| Steve French | 790fe57 | 2007-07-07 19:25:05 +0000 | [diff] [blame] | 1 | /* | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 2 |    Unix SMB/Netbios implementation. | 
 | 3 |    Version 1.9. | 
 | 4 |    SMB parameters and setup | 
 | 5 |    Copyright (C) Andrew Tridgell 1992-2000 | 
 | 6 |    Copyright (C) Luke Kenneth Casson Leighton 1996-2000 | 
 | 7 |    Modified by Jeremy Allison 1995. | 
 | 8 |    Copyright (C) Andrew Bartlett <abartlet@samba.org> 2002-2003 | 
 | 9 |    Modified by Steve French (sfrench@us.ibm.com) 2002-2003 | 
| Steve French | 50c2f75 | 2007-07-13 00:33:32 +0000 | [diff] [blame] | 10 |  | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 11 |    This program is free software; you can redistribute it and/or modify | 
 | 12 |    it under the terms of the GNU General Public License as published by | 
 | 13 |    the Free Software Foundation; either version 2 of the License, or | 
 | 14 |    (at your option) any later version. | 
| Steve French | 50c2f75 | 2007-07-13 00:33:32 +0000 | [diff] [blame] | 15 |  | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 16 |    This program is distributed in the hope that it will be useful, | 
 | 17 |    but WITHOUT ANY WARRANTY; without even the implied warranty of | 
 | 18 |    MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the | 
 | 19 |    GNU General Public License for more details. | 
| Steve French | 50c2f75 | 2007-07-13 00:33:32 +0000 | [diff] [blame] | 20 |  | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 21 |    You should have received a copy of the GNU General Public License | 
 | 22 |    along with this program; if not, write to the Free Software | 
 | 23 |    Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA. | 
 | 24 | */ | 
 | 25 |  | 
 | 26 | #include <linux/module.h> | 
| Tejun Heo | 5a0e3ad | 2010-03-24 17:04:11 +0900 | [diff] [blame] | 27 | #include <linux/slab.h> | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 28 | #include <linux/fs.h> | 
 | 29 | #include <linux/string.h> | 
 | 30 | #include <linux/kernel.h> | 
 | 31 | #include <linux/random.h> | 
 | 32 | #include "cifs_unicode.h" | 
 | 33 | #include "cifspdu.h" | 
| Steve French | 3979877 | 2006-05-31 22:40:51 +0000 | [diff] [blame] | 34 | #include "cifsglob.h" | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 35 | #include "cifs_debug.h" | 
| Shirish Pargaonkar | ee2c925 | 2011-01-27 09:58:04 -0600 | [diff] [blame] | 36 | #include "cifsproto.h" | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 37 |  | 
| Steve French | 4b18f2a | 2008-04-29 00:06:05 +0000 | [diff] [blame] | 38 | #ifndef false | 
 | 39 | #define false 0 | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 40 | #endif | 
| Steve French | 4b18f2a | 2008-04-29 00:06:05 +0000 | [diff] [blame] | 41 | #ifndef true | 
 | 42 | #define true 1 | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 43 | #endif | 
 | 44 |  | 
 | 45 | /* following came from the other byteorder.h to avoid include conflicts */ | 
 | 46 | #define CVAL(buf,pos) (((unsigned char *)(buf))[pos]) | 
 | 47 | #define SSVALX(buf,pos,val) (CVAL(buf,pos)=(val)&0xFF,CVAL(buf,pos+1)=(val)>>8) | 
 | 48 | #define SSVAL(buf,pos,val) SSVALX((buf),(pos),((__u16)(val))) | 
 | 49 |  | 
| Steve French | 43988d7 | 2011-04-19 18:23:31 +0000 | [diff] [blame] | 50 | static void | 
 | 51 | str_to_key(unsigned char *str, unsigned char *key) | 
 | 52 | { | 
 | 53 | 	int i; | 
 | 54 |  | 
 | 55 | 	key[0] = str[0] >> 1; | 
 | 56 | 	key[1] = ((str[0] & 0x01) << 6) | (str[1] >> 2); | 
 | 57 | 	key[2] = ((str[1] & 0x03) << 5) | (str[2] >> 3); | 
 | 58 | 	key[3] = ((str[2] & 0x07) << 4) | (str[3] >> 4); | 
 | 59 | 	key[4] = ((str[3] & 0x0F) << 3) | (str[4] >> 5); | 
 | 60 | 	key[5] = ((str[4] & 0x1F) << 2) | (str[5] >> 6); | 
 | 61 | 	key[6] = ((str[5] & 0x3F) << 1) | (str[6] >> 7); | 
 | 62 | 	key[7] = str[6] & 0x7F; | 
 | 63 | 	for (i = 0; i < 8; i++) | 
 | 64 | 		key[i] = (key[i] << 1); | 
 | 65 | } | 
 | 66 |  | 
 | 67 | static int | 
 | 68 | smbhash(unsigned char *out, const unsigned char *in, unsigned char *key) | 
 | 69 | { | 
 | 70 | 	int rc; | 
 | 71 | 	unsigned char key2[8]; | 
 | 72 | 	struct crypto_blkcipher *tfm_des; | 
 | 73 | 	struct scatterlist sgin, sgout; | 
 | 74 | 	struct blkcipher_desc desc; | 
 | 75 |  | 
 | 76 | 	str_to_key(key, key2); | 
 | 77 |  | 
 | 78 | 	tfm_des = crypto_alloc_blkcipher("ecb(des)", 0, CRYPTO_ALG_ASYNC); | 
 | 79 | 	if (IS_ERR(tfm_des)) { | 
 | 80 | 		rc = PTR_ERR(tfm_des); | 
 | 81 | 		cERROR(1, "could not allocate des crypto API\n"); | 
 | 82 | 		goto smbhash_err; | 
 | 83 | 	} | 
 | 84 |  | 
 | 85 | 	desc.tfm = tfm_des; | 
 | 86 |  | 
 | 87 | 	crypto_blkcipher_setkey(tfm_des, key2, 8); | 
 | 88 |  | 
 | 89 | 	sg_init_one(&sgin, in, 8); | 
 | 90 | 	sg_init_one(&sgout, out, 8); | 
 | 91 |  | 
 | 92 | 	rc = crypto_blkcipher_encrypt(&desc, &sgout, &sgin, 8); | 
| Jeff Layton | e4fb0ed | 2011-06-20 14:33:16 -0400 | [diff] [blame] | 93 | 	if (rc) | 
| Steve French | 43988d7 | 2011-04-19 18:23:31 +0000 | [diff] [blame] | 94 | 		cERROR(1, "could not encrypt crypt key rc: %d\n", rc); | 
| Steve French | 43988d7 | 2011-04-19 18:23:31 +0000 | [diff] [blame] | 95 |  | 
| Jeff Layton | e4fb0ed | 2011-06-20 14:33:16 -0400 | [diff] [blame] | 96 | 	crypto_free_blkcipher(tfm_des); | 
| Steve French | 43988d7 | 2011-04-19 18:23:31 +0000 | [diff] [blame] | 97 | smbhash_err: | 
 | 98 | 	return rc; | 
 | 99 | } | 
 | 100 |  | 
 | 101 | static int | 
 | 102 | E_P16(unsigned char *p14, unsigned char *p16) | 
 | 103 | { | 
 | 104 | 	int rc; | 
 | 105 | 	unsigned char sp8[8] = | 
 | 106 | 	    { 0x4b, 0x47, 0x53, 0x21, 0x40, 0x23, 0x24, 0x25 }; | 
 | 107 |  | 
 | 108 | 	rc = smbhash(p16, sp8, p14); | 
 | 109 | 	if (rc) | 
 | 110 | 		return rc; | 
 | 111 | 	rc = smbhash(p16 + 8, sp8, p14 + 7); | 
 | 112 | 	return rc; | 
 | 113 | } | 
 | 114 |  | 
 | 115 | static int | 
 | 116 | E_P24(unsigned char *p21, const unsigned char *c8, unsigned char *p24) | 
 | 117 | { | 
 | 118 | 	int rc; | 
 | 119 |  | 
 | 120 | 	rc = smbhash(p24, c8, p21); | 
 | 121 | 	if (rc) | 
 | 122 | 		return rc; | 
 | 123 | 	rc = smbhash(p24 + 8, c8, p21 + 7); | 
 | 124 | 	if (rc) | 
 | 125 | 		return rc; | 
 | 126 | 	rc = smbhash(p24 + 16, c8, p21 + 14); | 
 | 127 | 	return rc; | 
 | 128 | } | 
 | 129 |  | 
| Shirish Pargaonkar | ee2c925 | 2011-01-27 09:58:04 -0600 | [diff] [blame] | 130 | /* produce a md4 message digest from data of length n bytes */ | 
 | 131 | int | 
 | 132 | mdfour(unsigned char *md4_hash, unsigned char *link_str, int link_len) | 
 | 133 | { | 
 | 134 | 	int rc; | 
 | 135 | 	unsigned int size; | 
 | 136 | 	struct crypto_shash *md4; | 
 | 137 | 	struct sdesc *sdescmd4; | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 138 |  | 
| Shirish Pargaonkar | ee2c925 | 2011-01-27 09:58:04 -0600 | [diff] [blame] | 139 | 	md4 = crypto_alloc_shash("md4", 0, 0); | 
 | 140 | 	if (IS_ERR(md4)) { | 
| Jeff Layton | ffeb414 | 2011-01-29 07:03:02 -0500 | [diff] [blame] | 141 | 		rc = PTR_ERR(md4); | 
| Shirish Pargaonkar | ee2c925 | 2011-01-27 09:58:04 -0600 | [diff] [blame] | 142 | 		cERROR(1, "%s: Crypto md4 allocation error %d\n", __func__, rc); | 
| Jeff Layton | ffeb414 | 2011-01-29 07:03:02 -0500 | [diff] [blame] | 143 | 		return rc; | 
| Shirish Pargaonkar | ee2c925 | 2011-01-27 09:58:04 -0600 | [diff] [blame] | 144 | 	} | 
 | 145 | 	size = sizeof(struct shash_desc) + crypto_shash_descsize(md4); | 
 | 146 | 	sdescmd4 = kmalloc(size, GFP_KERNEL); | 
 | 147 | 	if (!sdescmd4) { | 
 | 148 | 		rc = -ENOMEM; | 
 | 149 | 		cERROR(1, "%s: Memory allocation failure\n", __func__); | 
 | 150 | 		goto mdfour_err; | 
 | 151 | 	} | 
 | 152 | 	sdescmd4->shash.tfm = md4; | 
 | 153 | 	sdescmd4->shash.flags = 0x0; | 
 | 154 |  | 
 | 155 | 	rc = crypto_shash_init(&sdescmd4->shash); | 
 | 156 | 	if (rc) { | 
 | 157 | 		cERROR(1, "%s: Could not init md4 shash\n", __func__); | 
 | 158 | 		goto mdfour_err; | 
 | 159 | 	} | 
| Shirish Pargaonkar | 14cae32 | 2011-06-20 16:14:03 -0500 | [diff] [blame] | 160 | 	rc = crypto_shash_update(&sdescmd4->shash, link_str, link_len); | 
 | 161 | 	if (rc) { | 
 | 162 | 		cERROR(1, "%s: Could not update with link_str\n", __func__); | 
 | 163 | 		goto mdfour_err; | 
 | 164 | 	} | 
| Shirish Pargaonkar | ee2c925 | 2011-01-27 09:58:04 -0600 | [diff] [blame] | 165 | 	rc = crypto_shash_final(&sdescmd4->shash, md4_hash); | 
| Shirish Pargaonkar | 14cae32 | 2011-06-20 16:14:03 -0500 | [diff] [blame] | 166 | 	if (rc) | 
 | 167 | 		cERROR(1, "%s: Could not genereate md4 hash\n", __func__); | 
| Shirish Pargaonkar | ee2c925 | 2011-01-27 09:58:04 -0600 | [diff] [blame] | 168 |  | 
 | 169 | mdfour_err: | 
 | 170 | 	crypto_free_shash(md4); | 
 | 171 | 	kfree(sdescmd4); | 
 | 172 |  | 
 | 173 | 	return rc; | 
 | 174 | } | 
 | 175 |  | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 176 | /* | 
 | 177 |    This implements the X/Open SMB password encryption | 
| Steve French | 790fe57 | 2007-07-07 19:25:05 +0000 | [diff] [blame] | 178 |    It takes a password, a 8 byte "crypt key" and puts 24 bytes of | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 179 |    encrypted password into p24 */ | 
 | 180 | /* Note that password must be uppercased and null terminated */ | 
| Steve French | 43988d7 | 2011-04-19 18:23:31 +0000 | [diff] [blame] | 181 | int | 
| Jeff Layton | 4e53a3f | 2008-12-05 20:41:21 -0500 | [diff] [blame] | 182 | SMBencrypt(unsigned char *passwd, const unsigned char *c8, unsigned char *p24) | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 183 | { | 
| Steve French | 43988d7 | 2011-04-19 18:23:31 +0000 | [diff] [blame] | 184 | 	int rc; | 
 | 185 | 	unsigned char p14[14], p16[16], p21[21]; | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 186 |  | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 187 | 	memset(p14, '\0', 14); | 
| Steve French | 43988d7 | 2011-04-19 18:23:31 +0000 | [diff] [blame] | 188 | 	memset(p16, '\0', 16); | 
 | 189 | 	memset(p21, '\0', 21); | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 190 |  | 
| Steve French | 43988d7 | 2011-04-19 18:23:31 +0000 | [diff] [blame] | 191 | 	memcpy(p14, passwd, 14); | 
 | 192 | 	rc = E_P16(p14, p16); | 
 | 193 | 	if (rc) | 
 | 194 | 		return rc; | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 195 |  | 
| Steve French | 43988d7 | 2011-04-19 18:23:31 +0000 | [diff] [blame] | 196 | 	memcpy(p21, p16, 16); | 
 | 197 | 	rc = E_P24(p21, c8, p24); | 
| Steve French | 50c2f75 | 2007-07-13 00:33:32 +0000 | [diff] [blame] | 198 |  | 
| Steve French | 43988d7 | 2011-04-19 18:23:31 +0000 | [diff] [blame] | 199 | 	return rc; | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 200 | } | 
 | 201 |  | 
| Steve French | 790fe57 | 2007-07-07 19:25:05 +0000 | [diff] [blame] | 202 | /* | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 203 |  * Creates the MD4 Hash of the users password in NT UNICODE. | 
 | 204 |  */ | 
 | 205 |  | 
| Shirish Pargaonkar | ee2c925 | 2011-01-27 09:58:04 -0600 | [diff] [blame] | 206 | int | 
| Shirish Pargaonkar | 9ef5992 | 2011-10-20 13:21:59 -0500 | [diff] [blame] | 207 | E_md4hash(const unsigned char *passwd, unsigned char *p16, | 
 | 208 | 	const struct nls_table *codepage) | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 209 | { | 
| Shirish Pargaonkar | ee2c925 | 2011-01-27 09:58:04 -0600 | [diff] [blame] | 210 | 	int rc; | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 211 | 	int len; | 
 | 212 | 	__u16 wpwd[129]; | 
 | 213 |  | 
 | 214 | 	/* Password cannot be longer than 128 characters */ | 
| Shirish Pargaonkar | 9ef5992 | 2011-10-20 13:21:59 -0500 | [diff] [blame] | 215 | 	if (passwd) /* Password must be converted to NT unicode */ | 
 | 216 | 		len = cifs_strtoUCS(wpwd, passwd, 128, codepage); | 
 | 217 | 	else { | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 218 | 		len = 0; | 
| Shirish Pargaonkar | 9ef5992 | 2011-10-20 13:21:59 -0500 | [diff] [blame] | 219 | 		*wpwd = 0; /* Ensure string is null terminated */ | 
 | 220 | 	} | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 221 |  | 
| Shirish Pargaonkar | 9ef5992 | 2011-10-20 13:21:59 -0500 | [diff] [blame] | 222 | 	rc = mdfour(p16, (unsigned char *) wpwd, len * sizeof(__u16)); | 
 | 223 | 	memset(wpwd, 0, 129 * sizeof(__u16)); | 
| Shirish Pargaonkar | ee2c925 | 2011-01-27 09:58:04 -0600 | [diff] [blame] | 224 |  | 
 | 225 | 	return rc; | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 226 | } | 
 | 227 |  | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 228 | /* Does the NT MD4 hash then des encryption. */ | 
| Shirish Pargaonkar | ee2c925 | 2011-01-27 09:58:04 -0600 | [diff] [blame] | 229 | int | 
| Shirish Pargaonkar | 9ef5992 | 2011-10-20 13:21:59 -0500 | [diff] [blame] | 230 | SMBNTencrypt(unsigned char *passwd, unsigned char *c8, unsigned char *p24, | 
 | 231 | 		const struct nls_table *codepage) | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 232 | { | 
| Shirish Pargaonkar | ee2c925 | 2011-01-27 09:58:04 -0600 | [diff] [blame] | 233 | 	int rc; | 
| Steve French | 43988d7 | 2011-04-19 18:23:31 +0000 | [diff] [blame] | 234 | 	unsigned char p16[16], p21[21]; | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 235 |  | 
| Steve French | 43988d7 | 2011-04-19 18:23:31 +0000 | [diff] [blame] | 236 | 	memset(p16, '\0', 16); | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 237 | 	memset(p21, '\0', 21); | 
 | 238 |  | 
| Shirish Pargaonkar | 9ef5992 | 2011-10-20 13:21:59 -0500 | [diff] [blame] | 239 | 	rc = E_md4hash(passwd, p16, codepage); | 
| Shirish Pargaonkar | ee2c925 | 2011-01-27 09:58:04 -0600 | [diff] [blame] | 240 | 	if (rc) { | 
 | 241 | 		cFYI(1, "%s Can't generate NT hash, error: %d", __func__, rc); | 
 | 242 | 		return rc; | 
 | 243 | 	} | 
| Steve French | 43988d7 | 2011-04-19 18:23:31 +0000 | [diff] [blame] | 244 | 	memcpy(p21, p16, 16); | 
 | 245 | 	rc = E_P24(p21, c8, p24); | 
| Shirish Pargaonkar | ee2c925 | 2011-01-27 09:58:04 -0600 | [diff] [blame] | 246 | 	return rc; | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 247 | } |