#include "k5-int.h"
#include "des_int.h"
#include "keyhash_provider.h"
#define CONFLENGTH 8
#define KRB5_MD5DES_BETA5_COMPAT
static krb5_error_code
k5_md5des_hash(krb5_context context, krb5_const krb5_keyblock *key,
krb5_keyusage usage, const krb5_data *ivec,
const krb5_data *input, krb5_data *output)
{
krb5_error_code ret = 0;
krb5_data data;
unsigned char conf[CONFLENGTH];
krb5_keyblock xorkey;
int i;
CK_MECHANISM mechanism;
CK_RV rv;
CK_ULONG hashlen = MD5_CKSUM_LENGTH;
if (key->length != 8)
return(KRB5_BAD_KEYSIZE);
if (ivec)
return(KRB5_CRYPTO_INTERNAL);
if (output->length != (CONFLENGTH+MD5_CKSUM_LENGTH))
return(KRB5_CRYPTO_INTERNAL);
data.length = CONFLENGTH;
data.data = (char *) conf;
if ((ret = krb5_c_random_make_octets(context, &data)))
return(ret);
xorkey.magic = key->magic;
xorkey.enctype = key->enctype;
xorkey.length = key->length;
xorkey.contents = (krb5_octet *)malloc(key->length);
if (xorkey.contents == NULL)
return(KRB5_CRYPTO_INTERNAL);
(void) memcpy(xorkey.contents, key->contents, xorkey.length);
for (i=0; i<xorkey.length; i++)
xorkey.contents[i] ^= 0xf0;
if (!mit_des_check_key_parity(xorkey.contents)) {
ret = KRB5DES_BAD_KEYPAR;
goto cleanup;
}
if (mit_des_is_weak_key(xorkey.contents)) {
ret = KRB5DES_WEAK_KEY;
goto cleanup;
}
mechanism.mechanism = CKM_MD5;
mechanism.pParameter = NULL_PTR;
mechanism.ulParameterLen = 0;
if ((rv = C_DigestInit(krb_ctx_hSession(context), &mechanism)) != CKR_OK) {
KRB5_LOG(KRB5_ERR, "C_DigestInit failed in k5_md5des_hash: "
"rv = 0x%x.", rv);
ret = PKCS_ERR;
goto cleanup;
}
if ((rv = C_DigestUpdate(krb_ctx_hSession(context),
(CK_BYTE_PTR)conf, (CK_ULONG)sizeof(conf))) != CKR_OK) {
KRB5_LOG(KRB5_ERR, "C_DigestUpdate failed in k5_md5des_hash: "
"rv = 0x%x", rv);
ret = PKCS_ERR;
goto cleanup;
}
if ((rv = C_DigestUpdate(krb_ctx_hSession(context),
(CK_BYTE_PTR)input->data, (CK_ULONG)input->length)) != CKR_OK) {
KRB5_LOG(KRB5_ERR, "C_DigestUpdate failed in k5_md5des_hash: "
"rv = 0x%x", rv);
return(PKCS_ERR);
}
if ((rv = C_DigestFinal(krb_ctx_hSession(context),
(CK_BYTE_PTR)(output->data + CONFLENGTH),
(CK_ULONG_PTR)&hashlen)) != CKR_OK) {
KRB5_LOG(KRB5_ERR, "C_DigestFinal failed in k5_md5des_hash: "
"rv = 0x%x", rv);
ret = PKCS_ERR;
goto cleanup;
}
(void) memcpy(output->data, conf, CONFLENGTH);
ret = mit_des_cbc_encrypt(context,
(krb5_pointer) output->data,
(krb5_pointer) output->data, output->length,
&xorkey, (unsigned char*) mit_des_zeroblock, 1);
cleanup:
free(xorkey.contents);
return(ret);
}
static krb5_error_code
k5_md5des_verify(krb5_context context,
krb5_const krb5_keyblock *key,
krb5_keyusage usage,
krb5_const krb5_data *ivec,
krb5_const krb5_data *input,
krb5_const krb5_data *hash,
krb5_boolean *valid)
{
krb5_error_code ret = 0;
unsigned char plaintext[CONFLENGTH+MD5_CKSUM_LENGTH];
unsigned char digest[MD5_CKSUM_LENGTH];
krb5_keyblock xorkey;
int i;
int compathash = 0;
CK_MECHANISM mechanism;
CK_RV rv;
CK_ULONG hashlen = MD5_CKSUM_LENGTH;
if (key->length != 8)
return(KRB5_BAD_KEYSIZE);
if (ivec)
return(KRB5_CRYPTO_INTERNAL);
if (hash->length != (CONFLENGTH + MD5_CKSUM_LENGTH)) {
#ifdef KRB5_MD5DES_BETA5_COMPAT
if (hash->length != MD5_CKSUM_LENGTH)
return(KRB5_CRYPTO_INTERNAL);
else
compathash = 1;
#else
return(KRB5_CRYPTO_INTERNAL);
#endif
}
xorkey.magic = key->magic;
xorkey.enctype = key->enctype;
xorkey.length = key->length;
xorkey.contents = (krb5_octet *)malloc(key->length);
if (xorkey.contents == NULL)
return(KRB5_CRYPTO_INTERNAL);
(void) memcpy(xorkey.contents, key->contents, xorkey.length);
if (!compathash) {
for (i=0; i<xorkey.length; i++)
xorkey.contents[i] ^= 0xf0;
}
if (!mit_des_check_key_parity(xorkey.contents)) {
ret = KRB5DES_BAD_KEYPAR;
goto cleanup;
}
if (mit_des_is_weak_key(xorkey.contents)) {
ret = KRB5DES_WEAK_KEY;
goto cleanup;
}
if (!compathash) {
ret = mit_des_cbc_encrypt(context,
(krb5_pointer) hash->data,
(krb5_pointer) plaintext, hash->length,
&xorkey, (unsigned char*) mit_des_zeroblock, 0);
} else {
ret = mit_des_cbc_encrypt(context,
(krb5_pointer) hash->data,
(krb5_pointer) plaintext, hash->length,
&xorkey, xorkey.contents, 0);
}
if (ret) goto cleanup;
mechanism.mechanism = CKM_MD5;
mechanism.pParameter = NULL_PTR;
mechanism.ulParameterLen = 0;
if ((rv = C_DigestInit(krb_ctx_hSession(context), &mechanism)) != CKR_OK) {
KRB5_LOG(KRB5_ERR, "C_DigestInit failed in k5_md5des_verify: "
"rv = 0x%x.", rv);
ret = PKCS_ERR;
goto cleanup;
}
if (!compathash) {
if ((rv = C_DigestUpdate(krb_ctx_hSession(context),
(CK_BYTE_PTR)plaintext, (CK_ULONG)CONFLENGTH)) != CKR_OK) {
KRB5_LOG(KRB5_ERR, "C_DigestUpdate failed in k5_md5des_verify: "
"rv = 0x%x", rv);
ret = PKCS_ERR;
goto cleanup;
}
}
if ((rv = C_DigestUpdate(krb_ctx_hSession(context),
(CK_BYTE_PTR)input->data, (CK_ULONG)input->length)) != CKR_OK) {
KRB5_LOG(KRB5_ERR, "C_DigestUpdate failed in k5_md5des_verify: "
"rv = 0x%x", rv);
ret = PKCS_ERR;
goto cleanup;
}
if ((rv = C_DigestFinal(krb_ctx_hSession(context),
(CK_BYTE_PTR)digest, (CK_ULONG_PTR)&hashlen)) != CKR_OK) {
KRB5_LOG(KRB5_ERR, "C_DigestFinal failed in k5_md5des_verify: "
"rv = 0x%x", rv);
ret = PKCS_ERR;
goto cleanup;
}
if (!compathash) {
*valid = (memcmp(plaintext+CONFLENGTH, digest, sizeof(digest)) == 0);
} else {
*valid = (memcmp(plaintext, digest, sizeof(digest)) == 0);
}
(void) memset(plaintext, 0, sizeof(plaintext));
cleanup:
free(xorkey.contents);
return(ret);
}
const struct krb5_keyhash_provider krb5int_keyhash_md5des = {
CONFLENGTH + MD5_CKSUM_LENGTH,
k5_md5des_hash,
k5_md5des_verify
};