=================================================================== RCS file: /cvs/palm/Palm-Keyring/lib/Palm/Keyring.pm,v retrieving revision 1.35 retrieving revision 1.45 diff -u -r1.35 -r1.45 --- palm/Palm-Keyring/lib/Palm/Keyring.pm 2007/02/22 04:11:35 1.35 +++ palm/Palm-Keyring/lib/Palm/Keyring.pm 2007/02/26 00:02:13 1.45 @@ -1,5 +1,5 @@ package Palm::Keyring; -# $RedRiver: Keyring.pm,v 1.34 2007/02/21 05:24:14 andrew Exp $ +# $RedRiver: Keyring.pm,v 1.44 2007/02/23 22:11:33 andrew Exp $ ######################################################################## # Keyring.pm *** Perl class for Keyring for Palm OS databases. # @@ -16,7 +16,6 @@ use warnings; use Carp; -$Carp::Verbose = 1; use base qw/ Palm::StdAppInfo /; @@ -108,11 +107,11 @@ # Set defaults if ($self->{version} == 5) { $self->{options}->{cipher} ||= 0; # 'None' - $self->{options}->{iterations} ||= - $CRYPTS[ $self->{options}->{cipher} ]{default_iter}; - - $self->{appinfo}->{cipher} ||= $self->{options}->{cipher}; - $self->{appinfo}->{iter} ||= $self->{options}->{iterations}; + my $c = crypts($self->{options}->{cipher}) + or croak('Unknown cipher ' . $self->{options}->{cipher}); + $self->{options}->{iterations} ||= $c->{default_iter}; + $self->{appinfo}->{cipher} ||= $self->{options}->{cipher}; + $self->{appinfo}->{iter} ||= $self->{options}->{iterations}; }; if ( defined $options->{password} ) { @@ -133,7 +132,9 @@ sub crypts { my $crypt = shift; - if ($crypt =~ /\D/) { + if (! defined $crypt || ! length $crypt) { + return; + } elsif ($crypt =~ /\D/) { foreach my $c (@CRYPTS) { if ($c->{alias} eq $crypt) { return $c; @@ -167,15 +168,15 @@ delete $rec->{data}; } elsif ($self->{version} == 5) { - my $blocksize = $CRYPTS[ $self->{appinfo}->{cipher} ]{blocksize}; + my $c = crypts( $self->{appinfo}->{cipher} ) + or croak('Unknown cipher ' . $self->{appinfo}->{cipher}); + my $blocksize = $c->{blocksize}; my ($field, $extra) = _parse_field($rec->{data}); - my $ivec = substr $extra, 0, $blocksize; - my $encrypted = substr $extra, $blocksize; + delete $rec->{data}; $rec->{name} = $field->{data}; - $rec->{ivec} = $ivec; - $rec->{encrypted} = $encrypted; - delete $rec->{data}; + $rec->{ivec} = substr $extra, 0, $blocksize; + $rec->{encrypted} = substr $extra, $blocksize; } else { die 'Unsupported Version'; @@ -203,12 +204,21 @@ } } elsif ($self->{version} == 5) { - my $field = { - 'label_id' => 1, - 'data' => $rec->{name}, - 'font' => 0, - }; - my $packed .= _pack_field($field); + my $field; + if ($rec->{name}) { + $field = { + 'label_id' => 1, + 'data' => $rec->{name}, + 'font' => 0, + }; + } else { + $field = { + 'label_id' => $EMPTY, + 'data' => $EMPTY, + 'font' => 0, + }; + } + my $packed = _pack_field($field); $rec->{data} = join '', $packed, $rec->{ivec}, $rec->{encrypted}; @@ -482,12 +492,10 @@ my $key = shift; my $cipher = shift; my $ivec = shift; - my $blocksize = $CRYPTS[ $cipher ]{blocksize}; - my $keylen = $CRYPTS[ $cipher ]{keylen}; - my $cipher_name = $CRYPTS[ $cipher ]{name}; + my $c = crypts($cipher) or croak('Unknown cipher ' . $cipher); if (! defined $ivec) { - $ivec = pack("C*",map {rand(256)} 1..$blocksize); + $ivec = pack("C*",map {rand(256)} 1..$c->{blocksize}); } my $changed = 0; @@ -495,18 +503,17 @@ my $date_index; for (my $i = 0; $i < @{ $new }; $i++) { if ( - (exists $new->[$i]->{label_id} && $new->[$i]->{label_id} == 3) || - (exists $new->[$i]->{label} && $new->[$i]->{label} eq 'lastchange') + ($new->[$i]->{label_id} && $new->[$i]->{label_id} == 3) || + ($new->[$i]->{label} && $new->[$i]->{label} eq 'lastchange') ) { $date_index = $i; if ( $old && $#{ $new } == $#{ $old } && ( - $new->[$i]->{data}->{day} != $old->[$i]->{data}->{day} || - $new->[$i]->{data}->{month} != $old->[$i]->{data}->{month} || - $new->[$i]->{data}->{year} != $old->[$i]->{data}->{year} + $new->[$i]{data}{day} != $old->[$i]{data}{day} || + $new->[$i]{data}{month} != $old->[$i]{data}{month} || + $new->[$i]{data}{year} != $old->[$i]{data}{year} )) { $changed = 1; $need_newdate = 0; - last; } } elsif ($old && $#{ $new } == $#{ $old }) { @@ -553,19 +560,19 @@ $decrypted .= _pack_field($field); } my $encrypted; - if ($cipher_name eq 'None') { + if ($c->{name} eq 'None') { # do nothing $encrypted = $decrypted; - } elsif ($cipher_name eq 'DES_EDE3' or $cipher_name eq 'Rijndael') { + } elsif ($c->{name} eq 'DES_EDE3' or $c->{name} eq 'Rijndael') { require Crypt::CBC; - my $c = Crypt::CBC->new( + my $cbc = Crypt::CBC->new( -key => $key, -literal_key => 1, -iv => $ivec, - -cipher => $cipher_name, - -keysize => $keylen, - -blocksize => $blocksize, + -cipher => $c->{name}, + -keysize => $c->{keylen}, + -blocksize => $c->{blocksize}, -header => 'none', -padding => 'oneandzeroes', ); @@ -574,7 +581,7 @@ croak("Unable to set up encryption!"); } - $encrypted = $c->encrypt($decrypted); + $encrypted = $cbc->encrypt($decrypted); } else { die "Unsupported Version"; @@ -665,25 +672,23 @@ my $cipher = shift; my $ivec = shift; - my $keylen = $CRYPTS[ $cipher ]{keylen}; - my $cipher_name = $CRYPTS[ $cipher ]{name}; - my $blocksize = $CRYPTS[ $cipher ]{blocksize}; + my $c = crypts($cipher) or croak('Unknown cipher ' . $cipher); my $decrypted; - if ($cipher_name eq 'None') { + if ($c->{name} eq 'None') { # do nothing $decrypted = $encrypted; - } elsif ($cipher_name eq 'DES_EDE3' or $cipher_name eq 'Rijndael') { + } elsif ($c->{name} eq 'DES_EDE3' or $c->{name} eq 'Rijndael') { require Crypt::CBC; - my $c = Crypt::CBC->new( + my $cbc = Crypt::CBC->new( -key => $key, -literal_key => 1, -iv => $ivec, - -cipher => $cipher_name, - -keysize => $keylen, - -blocksize => $blocksize, + -cipher => $c->{name}, + -keysize => $c->{keylen}, + -blocksize => $c->{blocksize}, -header => 'none', -padding => 'oneandzeroes', ); @@ -691,9 +696,9 @@ if (! $c) { croak("Unable to set up encryption!"); } - my $len = $blocksize - length($encrypted) % $blocksize; + my $len = $c->{blocksize} - length($encrypted) % $c->{blocksize}; $encrypted .= $NULL x $len; - $decrypted = $c->decrypt($encrypted); + $decrypted = $cbc->decrypt($encrypted); } else { die "Unsupported Version"; @@ -835,10 +840,12 @@ my $salt = pack("H*", $appinfo->{salt}); + my $c = crypts($appinfo->{cipher}) + or croak('Unknown cipher ' . $appinfo->{cipher}); my ($key, $hash) = _calc_key_v5( $pass, $salt, $appinfo->{iter}, - $CRYPTS[ $appinfo->{cipher} ]{keylen}, - $CRYPTS[ $appinfo->{cipher} ]{DES_odd_parity}, + $c->{keylen}, + $c->{DES_odd_parity}, ); #print "Iter: '" . $appinfo->{iter} . "'\n"; @@ -941,18 +948,18 @@ my $length = 8; my $salt = shift || pack("C*",map {rand(256)} 1..$length); + my $c = crypts($cipher) or croak('Unknown cipher ' . $cipher); my ($key, $hash) = _calc_key_v5( $pass, $salt, $iter, - $CRYPTS[ $cipher ]->{keylen}, - $CRYPTS[ $cipher ]->{DES_odd_parity}, + $c->{keylen}, + $c->{DES_odd_parity}, ); $appinfo->{salt} = unpack "H*", $salt; $appinfo->{iter} = $iter; $appinfo->{cipher} = $cipher; - - $appinfo->{key} = $key; $appinfo->{masterhash} = $hash; + $appinfo->{key} = $key; return $key; } @@ -993,7 +1000,7 @@ import Digest::SHA1 qw(sha1); my $key = _pbkdf2( $pass, $salt, $iter, $keylen, \&hmac_sha1 ); - if ($dop) { $key = DES_odd_parity($key); } + if ($dop) { $key = _DES_odd_parity($key); } my $hash = unpack("H*", substr(sha1($key.$salt),0, 8)); @@ -1077,7 +1084,7 @@ my ($label, $font, $data) = unpack $unpackstr, $field; my $leftover = substr $field, $offset; - if ($label == 3) { + if ($label && $label == 3) { $data = _parse_keyring_date($data); } return { @@ -1101,21 +1108,30 @@ notes => 255, ); - my $label = $field->{label_id} || $labels{ $field->{label} }; - my $font = $field->{font} || 0; - my $data = $field->{data} || ''; + my $packed; + if (defined $field) { + my $label = $field->{label_id} || 0; + if (defined $field->{label} && ! $label) { + $label = $labels{ $field->{label} }; + } + my $font = $field->{font} || 0; + my $data = defined $field->{data} ? $field->{data} : $EMPTY; - if ($label == 3) { - $data = _pack_keyring_date($data); - } - my $len = length $data; - my $packstr = "n1 C1 C1 A*"; + if ($label && $label == 3) { + $data = _pack_keyring_date($data); + } + my $len = length $data; + my $packstr = "n1 C1 C1 A*"; - my $packed = pack $packstr, ($len, $label, $font, $data); + $packed = pack $packstr, ($len, $label, $font, $data); - if ($len % 2) { - # add byte padding for next even address. - $packed .= $NULL; + if ($len % 2) { + # add byte padding for next even address. + $packed .= $NULL; + } + } else { + my $packstr = "n1 C1 C1 x1"; + $packed = pack $packstr, 0, 0, 0; } return $packed; @@ -1226,7 +1242,7 @@ return substr($t, 0, $keylen); } -sub DES_odd_parity($) { +sub _DES_odd_parity($) { my $key = $_[0]; my ($r, $i); my @odd_parity = ( @@ -1267,9 +1283,10 @@ It has the standard Palm::PDB methods with 2 additional public methods. Decrypt and Encrypt. -It currently supports the v4 Keyring databases. -The pre-release v5 databases are mostly supported. There are definitely some -bugs, For example, t/keyring5.t sometimes fails. I am not sure why yet. +It currently supports the v4 Keyring databases as well as +the pre-release v5 databases. I am not completely happy with the interface +for accessing v5 databases, so any suggestions on improvements on +the interface are appreciated. This module doesn't store the decrypted content. It only keeps it until it returns it to you or encrypts it. @@ -1289,7 +1306,18 @@ next if $_ == 0 && $pdb->{version} == 4; my $rec = $pdb->{records}->[$_]; my $acct = $pdb->Decrypt($rec, $pass); - print $rec->{name}, ' - ', $acct->{account}, "\n"; + print $rec->{name}, ' - '; + if ($pdb->{version} == 4 || $pdb->{options}->{v4compatible}) { + print ' - ', $acct->{account}; + } else { + foreach my $a (@{ $acct }) { + if ($a->{label} eq 'account') { + print ' - ', $a->{data}; + last; + } + } + } + print "\n"; } =head1 SUBROUTINES/METHODS @@ -1312,8 +1340,10 @@ $pdb = new Palm::Keyring({ key1 => value1, key2 => value2 }); $pdb = new Palm::Keyring( -key1 => value1, -key2 => value2); -=head3 Supported options are: +=over +=item Supported options + =over =item password @@ -1331,7 +1361,7 @@ =item cipher -The cipher to use. 0, 1, 2 or 3. +The cipher to use. Either the number or the name. 0 => None 1 => DES_EDE3 @@ -1342,14 +1372,33 @@ The number of iterations to encrypt with. +=item options + +A hashref of the options that are set + =back -=head2 crypt +=back +For v5 databases there are some additional appinfo fields set. +These are set either on new() or Load(). + + $pdb->{appinfo} = { + # normal appinfo stuff described in L + cipher => The index number of the cipher being used + iter => Number of iterations for the cipher + }; + +=head2 crypts + Pass in the alias of the crypt to use, or the index. +These only make sense for v5 databases. + This is a function, not a method. +$cipher can be 0, 1, 2, 3, None, DES_EDE3, AES128 or AES256. + my $c = Palm::Keyring::crypt($cipher); $c is now: @@ -1357,12 +1406,11 @@ $c = { alias => (None|DES_EDE3|AES128|AES256), name => (None|DES_EDE3|Rijndael), - keylen => , + keylen => , blocksize => , default_iter => , }; - =head2 Encrypt $pdb->Encrypt($rec, $acct[, $password[, $ivec]]); @@ -1418,7 +1466,7 @@ The account name is stored in $rec->{name} for both v4 and v5 databases. -It is not returned in the decrypted information for v5. +It is not returned in the decrypted information for v5. $rec->{name} = 'account name'; @@ -1437,7 +1485,7 @@ Decrypts the record and returns a reference for the account as described under Encrypt(). - foreach (0..$#{ $pdb->{records}) { + foreach (0..$#{ $pdb->{records} }) { next if $_ == 0 && $pdb->{version} == 4; my $rec = $pdb->{records}->[$_]; my $acct = $pdb->Decrypt($rec); @@ -1458,16 +1506,87 @@ If nothing is passed, it forgets the password that it was remembering. +After a successful password verification the following fields are set + +For v4 + + $pdb->{digest} = the calculated digest used from the key; + $pdb->{password} = the password that was passed in; + +For v5 + + $pdb->{appinfo} = { + # As described under new() with these additional fields + cipher => The index number of the cipher being used + iter => Number of iterations for the cipher + key => The key that is calculated from the password + and salt and is used to decrypt the records. + masterhash => the hash of the key that is stored in the + database. Either set when Loading the database + or when setting a new password. + salt => the salt that is either read out of the database + or calculated when setting a new password. + }; + +=head2 Other overridden subroutines/methods + +=over + +=item ParseAppInfoBlock + +Converts the extra returned by Palm::StdAppInfo::ParseAppInfoBlock() into +the following additions to $pdb->{appinfo} + + $pdb->{appinfo} = { + cipher => The index number of the cipher being used (Not v4) + iter => Number of iterations for the cipher (Not v4) + }; + +=item PackAppInfoBlock + +Reverses ParseAppInfoBlock before +sending it on to Palm::StdAppInfo::PackAppInfoBlock() + +=item ParseRecord + +Adds some fields to a record from Palm::StdAppInfo::ParseRecord() + + $rec = { + name => Account name + ivec => The IV for the encrypted record. (Not v4) + encrypted => the encrypted information + }; + +=item PackRecord + +Reverses ParseRecord and then sends it through Palm::StdAppInfo::PackRecord() + +=back + =head1 DEPENDENCIES Palm::StdAppInfo +B + Digest::MD5 Crypt::DES -Readonly +B +Digest::HMAC_SHA1 + +Digest::SHA1 + +Depending on how the database is encrypted + +Crypt::CBC - For any encryption but None + +Crypt::DES_EDE3 - DES_EDE3 encryption + +Crytp::Rijndael - AES encryption schemes + =head1 THANKS I would like to thank the helpful Perlmonk shigetsu who gave me some great advice @@ -1482,7 +1601,32 @@ as giving me some very helpful hints about doing a few things that I was unsure of. He is really great. +And finally, +thanks to Jochen Hoenicke Ehoenicke@gmail.comE +(one of the authors of Palm Keyring) +for getting me started on the v5 support as well as providing help +and some subroutines. + =head1 BUGS AND LIMITATIONS + +I am sure there are problems with this module. For example, I have +not done very extensive testing of the v5 databases. + +I am not sure I am 'require module' the best way, but I don't want to +depend on modules that you don't need to use. + +I am not very happy with the data structures used by Encrypt() and +Decrypt() for v5 databases, but I am not sure of a better way. + +The v4 compatibility mode does not insert a fake record 0 where +normally the encrypted password is stored. + +The date validation for packing new dates is very poor. + +I have not gone through and standardized on how the module fails. Some +things fail with croak, some return undef, some may even fail silently. +Nothing initializes a lasterr method or anything like that. I need +to fix all that before it is a 1.0 candidate. Please report any bugs or feature requests to C, or through the web interface at