2 Unix SMB/CIFS implementation.
4 code to encrypt/decrypt data using the user session key
6 Copyright (C) Andrew Tridgell 2004
8 This program is free software; you can redistribute it and/or modify
9 it under the terms of the GNU General Public License as published by
10 the Free Software Foundation; either version 2 of the License, or
11 (at your option) any later version.
13 This program is distributed in the hope that it will be useful,
14 but WITHOUT ANY WARRANTY; without even the implied warranty of
15 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
16 GNU General Public License for more details.
18 You should have received a copy of the GNU General Public License
19 along with this program; if not, write to the Free Software
20 Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
26 encrypt or decrypt a blob of data using the user session key
27 as used in lsa_SetSecret
29 before calling, the out blob must be initialised to be the same size
32 void sess_crypt_blob(DATA_BLOB *out, const DATA_BLOB *in, const DATA_BLOB *session_key,
40 uint8_t bin[8], bout[8], key[7];
43 memcpy(bin, &in->data[i], MIN(8, in->length-i));
45 if (k + 7 > session_key->length) {
46 k = (session_key->length - k);
48 memcpy(key, &session_key->data[k], 7);
50 des_crypt56(bout, bin, key, forward?1:0);
52 memcpy(&out->data[i], bout, MIN(8, in->length-i));
58 a convenient wrapper around sess_crypt_blob() for strings, using the LSA convention
60 note that we round the length to a multiple of 8. This seems to be needed for
61 compatibility with windows
63 caller should free using data_blob_free()
65 DATA_BLOB sess_encrypt_string(const char *str, const DATA_BLOB *session_key)
68 int slen = strlen(str);
69 int dlen = (slen+7) & ~7;
71 src = data_blob(NULL, 8+dlen);
73 return data_blob(NULL, 0);
76 ret = data_blob(NULL, 8+dlen);
79 return data_blob(NULL, 0);
82 SIVAL(src.data, 0, slen);
83 SIVAL(src.data, 4, 1);
84 memset(src.data+8, 0, dlen);
85 memcpy(src.data+8, str, slen);
87 sess_crypt_blob(&ret, &src, session_key, True);
95 a convenient wrapper around sess_crypt_blob() for strings, using the LSA convention
97 caller should free the returned string
99 char *sess_decrypt_string(DATA_BLOB *blob, const DATA_BLOB *session_key)
105 if (blob->length < 8) {
109 out = data_blob(NULL, blob->length);
114 sess_crypt_blob(&out, blob, session_key, False);
116 slen = IVAL(out.data, 0);
117 if (slen > blob->length - 8) {
118 DEBUG(0,("Invalid crypt length %d\n", slen));
122 if (IVAL(out.data, 4) != 1) {
123 DEBUG(0,("Unexpected revision number %d in session crypted string\n",
128 ret = strndup(out.data+8, slen);
130 data_blob_free(&out);