Unix Technical Forum

ap_SHA1Update Broken?

This is a discussion on ap_SHA1Update Broken? within the mailing.openbsd.tech forums, part of the OpenBSD category; --> I'm hoping somebody can independently whip up a test to confirm, but I think the SHA1 implementation in Apache ...


Go Back   Unix Technical Forum > Unix Operating Systems > OpenBSD > mailing.openbsd.tech

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 02-18-2008, 07:38 AM
William Ahern
 
Posts: n/a
Default ap_SHA1Update Broken?

I'm hoping somebody can independently whip up a test to confirm, but I think
the SHA1 implementation in Apache in broken for 64-bit platforms.

I had written an HMAC implementation using it (for mod_auth_bsd), and was
getting different HMAC's for the same inputs. So, then I tried a straight
hash of a static string and am still getting different outputs everytime. It
seems so improbable, so I'm hoping somebody could throw together a test to
confirm. In the mean time I'll try to pull out the SHA1 code and try testing
it outside of my module (in case my module is doing something funky).

I'm not very adept at bit twiddling, so I can't examine the Apache code
directly w/ any confidence.

MD5 seems to work find, BTW.

- Bill

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT. The time now is 05:26 PM.


Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0
www.UnixAdminTalk.com