Resetting OpenSSL HMAC with NULL key reuses existing key

This commit is contained in:
Martin Willi
2012-07-16 14:55:07 +02:00
parent 9138f49e6a
commit 3aca89c8e6
@@ -65,11 +65,6 @@ struct private_mac_t {
* Current HMAC context * Current HMAC context
*/ */
HMAC_CTX hmac; HMAC_CTX hmac;
/**
* Key
*/
chunk_t key;
}; };
/** /**
@@ -77,8 +72,7 @@ struct private_mac_t {
*/ */
static bool reset(private_mac_t *this) static bool reset(private_mac_t *this)
{ {
return HMAC_Init_ex(&this->hmac, this->key.ptr, this->key.len, return HMAC_Init_ex(&this->hmac, NULL, 0, this->hasher, NULL);
this->hasher, NULL);
} }
METHOD(mac_t, get_mac, bool, METHOD(mac_t, get_mac, bool,
@@ -102,16 +96,13 @@ METHOD(mac_t, get_mac_size, size_t,
METHOD(mac_t, set_key, bool, METHOD(mac_t, set_key, bool,
private_mac_t *this, chunk_t key) private_mac_t *this, chunk_t key)
{ {
chunk_clear(&this->key); return HMAC_Init_ex(&this->hmac, key.ptr, key.len, this->hasher, NULL);
this->key = chunk_clone(key);
return reset(this);
} }
METHOD(mac_t, destroy, void, METHOD(mac_t, destroy, void,
private_mac_t *this) private_mac_t *this)
{ {
HMAC_CTX_cleanup(&this->hmac); HMAC_CTX_cleanup(&this->hmac);
chunk_clear(&this->key);
free(this); free(this);
} }