man.isc-hmac-fixup.html revision 66f25f2ceeb589e67efe7af2413baaa3426b0042
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe<!--
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe - Copyright (C) 2004-2010 Internet Systems Consortium, Inc. ("ISC")
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe - Copyright (C) 2000-2003 Internet Software Consortium.
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe -
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe - Permission to use, copy, modify, and/or distribute this software for any
ed22c7109fc5dd9e1b7a5d0333bdc7ad2718e2abYuri Pankov - purpose with or without fee is hereby granted, provided that the above
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe - copyright notice and this permission notice appear in all copies.
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe -
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe - PERFORMANCE OF THIS SOFTWARE.
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe-->
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe<!-- $Id: man.isc-hmac-fixup.html,v 1.26 2010/12/26 01:14:08 tbox Exp $ -->
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe<html>
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe<head>
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe<title>isc-hmac-fixup</title>
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe<meta name="generator" content="DocBook XSL Stylesheets V1.71.1">
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe<link rel="start" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe<link rel="up" href="Bv9ARM.ch10.html" title="Manual pages">
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe<link rel="prev" href="man.genrandom.html" title="genrandom">
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe<link rel="next" href="man.nsec3hash.html" title="nsec3hash">
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe</head>
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF">
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe<div class="navheader">
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe<table width="100%" summary="Navigation header">
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe<tr><th colspan="3" align="center"><span class="application">isc-hmac-fixup</span></th></tr>
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe<tr>
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe<td width="20%" align="left">
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe<a accesskey="p" href="man.genrandom.html">Prev</a>�</td>
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe<th width="60%" align="center">Manual pages</th>
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe<td width="20%" align="right">�<a accesskey="n" href="man.nsec3hash.html">Next</a>
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe</td>
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe</tr>
ed22c7109fc5dd9e1b7a5d0333bdc7ad2718e2abYuri Pankov</table>
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe<hr>
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe</div>
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe<div class="refentry" lang="en">
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe<a name="man.isc-hmac-fixup"></a><div class="titlepage"></div>
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe<div class="refnamediv">
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe<h2>Name</h2>
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe<p><span class="application">isc-hmac-fixup</span> &#8212; fixes HMAC keys generated by older versions of BIND</p>
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe</div>
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe<div class="refsynopsisdiv">
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe<h2>Synopsis</h2>
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe<div class="cmdsynopsis"><p><code class="command">isc-hmac-fixup</code> {<em class="replaceable"><code>algorithm</code></em>} {<em class="replaceable"><code>secret</code></em>}</p></div>
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe</div>
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe<div class="refsect1" lang="en">
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe<a name="id2616929"></a><h2>DESCRIPTION</h2>
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe<p>
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe Versions of BIND 9 up to and including BIND 9.6 had a bug causing
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe HMAC-SHA* TSIG keys which were longer than the digest length of the
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe hash algorithm (i.e., SHA1 keys longer than 160 bits, SHA256 keys
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe longer than 256 bits, etc) to be used incorrectly, generating a
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe message authentication code that was incompatible with other DNS
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe implementations.
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe </p>
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe<p>
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe This bug has been fixed in BIND 9.7. However, the fix may
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe cause incompatibility between older and newer versions of
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe BIND, when using long keys. <span><strong class="command">isc-hmac-fixup</strong></span>
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe modifies those keys to restore compatibility.
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe </p>
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe<p>
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe To modify a key, run <span><strong class="command">isc-hmac-fixup</strong></span> and
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe specify the key's algorithm and secret on the command line. If the
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe secret is longer than the digest length of the algorithm (64 bytes
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe for SHA1 through SHA256, or 128 bytes for SHA384 and SHA512), then a
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe new secret will be generated consisting of a hash digest of the old
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe secret. (If the secret did not require conversion, then it will be
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe printed without modification.)
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe </p>
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe</div>
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe<div class="refsect1" lang="en">
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe<a name="id2651499"></a><h2>SECURITY CONSIDERATIONS</h2>
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe<p>
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe Secrets that have been converted by <span><strong class="command">isc-hmac-fixup</strong></span>
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe are shortened, but as this is how the HMAC protocol works in
c10c16dec587a0662068f6e2991c29ed3a9db943Richard Lowe operation anyway, it does not affect security. RFC 2104 notes,
"Keys longer than [the digest length] are acceptable but the
extra length would not significantly increase the function
strength."
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2651515"></a><h2>SEE ALSO</h2>
<p>
<em class="citetitle">BIND 9 Administrator Reference Manual</em>,
<em class="citetitle">RFC 2104</em>.
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2651532"></a><h2>AUTHOR</h2>
<p><span class="corpauthor">Internet Systems Consortium</span>
</p>
</div>
</div>
<div class="navfooter">
<hr>
<table width="100%" summary="Navigation footer">
<tr>
<td width="40%" align="left">
<a accesskey="p" href="man.genrandom.html">Prev</a>�</td>
<td width="20%" align="center"><a accesskey="u" href="Bv9ARM.ch10.html">Up</a></td>
<td width="40%" align="right">�<a accesskey="n" href="man.nsec3hash.html">Next</a>
</td>
</tr>
<tr>
<td width="40%" align="left" valign="top">
<span class="application">genrandom</span>�</td>
<td width="20%" align="center"><a accesskey="h" href="Bv9ARM.html">Home</a></td>
<td width="40%" align="right" valign="top">�<span class="application">nsec3hash</span>
</td>
</tr>
</table>
</div>
</body>
</html>