Re: NegoEx broke GSSAPI in BIND 9

Ondřej Surý <[email protected]>
Newsgroups gmane.comp.encryption.kerberos.devel
Message-ID <[email protected]>
Ok, so I do have more information, the gss_accept_sec_context() now returns in minor:

> 20-May-2020 12:02:03.077 failed gss_accept_sec_context: GSSAPI error: Major = Unspecified GSS failure.  Minor code may provide more information, Minor = SPNEGO cannot find mechanisms to negotiate.

also I see:

> 20-May-2020 13:06:31.121 failed gss_inquire_cred: GSSAPI error: Major = Unspecified GSS failure.  Minor code may provide more information, Minor = No Kerberos credentials available (default cache: FILE:/tmp/krb5cc_0).

But that’s error I am also seeing on the branch that work for us.

Ondrej
--
Ondřej Surý
[email protected]

> On 20 May 2020, at 11:34, Ondřej Surý <[email protected]> wrote:
> 
> Hi,
> 
> there’s a regression in krb5 1.18.x that broke SPNEGO usage in BIND 9.
> 
> There’s a little bit of history there - historically BIND 9 used internal implementation
> of SPNEGO and that still works.  But in the development version, I did drop the
> internal implementation in favor of using KRB5 SPNEGO mechanism implementation.
> 
> We don’t do anything fancy, the code is basically:
> 
> #ifndef GSS_KRB5_MECHANISM
> static unsigned char krb5_mech_oid_bytes[] = { 0x2a, 0x86, 0x48, 0x86, 0xf7,
>                                              0x12, 0x01, 0x02, 0x02 };
> static gss_OID_desc __gss_krb5_mechanism_oid_desc = {
>       sizeof(krb5_mech_oid_bytes), krb5_mech_oid_bytes
> };
> #define GSS_KRB5_MECHANISM (&__gss_krb5_mechanism_oid_desc)
> #endif /* ifndef GSS_KRB5_MECHANISM */
> 
> #ifndef GSS_SPNEGO_MECHANISM
> static unsigned char spnego_mech_oid_bytes[] = { 0x2b, 0x06, 0x01,
>                                                0x05, 0x05, 0x02 };
> static gss_OID_desc __gss_spnego_mechanism_oid_desc = {
>       sizeof(spnego_mech_oid_bytes), spnego_mech_oid_bytes
> };
> #define GSS_SPNEGO_MECHANISM (&__gss_spnego_mechanism_oid_desc)
> #endif /* ifndef GSS_SPNEGO_MECHANISM */
> 
> […]
> 
> static OM_uint32
> mech_oid_set_create(OM_uint32 *minor, gss_OID_set *mech_oid_set) {
>       OM_uint32 gret;
> 
>       gret = gss_create_empty_oid_set(minor, mech_oid_set);
>       if (gret != GSS_S_COMPLETE) {
>               return (gret);
>       }
> 
>       gret = gss_add_oid_set_member(minor, GSS_KRB5_MECHANISM, mech_oid_set);
>       if (gret != GSS_S_COMPLETE) {
>               goto release;
>       }
> 
>       gret = gss_add_oid_set_member(minor, GSS_SPNEGO_MECHANISM,
>                                     mech_oid_set);
>       if (gret != GSS_S_COMPLETE) {
>               goto release;
>       }
> 
> release:
>       REQUIRE(gss_release_oid_set(minor, mech_oid_set) == GSS_S_COMPLETE);
> 
>       return (gret);
> }
> 
> static void
> mech_oid_set_release(gss_OID_set *mech_oid_set) {
>       OM_uint32 minor;
> 
>       REQUIRE(gss_release_oid_set(&minor, mech_oid_set) == GSS_S_COMPLETE);
> }
> 
> and then it’s used like this:
> 
>       gss_OID_set mech_oid_set;
> 
> […]
> 
>       gret = mech_oid_set_create(&minor, &mech_oid_set);
>       if (gret != GSS_S_COMPLETE) {
>               gss_log(3, "failed to create OID_set: %s",
>                       gss_error_tostring(gret, minor, buf, sizeof(buf)));
>               return (ISC_R_FAILURE);
>       }
> 
>       gret = gss_acquire_cred(&minor, gname, GSS_C_INDEFINITE, mech_oid_set,
>                               usage, cred, NULL, &lifetime);
> 
> 
> Unfortunately, this stopped working since 1.18.1, but perhaps we were doing something
> wrong from the beginning. Honestly, looking at the GSSAPI is like reading tea leaves :-),
> so I would appreciate if I can get some pointers where to start with the debugging.
> 
> The code is working in 1.17.1 and it’s neither working in 1.18.1 nor master branch (I saw
> some fixes in there, so I tried).
> 
> Thanks,
> Ondrej
> --
> Ondřej Surý
> [email protected]
>

_______________________________________________
krbdev mailing list             [email protected]
https://mailman.mit.edu/mailman/listinfo/krbdev
signature.asc (application/pgp-signature, 963 B)
-----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEEw2Gx4wKVQ+vGJel9g3Kkd++uWcIFAl7FK69fFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEMz
NjFCMUUzMDI5NTQzRUJDNjI1RTk3RDgzNzJBNDc3RUZBRTU5QzIACgkQg3Kkd++u
WcLCAg/+P6MUISIAJZDibxEArAiC97ZDR4QXIv+6oaAowPugG3kv2xvm0axgcBOH
6IW6S4CrO8IZRjNmDr669RLsa2Yw3x3QZoe212M3bb/lNrrzZ9h1ElsXcLybpiMi
402Lxa+aKqMvboTyVCxrRr0/wGrOdqBx53qkrI2bFTOSwBFqKGFlW/bC2VeuMYpE
UcQEs1S9+2c+/KsLRLiGyrrmnnt6FASlHYhu3miDXpR0b4c+/aVarFti9uk4YLNM
mnT5XYyVm28UENSIFrkQrt7gUWWEYiQ0x9Z/0dryBX2nKRWn2G3MMPfZAtkdRz90
DsXeYypovjFhE+JbmXWIW0IcnIzVeuPpvnTyMdDfHGAyNh2GicKKUcjVAkyECJRx
K4BknjSUQEQ03z54N6O7sZKxM2GI8UPd39HG0wYfecIRHaMKvhtEihenbP7i+WdE
c8wvbIMdosLusgADglmUlo3mDo3/tQ/a/QiWNUdz7bWVncISsqhFgk3rduRI8Y5K
DE8t6/JjGbGl2F86A7FQfgeRXFPCCNh6bgku2XbvQtVe+8YI7HLEIvwKM4KsPcmF
nlLxKBm9v+eYx8tsqLic00Pr62bj6r4Ic6B+G0TJtfCgyj1jvReQYbI5H2RuozWR
zi04v7o15vGXVtQgR/4//AAXEPdkNFe2+C3Gy+MfTckAuioKc/I=
=K+uu
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.