RE: server secret

"Brian K. Jones" <[email protected]>
Newsgroups gmane.network.up2date.current.devel
Message-ID <1034275807.15886.58.camel@newhotness>
ACK!

This was in response to an email originally sent by me, but it was just
before I officially (re)joined the list.

Thanks for the pointer.

On Thu, 2002-10-10 at 14:34, Bingner Sam J Contractor CAF CSS/SCHE
wrote:
> er, THIS email, sorry
> 
> Sam
> 
> -----Original Message-----
> From: Hunter Matthews [mailto:[email protected]]
> Sent: Tuesday, October 08, 2002 7:00 AM
> To: Current Server Mailing List
> Subject: Re: [Current-server] what exactly is the server secret *for*
> 
> 
> On Tue, 2002-10-08 at 08:55, Brian K. Jones wrote:
> > Hello.
> > 
> > It would seem logical that the server secret be used for client access
> > to the server resources.  However, in practice, this doesn't seem to be
> > happening.  
> > 
> > The comments in current.conf say:
> > # server_secret = text to get sha1'd for systemid tokens.
> > #                 Must be kept secret, and site specific.
> > 
> > First of all, what the h*** does that word "sha1'd" mean?  Can you dumb
> > that down for me?  Is that a star trek reference or something that I'm
> > just not geeky enough to get or something? :-)
> 
> SHA-1 is the Secure Hashing Algorithm, version 1. It is a NIST (US govt
> standards agency) standard for securely hashing something. It is the
> official replacement for md5.
> 
> > 
> > Second, if this is to be kept secret, why is it essentially in plain
> > view of everything?  What is at risk by keeping this 'not secret'?  Even
> > if someone knows the server secret, they still need the server's
> > RHNS-CA-CERT, no?  Maybe I'm a little confused here.  Did I miss a doc? 
> 
> Its in plain text because I didn't have any other place to put it. Your
> /etc/current.conf file has to be readable by apache, but not by anyone
> else. (generally, I assume that current servers are _servers_, IE there
> are no users logging in).
> 
> By not keeping it secret, it is theoretically possible for someone to
> spoof being a valid client when they are not. Since current only runs in
> anonymous mode right now, this is not a major threat. In the future, it
> will become more of a concern, but by then the secret will not be stored
> in plain text in a config file.
> 
> Its not in any docs, as I really didn't see the need for a great deal of
> doc about a "feature" we don't take advantage of right now.
> 
> HOWEVER, the server secret IS used, in the auth module. Scan auth.py for
> how.
> 
> > 
> > Third, is this secret somehow used in creating the RHNS-CA-CERT?  I
> > can't think of another reason you'd have to re-register clients after
> > changing the secret.  
> 
> No. The server secret is used when generating the system id's for the
> clients. (See /etc/sysconfig/rhn/sysid.)
> 
> Basically, you concatenate all the fields that matter, concatenate the
> server secret, and run the SHA-1 algorithm over it. If some nefarious
> user changes an important field, the checksum on the server will no
> longer match, and the client requests will be rejected. The server
> secret also keeps this ner-do-well from also trying to get smart and
> change the checksum - since they don't have the server secret, they'll
> never be able to generate the same checksum that the server would have.
> 
> 
> > 
> > Also, while we're on registration, I don't remember ever seeing a place
> > that kept track of who has registered with the server.  Is this logged
> > somewhere along with the activity (what packages were grabbed, and the
> > like)?  
> 
> Nope. As specified above, current is completely anonymous at the moment.
> John and I are both working on an SQL backend right now.
> 
> > 
> > Thanks.
> > 
> > -- 
> > 
> > Brian K. Jones
> > System Administrator
> > Dept. of Computer Science, Princeton University
> > http://www.linuxlaboratory.org
> > [email protected]
> > Voice: (609) 258-6080
> > 
> > _______________________________________________
> > Current-server mailing list
> > [email protected]
> > http://lists.dulug.duke.edu/mailman/listinfo/current-server
> > 
> > 
> -- 
> Hunter Matthews                          Unix / Network Administrator
> Office: BioScience 145/244               Duke Univ. Biology Department
> Key: F0F88438 / FFB5 34C0 B350 99A4 BB02  9779 A5DB 8B09 F0F8 8438
> Never take candy from strangers. Especially on the internet.
> 
> _______________________________________________
> Current-server mailing list
> [email protected]
> http://lists.dulug.duke.edu/mailman/listinfo/current-server
> _______________________________________________
> Current-server mailing list
> [email protected]
> http://lists.dulug.duke.edu/mailman/listinfo/current-server
-- 

Brian K. Jones
System Administrator
Dept. of Computer Science, Princeton University
http://www.linuxlaboratory.org
[email protected]
Voice: (609) 258-6080
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.