=================================================================== RCS file: /cvs/palm/Palm-Keyring/lib/Palm/Keyring.pm,v retrieving revision 1.34 retrieving revision 1.37 diff -u -r1.34 -r1.37 --- palm/Palm-Keyring/lib/Palm/Keyring.pm 2007/02/21 05:24:14 1.34 +++ palm/Palm-Keyring/lib/Palm/Keyring.pm 2007/02/23 02:34:01 1.37 @@ -1,5 +1,5 @@ package Palm::Keyring; -# $RedRiver: Keyring.pm,v 1.33 2007/02/21 01:26:07 andrew Exp $ +# $RedRiver: Keyring.pm,v 1.36 2007/02/22 05:16:04 andrew Exp $ ######################################################################## # Keyring.pm *** Perl class for Keyring for Palm OS databases. # @@ -168,13 +168,11 @@ } elsif ($self->{version} == 5) { my $blocksize = $CRYPTS[ $self->{appinfo}->{cipher} ]{blocksize}; my ($field, $extra) = _parse_field($rec->{data}); - my $ivec = substr $extra, 0, $blocksize; - my $encrypted = substr $extra, $blocksize; + delete $rec->{data}; $rec->{name} = $field->{data}; - $rec->{ivec} = $ivec; - $rec->{encrypted} = $encrypted; - delete $rec->{data}; + $rec->{ivec} = substr $extra, 0, $blocksize; + $rec->{encrypted} = substr $extra, $blocksize; } else { die 'Unsupported Version'; @@ -202,12 +200,21 @@ } } elsif ($self->{version} == 5) { - my $field = { - 'label_id' => 1, - 'data' => $rec->{name}, - 'font' => 0, - }; - my $packed .= _pack_field($field); + my $field; + if ($rec->{name}) { + $field = { + 'label_id' => 1, + 'data' => $rec->{name}, + 'font' => 0, + }; + } else { + $field = { + 'label_id' => $EMPTY, + 'data' => $EMPTY, + 'font' => 0, + }; + } + my $packed = _pack_field($field); $rec->{data} = join '', $packed, $rec->{ivec}, $rec->{encrypted}; @@ -262,7 +269,7 @@ my $unpackstr = ("C1" x 8) # 8 uint8s in an array for the salt - . ("S1" x 2) # the iter (uint16) and the cipher (uint16) + . ("n1" x 2) # the iter (uint16) and the cipher (uint16) . ("C1" x 8); # and finally 8 more uint8s for the hash my (@salt, $iter, $cipher, @hash); @@ -303,7 +310,7 @@ my $packstr = ("C1" x 8) # 8 uint8s in an array for the salt - . ("S1" x 2) # the iter (uint16) and the cipher (uint16) + . ("n1" x 2) # the iter (uint16) and the cipher (uint16) . ("C1" x 8); # and finally 8 more uint8s for the hash my @salt = map { hex $_ } $appinfo->{salt} =~ /../gxm; @@ -407,8 +414,6 @@ sub _encrypt_v4 { - require Crypt::CBC; - my $new = shift; my $old = shift; my $digest = shift; @@ -496,18 +501,17 @@ my $date_index; for (my $i = 0; $i < @{ $new }; $i++) { if ( - (exists $new->[$i]->{label_id} && $new->[$i]->{label_id} == 3) || - (exists $new->[$i]->{label} && $new->[$i]->{label} eq 'lastchange') + ($new->[$i]->{label_id} && $new->[$i]->{label_id} == 3) || + ($new->[$i]->{label} && $new->[$i]->{label} eq 'lastchange') ) { $date_index = $i; if ( $old && $#{ $new } == $#{ $old } && ( - $new->[$i]->{data}->{day} != $old->[$i]->{data}->{day} || - $new->[$i]->{data}->{month} != $old->[$i]->{data}->{month} || - $new->[$i]->{data}->{year} != $old->[$i]->{data}->{year} + $new->[$i]{data}{day} != $old->[$i]{data}{day} || + $new->[$i]{data}{month} != $old->[$i]{data}{month} || + $new->[$i]{data}{year} != $old->[$i]{data}{year} )) { $changed = 1; $need_newdate = 0; - last; } } elsif ($old && $#{ $new } == $#{ $old }) { @@ -559,9 +563,10 @@ $encrypted = $decrypted; } elsif ($cipher_name eq 'DES_EDE3' or $cipher_name eq 'Rijndael') { + require Crypt::CBC; my $c = Crypt::CBC->new( - -literal_key => 1, -key => $key, + -literal_key => 1, -iv => $ivec, -cipher => $cipher_name, -keysize => $keylen, @@ -659,7 +664,6 @@ sub _decrypt_v5 { - require Crypt::CBC; my $encrypted = shift; my $key = shift; @@ -677,9 +681,10 @@ $decrypted = $encrypted; } elsif ($cipher_name eq 'DES_EDE3' or $cipher_name eq 'Rijndael') { + require Crypt::CBC; my $c = Crypt::CBC->new( - -literal_key => 1, -key => $key, + -literal_key => 1, -iv => $ivec, -cipher => $cipher_name, -keysize => $keylen, @@ -791,7 +796,7 @@ } } } elsif ($self->{version} == 5) { - return _password_verify_v5($pass, $self->{appinfo}); + return _password_verify_v5($self->{appinfo}, $pass); } else { # XXX unsupported version } @@ -830,8 +835,8 @@ sub _password_verify_v5 { - my $pass = shift; my $appinfo = shift; + my $pass = shift; my $salt = pack("H*", $appinfo->{salt}); @@ -841,7 +846,9 @@ $CRYPTS[ $appinfo->{cipher} ]{DES_odd_parity}, ); + #print "Iter: '" . $appinfo->{iter} . "'\n"; #print "Key: '". unpack("H*", $key) . "'\n"; + #print "Salt: '". unpack("H*", $salt) . "'\n"; #print "Hash: '". $hash . "'\n"; #print "Hash: '". $appinfo->{masterhash} . "'\n"; @@ -1060,7 +1067,7 @@ $labels[3] = 'lastchange'; $labels[255] = 'notes'; - my ($len) = unpack "S1", $field; + my ($len) = unpack "n1", $field; if ($len + 4 > length $field) { return undef, $field; } @@ -1075,7 +1082,7 @@ my ($label, $font, $data) = unpack $unpackstr, $field; my $leftover = substr $field, $offset; - if ($label == 3) { + if ($label && $label == 3) { $data = _parse_keyring_date($data); } return { @@ -1099,21 +1106,30 @@ notes => 255, ); - my $label = $field->{label_id} || $labels{ $field->{label} }; - my $font = $field->{font} || 0; - my $data = $field->{data} || ''; + my $packed; + if (defined $field) { + my $label = $field->{label_id} || 0; + if (defined $field->{label} && ! $label) { + $label = $labels{ $field->{label} }; + } + my $font = $field->{font} || 0; + my $data = defined $field->{data} ? $field->{data} : $EMPTY; - if ($label == 3) { - $data = _pack_keyring_date($data); - } - my $len = length $data; - my $packstr = "S1 C1 C1 A*"; + if ($label && $label == 3) { + $data = _pack_keyring_date($data); + } + my $len = length $data; + my $packstr = "n1 C1 C1 A*"; - my $packed = pack $packstr, ($len, $label, $font, $data); + $packed = pack $packstr, ($len, $label, $font, $data); - if ($len % 2) { - # add byte padding for next even address. - $packed .= $NULL; + if ($len % 2) { + # add byte padding for next even address. + $packed .= $NULL; + } + } else { + my $packstr = "n1 c1 c1 x1"; + $packed = pack $packstr, 0, 0, 0; } return $packed; @@ -1265,9 +1281,10 @@ It has the standard Palm::PDB methods with 2 additional public methods. Decrypt and Encrypt. -It currently supports the v4 Keyring databases. -The pre-release v5 databases are mostly supported. There are definitely some -bugs, For example, t/keyring5.t sometimes fails. I am not sure why yet. +It currently supports the v4 Keyring databases as well as +the pre-release v5 databases. I am not completely happy with the interface +for accessing the v5 database, so any suggestions on improvements on +the interface are appreciated. This module doesn't store the decrypted content. It only keeps it until it returns it to you or encrypts it. @@ -1287,7 +1304,18 @@ next if $_ == 0 && $pdb->{version} == 4; my $rec = $pdb->{records}->[$_]; my $acct = $pdb->Decrypt($rec, $pass); - print $rec->{name}, ' - ', $acct->{account}, "\n"; + print $rec->{name}, ' - '; + if ($pdb->{version} == 4 || $pdb->{options}->{v4compatible}) { + print ' - ', $acct->{account}; + } else { + foreach my $a (@{ $acct }) { + if ($a->{type} eq 'account') { + print ' - ', $a->{data}; + last; + } + } + } + print "\n"; } =head1 SUBROUTINES/METHODS @@ -1310,7 +1338,7 @@ $pdb = new Palm::Keyring({ key1 => value1, key2 => value2 }); $pdb = new Palm::Keyring( -key1 => value1, -key2 => value2); -=head3 Supported options are: +Supported options =over @@ -1340,8 +1368,20 @@ The number of iterations to encrypt with. +=item options + +A hashref of the options that are set + =back +For v5 databases there are some additional appinfo fields set. + + $pdb->{appinfo} = { + # normal appinfo stuff described in L + cipher => The index number of the cipher being used + iter => Number of iterations for the cipher + }; + =head2 crypt Pass in the alias of the crypt to use, or the index. @@ -1360,7 +1400,6 @@ default_iter => , }; - =head2 Encrypt $pdb->Encrypt($rec, $acct[, $password[, $ivec]]); @@ -1416,7 +1455,7 @@ The account name is stored in $rec->{name} for both v4 and v5 databases. -It is not returned in the decrypted information for v5. +It is not returned in the decrypted information for v5. $rec->{name} = 'account name'; @@ -1455,6 +1494,28 @@ the password. If nothing is passed, it forgets the password that it was remembering. + +After a successful password verification the following fields are set + +For v4 + + $pdb->{digest} = the calculated digest used from the key; + $pdb->{password} = the password that was passed in; + +For v5 + + $pdb->{appinfo} = { + # As described under new() with these additional fields + cipher => The index number of the cipher being used + iter => Number of iterations for the cipher + key => The key that is calculated from the password + and salt and is used to decrypt the records. + masterhash => the hash of the key that is stored in the + database. Either set when Loading the database + or when setting a new password. + salt => the salt that is either read out of the database + or calculated when setting a new password. + }; =head1 DEPENDENCIES