From nobody Tue Oct 3 13:02:04 2023 X-Original-To: current@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4S0J0H0bxcz4wF2B for ; Tue, 3 Oct 2023 13:03:11 +0000 (UTC) (envelope-from Alexander@Leidinger.net) Received: from mailgate.Leidinger.net (mailgate.leidinger.net [IPv6:2a00:1828:2000:313::1:5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature ECDSA (P-256) client-digest SHA256) (Client CN "mailgate.leidinger.net", Issuer "R3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4S0J0F6Qjxz4Zhx for ; Tue, 3 Oct 2023 13:03:09 +0000 (UTC) (envelope-from Alexander@Leidinger.net) Authentication-Results: mx1.freebsd.org; dkim=pass header.d=leidinger.net header.s=outgoing-alex header.b=XGPUZRhM; spf=pass (mx1.freebsd.org: domain of Alexander@Leidinger.net designates 2a00:1828:2000:313::1:5 as permitted sender) smtp.mailfrom=Alexander@Leidinger.net; dmarc=pass (policy=quarantine) header.from=leidinger.net List-Id: Discussions about the use of FreeBSD-current List-Archive: https://lists.freebsd.org/archives/freebsd-current List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-freebsd-current@freebsd.org MIME-Version: 1.0 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=leidinger.net; s=outgoing-alex; t=1696338175; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type; bh=2RiNYs6ZkL81fqK0iLjijY0TUbWvJk/1lwn7xBCajYk=; b=XGPUZRhMufKr4uFketOcSvsASpSUyG8st3MIK7Qguksb/4bgdFJ65/I2My35g/dAUueHhu oAp3L0Vf2ceEbS8p9ij3Qi1zvnUJg1YuyDKP2DhxTI1QT8I5UBHf7OPuqHT0pkmp7YbSsa 6em2LS4YmM9wJGnpwpgBzwv8PbYxSIV/uCXGQS4QvV7rhGPg2mlYZHqNgktWBc64Tn5IFT BGcXEOCpK/1R97oLBWbGFoa+72vZpkikarKM9MxOFj9x21v/EYF0h92CbwTFLyHbh8idX6 aiuCIgndZvTMaAXv8dyQqVSNRoRMO5gSm3hBW9hLD8bsLz6zLDX+gbKl0yuZ2w== Date: Tue, 03 Oct 2023 15:02:04 +0200 From: Alexander Leidinger To: Current Subject: base-krb5 issues (segfaults when adding principals in openssl) Message-ID: X-Sender: Alexander@Leidinger.net Organization: No organization, this is a private message. Content-Type: multipart/signed; protocol="application/pgp-signature"; boundary="=_47070f313bceb00668151db53268a957"; micalg=pgp-sha256 X-Spamd-Bar: ------ X-Spamd-Result: default: False [-6.03 / 15.00]; SIGNED_PGP(-2.00)[]; NEURAL_HAM_LONG(-1.00)[-1.000]; NEURAL_HAM_MEDIUM(-1.00)[-1.000]; NEURAL_HAM_SHORT(-0.93)[-0.930]; DMARC_POLICY_ALLOW(-0.50)[leidinger.net,quarantine]; R_SPF_ALLOW(-0.20)[+mx]; MIME_GOOD(-0.20)[multipart/signed,text/plain]; R_DKIM_ALLOW(-0.20)[leidinger.net:s=outgoing-alex]; MLMMJ_DEST(0.00)[current@freebsd.org]; RCVD_COUNT_ZERO(0.00)[0]; MIME_TRACE(0.00)[0:+,1:+,2:~]; FROM_EQ_ENVFROM(0.00)[]; ARC_NA(0.00)[]; HAS_ORG_HEADER(0.00)[]; TO_DN_ALL(0.00)[]; TO_MATCH_ENVRCPT_ALL(0.00)[]; FROM_HAS_DN(0.00)[]; DKIM_TRACE(0.00)[leidinger.net:+]; HAS_ATTACHMENT(0.00)[]; ASN(0.00)[asn:34240, ipnet:2a00:1828::/32, country:DE]; RCPT_COUNT_ONE(0.00)[1]; MID_RHS_MATCH_FROM(0.00)[] X-Rspamd-Queue-Id: 4S0J0F6Qjxz4Zhx This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --=_47070f313bceb00668151db53268a957 Content-Transfer-Encoding: 7bit Content-Type: text/plain; charset=US-ASCII; format=flowed Hi, has someone else issues with krb5 on -current when adding principals? With -current as of 2023-09-11 I get a segfault in openssl: ---snip--- Reading symbols from /usr/bin/kadmin... Reading symbols from /usr/lib/debug//usr/bin/kadmin.debug... [New LWP 270171] btCore was generated by `kadmin -l'. Program terminated with signal SIGSEGV, Segmentation fault. Address not mapped to object. #0 0x0000000000000000 in ?? () (gdb) bt #0 0x0000000000000000 in ?? () #1 0x00000e118da145f8 in ARCFOUR_string_to_key (context=0x44f9fba1a000, enctype=KRB5_ENCTYPE_ARCFOUR_HMAC_MD5, password=..., salt=..., opaque=..., key=0x44f9fba211d8) at /space/system/usr_src/crypto/heimdal/lib/krb5/salt-arcfour.c:84 #2 0x00000e118da156e9 in krb5_string_to_key_data_salt_opaque (enctype=KRB5_ENCTYPE_ARCFOUR_HMAC_MD5, salt=..., opaque=..., context=, password=..., key=) at /space/system/usr_src/crypto/heimdal/lib/krb5/salt.c:201 #3 krb5_string_to_key_data_salt (context=0x44f9fba1a000, enctype=KRB5_ENCTYPE_ARCFOUR_HMAC_MD5, password=..., salt=..., key=0x44f9fba211d8) at /space/system/usr_src/crypto/heimdal/lib/krb5/salt.c:173 #4 0x00000e118da158cb in krb5_string_to_key_salt (context=0x44f9fba4bc60, context@entry=0x44f9fba1a000, enctype=-1980854121, password=0x0, password@entry=0xe1189ee9510 "1kad$uwi6!", salt=..., key=0x5) at /space/system/usr_src/crypto/heimdal/lib/krb5/salt.c:225 #5 0x00000e118ba75423 in hdb_generate_key_set_password (context=0x44f9fba1a000, principal=, password=password@entry=0xe1189ee9510 "1kad$uwi6!", keys=keys@entry=0xe1189ee9210, num_keys=num_keys@entry=0xe1189ee9208) at /space/system/usr_src/crypto/heimdal/lib/hdb/keys.c:381 #6 0x00000e118ca91c9a in _kadm5_set_keys (context=context@entry=0x44f9fba1a140, ent=ent@entry=0xe1189ee9258, password=0x1 , password@entry=0xe1189ee9510 "1kad$uwi6!") at /space/system/usr_src/crypto/heimdal/lib/kadm5/set_keys.c:51 #7 0x00000e118ca8caac in kadm5_s_create_principal (server_handle=0x44f9fba1a140, princ=, mask=, password=0xe1189ee9510 "1kad$uwi6!") at /space/system/usr_src/crypto/heimdal/lib/kadm5/create_s.c:172 #8 0x00000e0969e1a57b in add_one_principal (name=, rand_key=0, rand_password=0, use_defaults=0, password=0xe1189ee9510 "1kad$uwi6!", key_data=0x0, max_ticket_life=, max_renewable_life=, attributes=0x0, expiration=, pw_expiration=0x0) at /space/system/usr_src/crypto/heimdal/kadmin/ank.c:141 #9 add_new_key (opt=opt@entry=0xe1189ee9960, argc=argc@entry=1, argv=0x44f9fba49238, argv@entry=0x44f9fba49230) at /space/system/usr_src/crypto/heimdal/kadmin/ank.c:243 #10 0x00000e0969e1e124 in add_wrap (argc=, argv=0x44f9fba49230) at kadmin-commands.c:210 #11 0x00000e0969e23945 in sl_command (cmds=, argc=2, argv=0x44f9fba49230) at /space/system/usr_src/crypto/heimdal/lib/sl/sl.c:209 #12 sl_command_loop (cmds=cmds@entry=0xe0969e282a0 , prompt=prompt@entry=0xe0969e15cca "kadmin> ", data=) at /space/system/usr_src/crypto/heimdal/lib/sl/sl.c:328 #13 0x00000e0969e1d876 in main (argc=, argv=) at /space/system/usr_src/crypto/heimdal/kadmin/kadmin.c:275 (gdb) up 1 #1 0x00000e118da145f8 in ARCFOUR_string_to_key (context=0x44f9fba1a000, enctype=KRB5_ENCTYPE_ARCFOUR_HMAC_MD5, password=..., salt=..., opaque=..., key=0x44f9fba211d8) at /space/system/usr_src/crypto/heimdal/lib/krb5/salt-arcfour.c:84 84 EVP_DigestUpdate (m, &p, 1); (gdb) list 79 80 /* LE encoding */ 81 for (i = 0; i < len; i++) { 82 unsigned char p; 83 p = (s[i] & 0xff); 84 EVP_DigestUpdate (m, &p, 1); 85 p = (s[i] >> 8) & 0xff; 86 EVP_DigestUpdate (m, &p, 1); 87 } 88 (gdb) print i $1 = 0 (gdb) print len $2 = (gdb) print p $3 = 49 '1' (gdb) print m $4 = (EVP_MD_CTX *) 0x43e31de4bc60 (gdb) print *m $5 = {reqdigest = 0x17e678afd470, digest = 0x0, engine = 0x0, flags = 0, md_data = 0x0, pctx = 0x0, update = 0x0, algctx = 0x0, fetched_digest = 0x0} (gdb) ---snip--- Bye, Alexander. -- http://www.Leidinger.net Alexander@Leidinger.net: PGP 0x8F31830F9F2772BF http://www.FreeBSD.org netchild@FreeBSD.org : PGP 0x8F31830F9F2772BF --=_47070f313bceb00668151db53268a957 Content-Type: application/pgp-signature; name=signature.asc Content-Disposition: attachment; filename=signature.asc; size=833 Content-Description: OpenPGP digital signature -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEER9UlYXp1PSd08nWXEg2wmwP42IYFAmUcENwACgkQEg2wmwP4 2IZwDhAAqCe0eEqofPb0YxyFDixqt20AFzl/YIHpylhLCiD5gARlJTLkbwSVdHsJ MlKLiEdSlhk7csUBG9FRiYvO1A4tjW72F1SFJpvBpH0h8+O9Chr+hs96oNzyPAmF tkrtybEUobcPIipzPiGwc/pJDg2RU4OSiMIIRtgCIegPHHPKVbfaDdAbHyOnNGdA LAsvnUPlzfWdo0LSij+COCHO8ueOFZckrY8hjI6C8LvGadfF2Fb7YdvQKG6OFJDg 50Jk6FMCdzriy1IsgULkRCoEuoa3yMXmomwegIr5nMXZw5FAx5OrJYL+AODVQjQV q3Yz1whqfM4cPSoVjdPdrAbxGOcI8IDlhk04OG2pecJK5dWvYSj91JNJ4EY7UaT5 kjwm5q4milqTpR41SGsZOkKv32nQ1+LAXcVcGDLBQ1j0wlLsatUmctbBJx9BW0Sc JUlw7Wp9bhuoFBe3+TcwyQQ/MXLvusRrF5nwyPfyD29rjGuKNnzNXP12GNxhTh/U UDX1rXx8ENrSvYkBNUyMgHsP3Kk9P9cXL1JIWTWxmKXZuPxVNnuoMrD5FFgUhHtD gjXW5ttMRko85v/dQyYux7wHM7A3sS4nDlwZA0Vx6wrkJPK8bOgHZpLiWCPI64Bh GRszHOnYdLcaML6npxH1zp5PZk54YqjscDn/gvSuYBenpVHU/ys= =Ho/s -----END PGP SIGNATURE----- --=_47070f313bceb00668151db53268a957--