2 * Copyright (c) 1995, 1996, 1997 Kungliga Tekniska Högskolan
3 * (Royal Institute of Technology, Stockholm, Sweden).
6 * Redistribution and use in source and binary forms, with or without
7 * modification, are permitted provided that the following conditions
10 * 1. Redistributions of source code must retain the above copyright
11 * notice, this list of conditions and the following disclaimer.
13 * 2. Redistributions in binary form must reproduce the above copyright
14 * notice, this list of conditions and the following disclaimer in the
15 * documentation and/or other materials provided with the distribution.
17 * 3. Neither the name of the Institute nor the names of its contributors
18 * may be used to endorse or promote products derived from this software
19 * without specific prior written permission.
21 * THIS SOFTWARE IS PROVIDED BY THE INSTITUTE AND CONTRIBUTORS ``AS IS'' AND
22 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
23 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
24 * ARE DISCLAIMED. IN NO EVENT SHALL THE INSTITUTE OR CONTRIBUTORS BE LIABLE
25 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
26 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
27 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
28 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
29 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
30 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
33 /* $FreeBSD: src/crypto/kerberosIV/lib/krb/rd_priv.c,v 1.1.1.3.2.1 2003/02/13 21:34:36 nectar Exp $ */
34 /* $DragonFly: src/crypto/kerberosIV/lib/krb/Attic/rd_priv.c,v 1.2 2003/06/17 04:24:36 dillon Exp $ */
38 RCSID("$Id: rd_priv.c,v 1.27 1999/12/02 16:58:43 joda Exp $");
40 /* application include files */
41 #include "krb-archaeology.h"
44 * krb_rd_priv() decrypts and checks the integrity of an
45 * AUTH_MSG_PRIVATE message. Given the message received, "in",
46 * the length of that message, "in_length", the key "schedule"
47 * and "key", and the network addresses of the
48 * "sender" and "receiver" of the message, krb_rd_safe() returns
49 * RD_AP_OK if the message is okay, otherwise some error code.
51 * The message data retrieved from "in" are returned in the structure
52 * "m_data". The pointer to the application data
53 * (m_data->app_data) refers back to the appropriate place in "in".
55 * See the file "mk_priv.c" for the format of the AUTH_MSG_PRIVATE
56 * message. The structure containing the extracted message
57 * information, MSG_DAT, is defined in "krb.h".
61 krb_rd_priv(void *in, u_int32_t in_length,
62 des_key_schedule schedule, des_cblock *key,
63 struct sockaddr_in *sender, struct sockaddr_in *receiver,
66 unsigned char *p = (unsigned char*)in;
73 unsigned char pvno, type;
76 if(pvno != KRB_PROT_VERSION)
80 little_endian = type & 1;
83 p += krb_get_int(p, &clen, 4, little_endian);
85 if(clen + 2 > in_length)
86 return RD_AP_MODIFIED;
88 des_pcbc_encrypt((des_cblock*)p, (des_cblock*)p, clen,
89 schedule, key, DES_DECRYPT);
91 p += krb_get_int(p, &m_data->app_length, 4, little_endian);
92 if(m_data->app_length + 17 > in_length)
93 return RD_AP_MODIFIED;
96 p += m_data->app_length;
98 m_data->time_5ms = *p++;
100 p += krb_get_address(p, &src_addr);
102 if (!krb_equiv(src_addr, sender->sin_addr.s_addr))
105 p += krb_get_int(p, (u_int32_t *)&m_data->time_sec, 4, little_endian);
107 m_data->time_sec = lsb_time(m_data->time_sec, sender, receiver);
109 gettimeofday(&tv, NULL);
111 /* check the time integrity of the msg */
112 delta_t = abs((int)((long) tv.tv_sec - m_data->time_sec));
113 if (delta_t > CLOCK_SKEW)
116 krb_warning("delta_t = %d\n", (int) delta_t);
119 * caller must check timestamps for proper order and
120 * replays, since server might have multiple clients
121 * each with its own timestamps and we don't assume
122 * tightly synchronized clocks.