use new master key functions

git-svn-id: svn://svn.h5l.se/heimdal/trunk/heimdal@3369 ec53bebd-3082-4978-b11e-865c3cabbd6b
This commit is contained in:
Johan Danielsson
1997-09-03 20:15:08 +00:00
parent 4763026f1f
commit 7aae890bf5
2 changed files with 18 additions and 31 deletions

View File

@@ -52,39 +52,25 @@ sigterm(int sig)
int
main(int argc, char **argv)
{
int c;
krb5_error_code ret;
EncryptionKey key;
set_progname(argv[0]);
krb5_init_context(&context);
configure(argc, argv);
if(keyfile){
FILE *f;
size_t len;
unsigned char buf[1024];
EncryptionKey key;
f = fopen(keyfile, "r");
if(f == NULL){
kdc_log(0, "Failed to open master key file %s", keyfile);
exit(1);
}
len = fread(buf, 1, sizeof(buf), f);
fclose(f);
if(decode_EncryptionKey(buf, len, &key, &len)){
kdc_log(0, "Failed to parse contents of master key file %s", keyfile);
exit(1);
}
set_master_key(&key);
ret = hdb_read_master_key(context, keyfile, &key);
if(ret && ret != ENOENT)
krb5_err(context, 1, ret, "Failed to open master key file");
if(ret == 0){
set_master_key(key);
memset(key.keyvalue.data, 0, key.keyvalue.length);
free_EncryptionKey(&key);
}else{
des_cblock key;
des_new_random_key(&key);
memset(&key, 0, sizeof(key));
}
kdc_log(5, "Database is encrypted");
}else
kdc_log(5, "Database is not encrypted");
signal(SIGINT, sigterm);
loop();
krb5_free_context(context);

View File

@@ -66,16 +66,17 @@ db_fetch(krb5_principal principal)
return ent;
}
static des_key_schedule master_key;
static krb5_data master_key;
static int master_key_set;
void
set_master_key(EncryptionKey *key)
set_master_key(EncryptionKey key)
{
if(key->keytype != KEYTYPE_DES || key->keyvalue.length != 8)
abort();
des_set_random_generator_seed(key->keyvalue.data);
des_set_key(key->keyvalue.data, master_key);
krb5_error_code ret;
ret = hdb_process_master_key(context, key, &master_key);
if(ret)
krb5_err(context, 1, ret, "Error processing master key file");
des_set_random_generator_seed(key.keyvalue.data);
master_key_set = 1;
}