man.isc-hmac-fixup.html revision 369963ad26cef09c3839d76c74c2d856f91be27a
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster<!--
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster - Copyright (C) 2004-2014 Internet Systems Consortium, Inc. ("ISC")
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster - Copyright (C) 2000-2003 Internet Software Consortium.
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster -
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster - Permission to use, copy, modify, and/or distribute this software for any
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster - purpose with or without fee is hereby granted, provided that the above
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster - copyright notice and this permission notice appear in all copies.
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster -
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster - PERFORMANCE OF THIS SOFTWARE.
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster-->
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster<!-- $Id$ -->
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster<html>
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster<head>
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster<title>isc-hmac-fixup</title>
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster<meta name="generator" content="DocBook XSL Stylesheets V1.71.1">
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster<link rel="start" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster<link rel="up" href="Bv9ARM.ch10.html" title="Manual pages">
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster<link rel="prev" href="man.genrandom.html" title="genrandom">
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster<link rel="next" href="man.nsec3hash.html" title="nsec3hash">
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster</head>
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF">
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster<div class="navheader">
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster<table width="100%" summary="Navigation header">
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster<tr><th colspan="3" align="center"><span class="application">isc-hmac-fixup</span></th></tr>
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster<tr>
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster<td width="20%" align="left">
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster<a accesskey="p" href="man.genrandom.html">Prev</a>�</td>
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster<th width="60%" align="center">Manual pages</th>
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster<td width="20%" align="right">�<a accesskey="n" href="man.nsec3hash.html">Next</a>
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster</td>
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster</tr>
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster</table>
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster<hr>
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster</div>
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster<div class="refentry" lang="en">
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster<a name="man.isc-hmac-fixup"></a><div class="titlepage"></div>
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster<div class="refnamediv">
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster<h2>Name</h2>
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster<p><span class="application">isc-hmac-fixup</span> &#8212; fixes HMAC keys generated by older versions of BIND</p>
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster</div>
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster<div class="refsynopsisdiv">
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster<h2>Synopsis</h2>
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster<div class="cmdsynopsis"><p><code class="command">isc-hmac-fixup</code> {<em class="replaceable"><code>algorithm</code></em>} {<em class="replaceable"><code>secret</code></em>}</p></div>
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster</div>
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster<div class="refsect1" lang="en">
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster<a name="id2623523"></a><h2>DESCRIPTION</h2>
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster<p>
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster Versions of BIND 9 up to and including BIND 9.6 had a bug causing
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster HMAC-SHA* TSIG keys which were longer than the digest length of the
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster hash algorithm (i.e., SHA1 keys longer than 160 bits, SHA256 keys
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster longer than 256 bits, etc) to be used incorrectly, generating a
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster message authentication code that was incompatible with other DNS
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster implementations.
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster </p>
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster<p>
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster This bug has been fixed in BIND 9.7. However, the fix may
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster cause incompatibility between older and newer versions of
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster BIND, when using long keys. <span><strong class="command">isc-hmac-fixup</strong></span>
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster modifies those keys to restore compatibility.
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster </p>
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster<p>
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster To modify a key, run <span><strong class="command">isc-hmac-fixup</strong></span> and
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster specify the key's algorithm and secret on the command line. If the
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster secret is longer than the digest length of the algorithm (64 bytes
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster for SHA1 through SHA256, or 128 bytes for SHA384 and SHA512), then a
new secret will be generated consisting of a hash digest of the old
secret. (If the secret did not require conversion, then it will be
printed without modification.)
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2623550"></a><h2>SECURITY CONSIDERATIONS</h2>
<p>
Secrets that have been converted by <span><strong class="command">isc-hmac-fixup</strong></span>
are shortened, but as this is how the HMAC protocol works in
operation anyway, it does not affect security. RFC 2104 notes,
"Keys longer than [the digest length] are acceptable but the
extra length would not significantly increase the function
strength."
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2669032"></a><h2>SEE ALSO</h2>
<p>
<em class="citetitle">BIND 9 Administrator Reference Manual</em>,
<em class="citetitle">RFC 2104</em>.
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2669049"></a><h2>AUTHOR</h2>
<p><span class="corpauthor">Internet Systems Consortium</span>
</p>
</div>
</div>
<div class="navfooter">
<hr>
<table width="100%" summary="Navigation footer">
<tr>
<td width="40%" align="left">
<a accesskey="p" href="man.genrandom.html">Prev</a>�</td>
<td width="20%" align="center"><a accesskey="u" href="Bv9ARM.ch10.html">Up</a></td>
<td width="40%" align="right">�<a accesskey="n" href="man.nsec3hash.html">Next</a>
</td>
</tr>
<tr>
<td width="40%" align="left" valign="top">
<span class="application">genrandom</span>�</td>
<td width="20%" align="center"><a accesskey="h" href="Bv9ARM.html">Home</a></td>
<td width="40%" align="right" valign="top">�<span class="application">nsec3hash</span>
</td>
</tr>
</table>
</div>
<p style="text-align: center;">BIND 9.11.0pre-alpha</p>
</body>
</html>