Skip to content

cram-md5: do not accept challenge if own hostname is used#536

Merged
franku merged 7 commits intomasterfrom
dev/franku/master/cram-md5
Jul 1, 2020
Merged

cram-md5: do not accept challenge if own hostname is used#536
franku merged 7 commits intomasterfrom
dev/franku/master/cram-md5

Conversation

@franku
Copy link
Contributor

@franku franku commented Jun 3, 2020

based on master

@franku franku force-pushed the dev/franku/master/cram-md5 branch 6 times, most recently from 3de815d to 693cbcf Compare June 7, 2020 15:32
Copy link
Member

@pstorz pstorz left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Very good, this way the log messages are very
helpful.

@franku franku force-pushed the dev/franku/master/cram-md5 branch from 6116ef7 to 52ffda7 Compare June 9, 2020 12:02
@franku franku force-pushed the dev/franku/master/cram-md5 branch from c6caf94 to c116dae Compare June 9, 2020 16:15
@franku
Copy link
Contributor Author

franku commented Jun 9, 2020

Force pushed after hands-on review with arogge.

@franku franku force-pushed the dev/franku/master/cram-md5 branch 6 times, most recently from ccc1be6 to 81e2b03 Compare June 15, 2020 16:41
Copy link
Member

@arogge arogge left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good overall.
However, the test for two storages with different names is missing.

Maybe we should also find a better name for "Challenge Attack".

franku added 2 commits June 29, 2020 16:31
Fixes #1250: Authentication bypass in Director

use the unified-resource-name for the cram challenge
i.e. auth cram-md5 <1001326377.1591525437@R_CLIENT::backup-bareos-test-fd>
@franku franku force-pushed the dev/franku/master/cram-md5 branch from b7e6d21 to ae8d9e8 Compare June 29, 2020 16:14
@franku franku force-pushed the dev/franku/master/cram-md5 branch from ae8d9e8 to a105df3 Compare June 30, 2020 06:42
@franku franku merged commit fd28191 into master Jul 1, 2020
@franku franku deleted the dev/franku/master/cram-md5 branch July 3, 2020 13:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants