCTYPE_DSA_SHA1_CMS)
|
||||
diff --git a/src/kdc/main.c b/src/kdc/main.c
|
||||
index 89dac23ae..78ddeed72 100644
|
||||
--- a/src/kdc/main.c
|
||||
+++ b/src/kdc/main.c
|
||||
@@ -214,12 +214,23 @@ init_realm(kdc_realm_t * rdp, krb5_pointer aprof, char *realm,
|
||||
char *svalue = NULL;
|
||||
const char *hierarchy[4];
|
||||
krb5_kvno mkvno = IGNORE_VNO;
|
||||
+ char ename[32];
|
||||
|
||||
memset(rdp, 0, sizeof(kdc_realm_t));
|
||||
if (!realm) {
|
||||
kret = EINVAL;
|
||||
goto whoops;
|
||||
}
|
||||
+
|
||||
+ if (def_enctype != ENCTYPE_UNKNOWN &&
|
||||
+ krb5int_c_deprecated_enctype(def_enctype)) {
|
||||
+ if (krb5_enctype_to_name(def_enctype, FALSE, ename, sizeof(ename)))
|
||||
+ ename[0] = '\0';
|
||||
+ fprintf(stderr,
|
||||
+ _("Requested master password enctype %s in %s is DEPRECATED!"),
|
||||
+ ename, realm);
|
||||
+ }
|
||||
+
|
||||
hierarchy[0] = KRB5_CONF_REALMS;
|
||||
hierarchy[1] = realm;
|
||||
hierarchy[3] = NULL;
|
||||
@@ -374,6 +385,14 @@ init_realm(kdc_realm_t * rdp, krb5_pointer aprof, char *realm,
|
||||
goto whoops;
|
||||
}
|
||||
|
||||
+ if (krb5int_c_deprecated_enctype(rdp->realm_mkey.enctype)) {
|
||||
+ if (krb5_enctype_to_name(rdp->realm_mkey.enctype, FALSE, ename,
|
||||
+ sizeof(ename)))
|
||||
+ ename[0] = '\0';
|
||||
+ fprintf(stderr, _("Stash file %s uses DEPRECATED enctype %s!"),
|
||||
+ rdp->realm_stash, ename);
|
||||
+ }
|
||||
+
|
||||
if ((kret = krb5_db_fetch_mkey_list(rdp->realm_context, rdp->realm_mprinc,
|
||||
&rdp->realm_mkey))) {
|
||||
kdc_err(rdp->realm_context, kret,
|
||||
diff --git a/src/tests/gssapi/t_enctypes.py b/src/tests/gssapi/t_enctypes.py
|
||||
index 5d9f80e04..ca3d32d21 100755
|
||||
--- a/src/tests/gssapi/t_enctypes.py
|
||||
+++ b/src/tests/gssapi/t_enctypes.py
|
||||
@@ -9,8 +9,11 @@ from k5test import *
|
||||
aes256 = 'aes256-cts-hmac-sha1-96'
|
||||
aes128 = 'aes128-cts-hmac-sha1-96'
|
||||
des3 = 'des3-cbc-sha1'
|
||||
+d_des3 = 'DEPRECATED:des3-cbc-sha1'
|
||||
des3raw = 'des3-cbc-raw'
|
||||
+d_des3raw = 'DEPRECATED:des3-cbc-raw'
|
||||
rc4 = 'arcfour-hmac'
|
||||
+d_rc4 = 'DEPRECATED:arcfour-hmac'
|
||||
|
||||
# These tests make assumptions about the default enctype lists, so set
|
||||
# them explicitly rather than relying on the library defaults.
|
||||
@@ -92,7 +95,7 @@ test_err('acc aes128', None, 'aes128-cts',
|
||||
# no acceptor subkey will be generated because we can't upgrade to a
|
||||
# CFX enctype.
|
||||
test('init des3', 'des3', None,
|
||||
- tktenc=aes256, tktsession=des3,
|
||||
+ tktenc=aes256, tktsession=d_des3,
|
||||
proto='rfc1964', isubkey=des3raw, asubkey=None)
|
||||
|
||||
# Force the ticket session key to be rc4, so we can test some subkey
|
||||
@@ -103,7 +106,7 @@ realm.run([kadminl, 'setstr', realm.host_princ, 'session_enctypes', 'rc4'])
|
||||
# [aes256 aes128 des3] and the acceptor should upgrade to an aes256
|
||||
# subkey.
|
||||
test('upgrade noargs', None, None,
|
||||
- tktenc=aes256, tktsession=rc4,
|
||||
+ tktenc=aes256, tktsession=d_rc4,
|
||||
proto='cfx', isubkey=rc4, asubkey=aes256)
|
||||
|
||||
# If the initiator won't permit rc4 as a session key, it won't be able
|
||||
@@ -113,14 +116,14 @@ test_err('upgrade init aes', 'aes', None, 'no support for encryption type')
|
||||
# If the initiator permits rc4 but prefers aes128, it will send an
|
||||
# upgrade list of [aes128] and the acceptor will upgrade to aes128.
|
||||
test('upgrade init aes128+rc4', 'aes128-cts rc4', None,
|
||||
- tktenc=aes256, tktsession=rc4,
|
||||
+ tktenc=aes256, tktsession=d_rc4,
|
||||
proto='cfx', isubkey=rc4, asubkey=aes128)
|
||||
|
||||
# If the initiator permits rc4 but prefers des3, it will send an
|
||||
# upgrade list of [des3], but the acceptor won't generate a subkey
|
||||
# because des3 isn't a CFX enctype.
|
||||
test('upgrade init des3+rc4', 'des3 rc4', None,
|
||||
- tktenc=aes256, tktsession=rc4,
|
||||
+ tktenc=aes256, tktsession=d_rc4,
|
||||
proto='rfc1964', isubkey=rc4, asubkey=None)
|
||||
|
||||
# If the acceptor permits only aes128, subkey negotiation will fail
|
||||
@@ -134,14 +137,14 @@ test_err('upgrade acc aes128', None, 'aes128-cts',
|
||||
# If the acceptor permits rc4 but prefers aes128, it will negotiate an
|
||||
# upgrade to aes128.
|
||||
test('upgrade acc aes128 rc4', None, 'aes128-cts rc4',
|
||||
- tktenc=aes256, tktsession=rc4,
|
||||
+ tktenc=aes256, tktsession=d_rc4,
|
||||
proto='cfx', isubkey=rc4, asubkey=aes128)
|
||||
|
||||
# In this test, the initiator and acceptor each prefer an AES enctype
|
||||
# to rc4, but they can't agree on which one, so no subkey is
|
||||
# generated.
|
||||
test('upgrade mismatch', 'aes128-cts rc4', 'aes256-cts rc4',
|
||||
- tktenc=aes256, tktsession=rc4,
|
||||
+ tktenc=aes256, tktsession=d_rc4,
|
||||
proto='rfc1964', isubkey=rc4, asubkey=None)
|
||||
|
||||
success('gss_krb5_set_allowable_enctypes tests')
|
||||
diff --git a/src/tests/t_keyrollover.py b/src/tests/t_keyrollover.py
|
||||
index 7c8d828f0..4af6804f2 100755
|
||||
--- a/src/tests/t_keyrollover.py
|
||||
+++ b/src/tests/t_keyrollover.py
|
||||
@@ -22,8 +22,9 @@ realm.run([kvno, princ1])
|
||||
realm.run([kadminl, 'purgekeys', realm.krbtgt_princ])
|
||||
# Make sure an old TGT fails after purging old TGS key.
|
||||
realm.run([kvno, princ2], expected_code=1)
|
||||
-msg = 'krbtgt/%s@%s\n\tEtype (skey, tkt): des-cbc-crc, des-cbc-crc' % \
|
||||
- (realm.realm, realm.realm)
|
||||
+ddes = "DEPRECATED:des-cbc-crc"
|
||||
+msg = 'krbtgt/%s@%s\n\tEtype (skey, tkt): %s, %s' % \
|
||||
+ (realm.realm, realm.realm, ddes, ddes)
|
||||
realm.run([klist, '-e'], expected_msg=msg)
|
||||
|
||||
# Check that new key actually works.
|
||||
@@ -48,7 +49,8 @@ realm.run([kadminl, 'cpw', '-randkey', '-keepold', '-e', 'aes256-cts',
|
||||
realm.krbtgt_princ])
|
||||
realm.run([kadminl, 'modprinc', '-kvno', '1', realm.krbtgt_princ])
|
||||
out = realm.run([kadminl, 'getprinc', realm.krbtgt_princ])
|
||||
-if 'vno 1, aes256' not in out or 'vno 1, des3' not in out:
|
||||
+if 'vno 1, aes256-cts' not in out or \
|
||||
+ 'vno 1, DEPRECATED:des3-cbc-sha1' not in out:
|
||||
fail('keyrollover: setup for TGS enctype test failed')
|
||||
# Now present the DES3 ticket to the KDC and make sure it's rejected.
|
||||
realm.run([kvno, realm.host_princ], expected_code=1)
|
||||
diff --git a/src/tests/t_sesskeynego.py b/src/tests/t_sesskeynego.py
|
||||
index 448092387..da02f224a 100755
|
||||
--- a/src/tests/t_sesskeynego.py
|
||||
+++ b/src/tests/t_sesskeynego.py
|
||||
@@ -62,11 +62,11 @@ test_kvno(realm, 'aes128-cts-hmac-sha1-96', 'aes256-cts-hmac-sha1-96')
|
||||
# 3b: Negotiate rc4-hmac session key when principal only has aes256 long-term.
|
||||
realm.run([kadminl, 'setstr', 'server', 'session_enctypes',
|
||||
'rc4-hmac,aes128-cts,aes256-cts'])
|
||||
-test_kvno(realm, 'arcfour-hmac', 'aes256-cts-hmac-sha1-96')
|
||||
+test_kvno(realm, 'DEPRECATED:arcfour-hmac', 'aes256-cts-hmac-sha1-96')
|
||||
|
||||
# 3c: Test des-cbc-crc default assumption.
|
||||
realm.run([kadminl, 'delstr', 'server', 'session_enctypes'])
|
||||
-test_kvno(realm, 'des-cbc-crc', 'aes256-cts-hmac-sha1-96')
|
||||
+test_kvno(realm, 'DEPRECATED:des-cbc-crc', 'aes256-cts-hmac-sha1-96')
|
||||
realm.stop()
|
||||
|
||||
# Last go: test that we can disable the des-cbc-crc assumption
|
||||
151
Move-zap-definition-to-k5-platform.h.patch
Normal file
151
Move-zap-definition-to-k5-platform.h.patch
Normal file
|
|
@ -0,0 +1,151 @@
|
|||
From ee941a490268bb045ec7e153bdf229adcd6d2f73 Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Mon, 26 Mar 2018 10:54:29 -0400
|
||||
Subject: [PATCH] Move zap() definition to k5-platform.h
|
||||
|
||||
Make it possible to use zap() in parts of the code which should not
|
||||
include k5-int.h by moving its definition to k5-platform.h.
|
||||
|
||||
(cherry picked from commit df6bef6f9ea6a5f6f3956a2988cd658c78aae817)
|
||||
---
|
||||
src/include/k5-int.h | 45 -------------------------------------
|
||||
src/include/k5-platform.h | 47 ++++++++++++++++++++++++++++++++++++++-
|
||||
src/util/support/zap.c | 4 ++--
|
||||
3 files changed, 48 insertions(+), 48 deletions(-)
|
||||
|
||||
diff --git a/src/include/k5-int.h b/src/include/k5-int.h
|
||||
index 1c1d9783b..69b81a7f7 100644
|
||||
--- a/src/include/k5-int.h
|
||||
+++ b/src/include/k5-int.h
|
||||
@@ -639,51 +639,6 @@ krb5int_arcfour_gsscrypt(const krb5_keyblock *keyblock, krb5_keyusage usage,
|
||||
krb5_error_code
|
||||
k5_sha256(const krb5_data *in, size_t n, uint8_t out[K5_SHA256_HASHLEN]);
|
||||
|
||||
-/*
|
||||
- * Attempt to zero memory in a way that compilers won't optimize out.
|
||||
- *
|
||||
- * This mechanism should work even for heap storage about to be freed,
|
||||
- * or automatic storage right before we return from a function.
|
||||
- *
|
||||
- * Then, even if we leak uninitialized memory someplace, or UNIX
|
||||
- * "core" files get created with world-read access, some of the most
|
||||
- * sensitive data in the process memory will already be safely wiped.
|
||||
- *
|
||||
- * We're not going so far -- yet -- as to try to protect key data that
|
||||
- * may have been written into swap space....
|
||||
- */
|
||||
-#ifdef _WIN32
|
||||
-# define zap(ptr, len) SecureZeroMemory(ptr, len)
|
||||
-#elif defined(__STDC_LIB_EXT1__)
|
||||
-/*
|
||||
- * Use memset_s() which cannot be optimized out. Avoid memset_s(NULL, 0, 0, 0)
|
||||
- * which would cause a runtime constraint violation.
|
||||
- */
|
||||
-static inline void zap(void *ptr, size_t len)
|
||||
-{
|
||||
- if (len > 0)
|
||||
- memset_s(ptr, len, 0, len);
|
||||
-}
|
||||
-#elif defined(__GNUC__) || defined(__clang__)
|
||||
-/*
|
||||
- * Use an asm statement which declares a memory clobber to force the memset to
|
||||
- * be carried out. Avoid memset(NULL, 0, 0) which has undefined behavior.
|
||||
- */
|
||||
-static inline void zap(void *ptr, size_t len)
|
||||
-{
|
||||
- if (len > 0)
|
||||
- memset(ptr, 0, len);
|
||||
- __asm__ __volatile__("" : : "r" (ptr) : "memory");
|
||||
-}
|
||||
-#else
|
||||
-/*
|
||||
- * Use a function from libkrb5support to defeat inlining unless link-time
|
||||
- * optimization is used. The function uses a volatile pointer, which prevents
|
||||
- * current compilers from optimizing out the memset.
|
||||
- */
|
||||
-# define zap(ptr, len) krb5int_zap(ptr, len)
|
||||
-#endif
|
||||
-
|
||||
/* Convenience function: zap and free ptr if it is non-NULL. */
|
||||
static inline void
|
||||
zapfree(void *ptr, size_t len)
|
||||
diff --git a/src/include/k5-platform.h b/src/include/k5-platform.h
|
||||
index 548c0486d..07ef6a4ca 100644
|
||||
--- a/src/include/k5-platform.h
|
||||
+++ b/src/include/k5-platform.h
|
||||
@@ -40,7 +40,7 @@
|
||||
* + [v]asprintf
|
||||
* + strerror_r
|
||||
* + mkstemp
|
||||
- * + zap (support function; macro is in k5-int.h)
|
||||
+ * + zap (support function and macro)
|
||||
* + constant time memory comparison
|
||||
* + path manipulation
|
||||
* + _, N_, dgettext, bindtextdomain (for localization)
|
||||
@@ -1022,6 +1022,51 @@ extern int krb5int_gettimeofday(struct timeval *tp, void *ignore);
|
||||
#define gettimeofday krb5int_gettimeofday
|
||||
#endif
|
||||
|
||||
+/*
|
||||
+ * Attempt to zero memory in a way that compilers won't optimize out.
|
||||
+ *
|
||||
+ * This mechanism should work even for heap storage about to be freed,
|
||||
+ * or automatic storage right before we return from a function.
|
||||
+ *
|
||||
+ * Then, even if we leak uninitialized memory someplace, or UNIX
|
||||
+ * "core" files get created with world-read access, some of the most
|
||||
+ * sensitive data in the process memory will already be safely wiped.
|
||||
+ *
|
||||
+ * We're not going so far -- yet -- as to try to protect key data that
|
||||
+ * may have been written into swap space....
|
||||
+ */
|
||||
+#ifdef _WIN32
|
||||
+# define zap(ptr, len) SecureZeroMemory(ptr, len)
|
||||
+#elif defined(__STDC_LIB_EXT1__)
|
||||
+/*
|
||||
+ * Use memset_s() which cannot be optimized out. Avoid memset_s(NULL, 0, 0, 0)
|
||||
+ * which would cause a runtime constraint violation.
|
||||
+ */
|
||||
+static inline void zap(void *ptr, size_t len)
|
||||
+{
|
||||
+ if (len > 0)
|
||||
+ memset_s(ptr, len, 0, len);
|
||||
+}
|
||||
+#elif defined(__GNUC__) || defined(__clang__)
|
||||
+/*
|
||||
+ * Use an asm statement which declares a memory clobber to force the memset to
|
||||
+ * be carried out. Avoid memset(NULL, 0, 0) which has undefined behavior.
|
||||
+ */
|
||||
+static inline void zap(void *ptr, size_t len)
|
||||
+{
|
||||
+ if (len > 0)
|
||||
+ memset(ptr, 0, len);
|
||||
+ __asm__ __volatile__("" : : "r" (ptr) : "memory");
|
||||
+}
|
||||
+#else
|
||||
+/*
|
||||
+ * Use a function from libkrb5support to defeat inlining unless link-time
|
||||
+ * optimization is used. The function uses a volatile pointer, which prevents
|
||||
+ * current compilers from optimizing out the memset.
|
||||
+ */
|
||||
+# define zap(ptr, len) krb5int_zap(ptr, len)
|
||||
+#endif
|
||||
+
|
||||
extern void krb5int_zap(void *ptr, size_t len);
|
||||
|
||||
/*
|
||||
diff --git a/src/util/support/zap.c b/src/util/support/zap.c
|
||||
index ed31630db..2f6cdd70e 100644
|
||||
--- a/src/util/support/zap.c
|
||||
+++ b/src/util/support/zap.c
|
||||
@@ -25,8 +25,8 @@
|
||||
*/
|
||||
|
||||
/*
|
||||
- * krb5int_zap() is used by zap() (a static inline function defined in
|
||||
- * k5-int.h) on non-Windows, non-gcc compilers, in order to prevent the
|
||||
+ * krb5int_zap() is used by zap() (a macro or static inline function defined in
|
||||
+ * k5-platform.h) on non-Windows, non-gcc compilers, in order to prevent the
|
||||
* compiler from inlining and optimizing out the memset() call.
|
||||
*/
|
||||
|
||||
114
Process-profile-includedir-in-sorted-order.patch
Normal file
114
Process-profile-includedir-in-sorted-order.patch
Normal file
|
|
@ -0,0 +1,114 @@
|
|||
From 5d868264bca1771aa16abbc8cc0aefb0e1750a73 Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Wed, 6 Jun 2018 17:58:41 -0400
|
||||
Subject: [PATCH] Process profile includedir in sorted order
|
||||
|
||||
In the profile library, use k5_dir_filenames() so that files within an
|
||||
included directory are read in a predictable order (alphanumeric
|
||||
within the C locale).
|
||||
|
||||
ticket: 8686
|
||||
(cherry picked from commit f574eda48740ad192f51e9a382a205e2ea0e60ad)
|
||||
---
|
||||
doc/admin/conf_files/krb5_conf.rst | 4 ++-
|
||||
src/util/profile/prof_parse.c | 56 +++++-------------------------
|
||||
2 files changed, 12 insertions(+), 48 deletions(-)
|
||||
|
||||
diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst
|
||||
index 2574e5c26..ce545492d 100644
|
||||
--- a/doc/admin/conf_files/krb5_conf.rst
|
||||
+++ b/doc/admin/conf_files/krb5_conf.rst
|
||||
@@ -60,7 +60,9 @@ alphanumeric characters, dashes, or underscores. Starting in release
|
||||
1.15, files with names ending in ".conf" are also included, unless the
|
||||
name begins with ".". Included profile files are syntactically
|
||||
independent of their parents, so each included file must begin with a
|
||||
-section header.
|
||||
+section header. Starting in release 1.17, files are read in
|
||||
+alphanumeric order; in previous releases, they may be read in any
|
||||
+order.
|
||||
|
||||
The krb5.conf file can specify that configuration should be obtained
|
||||
from a loadable module, rather than the file itself, using the
|
||||
diff --git a/src/util/profile/prof_parse.c b/src/util/profile/prof_parse.c
|
||||
index 1baceea9e..531e4a099 100644
|
||||
--- a/src/util/profile/prof_parse.c
|
||||
+++ b/src/util/profile/prof_parse.c
|
||||
@@ -246,59 +246,22 @@ static int valid_name(const char *filename)
|
||||
* Include files within dirname. Only files with names ending in ".conf", or
|
||||
* consisting entirely of alphanumeric characters, dashes, and underscores are
|
||||
* included. This restriction avoids including editor backup files, .rpmsave
|
||||
- * files, and the like.
|
||||
+ * files, and the like. Files are processed in alphanumeric order.
|
||||
*/
|
||||
static errcode_t parse_include_dir(const char *dirname,
|
||||
struct profile_node *root_section)
|
||||
{
|
||||
-#ifdef _WIN32
|
||||
- char *wildcard = NULL, *pathname;
|
||||
- WIN32_FIND_DATA ffd;
|
||||
- HANDLE handle;
|
||||
errcode_t retval = 0;
|
||||
+ char **fnames, *pathname;
|
||||
+ int i;
|
||||
|
||||
- if (asprintf(&wildcard, "%s\\*", dirname) < 0)
|
||||
- return ENOMEM;
|
||||
-
|
||||
- handle = FindFirstFile(wildcard, &ffd);
|
||||
- if (handle == INVALID_HANDLE_VALUE) {
|
||||
- retval = PROF_FAIL_INCLUDE_DIR;
|
||||
- goto cleanup;
|
||||
- }
|
||||
-
|
||||
- do {
|
||||
- if (!valid_name(ffd.cFileName))
|
||||
- continue;
|
||||
- if (asprintf(&pathname, "%s\\%s", dirname, ffd.cFileName) < 0) {
|
||||
- retval = ENOMEM;
|
||||
- break;
|
||||
- }
|
||||
- retval = parse_include_file(pathname, root_section);
|
||||
- free(pathname);
|
||||
- if (retval)
|
||||
- break;
|
||||
- } while (FindNextFile(handle, &ffd) != 0);
|
||||
-
|
||||
- FindClose(handle);
|
||||
-
|
||||
-cleanup:
|
||||
- free(wildcard);
|
||||
- return retval;
|
||||
-
|
||||
-#else /* not _WIN32 */
|
||||
-
|
||||
- DIR *dir;
|
||||
- char *pathname;
|
||||
- errcode_t retval = 0;
|
||||
- struct dirent *ent;
|
||||
-
|
||||
- dir = opendir(dirname);
|
||||
- if (dir == NULL)
|
||||
+ if (k5_dir_filenames(dirname, &fnames) != 0)
|
||||
return PROF_FAIL_INCLUDE_DIR;
|
||||
- while ((ent = readdir(dir)) != NULL) {
|
||||
- if (!valid_name(ent->d_name))
|
||||
+
|
||||
+ for (i = 0; fnames != NULL && fnames[i] != NULL; i++) {
|
||||
+ if (!valid_name(fnames[i]))
|
||||
continue;
|
||||
- if (asprintf(&pathname, "%s/%s", dirname, ent->d_name) < 0) {
|
||||
+ if (asprintf(&pathname, "%s/%s", dirname, fnames[i]) < 0) {
|
||||
retval = ENOMEM;
|
||||
break;
|
||||
}
|
||||
@@ -307,9 +270,8 @@ cleanup:
|
||||
if (retval)
|
||||
break;
|
||||
}
|
||||
- closedir(dir);
|
||||
+ k5_free_filenames(fnames);
|
||||
return retval;
|
||||
-#endif /* not _WIN32 */
|
||||
}
|
||||
|
||||
static errcode_t parse_line(char *line, struct parse_state *state,
|
||||
393
Refactor-KDC-krb5_pa_data-utility-functions.patch
Normal file
393
Refactor-KDC-krb5_pa_data-utility-functions.patch
Normal file
|
|
@ -0,0 +1,393 @@
|
|||
From 7c59b7ee063489a4259c34b725728fee7e411c46 Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Thu, 21 Dec 2017 11:28:52 -0500
|
||||
Subject: [PATCH] Refactor KDC krb5_pa_data utility functions
|
||||
|
||||
Move alloc_padata from fast_util.c to kdc_util.c and make it
|
||||
non-static so it can be used by other files. Rename it to
|
||||
alloc_pa_data for consistency with add_pa_data_element. Make it
|
||||
correctly handle zero length using a null contents pointer.
|
||||
|
||||
Make add_pa_data_element claim both the container and contents memory
|
||||
from the caller, now that callers can use alloc_pa_data to simplify
|
||||
allocation and copying. Remove the copy parameter and the unused
|
||||
context parameter, and put the list parameter first. Adjust all
|
||||
callers accordingly, making small simplifications to memory handling
|
||||
where applicable.
|
||||
|
||||
(cherry picked from commit 4af478c18b02e1d2444a328bb79e6976ef3d312b)
|
||||
---
|
||||
src/kdc/fast_util.c | 28 +------
|
||||
src/kdc/kdc_preauth.c | 14 ++--
|
||||
src/kdc/kdc_util.c | 187 +++++++++++++++++++++---------------------
|
||||
src/kdc/kdc_util.h | 8 +-
|
||||
4 files changed, 109 insertions(+), 128 deletions(-)
|
||||
|
||||
diff --git a/src/kdc/fast_util.c b/src/kdc/fast_util.c
|
||||
index e05107ef3..6a3fc11b9 100644
|
||||
--- a/src/kdc/fast_util.c
|
||||
+++ b/src/kdc/fast_util.c
|
||||
@@ -451,36 +451,12 @@ kdc_fast_hide_client(struct kdc_request_state *state)
|
||||
return (state->fast_options & KRB5_FAST_OPTION_HIDE_CLIENT_NAMES) != 0;
|
||||
}
|
||||
|
||||
-/* Allocate a pa-data entry with an uninitialized buffer of size len. */
|
||||
-static krb5_error_code
|
||||
-alloc_padata(krb5_preauthtype pa_type, size_t len, krb5_pa_data **out)
|
||||
-{
|
||||
- krb5_pa_data *pa;
|
||||
- uint8_t *buf;
|
||||
-
|
||||
- *out = NULL;
|
||||
- buf = malloc(len);
|
||||
- if (buf == NULL)
|
||||
- return ENOMEM;
|
||||
- pa = malloc(sizeof(*pa));
|
||||
- if (pa == NULL) {
|
||||
- free(buf);
|
||||
- return ENOMEM;
|
||||
- }
|
||||
- pa->magic = KV5M_PA_DATA;
|
||||
- pa->pa_type = pa_type;
|
||||
- pa->length = len;
|
||||
- pa->contents = buf;
|
||||
- *out = pa;
|
||||
- return 0;
|
||||
-}
|
||||
-
|
||||
/* Create a pa-data entry with the specified type and contents. */
|
||||
static krb5_error_code
|
||||
make_padata(krb5_preauthtype pa_type, const void *contents, size_t len,
|
||||
krb5_pa_data **out)
|
||||
{
|
||||
- if (alloc_padata(pa_type, len, out) != 0)
|
||||
+ if (alloc_pa_data(pa_type, len, out) != 0)
|
||||
return ENOMEM;
|
||||
memcpy((*out)->contents, contents, len);
|
||||
return 0;
|
||||
@@ -720,7 +696,7 @@ kdc_fast_make_cookie(krb5_context context, struct kdc_request_state *state,
|
||||
goto cleanup;
|
||||
|
||||
/* Construct the cookie pa-data entry. */
|
||||
- ret = alloc_padata(KRB5_PADATA_FX_COOKIE, 8 + enc.ciphertext.length, &pa);
|
||||
+ ret = alloc_pa_data(KRB5_PADATA_FX_COOKIE, 8 + enc.ciphertext.length, &pa);
|
||||
memcpy(pa->contents, "MIT1", 4);
|
||||
store_32_be(kvno, pa->contents + 4);
|
||||
memcpy(pa->contents + 8, enc.ciphertext.data, enc.ciphertext.length);
|
||||
diff --git a/src/kdc/kdc_preauth.c b/src/kdc/kdc_preauth.c
|
||||
index 739c5e776..edc30bd83 100644
|
||||
--- a/src/kdc/kdc_preauth.c
|
||||
+++ b/src/kdc/kdc_preauth.c
|
||||
@@ -1617,18 +1617,20 @@ return_referral_enc_padata( krb5_context context,
|
||||
{
|
||||
krb5_error_code code;
|
||||
krb5_tl_data tl_data;
|
||||
- krb5_pa_data pa_data;
|
||||
+ krb5_pa_data *pa;
|
||||
|
||||
tl_data.tl_data_type = KRB5_TL_SVR_REFERRAL_DATA;
|
||||
code = krb5_dbe_lookup_tl_data(context, server, &tl_data);
|
||||
if (code || tl_data.tl_data_length == 0)
|
||||
return 0;
|
||||
|
||||
- pa_data.magic = KV5M_PA_DATA;
|
||||
- pa_data.pa_type = KRB5_PADATA_SVR_REFERRAL_INFO;
|
||||
- pa_data.length = tl_data.tl_data_length;
|
||||
- pa_data.contents = tl_data.tl_data_contents;
|
||||
- return add_pa_data_element(context, &pa_data, &reply->enc_padata, TRUE);
|
||||
+ code = alloc_pa_data(KRB5_PADATA_SVR_REFERRAL_INFO, tl_data.tl_data_length,
|
||||
+ &pa);
|
||||
+ if (code)
|
||||
+ return code;
|
||||
+ memcpy(pa->contents, tl_data.tl_data_contents, tl_data.tl_data_length);
|
||||
+ /* add_pa_data_element() claims pa on success or failure. */
|
||||
+ return add_pa_data_element(&reply->enc_padata, pa);
|
||||
}
|
||||
|
||||
krb5_error_code
|
||||
diff --git a/src/kdc/kdc_util.c b/src/kdc/kdc_util.c
|
||||
index 754570c01..13111215d 100644
|
||||
--- a/src/kdc/kdc_util.c
|
||||
+++ b/src/kdc/kdc_util.c
|
||||
@@ -1353,9 +1353,9 @@ kdc_make_s4u2self_rep(krb5_context context,
|
||||
krb5_enc_kdc_rep_part *reply_encpart)
|
||||
{
|
||||
krb5_error_code code;
|
||||
- krb5_data *data = NULL;
|
||||
+ krb5_data *der_user_id = NULL, *der_s4u_x509_user = NULL;
|
||||
krb5_pa_s4u_x509_user rep_s4u_user;
|
||||
- krb5_pa_data padata;
|
||||
+ krb5_pa_data *pa;
|
||||
krb5_enctype enctype;
|
||||
krb5_keyusage usage;
|
||||
|
||||
@@ -1366,7 +1366,7 @@ kdc_make_s4u2self_rep(krb5_context context,
|
||||
rep_s4u_user.user_id.options =
|
||||
req_s4u_user->user_id.options & KRB5_S4U_OPTS_USE_REPLY_KEY_USAGE;
|
||||
|
||||
- code = encode_krb5_s4u_userid(&rep_s4u_user.user_id, &data);
|
||||
+ code = encode_krb5_s4u_userid(&rep_s4u_user.user_id, &der_user_id);
|
||||
if (code != 0)
|
||||
goto cleanup;
|
||||
|
||||
@@ -1377,29 +1377,25 @@ kdc_make_s4u2self_rep(krb5_context context,
|
||||
|
||||
code = krb5_c_make_checksum(context, req_s4u_user->cksum.checksum_type,
|
||||
tgs_subkey != NULL ? tgs_subkey : tgs_session,
|
||||
- usage, data,
|
||||
- &rep_s4u_user.cksum);
|
||||
+ usage, der_user_id, &rep_s4u_user.cksum);
|
||||
if (code != 0)
|
||||
goto cleanup;
|
||||
|
||||
- krb5_free_data(context, data);
|
||||
- data = NULL;
|
||||
-
|
||||
- code = encode_krb5_pa_s4u_x509_user(&rep_s4u_user, &data);
|
||||
+ code = encode_krb5_pa_s4u_x509_user(&rep_s4u_user, &der_s4u_x509_user);
|
||||
if (code != 0)
|
||||
goto cleanup;
|
||||
|
||||
- padata.magic = KV5M_PA_DATA;
|
||||
- padata.pa_type = KRB5_PADATA_S4U_X509_USER;
|
||||
- padata.length = data->length;
|
||||
- padata.contents = (krb5_octet *)data->data;
|
||||
-
|
||||
- code = add_pa_data_element(context, &padata, &reply->padata, FALSE);
|
||||
+ /* Add a padata element, stealing memory from der_s4u_x509_user. */
|
||||
+ code = alloc_pa_data(KRB5_PADATA_S4U_X509_USER, 0, &pa);
|
||||
+ if (code != 0)
|
||||
+ goto cleanup;
|
||||
+ pa->length = der_s4u_x509_user->length;
|
||||
+ pa->contents = (uint8_t *)der_s4u_x509_user->data;
|
||||
+ der_s4u_x509_user->data = NULL;
|
||||
+ /* add_pa_data_element() claims pa on success or failure. */
|
||||
+ code = add_pa_data_element(&reply->padata, pa);
|
||||
if (code != 0)
|
||||
goto cleanup;
|
||||
-
|
||||
- free(data);
|
||||
- data = NULL;
|
||||
|
||||
if (tgs_subkey != NULL)
|
||||
enctype = tgs_subkey->enctype;
|
||||
@@ -1413,33 +1409,27 @@ kdc_make_s4u2self_rep(krb5_context context,
|
||||
*/
|
||||
if ((req_s4u_user->user_id.options & KRB5_S4U_OPTS_USE_REPLY_KEY_USAGE) &&
|
||||
enctype_requires_etype_info_2(enctype) == FALSE) {
|
||||
- padata.length = req_s4u_user->cksum.length +
|
||||
- rep_s4u_user.cksum.length;
|
||||
- padata.contents = malloc(padata.length);
|
||||
- if (padata.contents == NULL) {
|
||||
- code = ENOMEM;
|
||||
+ code = alloc_pa_data(KRB5_PADATA_S4U_X509_USER,
|
||||
+ req_s4u_user->cksum.length +
|
||||
+ rep_s4u_user.cksum.length, &pa);
|
||||
+ if (code != 0)
|
||||
goto cleanup;
|
||||
- }
|
||||
+ memcpy(pa->contents,
|
||||
+ req_s4u_user->cksum.contents, req_s4u_user->cksum.length);
|
||||
+ memcpy(&pa->contents[req_s4u_user->cksum.length],
|
||||
+ rep_s4u_user.cksum.contents, rep_s4u_user.cksum.length);
|
||||
|
||||
- memcpy(padata.contents,
|
||||
- req_s4u_user->cksum.contents,
|
||||
- req_s4u_user->cksum.length);
|
||||
- memcpy(&padata.contents[req_s4u_user->cksum.length],
|
||||
- rep_s4u_user.cksum.contents,
|
||||
- rep_s4u_user.cksum.length);
|
||||
-
|
||||
- code = add_pa_data_element(context,&padata,
|
||||
- &reply_encpart->enc_padata, FALSE);
|
||||
- if (code != 0) {
|
||||
- free(padata.contents);
|
||||
+ /* add_pa_data_element() claims pa on success or failure. */
|
||||
+ code = add_pa_data_element(&reply_encpart->enc_padata, pa);
|
||||
+ if (code != 0)
|
||||
goto cleanup;
|
||||
- }
|
||||
}
|
||||
|
||||
cleanup:
|
||||
if (rep_s4u_user.cksum.contents != NULL)
|
||||
krb5_free_checksum_contents(context, &rep_s4u_user.cksum);
|
||||
- krb5_free_data(context, data);
|
||||
+ krb5_free_data(context, der_user_id);
|
||||
+ krb5_free_data(context, der_s4u_x509_user);
|
||||
|
||||
return code;
|
||||
}
|
||||
@@ -1707,46 +1697,50 @@ enctype_requires_etype_info_2(krb5_enctype enctype)
|
||||
}
|
||||
}
|
||||
|
||||
-/* XXX where are the generic helper routines for this? */
|
||||
+/* Allocate a pa-data entry with an uninitialized buffer of size len. */
|
||||
krb5_error_code
|
||||
-add_pa_data_element(krb5_context context,
|
||||
- krb5_pa_data *padata,
|
||||
- krb5_pa_data ***inout_padata,
|
||||
- krb5_boolean copy)
|
||||
+alloc_pa_data(krb5_preauthtype pa_type, size_t len, krb5_pa_data **out)
|
||||
{
|
||||
- int i;
|
||||
- krb5_pa_data **p;
|
||||
+ krb5_pa_data *pa;
|
||||
+ uint8_t *buf = NULL;
|
||||
|
||||
- if (*inout_padata != NULL) {
|
||||
- for (i = 0; (*inout_padata)[i] != NULL; i++)
|
||||
- ;
|
||||
- } else
|
||||
- i = 0;
|
||||
-
|
||||
- p = realloc(*inout_padata, (i + 2) * sizeof(krb5_pa_data *));
|
||||
- if (p == NULL)
|
||||
- return ENOMEM;
|
||||
-
|
||||
- *inout_padata = p;
|
||||
-
|
||||
- p[i] = (krb5_pa_data *)malloc(sizeof(krb5_pa_data));
|
||||
- if (p[i] == NULL)
|
||||
- return ENOMEM;
|
||||
- *(p[i]) = *padata;
|
||||
-
|
||||
- p[i + 1] = NULL;
|
||||
-
|
||||
- if (copy) {
|
||||
- p[i]->contents = (krb5_octet *)malloc(padata->length);
|
||||
- if (p[i]->contents == NULL) {
|
||||
- free(p[i]);
|
||||
- p[i] = NULL;
|
||||
+ *out = NULL;
|
||||
+ if (len > 0) {
|
||||
+ buf = malloc(len);
|
||||
+ if (buf == NULL)
|
||||
return ENOMEM;
|
||||
- }
|
||||
-
|
||||
- memcpy(p[i]->contents, padata->contents, padata->length);
|
||||
}
|
||||
+ pa = malloc(sizeof(*pa));
|
||||
+ if (pa == NULL) {
|
||||
+ free(buf);
|
||||
+ return ENOMEM;
|
||||
+ }
|
||||
+ pa->magic = KV5M_PA_DATA;
|
||||
+ pa->pa_type = pa_type;
|
||||
+ pa->length = len;
|
||||
+ pa->contents = buf;
|
||||
+ *out = pa;
|
||||
+ return 0;
|
||||
+}
|
||||
|
||||
+/* Add pa to list, claiming its memory. Free pa on failure. */
|
||||
+krb5_error_code
|
||||
+add_pa_data_element(krb5_pa_data ***list, krb5_pa_data *pa)
|
||||
+{
|
||||
+ size_t count;
|
||||
+ krb5_pa_data **newlist;
|
||||
+
|
||||
+ for (count = 0; *list != NULL && (*list)[count] != NULL; count++);
|
||||
+
|
||||
+ newlist = realloc(*list, (count + 2) * sizeof(*newlist));
|
||||
+ if (newlist == NULL) {
|
||||
+ free(pa->contents);
|
||||
+ free(pa);
|
||||
+ return ENOMEM;
|
||||
+ }
|
||||
+ newlist[count] = pa;
|
||||
+ newlist[count + 1] = NULL;
|
||||
+ *list = newlist;
|
||||
return 0;
|
||||
}
|
||||
|
||||
@@ -1850,38 +1844,47 @@ kdc_handle_protected_negotiation(krb5_context context,
|
||||
{
|
||||
krb5_error_code retval = 0;
|
||||
krb5_checksum checksum;
|
||||
- krb5_data *out = NULL;
|
||||
- krb5_pa_data pa, *pa_in;
|
||||
+ krb5_data *der_cksum = NULL;
|
||||
+ krb5_pa_data *pa, *pa_in;
|
||||
+
|
||||
+ memset(&checksum, 0, sizeof(checksum));
|
||||
+
|
||||
pa_in = krb5int_find_pa_data(context, request->padata,
|
||||
KRB5_ENCPADATA_REQ_ENC_PA_REP);
|
||||
if (pa_in == NULL)
|
||||
return 0;
|
||||
- pa.magic = KV5M_PA_DATA;
|
||||
- pa.pa_type = KRB5_ENCPADATA_REQ_ENC_PA_REP;
|
||||
- memset(&checksum, 0, sizeof(checksum));
|
||||
- retval = krb5_c_make_checksum(context,0, reply_key,
|
||||
- KRB5_KEYUSAGE_AS_REQ, req_pkt, &checksum);
|
||||
+
|
||||
+ /* Compute and encode a checksum over the AS-REQ. */
|
||||
+ retval = krb5_c_make_checksum(context, 0, reply_key, KRB5_KEYUSAGE_AS_REQ,
|
||||
+ req_pkt, &checksum);
|
||||
if (retval != 0)
|
||||
goto cleanup;
|
||||
- retval = encode_krb5_checksum(&checksum, &out);
|
||||
+ retval = encode_krb5_checksum(&checksum, &der_cksum);
|
||||
if (retval != 0)
|
||||
goto cleanup;
|
||||
- pa.contents = (krb5_octet *) out->data;
|
||||
- pa.length = out->length;
|
||||
- retval = add_pa_data_element(context, &pa, out_enc_padata, FALSE);
|
||||
+
|
||||
+ /* Add a pa-data element to the list, stealing memory from der_cksum. */
|
||||
+ retval = alloc_pa_data(KRB5_ENCPADATA_REQ_ENC_PA_REP, 0, &pa);
|
||||
if (retval)
|
||||
goto cleanup;
|
||||
- out->data = NULL;
|
||||
- pa.magic = KV5M_PA_DATA;
|
||||
- pa.pa_type = KRB5_PADATA_FX_FAST;
|
||||
- pa.length = 0;
|
||||
- pa.contents = NULL;
|
||||
- retval = add_pa_data_element(context, &pa, out_enc_padata, FALSE);
|
||||
+ pa->length = der_cksum->length;
|
||||
+ pa->contents = (uint8_t *)der_cksum->data;
|
||||
+ der_cksum->data = NULL;
|
||||
+ /* add_pa_data_element() claims pa on success or failure. */
|
||||
+ retval = add_pa_data_element(out_enc_padata, pa);
|
||||
+ if (retval)
|
||||
+ goto cleanup;
|
||||
+
|
||||
+ /* Add a zero-length PA-FX-FAST element to the list. */
|
||||
+ retval = alloc_pa_data(KRB5_PADATA_FX_FAST, 0, &pa);
|
||||
+ if (retval)
|
||||
+ goto cleanup;
|
||||
+ /* add_pa_data_element() claims pa on success or failure. */
|
||||
+ retval = add_pa_data_element(out_enc_padata, pa);
|
||||
+
|
||||
cleanup:
|
||||
- if (checksum.contents)
|
||||
- krb5_free_checksum_contents(context, &checksum);
|
||||
- if (out != NULL)
|
||||
- krb5_free_data(context, out);
|
||||
+ krb5_free_checksum_contents(context, &checksum);
|
||||
+ krb5_free_data(context, der_cksum);
|
||||
return retval;
|
||||
}
|
||||
|
||||
diff --git a/src/kdc/kdc_util.h b/src/kdc/kdc_util.h
|
||||
index c57d48f73..198eab9c4 100644
|
||||
--- a/src/kdc/kdc_util.h
|
||||
+++ b/src/kdc/kdc_util.h
|
||||
@@ -202,10 +202,10 @@ void
|
||||
free_padata_context(krb5_context context, void *padata_context);
|
||||
|
||||
krb5_error_code
|
||||
-add_pa_data_element (krb5_context context,
|
||||
- krb5_pa_data *padata,
|
||||
- krb5_pa_data ***out_padata,
|
||||
- krb5_boolean copy);
|
||||
+alloc_pa_data(krb5_preauthtype pa_type, size_t len, krb5_pa_data **out);
|
||||
+
|
||||
+krb5_error_code
|
||||
+add_pa_data_element(krb5_pa_data ***list, krb5_pa_data *pa);
|
||||
|
||||
/* kdc_preauth_ec.c */
|
||||
krb5_error_code
|
||||
43
Remove-incorrect-KDC-assertion.patch
Normal file
43
Remove-incorrect-KDC-assertion.patch
Normal file
|
|
@ -0,0 +1,43 @@
|
|||
From ca75a685d19fec7c481fd3de9769ac3546e37a11 Mon Sep 17 00:00:00 2001
|
||||
From: Isaac Boukris <iboukris@gmail.com>
|
||||
Date: Sat, 15 Dec 2018 11:56:36 +0200
|
||||
Subject: [PATCH] Remove incorrect KDC assertion
|
||||
|
||||
The assertion in return_enc_padata() is reachable because
|
||||
kdc_make_s4u2self_rep() may have previously added encrypted padata.
|
||||
It is no longer necessary because the code uses add_pa_data_element()
|
||||
instead of allocating a new list.
|
||||
|
||||
CVE-2018-20217:
|
||||
|
||||
In MIT krb5 1.8 or later, an authenticated user who can obtain a TGT
|
||||
using an older encryption type (DES, DES3, or RC4) can cause an
|
||||
assertion failure in the KDC by sending an S4U2Self request.
|
||||
|
||||
[ghudson@mit.edu: rewrote commit message with CVE description]
|
||||
|
||||
ticket: 8767 (new)
|
||||
tags: pullup
|
||||
target_version: 1.17
|
||||
target_version: 1.16-next
|
||||
target_version: 1.15-next
|
||||
|
||||
(cherry picked from commit 94e5eda5bb94d1d44733a49c3d9b6d1e42c74def)
|
||||
(cherry picked from commit 5ab44ff3ecdf362a792f193cf18df42866b70f80)
|
||||
[rharwood@redhat.com: don't backport the tests]
|
||||
---
|
||||
src/kdc/kdc_preauth.c | 1 -
|
||||
1 file changed, 1 deletion(-)
|
||||
|
||||
diff --git a/src/kdc/kdc_preauth.c b/src/kdc/kdc_preauth.c
|
||||
index 811c16368..6f0cf68d9 100644
|
||||
--- a/src/kdc/kdc_preauth.c
|
||||
+++ b/src/kdc/kdc_preauth.c
|
||||
@@ -1666,7 +1666,6 @@ return_enc_padata(krb5_context context, krb5_data *req_pkt,
|
||||
krb5_error_code code = 0;
|
||||
/* This should be initialized and only used for Win2K compat and other
|
||||
* specific standardized uses such as FAST negotiation. */
|
||||
- assert(reply_encpart->enc_padata == NULL);
|
||||
if (is_referral) {
|
||||
code = return_referral_enc_padata(context, reply_encpart, server);
|
||||
if (code)
|
||||
45
Remove-nodes-option-from-make-certs-scripts.patch
Normal file
45
Remove-nodes-option-from-make-certs-scripts.patch
Normal file
|
|
@ -0,0 +1,45 @@
|
|||
From 83da5675551dba13fee837adc26ce885a061dbc1 Mon Sep 17 00:00:00 2001
|
||||
From: Robbie Harwood <rharwood@redhat.com>
|
||||
Date: Thu, 3 May 2018 14:40:45 -0400
|
||||
Subject: [PATCH] Remove "-nodes" option from make-certs scripts
|
||||
|
||||
The openssl command does not recognize options after positional
|
||||
arguments, so in "openssl genrsa $KEYSIZE -nodes", the "-nodes" was
|
||||
ignored as a excess positional argument prior to OpenSSL 1.1.0h, and
|
||||
now causes an error. "-nodes" is an option to the openssl req and
|
||||
pkcs12 subcommands, but genrsa creates unencrypted keys by default.
|
||||
|
||||
[ghudson@mit.edu: edited commit message]
|
||||
|
||||
(cherry picked from commit 928a36aae326d496c9a73f2cd41b4da45eef577c)
|
||||
---
|
||||
src/tests/dejagnu/pkinit-certs/make-certs.sh | 2 +-
|
||||
src/tests/dejagnu/proxy-certs/make-certs.sh | 2 +-
|
||||
2 files changed, 2 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/src/tests/dejagnu/pkinit-certs/make-certs.sh b/src/tests/dejagnu/pkinit-certs/make-certs.sh
|
||||
index 63f0c6f75..387311aed 100755
|
||||
--- a/src/tests/dejagnu/pkinit-certs/make-certs.sh
|
||||
+++ b/src/tests/dejagnu/pkinit-certs/make-certs.sh
|
||||
@@ -114,7 +114,7 @@ extendedKeyUsage = $CLIENT_EKU_LIST
|
||||
EOF
|
||||
|
||||
# Generate a private key.
|
||||
-openssl genrsa $KEYSIZE -nodes > privkey.pem
|
||||
+openssl genrsa $KEYSIZE > privkey.pem
|
||||
openssl rsa -in privkey.pem -out privkey-enc.pem -des3 -passout pass:encrypted
|
||||
|
||||
# Generate a "CA" certificate.
|
||||
diff --git a/src/tests/dejagnu/proxy-certs/make-certs.sh b/src/tests/dejagnu/proxy-certs/make-certs.sh
|
||||
index 1191bf05e..24ef91bde 100755
|
||||
--- a/src/tests/dejagnu/proxy-certs/make-certs.sh
|
||||
+++ b/src/tests/dejagnu/proxy-certs/make-certs.sh
|
||||
@@ -79,7 +79,7 @@ extendedKeyUsage = $PROXY_EKU_LIST
|
||||
EOF
|
||||
|
||||
# Generate a private key.
|
||||
-openssl genrsa $KEYSIZE -nodes > privkey.pem
|
||||
+openssl genrsa $KEYSIZE > privkey.pem
|
||||
|
||||
# Generate a "CA" certificate.
|
||||
SUBJECT=signer openssl req -config openssl.cnf -new -x509 -extensions exts_ca \
|
||||
37
Remove-outdated-note-in-krb5kdc-man-page.patch
Normal file
37
Remove-outdated-note-in-krb5kdc-man-page.patch
Normal file
|
|
@ -0,0 +1,37 @@
|
|||
From 65130d13c59c13b7e5e07cfe69421ce1a08c0b7f Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Tue, 17 Jul 2018 11:33:03 -0400
|
||||
Subject: [PATCH] Remove outdated note in krb5kdc man page
|
||||
|
||||
Commit af5b77c887bfff24603715f8296c00d5eb839b0c (ticket 8348) removed
|
||||
the interface-scanning workaround for platforms without pktinfo
|
||||
support, so there is no longer an interaction between the krb5kdc -w
|
||||
option and this workaround.
|
||||
|
||||
ticket: 8716 (new)
|
||||
tags: pullup
|
||||
target_version: 1.16-next
|
||||
|
||||
(cherry picked from commit 728b66ab867e31c4c338c6a6309d629d39a4ec3f)
|
||||
---
|
||||
doc/admin/admin_commands/krb5kdc.rst | 7 -------
|
||||
1 file changed, 7 deletions(-)
|
||||
|
||||
diff --git a/doc/admin/admin_commands/krb5kdc.rst b/doc/admin/admin_commands/krb5kdc.rst
|
||||
index bda2c015c..b605b563d 100644
|
||||
--- a/doc/admin/admin_commands/krb5kdc.rst
|
||||
+++ b/doc/admin/admin_commands/krb5kdc.rst
|
||||
@@ -72,13 +72,6 @@ will relay SIGHUP signals to the worker subprocesses, and will
|
||||
terminate the worker subprocess if the it is itself terminated or if
|
||||
any other worker process exits.
|
||||
|
||||
-.. note::
|
||||
-
|
||||
- On operating systems which do not have *pktinfo* support,
|
||||
- using worker processes will prevent the KDC from listening
|
||||
- for UDP packets on network interfaces created after the KDC
|
||||
- starts.
|
||||
-
|
||||
The **-x** *db_args* option specifies database-specific arguments.
|
||||
See :ref:`Database Options <dboptions>` in :ref:`kadmin(1)` for
|
||||
supported arguments.
|
||||
27
Report-extended-errors-in-kinit-k-t-KDB.patch
Normal file
27
Report-extended-errors-in-kinit-k-t-KDB.patch
Normal file
|
|
@ -0,0 +1,27 @@
|
|||
From 3b3e31316ae247e18ea22293dffbc8f604338fa7 Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Sat, 17 Mar 2018 22:47:34 -0400
|
||||
Subject: [PATCH] Report extended errors in kinit -k -t KDB:
|
||||
|
||||
In kinit, if we recreate the context using kinit_kdb_init(), also
|
||||
reset the global errctx so that we use the new context to retrieve
|
||||
extended error messages.
|
||||
|
||||
ticket: 8652 (new)
|
||||
(cherry picked from commit d4d902d317a2acc46ee71094a33a9203b6135275)
|
||||
---
|
||||
src/clients/kinit/kinit.c | 1 +
|
||||
1 file changed, 1 insertion(+)
|
||||
|
||||
diff --git a/src/clients/kinit/kinit.c b/src/clients/kinit/kinit.c
|
||||
index a518284ea..3fdae2878 100644
|
||||
--- a/src/clients/kinit/kinit.c
|
||||
+++ b/src/clients/kinit/kinit.c
|
||||
@@ -718,6 +718,7 @@ k5_kinit(struct k_opts *opts, struct k5_data *k5)
|
||||
#ifndef _WIN32
|
||||
if (strncmp(opts->keytab_name, "KDB:", 4) == 0) {
|
||||
ret = kinit_kdb_init(&k5->ctx, k5->me->realm.data);
|
||||
+ errctx = k5->ctx;
|
||||
if (ret) {
|
||||
com_err(progname, ret,
|
||||
_("while setting up KDB keytab for realm %s"),
|
||||
491
Restrict-pre-authentication-fallback-cases.patch
Normal file
491
Restrict-pre-authentication-fallback-cases.patch
Normal file
|
|
@ -0,0 +1,491 @@
|
|||
From 70f41a8dafaadfb43aba4918564c22460f812dca Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Thu, 5 Apr 2018 16:23:34 -0400
|
||||
Subject: [PATCH] Restrict pre-authentication fallback cases
|
||||
|
||||
Add a new callback disable_fallback() and call it from each clpreauth
|
||||
module when it generates a client message using credentials to
|
||||
authenticate. (For SPAKE, this is the message responding to a
|
||||
challenge; for all other current mechanisms, it is the first and only
|
||||
client message.) If disable_fallback() is called, do not try another
|
||||
mechanism after a KDC error.
|
||||
|
||||
Remove k5_reset_preauth_types_tried() and its call sites, so that
|
||||
preauth mechanisms which are tried optimistically will no longer be
|
||||
retried after a failure.
|
||||
|
||||
ticket: 8654
|
||||
(cherry picked from commit 7a24a088c16d326127dd2b29084d4ca085c70d10)
|
||||
---
|
||||
src/include/krb5/clpreauth_plugin.h | 14 ++++
|
||||
src/lib/krb5/krb/get_in_tkt.c | 21 +++---
|
||||
src/lib/krb5/krb/init_creds_ctx.h | 1 +
|
||||
src/lib/krb5/krb/int-proto.h | 3 -
|
||||
src/lib/krb5/krb/preauth2.c | 23 +++----
|
||||
src/lib/krb5/krb/preauth_ec.c | 1 +
|
||||
src/lib/krb5/krb/preauth_encts.c | 2 +
|
||||
src/lib/krb5/krb/preauth_otp.c | 4 ++
|
||||
src/lib/krb5/krb/preauth_sam2.c | 1 +
|
||||
src/plugins/preauth/pkinit/pkinit_clnt.c | 1 +
|
||||
src/plugins/preauth/spake/spake_client.c | 4 ++
|
||||
src/plugins/preauth/test/cltest.c | 11 +++
|
||||
src/tests/t_preauth.py | 88 +++++++++++++++++++++---
|
||||
src/tests/t_spake.py | 9 +--
|
||||
14 files changed, 134 insertions(+), 49 deletions(-)
|
||||
|
||||
diff --git a/src/include/krb5/clpreauth_plugin.h b/src/include/krb5/clpreauth_plugin.h
|
||||
index 0106734ad..5317669b7 100644
|
||||
--- a/src/include/krb5/clpreauth_plugin.h
|
||||
+++ b/src/include/krb5/clpreauth_plugin.h
|
||||
@@ -160,7 +160,21 @@ typedef struct krb5_clpreauth_callbacks_st {
|
||||
krb5_error_code (*set_cc_config)(krb5_context context,
|
||||
krb5_clpreauth_rock rock,
|
||||
const char *key, const char *data);
|
||||
+
|
||||
/* End of version 2 clpreauth callbacks (added in 1.11). */
|
||||
+
|
||||
+ /*
|
||||
+ * Prevent further fallbacks to other preauth mechanisms if the KDC replies
|
||||
+ * with an error. (The module itself can still respond to errors with its
|
||||
+ * tryagain method, or continue after KDC_ERR_MORE_PREAUTH_DATA_REQUIRED
|
||||
+ * errors with its process method.) A module should invoke this callback
|
||||
+ * from the process method when it generates an authenticated request using
|
||||
+ * credentials; often this will be the first or only client message
|
||||
+ * generated by the mechanism.
|
||||
+ */
|
||||
+ void (*disable_fallback)(krb5_context context, krb5_clpreauth_rock rock);
|
||||
+
|
||||
+ /* End of version 3 clpreauth callbacks (added in 1.17). */
|
||||
} *krb5_clpreauth_callbacks;
|
||||
|
||||
/*
|
||||
diff --git a/src/lib/krb5/krb/get_in_tkt.c b/src/lib/krb5/krb/get_in_tkt.c
|
||||
index 1d96ff163..c026bbc6d 100644
|
||||
--- a/src/lib/krb5/krb/get_in_tkt.c
|
||||
+++ b/src/lib/krb5/krb/get_in_tkt.c
|
||||
@@ -1331,9 +1331,7 @@ init_creds_step_request(krb5_context context,
|
||||
krb5_free_pa_data(context, ctx->optimistic_padata);
|
||||
ctx->optimistic_padata = NULL;
|
||||
if (code) {
|
||||
- /* Make an unauthenticated request, and possibly try again using
|
||||
- * the same mechanisms as we tried optimistically. */
|
||||
- k5_reset_preauth_types_tried(ctx);
|
||||
+ /* Make an unauthenticated request. */
|
||||
krb5_clear_error_message(context);
|
||||
code = 0;
|
||||
}
|
||||
@@ -1361,6 +1359,9 @@ init_creds_step_request(krb5_context context,
|
||||
/* Don't continue after a keyboard interrupt. */
|
||||
if (code == KRB5_LIBOS_PWDINTR)
|
||||
goto cleanup;
|
||||
+ /* Don't continue if fallback is disabled. */
|
||||
+ if (code && ctx->fallback_disabled)
|
||||
+ goto cleanup;
|
||||
if (code) {
|
||||
/* See if we can try a different preauth mech before giving up. */
|
||||
k5_save_ctx_error(context, code, &save);
|
||||
@@ -1549,16 +1550,10 @@ init_creds_step_reply(krb5_context context,
|
||||
} else if (reply_code == KDC_ERR_PREAUTH_FAILED && retry) {
|
||||
note_req_timestamp(context, ctx, ctx->err_reply->stime,
|
||||
ctx->err_reply->susec);
|
||||
- if (ctx->method_padata == NULL) {
|
||||
- /* Optimistic preauth failed on the KDC. Allow all mechanisms
|
||||
- * to be tried again using method data. */
|
||||
- k5_reset_preauth_types_tried(ctx);
|
||||
- } else {
|
||||
- /* Don't try again with the mechanism that failed. */
|
||||
- code = k5_preauth_note_failed(ctx, ctx->selected_preauth_type);
|
||||
- if (code)
|
||||
- goto cleanup;
|
||||
- }
|
||||
+ /* Don't try again with the mechanism that failed. */
|
||||
+ code = k5_preauth_note_failed(ctx, ctx->selected_preauth_type);
|
||||
+ if (code)
|
||||
+ goto cleanup;
|
||||
ctx->selected_preauth_type = KRB5_PADATA_NONE;
|
||||
/* Accept or update method data if the KDC sent it. */
|
||||
if (ctx->err_padata != NULL)
|
||||
diff --git a/src/lib/krb5/krb/init_creds_ctx.h b/src/lib/krb5/krb/init_creds_ctx.h
|
||||
index b19410a13..7ba61e17c 100644
|
||||
--- a/src/lib/krb5/krb/init_creds_ctx.h
|
||||
+++ b/src/lib/krb5/krb/init_creds_ctx.h
|
||||
@@ -60,6 +60,7 @@ struct _krb5_init_creds_context {
|
||||
krb5_enctype etype;
|
||||
krb5_boolean info_pa_permitted;
|
||||
krb5_boolean restarted;
|
||||
+ krb5_boolean fallback_disabled;
|
||||
struct krb5_responder_context_st rctx;
|
||||
krb5_preauthtype selected_preauth_type;
|
||||
krb5_preauthtype allowed_preauth_type;
|
||||
diff --git a/src/lib/krb5/krb/int-proto.h b/src/lib/krb5/krb/int-proto.h
|
||||
index cda9010e3..d20133885 100644
|
||||
--- a/src/lib/krb5/krb/int-proto.h
|
||||
+++ b/src/lib/krb5/krb/int-proto.h
|
||||
@@ -197,9 +197,6 @@ k5_init_preauth_context(krb5_context context);
|
||||
void
|
||||
k5_free_preauth_context(krb5_context context);
|
||||
|
||||
-void
|
||||
-k5_reset_preauth_types_tried(krb5_init_creds_context ctx);
|
||||
-
|
||||
krb5_error_code
|
||||
k5_preauth_note_failed(krb5_init_creds_context ctx, krb5_preauthtype pa_type);
|
||||
|
||||
diff --git a/src/lib/krb5/krb/preauth2.c b/src/lib/krb5/krb/preauth2.c
|
||||
index 451e0b7a8..1f17ec2b0 100644
|
||||
--- a/src/lib/krb5/krb/preauth2.c
|
||||
+++ b/src/lib/krb5/krb/preauth2.c
|
||||
@@ -203,18 +203,6 @@ cleanup:
|
||||
free_handles(context, list);
|
||||
}
|
||||
|
||||
-/* Reset the memory of which preauth types we have already tried. */
|
||||
-void
|
||||
-k5_reset_preauth_types_tried(krb5_init_creds_context ctx)
|
||||
-{
|
||||
- krb5_preauth_req_context reqctx = ctx->preauth_reqctx;
|
||||
-
|
||||
- if (reqctx == NULL)
|
||||
- return;
|
||||
- free(reqctx->failed);
|
||||
- reqctx->failed = NULL;
|
||||
-}
|
||||
-
|
||||
/* Add pa_type to the list of types which has previously failed. */
|
||||
krb5_error_code
|
||||
k5_preauth_note_failed(krb5_init_creds_context ctx, krb5_preauthtype pa_type)
|
||||
@@ -553,8 +541,14 @@ set_cc_config(krb5_context context, krb5_clpreauth_rock rock,
|
||||
return ret;
|
||||
}
|
||||
|
||||
+static void
|
||||
+disable_fallback(krb5_context context, krb5_clpreauth_rock rock)
|
||||
+{
|
||||
+ ((krb5_init_creds_context)rock)->fallback_disabled = TRUE;
|
||||
+}
|
||||
+
|
||||
static struct krb5_clpreauth_callbacks_st callbacks = {
|
||||
- 2,
|
||||
+ 3,
|
||||
get_etype,
|
||||
fast_armor,
|
||||
get_as_key,
|
||||
@@ -564,7 +558,8 @@ static struct krb5_clpreauth_callbacks_st callbacks = {
|
||||
responder_get_answer,
|
||||
need_as_key,
|
||||
get_cc_config,
|
||||
- set_cc_config
|
||||
+ set_cc_config,
|
||||
+ disable_fallback
|
||||
};
|
||||
|
||||
/* Tweak the request body, for now adding any enctypes which the module claims
|
||||
diff --git a/src/lib/krb5/krb/preauth_ec.c b/src/lib/krb5/krb/preauth_ec.c
|
||||
index c1aa9090f..75aab770e 100644
|
||||
--- a/src/lib/krb5/krb/preauth_ec.c
|
||||
+++ b/src/lib/krb5/krb/preauth_ec.c
|
||||
@@ -138,6 +138,7 @@ ec_process(krb5_context context, krb5_clpreauth_moddata moddata,
|
||||
encoded_ts->data = NULL;
|
||||
*out_padata = pa;
|
||||
pa = NULL;
|
||||
+ cb->disable_fallback(context, rock);
|
||||
}
|
||||
free(pa);
|
||||
krb5_free_data(context, encoded_ts);
|
||||
diff --git a/src/lib/krb5/krb/preauth_encts.c b/src/lib/krb5/krb/preauth_encts.c
|
||||
index cec384227..45bf9da92 100644
|
||||
--- a/src/lib/krb5/krb/preauth_encts.c
|
||||
+++ b/src/lib/krb5/krb/preauth_encts.c
|
||||
@@ -109,6 +109,8 @@ encts_process(krb5_context context, krb5_clpreauth_moddata moddata,
|
||||
*out_padata = pa;
|
||||
pa = NULL;
|
||||
|
||||
+ cb->disable_fallback(context, rock);
|
||||
+
|
||||
cleanup:
|
||||
krb5_free_data(context, ts);
|
||||
krb5_free_data(context, enc_ts);
|
||||
diff --git a/src/lib/krb5/krb/preauth_otp.c b/src/lib/krb5/krb/preauth_otp.c
|
||||
index 48fcbb5d5..13e584657 100644
|
||||
--- a/src/lib/krb5/krb/preauth_otp.c
|
||||
+++ b/src/lib/krb5/krb/preauth_otp.c
|
||||
@@ -1123,6 +1123,10 @@ otp_client_process(krb5_context context, krb5_clpreauth_moddata moddata,
|
||||
|
||||
/* Encode the request into the pa_data output. */
|
||||
retval = set_pa_data(req, pa_data_out);
|
||||
+ if (retval != 0)
|
||||
+ goto error;
|
||||
+ cb->disable_fallback(context, rock);
|
||||
+
|
||||
error:
|
||||
krb5_free_data_contents(context, &value);
|
||||
krb5_free_data_contents(context, &pin);
|
||||
diff --git a/src/lib/krb5/krb/preauth_sam2.c b/src/lib/krb5/krb/preauth_sam2.c
|
||||
index c8a330655..4c70021a9 100644
|
||||
--- a/src/lib/krb5/krb/preauth_sam2.c
|
||||
+++ b/src/lib/krb5/krb/preauth_sam2.c
|
||||
@@ -410,6 +410,7 @@ sam2_process(krb5_context context, krb5_clpreauth_moddata moddata,
|
||||
sam_padata[1] = NULL;
|
||||
|
||||
*out_padata = sam_padata;
|
||||
+ cb->disable_fallback(context, rock);
|
||||
|
||||
return(0);
|
||||
}
|
||||
diff --git a/src/plugins/preauth/pkinit/pkinit_clnt.c b/src/plugins/preauth/pkinit/pkinit_clnt.c
|
||||
index 9483d69e5..77e9e5308 100644
|
||||
--- a/src/plugins/preauth/pkinit/pkinit_clnt.c
|
||||
+++ b/src/plugins/preauth/pkinit/pkinit_clnt.c
|
||||
@@ -179,6 +179,7 @@ pa_pkinit_gen_req(krb5_context context,
|
||||
|
||||
*out_padata = return_pa_data;
|
||||
return_pa_data = NULL;
|
||||
+ cb->disable_fallback(context, rock);
|
||||
|
||||
cleanup:
|
||||
krb5_free_data(context, der_req);
|
||||
diff --git a/src/plugins/preauth/spake/spake_client.c b/src/plugins/preauth/spake/spake_client.c
|
||||
index 47a6ba26c..00734a13b 100644
|
||||
--- a/src/plugins/preauth/spake/spake_client.c
|
||||
+++ b/src/plugins/preauth/spake/spake_client.c
|
||||
@@ -278,6 +278,10 @@ process_challenge(krb5_context context, groupstate *gstate, reqstate *st,
|
||||
goto cleanup;
|
||||
TRACE_SPAKE_SEND_RESPONSE(context);
|
||||
ret = convert_to_padata(response, pa_out);
|
||||
+ if (ret)
|
||||
+ goto cleanup;
|
||||
+
|
||||
+ cb->disable_fallback(context, rock);
|
||||
|
||||
cleanup:
|
||||
krb5_free_keyblock(context, k0);
|
||||
diff --git a/src/plugins/preauth/test/cltest.c b/src/plugins/preauth/test/cltest.c
|
||||
index f5f7c5aba..51b848481 100644
|
||||
--- a/src/plugins/preauth/test/cltest.c
|
||||
+++ b/src/plugins/preauth/test/cltest.c
|
||||
@@ -53,6 +53,9 @@
|
||||
* - If the "fail_optimistic", "fail_2rt", or "fail_tryagain" gic options are
|
||||
* set, it fails with a recognizable error string at the requested point in
|
||||
* processing.
|
||||
+ *
|
||||
+ * - If the "disable_fallback" gic option is set, fallback is disabled when a
|
||||
+ * client message is generated.
|
||||
*/
|
||||
|
||||
#include "k5-int.h"
|
||||
@@ -66,6 +69,7 @@ struct client_state {
|
||||
krb5_boolean fail_optimistic;
|
||||
krb5_boolean fail_2rt;
|
||||
krb5_boolean fail_tryagain;
|
||||
+ krb5_boolean disable_fallback;
|
||||
};
|
||||
|
||||
struct client_request_state {
|
||||
@@ -81,6 +85,7 @@ test_init(krb5_context context, krb5_clpreauth_moddata *moddata_out)
|
||||
assert(st != NULL);
|
||||
st->indicators = NULL;
|
||||
st->fail_optimistic = st->fail_2rt = st->fail_tryagain = FALSE;
|
||||
+ st->disable_fallback = FALSE;
|
||||
*moddata_out = (krb5_clpreauth_moddata)st;
|
||||
return 0;
|
||||
}
|
||||
@@ -138,6 +143,8 @@ test_process(krb5_context context, krb5_clpreauth_moddata moddata,
|
||||
return KRB5_PREAUTH_FAILED;
|
||||
}
|
||||
*out_pa_data = make_pa_list("optimistic", 10);
|
||||
+ if (st->disable_fallback)
|
||||
+ cb->disable_fallback(context, rock);
|
||||
return 0;
|
||||
} else if (reqst->second_round_trip) {
|
||||
printf("2rt: %.*s\n", pa_data->length, pa_data->contents);
|
||||
@@ -166,6 +173,8 @@ test_process(krb5_context context, krb5_clpreauth_moddata moddata,
|
||||
|
||||
indstr = (st->indicators != NULL) ? st->indicators : "";
|
||||
*out_pa_data = make_pa_list(indstr, strlen(indstr));
|
||||
+ if (st->disable_fallback)
|
||||
+ cb->disable_fallback(context, rock);
|
||||
return 0;
|
||||
}
|
||||
|
||||
@@ -212,6 +221,8 @@ test_gic_opt(krb5_context kcontext, krb5_clpreauth_moddata moddata,
|
||||
st->fail_2rt = TRUE;
|
||||
} else if (strcmp(attr, "fail_tryagain") == 0) {
|
||||
st->fail_tryagain = TRUE;
|
||||
+ } else if (strcmp(attr, "disable_fallback") == 0) {
|
||||
+ st->disable_fallback = TRUE;
|
||||
}
|
||||
return 0;
|
||||
}
|
||||
diff --git a/src/tests/t_preauth.py b/src/tests/t_preauth.py
|
||||
index efb3ea20d..32e35b08b 100644
|
||||
--- a/src/tests/t_preauth.py
|
||||
+++ b/src/tests/t_preauth.py
|
||||
@@ -37,8 +37,8 @@ expected_trace = ('Attempting optimistic preauth',
|
||||
realm.run(['./icred', '-o', '-123', realm.user_princ, password('user')],
|
||||
expected_trace=expected_trace)
|
||||
|
||||
-# Test optimistic preauth failing on client, followed by successful
|
||||
-# preauth using the same module.
|
||||
+# Test optimistic preauth failing on client, falling back to encrypted
|
||||
+# timestamp.
|
||||
msgs = ('Attempting optimistic preauth',
|
||||
'Processing preauth types: -123',
|
||||
'/induced optimistic fail',
|
||||
@@ -46,15 +46,15 @@ msgs = ('Attempting optimistic preauth',
|
||||
'/Additional pre-authentication required',
|
||||
'Preauthenticating using KDC method data',
|
||||
'Processing preauth types:',
|
||||
- 'Preauth module test (-123) (real) returned: 0/Success',
|
||||
- 'Produced preauth for next request: PA-FX-COOKIE (133), -123',
|
||||
+ 'Encrypted timestamp (for ',
|
||||
+ 'module encrypted_timestamp (2) (real) returned: 0/Success',
|
||||
+ 'preauth for next request: PA-FX-COOKIE (133), PA-ENC-TIMESTAMP (2)',
|
||||
'Decrypted AS reply')
|
||||
realm.run(['./icred', '-o', '-123', '-X', 'fail_optimistic', realm.user_princ,
|
||||
- password('user')], expected_msg='testval',
|
||||
- expected_trace=msgs)
|
||||
+ password('user')], expected_trace=msgs)
|
||||
|
||||
-# Test optimistic preauth failing on KDC, followed by successful preauth
|
||||
-# using the same module.
|
||||
+# Test optimistic preauth failing on KDC, falling back to encrypted
|
||||
+# timestamp.
|
||||
realm.run([kadminl, 'setstr', realm.user_princ, 'failopt', 'yes'])
|
||||
msgs = ('Attempting optimistic preauth',
|
||||
'Processing preauth types: -123',
|
||||
@@ -63,11 +63,24 @@ msgs = ('Attempting optimistic preauth',
|
||||
'/Preauthentication failed',
|
||||
'Preauthenticating using KDC method data',
|
||||
'Processing preauth types:',
|
||||
- 'Preauth module test (-123) (real) returned: 0/Success',
|
||||
- 'Produced preauth for next request: PA-FX-COOKIE (133), -123',
|
||||
+ 'Encrypted timestamp (for ',
|
||||
+ 'module encrypted_timestamp (2) (real) returned: 0/Success',
|
||||
+ 'preauth for next request: PA-FX-COOKIE (133), PA-ENC-TIMESTAMP (2)',
|
||||
'Decrypted AS reply')
|
||||
realm.run(['./icred', '-o', '-123', realm.user_princ, password('user')],
|
||||
- expected_msg='testval', expected_trace=msgs)
|
||||
+ expected_trace=msgs)
|
||||
+# Leave failopt set for the next test.
|
||||
+
|
||||
+# Test optimistic preauth failing on KDC, stopping because the test
|
||||
+# module disabled fallback.
|
||||
+msgs = ('Attempting optimistic preauth',
|
||||
+ 'Processing preauth types: -123',
|
||||
+ 'Preauth module test (-123) (real) returned: 0/Success',
|
||||
+ 'Produced preauth for next request: -123',
|
||||
+ '/Preauthentication failed')
|
||||
+realm.run(['./icred', '-X', 'disable_fallback', '-o', '-123', realm.user_princ,
|
||||
+ password('user')], expected_code=1,
|
||||
+ expected_msg='Preauthentication failed', expected_trace=msgs)
|
||||
realm.run([kadminl, 'delstr', realm.user_princ, 'failopt'])
|
||||
|
||||
# Test KDC_ERR_MORE_PREAUTH_DATA_REQUIRED and secure cookies.
|
||||
@@ -107,6 +120,23 @@ msgs = ('Sending unauthenticated request',
|
||||
realm.run(['./icred', '-X', 'fail_2rt', realm.user_princ, password('user')],
|
||||
expected_msg='2rt: secondtrip', expected_trace=msgs)
|
||||
|
||||
+# Test client-side failure after KDC_ERR_MORE_PREAUTH_DATA_REQUIRED,
|
||||
+# stopping because the test module disabled fallback.
|
||||
+msgs = ('Sending unauthenticated request',
|
||||
+ '/Additional pre-authentication required',
|
||||
+ 'Preauthenticating using KDC method data',
|
||||
+ 'Processing preauth types:',
|
||||
+ 'Preauth module test (-123) (real) returned: 0/Success',
|
||||
+ 'Produced preauth for next request: PA-FX-COOKIE (133), -123',
|
||||
+ '/More preauthentication data is required',
|
||||
+ 'Continuing preauth mech -123',
|
||||
+ 'Processing preauth types: -123, PA-FX-COOKIE (133)',
|
||||
+ '/induced 2rt fail')
|
||||
+realm.run(['./icred', '-X', 'fail_2rt', '-X', 'disable_fallback',
|
||||
+ realm.user_princ, password('user')], expected_code=1,
|
||||
+ expected_msg='Pre-authentication failed: induced 2rt fail',
|
||||
+ expected_trace=msgs)
|
||||
+
|
||||
# Test KDC-side failure after KDC_ERR_MORE_PREAUTH_DATA_REQUIRED,
|
||||
# falling back to encrypted timestamp.
|
||||
realm.run([kadminl, 'setstr', realm.user_princ, 'fail2rt', 'yes'])
|
||||
@@ -130,6 +160,25 @@ msgs = ('Sending unauthenticated request',
|
||||
'Decrypted AS reply')
|
||||
realm.run(['./icred', realm.user_princ, password('user')],
|
||||
expected_msg='2rt: secondtrip', expected_trace=msgs)
|
||||
+# Leave fail2rt set for the next test.
|
||||
+
|
||||
+# Test KDC-side failure after KDC_ERR_MORE_PREAUTH_DATA_REQUIRED,
|
||||
+# stopping because the test module disabled fallback.
|
||||
+msgs = ('Sending unauthenticated request',
|
||||
+ '/Additional pre-authentication required',
|
||||
+ 'Preauthenticating using KDC method data',
|
||||
+ 'Processing preauth types:',
|
||||
+ 'Preauth module test (-123) (real) returned: 0/Success',
|
||||
+ 'Produced preauth for next request: PA-FX-COOKIE (133), -123',
|
||||
+ '/More preauthentication data is required',
|
||||
+ 'Continuing preauth mech -123',
|
||||
+ 'Processing preauth types: -123, PA-FX-COOKIE (133)',
|
||||
+ 'Preauth module test (-123) (real) returned: 0/Success',
|
||||
+ 'Produced preauth for next request: PA-FX-COOKIE (133), -123',
|
||||
+ '/Preauthentication failed')
|
||||
+realm.run(['./icred', '-X', 'disable_fallback',
|
||||
+ realm.user_princ, password('user')], expected_code=1,
|
||||
+ expected_msg='Preauthentication failed', expected_trace=msgs)
|
||||
realm.run([kadminl, 'delstr', realm.user_princ, 'fail2rt'])
|
||||
|
||||
# Test tryagain flow by inducing a KDC_ERR_ENCTYPE_NOSUPP error on the KDC.
|
||||
@@ -170,6 +219,23 @@ msgs = ('Sending unauthenticated request',
|
||||
realm.run(['./icred', '-X', 'fail_tryagain', realm.user_princ,
|
||||
password('user')], expected_trace=msgs)
|
||||
|
||||
+# Test a client-side tryagain failure, stopping because the test
|
||||
+# module disabled fallback.
|
||||
+msgs = ('Sending unauthenticated request',
|
||||
+ '/Additional pre-authentication required',
|
||||
+ 'Preauthenticating using KDC method data',
|
||||
+ 'Processing preauth types:',
|
||||
+ 'Preauth module test (-123) (real) returned: 0/Success',
|
||||
+ 'Produced preauth for next request: PA-FX-COOKIE (133), -123',
|
||||
+ '/KDC has no support for encryption type',
|
||||
+ 'Recovering from KDC error 14 using preauth mech -123',
|
||||
+ 'Preauth tryagain input types (-123): -123, PA-FX-COOKIE (133)',
|
||||
+ '/induced tryagain fail')
|
||||
+realm.run(['./icred', '-X', 'fail_tryagain', '-X', 'disable_fallback',
|
||||
+ realm.user_princ, password('user')], expected_code=1,
|
||||
+ expected_msg='KDC has no support for encryption type',
|
||||
+ expected_trace=msgs)
|
||||
+
|
||||
# Test that multiple stepwise initial creds operations can be
|
||||
# performed with the same krb5_context, with proper tracking of
|
||||
# clpreauth module request handles.
|
||||
diff --git a/src/tests/t_spake.py b/src/tests/t_spake.py
|
||||
index a81a238b4..5b47e62d3 100644
|
||||
--- a/src/tests/t_spake.py
|
||||
+++ b/src/tests/t_spake.py
|
||||
@@ -31,9 +31,7 @@ for gnum, gname in groups:
|
||||
'Decrypted AS reply')
|
||||
realm.kinit('user', 'pw', expected_trace=msgs)
|
||||
|
||||
- # Test an unsuccessful authentication. (The client will try
|
||||
- # again with encrypted timestamp, which isn't really desired,
|
||||
- # but check for that as long as it is expected.)
|
||||
+ # Test an unsuccessful authentication.
|
||||
msgs = ('/Additional pre-authentication required',
|
||||
'Selected etype info:',
|
||||
'Sending SPAKE support message',
|
||||
@@ -42,9 +40,6 @@ for gnum, gname in groups:
|
||||
'Continuing preauth mech PA-SPAKE (151)',
|
||||
'SPAKE challenge received with group ' + str(gnum),
|
||||
'Sending SPAKE response',
|
||||
- '/Preauthentication failed',
|
||||
- 'Encrypted timestamp ',
|
||||
- 'for next request: PA-FX-COOKIE (133), PA-ENC-TIMESTAMP (2)',
|
||||
'/Preauthentication failed')
|
||||
realm.kinit('user', 'wrongpw', expected_code=1, expected_trace=msgs)
|
||||
|
||||
@@ -114,8 +109,6 @@ msgs = ('Attempting optimistic preauth',
|
||||
'for next request: PA-SPAKE (151)',
|
||||
'/Preauthentication failed',
|
||||
'Selected etype info:',
|
||||
- 'SPAKE challenge with group 1 rejected',
|
||||
- 'spake (151) (real) returned: -1765328360/Preauthentication failed',
|
||||
'Encrypted timestamp ',
|
||||
'for next request: PA-FX-COOKIE (133), PA-ENC-TIMESTAMP (2)',
|
||||
'AS key determined by preauth:',
|
||||
738
Simplify-kdc_preauth.c-systems-table.patch
Normal file
738
Simplify-kdc_preauth.c-systems-table.patch
Normal file
|
|
@ -0,0 +1,738 @@
|
|||
From 65f078dfc68f5680e87e686a59970291b64ebd95 Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Sun, 11 Feb 2018 15:23:35 -0500
|
||||
Subject: [PATCH] Simplify kdc_preauth.c systems table
|
||||
|
||||
Get rid of static_preauth_systems, and replace it with explicit calls
|
||||
to helper functions in get_preauth_hint_list() and return_padata().
|
||||
Stop preallocating pa-data lists, instead reallocating on each
|
||||
addition using add_pa_data_element(). Also simplify
|
||||
maybe_add_etype_info2() using add_pa_data_element().
|
||||
|
||||
The KRB5_PADATA_PAC_REQUEST table entry did nothing, and was probably
|
||||
originally added back when the KDC would error out on unrecognized
|
||||
padata types. The KRB5_PADATA_SERVER_REFERRAL entry has been disabled
|
||||
since it was first added.
|
||||
|
||||
(cherry picked from commit fea1a488924faa3938ef723feaa1ff12d22a91ff)
|
||||
---
|
||||
src/kdc/kdc_preauth.c | 526 +++++++++++++++---------------------------
|
||||
1 file changed, 184 insertions(+), 342 deletions(-)
|
||||
|
||||
diff --git a/src/kdc/kdc_preauth.c b/src/kdc/kdc_preauth.c
|
||||
index edc30bd83..6f34dc289 100644
|
||||
--- a/src/kdc/kdc_preauth.c
|
||||
+++ b/src/kdc/kdc_preauth.c
|
||||
@@ -101,108 +101,14 @@ typedef struct preauth_system_st {
|
||||
krb5_kdcpreauth_loop_fn loop;
|
||||
} preauth_system;
|
||||
|
||||
+static preauth_system *preauth_systems;
|
||||
+static size_t n_preauth_systems;
|
||||
+
|
||||
static krb5_error_code
|
||||
make_etype_info(krb5_context context, krb5_preauthtype pa_type,
|
||||
krb5_principal client, krb5_key_data *client_key,
|
||||
krb5_enctype enctype, krb5_pa_data **pa_out);
|
||||
|
||||
-static void
|
||||
-get_etype_info(krb5_context context, krb5_kdc_req *request,
|
||||
- krb5_kdcpreauth_callbacks cb, krb5_kdcpreauth_rock rock,
|
||||
- krb5_kdcpreauth_moddata moddata, krb5_preauthtype pa_type,
|
||||
- krb5_kdcpreauth_edata_respond_fn respond, void *arg);
|
||||
-
|
||||
-static krb5_error_code
|
||||
-return_etype_info(krb5_context, krb5_pa_data *padata,
|
||||
- krb5_data *req_pkt, krb5_kdc_req *request,
|
||||
- krb5_kdc_rep *reply, krb5_keyblock *encrypting_key,
|
||||
- krb5_pa_data **send_pa, krb5_kdcpreauth_callbacks cb,
|
||||
- krb5_kdcpreauth_rock rock, krb5_kdcpreauth_moddata moddata,
|
||||
- krb5_kdcpreauth_modreq modreq);
|
||||
-
|
||||
-static krb5_error_code
|
||||
-return_pw_salt(krb5_context, krb5_pa_data *padata,
|
||||
- krb5_data *req_pkt, krb5_kdc_req *request, krb5_kdc_rep *reply,
|
||||
- krb5_keyblock *encrypting_key, krb5_pa_data **send_pa,
|
||||
- krb5_kdcpreauth_callbacks cb, krb5_kdcpreauth_rock rock,
|
||||
- krb5_kdcpreauth_moddata moddata, krb5_kdcpreauth_modreq modreq);
|
||||
-
|
||||
-
|
||||
-
|
||||
-static preauth_system static_preauth_systems[] = {
|
||||
- {
|
||||
- "FAST",
|
||||
- KRB5_PADATA_FX_FAST,
|
||||
- PA_HARDWARE,
|
||||
- NULL,
|
||||
- NULL,
|
||||
- NULL,
|
||||
- NULL,
|
||||
- NULL,
|
||||
- 0
|
||||
- },
|
||||
- {
|
||||
- "etype-info",
|
||||
- KRB5_PADATA_ETYPE_INFO,
|
||||
- PA_HARDWARE,
|
||||
- NULL,
|
||||
- NULL,
|
||||
- NULL,
|
||||
- get_etype_info,
|
||||
- 0,
|
||||
- return_etype_info
|
||||
- },
|
||||
- {
|
||||
- "etype-info2",
|
||||
- KRB5_PADATA_ETYPE_INFO2,
|
||||
- PA_HARDWARE,
|
||||
- NULL,
|
||||
- NULL,
|
||||
- NULL,
|
||||
- get_etype_info,
|
||||
- 0,
|
||||
- return_etype_info
|
||||
- },
|
||||
- {
|
||||
- "pw-salt",
|
||||
- KRB5_PADATA_PW_SALT,
|
||||
- PA_PSEUDO, /* Don't include this in the error list */
|
||||
- NULL,
|
||||
- NULL,
|
||||
- NULL,
|
||||
- 0,
|
||||
- 0,
|
||||
- return_pw_salt
|
||||
- },
|
||||
- {
|
||||
- "pac-request",
|
||||
- KRB5_PADATA_PAC_REQUEST,
|
||||
- PA_PSEUDO,
|
||||
- NULL,
|
||||
- NULL,
|
||||
- NULL,
|
||||
- NULL,
|
||||
- NULL,
|
||||
- NULL
|
||||
- },
|
||||
-#if 0
|
||||
- {
|
||||
- "server-referral",
|
||||
- KRB5_PADATA_SERVER_REFERRAL,
|
||||
- PA_PSEUDO,
|
||||
- 0,
|
||||
- 0,
|
||||
- return_server_referral
|
||||
- },
|
||||
-#endif
|
||||
-};
|
||||
-
|
||||
-#define NUM_STATIC_PREAUTH_SYSTEMS (sizeof(static_preauth_systems) / \
|
||||
- sizeof(*static_preauth_systems))
|
||||
-
|
||||
-static preauth_system *preauth_systems;
|
||||
-static size_t n_preauth_systems;
|
||||
-
|
||||
/* Get all available kdcpreauth vtables and a count of preauth types they
|
||||
* support. Return an empty list on failure. */
|
||||
static void
|
||||
@@ -284,7 +190,6 @@ load_preauth_plugins(struct server_handle *handle, krb5_context context,
|
||||
get_plugin_vtables(context, &vtables, &n_tables, &n_systems);
|
||||
|
||||
/* Allocate the list of static and plugin preauth systems. */
|
||||
- n_systems += NUM_STATIC_PREAUTH_SYSTEMS;
|
||||
preauth_systems = calloc(n_systems + 1, sizeof(preauth_system));
|
||||
if (preauth_systems == NULL)
|
||||
goto cleanup;
|
||||
@@ -292,13 +197,8 @@ load_preauth_plugins(struct server_handle *handle, krb5_context context,
|
||||
if (get_realm_names(handle, &realm_names))
|
||||
goto cleanup;
|
||||
|
||||
- /* Add the static system to the list first. No static systems require
|
||||
- * initialization, so just make a direct copy. */
|
||||
- memcpy(preauth_systems, static_preauth_systems,
|
||||
- sizeof(static_preauth_systems));
|
||||
-
|
||||
/* Add the dynamically-loaded mechanisms to the list. */
|
||||
- n_systems = NUM_STATIC_PREAUTH_SYSTEMS;
|
||||
+ n_systems = 0;
|
||||
for (i = 0; i < n_tables; i++) {
|
||||
/* Try to initialize this module. */
|
||||
vt = &vtables[i];
|
||||
@@ -622,7 +522,9 @@ find_pa_system(int type, preauth_system **preauth)
|
||||
{
|
||||
preauth_system *ap;
|
||||
|
||||
- ap = preauth_systems ? preauth_systems : static_preauth_systems;
|
||||
+ if (preauth_systems == NULL)
|
||||
+ return KRB5_PREAUTH_BAD_TYPE;
|
||||
+ ap = preauth_systems;
|
||||
while ((ap->type != -1) && (ap->type != type))
|
||||
ap++;
|
||||
if (ap->type == -1)
|
||||
@@ -776,6 +678,98 @@ const char *missing_required_preauth(krb5_db_entry *client,
|
||||
return 0;
|
||||
}
|
||||
|
||||
+/* Return true if request's enctypes indicate support for etype-info2. */
|
||||
+static krb5_boolean
|
||||
+requires_info2(const krb5_kdc_req *request)
|
||||
+{
|
||||
+ int i;
|
||||
+
|
||||
+ for (i = 0; i < request->nktypes; i++) {
|
||||
+ if (enctype_requires_etype_info_2(request->ktype[i]))
|
||||
+ return TRUE;
|
||||
+ }
|
||||
+ return FALSE;
|
||||
+}
|
||||
+
|
||||
+/* Add PA-ETYPE-INFO2 and possibly PA-ETYPE-INFO entries to pa_list as
|
||||
+ * appropriate for the request and client principal. */
|
||||
+static krb5_error_code
|
||||
+add_etype_info(krb5_context context, krb5_kdcpreauth_rock rock,
|
||||
+ krb5_pa_data ***pa_list)
|
||||
+{
|
||||
+ krb5_error_code ret;
|
||||
+ krb5_pa_data *pa;
|
||||
+
|
||||
+ if (rock->client_key == NULL)
|
||||
+ return 0;
|
||||
+
|
||||
+ if (!requires_info2(rock->request)) {
|
||||
+ /* Include PA-ETYPE-INFO only for old clients. */
|
||||
+ ret = make_etype_info(context, KRB5_PADATA_ETYPE_INFO,
|
||||
+ rock->client->princ, rock->client_key,
|
||||
+ rock->client_keyblock->enctype, &pa);
|
||||
+ if (ret)
|
||||
+ return ret;
|
||||
+ /* add_pa_data_element() claims pa on success or failure. */
|
||||
+ ret = add_pa_data_element(pa_list, pa);
|
||||
+ if (ret)
|
||||
+ return ret;
|
||||
+ }
|
||||
+
|
||||
+ /* Always include PA-ETYPE-INFO2. */
|
||||
+ ret = make_etype_info(context, KRB5_PADATA_ETYPE_INFO2,
|
||||
+ rock->client->princ, rock->client_key,
|
||||
+ rock->client_keyblock->enctype, &pa);
|
||||
+ if (ret)
|
||||
+ return ret;
|
||||
+ /* add_pa_data_element() claims pa on success or failure. */
|
||||
+ return add_pa_data_element(pa_list, pa);
|
||||
+}
|
||||
+
|
||||
+/* Add PW-SALT or AFS3-SALT entries to pa_list as appropriate for the request
|
||||
+ * and client principal. */
|
||||
+static krb5_error_code
|
||||
+add_pw_salt(krb5_context context, krb5_kdcpreauth_rock rock,
|
||||
+ krb5_pa_data ***pa_list)
|
||||
+{
|
||||
+ krb5_error_code ret;
|
||||
+ krb5_pa_data *pa;
|
||||
+ krb5_data *salt = NULL;
|
||||
+ krb5_int16 salttype;
|
||||
+
|
||||
+ /* Only include this pa-data for old clients. */
|
||||
+ if (rock->client_key == NULL || requires_info2(rock->request))
|
||||
+ return 0;
|
||||
+
|
||||
+ ret = krb5_dbe_compute_salt(context, rock->client_key,
|
||||
+ rock->request->client, &salttype, &salt);
|
||||
+ if (ret)
|
||||
+ return 0;
|
||||
+
|
||||
+ if (salttype == KRB5_KDB_SALTTYPE_AFS3) {
|
||||
+ ret = alloc_pa_data(KRB5_PADATA_AFS3_SALT, salt->length + 1, &pa);
|
||||
+ if (ret)
|
||||
+ goto cleanup;
|
||||
+ memcpy(pa->contents, salt->data, salt->length);
|
||||
+ pa->contents[salt->length] = '\0';
|
||||
+ } else {
|
||||
+ /* Steal memory from salt to make the pa-data entry. */
|
||||
+ ret = alloc_pa_data(KRB5_PADATA_PW_SALT, 0, &pa);
|
||||
+ if (ret)
|
||||
+ goto cleanup;
|
||||
+ pa->length = salt->length;
|
||||
+ pa->contents = (uint8_t *)salt->data;
|
||||
+ salt->data = NULL;
|
||||
+ }
|
||||
+
|
||||
+ /* add_pa_data_element() claims pa on success or failure. */
|
||||
+ ret = add_pa_data_element(pa_list, pa);
|
||||
+
|
||||
+cleanup:
|
||||
+ krb5_free_data(context, salt);
|
||||
+ return ret;
|
||||
+}
|
||||
+
|
||||
struct hint_state {
|
||||
kdc_hint_respond_fn respond;
|
||||
void *arg;
|
||||
@@ -787,7 +781,7 @@ struct hint_state {
|
||||
|
||||
int hw_only;
|
||||
preauth_system *ap;
|
||||
- krb5_pa_data **pa_data, **pa_cur;
|
||||
+ krb5_pa_data **pa_data;
|
||||
krb5_preauthtype pa_type;
|
||||
};
|
||||
|
||||
@@ -799,7 +793,7 @@ hint_list_finish(struct hint_state *state, krb5_error_code code)
|
||||
kdc_realm_t *kdc_active_realm = state->realm;
|
||||
|
||||
if (!code) {
|
||||
- if (state->pa_data[0] == 0) {
|
||||
+ if (state->pa_data == NULL) {
|
||||
krb5_klog_syslog(LOG_INFO,
|
||||
_("%spreauth required but hint list is empty"),
|
||||
state->hw_only ? "hw" : "");
|
||||
@@ -820,20 +814,27 @@ hint_list_next(struct hint_state *arg);
|
||||
static void
|
||||
finish_get_edata(void *arg, krb5_error_code code, krb5_pa_data *pa)
|
||||
{
|
||||
+ krb5_error_code ret;
|
||||
struct hint_state *state = arg;
|
||||
|
||||
if (code == 0) {
|
||||
if (pa == NULL) {
|
||||
- /* Include an empty value of the current type. */
|
||||
- pa = calloc(1, sizeof(*pa));
|
||||
- pa->magic = KV5M_PA_DATA;
|
||||
- pa->pa_type = state->pa_type;
|
||||
+ ret = alloc_pa_data(state->pa_type, 0, &pa);
|
||||
+ if (ret)
|
||||
+ goto error;
|
||||
}
|
||||
- *state->pa_cur++ = pa;
|
||||
+ /* add_pa_data_element() claims pa on success or failure. */
|
||||
+ ret = add_pa_data_element(&state->pa_data, pa);
|
||||
+ if (ret)
|
||||
+ goto error;
|
||||
}
|
||||
|
||||
state->ap++;
|
||||
hint_list_next(state);
|
||||
+ return;
|
||||
+
|
||||
+error:
|
||||
+ hint_list_finish(state, ret);
|
||||
}
|
||||
|
||||
static void
|
||||
@@ -870,16 +871,16 @@ get_preauth_hint_list(krb5_kdc_req *request, krb5_kdcpreauth_rock rock,
|
||||
krb5_pa_data ***e_data_out, kdc_hint_respond_fn respond,
|
||||
void *arg)
|
||||
{
|
||||
+ kdc_realm_t *kdc_active_realm = rock->rstate->realm_data;
|
||||
struct hint_state *state;
|
||||
+ krb5_pa_data *pa;
|
||||
|
||||
*e_data_out = NULL;
|
||||
|
||||
/* Allocate our state. */
|
||||
state = calloc(1, sizeof(*state));
|
||||
- if (state == NULL) {
|
||||
- (*respond)(arg);
|
||||
- return;
|
||||
- }
|
||||
+ if (state == NULL)
|
||||
+ goto error;
|
||||
state->hw_only = isflagset(rock->client->attributes,
|
||||
KRB5_KDB_REQUIRES_HW_AUTH);
|
||||
state->respond = respond;
|
||||
@@ -888,17 +889,27 @@ get_preauth_hint_list(krb5_kdc_req *request, krb5_kdcpreauth_rock rock,
|
||||
state->rock = rock;
|
||||
state->realm = rock->rstate->realm_data;
|
||||
state->e_data_out = e_data_out;
|
||||
-
|
||||
- state->pa_data = calloc(n_preauth_systems + 1, sizeof(krb5_pa_data *));
|
||||
- if (!state->pa_data) {
|
||||
- free(state);
|
||||
- (*respond)(arg);
|
||||
- return;
|
||||
- }
|
||||
-
|
||||
- state->pa_cur = state->pa_data;
|
||||
+ state->pa_data = NULL;
|
||||
state->ap = preauth_systems;
|
||||
+
|
||||
+ /* Add an empty PA-FX-FAST element to advertise FAST support. */
|
||||
+ if (alloc_pa_data(KRB5_PADATA_FX_FAST, 0, &pa) != 0)
|
||||
+ goto error;
|
||||
+ /* add_pa_data_element() claims pa on success or failure. */
|
||||
+ if (add_pa_data_element(&state->pa_data, pa) != 0)
|
||||
+ goto error;
|
||||
+
|
||||
+ if (add_etype_info(kdc_context, rock, &state->pa_data) != 0)
|
||||
+ goto error;
|
||||
+
|
||||
hint_list_next(state);
|
||||
+ return;
|
||||
+
|
||||
+error:
|
||||
+ if (state != NULL)
|
||||
+ krb5_free_pa_data(kdc_context, state->pa_data);
|
||||
+ free(state);
|
||||
+ (*respond)(arg);
|
||||
}
|
||||
|
||||
/*
|
||||
@@ -1029,10 +1040,10 @@ filter_preauth_error(krb5_error_code code)
|
||||
static krb5_error_code
|
||||
maybe_add_etype_info2(struct padata_state *state, krb5_error_code code)
|
||||
{
|
||||
+ krb5_error_code ret;
|
||||
krb5_context context = state->context;
|
||||
krb5_kdcpreauth_rock rock = state->rock;
|
||||
- krb5_pa_data **list = state->pa_e_data;
|
||||
- size_t count;
|
||||
+ krb5_pa_data *pa;
|
||||
|
||||
/* Only add key information when requesting another preauth round trip. */
|
||||
if (code != KRB5KDC_ERR_MORE_PREAUTH_DATA_REQUIRED)
|
||||
@@ -1048,18 +1059,14 @@ maybe_add_etype_info2(struct padata_state *state, krb5_error_code code)
|
||||
KRB5_PADATA_FX_COOKIE) != NULL)
|
||||
return 0;
|
||||
|
||||
- /* Reallocate state->pa_e_data to make room for the etype-info2 element. */
|
||||
- for (count = 0; list != NULL && list[count] != NULL; count++);
|
||||
- list = realloc(list, (count + 2) * sizeof(*list));
|
||||
- if (list == NULL)
|
||||
- return ENOMEM;
|
||||
- list[count] = list[count + 1] = NULL;
|
||||
- state->pa_e_data = list;
|
||||
+ ret = make_etype_info(context, KRB5_PADATA_ETYPE_INFO2,
|
||||
+ rock->client->princ, rock->client_key,
|
||||
+ rock->client_keyblock->enctype, &pa);
|
||||
+ if (ret)
|
||||
+ return ret;
|
||||
|
||||
- /* Generate an etype-info2 element in the new slot. */
|
||||
- return make_etype_info(context, KRB5_PADATA_ETYPE_INFO2,
|
||||
- rock->client->princ, rock->client_key,
|
||||
- rock->client_keyblock->enctype, &list[count]);
|
||||
+ /* add_pa_data_element() claims pa on success or failure. */
|
||||
+ return add_pa_data_element(&state->pa_e_data, pa);
|
||||
}
|
||||
|
||||
/* Release state and respond to the AS-REQ processing code with the result of
|
||||
@@ -1279,17 +1286,20 @@ return_padata(krb5_context context, krb5_kdcpreauth_rock rock,
|
||||
{
|
||||
krb5_error_code retval;
|
||||
krb5_pa_data ** padata;
|
||||
- krb5_pa_data ** send_pa_list;
|
||||
- krb5_pa_data ** send_pa;
|
||||
+ krb5_pa_data ** send_pa_list = NULL;
|
||||
+ krb5_pa_data * send_pa;
|
||||
krb5_pa_data * pa = 0;
|
||||
krb5_pa_data null_item;
|
||||
preauth_system * ap;
|
||||
- int * pa_order;
|
||||
+ int * pa_order = NULL;
|
||||
int * pa_type;
|
||||
int size = 0;
|
||||
krb5_kdcpreauth_modreq *modreq_ptr;
|
||||
krb5_boolean key_modified;
|
||||
krb5_keyblock original_key;
|
||||
+
|
||||
+ memset(&original_key, 0, sizeof(original_key));
|
||||
+
|
||||
if ((!*padata_context) &&
|
||||
(make_padata_context(context, padata_context) != 0)) {
|
||||
return KRB5KRB_ERR_GENERIC;
|
||||
@@ -1300,26 +1310,18 @@ return_padata(krb5_context context, krb5_kdcpreauth_rock rock,
|
||||
size++;
|
||||
}
|
||||
|
||||
- if ((send_pa_list = malloc((size+1) * sizeof(krb5_pa_data *))) == NULL)
|
||||
- return ENOMEM;
|
||||
- if ((pa_order = malloc((size+1) * sizeof(int))) == NULL) {
|
||||
- free(send_pa_list);
|
||||
- return ENOMEM;
|
||||
- }
|
||||
+ pa_order = k5calloc(size + 1, sizeof(int), &retval);
|
||||
+ if (pa_order == NULL)
|
||||
+ goto cleanup;
|
||||
sort_pa_order(context, request, pa_order);
|
||||
|
||||
retval = krb5_copy_keyblock_contents(context, encrypting_key,
|
||||
&original_key);
|
||||
- if (retval) {
|
||||
- free(send_pa_list);
|
||||
- free(pa_order);
|
||||
- return retval;
|
||||
- }
|
||||
+ if (retval)
|
||||
+ goto cleanup;
|
||||
key_modified = FALSE;
|
||||
null_item.contents = NULL;
|
||||
null_item.length = 0;
|
||||
- send_pa = send_pa_list;
|
||||
- *send_pa = 0;
|
||||
|
||||
for (pa_type = pa_order; *pa_type != -1; pa_type++) {
|
||||
ap = &preauth_systems[*pa_type];
|
||||
@@ -1349,20 +1351,30 @@ return_padata(krb5_context context, krb5_kdcpreauth_rock rock,
|
||||
}
|
||||
}
|
||||
}
|
||||
+ send_pa = NULL;
|
||||
retval = ap->return_padata(context, pa, req_pkt, request, reply,
|
||||
- encrypting_key, send_pa, &callbacks, rock,
|
||||
+ encrypting_key, &send_pa, &callbacks, rock,
|
||||
ap->moddata, *modreq_ptr);
|
||||
if (retval)
|
||||
goto cleanup;
|
||||
|
||||
- if (*send_pa)
|
||||
- send_pa++;
|
||||
- *send_pa = 0;
|
||||
+ if (send_pa != NULL) {
|
||||
+ /* add_pa_data_element() claims send_pa on success or failure. */
|
||||
+ retval = add_pa_data_element(&send_pa_list, send_pa);
|
||||
+ if (retval)
|
||||
+ goto cleanup;
|
||||
+ }
|
||||
}
|
||||
|
||||
- retval = 0;
|
||||
+ /* Add etype-info and pw-salt pa-data as needed. */
|
||||
+ retval = add_etype_info(context, rock, &send_pa_list);
|
||||
+ if (retval)
|
||||
+ goto cleanup;
|
||||
+ retval = add_pw_salt(context, rock, &send_pa_list);
|
||||
+ if (retval)
|
||||
+ goto cleanup;
|
||||
|
||||
- if (send_pa_list[0]) {
|
||||
+ if (send_pa_list != NULL) {
|
||||
reply->padata = send_pa_list;
|
||||
send_pa_list = 0;
|
||||
}
|
||||
@@ -1370,8 +1382,7 @@ return_padata(krb5_context context, krb5_kdcpreauth_rock rock,
|
||||
cleanup:
|
||||
krb5_free_keyblock_contents(context, &original_key);
|
||||
free(pa_order);
|
||||
- if (send_pa_list)
|
||||
- krb5_free_pa_data(context, send_pa_list);
|
||||
+ krb5_free_pa_data(context, send_pa_list);
|
||||
|
||||
return (retval);
|
||||
}
|
||||
@@ -1438,9 +1449,8 @@ make_etype_info(krb5_context context, krb5_preauthtype pa_type,
|
||||
krb5_enctype enctype, krb5_pa_data **pa_out)
|
||||
{
|
||||
krb5_error_code retval;
|
||||
- krb5_pa_data *pa = NULL;
|
||||
krb5_etype_info_entry **entry = NULL;
|
||||
- krb5_data *scratch = NULL;
|
||||
+ krb5_data *der_etype_info = NULL;
|
||||
int etype_info2 = (pa_type == KRB5_PADATA_ETYPE_INFO2);
|
||||
|
||||
*pa_out = NULL;
|
||||
@@ -1454,125 +1464,23 @@ make_etype_info(krb5_context context, krb5_preauthtype pa_type,
|
||||
goto cleanup;
|
||||
|
||||
if (etype_info2)
|
||||
- retval = encode_krb5_etype_info2(entry, &scratch);
|
||||
+ retval = encode_krb5_etype_info2(entry, &der_etype_info);
|
||||
else
|
||||
- retval = encode_krb5_etype_info(entry, &scratch);
|
||||
+ retval = encode_krb5_etype_info(entry, &der_etype_info);
|
||||
if (retval)
|
||||
goto cleanup;
|
||||
- pa = k5alloc(sizeof(*pa), &retval);
|
||||
- if (pa == NULL)
|
||||
+
|
||||
+ /* Steal the data from der_etype_info to create a pa-data element. */
|
||||
+ retval = alloc_pa_data(pa_type, 0, pa_out);
|
||||
+ if (retval)
|
||||
goto cleanup;
|
||||
- pa->magic = KV5M_PA_DATA;
|
||||
- pa->pa_type = pa_type;
|
||||
- pa->contents = (unsigned char *)scratch->data;
|
||||
- pa->length = scratch->length;
|
||||
- scratch->data = NULL;
|
||||
- *pa_out = pa;
|
||||
+ (*pa_out)->contents = (uint8_t *)der_etype_info->data;
|
||||
+ (*pa_out)->length = der_etype_info->length;
|
||||
+ der_etype_info->data = NULL;
|
||||
|
||||
cleanup:
|
||||
krb5_free_etype_info(context, entry);
|
||||
- krb5_free_data(context, scratch);
|
||||
- return retval;
|
||||
-}
|
||||
-
|
||||
-/* Return true if request's enctypes indicate support for etype-info2. */
|
||||
-static krb5_boolean
|
||||
-requires_info2(const krb5_kdc_req *request)
|
||||
-{
|
||||
- int i;
|
||||
-
|
||||
- for (i = 0; i < request->nktypes; i++) {
|
||||
- if (enctype_requires_etype_info_2(request->ktype[i]))
|
||||
- return TRUE;
|
||||
- }
|
||||
- return FALSE;
|
||||
-}
|
||||
-
|
||||
-/* Generate hint list padata for PA-ETYPE-INFO or PA-ETYPE-INFO2. */
|
||||
-static void
|
||||
-get_etype_info(krb5_context context, krb5_kdc_req *request,
|
||||
- krb5_kdcpreauth_callbacks cb, krb5_kdcpreauth_rock rock,
|
||||
- krb5_kdcpreauth_moddata moddata, krb5_preauthtype pa_type,
|
||||
- krb5_kdcpreauth_edata_respond_fn respond, void *arg)
|
||||
-{
|
||||
- krb5_error_code ret;
|
||||
- krb5_pa_data *pa = NULL;
|
||||
-
|
||||
- if (rock->client_key == NULL) {
|
||||
- ret = KRB5KDC_ERR_PADATA_TYPE_NOSUPP;
|
||||
- } else if (pa_type == KRB5_PADATA_ETYPE_INFO && requires_info2(request)) {
|
||||
- ret = KRB5KDC_ERR_PADATA_TYPE_NOSUPP;
|
||||
- } else {
|
||||
- ret = make_etype_info(context, pa_type, rock->client->princ,
|
||||
- rock->client_key, rock->client_keyblock->enctype,
|
||||
- &pa);
|
||||
- }
|
||||
- (*respond)(arg, ret, pa);
|
||||
-}
|
||||
-
|
||||
-/* Generate AS-REP padata for PA-ETYPE-INFO or PA-ETYPE-INFO2. */
|
||||
-static krb5_error_code
|
||||
-return_etype_info(krb5_context context, krb5_pa_data *padata,
|
||||
- krb5_data *req_pkt, krb5_kdc_req *request,
|
||||
- krb5_kdc_rep *reply, krb5_keyblock *encrypting_key,
|
||||
- krb5_pa_data **send_pa, krb5_kdcpreauth_callbacks cb,
|
||||
- krb5_kdcpreauth_rock rock, krb5_kdcpreauth_moddata moddata,
|
||||
- krb5_kdcpreauth_modreq modreq)
|
||||
-{
|
||||
- *send_pa = NULL;
|
||||
- if (rock->client_key == NULL)
|
||||
- return 0;
|
||||
- if (padata->pa_type == KRB5_PADATA_ETYPE_INFO && requires_info2(request))
|
||||
- return 0;
|
||||
- return make_etype_info(context, padata->pa_type, rock->client->princ,
|
||||
- rock->client_key, encrypting_key->enctype, send_pa);
|
||||
-}
|
||||
-
|
||||
-static krb5_error_code
|
||||
-return_pw_salt(krb5_context context, krb5_pa_data *in_padata,
|
||||
- krb5_data *req_pkt, krb5_kdc_req *request, krb5_kdc_rep *reply,
|
||||
- krb5_keyblock *encrypting_key, krb5_pa_data **send_pa,
|
||||
- krb5_kdcpreauth_callbacks cb, krb5_kdcpreauth_rock rock,
|
||||
- krb5_kdcpreauth_moddata moddata, krb5_kdcpreauth_modreq modreq)
|
||||
-{
|
||||
- krb5_error_code retval;
|
||||
- krb5_pa_data * padata;
|
||||
- krb5_data * salt = NULL;
|
||||
- krb5_int16 salttype;
|
||||
- krb5_key_data * client_key = rock->client_key;
|
||||
-
|
||||
- if (client_key == NULL || requires_info2(request))
|
||||
- return 0;
|
||||
-
|
||||
- retval = krb5_dbe_compute_salt(context, client_key, request->client,
|
||||
- &salttype, &salt);
|
||||
- if (retval)
|
||||
- return 0;
|
||||
-
|
||||
- padata = k5alloc(sizeof(*padata), &retval);
|
||||
- if (padata == NULL)
|
||||
- goto cleanup;
|
||||
- padata->magic = KV5M_PA_DATA;
|
||||
-
|
||||
- if (salttype == KRB5_KDB_SALTTYPE_AFS3) {
|
||||
- padata->contents = k5memdup0(salt->data, salt->length, &retval);
|
||||
- if (padata->contents == NULL)
|
||||
- goto cleanup;
|
||||
- padata->pa_type = KRB5_PADATA_AFS3_SALT;
|
||||
- padata->length = salt->length + 1;
|
||||
- } else {
|
||||
- padata->pa_type = KRB5_PADATA_PW_SALT;
|
||||
- padata->length = salt->length;
|
||||
- padata->contents = (krb5_octet *)salt->data;
|
||||
- salt->data = NULL;
|
||||
- }
|
||||
-
|
||||
- *send_pa = padata;
|
||||
- padata = NULL;
|
||||
-
|
||||
-cleanup:
|
||||
- free(padata);
|
||||
- krb5_free_data(context, salt);
|
||||
+ krb5_free_data(context, der_etype_info);
|
||||
return retval;
|
||||
}
|
||||
|
||||
@@ -1656,69 +1564,3 @@ return_enc_padata(krb5_context context, krb5_data *req_pkt,
|
||||
cleanup:
|
||||
return code;
|
||||
}
|
||||
-
|
||||
-
|
||||
-#if 0
|
||||
-static krb5_error_code return_server_referral(krb5_context context,
|
||||
- krb5_pa_data * padata,
|
||||
- krb5_db_entry *client,
|
||||
- krb5_db_entry *server,
|
||||
- krb5_kdc_req *request,
|
||||
- krb5_kdc_rep *reply,
|
||||
- krb5_key_data *client_key,
|
||||
- krb5_keyblock *encrypting_key,
|
||||
- krb5_pa_data **send_pa)
|
||||
-{
|
||||
- krb5_error_code code;
|
||||
- krb5_tl_data tl_data;
|
||||
- krb5_pa_data *pa_data;
|
||||
- krb5_enc_data enc_data;
|
||||
- krb5_data plain;
|
||||
- krb5_data *enc_pa_data;
|
||||
-
|
||||
- *send_pa = NULL;
|
||||
-
|
||||
- tl_data.tl_data_type = KRB5_TL_SERVER_REFERRAL;
|
||||
-
|
||||
- code = krb5_dbe_lookup_tl_data(context, server, &tl_data);
|
||||
- if (code || tl_data.tl_data_length == 0)
|
||||
- return 0; /* no server referrals to return */
|
||||
-
|
||||
- plain.length = tl_data.tl_data_length;
|
||||
- plain.data = tl_data.tl_data_contents;
|
||||
-
|
||||
- /* Encrypt ServerReferralData */
|
||||
- code = krb5_encrypt_helper(context, encrypting_key,
|
||||
- KRB5_KEYUSAGE_PA_SERVER_REFERRAL_DATA,
|
||||
- &plain, &enc_data);
|
||||
- if (code)
|
||||
- return code;
|
||||
-
|
||||
- /* Encode ServerReferralData into PA-SERVER-REFERRAL-DATA */
|
||||
- code = encode_krb5_enc_data(&enc_data, &enc_pa_data);
|
||||
- if (code) {
|
||||
- krb5_free_data_contents(context, &enc_data.ciphertext);
|
||||
- return code;
|
||||
- }
|
||||
-
|
||||
- krb5_free_data_contents(context, &enc_data.ciphertext);
|
||||
-
|
||||
- /* Return PA-SERVER-REFERRAL-DATA */
|
||||
- pa_data = (krb5_pa_data *)malloc(sizeof(*pa_data));
|
||||
- if (pa_data == NULL) {
|
||||
- krb5_free_data(context, enc_pa_data);
|
||||
- return ENOMEM;
|
||||
- }
|
||||
-
|
||||
- pa_data->magic = KV5M_PA_DATA;
|
||||
- pa_data->pa_type = KRB5_PADATA_SVR_REFERRAL_INFO;
|
||||
- pa_data->length = enc_pa_data->length;
|
||||
- pa_data->contents = enc_pa_data->data;
|
||||
-
|
||||
- free(enc_pa_data); /* don't free contents */
|
||||
-
|
||||
- *send_pa = pa_data;
|
||||
-
|
||||
- return 0;
|
||||
-}
|
||||
-#endif
|
||||
53
Use-SHA-256-instead-of-MD5-for-audit-ticket-IDs.patch
Normal file
53
Use-SHA-256-instead-of-MD5-for-audit-ticket-IDs.patch
Normal file
|
|
@ -0,0 +1,53 @@
|
|||
From a9bc03fe03ef4b00bcdad13c99bb4c376a8b9964 Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Tue, 10 Jul 2018 16:17:15 -0400
|
||||
Subject: [PATCH] Use SHA-256 instead of MD5 for audit ticket IDs
|
||||
|
||||
ticket: 8711 (new)
|
||||
(cherry picked from commit c1e1bfa26bd2f045e88e6013c500fca9428c98f3)
|
||||
---
|
||||
src/kdc/kdc_audit.c | 21 ++++++++++-----------
|
||||
1 file changed, 10 insertions(+), 11 deletions(-)
|
||||
|
||||
diff --git a/src/kdc/kdc_audit.c b/src/kdc/kdc_audit.c
|
||||
index c9a7f9f9d..f40913dc8 100644
|
||||
--- a/src/kdc/kdc_audit.c
|
||||
+++ b/src/kdc/kdc_audit.c
|
||||
@@ -146,7 +146,7 @@ kau_make_tkt_id(krb5_context context,
|
||||
{
|
||||
krb5_error_code ret = 0;
|
||||
char *hash = NULL, *ptr;
|
||||
- krb5_checksum cksum;
|
||||
+ uint8_t hashbytes[K5_SHA256_HASHLEN];
|
||||
unsigned int i;
|
||||
|
||||
*out = NULL;
|
||||
@@ -154,19 +154,18 @@ kau_make_tkt_id(krb5_context context,
|
||||
if (ticket == NULL)
|
||||
return EINVAL;
|
||||
|
||||
- ret = krb5_c_make_checksum(context, CKSUMTYPE_RSA_MD5, NULL, 0,
|
||||
- &ticket->enc_part.ciphertext, &cksum);
|
||||
+ ret = k5_sha256(&ticket->enc_part.ciphertext, 1, hashbytes);
|
||||
if (ret)
|
||||
return ret;
|
||||
|
||||
- hash = k5alloc(cksum.length * 2 + 1, &ret);
|
||||
- if (hash != NULL) {
|
||||
- for (i = 0, ptr = hash; i < cksum.length; i++, ptr += 2)
|
||||
- snprintf(ptr, 3, "%02X", cksum.contents[i]);
|
||||
- *ptr = '\0';
|
||||
- *out = hash;
|
||||
- }
|
||||
- krb5_free_checksum_contents(context, &cksum);
|
||||
+ hash = k5alloc(sizeof(hashbytes) * 2 + 1, &ret);
|
||||
+ if (hash == NULL)
|
||||
+ return ret;
|
||||
+
|
||||
+ for (i = 0, ptr = hash; i < sizeof(hashbytes); i++, ptr += 2)
|
||||
+ snprintf(ptr, 3, "%02X", hashbytes[i]);
|
||||
+ *ptr = '\0';
|
||||
+ *out = hash;
|
||||
|
||||
return 0;
|
||||
}
|
||||
62
Use-k5_buf_init_dynamic_zap-where-appropriate.patch
Normal file
62
Use-k5_buf_init_dynamic_zap-where-appropriate.patch
Normal file
|
|
@ -0,0 +1,62 @@
|
|||
From c5df16a88027d7f9b6eb53b1c3fa949d6538616b Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Mon, 26 Mar 2018 11:24:49 -0400
|
||||
Subject: [PATCH] Use k5_buf_init_dynamic_zap where appropriate
|
||||
|
||||
(cherry picked from commit 9172599008f3a6790d4a9a67acff58049742dcb6)
|
||||
---
|
||||
src/lib/krb5/ccache/cc_file.c | 4 ++--
|
||||
src/lib/krb5/ccache/cc_keyring.c | 2 +-
|
||||
src/util/support/utf8_conv.c | 4 +++-
|
||||
3 files changed, 6 insertions(+), 4 deletions(-)
|
||||
|
||||
diff --git a/src/lib/krb5/ccache/cc_file.c b/src/lib/krb5/ccache/cc_file.c
|
||||
index 6789c09e1..9263a0054 100644
|
||||
--- a/src/lib/krb5/ccache/cc_file.c
|
||||
+++ b/src/lib/krb5/ccache/cc_file.c
|
||||
@@ -758,7 +758,7 @@ fcc_next_cred(krb5_context context, krb5_ccache id, krb5_cc_cursor *cursor,
|
||||
|
||||
memset(creds, 0, sizeof(*creds));
|
||||
k5_cc_mutex_lock(context, &data->lock);
|
||||
- k5_buf_init_dynamic(&buf);
|
||||
+ k5_buf_init_dynamic_zap(&buf);
|
||||
|
||||
ret = krb5_lock_file(context, fileno(fcursor->fp), KRB5_LOCKMODE_SHARED);
|
||||
if (ret)
|
||||
@@ -982,7 +982,7 @@ fcc_store(krb5_context context, krb5_ccache id, krb5_creds *creds)
|
||||
goto cleanup;
|
||||
|
||||
/* Marshal the cred and write it to the file with a single append write. */
|
||||
- k5_buf_init_dynamic(&buf);
|
||||
+ k5_buf_init_dynamic_zap(&buf);
|
||||
k5_marshal_cred(&buf, version, creds);
|
||||
ret = k5_buf_status(&buf);
|
||||
if (ret)
|
||||
diff --git a/src/lib/krb5/ccache/cc_keyring.c b/src/lib/krb5/ccache/cc_keyring.c
|
||||
index fba710b1b..8419f6ebf 100644
|
||||
--- a/src/lib/krb5/ccache/cc_keyring.c
|
||||
+++ b/src/lib/krb5/ccache/cc_keyring.c
|
||||
@@ -1295,7 +1295,7 @@ krcc_store(krb5_context context, krb5_ccache id, krb5_creds *creds)
|
||||
goto errout;
|
||||
|
||||
/* Serialize credential using the file ccache version 4 format. */
|
||||
- k5_buf_init_dynamic(&buf);
|
||||
+ k5_buf_init_dynamic_zap(&buf);
|
||||
k5_marshal_cred(&buf, 4, creds);
|
||||
ret = k5_buf_status(&buf);
|
||||
if (ret)
|
||||
diff --git a/src/util/support/utf8_conv.c b/src/util/support/utf8_conv.c
|
||||
index 5cfc2c512..08cef4168 100644
|
||||
--- a/src/util/support/utf8_conv.c
|
||||
+++ b/src/util/support/utf8_conv.c
|
||||
@@ -99,7 +99,9 @@ k5_utf8_to_utf16le(const char *utf8, uint8_t **utf16_out, size_t *nbytes_out)
|
||||
*utf16_out = NULL;
|
||||
*nbytes_out = 0;
|
||||
|
||||
- k5_buf_init_dynamic(&buf);
|
||||
+ /* UTF-16 conversion is used for RC4 string-to-key, so treat this data as
|
||||
+ * sensitive. */
|
||||
+ k5_buf_init_dynamic_zap(&buf);
|
||||
|
||||
/* Examine next UTF-8 character. */
|
||||
while (*utf8 != '\0') {
|
||||
869
Use-libkrb5support-hex-functions-where-appropriate.patch
Normal file
869
Use-libkrb5support-hex-functions-where-appropriate.patch
Normal file
|
|
@ -0,0 +1,869 @@
|
|||
From 19109505ad04efdfd70df3ee922e22bcf5a294f3 Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Mon, 19 Feb 2018 00:52:35 -0500
|
||||
Subject: [PATCH] Use libkrb5support hex functions where appropriate
|
||||
|
||||
(cherry picked from commit b0c700608be7455041a8afc0e4502e8783ee7f30)
|
||||
---
|
||||
src/kadmin/dbutil/deps | 16 ++---
|
||||
src/kadmin/dbutil/tabdump.c | 19 +++---
|
||||
src/kadmin/ktutil/deps | 13 ++--
|
||||
src/kadmin/ktutil/ktutil_funcs.c | 30 ++++-----
|
||||
src/lib/crypto/crypto_tests/deps | 39 ++++++-----
|
||||
src/lib/crypto/crypto_tests/t_cksum.c | 35 +++-------
|
||||
src/lib/crypto/crypto_tests/t_crc.c | 28 ++------
|
||||
src/lib/crypto/crypto_tests/t_hmac.c | 34 +++++-----
|
||||
src/plugins/kdb/ldap/ldap_util/deps | 18 ++---
|
||||
.../kdb/ldap/ldap_util/kdb5_ldap_services.c | 32 +++------
|
||||
.../kdb/ldap/ldap_util/kdb5_ldap_services.h | 2 -
|
||||
src/plugins/kdb/ldap/libkdb_ldap/deps | 19 +++---
|
||||
.../kdb/ldap/libkdb_ldap/ldap_service_stash.c | 65 +++----------------
|
||||
.../kdb/ldap/libkdb_ldap/ldap_service_stash.h | 3 -
|
||||
.../kdb/ldap/libkdb_ldap/libkdb_ldap.exports | 1 -
|
||||
src/slave/deps | 15 +++--
|
||||
src/slave/kproplog.c | 11 ++--
|
||||
src/tests/gssapi/deps | 14 ++--
|
||||
src/tests/gssapi/t_prf.c | 13 ++--
|
||||
19 files changed, 152 insertions(+), 255 deletions(-)
|
||||
|
||||
diff --git a/src/kadmin/dbutil/deps b/src/kadmin/dbutil/deps
|
||||
index 4dcc33628..8b0965aac 100644
|
||||
--- a/src/kadmin/dbutil/deps
|
||||
+++ b/src/kadmin/dbutil/deps
|
||||
@@ -185,14 +185,14 @@ $(OUTPRE)tabdump.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \
|
||||
$(top_srcdir)/include/gssrpc/xdr.h $(top_srcdir)/include/iprop.h \
|
||||
$(top_srcdir)/include/iprop_hdr.h $(top_srcdir)/include/k5-buf.h \
|
||||
$(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \
|
||||
- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \
|
||||
- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \
|
||||
- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \
|
||||
- $(top_srcdir)/include/kdb.h $(top_srcdir)/include/kdb_log.h \
|
||||
- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \
|
||||
- $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \
|
||||
- $(top_srcdir)/include/socket-utils.h kdb5_util.h tabdump.c \
|
||||
- tdumputil.h
|
||||
+ $(top_srcdir)/include/k5-hex.h $(top_srcdir)/include/k5-int-pkinit.h \
|
||||
+ $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \
|
||||
+ $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \
|
||||
+ $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/kdb.h \
|
||||
+ $(top_srcdir)/include/kdb_log.h $(top_srcdir)/include/krb5.h \
|
||||
+ $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \
|
||||
+ $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \
|
||||
+ kdb5_util.h tabdump.c tdumputil.h
|
||||
$(OUTPRE)tdumputil.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \
|
||||
$(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \
|
||||
$(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h \
|
||||
diff --git a/src/kadmin/dbutil/tabdump.c b/src/kadmin/dbutil/tabdump.c
|
||||
index fb36b060a..2f313dbb0 100644
|
||||
--- a/src/kadmin/dbutil/tabdump.c
|
||||
+++ b/src/kadmin/dbutil/tabdump.c
|
||||
@@ -32,6 +32,7 @@
|
||||
|
||||
#include <k5-int.h>
|
||||
#include "k5-platform.h" /* for asprintf */
|
||||
+#include "k5-hex.h"
|
||||
|
||||
#include <limits.h>
|
||||
#include <stdio.h>
|
||||
@@ -230,9 +231,7 @@ static int
|
||||
write_data(struct rec_args *args, krb5_data *data)
|
||||
{
|
||||
int ret;
|
||||
- char *p;
|
||||
- size_t i;
|
||||
- struct k5buf buf;
|
||||
+ char *hex;
|
||||
struct rechandle *h = args->rh;
|
||||
struct tdopts *opts = args->opts;
|
||||
|
||||
@@ -241,17 +240,15 @@ write_data(struct rec_args *args, krb5_data *data)
|
||||
return -1;
|
||||
return 0;
|
||||
}
|
||||
- k5_buf_init_dynamic(&buf);
|
||||
- p = data->data;
|
||||
- for (i = 0; i < data->length; i++)
|
||||
- k5_buf_add_fmt(&buf, "%02x", (unsigned char)p[i]);
|
||||
|
||||
- if (buf.data == NULL) {
|
||||
- errno = ENOMEM;
|
||||
+ ret = k5_hex_encode(data->data, data->length, FALSE, &hex);
|
||||
+ if (ret) {
|
||||
+ errno = ret;
|
||||
return -1;
|
||||
}
|
||||
- ret = writefield(h, "%s", (char *)buf.data);
|
||||
- k5_buf_free(&buf);
|
||||
+
|
||||
+ ret = writefield(h, "%s", hex);
|
||||
+ free(hex);
|
||||
return ret;
|
||||
}
|
||||
|
||||
diff --git a/src/kadmin/ktutil/deps b/src/kadmin/ktutil/deps
|
||||
index 4df399924..5863e63c7 100644
|
||||
--- a/src/kadmin/ktutil/deps
|
||||
+++ b/src/kadmin/ktutil/deps
|
||||
@@ -18,9 +18,10 @@ $(OUTPRE)ktutil_funcs.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \
|
||||
$(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \
|
||||
$(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h \
|
||||
$(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \
|
||||
- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \
|
||||
- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \
|
||||
- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \
|
||||
- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \
|
||||
- $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \
|
||||
- $(top_srcdir)/include/socket-utils.h ktutil.h ktutil_funcs.c
|
||||
+ $(top_srcdir)/include/k5-hex.h $(top_srcdir)/include/k5-int-pkinit.h \
|
||||
+ $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \
|
||||
+ $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \
|
||||
+ $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \
|
||||
+ $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \
|
||||
+ $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \
|
||||
+ ktutil.h ktutil_funcs.c
|
||||
diff --git a/src/kadmin/ktutil/ktutil_funcs.c b/src/kadmin/ktutil/ktutil_funcs.c
|
||||
index 7a3aa0dca..5843e24b7 100644
|
||||
--- a/src/kadmin/ktutil/ktutil_funcs.c
|
||||
+++ b/src/kadmin/ktutil/ktutil_funcs.c
|
||||
@@ -29,6 +29,7 @@
|
||||
*/
|
||||
|
||||
#include "k5-int.h"
|
||||
+#include "k5-hex.h"
|
||||
#include "ktutil.h"
|
||||
#include <string.h>
|
||||
#include <ctype.h>
|
||||
@@ -106,9 +107,8 @@ krb5_error_code ktutil_add(context, list, princ_str, kvno,
|
||||
krb5_keyblock key;
|
||||
char buf[BUFSIZ];
|
||||
char promptstr[1024];
|
||||
-
|
||||
- char *cp;
|
||||
- int i, tmp;
|
||||
+ uint8_t *keybytes;
|
||||
+ size_t keylen;
|
||||
unsigned int pwsize = BUFSIZ;
|
||||
|
||||
retval = krb5_parse_name(context, princ_str, &princ);
|
||||
@@ -199,24 +199,18 @@ krb5_error_code ktutil_add(context, list, princ_str, kvno,
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
- lp->entry->key.enctype = enctype;
|
||||
- lp->entry->key.contents = (krb5_octet *) malloc((strlen(buf) + 1) / 2);
|
||||
- if (!lp->entry->key.contents) {
|
||||
- retval = ENOMEM;
|
||||
+ retval = k5_hex_decode(buf, &keybytes, &keylen);
|
||||
+ if (retval) {
|
||||
+ if (retval == EINVAL) {
|
||||
+ fprintf(stderr, _("addent: Illegal character in key.\n"));
|
||||
+ retval = 0;
|
||||
+ }
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
- i = 0;
|
||||
- for (cp = buf; *cp; cp += 2) {
|
||||
- if (!isxdigit((int) cp[0]) || !isxdigit((int) cp[1])) {
|
||||
- fprintf(stderr, _("addent: Illegal character in key.\n"));
|
||||
- retval = 0;
|
||||
- goto cleanup;
|
||||
- }
|
||||
- sscanf(cp, "%02x", &tmp);
|
||||
- lp->entry->key.contents[i++] = (krb5_octet) tmp;
|
||||
- }
|
||||
- lp->entry->key.length = i;
|
||||
+ lp->entry->key.enctype = enctype;
|
||||
+ lp->entry->key.contents = keybytes;
|
||||
+ lp->entry->key.length = keylen;
|
||||
}
|
||||
lp->entry->principal = princ;
|
||||
lp->entry->vno = kvno;
|
||||
diff --git a/src/lib/crypto/crypto_tests/deps b/src/lib/crypto/crypto_tests/deps
|
||||
index bc5422a06..5d94a593d 100644
|
||||
--- a/src/lib/crypto/crypto_tests/deps
|
||||
+++ b/src/lib/crypto/crypto_tests/deps
|
||||
@@ -73,12 +73,13 @@ $(OUTPRE)t_hmac.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \
|
||||
$(srcdir)/../builtin/crypto_mod.h $(srcdir)/../builtin/sha2/sha2.h \
|
||||
$(srcdir)/../krb/crypto_int.h $(top_srcdir)/include/k5-buf.h \
|
||||
$(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \
|
||||
- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \
|
||||
- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \
|
||||
- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \
|
||||
- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \
|
||||
- $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \
|
||||
- $(top_srcdir)/include/socket-utils.h t_hmac.c
|
||||
+ $(top_srcdir)/include/k5-hex.h $(top_srcdir)/include/k5-int-pkinit.h \
|
||||
+ $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \
|
||||
+ $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \
|
||||
+ $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \
|
||||
+ $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \
|
||||
+ $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \
|
||||
+ t_hmac.c
|
||||
$(OUTPRE)t_pkcs5.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \
|
||||
$(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \
|
||||
$(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h \
|
||||
@@ -143,12 +144,13 @@ $(OUTPRE)t_cksum.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \
|
||||
$(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \
|
||||
$(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h \
|
||||
$(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \
|
||||
- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \
|
||||
- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \
|
||||
- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \
|
||||
- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \
|
||||
- $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \
|
||||
- $(top_srcdir)/include/socket-utils.h t_cksum.c
|
||||
+ $(top_srcdir)/include/k5-hex.h $(top_srcdir)/include/k5-int-pkinit.h \
|
||||
+ $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \
|
||||
+ $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \
|
||||
+ $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \
|
||||
+ $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \
|
||||
+ $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \
|
||||
+ t_cksum.c
|
||||
$(OUTPRE)t_cksums.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \
|
||||
$(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \
|
||||
$(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h \
|
||||
@@ -165,12 +167,13 @@ $(OUTPRE)t_crc.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \
|
||||
$(srcdir)/../builtin/crypto_mod.h $(srcdir)/../builtin/sha2/sha2.h \
|
||||
$(srcdir)/../krb/crypto_int.h $(top_srcdir)/include/k5-buf.h \
|
||||
$(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \
|
||||
- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \
|
||||
- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \
|
||||
- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \
|
||||
- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \
|
||||
- $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \
|
||||
- $(top_srcdir)/include/socket-utils.h t_crc.c
|
||||
+ $(top_srcdir)/include/k5-hex.h $(top_srcdir)/include/k5-int-pkinit.h \
|
||||
+ $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \
|
||||
+ $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \
|
||||
+ $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \
|
||||
+ $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \
|
||||
+ $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \
|
||||
+ t_crc.c
|
||||
$(OUTPRE)t_mddriver.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \
|
||||
$(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \
|
||||
$(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(srcdir)/../builtin/aes/aes.h \
|
||||
diff --git a/src/lib/crypto/crypto_tests/t_cksum.c b/src/lib/crypto/crypto_tests/t_cksum.c
|
||||
index 2200fe76e..0edaeb850 100644
|
||||
--- a/src/lib/crypto/crypto_tests/t_cksum.c
|
||||
+++ b/src/lib/crypto/crypto_tests/t_cksum.c
|
||||
@@ -27,6 +27,7 @@
|
||||
/* Test checksum and checksum compatability for rsa-md[4,5]-des. */
|
||||
|
||||
#include "k5-int.h"
|
||||
+#include "k5-hex.h"
|
||||
|
||||
#define MD5_K5BETA_COMPAT
|
||||
#define MD4_K5BETA_COMPAT
|
||||
@@ -50,29 +51,6 @@ print_checksum(char *text, int number, char *message, krb5_checksum *checksum)
|
||||
printf("\n");
|
||||
}
|
||||
|
||||
-static void
|
||||
-parse_hexstring(const char *s, krb5_checksum *cksum)
|
||||
-{
|
||||
- size_t i, len;
|
||||
- unsigned int byte;
|
||||
- unsigned char *cp;
|
||||
-
|
||||
- len = strlen(s);
|
||||
- cp = malloc(len / 2);
|
||||
- cksum->contents = cp;
|
||||
- if (cp == NULL) {
|
||||
- cksum->length = 0;
|
||||
- return;
|
||||
- }
|
||||
- cksum->length = len / 2;
|
||||
- for (i = 0; i + 1 < len; i += 2) {
|
||||
- sscanf(&s[i], "%2x", &byte);
|
||||
- *cp++ = byte;
|
||||
- }
|
||||
- cksum->checksum_type = CKTYPE;
|
||||
- cksum->magic = KV5M_CHECKSUM;
|
||||
-}
|
||||
-
|
||||
/*
|
||||
* Test the checksum verification of Old Style (tm) and correct RSA-MD[4,5]-DES
|
||||
* checksums.
|
||||
@@ -86,6 +64,7 @@ main(argc, argv)
|
||||
char **argv;
|
||||
{
|
||||
int msgindex;
|
||||
+ size_t len;
|
||||
krb5_boolean valid;
|
||||
krb5_keyblock keyblock;
|
||||
krb5_key key;
|
||||
@@ -150,12 +129,14 @@ main(argc, argv)
|
||||
free(checksum.contents);
|
||||
|
||||
/* Verify a known-good checksum for this plaintext. */
|
||||
- parse_hexstring(argv[msgindex+1], &knowncksum);
|
||||
- if (knowncksum.contents == NULL) {
|
||||
- printf("parse_hexstring failed\n");
|
||||
- kret = 1;
|
||||
+ kret = k5_hex_decode(argv[msgindex + 1], &knowncksum.contents, &len);
|
||||
+ if (kret) {
|
||||
+ printf("k5_hex_decode failed\n");
|
||||
break;
|
||||
}
|
||||
+ knowncksum.length = len;
|
||||
+ knowncksum.checksum_type = CKTYPE;
|
||||
+ knowncksum.magic = KV5M_CHECKSUM;
|
||||
kret = krb5_k_verify_checksum(NULL, key, 0, &plaintext, &knowncksum,
|
||||
&valid);
|
||||
if (kret != 0) {
|
||||
diff --git a/src/lib/crypto/crypto_tests/t_crc.c b/src/lib/crypto/crypto_tests/t_crc.c
|
||||
index 190773252..1a35cfba5 100644
|
||||
--- a/src/lib/crypto/crypto_tests/t_crc.c
|
||||
+++ b/src/lib/crypto/crypto_tests/t_crc.c
|
||||
@@ -32,6 +32,7 @@
|
||||
#include <stdio.h>
|
||||
#include <stdlib.h>
|
||||
#include <string.h>
|
||||
+#include <k5-hex.h>
|
||||
#include "crypto_int.h"
|
||||
|
||||
#define HEX 1
|
||||
@@ -139,31 +140,12 @@ timetest(unsigned int nblk, unsigned int blksiz)
|
||||
}
|
||||
#endif
|
||||
|
||||
-static void gethexstr(char *data, size_t *outlen, unsigned char *outbuf,
|
||||
- size_t buflen)
|
||||
-{
|
||||
- size_t inlen;
|
||||
- char *cp, buf[3];
|
||||
- long n;
|
||||
-
|
||||
- inlen = strlen(data);
|
||||
- *outlen = 0;
|
||||
- for (cp = data; (size_t) (cp - data) < inlen; cp += 2) {
|
||||
- strncpy(buf, cp, 2);
|
||||
- buf[2] = '\0';
|
||||
- n = strtol(buf, NULL, 16);
|
||||
- outbuf[(*outlen)++] = n;
|
||||
- if (*outlen > buflen)
|
||||
- break;
|
||||
- }
|
||||
-}
|
||||
-
|
||||
static void
|
||||
verify(void)
|
||||
{
|
||||
unsigned int i;
|
||||
struct crc_trial trial;
|
||||
- unsigned char buf[4];
|
||||
+ uint8_t *bytes;
|
||||
size_t len;
|
||||
unsigned long cksum;
|
||||
char *typestr;
|
||||
@@ -179,9 +161,11 @@ verify(void)
|
||||
break;
|
||||
case HEX:
|
||||
typestr = "HEX";
|
||||
- gethexstr(trial.data, &len, buf, 4);
|
||||
+ if (k5_hex_decode(trial.data, &bytes, &len) != 0)
|
||||
+ abort();
|
||||
cksum = 0;
|
||||
- mit_crc32(buf, len, &cksum);
|
||||
+ mit_crc32(bytes, len, &cksum);
|
||||
+ free(bytes);
|
||||
break;
|
||||
default:
|
||||
typestr = "BOGUS";
|
||||
diff --git a/src/lib/crypto/crypto_tests/t_hmac.c b/src/lib/crypto/crypto_tests/t_hmac.c
|
||||
index 8961380ea..93d54828f 100644
|
||||
--- a/src/lib/crypto/crypto_tests/t_hmac.c
|
||||
+++ b/src/lib/crypto/crypto_tests/t_hmac.c
|
||||
@@ -34,6 +34,7 @@
|
||||
#include <string.h>
|
||||
#include <ctype.h>
|
||||
|
||||
+#include <k5-hex.h>
|
||||
#include "crypto_int.h"
|
||||
|
||||
#define ASIZE(ARRAY) (sizeof(ARRAY)/sizeof(ARRAY[0]))
|
||||
@@ -136,12 +137,10 @@ static void test_hmac()
|
||||
{
|
||||
krb5_keyblock key;
|
||||
krb5_data in, out;
|
||||
- char outbuf[20];
|
||||
- char stroutbuf[80];
|
||||
+ char outbuf[20], *hexdigest;
|
||||
krb5_error_code err;
|
||||
- unsigned int i, j;
|
||||
+ unsigned int i;
|
||||
int lose = 0;
|
||||
- struct k5buf buf;
|
||||
|
||||
/* RFC 2202 test vector. */
|
||||
static const struct hmac_test md5tests[] = {
|
||||
@@ -151,13 +150,13 @@ static void test_hmac()
|
||||
0xb, 0xb, 0xb, 0xb, 0xb, 0xb, 0xb, 0xb,
|
||||
},
|
||||
8, "Hi There",
|
||||
- "0x9294727a3638bb1c13f48ef8158bfc9d"
|
||||
+ "9294727a3638bb1c13f48ef8158bfc9d"
|
||||
},
|
||||
|
||||
{
|
||||
4, "Jefe",
|
||||
28, "what do ya want for nothing?",
|
||||
- "0x750c783e6ab0b503eaa86e310a5db738"
|
||||
+ "750c783e6ab0b503eaa86e310a5db738"
|
||||
},
|
||||
|
||||
{
|
||||
@@ -172,7 +171,7 @@ static void test_hmac()
|
||||
0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd,
|
||||
0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd,
|
||||
},
|
||||
- "0x56be34521d144c88dbb8c733f0e8b3f6"
|
||||
+ "56be34521d144c88dbb8c733f0e8b3f6"
|
||||
},
|
||||
|
||||
{
|
||||
@@ -188,7 +187,7 @@ static void test_hmac()
|
||||
0xcd, 0xcd, 0xcd, 0xcd, 0xcd, 0xcd, 0xcd, 0xcd, 0xcd, 0xcd,
|
||||
0xcd, 0xcd, 0xcd, 0xcd, 0xcd, 0xcd, 0xcd, 0xcd, 0xcd, 0xcd,
|
||||
},
|
||||
- "0x697eaf0aca3a3aea3a75164746ffaa79"
|
||||
+ "697eaf0aca3a3aea3a75164746ffaa79"
|
||||
},
|
||||
|
||||
{
|
||||
@@ -197,7 +196,7 @@ static void test_hmac()
|
||||
0x0c, 0x0c, 0x0c, 0x0c, 0x0c, 0x0c, 0x0c, 0x0c
|
||||
},
|
||||
20, "Test With Truncation",
|
||||
- "0x56461ef2342edc00f9bab995690efd4c"
|
||||
+ "56461ef2342edc00f9bab995690efd4c"
|
||||
},
|
||||
|
||||
{
|
||||
@@ -212,7 +211,7 @@ static void test_hmac()
|
||||
0xaa, 0xaa, 0xaa, 0xaa, 0xaa, 0xaa, 0xaa, 0xaa, 0xaa, 0xaa,
|
||||
},
|
||||
54, "Test Using Larger Than Block-Size Key - Hash Key First",
|
||||
- "0x6b1ab7fe4bd7bf8f0b62e6ce61b9d0cd"
|
||||
+ "6b1ab7fe4bd7bf8f0b62e6ce61b9d0cd"
|
||||
},
|
||||
|
||||
{
|
||||
@@ -228,7 +227,7 @@ static void test_hmac()
|
||||
},
|
||||
73,
|
||||
"Test Using Larger Than Block-Size Key and Larger Than One Block-Size Data",
|
||||
- "0x6f630fad67cda0ee1fb1f562db3aa53e"
|
||||
+ "6f630fad67cda0ee1fb1f562db3aa53e"
|
||||
},
|
||||
};
|
||||
|
||||
@@ -246,19 +245,16 @@ static void test_hmac()
|
||||
exit(1);
|
||||
}
|
||||
|
||||
- k5_buf_init_fixed(&buf, stroutbuf, sizeof(stroutbuf));
|
||||
- k5_buf_add(&buf, "0x");
|
||||
- for (j = 0; j < out.length; j++)
|
||||
- k5_buf_add_fmt(&buf, "%02x", 0xff & outbuf[j]);
|
||||
- if (k5_buf_status(&buf) != 0)
|
||||
+ if (k5_hex_encode(out.data, out.length, FALSE, &hexdigest) != 0)
|
||||
abort();
|
||||
- if (strcmp(stroutbuf, md5tests[i].hexdigest)) {
|
||||
+ if (strcmp(hexdigest, md5tests[i].hexdigest)) {
|
||||
printf("*** CHECK FAILED!\n"
|
||||
- "\tReturned: %s.\n"
|
||||
- "\tExpected: %s.\n", stroutbuf, md5tests[i].hexdigest);
|
||||
+ "\tReturned: 0x%s.\n"
|
||||
+ "\tExpected: 0x%s.\n", hexdigest, md5tests[i].hexdigest);
|
||||
lose++;
|
||||
} else
|
||||
printf("Matches expected result.\n");
|
||||
+ free(hexdigest);
|
||||
}
|
||||
|
||||
/* Do again with SHA-1 tests.... */
|
||||
diff --git a/src/plugins/kdb/ldap/ldap_util/deps b/src/plugins/kdb/ldap/ldap_util/deps
|
||||
index 75d4dd0cf..be0194c00 100644
|
||||
--- a/src/plugins/kdb/ldap/ldap_util/deps
|
||||
+++ b/src/plugins/kdb/ldap/ldap_util/deps
|
||||
@@ -89,15 +89,15 @@ $(OUTPRE)kdb5_ldap_services.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \
|
||||
$(srcdir)/../libkdb_ldap/ldap_krbcontainer.h $(srcdir)/../libkdb_ldap/ldap_misc.h \
|
||||
$(srcdir)/../libkdb_ldap/ldap_realm.h $(top_srcdir)/include/k5-buf.h \
|
||||
$(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \
|
||||
- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \
|
||||
- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \
|
||||
- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \
|
||||
- $(top_srcdir)/include/kdb.h $(top_srcdir)/include/krb5.h \
|
||||
- $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \
|
||||
- $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \
|
||||
- $(top_srcdir)/lib/kdb/kdb5.h kdb5_ldap_list.h kdb5_ldap_policy.h \
|
||||
- kdb5_ldap_realm.h kdb5_ldap_services.c kdb5_ldap_services.h \
|
||||
- kdb5_ldap_util.h
|
||||
+ $(top_srcdir)/include/k5-hex.h $(top_srcdir)/include/k5-int-pkinit.h \
|
||||
+ $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \
|
||||
+ $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \
|
||||
+ $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/kdb.h \
|
||||
+ $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \
|
||||
+ $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \
|
||||
+ $(top_srcdir)/include/socket-utils.h $(top_srcdir)/lib/kdb/kdb5.h \
|
||||
+ kdb5_ldap_list.h kdb5_ldap_policy.h kdb5_ldap_realm.h \
|
||||
+ kdb5_ldap_services.c kdb5_ldap_services.h kdb5_ldap_util.h
|
||||
$(OUTPRE)getdate.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \
|
||||
$(BUILDTOP)/include/krb5/krb5.h $(COM_ERR_DEPS) $(top_srcdir)/include/krb5.h \
|
||||
getdate.c
|
||||
diff --git a/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c b/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c
|
||||
index 3d6994c67..ce038fc3d 100644
|
||||
--- a/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c
|
||||
+++ b/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c
|
||||
@@ -37,6 +37,7 @@
|
||||
*/
|
||||
|
||||
#include <k5-int.h>
|
||||
+#include <k5-hex.h>
|
||||
#include "kdb5_ldap_util.h"
|
||||
#include "kdb5_ldap_list.h"
|
||||
|
||||
@@ -96,11 +97,10 @@ kdb5_ldap_stash_service_password(int argc, char **argv)
|
||||
char *service_object = NULL;
|
||||
char *file_name = NULL, *tmp_file = NULL;
|
||||
char passwd[MAX_SERVICE_PASSWD_LEN];
|
||||
- char *str = NULL;
|
||||
+ char *str = NULL, *hexpasswd = NULL;
|
||||
char line[MAX_LEN];
|
||||
FILE *pfile = NULL;
|
||||
krb5_boolean print_usage = FALSE;
|
||||
- krb5_data hexpasswd = {0, 0, NULL};
|
||||
mode_t old_mode = 0;
|
||||
|
||||
/*
|
||||
@@ -183,21 +183,12 @@ kdb5_ldap_stash_service_password(int argc, char **argv)
|
||||
}
|
||||
|
||||
/* Convert the password to hexadecimal */
|
||||
- {
|
||||
- krb5_data pwd;
|
||||
-
|
||||
- pwd.length = passwd_len;
|
||||
- pwd.data = passwd;
|
||||
-
|
||||
- ret = tohex(pwd, &hexpasswd);
|
||||
- if (ret != 0) {
|
||||
- com_err(me, ret,
|
||||
- _("Failed to convert the password to hexadecimal"));
|
||||
- memset(passwd, 0, passwd_len);
|
||||
- goto cleanup;
|
||||
- }
|
||||
+ ret = k5_hex_encode(passwd, passwd_len, FALSE, &hexpasswd);
|
||||
+ zap(passwd, passwd_len);
|
||||
+ if (ret != 0) {
|
||||
+ com_err(me, ret, _("Failed to convert the password to hexadecimal"));
|
||||
+ goto cleanup;
|
||||
}
|
||||
- memset(passwd, 0, passwd_len);
|
||||
|
||||
/* TODO: file lock for the service password file */
|
||||
|
||||
@@ -225,7 +216,7 @@ kdb5_ldap_stash_service_password(int argc, char **argv)
|
||||
if (str == NULL) {
|
||||
if (feof(pfile)) {
|
||||
/* If the service object dn is not present in the service password file */
|
||||
- if (fprintf(pfile, "%s#{HEX}%s\n", service_object, hexpasswd.data) < 0) {
|
||||
+ if (fprintf(pfile, "%s#{HEX}%s\n", service_object, hexpasswd) < 0) {
|
||||
com_err(me, errno,
|
||||
_("Failed to write service object password to file"));
|
||||
fclose(pfile);
|
||||
@@ -277,7 +268,7 @@ kdb5_ldap_stash_service_password(int argc, char **argv)
|
||||
while (fgets(line, MAX_LEN, pfile) != NULL) {
|
||||
if (((str = strstr(line, service_object)) != NULL) &&
|
||||
(line[strlen(service_object)] == '#')) {
|
||||
- if (fprintf(newfile, "%s#{HEX}%s\n", service_object, hexpasswd.data) < 0) {
|
||||
+ if (fprintf(newfile, "%s#{HEX}%s\n", service_object, hexpasswd) < 0) {
|
||||
com_err(me, errno, _("Failed to write service object "
|
||||
"password to file"));
|
||||
fclose(newfile);
|
||||
@@ -322,10 +313,7 @@ kdb5_ldap_stash_service_password(int argc, char **argv)
|
||||
|
||||
cleanup:
|
||||
|
||||
- if (hexpasswd.length != 0) {
|
||||
- memset(hexpasswd.data, 0, hexpasswd.length);
|
||||
- free(hexpasswd.data);
|
||||
- }
|
||||
+ zapfreestr(hexpasswd);
|
||||
|
||||
if (service_object)
|
||||
free(service_object);
|
||||
diff --git a/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.h b/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.h
|
||||
index cf652c578..08af62e17 100644
|
||||
--- a/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.h
|
||||
+++ b/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.h
|
||||
@@ -32,6 +32,4 @@
|
||||
#define MAX_LEN 1024
|
||||
#define MAX_SERVICE_PASSWD_LEN 256
|
||||
|
||||
-extern int tohex(krb5_data, krb5_data *);
|
||||
-
|
||||
extern void kdb5_ldap_stash_service_password(int argc, char **argv);
|
||||
diff --git a/src/plugins/kdb/ldap/libkdb_ldap/deps b/src/plugins/kdb/ldap/libkdb_ldap/deps
|
||||
index 1ff28553f..afca604dc 100644
|
||||
--- a/src/plugins/kdb/ldap/libkdb_ldap/deps
|
||||
+++ b/src/plugins/kdb/ldap/libkdb_ldap/deps
|
||||
@@ -220,15 +220,16 @@ ldap_service_stash.so ldap_service_stash.po $(OUTPRE)ldap_service_stash.$(OBJEXT
|
||||
$(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \
|
||||
$(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \
|
||||
$(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h $(top_srcdir)/include/k5-err.h \
|
||||
- $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-int-pkinit.h \
|
||||
- $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \
|
||||
- $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \
|
||||
- $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/kdb.h \
|
||||
- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \
|
||||
- $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \
|
||||
- $(top_srcdir)/include/socket-utils.h $(top_srcdir)/lib/kdb/kdb5.h \
|
||||
- kdb_ldap.h ldap_handle.h ldap_krbcontainer.h ldap_main.h \
|
||||
- ldap_misc.h ldap_realm.h ldap_service_stash.c ldap_service_stash.h
|
||||
+ $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-hex.h \
|
||||
+ $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \
|
||||
+ $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \
|
||||
+ $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \
|
||||
+ $(top_srcdir)/include/kdb.h $(top_srcdir)/include/krb5.h \
|
||||
+ $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \
|
||||
+ $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \
|
||||
+ $(top_srcdir)/lib/kdb/kdb5.h kdb_ldap.h ldap_handle.h \
|
||||
+ ldap_krbcontainer.h ldap_main.h ldap_misc.h ldap_realm.h \
|
||||
+ ldap_service_stash.c ldap_service_stash.h
|
||||
kdb_xdr.so kdb_xdr.po $(OUTPRE)kdb_xdr.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \
|
||||
$(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \
|
||||
$(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h \
|
||||
diff --git a/src/plugins/kdb/ldap/libkdb_ldap/ldap_service_stash.c b/src/plugins/kdb/ldap/libkdb_ldap/ldap_service_stash.c
|
||||
index 87a2118ff..cb30f4a7f 100644
|
||||
--- a/src/plugins/kdb/ldap/libkdb_ldap/ldap_service_stash.c
|
||||
+++ b/src/plugins/kdb/ldap/libkdb_ldap/ldap_service_stash.c
|
||||
@@ -31,16 +31,16 @@
|
||||
#include "ldap_main.h"
|
||||
#include "kdb_ldap.h"
|
||||
#include "ldap_service_stash.h"
|
||||
+#include <k5-hex.h>
|
||||
#include <ctype.h>
|
||||
|
||||
/* Decode a password of the form {HEX}<hexstring>. */
|
||||
static krb5_error_code
|
||||
dec_password(krb5_context context, const char *str, char **password_out)
|
||||
{
|
||||
+ krb5_error_code ret;
|
||||
+ uint8_t *bytes;
|
||||
size_t len;
|
||||
- const unsigned char *p;
|
||||
- unsigned char *password, *q;
|
||||
- unsigned int k;
|
||||
|
||||
*password_out = NULL;
|
||||
|
||||
@@ -48,30 +48,15 @@ dec_password(krb5_context context, const char *str, char **password_out)
|
||||
k5_setmsg(context, EINVAL, _("Not a hexadecimal password"));
|
||||
return EINVAL;
|
||||
}
|
||||
- str += 5;
|
||||
|
||||
- len = strlen(str);
|
||||
- if (len % 2 != 0) {
|
||||
- k5_setmsg(context, EINVAL, _("Password corrupt"));
|
||||
- return EINVAL;
|
||||
+ ret = k5_hex_decode(str + 5, &bytes, &len);
|
||||
+ if (ret) {
|
||||
+ if (ret == EINVAL)
|
||||
+ k5_setmsg(context, ret, _("Password corrupt"));
|
||||
+ return ret;
|
||||
}
|
||||
|
||||
- q = password = malloc(len / 2 + 1);
|
||||
- if (password == NULL)
|
||||
- return ENOMEM;
|
||||
-
|
||||
- for (p = (unsigned char *)str; *p != '\0'; p += 2) {
|
||||
- if (!isxdigit(*p) || !isxdigit(p[1])) {
|
||||
- free(password);
|
||||
- k5_setmsg(context, EINVAL, _("Password corrupt"));
|
||||
- return EINVAL;
|
||||
- }
|
||||
- sscanf((char *)p, "%2x", &k);
|
||||
- *q++ = k;
|
||||
- }
|
||||
- *q = '\0';
|
||||
-
|
||||
- *password_out = (char *)password;
|
||||
+ *password_out = (char *)bytes;
|
||||
return 0;
|
||||
}
|
||||
|
||||
@@ -128,35 +113,3 @@ krb5_ldap_readpassword(krb5_context context, const char *filename,
|
||||
/* Extract the plain password information. */
|
||||
return dec_password(context, val, password_out);
|
||||
}
|
||||
-
|
||||
-/* Encodes a sequence of bytes in hexadecimal */
|
||||
-
|
||||
-int
|
||||
-tohex(krb5_data in, krb5_data *ret)
|
||||
-{
|
||||
- unsigned int i=0;
|
||||
- int err = 0;
|
||||
-
|
||||
- ret->length = 0;
|
||||
- ret->data = NULL;
|
||||
-
|
||||
- ret->data = malloc((unsigned int)in.length * 2 + 1 /*Null termination */);
|
||||
- if (ret->data == NULL) {
|
||||
- err = ENOMEM;
|
||||
- goto cleanup;
|
||||
- }
|
||||
- ret->length = in.length * 2;
|
||||
- ret->data[ret->length] = 0;
|
||||
-
|
||||
- for (i = 0; i < in.length; i++)
|
||||
- snprintf(ret->data + 2 * i, 3, "%02x", in.data[i] & 0xff);
|
||||
-
|
||||
-cleanup:
|
||||
-
|
||||
- if (ret->length == 0) {
|
||||
- free(ret->data);
|
||||
- ret->data = NULL;
|
||||
- }
|
||||
-
|
||||
- return err;
|
||||
-}
|
||||
diff --git a/src/plugins/kdb/ldap/libkdb_ldap/ldap_service_stash.h b/src/plugins/kdb/ldap/libkdb_ldap/ldap_service_stash.h
|
||||
index dbf62443a..03cf9a1f7 100644
|
||||
--- a/src/plugins/kdb/ldap/libkdb_ldap/ldap_service_stash.h
|
||||
+++ b/src/plugins/kdb/ldap/libkdb_ldap/ldap_service_stash.h
|
||||
@@ -37,7 +37,4 @@ krb5_error_code
|
||||
krb5_ldap_readpassword(krb5_context context, const char *filename,
|
||||
const char *name, char **password_out);
|
||||
|
||||
-int
|
||||
-tohex(krb5_data, krb5_data *);
|
||||
-
|
||||
#endif
|
||||
diff --git a/src/plugins/kdb/ldap/libkdb_ldap/libkdb_ldap.exports b/src/plugins/kdb/ldap/libkdb_ldap/libkdb_ldap.exports
|
||||
index 2342f1db8..5376d3453 100644
|
||||
--- a/src/plugins/kdb/ldap/libkdb_ldap/libkdb_ldap.exports
|
||||
+++ b/src/plugins/kdb/ldap/libkdb_ldap/libkdb_ldap.exports
|
||||
@@ -1,4 +1,3 @@
|
||||
-tohex
|
||||
krb5_ldap_open
|
||||
krb5_ldap_close
|
||||
krb5_ldap_db_init
|
||||
diff --git a/src/slave/deps b/src/slave/deps
|
||||
index c3677a5e1..c0f558ecd 100644
|
||||
--- a/src/slave/deps
|
||||
+++ b/src/slave/deps
|
||||
@@ -64,10 +64,11 @@ $(OUTPRE)kproplog.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \
|
||||
$(top_srcdir)/include/gssrpc/xdr.h $(top_srcdir)/include/iprop.h \
|
||||
$(top_srcdir)/include/iprop_hdr.h $(top_srcdir)/include/k5-buf.h \
|
||||
$(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \
|
||||
- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \
|
||||
- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \
|
||||
- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \
|
||||
- $(top_srcdir)/include/kdb.h $(top_srcdir)/include/kdb_log.h \
|
||||
- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \
|
||||
- $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \
|
||||
- $(top_srcdir)/include/socket-utils.h kproplog.c
|
||||
+ $(top_srcdir)/include/k5-hex.h $(top_srcdir)/include/k5-int-pkinit.h \
|
||||
+ $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \
|
||||
+ $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \
|
||||
+ $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/kdb.h \
|
||||
+ $(top_srcdir)/include/kdb_log.h $(top_srcdir)/include/krb5.h \
|
||||
+ $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \
|
||||
+ $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \
|
||||
+ kproplog.c
|
||||
diff --git a/src/slave/kproplog.c b/src/slave/kproplog.c
|
||||
index 4f19eeb8c..d4aed7ba6 100644
|
||||
--- a/src/slave/kproplog.c
|
||||
+++ b/src/slave/kproplog.c
|
||||
@@ -9,6 +9,7 @@
|
||||
*/
|
||||
|
||||
#include "k5-int.h"
|
||||
+#include "k5-hex.h"
|
||||
#include <locale.h>
|
||||
#include <sys/types.h>
|
||||
#include <sys/mman.h>
|
||||
@@ -106,15 +107,15 @@ print_deltat(uint32_t *deltat)
|
||||
static void
|
||||
print_hex(const char *tag, utf8str_t *str)
|
||||
{
|
||||
- unsigned int i;
|
||||
unsigned int len;
|
||||
+ char *hex;
|
||||
|
||||
len = str->utf8str_t_len;
|
||||
|
||||
- printf("\t\t\t%s(%d): 0x", tag, len);
|
||||
- for (i = 0; i < len; i++)
|
||||
- printf("%02x", (krb5_octet)str->utf8str_t_val[i]);
|
||||
- printf("\n");
|
||||
+ if (k5_hex_encode(str->utf8str_t_val, len, FALSE, &hex) != 0)
|
||||
+ abort();
|
||||
+ printf("\t\t\t%s(%d): 0x%s\n", tag, len, hex);
|
||||
+ free(hex);
|
||||
}
|
||||
|
||||
/* Display string primitive. */
|
||||
diff --git a/src/tests/gssapi/deps b/src/tests/gssapi/deps
|
||||
index b784deb63..0b50d9ed3 100644
|
||||
--- a/src/tests/gssapi/deps
|
||||
+++ b/src/tests/gssapi/deps
|
||||
@@ -149,13 +149,13 @@ $(OUTPRE)t_prf.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \
|
||||
$(srcdir)/../../lib/gssapi/krb5/gssapiP_krb5.h $(srcdir)/../../lib/gssapi/krb5/gssapi_krb5.h \
|
||||
$(srcdir)/../../lib/gssapi/mechglue/mechglue.h $(srcdir)/../../lib/gssapi/mechglue/mglueP.h \
|
||||
$(top_srcdir)/include/k5-buf.h $(top_srcdir)/include/k5-err.h \
|
||||
- $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-int-pkinit.h \
|
||||
- $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \
|
||||
- $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \
|
||||
- $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \
|
||||
- $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \
|
||||
- $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \
|
||||
- common.h t_prf.c
|
||||
+ $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-hex.h \
|
||||
+ $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \
|
||||
+ $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \
|
||||
+ $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \
|
||||
+ $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \
|
||||
+ $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \
|
||||
+ $(top_srcdir)/include/socket-utils.h common.h t_prf.c
|
||||
$(OUTPRE)t_s4u.$(OBJEXT): $(BUILDTOP)/include/gssapi/gssapi.h \
|
||||
$(BUILDTOP)/include/gssapi/gssapi_ext.h $(BUILDTOP)/include/gssapi/gssapi_krb5.h \
|
||||
$(BUILDTOP)/include/krb5/krb5.h $(COM_ERR_DEPS) $(top_srcdir)/include/krb5.h \
|
||||
diff --git a/src/tests/gssapi/t_prf.c b/src/tests/gssapi/t_prf.c
|
||||
index 2c8c85188..6a698ce0f 100644
|
||||
--- a/src/tests/gssapi/t_prf.c
|
||||
+++ b/src/tests/gssapi/t_prf.c
|
||||
@@ -24,6 +24,7 @@
|
||||
*/
|
||||
|
||||
#include "k5-int.h"
|
||||
+#include "k5-hex.h"
|
||||
#include "common.h"
|
||||
#include "mglueP.h"
|
||||
#include "gssapiP_krb5.h"
|
||||
@@ -109,12 +110,14 @@ static struct {
|
||||
static size_t
|
||||
fromhex(const char *hexstr, unsigned char *out)
|
||||
{
|
||||
- const char *p;
|
||||
- size_t count;
|
||||
+ uint8_t *bytes;
|
||||
+ size_t len;
|
||||
|
||||
- for (p = hexstr, count = 0; *p != '\0'; p += 2, count++)
|
||||
- sscanf(p, "%2hhx", &out[count]);
|
||||
- return count;
|
||||
+ if (k5_hex_decode(hexstr, &bytes, &len) != 0)
|
||||
+ abort();
|
||||
+ memcpy(out, bytes, len);
|
||||
+ free(bytes);
|
||||
+ return len;
|
||||
}
|
||||
|
||||
int
|
||||
30
Zap-copy-of-secret-in-RC4-string-to-key.patch
Normal file
30
Zap-copy-of-secret-in-RC4-string-to-key.patch
Normal file
|
|
@ -0,0 +1,30 @@
|
|||
From 55a8161c3f5238df522447499a38bf2e9497b074 Mon Sep 17 00:00:00 2001
|
||||
From: Dylan Gray <35609490+Dylan-MSFT@users.noreply.github.com>
|
||||
Date: Fri, 13 Jul 2018 15:09:01 -0700
|
||||
Subject: [PATCH] Zap copy of secret in RC4 string-to-key
|
||||
|
||||
Commit b8814745049b5f401e3ae39a81dc1e14598ae48c (ticket 8576) added a
|
||||
zero-terminated copy of the input string in
|
||||
krb5int_arcfour_string_to_key(). This copy should be zeroed when
|
||||
freed as the input string typically contains a password.
|
||||
|
||||
[ghudson@mit.edu: rewrote commit message]
|
||||
|
||||
ticket: 8713 (new)
|
||||
---
|
||||
src/lib/crypto/krb/s2k_rc4.c | 2 +-
|
||||
1 file changed, 1 insertion(+), 1 deletion(-)
|
||||
|
||||
diff --git a/src/lib/crypto/krb/s2k_rc4.c b/src/lib/crypto/krb/s2k_rc4.c
|
||||
index 081a91217..f7e699d60 100644
|
||||
--- a/src/lib/crypto/krb/s2k_rc4.c
|
||||
+++ b/src/lib/crypto/krb/s2k_rc4.c
|
||||
@@ -25,7 +25,7 @@ krb5int_arcfour_string_to_key(const struct krb5_keytypes *ktp,
|
||||
if (utf8 == NULL)
|
||||
return err;
|
||||
err = k5_utf8_to_utf16le(utf8, ©str, ©strlen);
|
||||
- free(utf8);
|
||||
+ zapfree(utf8, string->length);
|
||||
if (err)
|
||||
return err;
|
||||
|
||||
29
Zap-data-when-freeing-krb5_spake_factor.patch
Normal file
29
Zap-data-when-freeing-krb5_spake_factor.patch
Normal file
|
|
@ -0,0 +1,29 @@
|
|||
From 5d970e16e768a134e65ee7cf367b8f34a80e0980 Mon Sep 17 00:00:00 2001
|
||||
From: Greg Hudson <ghudson@mit.edu>
|
||||
Date: Tue, 27 Mar 2018 15:42:28 -0400
|
||||
Subject: [PATCH] Zap data when freeing krb5_spake_factor
|
||||
|
||||
krb5_spake_factor structures will sometimes hold sensitive data when
|
||||
second-factor SPAKE is implemented, so should be zapped when freed.
|
||||
|
||||
ticket: 8647
|
||||
(cherry picked from commit 9cc94a3f1ce06a4430f684300a747ec079102403)
|
||||
---
|
||||
src/lib/krb5/krb/kfree.c | 4 +++-
|
||||
1 file changed, 3 insertions(+), 1 deletion(-)
|
||||
|
||||
diff --git a/src/lib/krb5/krb/kfree.c b/src/lib/krb5/krb/kfree.c
|
||||
index e1ea1494a..71e7fcad0 100644
|
||||
--- a/src/lib/krb5/krb/kfree.c
|
||||
+++ b/src/lib/krb5/krb/kfree.c
|
||||
@@ -897,7 +897,9 @@ k5_free_spake_factor(krb5_context context, krb5_spake_factor *val)
|
||||
{
|
||||
if (val == NULL)
|
||||
return;
|
||||
- krb5_free_data(context, val->data);
|
||||
+ if (val->data != NULL)
|
||||
+ zapfree(val->data->data, val->data->length);
|
||||
+ free(val->data);
|
||||
free(val);
|
||||
}
|
||||
|
||||
1
ci.fmf
1
ci.fmf
|
|
@ -1 +0,0 @@
|
|||
resultsdb-testcase: separate
|
||||
|
|
@ -1,8 +0,0 @@
|
|||
--- !Policy
|
||||
product_versions:
|
||||
- fedora-*
|
||||
decision_contexts:
|
||||
- bodhi_update_push_stable
|
||||
subject_type: koji_build
|
||||
rules:
|
||||
- !PassingTestCaseRule {test_case_name: fedora-ci.koji-build./plans/tests.functional}
|
||||
|
|
@ -6,9 +6,9 @@ AssertPathExists=!/var/kerberos/krb5kdc/kpropd.acl
|
|||
|
||||
[Service]
|
||||
Type=forking
|
||||
PIDFile=/run/kadmind.pid
|
||||
PIDFile=/var/run/kadmind.pid
|
||||
EnvironmentFile=-/etc/sysconfig/kadmin
|
||||
ExecStart=/usr/sbin/kadmind -P /run/kadmind.pid $KADMIND_ARGS
|
||||
ExecStart=/usr/sbin/kadmind -P /var/run/kadmind.pid $KADMIND_ARGS
|
||||
ExecReload=/bin/kill -HUP $MAINPID
|
||||
|
||||
[Install]
|
||||
|
|
|
|||
|
|
@ -4,6 +4,6 @@
|
|||
monthly
|
||||
rotate 12
|
||||
postrotate
|
||||
systemctl reload kadmin.service || true
|
||||
/bin/kill -HUP `cat /var/run/kadmind.pid 2>/dev/null` 2> /dev/null || true
|
||||
endscript
|
||||
}
|
||||
|
|
|
|||
11
kdc.conf
11
kdc.conf
|
|
@ -1,7 +1,3 @@
|
|||
[libdefaults]
|
||||
# Allow RC4 HMAC-MD5 for session keys (see CVE-2022-37966)
|
||||
#allow_rc4 = true
|
||||
|
||||
[kdcdefaults]
|
||||
kdc_ports = 88
|
||||
kdc_tcp_ports = 88
|
||||
|
|
@ -9,12 +5,9 @@
|
|||
|
||||
[realms]
|
||||
EXAMPLE.COM = {
|
||||
master_key_type = aes256-cts-hmac-sha384-192
|
||||
#master_key_type = aes256-cts
|
||||
acl_file = /var/kerberos/krb5kdc/kadm5.acl
|
||||
dict_file = /usr/share/dict/words
|
||||
default_principal_flags = +preauth
|
||||
admin_keytab = /var/kerberos/krb5kdc/kadm5.keytab
|
||||
supported_enctypes = aes256-cts-hmac-sha384-192:normal aes128-cts-hmac-sha256-128:normal aes256-cts-hmac-sha1-96:normal aes128-cts-hmac-sha1-96:normal camellia256-cts-cmac:normal camellia128-cts-cmac:normal arcfour-hmac-md5:normal
|
||||
# Supported encryption types for FIPS mode:
|
||||
#supported_enctypes = aes256-cts-hmac-sha384-192:normal aes128-cts-hmac-sha256-128:normal
|
||||
supported_enctypes = aes256-cts:normal aes128-cts:normal des3-hmac-sha1:normal arcfour-hmac:normal camellia256-cts:normal camellia128-cts:normal
|
||||
}
|
||||
|
|
|
|||
21
krb5-1.11-kpasswdtest.patch
Normal file
21
krb5-1.11-kpasswdtest.patch
Normal file
|
|
@ -0,0 +1,21 @@
|
|||
From fc2953ce9ce06ff896b1687e1c0cc9b8a4357d09 Mon Sep 17 00:00:00 2001
|
||||
From: Robbie Harwood <rharwood@redhat.com>
|
||||
Date: Tue, 23 Aug 2016 16:52:01 -0400
|
||||
Subject: [PATCH] krb5-1.11-kpasswdtest.patch
|
||||
|
||||
---
|
||||
src/kadmin/testing/proto/krb5.conf.proto | 1 +
|
||||
1 file changed, 1 insertion(+)
|
||||
|
||||
diff --git a/src/kadmin/testing/proto/krb5.conf.proto b/src/kadmin/testing/proto/krb5.conf.proto
|
||||
index 00c442978..9c4bc1de7 100644
|
||||
--- a/src/kadmin/testing/proto/krb5.conf.proto
|
||||
+++ b/src/kadmin/testing/proto/krb5.conf.proto
|
||||
@@ -9,6 +9,7 @@
|
||||
__REALM__ = {
|
||||
kdc = __KDCHOST__:1750
|
||||
admin_server = __KDCHOST__:1751
|
||||
+ kpasswd_server = __KDCHOST__:1752
|
||||
database_module = foobar_db2_module_blah
|
||||
}
|
||||
|
||||
44
krb5-1.11-run_user_0.patch
Normal file
44
krb5-1.11-run_user_0.patch
Normal file
|
|
@ -0,0 +1,44 @@
|
|||
From b0adf9a65d5c22a77cf957ceb1c298baff01555d Mon Sep 17 00:00:00 2001
|
||||
From: Robbie Harwood <rharwood@redhat.com>
|
||||
Date: Tue, 23 Aug 2016 16:49:57 -0400
|
||||
Subject: [PATCH] krb5-1.11-run_user_0.patch
|
||||
|
||||
A hack: if we're looking at creating a ccache directory directly below
|
||||
the /run/user/0 directory, and /run/user/0 doesn't exist, try to create
|
||||
it, too.
|
||||
---
|
||||
src/lib/krb5/ccache/cc_dir.c | 14 ++++++++++++++
|
||||
1 file changed, 14 insertions(+)
|
||||
|
||||
diff --git a/src/lib/krb5/ccache/cc_dir.c b/src/lib/krb5/ccache/cc_dir.c
|
||||
index 73f0fe62d..4850c0d07 100644
|
||||
--- a/src/lib/krb5/ccache/cc_dir.c
|
||||
+++ b/src/lib/krb5/ccache/cc_dir.c
|
||||
@@ -61,6 +61,8 @@
|
||||
|
||||
#include <dirent.h>
|
||||
|
||||
+#define ROOT_SPECIAL_DCC_PARENT "/run/user/0"
|
||||
+
|
||||
extern const krb5_cc_ops krb5_dcc_ops;
|
||||
extern const krb5_cc_ops krb5_fcc_ops;
|
||||
|
||||
@@ -237,6 +239,18 @@ verify_dir(krb5_context context, const char *dirname)
|
||||
|
||||
if (stat(dirname, &st) < 0) {
|
||||
if (errno == ENOENT) {
|
||||
+ if (strncmp(dirname, ROOT_SPECIAL_DCC_PARENT "/",
|
||||
+ sizeof(ROOT_SPECIAL_DCC_PARENT)) == 0 &&
|
||||
+ stat(ROOT_SPECIAL_DCC_PARENT, &st) < 0 &&
|
||||
+ errno == ENOENT) {
|
||||
+#ifdef USE_SELINUX
|
||||
+ selabel = krb5int_push_fscreatecon_for(ROOT_SPECIAL_DCC_PARENT);
|
||||
+#endif
|
||||
+ status = mkdir(ROOT_SPECIAL_DCC_PARENT, S_IRWXU);
|
||||
+#ifdef USE_SELINUX
|
||||
+ krb5int_pop_fscreatecon(selabel);
|
||||
+#endif
|
||||
+ }
|
||||
#ifdef USE_SELINUX
|
||||
selabel = krb5int_push_fscreatecon_for(dirname);
|
||||
#endif
|
||||
37
krb5-1.12-api.patch
Normal file
37
krb5-1.12-api.patch
Normal file
|
|
@ -0,0 +1,37 @@
|
|||
From abb19d2d2eac5f9f6e4a1bf26f59f3a62143dab9 Mon Sep 17 00:00:00 2001
|
||||
From: Robbie Harwood <rharwood@redhat.com>
|
||||
Date: Tue, 23 Aug 2016 16:47:00 -0400
|
||||
Subject: [PATCH] krb5-1.12-api.patch
|
||||
|
||||
Reference docs don't define what happens if you call krb5_realm_compare() with
|
||||
malformed krb5_principal structures. Define a behavior which keeps it from
|
||||
crashing if applications don't check ahead of time.
|
||||
---
|
||||
src/lib/krb5/krb/princ_comp.c | 7 +++++++
|
||||
1 file changed, 7 insertions(+)
|
||||
|
||||
diff --git a/src/lib/krb5/krb/princ_comp.c b/src/lib/krb5/krb/princ_comp.c
|
||||
index a6936107d..0ed78833b 100644
|
||||
--- a/src/lib/krb5/krb/princ_comp.c
|
||||
+++ b/src/lib/krb5/krb/princ_comp.c
|
||||
@@ -36,6 +36,10 @@ realm_compare_flags(krb5_context context,
|
||||
const krb5_data *realm1 = &princ1->realm;
|
||||
const krb5_data *realm2 = &princ2->realm;
|
||||
|
||||
+ if (princ1 == NULL || princ2 == NULL)
|
||||
+ return FALSE;
|
||||
+ if (realm1 == NULL || realm2 == NULL)
|
||||
+ return FALSE;
|
||||
if (realm1->length != realm2->length)
|
||||
return FALSE;
|
||||
if (realm1->length == 0)
|
||||
@@ -88,6 +92,9 @@ krb5_principal_compare_flags(krb5_context context,
|
||||
krb5_principal upn2 = NULL;
|
||||
krb5_boolean ret = FALSE;
|
||||
|
||||
+ if (princ1 == NULL || princ2 == NULL)
|
||||
+ return FALSE;
|
||||
+
|
||||
if (flags & KRB5_PRINCIPAL_COMPARE_ENTERPRISE) {
|
||||
/* Treat UPNs as if they were real principals */
|
||||
if (princ1->type == KRB5_NT_ENTERPRISE_PRINCIPAL) {
|
||||
Some files were not shown because too many files have changed in this diff Show more
Loading…
Add table
Add a link
Reference in a new issue