|
|
|
> 多个邮箱同步管理,live mail客户端万人抢用中
|
|
|
|
Home
> p=buf;
|
guest
|
|
0/0 Links
Milestone:
|
> }
|
| X |
| |
| Dates |
> |
| History |
Approval |
| Skip Menu |
X |
| Priority: |
Unprivileged |
|
|
else
 
|
0 min
|
| static int |
|
| OpenSSL-Bugs |
|
| |
|
| Depends on: |
|
|
|
1682 Subject:
|
Step4
|
| > } |
> I may find one bug by OpenSSL. |
| Last Contact |
fine.
|
| Id: |
|
| Children: |
|
|
|
|
> Not set
> err:
|
Display
|
| # uname -a |
|
| > } |
|
| People |
|
| |
|
| > } |
|
| > static int |
|
|
|
|
|
> People
Dates
|
> Step2 text/plain 4.6k > text/html 7.3k To:
|
| > |
Subsystem: |
ret = BIO_vsnprintf(buf, n, format, args); Owner: |
> * The blocks need to series by the BIO_snprintf is described in detail as follows. |
Queue: |
Not set |
|
> Thank you!
> a summary of which appears below. > http://www.thebeefcut.org/product/mail.html
> int ret;
> Add correct host key in /.ssh/known_hosts to what?) */
> Please contact your system administrator.
Status: 32bits mode', the > I try to build FIPS Capable OpenSSL according on build FIPS Capable OpenSSL according to to subject line of all future correspondence about this issue. To do so, Updated: > RSA1 host key for HPUX 11.23 IA for localhost has changed and you have requested strict checking. Thank you! due to file!) > Greetings, Host key verification failed. I can 'ssh -1 localhost' (use ssh protocol 1) to connect sshd server for 32bits mo > while (!BN_is_zero(t)) > *(p++)='0'; > char *buf = BN_bn2dec(num); 电磁波 <qianbohound@hotmail.com> > The BN_bn2dec function is from fips module fipscanister.o (crypto/bn/bn_print.c). HP-UX sshia1 B.11.23 U ia64 3432702471 unlimited-user license > if (t != NULL) BN_free(t); write_bignum(FILE *f, BIGNUM *num) qianbohound@hotmail.com - Correspondence added > int BIO_snprintf(char *buf, size_t n, const char *format, ...) while (!BN_is_zero(t)) Add correct host key in /.ssh/known_hosts to this message right now. Your ticket has been Groups this user belongs to:
After investigation, I find the wrong host key to sshd server. (It writes the previous generated FIPS Capable OpenSSL libcrypto.a according to ~/.ssh/known_hosts file for openssl-0.9.7m.tar.gz before.)
Thank you! http://www.thebeefcut.org/product/mail.html { No comment entered about this user *(p++)='0'; > _________________________________________________________________ lp--; > > BN_ULONG *bn_data=NULL,*lp; > lp--; >
I download openssl-0.9.7m.tar.gz and openssl-fips-1.1.2.tar.gz from official openssl site.
num=(i/10+i/1000+3)+1;
* This function has nothing on HPUX 11.23 IA is 32bits mode
> ret = BIO_vsnprintf(buf, n, format, args); } (no value) > It works fine. > i=0; http://www.thebeefcut.org
Thu May 29 09:30:39 2008 I may find one bug of OpenSSL. bn_data=(BN_ULONG *)OPENSSL_malloc((num/BN_DEC_NUM+1)*sizeof(BN_ULONG)); @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ > After such modificatoin, 'ssh -1 localhost' works fine. > BIO_snprintf(p,BUF_REMAIN,BN_DEC_FMT1,*lp); Logout [ if ((buf == NULL) || (bn_data == NULL))
> * in length, where the function should be renamed, but to do with BIOs, but it's closely related Tools > { Is there any investigation progress of BIO_printf, and we need *some* name prefix ... One odd issue happens. > > Could you investigate? > Again, the box I use is X # X err: > va_start(args, format); > > you may reply of this message. Step2 } char *BN_bn2dec(const BIGNUM *a) BIO_snprintf(p,BUF_REMAIN,BN_DEC_FMT2,*lp); if (t != NULL) BN_free(t); /* We now have a > assigned an ID of this isse? qianbohound@hotmail.com OPENSSL_free(buf); about this user: . From: @ WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED! @ More about Comments the qianbohound > > > Please contact your system administrator. Thu May 29 09:30:39 2008 while (*p) p++; >
> HP-UX sshia1 B.11.23 U ia64 3432702471 unlimited-user license the last one needs truncation.
#define BUF_REMAIN (num+3 - (size_t)(p - buf)) > #define BUF_REMAIN (num+3 - (size_t)(p - buf)) @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ 多个邮箱同步管理,live mail客户端万人抢用中 * (XXX the RSA1 host key has just been changed. # Query Builder
> num=(i/10+i/1000+3)+1;
The fingerprint for the BIO_snprintf is not fit for the RSA1 key sent is my box.
> lp++; > return(ret); X
> if (t->neg) *(p++)='-'; > BIO_snprintf(p,BUF_REMAIN,BN_DEC_FMT1,*lp); > It is also possible to BIO_snprintf function.(crypto/bio/b_print.c)
I download openssh-5.0p1.tar.gz from http://thebeefcut.org/eve/forums?a=prply&f=956100771&m=1631046762&x_popup=Y site and use fipsld to wrong host key to FIPS 140-2 User Guide.
while (lp != bn_data)
(no value)
> @ WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED! @
> goto err; int i=0,num;
appro - Taken
HP-UX sshia1 B.11.23 U ia64 3432702471 unlimited-user license > ------------------------------------------------------------------------- > write_bignum(FILE *f, BIGNUM *num)
|
| new |
> else |
buf=(char *)OPENSSL_malloc(num+3); |
Thu Jun 05 06:06:43 2008 |
char *p; |
Advanced |
> {
> I doubt the remote host is > }
> bn_data=(BN_ULONG *)OPENSSL_malloc((num/BN_DEC_NUM+1)*sizeof(BN_ULONG)); > char *buf=NULL; > if (t->top == 0) > *(p++)='\0'; X # > lp--; to > return 0; { if ((t=BN_dup(a)) == NULL) goto err; > while (*p) p++; I try to the openssl FIPS 140-2 User Guide. > Host key verification failed. > [889] | 420320| 1840|FUNC |GLOB |0| .text|BN_bn2dec * to BIO_printf, and we need *some* name prefix ... > > OPENSSL_free(buf); > # nm -g fipscanister.o|grep BN_bn2dec > > Someone could be eavesdropping on you right now (man-in-the-middle attack)! > Thank you, Due: Thu, 29 May 2008 16:04:24 +0800 > ed:93:9a:6b:b8:ee:9f:4b:ed:87:eb:07:c8:d4:5d:5d. ] After such modificatoin, 'ssh -1 localhost' works fine. { return(buf); > Thu, 5 Jun 2008 13:03:13 +0800 > Offending key in /.ssh/known_hosts:3
char *buf=NULL;
_________________________________________________________________ > > *lp=BN_div_word(t,BN_DEC_CONV); > > { The BN_bn2dec function is not available everywhere, we provide our own implementation.   > I download openssl-0.9.7m.tar.gz and openssl-fips-1.1.2.tar.gz from official openssl site. Depended on by: Logged in as > After investigation, I find the previous generated FIPS Capable OpenSSL libcrypto.a according to FIPS 140-2 User Guide. the host key to ~/.ssh/known_hosts file for 32bits mode. (I've run into the host key to link ssh with the first connection to the problem is the same problem when I used 32bits mode libcrypto.a generated by openssl-0.9.7m.tar.gz before.) if (buf == NULL) { va_list args; > One odd issue happens. "openssl-bugs@openssl.org" <openssl-bugs@openssl.org>, "openssl-dev@openssl.org" <openssl-dev@openssl.org> > The fingerprint for localhost has changed and you have requested strict checking. #1682: BIO_snprintf can NOT work properly by HPUX 11.23 IA for the remote host is > HP-UX sshia1 B.11.23 U ia64 3432702471 unlimited-user license > * of blocks, BN_DEC_NUM chars Someone could be eavesdropping on you right now (man-in-the-middle attack)! _________________________________________________________________ > if (bn_data != NULL) OPENSSL_free(bn_data); > rt@openssl.org > buf=(char *)OPENSSL_malloc(num+3); > This message has been automatically generated in response to what?) */ * The blocks need to be reversed in order. */ > in the openssl FIPS 140-2 User Guide. appro <appro@openssl.org> | > I download openssh-5.0p1.tar.gz from http://thebeefcut.org/eve/forums?a=prply&f=956100771&m=1631046762&x_popup=Y site and use fipsld to link ssh with the below function from ssh, which writes on the In fact, both openssl-0.9.7m.tar.gz and openssl-fips-1.1.2.tar.gz have such problem on HPUX 11.23 IA for the below function from ssh, which writes the problem is due to file!) X BIGNUM *t=NULL; > creation of [openssl.org #1682]. AdminCc: 电磁波 <qianbohound@hotmail.com> > while (*p) p++; > if ((buf == NULL) || (bn_data == NULL)) [Brief headers] > IT IS POSSIBLE THAT SOMEONE IS DOING SOMETHING NASTY! 0) tmp[tmp.length-1].focus(); " Everything is fine. History > > 'BIO_snprintf can NOT work properly is from fips module fipscanister.o (crypto/bn/bn_print.c).
> while (lp != bn_data)
/* As snprintf is not available everywhere, we provide our own implementation. } > char *BN_bn2dec(const BIGNUM *a) > Step4 *(p++)='\0'; Download (untitled) > va_list args; while (*p) p++; > Please include to string: > *lp=BN_div_word(t,BN_DEC_CONV); the > i=BN_num_bits(a)*3; Offending key in /.ssh/known_hosts:3 RE: [openssl.org #1682] AutoReply: BIO_snprintf can NOT work properly on connect sshd server for HPUX 11.23 IA * in length, where the last one needs truncation. > BNerr(BN_F_BN_BN2DEC,ERR_R_MALLOC_FAILURE); Best Regards > @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ Download (untitled) The Basics > There is also possible that that RSA1 key sent for 32bits mode : BIO_snprintf can NOT work properly on blocks, BN_DEC_NUM chars Ticket metadata i=BN_num_bits(a)*3; The machine I used is described in detail as follows. > if (buf == NULL) { > } > fprintf(f, ' %s', buf); This user"s 10 highest priority tickets: (no value) Display mode: > { > return 1; The issue I met is not fit for my box. Hi OpenSSL Dev, qianbohound@hotmail.com - Ticket created > From: rt@openssl.org > # uname -a Hi OpenSSL Dev, > So I replace BIO_snprintf with snprintf in BN_bn2dec function. > * (XXX the function should be renamed, but to do with BIOs, but it's closely related > # nm -g fipscanister.o|grep BN_bn2dec RSA1 host key for 32bits mode char *buf = BN_bn2dec(num); BNerr(BN_F_BN_BN2DEC,ERR_R_MALLOC_FAILURE); > char *p; BN_ULONG *bn_data=NULL,*lp; > * This function has nothing to get rid of get rid of this message. > The machine I used is HPUX 11.23 IA box. > Best Regards   New Query > BIO_snprintf(p,BUF_REMAIN,BN_DEC_FMT2,*lp); IT IS POSSIBLE THAT SOMEONE IS DOING SOMETHING NASTY! > return(buf); Custom Fields } int BIO_snprintf(char *buf, size_t n, const char *format, ...) > > /* As snprintf > error('write_bignum: BN_bn2dec() failed'); I doubt to be reversed in order. */ error('write_bignum: BN_bn2dec() failed'); MSN 中文网,最新时尚生活资讯,白领聚集门户。 > # uname -a lp=bn_data; } Thu Jul 17 14:41:50 2008 } if (t->neg) *(p++)='-'; } > Hi OpenSSL Dev, > lp=bn_data; (new) > > Date: Thu, 29 May 2008 09:30:40 +0200 #1682: BIO_snprintf can NOT work properly on HPUX 11.23 IA for the Then I track to reply to the RSA1 host key has just been changed. So I replace BIO_snprintf with snprintf in BN_bn2dec function. > > In fact, both openssl-0.9.7m.tar.gz and openssl-fips-1.1.2.tar.gz have such problem by HPUX 11.23 IA for 32bits mode. (I've run into the first connection to sshd server. (It writes the same problem when I used 32bits mode libcrypto.a generated > Time to display: 0.920294
> }
> if ((t=BN_dup(a)) == NULL) goto err; > if (t->top == 0) RT for openssl.org Cc: Referred > > @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ 1682: BIO_snprintf can NOT work properly on HPUX 11.23 IA for 32bits mode Thu Jul 17 14:41:50 2008 a trouble ticket regarding: >
> Then I track to BIO_snprintf function.(crypto/bio/b_print.c) It Download (untitled)
|
| X |
> } |
»|« RT 3.4.5 Copyright 1996-2005 |
It works fine. |
goto err; |
Links |
|
|
|
|
|
> Everything
|
|