b6b438
From 34c4199f21f5d2dfbf3d732fd4da7be390ce095b Mon Sep 17 00:00:00 2001
b6b438
From: Andreas Schneider <asn@samba.org>
b6b438
Date: Wed, 31 Jul 2019 15:44:24 +0200
b6b438
Subject: [PATCH 074/187] libcli:auth: Use generate_secret_buffer() for
b6b438
 netlogon challenge
b6b438
b6b438
Signed-off-by: Andreas Schneider <asn@samba.org>
b6b438
Reviewed-by: Andrew Bartlett <abartlet@samba.org>
b6b438
b6b438
Autobuild-User(master): Andreas Schneider <asn@cryptomilk.org>
b6b438
Autobuild-Date(master): Mon Aug 12 10:42:35 UTC 2019 on sn-devel-184
b6b438
b6b438
(cherry picked from commit c3ba556f52b15dd80efc26e4fb8f43ce2ee3a7f0)
b6b438
---
b6b438
 libcli/auth/netlogon_creds_cli.c | 3 ++-
b6b438
 1 file changed, 2 insertions(+), 1 deletion(-)
b6b438
b6b438
diff --git a/libcli/auth/netlogon_creds_cli.c b/libcli/auth/netlogon_creds_cli.c
b6b438
index 50a5f50a57d..18143ca36d0 100644
b6b438
--- a/libcli/auth/netlogon_creds_cli.c
b6b438
+++ b/libcli/auth/netlogon_creds_cli.c
b6b438
@@ -1177,7 +1177,8 @@ static void netlogon_creds_cli_auth_challenge_start(struct tevent_req *req)
b6b438
 
b6b438
 	TALLOC_FREE(state->creds);
b6b438
 
b6b438
-	generate_random_buffer(state->client_challenge.data,
b6b438
+	/* We need to use a CSPRNG which reseeds for generating session keys. */
b6b438
+	generate_secret_buffer(state->client_challenge.data,
b6b438
 			       sizeof(state->client_challenge.data));
b6b438
 
b6b438
 	subreq = dcerpc_netr_ServerReqChallenge_send(state, state->ev,
b6b438
-- 
b6b438
2.23.0
b6b438