vici: Add support for NT Hash secrets

Fixes #1002.
This commit is contained in:
Tobias Brunner
2017-02-16 19:23:51 +01:00
parent 3bedf10b25
commit ed105f45af
3 changed files with 29 additions and 1 deletions
+4
View File
@@ -339,6 +339,10 @@ CALLBACK(load_shared, vici_message_t*,
{ {
type = SHARED_EAP; type = SHARED_EAP;
} }
else if (strcaseeq(str, "ntlm"))
{
type = SHARED_NT_HASH;
}
else else
{ {
return create_reply("invalid shared key type: %s", str); return create_reply("invalid shared key type: %s", str);
+3 -1
View File
@@ -583,6 +583,7 @@ static bool load_secret(load_ctx_t *ctx, char *section)
char *types[] = { char *types[] = {
"eap", "eap",
"xauth", "xauth",
"ntlm",
"ike", "ike",
"private", "private",
"rsa", "rsa",
@@ -605,7 +606,8 @@ static bool load_secret(load_ctx_t *ctx, char *section)
fprintf(stderr, "ignoring unsupported secret '%s'\n", section); fprintf(stderr, "ignoring unsupported secret '%s'\n", section);
return FALSE; return FALSE;
} }
if (!streq(type, "eap") && !streq(type, "xauth") && !streq(type, "ike")) if (!streq(type, "eap") && !streq(type, "xauth") && !streq(type, "ntlm") &&
!streq(type, "ike"))
{ /* skip non-shared secrets */ { /* skip non-shared secrets */
return TRUE; return TRUE;
} }
+22
View File
@@ -831,6 +831,28 @@ secrets.eap<suffix>.id<suffix> =
be specified, each having an _id_ prefix, if a secret is shared between be specified, each having an _id_ prefix, if a secret is shared between
multiple users. multiple users.
secrets.ntlm<suffix> { # }
NTLM secret section for a specific secret.
NTLM secret section for a specific secret. Each NTLM secret is defined in
a unique section having the _ntlm_ prefix. NTLM secrets may only be used for
EAP-MSCHAPv2 authentication.
secrets.ntlm<suffix>.secret =
Value of the NTLM secret.
Value of the NTLM secret, which is the NT Hash of the actual secret, that
is, MD4(UTF-16LE(secret)). The resulting 16-byte value may either be given
as a hex encoded string with a _0x_ prefix or as a Base64 encoded string
with a _0s_ prefix.
secrets.ntlm<suffix>.id<suffix> =
Identity the NTLM secret belongs to.
Identity the NTLM secret belongs to. Multiple unique identities may
be specified, each having an _id_ prefix, if a secret is shared between
multiple users.
secrets.ike<suffix> { # } secrets.ike<suffix> { # }
IKE preshared secret section for a specific secret. IKE preshared secret section for a specific secret.