d738b9
From c931cdfaa3539e42cfc57caca6b67fe9a03227e2 Mon Sep 17 00:00:00 2001
d738b9
From: Greg Hudson <ghudson@mit.edu>
d738b9
Date: Tue, 10 Jul 2018 16:17:15 -0400
d738b9
Subject: [PATCH] Use SHA-256 instead of MD5 for audit ticket IDs
d738b9
d738b9
ticket: 8711 (new)
d738b9
(cherry picked from commit c1e1bfa26bd2f045e88e6013c500fca9428c98f3)
d738b9
---
d738b9
 src/kdc/kdc_audit.c | 21 ++++++++++-----------
d738b9
 1 file changed, 10 insertions(+), 11 deletions(-)
d738b9
d738b9
diff --git a/src/kdc/kdc_audit.c b/src/kdc/kdc_audit.c
d738b9
index c9a7f9f9d..f40913dc8 100644
d738b9
--- a/src/kdc/kdc_audit.c
d738b9
+++ b/src/kdc/kdc_audit.c
d738b9
@@ -146,7 +146,7 @@ kau_make_tkt_id(krb5_context context,
d738b9
 {
d738b9
     krb5_error_code ret = 0;
d738b9
     char *hash = NULL, *ptr;
d738b9
-    krb5_checksum cksum;
d738b9
+    uint8_t hashbytes[K5_SHA256_HASHLEN];
d738b9
     unsigned int i;
d738b9
 
d738b9
     *out = NULL;
d738b9
@@ -154,19 +154,18 @@ kau_make_tkt_id(krb5_context context,
d738b9
     if (ticket == NULL)
d738b9
         return EINVAL;
d738b9
 
d738b9
-    ret = krb5_c_make_checksum(context, CKSUMTYPE_RSA_MD5, NULL, 0,
d738b9
-                               &ticket->enc_part.ciphertext, &cksum);
d738b9
+    ret = k5_sha256(&ticket->enc_part.ciphertext, 1, hashbytes);
d738b9
     if (ret)
d738b9
         return ret;
d738b9
 
d738b9
-    hash = k5alloc(cksum.length * 2 + 1, &ret;;
d738b9
-    if (hash != NULL) {
d738b9
-        for (i = 0, ptr = hash; i < cksum.length; i++, ptr += 2)
d738b9
-            snprintf(ptr, 3, "%02X", cksum.contents[i]);
d738b9
-        *ptr = '\0';
d738b9
-        *out = hash;
d738b9
-    }
d738b9
-    krb5_free_checksum_contents(context, &cksum);
d738b9
+    hash = k5alloc(sizeof(hashbytes) * 2 + 1, &ret;;
d738b9
+    if (hash == NULL)
d738b9
+        return ret;
d738b9
+
d738b9
+    for (i = 0, ptr = hash; i < sizeof(hashbytes); i++, ptr += 2)
d738b9
+        snprintf(ptr, 3, "%02X", hashbytes[i]);
d738b9
+    *ptr = '\0';
d738b9
+    *out = hash;
d738b9
 
d738b9
     return 0;
d738b9
 }