summaryrefslogtreecommitdiff
path: root/pppd/chap-md5.c
blob: 0b76d9a79c8961380abfb257e9ee30581afa5305 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
/*
 * chap-md5.c - New CHAP/MD5 implementation.
 *
 * Copyright (c) 2003 Paul Mackerras. All rights reserved.
 *
 * Redistribution and use in source and binary forms, with or without
 * modification, are permitted provided that the following conditions
 * are met:
 *
 * 1. Redistributions of source code must retain the above copyright
 *    notice, this list of conditions and the following disclaimer.
 *
 * 2. The name(s) of the authors of this software must not be used to
 *    endorse or promote products derived from this software without
 *    prior written permission.
 *
 * 3. Redistributions of any form whatsoever must retain the following
 *    acknowledgment:
 *    "This product includes software developed by Paul Mackerras
 *     <paulus@samba.org>".
 *
 * THE AUTHORS OF THIS SOFTWARE DISCLAIM ALL WARRANTIES WITH REGARD TO
 * THIS SOFTWARE, INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
 * AND FITNESS, IN NO EVENT SHALL THE AUTHORS BE LIABLE FOR ANY
 * SPECIAL, INDIRECT OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
 * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN
 * AN ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING
 * OUT OF OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
 */

#define RCSID	"$Id: chap-md5.c,v 1.4 2004/11/09 22:39:25 paulus Exp $"

#ifdef HAVE_CONFIG_H
#include "config.h"
#endif

#include <stdlib.h>
#include <string.h>
#include "pppd-private.h"
#include "chap.h"
#include "chap-md5.h"
#include "magic.h"
#include "crypto.h"

#define MD5_MIN_CHALLENGE	16
#define MD5_MAX_CHALLENGE	24

static void
chap_md5_generate_challenge(unsigned char *cp)
{
	int clen;

	clen = (int)(drand48() * (MD5_MAX_CHALLENGE - MD5_MIN_CHALLENGE))
		+ MD5_MIN_CHALLENGE;
	*cp++ = clen;
	random_bytes(cp, clen);
}

static int
chap_md5_verify_response(int id, char *name,
			 unsigned char *secret, int secret_len,
			 unsigned char *challenge, unsigned char *response,
			 char *message, int message_space)
{
	unsigned char idbyte = id;
	unsigned char hash[MD5_DIGEST_LENGTH];
	unsigned int  hash_len = MD5_DIGEST_LENGTH;
	int challenge_len, response_len;
	bool success = 0;

	challenge_len = *challenge++;
	response_len = *response++;
	if (response_len == MD5_DIGEST_LENGTH) {

		/* Generate hash of ID, secret, challenge */
		PPP_MD_CTX* ctx = PPP_MD_CTX_new();
		if (ctx) {

			if (PPP_DigestInit(ctx, PPP_md5())) {

				if (PPP_DigestUpdate(ctx, &idbyte, 1)) {

					if (PPP_DigestUpdate(ctx, secret, secret_len)) {

						if (PPP_DigestUpdate(ctx, challenge, challenge_len)) {

							if (PPP_DigestFinal(ctx, hash, &hash_len)) {

								success = 1;
							}
						}
					}
				}
			}
			PPP_MD_CTX_free(ctx);
		}
	}
	if (success && memcmp(hash, response, hash_len) == 0) {
		slprintf(message, message_space, "Access granted");
		return 1;
	}
	slprintf(message, message_space, "Access denied");
	return 0;
}

static void
chap_md5_make_response(unsigned char *response, int id, char *our_name,
		       unsigned char *challenge, char *secret, int secret_len,
		       unsigned char *private)
{
	unsigned char idbyte = id;
	int challenge_len = *challenge++;
	int hash_len = MD5_DIGEST_LENGTH;

	PPP_MD_CTX* ctx = PPP_MD_CTX_new();
	if (ctx) {

		if (PPP_DigestInit(ctx, PPP_md5())) {

			if (PPP_DigestUpdate(ctx, &idbyte, 1)) {

				if (PPP_DigestUpdate(ctx, secret, secret_len)) {

					if (PPP_DigestUpdate(ctx, challenge, challenge_len)) {

						if (PPP_DigestFinal(ctx, &response[1], &hash_len)) {

							response[0] = hash_len;
						}
					}
				}
			}
		}
		PPP_MD_CTX_free(ctx);
	}
}

static struct chap_digest_type md5_digest = {
	CHAP_MD5,		/* code */
	chap_md5_generate_challenge,
	chap_md5_verify_response,
	chap_md5_make_response,
	NULL,			/* check_success */
	NULL,			/* handle_failure */
};

void
chap_md5_init(void)
{
	chap_register_digest(&md5_digest);
}