3 #if defined(KERBEROS) && !defined(openbsd)
5 * $Source: /repo/OpenLDAP/pkg/ldap/clients/ud/string_to_key.c,v $
8 * Copyright 1985, 1986, 1987, 1988, 1989 by the Massachusetts Institute
11 * For copying and distribution information, please see the file
14 * These routines perform encryption and decryption using the DES
15 * private key algorithm, or else a subset of it-- fewer inner loops.
16 * (AUTH_DES_ITER defaults to 16, may be less.)
18 * Under U.S. law, this software may not be exported outside the US
19 * without license from the U.S. Commerce department.
21 * The key schedule is passed as an arg, as well as the cleartext or
22 * ciphertext. The cleartext and ciphertext should be in host order.
24 * These routines form the library interface to the DES facilities.
26 * spm 8/85 MIT project athena
30 #include <kerberosIV/mit-copyright.h>
31 #include <kerberosIV/des.h>
33 #include <mit-copyright.h>
35 #endif /* KERBEROS_V */
39 /* #include "des_internal.h" */
42 #include <kerberosIV/krb.h>
45 #endif /* KERBEROS_V */
49 extern int des_debug_print();
50 extern void des_fixup_key_parity();
53 #define WORLDPEACEINOURTIME
56 #if defined(WORLDPEACEINOURTIME) /* Use original, not ifs version */
59 * convert an arbitrary length string to a DES key
62 des_string_to_key(str,key)
64 register des_cblock *key;
66 register char *in_str;
67 register unsigned temp,i;
70 static unsigned char *k_p;
72 register char *p_char;
73 static char k_char[64];
74 static des_key_schedule key_sked;
75 extern unsigned long des_cbc_cksum();
82 /* init key array for bits */
83 memset(k_char, 0, sizeof(k_char));
88 "\n\ninput str length = %d string = %s\nstring = 0x ",
92 /* get next 8 bytes, strip parity, xor */
93 for (i = 1; i <= length; i++) {
94 /* get next input key byte */
95 temp = (unsigned int) *str++;
98 fprintf(stdout,"%02x ",temp & 0xff);
100 /* loop through bits within byte, ignore parity */
101 for (j = 0; j <= 6; j++) {
103 *p_char++ ^= (int) temp & 01;
105 *--p_char ^= (int) temp & 01;
109 /* check and flip direction */
114 /* now stuff into the key des_cblock, and force odd parity */
116 k_p = (unsigned char *) key;
118 for (i = 0; i <= 7; i++) {
120 for (j = 0; j <= 6; j++)
121 temp |= *p_char++ << (1+j);
122 *k_p++ = (unsigned char) temp;
126 des_fixup_key_parity(key);
128 /* Now one-way encrypt it with the folded key */
129 (void) des_key_sched(key,key_sked);
130 (void) des_cbc_cksum((des_cblock *)in_str,key,length,key_sked,key);
132 memset((char *)key_sked, 0, sizeof(key_sked));
134 /* now fix up key parity again */
135 des_fixup_key_parity(key);
139 "\nResulting string_to_key = 0x%x 0x%x\n",
140 *((unsigned long *) key),
141 *((unsigned long *) key+1));
144 #endif /* KERBEROS_V */
145 #else /* Use ifs version */
149 /* These two needed for rxgen output to work */
150 #include <sys/types.h>
152 #include <afs/cellconfig.h>
153 #include <afs/auth.h>
155 #include "/usr/andy/kauth/kauth.h"
156 #include "/usr/andy/kauth/kautils.h"
159 /* This defines the Andrew string_to_key function. It accepts a password
160 string as input and converts its via a one-way encryption algorithm to a DES
161 encryption key. It is compatible with the original Andrew authentication
162 service password database. */
164 static void Andrew_StringToKey (str, cell, key)
166 char *cell; /* cell for password */
168 { char password[8+1]; /* crypt is limited to 8 chars anyway */
172 memset(key, 0, sizeof(des_cblock));
173 memset(password, 0, sizeof(password));
175 strncpy (password, cell, 8);
176 passlen = strlen (str);
177 if (passlen > 8) passlen = 8;
179 for (i=0; i<passlen; i++)
180 password[i] = str[i] ^ cell[i];
183 if (password[i] == '\0') password[i] = 'X';
185 /* crypt only considers the first 8 characters of password but for some
186 reason returns eleven characters of result (plus the two salt chars). */
187 strncpy(key, crypt(password, "#~") + 2, sizeof(des_cblock));
189 /* parity is inserted into the LSB so leftshift each byte up one bit. This
190 allows ascii characters with a zero MSB to retain as much significance
192 { char *keybytes = (char *)key;
195 for (i = 0; i < 8; i++) {
196 temp = (unsigned int) keybytes[i];
197 keybytes[i] = (unsigned char) (temp << 1);
200 des_fixup_key_parity (key);
203 static void StringToKey (str, cell, key)
205 char *cell; /* cell for password */
207 { des_key_schedule schedule;
210 char password[BUFSIZ];
213 strncpy (password, str, sizeof(password));
214 if ((passlen = strlen (password)) < sizeof(password)-1)
215 strncat (password, cell, sizeof(password)-passlen);
216 if ((passlen = strlen(password)) > sizeof(password)) passlen = sizeof(password);
218 memcpy(ivec, "kerberos", 8);
219 memcpy(temp_key, "kerberos", 8);
220 des_fixup_key_parity (temp_key);
221 des_key_sched (temp_key, schedule);
222 des_cbc_cksum (password, ivec, passlen, schedule, ivec);
224 memcpy(temp_key, ivec, 8);
225 des_fixup_key_parity (temp_key);
226 des_key_sched (temp_key, schedule);
227 des_cbc_cksum (password, key, passlen, schedule, ivec);
229 des_fixup_key_parity (key);
233 ka_StringToKey (str, cell, key)
235 char *cell; /* cell for password */
237 { char realm[REALM_SZ];
241 /* code = ka_CellToRealm (cell, realm, 0/*local*/); */
242 if (code) strcpy (realm, "");
243 else lcstring (realm, realm, sizeof(realm)); /* for backward compatibility */
245 (void)strcpy(realm, cell);
248 if (strlen(str) > 8) StringToKey (str, realm, key);
249 else Andrew_StringToKey (str, realm, key);
253 * convert an arbitrary length string to a DES key
256 des_string_to_key(str,key)
258 register des_cblock *key;
260 /* NB: i should probably call routine to get local cell here */
261 ka_StringToKey(str, "umich.edu", key);
265 #endif /* Use IFS Version */
267 #endif /* kerberos */