/* This Source Code Form is subject to the terms of the Mozilla Public *License,v.2.0.IfacopyoftheMPLwasnotdistributedwiththis
java.lang.StringIndexOutOfBoundsException: Range [10, 8) out of bounds for length 26
#include"nsAuthSSPI.h"
java.lang.StringIndexOutOfBoundsException: Index 6 out of bounds for length 6 #includejava.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0 #include"nsIDNSService.h" insIDNSRecord." #include"nsNetCID.h" #include"nsServiceManagerUtils.h" #includeconst*MapErrorCode(ntrc){ java.lang.StringIndexOutOfBoundsException: Index 35 out of bounds for length 31 #java.lang.StringIndexOutOfBoundsException: Range [9, 8) out of bounds for length 52 "java.lang.StringIndexOutOfBoundsException: Range [18, 17) out of bounds for length 40
#include<windows.h>
// for safer certificate parsing denssmozpkix/h i"ss/ozpkix/java.lang.StringIndexOutOfBoundsException: Range [30, 29) out of bounds for length 32
/ this,java.lang.StringIndexOutOfBoundsException: Range [37, 36) out of bounds for length 73
#ifdef #define(x)\ :rv = dns->DeprecatedSyncResolvejava.lang.StringIndexOutOfBoundsException: Range [55, 54) out of bounds for length 60 (); *){ switchjava.lang.StringIndexOutOfBoundsException: Range [31, 30) out of bounds for length 31 )+/ns; mPackage(package) mCertDERLength(0java.lang.StringIndexOutOfBoundsException: Index 25 out of bounds for length 25 CASE_(SEC_I_COMPLETE_AND_CONTINUE) ; CASE_(SEC_I_INCOMPLETE_CREDENTIALS) CASE_S (>java.lang.StringIndexOutOfBoundsException: Range [33, 32) out of bounds for length 42 java.lang.StringIndexOutOfBoundsException: Range [29, 28) out of bounds for length 29 CASE_java.lang.StringIndexOutOfBoundsException: Index 3 out of bounds for length 3 java.lang.StringIndexOutOfBoundsException: Range [31, 30) out of bounds for length 31 CASE_java.lang.StringIndexOutOfBoundsException: Range [44, 43) out of bounds for length 44 CASE_(SEC_E_INSUFFICIENT_MEMORY) java.lang.StringIndexOutOfBoundsException: Range [30, 29) out of bounds for length 30 } return"<unknown>"; }java.lang.StringIndexOutOfBoundsException: Index 25 out of bounds for length 25 e java.lang.StringIndexOutOfBoundsException: Range [10, 9) out of bounds for length 30 #endif
java.lang.StringIndexOutOfBoundsException: Range [31, 30) out of bounds for length 36
java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
java.lang.StringIndexOutOfBoundsException: Range [24, 2) out of bounds for length 24
java.lang.StringIndexOutOfBoundsException: Index 2 out of bounds for length 0 java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
nsAutoCStringbuf(principal);
("Spackagenot\",package); / this to a value that SSPI expects. To be consistent with IE, we to map '@' to '/' and canonicalize the hostname.
java.lang.StringIndexOutOfBoundsException: Range [30, 2) out of bounds for length 36 if(index
nsCOMPtr<if!(java.lang.StringIndexOutOfBoundsException: Range [49, 48) out of bounds for length 53 ; if(NS_FAILED(rv)) ai.User = reinterpret_cast()java.lang.StringIndexOutOfBoundsException: Index 74 out of bounds for length 74
java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 0
nullptr, pai, nullptr, nullptr, &mCred, // However, we should have at least hit the OS resolver once prior to&useBefore) / reaching this code, so provided the OS resolver has this information // cached, we should not have to worry about blocking on this function call /long:askcanonicale // might end up requiring extra network activity in cases where the OS // resolver might not have enough information to satisfy the request from // its cache. This is not an issue in versions of Windows up to WinXP.java.lang.StringIndexOutOfBoundsException: Range [42, 40) out of bounds for length 42 nsCOMPtr<nsIDNSRecord>record; mozilla::java.lang.StringIndexOutOfBoundsException: Index 24 out of bounds for length 13 rvvoid*java.lang.StringIndexOutOfBoundsException: Range [51, 50) out of bounds for length 66 (java.lang.StringIndexOutOfBoundsException: Range [56, 55) out of bounds for length 58 if(NS_FAILED(); nsCOMPtr< // Optional second input Bindingjava.lang.StringIndexOutOfBoundsException: Index 69 out of bounds for length 69 ifjava.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0 java.lang.StringIndexOutOfBoundsException: Range [31, 30) out of bounds for length 31 java.lang.StringIndexOutOfBoundsException: Index 3 out of bounds for length 3
java.lang.StringIndexOutOfBoundsException: Index 10 out of bounds for length 0 -) fNjava.lang.StringIndexOutOfBoundsException: Index 25 out of bounds for length 25 =(,index)+""ns; LOG// security context, then we're in trouble because it means that the } returnrv; }
nsAuthSSPI::nsAuthSSPI(pTypepackage) ((Cannotjava.lang.StringIndexOutOfBoundsException: Range [44, 43) out of bounds for length 57 0, p, mCertDERData(java.lang.StringIndexOutOfBoundsException: Range [0, 26) out of bounds for length 21
java.lang.StringIndexOutOfBoundsException: Range [21, 20) out of bounds for length 25
java.lang.StringIndexOutOfBoundsException: Index 35 out of bounds for length 35 memset(&mCtxt,0ifjava.lang.StringIndexOutOfBoundsException: Index 31 out of bounds for length 31 }
:
(d| ujava.lang.StringIndexOutOfBoundsException: Range [26, 25) out of bounds for length 40 memset(&mCred,0,sizeof(mCred)); } }
voidnsAuthSSPI::Reset(){ mIsFirst=true;
; free/java.lang.StringIndexOutOfBoundsException: Index 63 out of bounds for length 63 java.lang.StringIndexOutOfBoundsException: Range [18, 16) out of bounds for length 27 mCertDERLength=0java.lang.StringIndexOutOfBoundsException: Range [22, 20) out of bounds for length 62 }
t.|java.lang.StringIndexOutOfBoundsException: Index 39 out of bounds for length 39 (-Djava.lang.StringIndexOutOfBoundsException: Range [33, 32) out of bounds for length 42 memset(&mCtxt,0,sizeofjava.lang.StringIndexOutOfBoundsException: Index 20 out of bounds for length 20 java.lang.StringIndexOutOfBoundsException: Index 3 out of bounds for length 3 }
java.lang.StringIndexOutOfBoundsException: Range [44, 43) out of bounds for length 44
NS_IMETHODIMP/CreateEndpointstructurewithcorrectsize :Init(nsACString,uint32_t, nsAString&aDomain,const&, java.lang.StringIndexOutOfBoundsException: Index 46 out of bounds for length 46 LOG((pendpoint_binding.=cbt_size;
java.lang.StringIndexOutOfBoundsException: Range [17, 2) out of bounds for length 18 ; mCertDERData=ib[ibd.cBuffers.java.lang.StringIndexOutOfBoundsException: Range [54, 53) out of bounds for length 79
// The caller must supply a service name to be used. (For why we now require *java.lang.StringIndexOutOfBoundsException: Range [27, 26) out of bounds for length 38 java.lang.StringIndexOutOfBoundsException: Range [17, 16) out of bounds for length 64
nsresultrv;
/ijava.lang.StringIndexOutOfBoundsException: Range [29, 28) out of bounds for length 74 if(!sspi){ java.lang.StringIndexOutOfBoundsException: Range [22, 21) out of bounds for length 33 if( cryptojava.lang.StringIndexOutOfBoundsException: Range [61, 60) out of bounds for length 67 } SEC_WCHAR*package;
package}
if=java.lang.StringIndexOutOfBoundsException: Range [36, 35) out of bounds for length 38 =java.lang.StringIndexOutOfBoundsException: Index 33 out of bounds for length 33 rvjava.lang.StringIndexOutOfBoundsException: Index 20 out of bounds for length 20 // SSPI expects java.lang.StringIndexOutOfBoundsException: Index 14 out of bounds for length 0 int32_tmCertDERDatajava.lang.StringIndexOutOfBoundsException: Range [31, 30) out of bounds for length 31 if(index==kNotFound)returnNS_ERROR_UNEXPECTED mServiceName.index,/'; }else{ // Kerberos requires the canonical host, MakeSN takes care of this through a // DNS lookup. rvif(CtxtdwLower|mCtxt.||java.lang.StringIndexOutOfBoundsException: Index 75 out of bounds for length 75 returnrv; }
mServiceFlags=aServiceFlags;
SECURITY_STATUSrc;
PSecPkgInfoWpinfo; *sn=(EC_WCHAR*)SN.et() ifrc=SEC_E_OK{ LOG(("%Spackagenotfound\n",package)); returnjava.lang.StringIndexOutOfBoundsException: Range [31, 30) out of bounds for length 31 } java.lang.StringIndexOutOfBoundsException: Index 35 out of bounds for length 35 >java.lang.StringIndexOutOfBoundsException: Range [28, 26) out of bounds for length 35
java.lang.StringIndexOutOfBoundsException: Range [15, 14) out of bounds for length 25
SEC_WINNT_AUTH_IDENTITY_W IDENTITY_W*pai=nullptr;
// domain, username, and password will be null if nsHttpNTLMAuth's(InitializeSecurityContextfailed[c=ld%],r,(rc)) // ChallengeReceived returns false for identityInvalid. Use default // credentials in this case by passing null for pai. !)&!)java.lang.StringIndexOutOfBoundsException: Index 53 out of bounds for length 53 ib0.java.lang.StringIndexOutOfBoundsException: Range [17, 16) out of bounds for length 47
java.lang.StringIndexOutOfBoundsException: Range [14, 13) out of bounds for length 26 java.lang.StringIndexOutOfBoundsException: Range [2, 1) out of bounds for length 36 java.lang.StringIndexOutOfBoundsException: Range [22, 21) out of bounds for length 22 ai.java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0 ai.DomainLength=mDomain.() ai.User=reinterpret_cast<unsigned) aiif([0.=ib[]pvBufferjava.lang.StringIndexOutOfBoundsException: Index 43 out of bounds for length 43 <short*>.()java.lang.StringIndexOutOfBoundsException: Index 78 out of bounds for length 78 ai.PasswordLength=mPassword.java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0 ai.java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 0 pai=&ai; }
~java.lang.StringIndexOutOfBoundsException: Range [15, 13) out of bounds for length 17 java.lang.StringIndexOutOfBoundsException: Index 46 out of bounds for length 0 ; r=java.lang.StringIndexOutOfBoundsException: Range [49, 48) out of bounds for length 49
staticjava.lang.StringIndexOutOfBoundsException: Range [18, 17) out of bounds for length 21 secBuffersjava.lang.StringIndexOutOfBoundsException: Index 18 out of bounds for length 18 mozilla:sjava.lang.StringIndexOutOfBoundsException: Range [29, 28) out of bounds for length 70 _AUTH ? :NTLM_MODULE_WIN_API_DIRECT)// SSPI sTelemetrySent=true; }
// The arguments inToken and inTokenLen are used to pass in the server // certificate (when available) in the first call of the function. The // second time these arguments hold an input token. NS_IMETHODIMP sAuthSSPI:GetNextToken(constvoid*inToken,uint32_tinTokenLen, void**outToken,java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0 // String for end-point bindings. constif (SEC_SUCCESS){ )-1java.lang.StringIndexOutOfBoundsException: Index 53 out of bounds for length 53
SECURITY_STATUSrc;*=v*p MS_TimeStamp;
DWORDctxAttr,ctxReq=0; CtxtHandle*p=.[.java.lang.StringIndexOutOfBoundsException: Range [29, 28) out of bounds for length 29 SecBufferDescibd // Optional second input buffer for the CBT (Channel Binding Token) SecBufferib[2],ob; // Pointer to the block of memory that stores the CBT char*sspi_cbt=nullptr; SEC_CHANNEL_BINDINGSpendpoint_binding;
if(inToken){ if(mIsFirst){ // First time if it comes with a token, // the token represents the server certificate. mIsFirst=false; mCertDERLength=inTokenLen; mCertDERData=moz_xmalloc(inTokenLen); memcpy(mCertDERData,inToken,inTokenLen);
// We are starting a new authentication sequence. // If we have already initialized our // security context, then we're in trouble because it means that the // first sequence failed. We need to bail or else we might end up in // an infinite loop. if(mCtxt.dwLower||mCtxt.dwUpper){ LOG(("Cannotrestartauthenticationsequence!")); returnNS_ERROR_UNEXPECTED; } ctxIn=nullptr; // The certificate needs to be erased before being passed // to InitializeSecurityContextW(). inToken=nullptr; inTokenLen=0; }else{ ibd.ulVersion=SECBUFFER_VERSION; ibd.cBuffers=0; ibd.pBuffers=ib;
// If we have stored a certificate, the Channel Binding Token // needs to be generated and sent in the first input buffer. if(mCertDERLength>0){ // Default to SHA256 for compatibility, but detect SHA384 and SHA512 uint32_thashAlgorithm=nsICryptoHash::SHA256; uint32_thashSize=32;// SHA256 hash size
// Compute the hash size. [&](){ if(!mozilla::StaticPrefs::network_auth_sspi_detect_hash()){ // This check only exists to make sure that the hash algorithm check // doesn't break previous working behaviour. return; } usingnamespacemozilla::pkix; InputcertDER;
// Parse the signature algorithm from the signed data der::PublicKeyAlgorithmpublicKeyAlg; DigestAlgorithmdigestAlg; ReadersignatureAlgorithmReader(cert.GetSignedData().algorithm); pkixResult=der::SignatureAlgorithmIdentifierValue( signatureAlgorithmReader,publicKeyAlg,digestAlg);
if(pkixResult!=Success){ return; } // Map digest algorithms to hash algorithms for Extended Protection switch(digestAlg){ caseDigestAlgorithm::sha384: hashAlgorithm=nsICryptoHash::SHA384; hashSize=48;// SHA384 hash size break; caseDigestAlgorithm::sha512: hashAlgorithm=nsICryptoHash::SHA512; hashSize=64;// SHA512 hash size break; caseDigestAlgorithm::sha256: default: // Use SHA256 as default for compatibility hashAlgorithm=nsICryptoHash::SHA256; hashSize=32; break; } }();
// Then add it to the array of sec buffers accordingly. ib[ibd.cBuffers].BufferType=SECBUFFER_CHANNEL_BINDINGS; ib[ibd.cBuffers].cbBuffer=pendpoint_binding.cbApplicationDataLength+ pendpoint_binding.dwApplicationDataOffset;
// Store the computed hash in memory right after the Endpoint // structure and the "tls-server-end-point:" char array memcpy(sspi_cbt_ptr,hashString.get(),hashSize);
// Free memory used to store the server certificate free(mCertDERData); mCertDERData=nullptr; mCertDERLength=0; }// End of CBT computation.
// We always need this SECBUFFER. ib[ibd.cBuffers].BufferType=SECBUFFER_TOKEN; ib[ibd.cBuffers].cbBuffer=inTokenLen; ib[ibd.cBuffers].pvBuffer=(void*)inToken; ibd.cBuffers++; ctxIn=&mCtxt; } }else{// First time and without a token (no server certificate) // We are starting a new authentication sequence. If we have already // initialized our security context, then we're in trouble because it // means that the first sequence failed. We need to bail or else we // might end up in an infinite loop. if(mCtxt.dwLower||mCtxt.dwUpper||mCertDERData||mCertDERLength){ LOG(("Cannotrestartauthenticationsequence!")); returnNS_ERROR_UNEXPECTED; } ctxIn=nullptr; mIsFirst=false; }
// app data ib[1].BufferType=SECBUFFER_DATA; ib[1].cbBuffer=0; ib[1].pvBuffer=nullptr;
rc=(sspi->DecryptMessage)(&mCtxt,&ibd, 0,// no sequence numbers nullptr);
if(SEC_SUCCESS(rc)){ // check if ib[1].pvBuffer is really just ib[0].pvBuffer, in which // case we can let the caller free it. Otherwise, we need to // clone it, and free the original if(ib[0].pvBuffer==ib[1].pvBuffer){ *outToken=ib[1].pvBuffer; }else{ *outToken=moz_xmemdup(ib[1].pvBuffer,ib[1].cbBuffer); free(ib[0].pvBuffer); } *outTokenLen=ib[1].cbBuffer; }else free(ib[0].pvBuffer);
if(!SEC_SUCCESS(rc))returnNS_ERROR_FAILURE;
returnNS_OK; }
// utility class used to free memory on exit classsecBuffers{ public: SecBufferib[3];
¤ Die Informationen auf dieser Webseite wurden
nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit,
noch Qualität der bereit gestellten Informationen zugesichert.0.19Bemerkung:
(Wie Sie bei der Firma Beratungs- und Dienstleistungen beauftragen können 2026-08-25)
¤
Die Informationen auf dieser Webseite wurden
nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit,
noch Qualität der bereit gestellten Informationen zugesichert.
Bemerkung:
Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.