6 * Copyright (C) 2010 pier11 <pier11@operamail.com>
7 * Copyright (C) 2008 Novell, Inc.
9 * Implemented with reference to the follow documentation:
10 * - http://davenport.sourceforge.net/ntlm.html
11 * - MS-NLMP: http://msdn.microsoft.com/en-us/library/cc207842.aspx
12 * - MS-SIP : http://msdn.microsoft.com/en-us/library/cc246115.aspx
14 * Please use "make tests" to build & run them!
16 * This program is free software; you can redistribute it and/or modify
17 * it under the terms of the GNU General Public License as published by
18 * the Free Software Foundation; either version 2 of the License, or
19 * (at your option) any later version.
21 * This program is distributed in the hope that it will be useful,
22 * but WITHOUT ANY WARRANTY; without even the implied warranty of
23 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
24 * GNU General Public License for more details.
26 * You should have received a copy of the GNU General Public License
27 * along with this program; if not, write to the Free Software
28 * Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
34 #include "sipe-sign.h"
35 #define _SIPE_COMPILING_TESTS
36 #include "sip-sec-ntlm.c"
40 static int successes
= 0;
41 static int failures
= 0;
43 static void assert_equal(const char * expected
, const guchar
* got
, int len
, gboolean stringify
)
45 const gchar
* res
= (gchar
*) got
;
50 for (i
= 0, j
= 0; i
< len
; i
++, j
+=2) {
51 g_sprintf(&to_str
[j
], "%02X", (got
[i
]&0xff));
57 printf("expected: %s\n", expected
);
58 printf("received: %s\n", res
);
60 if (g_ascii_strncasecmp(expected
, res
, len
) == 0) {
69 /* NOTE: both values are expected to be in host byte order! */
70 static void assert_equal_guint32(guint32 expected
, guint32 got
)
72 printf("expected: %08X\n", expected
);
73 printf("received: %08X\n", got
);
75 if (expected
== got
) {
86 printf ("Starting Tests\n");
88 /* Initialization that libpurple/core.c would normally do */
89 purple_signals_init();
91 purple_debug_set_enabled(TRUE
);
92 purple_ciphers_init();
95 /* These tests are from the MS-SIPE document */
97 const char * password
= "Password";
98 const char * user
= "User";
99 const char * domain
= "Domain";
100 const guchar client_challenge
[] = {0xaa, 0xaa, 0xaa, 0xaa, 0xaa, 0xaa, 0xaa, 0xaa};
101 /* server challenge */
102 const guchar nonce
[] = {0x01, 0x23, 0x45, 0x67, 0x89, 0xab, 0xcd, 0xef};
104 const guchar exported_session_key
[] = {0x55, 0x55, 0x55, 0x55, 0x55, 0x55, 0x55, 0x55, 0x55, 0x55, 0x55, 0x55, 0x55, 0x55, 0x55, 0x55};
105 const guchar text
[] = {0x50, 0x00, 0x6c, 0x00, 0x61, 0x00, 0x69, 0x00, 0x6e, 0x00, 0x74, 0x00, 0x65, 0x00, 0x78, 0x00, 0x74, 0x00}; //P·l·a·i·n·t·e·x·t·
108 ////// internal Cyphers tests ///////
109 printf ("\nTesting MD4()\n");
111 MD4 ((const unsigned char *)"message digest", 14, md4
);
112 assert_equal("D9130A8164549FE818874806E1C7014B", md4
, 16, TRUE
);
114 printf ("\nTesting MD5()\n");
116 MD5 ((const unsigned char *)"message digest", 14, md5
);
117 assert_equal("F96B697D7CB7938D525A2F31AAF161D0", md5
, 16, TRUE
);
119 printf ("\nTesting HMAC_MD5()\n");
120 guchar hmac_md5
[16];
121 HMAC_MD5 ((const unsigned char *)"\x0b\x0b\x0b\x0b\x0b\x0b\x0b\x0b\x0b\x0b\x0b\x0b\x0b\x0b\x0b\x0b", 16, (const unsigned char *)"Hi There", 8, hmac_md5
);
122 assert_equal("9294727A3638BB1C13F48EF8158BFC9D", hmac_md5
, 16, TRUE
);
125 ////// NTLMv1 (without Extended Session Security) ///////
129 | NTLMSSP_NEGOTIATE_KEY_EXCH
130 | NTLMSSP_NEGOTIATE_56
131 | NTLMSSP_NEGOTIATE_128
132 | NTLMSSP_NEGOTIATE_VERSION
133 | NTLMSSP_TARGET_TYPE_SERVER
134 | NTLMSSP_NEGOTIATE_ALWAYS_SIGN
135 | NTLMSSP_NEGOTIATE_NTLM
136 | NTLMSSP_NEGOTIATE_SEAL
137 | NTLMSSP_NEGOTIATE_SIGN
138 | NTLMSSP_NEGOTIATE_OEM
139 | NTLMSSP_NEGOTIATE_UNICODE
;
141 printf ("\n\nTesting Negotiation Flags\n");
142 assert_equal_guint32(0xE2028233, flags
);
144 printf ("\n\nTesting LMOWFv1()\n");
145 guchar response_key_lm
[16];
146 LMOWFv1 (password
, user
, domain
, response_key_lm
);
147 assert_equal("E52CAC67419A9A224A3B108F3FA6CB6D", response_key_lm
, 16, TRUE
);
149 printf ("\n\nTesting NTOWFv1()\n");
150 guchar response_key_nt
[16];
151 NTOWFv1 (password
, user
, domain
, response_key_nt
);
152 assert_equal("A4F49C406510BDCAB6824EE7C30FD852", response_key_nt
, 16, TRUE
);
154 printf ("\n\nTesting LM Response Generation\n");
155 printf ("Testing NT Response Generation\n");
156 printf ("Testing Session Base Key\n");
157 guchar nt_challenge_response
[24];
158 guchar lm_challenge_response
[24];
159 guchar session_base_key
[16];
161 compute_response(flags
,
167 NULL
, /* target_info */
168 0, /* target_info_len */
169 lm_challenge_response
, /* out */
170 nt_challenge_response
, /* out */
171 session_base_key
); /* out */
173 assert_equal("98DEF7B87F88AA5DAFE2DF779688A172DEF11C7D5CCDEF13", lm_challenge_response
, 24, TRUE
);
174 assert_equal("67C43011F30298A2AD35ECE64F16331C44BDBED927841F94", nt_challenge_response
, 24, TRUE
);
175 assert_equal("D87262B0CDE4B1CB7499BECCCDF10784", session_base_key
, 16, TRUE
);
177 printf ("\n\nTesting Key Exchange Key\n");
178 guchar key_exchange_key
[16];
179 KXKEY(flags
, session_base_key
, lm_challenge_response
, nonce
, key_exchange_key
);
180 assert_equal("D87262B0CDE4B1CB7499BECCCDF10784", key_exchange_key
, 16, TRUE
);
182 printf ("\n\nTesting Encrypted Session Key Generation\n");
183 guchar encrypted_random_session_key
[16];
184 RC4K (key_exchange_key
, 16, exported_session_key
, 16, encrypted_random_session_key
);
185 assert_equal("518822B1B3F350C8958682ECBB3E3CB7", encrypted_random_session_key
, 16, TRUE
);
187 printf ("\n\nTesting CRC32\n");
188 guint32 crc
= CRC32((char*)text
, 18);
189 assert_equal_guint32(0x93AA847D, crc
);
191 printf ("\n\nTesting Encryption\n");
192 guchar client_seal_key
[16];
193 //SEALKEY (flags, exported_session_key, TRUE, client_seal_key);
194 guchar buff
[18 + 12];
195 memcpy(buff
, text
, 18);
196 guchar text_enc
[18 + 12];
198 to_enc
[0] = GUINT32_TO_LE(0); // random pad
199 to_enc
[1] = GUINT32_TO_LE(crc
);
200 to_enc
[2] = GUINT32_TO_LE(0); // zero
201 memcpy(buff
+18, (gchar
*)to_enc
, 12);
202 RC4K (exported_session_key
, 16, buff
, 18 + 12, text_enc
);
203 //The point is to not reinitialize rc4 cypher
205 assert_equal("56FE04D861F9319AF0D7238A2E3B4D457FB8" "45C844E5" "09DCD1DF" "2E459D36", text_enc
, 18 + 12, TRUE
);
207 printf ("\n\nTesting MAC\n");
209 // won't work in the case with sealing because RC4 is re-initialized inside.
210 // MAC (flags, (gchar*)text, 18, (guchar*)exported_session_key, 16, (guchar*)exported_session_key,16, 0x00000000, 0, mac);
212 memcpy((gchar
*)enc
, text_enc
+18, 12);
214 mac2
[0] = GUINT32_TO_LE(1); // version
217 mac2
[3] = enc
[2] ^ (GUINT32_TO_LE(0)); // ^ seq
218 assert_equal("0100000045C844E509DCD1DF2E459D36", (guchar
*)mac2
, 16, TRUE
);
221 ////// EXTENDED_SESSIONSECURITY ///////
224 | NTLMSSP_NEGOTIATE_56
225 | NTLMSSP_NEGOTIATE_VERSION
226 | NTLMSSP_NEGOTIATE_EXTENDED_SESSIONSECURITY
227 | NTLMSSP_TARGET_TYPE_SERVER
228 | NTLMSSP_NEGOTIATE_ALWAYS_SIGN
229 | NTLMSSP_NEGOTIATE_NTLM
230 | NTLMSSP_NEGOTIATE_SEAL
231 | NTLMSSP_NEGOTIATE_SIGN
232 | NTLMSSP_NEGOTIATE_OEM
233 | NTLMSSP_NEGOTIATE_UNICODE
;
235 printf ("\n\n(Extended session security) Testing Negotiation Flags\n");
236 assert_equal_guint32(0x820A8233, flags
);
238 /* NTOWFv1() is not different from the above test for the same */
240 printf ("\n\n(Extended session security) Testing LM Response\n");
241 printf ("(Extended session security) Testing NT Response\n");
242 printf ("(Extended session security) Testing Session Base Key\n");
243 compute_response(flags
,
249 NULL
, /* target_info */
250 0, /* target_info_len */
251 lm_challenge_response
, /* out */
252 nt_challenge_response
, /* out */
253 session_base_key
); /* out */
255 assert_equal("AAAAAAAAAAAAAAAA00000000000000000000000000000000", lm_challenge_response
, 24, TRUE
);
256 assert_equal("7537F803AE367128CA458204BDE7CAF81E97ED2683267232", nt_challenge_response
, 24, TRUE
);
257 assert_equal("D87262B0CDE4B1CB7499BECCCDF10784", session_base_key
, 16, TRUE
);
259 printf ("\n\n(Extended session security) Testing Key Exchange Key\n");
260 KXKEY(flags
, session_base_key
, lm_challenge_response
, nonce
, key_exchange_key
);
261 assert_equal("EB93429A8BD952F8B89C55B87F475EDC", key_exchange_key
, 16, TRUE
);
263 printf ("\n\n(Extended session security) SIGNKEY\n");
264 guchar client_sign_key
[16];
265 SIGNKEY (key_exchange_key
, TRUE
, client_sign_key
);
266 assert_equal("60E799BE5C72FC92922AE8EBE961FB8D", client_sign_key
, 16, TRUE
);
268 printf ("\n\n(Extended session security) SEALKEY\n");
269 SEALKEY (flags
, key_exchange_key
, TRUE
, client_seal_key
);
270 assert_equal("04DD7F014D8504D265A25CC86A3A7C06", client_seal_key
, 16, TRUE
);
272 printf ("\n\n(Extended session security) Testing Encryption\n");
273 RC4K (client_seal_key
, 16, text
, 18, text_enc
);
274 assert_equal("A02372F6530273F3AA1EB90190CE5200C99D", text_enc
, 18, TRUE
);
276 printf ("\n\n(Extended session security) Testing MAC\n");
277 MAC (flags
, (gchar
*)text
,18, client_sign_key
,16, client_seal_key
,16, 0, 0, mac
);
278 assert_equal("01000000FF2AEB52F681793A00000000", mac
, 16, TRUE
);
281 ////// NTLMv2 ///////
284 | NTLMSSP_NEGOTIATE_KEY_EXCH
285 | NTLMSSP_NEGOTIATE_56
286 | NTLMSSP_NEGOTIATE_128
287 | NTLMSSP_NEGOTIATE_VERSION
288 | NTLMSSP_NEGOTIATE_TARGET_INFO
289 | NTLMSSP_NEGOTIATE_EXTENDED_SESSIONSECURITY
290 | NTLMSSP_TARGET_TYPE_SERVER
291 | NTLMSSP_NEGOTIATE_ALWAYS_SIGN
292 | NTLMSSP_NEGOTIATE_NTLM
293 | NTLMSSP_NEGOTIATE_SEAL
294 | NTLMSSP_NEGOTIATE_SIGN
295 | NTLMSSP_NEGOTIATE_OEM
296 | NTLMSSP_NEGOTIATE_UNICODE
;
298 printf ("\n\nTesting (NTLMv2) Negotiation Flags\n");
299 assert_equal_guint32(0xE28A8233, flags
);
301 printf ("\n\nTesting NTOWFv2()\n");
302 NTOWFv2 (password
, user
, domain
, response_key_nt
);
303 NTOWFv2 (password
, user
, domain
, response_key_lm
);
304 assert_equal("0C868A403BFD7A93A3001EF22EF02E3F", response_key_nt
, 16, TRUE
);
307 printf ("\n\nTesting (NTLMv2) LM Response Generation\n");
308 printf ("Testing (NTLMv2) NT Response Generation and Session Base Key\n");
311 4e544c4d53535000020000000c000c003800000033828ae20123456789abcdef00000000000000002400240044000000060070170000000f53006500720076006500720002000c0044006f006d00610069006e0001000c0053006500720076006500720000000000
313 NTLMSSP_NEGOTIATE_UNICODE
314 NTLMSSP_NEGOTIATE_OEM
315 NTLMSSP_NEGOTIATE_SIGN
316 NTLMSSP_NEGOTIATE_SEAL
317 NTLMSSP_NEGOTIATE_NTLM
318 NTLMSSP_NEGOTIATE_ALWAYS_SIGN
319 NTLMSSP_TARGET_TYPE_SERVER
320 NTLMSSP_NEGOTIATE_EXTENDED_SESSIONSECURITY
321 NTLMSSP_NEGOTIATE_TARGET_INFO
322 NTLMSSP_NEGOTIATE_VERSION
323 NTLMSSP_NEGOTIATE_128
324 NTLMSSP_NEGOTIATE_KEY_EXCH
327 target_name.maxlen: 12
328 target_name.offset: 56
330 target_info.maxlen: 36
331 target_info.offset: 68
332 product: 6.0.6000 (Windows Vista, Windows Server 2008, Windows 7 or Windows Server 2008 R2)
333 ntlm_revision_current: 0x0F (NTLMSSP_REVISION_W2K3)
335 MsvAvNbDomainName: Domain
336 MsvAvNbComputerName: Server
339 530065007200760065007200
341 02000c0044006f006d00610069006e0001000c0053006500720076006500720000000000
344 4e544c4d5353500003000000180018006c00000054005400840000000c000c00480000000800080054000000100010005c00000010001000d8000000358288e20501280a0000000f44006f006d00610069006e00550073006500720043004f004d005000550054004500520086c35097ac9cec102554764a57cccc19aaaaaaaaaaaaaaaa68cd0ab851e51c96aabc927bebef6a1c01010000000000000000000000000000aaaaaaaaaaaaaaaa0000000002000c0044006f006d00610069006e0001000c005300650072007600650072000000000000000000c5dad2544fc9799094ce1ce90bc9d03e
348 const guint64 time_val
= 0;
349 const guint8 target_info
[] = {
350 0x02, 0x00, 0x0C, 0x00, //NetBIOS Domain name, 4 bytes
351 0x44, 0x00, 0x6F, 0x00, 0x6D, 0x00, 0x61, 0x00, 0x69, 0x00, 0x6E, 0x00, //D.o.m.a.i.n. 12bytes
352 0x01, 0x00, 0x0C, 0x00, //NetBIOS Server name, 4 bytes
353 0x53, 0x00, 0x65, 0x00, 0x72, 0x00, 0x76, 0x00, 0x65, 0x00, 0x72, 0x00, //S.e.r.v.e.r. 12bytes
354 0x00, 0x00, 0x00, 0x00, //Av End, 4 bytes
356 const int target_info_len
= 32+4;
357 int ntlmssp_nt_resp_len
= (16 + (32+target_info_len
));
358 guchar nt_challenge_response_v2
[ntlmssp_nt_resp_len
];
360 compute_response(flags
,
366 target_info
, /* target_info */
367 target_info_len
, /* target_info_len */
368 lm_challenge_response
, /* out */
369 nt_challenge_response_v2
, /* out */
370 session_base_key
); /* out */
372 assert_equal("86C35097AC9CEC102554764A57CCCC19AAAAAAAAAAAAAAAA", lm_challenge_response
, 24, TRUE
);
373 assert_equal("68CD0AB851E51C96AABC927BEBEF6A1C", nt_challenge_response_v2
, 16, TRUE
);
374 /* the ref string is taken from binary dump of AUTHENTICATE_MESSAGE */
375 assert_equal("68CD0AB851E51C96AABC927BEBEF6A1C01010000000000000000000000000000AAAAAAAAAAAAAAAA0000000002000C0044006F006D00610069006E0001000C005300650072007600650072000000000000000000", nt_challenge_response_v2
, ntlmssp_nt_resp_len
, TRUE
);
376 assert_equal("8DE40CCADBC14A82F15CB0AD0DE95CA3", session_base_key
, 16, TRUE
);
378 printf ("\n\nTesting (NTLMv2) Encrypted Session Key\n");
379 // key_exchange_key = session_base_key for NTLMv2
380 KXKEY(flags
, session_base_key
, lm_challenge_response
, nonce
, key_exchange_key
);
381 //RC4 encryption of the RandomSessionKey with the KeyExchangeKey:
382 RC4K (key_exchange_key
, 16, exported_session_key
, 16, encrypted_random_session_key
);
383 assert_equal("C5DAD2544FC9799094CE1CE90BC9D03E", encrypted_random_session_key
, 16, TRUE
);
385 printf ("\n\nTesting (NTLMv2) SIGNKEY\n");
386 SIGNKEY (exported_session_key
, TRUE
, client_sign_key
);
387 assert_equal("4788DC861B4782F35D43FD98FE1A2D39", client_sign_key
, 16, TRUE
);
389 printf ("\n\nTesting (NTLMv2) SEALKEY\n");
390 SEALKEY (flags
, exported_session_key
, TRUE
, client_seal_key
);
391 assert_equal("59F600973CC4960A25480A7C196E4C58", client_seal_key
, 16, TRUE
);
393 printf ("\n\nTesting (NTLMv2) Encryption\n");
394 RC4K (client_seal_key
, 16, text
, 18, text_enc
);
395 assert_equal("54E50165BF1936DC996020C1811B0F06FB5F", text_enc
, 18, TRUE
);
397 // printf ("\n\nTesting (NTLMv2) Encryption\n");
398 //const guchar text2 [] = {0x50, 0x00, 0x6c, 0x00, 0x61, 0x00, 0x69, 0x00, 0x6e, 0x00, 0x74, 0x00, 0x65, 0x00, 0x78, 0x00, 0x74, 0x00
399 // , 0x70, 0x35, 0x28, 0x51, 0xf2, 0x56, 0x43, 0x09}; //P·l·a·i·n·t·e·x·t·
400 //guchar text_enc2 [18+8];
401 // RC4K (client_seal_key, 16, text2, 18+8, text_enc2);
402 // assert_equal("54E50165BF1936DC996020C1811B0F06FB5F", text_enc2, 18+8, TRUE);
404 printf ("\n\nTesting (NTLMv2) MAC (without RC4, as we don't keep its handle yet)\n");
405 MAC (flags
& ~NTLMSSP_NEGOTIATE_KEY_EXCH
, (gchar
*)text
,18, client_sign_key
,16, client_seal_key
,16, 0, 0, mac
);
406 assert_equal("0100000070352851F256430900000000", mac
, 16, TRUE
);
409 /* End tests from the MS-SIPE document */
412 ////// davenport tests ///////
413 // Test from http://davenport.sourceforge.net/ntlm.html#ntlm1Signing
414 const gchar
*text_j
= "jCIFS";
415 printf ("\n\n(davenport) Testing Signature Algorithm\n");
416 guchar sk
[] = {0x01, 0x02, 0x03, 0x04, 0x05, 0xe5, 0x38, 0xb0};
417 MAC (NEGOTIATE_FLAGS_CONNLESS
& ~NTLMSSP_NEGOTIATE_EXTENDED_SESSIONSECURITY
, text_j
, strlen(text_j
), sk
, 8, sk
,8, 0x00090178, 0, mac
);
418 assert_equal("0100000078010900397420FE0E5A0F89", mac
, 16, TRUE
);
420 // Tests from http://davenport.sourceforge.net/ntlm.html#ntlm2Signing
421 printf ("\n\n(davenport) SIGNKEY\n");
422 const guchar master_key
[] = {0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07, 0x08, 0x09, 0x0a, 0x0b, 0x0c, 0x0d, 0x0e, 0x0f, 0x00};
423 SIGNKEY (master_key
, TRUE
, client_sign_key
);
424 assert_equal("F7F97A82EC390F9C903DAC4F6ACEB132", client_sign_key
, 16, TRUE
);
426 printf ("\n\n(davenport) Testing MAC - no Key Exchange flag\n");
427 MAC (flags
& ~NTLMSSP_NEGOTIATE_KEY_EXCH
, text_j
, strlen(text_j
), client_sign_key
, 16, client_sign_key
,16, 0, 0, mac
);
428 assert_equal("010000000A003602317A759A00000000", mac
, 16, TRUE
);
431 ////// SIPE internal tests ///////
432 // Verify signature of SIPE message received from OCS 2007 after authenticating with pidgin-sipe
433 printf ("\n\nTesting MS-SIPE Example Message Signing\n");
434 char * msg1
= "<NTLM><0878F41B><1><SIP Communications Service><ocs1.ocs.provo.novell.com><8592g5DCBa1694i5887m0D0Bt2247b3F38xAE9Fx><3><REGISTER><sip:gabriel@ocs.provo.novell.com><2947328781><B816D65C2300A32CFA6D371F2AF537FD><900><200>";
435 guchar exported_session_key2
[] = { 0x5F, 0x02, 0x91, 0x53, 0xBC, 0x02, 0x50, 0x58, 0x96, 0x95, 0x48, 0x61, 0x5E, 0x70, 0x99, 0xBA };
436 MAC (NEGOTIATE_FLAGS_CONNLESS
& ~NTLMSSP_NEGOTIATE_EXTENDED_SESSIONSECURITY
,
437 msg1
, strlen(msg1
), exported_session_key2
, 16, exported_session_key2
,16, 0, 100, mac
);
438 assert_equal("0100000000000000BF2E52667DDF6DED", mac
, 16, TRUE
);
440 // Verify parsing of message and signature verification
441 printf ("\n\nTesting MS-SIPE Example Message Parsing, Signing, and Verification\n(Authentication Protocol Version 2)\n");
442 char * msg2
= "SIP/2.0 200 OK\r\nms-keep-alive: UAS; tcp=no; hop-hop=yes; end-end=no; timeout=300\r\nAuthentication-Info: NTLM rspauth=\"0100000000000000BF2E52667DDF6DED\", srand=\"0878F41B\", snum=\"1\", opaque=\"4452DFB0\", qop=\"auth\", targetname=\"ocs1.ocs.provo.novell.com\", realm=\"SIP Communications Service\"\r\nFrom: \"Gabriel Burt\"<sip:gabriel@ocs.provo.novell.com>;tag=2947328781;epid=1234567890\r\nTo: <sip:gabriel@ocs.provo.novell.com>;tag=B816D65C2300A32CFA6D371F2AF537FD\r\nCall-ID: 8592g5DCBa1694i5887m0D0Bt2247b3F38xAE9Fx\r\nCSeq: 3 REGISTER\r\nVia: SIP/2.0/TLS 164.99.194.49:10409;branch=z9hG4bKE0E37DBAF252C3255BAD;received=164.99.195.20;ms-received-port=10409;ms-received-cid=1E00\r\nContact: <sip:164.99.195.20:10409;transport=tls;ms-received-cid=1E00>;expires=900\r\nExpires: 900\r\nAllow-Events: vnd-microsoft-provisioning,vnd-microsoft-roaming-contacts,vnd-microsoft-roaming-ACL,presence,presence.wpending,vnd-microsoft-roaming-self,vnd-microsoft-provisioning-v2\r\nSupported: adhoclist\r\nServer: RTC/3.0\r\nSupported: com.microsoft.msrtc.presence\r\nContent-Length: 0\r\n\r\n";
443 struct sipmsg
* msg
= sipmsg_parse_msg(msg2
);
444 struct sipmsg_breakdown msgbd
;
446 sipmsg_breakdown_parse(&msgbd
, "SIP Communications Service", "ocs1.ocs.provo.novell.com");
447 gchar
* msg_str
= sipmsg_breakdown_get_string(2, &msgbd
);
448 sip_sec_ntlm_sipe_signature_make (NEGOTIATE_FLAGS_CONNLESS
& ~NTLMSSP_NEGOTIATE_EXTENDED_SESSIONSECURITY
,
449 msg_str
, 0, exported_session_key2
, exported_session_key2
, mac
);
450 sipmsg_breakdown_free(&msgbd
);
451 assert_equal ("0100000000000000BF2E52667DDF6DED", mac
, 16, TRUE
);
452 gchar
*sig
= buff_to_hex_str(mac
, 16);
455 ////// real Communicator 2007 R2 tests //////
456 ////// Recreated/verifyed real authentication communication between
457 ////// Communicator 2007 R2 and Office Communications Server 2007 R2
458 ////// with SIPE NTLMv2 implementation.
460 const char *password2
= "Pa$$word";
461 const char *user2
= "User";
462 const char *domain2
= "COSMO";
463 const char *host2
= "COSMO-OCS-R2";
466 //const char *type2 = "TlRMTVNTUAACAAAAAAAAADgAAADzgpji3Ruq9OfiGNEAAAAAAAAAAJYAlgA4AAAABQLODgAAAA8CAAoAQwBPAFMATQBPAAEAGABDAE8AUwBNAE8ALQBPAEMAUwAtAFIAMgAEABYAYwBvAHMAbQBvAC4AbABvAGMAYQBsAAMAMABjAG8AcwBtAG8ALQBvAGMAcwAtAHIAMgAuAGMAbwBzAG0AbwAuAGwAbwBjAGEAbAAFABYAYwBvAHMAbQBvAC4AbABvAGMAYQBsAAAAAAA=";
467 //in hex (base64 decoded):
468 const char *type2_hex
= "4E544C4D53535000020000000000000038000000F38298E2DD1BAAF4E7E218D1000000000000000096009600380000000502CE0E0000000F02000A0043004F0053004D004F000100180043004F0053004D004F002D004F00430053002D00520032000400160063006F0073006D006F002E006C006F00630061006C000300300063006F0073006D006F002D006F00630073002D00720032002E0063006F0073006D006F002E006C006F00630061006C000500160063006F0073006D006F002E006C006F00630061006C0000000000";
470 Message (length 206):
471 NTLMSSP_NEGOTIATE_UNICODE
472 NTLMSSP_NEGOTIATE_OEM
473 NTLMSSP_NEGOTIATE_SIGN
474 NTLMSSP_NEGOTIATE_SEAL
475 NTLMSSP_NEGOTIATE_DATAGRAM
476 NTLMSSP_NEGOTIATE_LM_KEY
477 NTLMSSP_NEGOTIATE_NTLM
478 NTLMSSP_NEGOTIATE_ALWAYS_SIGN
479 NTLMSSP_NEGOTIATE_EXTENDED_SESSIONSECURITY
480 NTLMSSP_NEGOTIATE_IDENTIFY
481 NTLMSSP_NEGOTIATE_TARGET_INFO
482 NTLMSSP_NEGOTIATE_VERSION
483 NTLMSSP_NEGOTIATE_128
484 NTLMSSP_NEGOTIATE_KEY_EXCH
486 server_challenge: DD1BAAF4E7E218D1
488 target_name.maxlen: 0
489 target_name.offset: 56
490 target_info.len : 150
491 target_info.maxlen: 150
492 target_info.offset: 56
493 product: 5.2.3790 (Windows Server 2003)
494 ntlm_revision_current: 0x0F (NTLMSSP_REVISION_W2K3)
495 target_info raw: 02000A0043004F0053004D004F000100180043004F0053004D004F002D004F00430053002D00520032000400160063006F0073006D006F002E006C006F00630061006C000300300063006F0073006D006F002D006F00630073002D00720032002E0063006F0073006D006F002E006C006F00630061006C000500160063006F0073006D006F002E006C006F00630061006C0000000000
496 MsvAvNbDomainName: COSMO
497 MsvAvNbComputerName: COSMO-OCS-R2
498 MsvAvDnsDomainName: cosmo.local
499 MsvAvDnsComputerName: cosmo-ocs-r2.cosmo.local
500 MsvAvDnsTreeName: cosmo.local
505 //const char *type3 = "TlRMTVNTUAADAAAAGAAYAHIAAADGAMYAigAAAAoACgBIAAAACAAIAFIAAAAYABgAWgAAABAAEABQAQAAVYKYYgUCzg4AAAAPQwBPAFMATQBPAFUAcwBlAHIAQwBPAFMATQBPAC0ATwBDAFMALQBSADIAoeku/k4Hi/fFwASazGFmwtauh1yw/apBjcDIAK527KYG0rn769BHMQEBAAAAAAAAWVGaFye5ygHWrodcsP2qQQAAAAACAAoAQwBPAFMATQBPAAEAGABDAE8AUwBNAE8ALQBPAEMAUwAtAFIAMgAEABYAYwBvAHMAbQBvAC4AbABvAGMAYQBsAAMAMABjAG8AcwBtAG8ALQBvAGMAcwAtAHIAMgAuAGMAbwBzAG0AbwAuAGwAbwBjAGEAbAAFABYAYwBvAHMAbQBvAC4AbABvAGMAYQBsAAAAAAAAAAAAMctznhyoCkmFkeiueXEV5A==";
506 //in hex (base64 decoded):
507 const char *type3_hex
= "4E544C4D53535000030000001800180072000000C600C6008A0000000A000A00480000000800080052000000180018005A0000001000100050010000558298620502CE0E0000000F43004F0053004D004F00550073006500720043004F0053004D004F002D004F00430053002D0052003200A1E92EFE4E078BF7C5C0049ACC6166C2D6AE875CB0FDAA418DC0C800AE76ECA606D2B9FBEBD04731010100000000000059519A1727B9CA01D6AE875CB0FDAA410000000002000A0043004F0053004D004F000100180043004F0053004D004F002D004F00430053002D00520032000400160063006F0073006D006F002E006C006F00630061006C000300300063006F0073006D006F002D006F00630073002D00720032002E0063006F0073006D006F002E006C006F00630061006C000500160063006F0073006D006F002E006C006F00630061006C00000000000000000031CB739E1CA80A498591E8AE797115E4";
509 Message (length 352):
510 NTLMSSP_NEGOTIATE_UNICODE
511 NTLMSSP_REQUEST_TARGET
512 NTLMSSP_NEGOTIATE_SIGN
513 NTLMSSP_NEGOTIATE_DATAGRAM
514 NTLMSSP_NEGOTIATE_NTLM
515 NTLMSSP_NEGOTIATE_ALWAYS_SIGN
516 NTLMSSP_NEGOTIATE_EXTENDED_SESSIONSECURITY
517 NTLMSSP_NEGOTIATE_IDENTIFY
518 NTLMSSP_NEGOTIATE_TARGET_INFO
519 NTLMSSP_NEGOTIATE_VERSION
520 NTLMSSP_NEGOTIATE_128
521 NTLMSSP_NEGOTIATE_KEY_EXCH
538 session_key.maxlen: 16
539 session_key.offset: 336
540 product: 5.2.3790 (Windows Server 2003)
541 ntlm_revision_current: 0x0F (NTLMSSP_REVISION_W2K3)
542 lm_resp: A1E92EFE4E078BF7C5C0049ACC6166C2D6AE875CB0FDAA41
543 nt_resp raw: 8DC0C800AE76ECA606D2B9FBEBD04731010100000000000059519A1727B9CA01D6AE875CB0FDAA410000000002000A0043004F0053004D004F000100180043004F0053004D004F002D004F00430053002D00520032000400160063006F0073006D006F002E006C006F00630061006C000300300063006F0073006D006F002D006F00630073002D00720032002E0063006F0073006D006F002E006C006F00630061006C000500160063006F0073006D006F002E006C006F00630061006C000000000000000000
544 nt_resp: 8DC0C800AE76ECA606D2B9FBEBD04731
545 target_info raw: 02000A0043004F0053004D004F000100180043004F0053004D004F002D004F00430053002D00520032000400160063006F0073006D006F002E006C006F00630061006C000300300063006F0073006D006F002D006F00630073002D00720032002E0063006F0073006D006F002E006C006F00630061006C000500160063006F0073006D006F002E006C006F00630061006C0000000000
547 hi_response_version: 1
548 time: 59519A1727B9CA01 - Mon Mar 01 10:08:08 2010
549 client_challenge: D6AE875CB0FDAA41
550 MsvAvNbDomainName: COSMO
551 MsvAvNbComputerName: COSMO-OCS-R2
552 MsvAvDnsDomainName: cosmo.local
553 MsvAvDnsComputerName: cosmo-ocs-r2.cosmo.local
554 MsvAvDnsTreeName: cosmo.local
555 ----------- end of nt_resp v2 -----------
559 session_key: 31CB739E1CA80A498591E8AE797115E4
562 const char *request
=
563 "REGISTER sip:cosmo.local SIP/2.0\r\n"
564 "Via: SIP/2.0/TLS 192.168.172.6:12723\r\n"
565 "Max-Forwards: 70\r\n"
566 "From: <sip:user@cosmo.local>;tag=3e49177a52;epid=c8ca638a15\r\n"
567 "To: <sip:user@cosmo.local>\r\n"
568 "Call-ID: 4037df9284354df39065195bd57a4b14\r\n"
569 "CSeq: 3 REGISTER\r\n"
570 "Contact: <sip:192.168.172.6:12723;transport=tls;ms-opaque=fad3dfab32>;methods=\"INVITE, MESSAGE, INFO, OPTIONS, BYE, CANCEL, NOTIFY, ACK, REFER, BENOTIFY\";proxy=replace;+sip.instance=\"<urn:uuid:34D859DB-6585-5F91-A3B4-DE853C15347D>\"\r\n"
571 "User-Agent: UCCAPI/3.5.6907.0 OC/3.5.6907.0 (Microsoft Office Communicator 2007 R2)\r\n"
572 "Supported: gruu-10, adhoclist, msrtc-event-categories\r\n"
573 "Supported: ms-forking\r\n"
574 "ms-keep-alive: UAC;hop-hop=yes\r\n"
575 "Event: registration\r\n"
576 "Proxy-Authorization: NTLM qop=\"auth\", realm=\"SIP Communications Service\", opaque=\"2BDBAC9D\", targetname=\"cosmo-ocs-r2.cosmo.local\", version=4, gssapi-data=\"TlRMTVNTUAADAAAAGAAYAHIAAADGAMYAigAAAAoACgBIAAAACAAIAFIAAAAYABgAWgAAABAAEABQAQAAVYKYYgUCzg4AAAAPQwBPAFMATQBPAFUAcwBlAHIAQwBPAFMATQBPAC0ATwBDAFMALQBSADIAoeku/k4Hi/fFwASazGFmwtauh1yw/apBjcDIAK527KYG0rn769BHMQEBAAAAAAAAWVGaFye5ygHWrodcsP2qQQAAAAACAAoAQwBPAFMATQBPAAEAGABDAE8AUwBNAE8ALQBPAEMAUwAtAFIAMgAEABYAYwBvAHMAbQBvAC4AbABvAGMAYQBsAAMAMABjAG8AcwBtAG8ALQBvAGMAcwAtAHIAMgAuAGMAbwBzAG0AbwAuAGwAbwBjAGEAbAAFABYAYwBvAHMAbQBvAC4AbABvAGMAYQBsAAAAAAAAAAAAMctznhyoCkmFkeiueXEV5A==\", crand=\"13317733\", cnum=\"1\", response=\"0100000029618e9651b65a7764000000\"\r\n"
577 "Content-Length: 0\r\n"
580 const gchar
*request_sig
= "<NTLM><13317733><1><SIP Communications Service><cosmo-ocs-r2.cosmo.local><4037df9284354df39065195bd57a4b14><3><REGISTER><sip:user@cosmo.local><3e49177a52><sip:user@cosmo.local><><><><>";
582 //0100000029618e9651b65a7764000000
584 const char *response
=
586 "ms-keep-alive: UAS; tcp=no; hop-hop=yes; end-end=no; timeout=300\r\n"
587 "Authentication-Info: NTLM rspauth=\"01000000E615438A917661BE64000000\", srand=\"9616454F\", snum=\"1\", opaque=\"2BDBAC9D\", qop=\"auth\", targetname=\"cosmo-ocs-r2.cosmo.local\", realm=\"SIP Communications Service\"\r\n"
588 "From: \"User\"<sip:user@cosmo.local>;tag=3e49177a52;epid=c8ca638a15\r\n"
589 "To: <sip:user@cosmo.local>;tag=5E61CCD925D17E043D9A74835A88F664\r\n"
590 "Call-ID: 4037df9284354df39065195bd57a4b14\r\n"
591 "CSeq: 3 REGISTER\r\n"
592 "Via: SIP/2.0/TLS 192.168.172.6:12723;ms-received-port=12723;ms-received-cid=2600\r\n"
593 "Contact: <sip:192.168.172.6:12723;transport=tls;ms-opaque=fad3dfab32;ms-received-cid=2600>;expires=7200;+sip.instance=\"<urn:uuid:34d859db-6585-5f91-a3b4-de853c15347d>\";gruu=\"sip:user@cosmo.local;opaque=user:epid:21nYNIVlkV-jtN6FPBU0fQAA;gruu\"\r\n"
595 "presence-state: register-action=\"added\"\r\n"
596 "Allow-Events: vnd-microsoft-provisioning,vnd-microsoft-roaming-contacts,vnd-microsoft-roaming-ACL,presence,presence.wpending,vnd-microsoft-roaming-self,vnd-microsoft-provisioning-v2\r\n"
597 "Supported: adhoclist\r\n"
598 "Server: RTC/3.5\r\n"
599 "Supported: msrtc-event-categories\r\n"
600 "Content-Length: 0\r\n"
603 const gchar
*response_sig
= "<NTLM><9616454F><1><SIP Communications Service><cosmo-ocs-r2.cosmo.local><4037df9284354df39065195bd57a4b14><3><REGISTER><sip:user@cosmo.local><3e49177a52><sip:user@cosmo.local><5E61CCD925D17E043D9A74835A88F664><><><7200><200>";
605 //01000000E615438A917661BE64000000
609 | NTLMSSP_NEGOTIATE_UNICODE
610 | NTLMSSP_REQUEST_TARGET
611 | NTLMSSP_NEGOTIATE_SIGN
612 | NTLMSSP_NEGOTIATE_DATAGRAM
613 | NTLMSSP_NEGOTIATE_NTLM
614 | NTLMSSP_NEGOTIATE_ALWAYS_SIGN
615 | NTLMSSP_NEGOTIATE_EXTENDED_SESSIONSECURITY
616 | NTLMSSP_NEGOTIATE_IDENTIFY
617 | NTLMSSP_NEGOTIATE_TARGET_INFO
618 | NTLMSSP_NEGOTIATE_VERSION
619 | NTLMSSP_NEGOTIATE_128
620 | NTLMSSP_NEGOTIATE_KEY_EXCH
;
623 test_version
.product_major_version
= 5;
624 test_version
.product_minor_version
= 2;
625 test_version
.product_build
= GUINT16_FROM_LE(3790);
626 test_version
.ntlm_revision_current
= 0x0F;
628 NTOWFv2 (password2
, user2
, domain2
, response_key_nt
);
629 NTOWFv2 (password2
, user2
, domain2
, response_key_lm
);
632 hex_str_to_buff("59519A1727B9CA01", &buff2
);
634 test_time_val
= GUINT64_FROM_LE(*((guint64
*)buff2
));
637 guint8
*target_info2
;
638 const int target_info2_len
= hex_str_to_buff("02000A0043004F0053004D004F000100180043004F0053004D004F002D004F00430053002D00520032000400160063006F0073006D006F002E006C006F00630061006C000300300063006F0073006D006F002D006F00630073002D00720032002E0063006F0073006D006F002E006C006F00630061006C000500160063006F0073006D006F002E006C006F00630061006C0000000000", &target_info2
);
641 hex_str_to_buff("DD1BAAF4E7E218D1", &nonce2
);
643 hex_str_to_buff("D6AE875CB0FDAA41", &buff2
);
645 memcpy(test_client_challenge
, buff2
, 8);
648 ntlmssp_nt_resp_len
= (16 + (32+target_info2_len
));
649 guchar nt_challenge_response_v2_2
[ntlmssp_nt_resp_len
];
651 printf ("\n\nTesting (NTLMv2 / OC 2007 R2) LM Response Generation\n");
652 printf ( "Testing (NTLMv2 / OC 2007 R2) NT Response Generation\n");
653 compute_response(flags
,
657 test_client_challenge
,
659 target_info2
, /* target_info */
660 target_info2_len
, /* target_info_len */
661 lm_challenge_response
, /* out */
662 nt_challenge_response_v2_2
, /* out */
663 session_base_key
); /* out */
665 g_free(target_info2
);
667 assert_equal("A1E92EFE4E078BF7C5C0049ACC6166C2D6AE875CB0FDAA41", lm_challenge_response
, 24, TRUE
);
668 assert_equal("8DC0C800AE76ECA606D2B9FBEBD04731", nt_challenge_response_v2_2
, 16, TRUE
);
669 /* the ref string is taken from binary dump of AUTHENTICATE_MESSAGE */
670 assert_equal("8DC0C800AE76ECA606D2B9FBEBD04731010100000000000059519A1727B9CA01D6AE875CB0FDAA410000000002000A0043004F0053004D004F000100180043004F0053004D004F002D004F00430053002D00520032000400160063006F0073006D006F002E006C006F00630061006C000300300063006F0073006D006F002D006F00630073002D00720032002E0063006F0073006D006F002E006C006F00630061006C000500160063006F0073006D006F002E006C006F00630061006C000000000000000000", nt_challenge_response_v2_2
, ntlmssp_nt_resp_len
, TRUE
);
672 KXKEY(flags
, session_base_key
, lm_challenge_response
, nonce2
, key_exchange_key
);
673 //as in the Type3 message
674 guint8
*encrypted_random_session_key2
;
675 hex_str_to_buff("31CB739E1CA80A498591E8AE797115E4", &encrypted_random_session_key2
);
676 /* global buff - test_random_session_key */
677 //decoding exported_session_key
678 RC4K (key_exchange_key
, 16, encrypted_random_session_key2
, 16, test_random_session_key
);
679 g_free(encrypted_random_session_key2
);
681 guchar server_sign_key
[16];
682 guchar server_seal_key
[16];
683 SIGNKEY (test_random_session_key
, TRUE
, client_sign_key
);
684 SEALKEY (flags
, test_random_session_key
, TRUE
, client_seal_key
);
685 SIGNKEY (test_random_session_key
, FALSE
, server_sign_key
);
686 SEALKEY (flags
, test_random_session_key
, FALSE
, server_seal_key
);
688 printf ("\n\nTesting (NTLMv2 / OC 2007 R2) Message Parsing, Signing, and Verification\nClient request\n(Authentication Protocol version 4)\n");
689 msg
= sipmsg_parse_msg(request
);
691 sipmsg_breakdown_parse(&msgbd
, "SIP Communications Service", "cosmo-ocs-r2.cosmo.local");
692 msg_str
= sipmsg_breakdown_get_string(4, &msgbd
);
693 assert_equal (request_sig
, (guchar
*)msg_str
, strlen(request_sig
), FALSE
);
694 sip_sec_ntlm_sipe_signature_make (flags
, msg_str
, 0, client_sign_key
, client_seal_key
, mac
);
695 sipmsg_breakdown_free(&msgbd
);
696 assert_equal ("0100000029618e9651b65a7764000000", mac
, 16, TRUE
);
697 sig
= buff_to_hex_str(mac
, 16);
699 printf ("\n\nTesting (NTLMv2 / OC 2007 R2) Message Parsing, Signing, and Verification\nServer response\n(Authentication Protocol version 4)\n");
700 msg
= sipmsg_parse_msg(response
);
702 sipmsg_breakdown_parse(&msgbd
, "SIP Communications Service", "cosmo-ocs-r2.cosmo.local");
703 msg_str
= sipmsg_breakdown_get_string(4, &msgbd
);
704 assert_equal (response_sig
, (guchar
*)msg_str
, strlen(response_sig
), FALSE
);
706 sip_sec_ntlm_sipe_signature_make (flags
, msg_str
, 0, server_sign_key
, server_seal_key
, mac
);
707 sipmsg_breakdown_free(&msgbd
);
708 assert_equal ("01000000E615438A917661BE64000000", mac
, 16, TRUE
);
709 sig
= buff_to_hex_str(mac
, 16);
711 printf ("\n\nTesting (NTLMv2 / OC 2007 R2) MAC - client signing\n");
712 MAC (flags
, (gchar
*)request_sig
,strlen(request_sig
), client_sign_key
,16, client_seal_key
,16, 0, 100, mac
);
713 assert_equal("0100000029618e9651b65a7764000000", mac
, 16, TRUE
);
715 printf ("\n\nTesting (NTLMv2 / OC 2007 R2) MAC - server's verifying\n");
716 MAC (flags
, (gchar
*)response_sig
,strlen(response_sig
), server_sign_key
,16, server_seal_key
,16, 0, 100, mac
);
717 assert_equal("01000000E615438A917661BE64000000", mac
, 16, TRUE
);
719 printf ("\n\nTesting (NTLMv2 / OC 2007 R2) Type3 generation test\n");
720 guchar
*client_sign_key2
;
721 guchar
*server_sign_key2
;
722 guchar
*client_seal_key2
;
723 guchar
*server_seal_key2
;
725 guchar
*server_challenge
= NULL
;
726 guint64 time_val2
= 0;
727 guchar
*target_info3
= NULL
;
728 int target_info3_len
= 0;
730 SipSecBuffer in_buff
;
731 SipSecBuffer out_buff
;
733 in_buff
.length
= hex_str_to_buff(type2_hex
, (guint8
**)&(in_buff
.value
));
735 sip_sec_ntlm_parse_challenge(in_buff
,
742 sip_sec_ntlm_gen_authenticate(&client_sign_key2
,
758 g_free(server_challenge
);
759 g_free(target_info3
);
761 assert_equal(type3_hex
, out_buff
.value
, out_buff
.length
, TRUE
);
763 ////// UUID tests ///////
764 /* begin tests from MS-SIPRE */
766 const char *testEpid
= "01010101";
767 const char *expectedUUID
= "4b1682a8-f968-5701-83fc-7c6741dc6697";
768 gchar
*calcUUID
= generateUUIDfromEPID(testEpid
);
770 printf("\n\nTesting MS-SIPRE UUID derivation\n");
772 assert_equal(expectedUUID
, (guchar
*) calcUUID
, strlen(expectedUUID
), FALSE
);
775 /* end tests from MS-SIPRE */
777 printf ("\nFinished With Tests; %d successs %d failures\n", successes
, failures
);
779 sip_sec_destroy__ntlm();