Resetting OpenSSL HMAC with NULL key reuses existing key
This commit is contained in:
@@ -65,11 +65,6 @@ struct private_mac_t {
|
|||||||
* Current HMAC context
|
* Current HMAC context
|
||||||
*/
|
*/
|
||||||
HMAC_CTX hmac;
|
HMAC_CTX hmac;
|
||||||
|
|
||||||
/**
|
|
||||||
* Key
|
|
||||||
*/
|
|
||||||
chunk_t key;
|
|
||||||
};
|
};
|
||||||
|
|
||||||
/**
|
/**
|
||||||
@@ -77,8 +72,7 @@ struct private_mac_t {
|
|||||||
*/
|
*/
|
||||||
static bool reset(private_mac_t *this)
|
static bool reset(private_mac_t *this)
|
||||||
{
|
{
|
||||||
return HMAC_Init_ex(&this->hmac, this->key.ptr, this->key.len,
|
return HMAC_Init_ex(&this->hmac, NULL, 0, this->hasher, NULL);
|
||||||
this->hasher, NULL);
|
|
||||||
}
|
}
|
||||||
|
|
||||||
METHOD(mac_t, get_mac, bool,
|
METHOD(mac_t, get_mac, bool,
|
||||||
@@ -102,16 +96,13 @@ METHOD(mac_t, get_mac_size, size_t,
|
|||||||
METHOD(mac_t, set_key, bool,
|
METHOD(mac_t, set_key, bool,
|
||||||
private_mac_t *this, chunk_t key)
|
private_mac_t *this, chunk_t key)
|
||||||
{
|
{
|
||||||
chunk_clear(&this->key);
|
return HMAC_Init_ex(&this->hmac, key.ptr, key.len, this->hasher, NULL);
|
||||||
this->key = chunk_clone(key);
|
|
||||||
return reset(this);
|
|
||||||
}
|
}
|
||||||
|
|
||||||
METHOD(mac_t, destroy, void,
|
METHOD(mac_t, destroy, void,
|
||||||
private_mac_t *this)
|
private_mac_t *this)
|
||||||
{
|
{
|
||||||
HMAC_CTX_cleanup(&this->hmac);
|
HMAC_CTX_cleanup(&this->hmac);
|
||||||
chunk_clear(&this->key);
|
|
||||||
free(this);
|
free(this);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user