/
[Apache-SVN]
Revision 794013
Jump to revision:
Author:
mullan
Date:
Tue Jul 14 18:51:46 2009 UTC
(15 years, 9 months ago)
Changed paths:
17
Log Message:
Fixed bug 47526: XML signature HMAC truncation authentication bypass
Changed paths
Path
Details
xml/security/trunk/data/javax/xml/crypto/dsig/signature-enveloping-hmac-sha1-trunclen-0-attack.xml
added
xml/security/trunk/data/javax/xml/crypto/dsig/signature-enveloping-hmac-sha1-trunclen-8-attack.xml
added
xml/security/trunk/src/org/apache/xml/security/algorithms/implementations/IntegrityHmac.java
modified
,
text changed
xml/security/trunk/src/org/apache/xml/security/resource/xmlsecurity_de.properties
modified
,
text changed
xml/security/trunk/src/org/apache/xml/security/resource/xmlsecurity_en.properties
modified
,
text changed
xml/security/trunk/src/org/apache/xml/security/signature/XMLSignature.java
modified
,
text changed
xml/security/trunk/src/org/jcp/xml/dsig/internal/dom/DOMHMACSignatureMethod.java
modified
,
text changed
xml/security/trunk/src_unitTests/javax/xml/crypto/test/dsig/Baltimore23Test.java
modified
,
text changed
xml/security/trunk/src_unitTests/javax/xml/crypto/test/dsig/CreateBaltimore23Test.java
modified
,
text changed
xml/security/trunk/src_unitTests/javax/xml/crypto/test/dsig/CreatePhaosXMLDSig3Test.java
modified
,
text changed
xml/security/trunk/src_unitTests/javax/xml/crypto/test/dsig/IaikSignatureAlgosTest.java
modified
,
text changed
xml/security/trunk/src_unitTests/javax/xml/crypto/test/dsig/PhaosXMLDSig3Test.java
modified
,
text changed
xml/security/trunk/src_unitTests/javax/xml/crypto/test/dsig/ValidateSignatureTest.java
modified
,
text changed
xml/security/trunk/src_unitTests/org/apache/xml/security/test/interop/BaltimoreTest.java
modified
,
text changed
xml/security/trunk/src_unitTests/org/apache/xml/security/test/interop/IAIKTest.java
modified
,
text changed
xml/security/trunk/src_unitTests/org/apache/xml/security/test/signature/AllTests.java
modified
,
text changed
xml/security/trunk/src_unitTests/org/apache/xml/security/test/signature/HMACOutputLengthTest.java
added
infrastructure at apache.org
ViewVC Help
Powered by
ViewVC 1.1.26