RT RT/krbdev.mit.edu: Ticket #6876 hmac-md5 checksum doesn't work with DES keys Signed in as guest.
[Logout]

[Home] [Search] [Configuration]

[Display] [History] [Basics] [Dates] [People] [Links] [Jumbo]

 
 

 The Basics  
Id
6876
Status
resolved
Worked
0 min
Priority
0/0
Queue
krb5
 

 Keyword Selections  
Component
Version_reported
Version_Fixed
  • 1.8.4
Target_Version
Tags
 

 Relationships  
Depends on:
Depended on by:
Parents:
Children:

Refers to:
  • 6869: (ghudson) hmac-md5 checksum doesn't work with DES keys [resolved]
Referred to by:
 
 Dates  
Created: Mon Feb 28 12:42:28 2011
Starts: Not set
Started: Mon Feb 28 12:42:29 2011
Last Contact: Not set
Due: Not set
Updated: Mon Feb 28 13:12:08 2011 by tlyu
 

 People  
Owner
 tlyu
Requestors
 tlyu@mit.edu
Cc
 
AdminCc
 
 

 More about Tom Yu  
Comments about this user:
No comment entered about this user
This user's 25 highest priority tickets:
 

History   Display mode: [Brief headers] [Full headers]
      Mon Feb 28 12:42:28 2011  tlyu - Ticket created    
     
From: tlyu@mit.edu
Subject: SVN Commit


pull up r24639, r24641 from trunk

 ------------------------------------------------------------------------
 r24641 | ghudson | 2011-02-18 10:06:57 -0500 (Fri, 18 Feb 2011) | 7 lines

 ticket: 6869

 Fix a conceptual bug in r24639: the intermediate key container length
 should be the hash's output size, not its block size.  (The bug did
 not show up in testing because it is harmless in practice; MD5 has a
 larger block size than output size.)
 ------------------------------------------------------------------------
 r24639 | ghudson | 2011-02-16 17:52:41 -0500 (Wed, 16 Feb 2011) | 11 lines

 ticket: 6869
 subject: hmac-md5 checksum doesn't work with DES keys
 target_version: 1.9
 tags: pullup

 krb5int_hmacmd5_checksum calculates an intermediate key using an HMAC.
 The container for this key should be allocated using the HMAC output
 size (which is the hash blocksize), not the original key size.  This
 bug was causing the function to fail with DES keys, which can be used
 with hmac-md5 in PAC signatures.

http://src.mit.edu/fisheye/changelog/krb5/?cs=24670
Commit By: tlyu
Revision: 24670
Changed Files:
U   branches/krb5-1-8/src/lib/crypto/krb/checksum/hmac_md5.c


Download (untitled) 1.1k
      Mon Feb 28 12:42:29 2011  tlyu - Requestor tlyu@mit.edu added    
      Mon Feb 28 12:42:29 2011  tlyu - Status changed from new to resolved    
      Mon Feb 28 12:42:29 2011  tlyu - Version_Fixed 1.8.4 added    
      Mon Feb 28 13:12:08 2011  tlyu - Ticket 6876 RefersTo ticket 6869.