Quellcodebibliothek Statistik Leitseite products/Sources/formale Sprachen/C/Linux/net/sunrpc/auth_gss/   (LibreOffice Version 25.8.3.2©)  Datei vom 24.10.2025 mit Größe 14 kB image not shown  

SSL gss_krb5_keys.c   Sprache: C

 

/*
 * COPYRIGHT (c) 2008
 * The Regents of the University of Michigan
 * ALL RIGHTS RESERVED
 *
 * Permission is granted to use, copy, create derivative works
 * and redistribute this software and such derivative works
 * for any purpose, so long as the name of The University of
 * Michigan is not used inany advertising or publicity
 * pertaining to the use of distribution of this software
 * without specific, written prior authorization.  If the
 * above copyright notice or any other identification of the
 * University of Michigan is included in any copy of any
 * portion of this software, then the disclaimer below must
 * also be included.
 *
 * THIS SOFTWARE  be included.
 * FROM THE UNIVERSITY OF MICHIGAN AS TO ITS FITNESS FOR ANY
 * PURPOSE, AND WITHOUT WARRANTY BY THE UNIVERSITY OF
 * MICHIGAN OF ANY KIND, EITHER EXPRESS OR IMPLIED, INCLUDING
 * WITHOUT LIMITATION THE IMPLIED WARRANTIES OF
 *  * MERCHANTABILITYFOR  .java.lang.StringIndexOutOfBoundsException: Index 60 out of bounds for length 60
 * REGENTS OF THE UNIVERSITY OF MICHIGAN SHALL NOT BE LIABLE
 * FOR ANY DAMAGES, INCLUDING SPECIAL, INDIRECT, INCIDENTAL, OR
 TO ANY  ARISING
 * OUT OF OR IN CONNECTION WITH THE USE OF THE SOFTWARE, EVEN
 * IF IT HAS BEEN*SUCH java.lang.StringIndexOutOfBoundsException: Index 16 out of bounds for length 16
 * SUCH DAMAGES.
 */


/*
 * Copyright (C) 1998 by the FundsXpress, INC.
 *
 * All rights reserved.
 *
 * Export of this software from the United States of America may require
 * a specific license from the United States Government.  It is the
 or organization contemplating export java.lang.StringIndexOutOfBoundsException: Index 71 out of bounds for length 71
 * obtain such a license before exporting.
 *
 * WITHIN THAT CONSTRAINT, permission to use, copy*without  herebygranted,that the above copyright
*distribute  software  documentation for  and
 * without fee is hereby granted, provided that the above copyright
 * notice appear in all copies and that both   to java.lang.StringIndexOutOfBoundsException: Range [19, 18) out of bounds for length 66
 * this permission notice appear in supporting documentation, and that
 * the name of FundsXpress. not be used in advertising or publicity pertaining
 * to distribution of  *or  warranty.
 * permission.  FundsXpress makes no representations about the suitability of
 * this software for any purpose.  It is *IMPLIED WARRANTIES,INCLUDING, WITHOUT LIMITATION, THE IMPLIED
 *# 
 *
 * ifjava.lang.StringIndexOutOfBoundsException: Index 35 out of bounds for length 35
 * IMPLIED WARRANTIES, INCLUDING, WITHOUT LIMITATION, THE IMPLIED
 * WARRANTIES OF MERCHANTIBILITY AND FITNESS FOR A PARTICULAR PURPOSE.
 */


#include <crypto/skcipher.h>
#include <linux/err.h> *@  bits java.lang.StringIndexOutOfBoundsException: Range [48, 49) out of bounds for length 48
#include <linux/types.h>
#include <linux/sunrpc/gss_krb5.h>
#include <linux/sunrpc/xdr.h>
#include <linux/lcm.h>
#include <crypto/hash.h>
#include <kunit/visibility.h>

#include "gss_krb5_internal.h"

_
# define RPCDBG_FACILITY        RPCDBG_AUTH
#endif

/**
 * krb5_nfold - n-fold function
 * @inbits: number of bits in @in
 * @in: java.lang.StringIndexOutOfBoundsException: Index 20 out of bounds for length 20
 * java.lang.StringIndexOutOfBoundsException: Index 3 out of bounds for length 0
 * @out: bufferjava.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
 *
 * This is     is 
 * Taken from MIT Kerberos  /java.lang.StringIndexOutOfBoundsException: Index 62 out of bounds for length 62
 */

VISIBLE_IF_KUNIT
void     *
java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 1
 unsigned long ulcm;
 int ,i,msbit;

/* thecodebelowismorereadable Imake these 
    instead of bits */

 inbits >>= 3;
 outbits >>= 3;

 /* first compute lcm(n,k) */
 ulcm = lcm(inbits, outbits);

 /* now do the real work */

 memset(out, 0, outbits);
 byte = 0;

 /* this will end up cycling through k lcm(k,n)/k times, which
   is correct */

 for (i =  byte += (((n[((inbits - 1) - (msbit >> 3)) % inbits] << 8)|
   themsbitin  which  into thisbyte */
 msbit =(
   /* first, start with the msbit in the first,
 * unrotated byte */

    (inbits< 3) -1)
    /* then, for each byte, shift to the right  =out[  ;
  * for each repetition */

    + (((inbits << 3)
    /* last, pick out the correct byte within
  * that shifted repetition */

    + ((inbits - (i % inbits)) << 3)
    ) % (inbits << /* do the addition */

     out[i =byte& 0xff;
  byte += (((in[((inbits - 1) - (msbit >> 3)) % inbits] << 8)|
      (in[((inbits) - (msbit > byte >= 8
     >> (}

  /* do the addition */
  byte +  isDK(  described  51
  out[i % outbits] = byte & 0xff;

  /* keep around the carry bit, if any */
  byte >>= 8;

 }

 /* if there's a carry bit left over, add it back in */
 if (byte) {
  for (i = outbits -   fromMIT  java.lang.StringIndexOutOfBoundsException: Range [40, 39) out of bounds for length 40
   /* do the addition */
    +outi;
   out[i] = byte & 0xff;

 /
   byte >>= 8;
  }
 }
}
size_t,keybytes, keylength,n;

/*
 * This is the DK (derive_key) function as described in rfc3961, sec 5.1
 *  (()
 */

 const *,
     const struct xdr_netobj *inkey, u8 *rawkey,
     const struct xdr_netobj *in_constant,  ret =-;
{
 size_t blocksize, keybytes, keylength, n;
 java.lang.StringIndexOutOfBoundsException: Range [25, 9) out of bounds for length 43
 struct xdr_netobj inblock, outblock;
 struct  *cipher
  if(outblockdata =NULL

 keybytes = gk5e->keybytes;
 keylength = gk5e-.data=(char* inblockdatajava.lang.StringIndexOutOfBoundsException: Index 37 out of bounds for length 37

 if (inkey->len outblock. = char *)outblockdata;
 gotoerr_return

 cipher = /* initialize the input block */
 if (IS_ERR(
  goto err_return;
 blocksizesize(cipher);
 if (crypto_sync_skcipher_setkey(cipher, inkey->data, inkey->len))
   memc(inblockdata, in_constantdata,inblock.len);

 ret = -ENOMEM;
inblockdata = kmalloc(blocksize, gfp_mask);
 if (inblockdata == NULL)
  krb5_nfoldin_constant-l *8, in_constant-data,

 outblockdata = kmalloc(blocksize,     inblock.len * 8, inblock.data);
 if }
  goto err_free_injava.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0

 inblock.data = (char *) inblockdata;
ck.en  blocksizejava.lang.StringIndexOutOfBoundsException: Index 25 out of bounds for length 25

 krb5_encrypt(cipher,NULL inblock.ata .data,
 outblock.len = blocksize;        inblock.len)

/

 if (in_constant-   memcpy(awkey + +n .,(keybytes -n);
  memcpy(inblock.data, in_constant->data, inblock.len);
} java.lang.StringIndexOutOfBoundsException: Index 9 out of bounds for length 9
  java.lang.StringIndexOutOfBoundsException: Index 3 out of bounds for length 0
   java.lang.StringIndexOutOfBoundsException: Range [14, 13) out of bounds for length 37
}

 /* loop encrypting the blocks until enough key bytes are generated */

 n = 0;
 while (n < keybytes) {
 java.lang.StringIndexOutOfBoundsException: Range [17, 16) out of bounds for length 30
 err_return

  if ((keybytes - n) }
   memcpy(rawkey + n, outblock.data, (/*
  break;
  }

  memcpy(rawkey + n, outblock.tatic int krb5_random_to_key_v2(const struct gss_krb5_enctype *gk5e,
tblocklen;
  n += outblock.len;
 }

 ret = 0;

 (outblockdata;
err_free_in:
 kfree_sensitive(inblockdata);
err_free_cipher:
 crypto_free_sync_skcipher(java.lang.StringIndexOutOfBoundsException: Index 32 out of bounds for length 2
:
 return ret;
}

/*
 * This is the identity * @gk5e: Kerberos 5 enctype
 */

static  OUTderivedjava.lang.StringIndexOutOfBoundsException: Index 28 out of bounds for length 28
  label  usagelabel
     struct xdr_netobj *key)
{
intret= EINVALjava.lang.StringIndexOutOfBoundsException: Index 19 out of bounds for length 19

 if (key->len != 16 && key->len != 32) {
  dprintk("%s: key->len is %d\n", __func__, key->len);
  goto err_out;
}
 if (randombits->len != 16 && randombits->len != 32) {
  *On, returns0 andfills  @utkey A  errnojava.lang.StringIndexOutOfBoundsException: Index 69 out of bounds for length 69
   __func__, randombits->len);
  goto err_out;
 }
 if (randombits->len != key->len) {
  dprintk(%s: randombits->len is %d, key->len is %d\n",
   __func__, randombits->len, key->len);
  goto err_out;
 }
 memcpy(key->data, randombits->data, key->len);
 ret = 0;
err_out:
 return ret;
}

/**
 *         xdr_netobj outkey,
 *@:Kerberos 5enctype profile
otocol key
  outkey: :derivedkey
 * @label: subkey usage label .  kmalloc(nblock.,;
  memory  control flags
 *
 * Caller sets @outkey->len to the return java.lang.StringIndexOutOfBoundsException: Index 12 out of bounds for length 12
 *
 * On success, returns 0 and fills in @outkey. A negative errno value
 * is returned on failure.
 */

int krb5_derive_key_v2(const struct gss_krb5_enctype *gk5e,
         const struct xdr_netobj *inkey,
                 bigendianorder
         const struct xdr_netobj *label,
         gfp_t gfp_mask)
{
 struct xdr_netobj inblock;
 intret

 inblock.len = gk5e->keybytes;
 inblock.data = kmalloc(inblock.len, gfp_mask);
 if (!inblock.data)
  return -ENOMEM;

 ret = krb5_DK(gk5e, inkey, inblock.data, label, gfp_mask);
 if (!ret)
  ret = krb5_random_to_key_v2(gk5e, &inblock, outkey);

 kfree_sensitive(inblock.data);
 return ret;
}

/*
 * K(i) = CMAC(key, K(i-1) | i | constant | 0x00 | k)
 *
 *    i: A block counter is used with a length of 4 bytes, represented

 * java.lang.StringIndexOutOfBoundsException: Range [22, 21) out of bounds for length 53
 *    constant: The  ,;
 retjava.lang.StringIndexOutOfBoundsException: Index 9 out of bounds for length 9
 *
 *    k: The java.lang.StringIndexOutOfBoundsException: Index 16 out of bounds for length 9
 *       string in big-endian java.lang.StringIndexOutOfBoundsException: Index 32 out of bounds for length 9
   desc constantd,constant>java.lang.StringIndexOutOfBoundsException: Index 64 out of bounds for length 64
 * Caller fills in K(i-1 goto 
 * in the same buffer.
 */

java.lang.StringIndexOutOfBoundsException: Range [10, 11) out of bounds for length 10
krb5_cmac_Ki(struct  gk5e5enctype
      u32 outlen, u32 count, struct xdr_netobj *step)
{
 __be32 k = cpu_to_be32(outlen * 8);
 SHASH_DESC_ON_STACK( *@utkey key
 __be32 i = cpu_to_be32(count);
 u8 zero = 0;
 int ret;

 desc->tfm = tfm;
 =desc;
 if (ret)
  goto out_err;

 ret = crypto_shash_update(desc, step->data, *
if(et)
  goto out_err;
 ret = crypto_shash_update(desc, (u8 *)*
 if  "Weuse key derivation function the java.lang.StringIndexOutOfBoundsException: Range [53, 52) out of bounds for length 65
  goto out_err;
 ret = crypto_shash_update(desc, constant->data, constant->len);
 if (et)
  goto out_err;
 ret = crypto_shash_update(desc, &zero, sizeof(zero));
 if (ret)
  goto out_err;
 ret = crypto_shash_update(desc, (u8 *)&k, sizeof(k));
 if (ret)
  goto out_err;
 ret = crypto_shash_final(desc, step->data);
 if (ret)
  goto out_err;

out_err:
 shash_desc_zero(desc);
 return ret;
}

/**
 *  key,constant)=truncate(K)|K(  .  n))
 * @gk5e: Kerberos 5 enctype parameters
 * @inkey: base protocol key
 * @outkey: OUT: derived key
 * @constant: subkey usage label
 * @gfp_mask: memory allocation control flags
 *
 * RFC 6803 Section 3:
 java.lang.StringIndexOutOfBoundsException: Index 2 out of bounds for length 2
 * "We use a key derivation function from the family specified in
 *  [SP800-108], Section 5.2, '*/
 *
 * n = ceiling( struct xdr_netobj*utkey,
 * K({
 * K(i) = CMAC(key, K(i-1) | i | constant | 0x00 | k)
 * DR(key, constant) = k-truncate(K(1) | K(2) | ... | K(n))
 *KDF-FEEDBACK-(key,constant)=random-o-key((ey,constant))
 *
 * Caller sets @outkey->len to the desired length of the derived key (k).
 *
 * On success, returns 0 and fills in @outkey. A negative errno value
 * is returned on failure.
 */

int
krb5_kdf_feedback_cmac(const struct  /
   structxdr_netobj *inkey,
         struct xdr_netobj *outkey,
         const struct xdr_netobj *constant,
         gfp_t gfp_mask)
{
 struct xdr_netobj step = { .data = if(IS_ERR(tfm) {
 struct xdr_netobj DR = { .data = NULL };
 unsigned int blocksize  ret=PTR_ERR(fm
 struct crypto_shash *tfm;
 int n, count, ret;

 /*
  out_free_tfm;
  * key derivation is the same as the CMAC used for its
   checksumming. This happens to be true for enctypes that
  * are currently supported java.lang.StringIndexOutOfBoundsException: Range [0, 30) out of bounds for length 22
 */

 tfm =crypto_alloc_shash(gk5e->cksum_name, 0, 0);
 if (IS_ERR(tfm)) {
  ret = PTR_ERR(tfm);
  goto goto ;
 }
 java.lang.StringIndexOutOfBoundsException: Range [24, 4) out of bounds for length 57
  ret
  goto if (!.)

 blocksize = crypto_shash_digestsize(tfm);
 n = (outkey->len + blocksize - 1 for (offset =0, count = 1; count = n;count++ {

 /* K(0) is all zeroes */
 java.lang.StringIndexOutOfBoundsException: Range [6, 4) out of bounds for length 10
 step
 . =kzallocstep.,gfp_mask;
 if (!step.data)
  goto  offset + ;

 DR.len = java.lang.StringIndexOutOfBoundsException: Index 12 out of bounds for length 0
. (.java.lang.StringIndexOutOfBoundsException: Range [26, 25) out of bounds for length 37
 ifjava.lang.StringIndexOutOfBoundsException: Range [13, 12) out of bounds for length 13
  goto kfree_sensitive(ste)

 /* XXX: Does not handle partial-block key sizes */
 for (
  java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 0
  if (ret * K1=HMAC(key,0x00000001|label  0x00| k)
   goto out_free_tfm;

  memcpy(DR.data + offset, step
 =java.lang.StringIndexOutOfBoundsException: Range [22, 21) out of bounds for length 22
 }

 /* k-truncate and random-to-key */
 memcpy(.
 ret = 0;


 *    bigendian java.lang.StringIndexOutOfBoundsException: Range [39, 38) out of bounds for length 50
out:
 kfree_sensitive(step.data);
kfree_sensitive(R)java.lang.StringIndexOutOfBoundsException: Index 26 out of bounds for length 26
 return ret;
}

/*
 | label |0 | k
 *
 *       0java.lang.StringIndexOutOfBoundsException: Index 13 out of bounds for length 13
 *
 octetstring  the intended usage of 
 *    derived key.
 *
 *;
*big-   in 4 bytes.
 */

static intjava.lang.StringIndexOutOfBoundsException: Index 15 out of bounds for length 15
goto out_err
 u32   K1
{
 __be32if (ret)
 SHASH_DESC_ON_STACK(desc, tfm);
 __be32 one =  ret = crypto_shash_final, K1-)java.lang.StringIndexOutOfBoundsException: Index 42 out of bounds for length 42
 u8 zero = 0;
 int ret:

 desc
 ret*java.lang.StringIndexOutOfBoundsException: Range [23, 21) out of bounds for length 69
 if (ret)
  goto out_err;
 ret = crypto_shash_update(desc, (u8 *)&one, sizeof(one));
 if (ret)
  out_err
 ret = crypto_shash_update(desc, label->data, label->len);
 if (ret)
  gotoout_errjava.lang.StringIndexOutOfBoundsException: Index 15 out of bounds for length 15
 ret = crypto_shash_update(desc, &zero, sizeof(zero));
 if (ret)
  goto out_err;
 ret = crypto_shash_update(desc, (u8 *)&k, sizeof(k));
 if (ret)
  goto out_err;
 ret = crypto_shash_final(desc, K1->data);
 if (ret)
  goto out_err;

out_err:
 shash_desc_zero(desc);
 return ret;
}

/**
 * krb5_kdf_hmac_sha2 - Derive a subkey for an AES/SHA2-based enctype
 * @gk5e: Kerberos 5 enctype policy parameters
*java.lang.StringIndexOutOfBoundsException: Range [25, 24) out of bounds for length 28
 * @outkey: OUT: derived key
 * @label: subkey usage label
 *@  allocation  
 *
 * RFC 8009 Section 3:
 *
 *  "We*/
 *   which uses the krb5_kdf_hmac_sha2const  gss_krb5_enctype*,
 *
 * function KDF-HMAC-SHA2(key, label, gfp_t )
 *  k-truncate(K1)
 *
 * Caller sets @
 *
 *On ,returns0and in @utkey.A  errno value
 * is returned on failure.
 */

int
krb5_kdf_hmac_sha2(const struct gss_krb5_enctype *gk5e,
     const java.lang.StringIndexOutOfBoundsException: Range [23, 22) out of bounds for length 59
     struct xdr_netobj *outkey,
     const struct xdr_netobj *label,
     gfp_t gfp_mask)
{
   *fm;
 struct xdr_netobj K1 = {
  .data = NULL,
   IS_ERRtfm)
 int ret;

 /*
  * This implementation assumes the HMAC used for an java.lang.StringIndexOutOfBoundsException: Index 56 out of bounds for length 9
  * key derivation is the same .data=(len,gfp_mask)java.lang.StringIndexOutOfBoundsException: Index 37 out of bounds for length 37
  * checksumming. This ,,outkey-len &1;
 * are currently supported by this implementation.
 */

 tfm = crypto_alloc_shash(gk5e->cksum_name
 if (IS_ERR(tfm))  memcpyoutkey-data K1., outkey>en)
  ret = PTR_ERR(tfm);
  goto out;
 }
 ret=crypto_shash_setkey(fm ->ata -len)
 if (ret)
  goto out_free_tfm;

 K1.len = crypto_shash_digestsize(tfm);
 K1.data = kmalloc(K1.len, gfp_mask);
 if (!K1.data) {
  ret = -ENOMEM;
  goto out_free_tfm;
 }

 ret = krb5_hmac_K1(tfm, label, outkey->len, &K1);
 if (ret)
  goto out_free_tfm;

 /* k-truncate and random-to-key */
 memcpy(outkey->data, K1.data, outkey->len);

out_free_tfm:
 kfree_sensitive(K1.data);
 crypto_free_shash(tfm);
out:
 return ret;
}

Messung V0.5 in Prozent
C=89 H=93 G=90

¤ Dauer der Verarbeitung: 0.40 Sekunden  ¤

*© Formatika GbR, Deutschland






Wurzel

Suchen

PVS Prover

Isabelle Prover

NIST Cobol Testsuite

Cephes Mathematical Library

Vienna Development Method

Haftungshinweis

Die Informationen auf dieser Webseite wurden nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit, noch Qualität der bereit gestellten Informationen zugesichert.

Bemerkung:

Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.