man.isc-hmac-fixup.html revision f2016fcecf098726740507a5522dca04c49aeb82
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw<!--
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw - Copyright (C) 2004-2014 Internet Systems Consortium, Inc. ("ISC")
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw - Copyright (C) 2000-2003 Internet Software Consortium.
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw -
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw - Permission to use, copy, modify, and/or distribute this software for any
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw - purpose with or without fee is hereby granted, provided that the above
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw - copyright notice and this permission notice appear in all copies.
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw -
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw - PERFORMANCE OF THIS SOFTWARE.
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw-->
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw<!-- $Id$ -->
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw<html>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw<head>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw<title>isc-hmac-fixup</title>
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego<meta name="generator" content="DocBook XSL Stylesheets V1.71.1">
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw<link rel="start" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw<link rel="up" href="Bv9ARM.ch10.html" title="Manual pages">
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw<link rel="prev" href="man.genrandom.html" title="genrandom">
bbf6f00c25b6a2bed23c35eac6d62998ecdb338cJordan Brown<link rel="next" href="man.nsec3hash.html" title="nsec3hash">
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw</head>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF">
dc20a3024900c47dd2ee44b9707e6df38f7d62a5as<div class="navheader">
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw<table width="100%" summary="Navigation header">
b89a8333f5e1f75ec0c269b22524bd2eccb972banatalie li - Sun Microsystems - Irvine United States<tr><th colspan="3" align="center"><span class="application">isc-hmac-fixup</span></th></tr>
b89a8333f5e1f75ec0c269b22524bd2eccb972banatalie li - Sun Microsystems - Irvine United States<tr>
b89a8333f5e1f75ec0c269b22524bd2eccb972banatalie li - Sun Microsystems - Irvine United States<td width="20%" align="left">
e3f2c991a8548408db0a2787bd8b43d5124821d3Keyur Desai<a accesskey="p" href="man.genrandom.html">Prev</a>�</td>
037cac007b685e7ea79f6ef7e8e62bfd342a4d56joyce mcintosh<th width="60%" align="center">Manual pages</th>
b89a8333f5e1f75ec0c269b22524bd2eccb972banatalie li - Sun Microsystems - Irvine United States<td width="20%" align="right">�<a accesskey="n" href="man.nsec3hash.html">Next</a>
b89a8333f5e1f75ec0c269b22524bd2eccb972banatalie li - Sun Microsystems - Irvine United States</td>
b89a8333f5e1f75ec0c269b22524bd2eccb972banatalie li - Sun Microsystems - Irvine United States</tr>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw</table>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw<hr>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw</div>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw<div class="refentry" lang="en">
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw<a name="man.isc-hmac-fixup"></a><div class="titlepage"></div>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw<div class="refnamediv">
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw<h2>Name</h2>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw<p><span class="application">isc-hmac-fixup</span> &#8212; fixes HMAC keys generated by older versions of BIND</p>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw</div>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw<div class="refsynopsisdiv">
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw<h2>Synopsis</h2>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw<div class="cmdsynopsis"><p><code class="command">isc-hmac-fixup</code> {<em class="replaceable"><code>algorithm</code></em>} {<em class="replaceable"><code>secret</code></em>}</p></div>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw</div>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw<div class="refsect1" lang="en">
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw<a name="id2661316"></a><h2>DESCRIPTION</h2>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw<p>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw Versions of BIND 9 up to and including BIND 9.6 had a bug causing
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw HMAC-SHA* TSIG keys which were longer than the digest length of the
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw hash algorithm (i.e., SHA1 keys longer than 160 bits, SHA256 keys
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw longer than 256 bits, etc) to be used incorrectly, generating a
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw message authentication code that was incompatible with other DNS
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw implementations.
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw </p>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw<p>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw This bug has been fixed in BIND 9.7. However, the fix may
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw cause incompatibility between older and newer versions of
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw BIND, when using long keys. <span><strong class="command">isc-hmac-fixup</strong></span>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw modifies those keys to restore compatibility.
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw </p>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw<p>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw To modify a key, run <span><strong class="command">isc-hmac-fixup</strong></span> and
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw specify the key's algorithm and secret on the command line. If the
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw secret is longer than the digest length of the algorithm (64 bytes
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw for SHA1 through SHA256, or 128 bytes for SHA384 and SHA512), then a
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw new secret will be generated consisting of a hash digest of the old
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw secret. (If the secret did not require conversion, then it will be
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw printed without modification.)
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw </p>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw</div>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw<div class="refsect1" lang="en">
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw<a name="id2661344"></a><h2>SECURITY CONSIDERATIONS</h2>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw<p>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw Secrets that have been converted by <span><strong class="command">isc-hmac-fixup</strong></span>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw are shortened, but as this is how the HMAC protocol works in
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw operation anyway, it does not affect security. RFC 2104 notes,
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw "Keys longer than [the digest length] are acceptable but the
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw extra length would not significantly increase the function
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw strength."
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw </p>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw</div>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw<div class="refsect1" lang="en">
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw<a name="id2661360"></a><h2>SEE ALSO</h2>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw<p>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw <em class="citetitle">BIND 9 Administrator Reference Manual</em>,
7b59d02d2a384be9a08087b14defadd214b3c1ddjb <em class="citetitle">RFC 2104</em>.
faa1795a28a5c712eed6d0a3f84d98c368a316c6jb </p>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw</div>
faa1795a28a5c712eed6d0a3f84d98c368a316c6jb<div class="refsect1" lang="en">
b89a8333f5e1f75ec0c269b22524bd2eccb972banatalie li - Sun Microsystems - Irvine United States<a name="id2661377"></a><h2>AUTHOR</h2>
b89a8333f5e1f75ec0c269b22524bd2eccb972banatalie li - Sun Microsystems - Irvine United States<p><span class="corpauthor">Internet Systems Consortium</span>
b89a8333f5e1f75ec0c269b22524bd2eccb972banatalie li - Sun Microsystems - Irvine United States </p>
faa1795a28a5c712eed6d0a3f84d98c368a316c6jb</div>
eb1d736b1c19f6abeee90c921a9320b67fedd016afshin salek ardakani - Sun Microsystems - Irvine United States</div>
eb1d736b1c19f6abeee90c921a9320b67fedd016afshin salek ardakani - Sun Microsystems - Irvine United States<div class="navfooter">
faa1795a28a5c712eed6d0a3f84d98c368a316c6jb<hr>
b89a8333f5e1f75ec0c269b22524bd2eccb972banatalie li - Sun Microsystems - Irvine United States<table width="100%" summary="Navigation footer">
faa1795a28a5c712eed6d0a3f84d98c368a316c6jb<tr>
faa1795a28a5c712eed6d0a3f84d98c368a316c6jb<td width="40%" align="left">
faa1795a28a5c712eed6d0a3f84d98c368a316c6jb<a accesskey="p" href="man.genrandom.html">Prev</a>�</td>
faa1795a28a5c712eed6d0a3f84d98c368a316c6jb<td width="20%" align="center"><a accesskey="u" href="Bv9ARM.ch10.html">Up</a></td>
faa1795a28a5c712eed6d0a3f84d98c368a316c6jb<td width="40%" align="right">�<a accesskey="n" href="man.nsec3hash.html">Next</a>
faa1795a28a5c712eed6d0a3f84d98c368a316c6jb</td>
faa1795a28a5c712eed6d0a3f84d98c368a316c6jb</tr>
faa1795a28a5c712eed6d0a3f84d98c368a316c6jb<tr>
faa1795a28a5c712eed6d0a3f84d98c368a316c6jb<td width="40%" align="left" valign="top">
faa1795a28a5c712eed6d0a3f84d98c368a316c6jb<span class="application">genrandom</span>�</td>
c8ec8eea9849cac239663c46be8a7f5d2ba7ca00jose borrego<td width="20%" align="center"><a accesskey="h" href="Bv9ARM.html">Home</a></td>
c8ec8eea9849cac239663c46be8a7f5d2ba7ca00jose borrego<td width="40%" align="right" valign="top">�<span class="application">nsec3hash</span>
c8ec8eea9849cac239663c46be8a7f5d2ba7ca00jose borrego</td>
b89a8333f5e1f75ec0c269b22524bd2eccb972banatalie li - Sun Microsystems - Irvine United States</tr>
b89a8333f5e1f75ec0c269b22524bd2eccb972banatalie li - Sun Microsystems - Irvine United States</table>
b89a8333f5e1f75ec0c269b22524bd2eccb972banatalie li - Sun Microsystems - Irvine United States</div>
b89a8333f5e1f75ec0c269b22524bd2eccb972banatalie li - Sun Microsystems - Irvine United States</body>
b89a8333f5e1f75ec0c269b22524bd2eccb972banatalie li - Sun Microsystems - Irvine United States</html>
b89a8333f5e1f75ec0c269b22524bd2eccb972banatalie li - Sun Microsystems - Irvine United States