gss-api: tag RFC 2478 NegTokenInit fields explicitly - #2464
Open
yuxi-liu-wired wants to merge 1 commit into
Open
yuxi-liu-wired wants to merge 1 commit into
yuxi-liu-wired wants to merge 1 commit into
Conversation
With the rfc2478 feature, NegTokenInit declared its four fields tag_mode = "IMPLICIT". The SPNEGO ASN.1 module is DEFINITIONS EXPLICIT TAGS (RFC 4178 Appendix A and section 4.1; RFC 2478 uses the same encoding), and every other context-tagged field in this crate, including NegTokenTarg's and NegTokenInit2's, is EXPLICIT. So NegTokenInit could not decode real tokens: the NTLM NegTokenInit from this crate's own InitialContextToken test fails with "expected OBJECT IDENTIFIER, got SEQUENCE", and encoding produced bytes no other SPNEGO implementation reads (pyasn1 with the RFC definition rejects them). Use EXPLICIT tagging, like the rest of the module.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
With the
rfc2478feature,NegTokenInitdeclares its four fieldstag_mode = "IMPLICIT". The SPNEGO ASN.1 module isDEFINITIONS EXPLICIT TAGS(RFC 4178 Appendix A and section 4.1; RFC 2478 uses the same encoding), and every other context-tagged field in this crate isEXPLICIT, includingNegTokenTarg's (the other half of therfc2478CHOICE) andNegTokenInit2's. As a result,NegTokenInitcan't decode real tokens:The reverse also holds: the only encoding it accepts, and the one it produces, puts the
[0]tag in place of theSEQUENCE OFtag (300e a00c 060a…). pyasn1 with the RFC definition rejects that, and decodes the real token above fine.The fix changes the four
tag_modes toEXPLICIT. The default (non-rfc2478) types are untouched.Test:
decode_rfc2478_neg_token_initdecodes the NTLM token above, checksmech_typesand theNTLMSSPmech token, and re-encodes it byte for byte. It fails on master. Thegss-api.ymlmatrix passed locally: powerset tests on stable and 1.85, thumbv7em/wasm32 powerset build, fmt, clippy.This PR was produced by AI agents (Claude) and reviewed by me before submission.