From darrenm@sac.sfbay.sun.com Tue Nov  6 03:19:58 2007
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id lA6BJvWR006955
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 6 Nov 2007 03:19:58 -0800 (PST)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id lA6BG767016171;
	Tue, 6 Nov 2007 11:16:16 GMT
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0JR300M090N08S00@brm-avmta-1.central.sun.com>; Tue,
 06 Nov 2007 04:16:12 -0700 (MST)
Received: from dm-sfbay-02.sfbay.sun.com ([129.146.11.31])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0JR3006CB0MZ9K90@brm-avmta-1.central.sun.com>; Tue,
 06 Nov 2007 04:16:12 -0700 (MST)
Received: from sac.sfbay.sun.com (new-sac.SFBay.Sun.COM [129.146.175.65])
	by dm-sfbay-02.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id lA6BGBbE027864; Tue, 06 Nov 2007 03:16:11 -0800 (PST)
Received: from sac.sfbay.sun.com (localhost [127.0.0.1])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id lA6BJmtQ006948; Tue,
 06 Nov 2007 03:19:48 -0800 (PST)
Received: (from darrenm@localhost)
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8/Submit) id lA6BJm8H006944; Tue,
 06 Nov 2007 03:19:48 -0800 (PST)
Date: Tue, 06 Nov 2007 03:19:48 -0800 (PST)
From: Darren J Moffat <darrenm@sac.sfbay.sun.com>
Subject: SHA256/SHA512 crypt(3C) plugins [PSARC/2007/642 FastTrack timeout
 11/13/2007]
To: PSARC-ext@Sun.COM
Cc: Jim.Hall@Sun.COM, security-discuss@opensolaris.org
Message-id: <200711061119.lA6BJm8H006944@sac.sfbay.sun.com>
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.2.0.264296
Status: RO
Content-Length: 2812


Template Version: @(#)sac_nextcase 1.64 07/13/07 SMI
This information is Copyright 2007 Sun Microsystems
1. Introduction
    1.1. Project/Component Working Name:
	 SHA256/SHA512 crypt(3C) plugins
    1.2. Name of Document Author/Supplier:
	 Author:  Darren Moffat
    1.3  Date of This Document:
	06 November, 2007
4. Technical Description

This case provides an additional pair of crypt(3C) plugins based on the SHA256
and SHA512 digest algorithms.  It does so by implementing the interfaces
defined in PSARC/2005/426.

This algorithm was designed to provide a crypt(3C) hash that uses
FIPS 140-2 approved algorithms and move away from MD5 based hashes.
The algorithm justification/background and specification are in the case dir
as [1] and [2] the canonical references are [3] and [4] respectively.

This case does NOT change the default crypt(3C) algorithm in policy.conf(4),
that will be the subject of a future case, it does however update
CRYPT_ALGORITHMS_ALLOW for new installs but does not do so for upgrade (since
that could change an admins intended policy).

The config file /etc/security/crypt.conf is updated to add support for the
two new crypt(3C) algorithms on upgrade and new install.

This case requests patch release binding - with intent to ship in a Solaris 10
update release or as a standalone patch.

The two modules are delivered in /usr/lib/security alongside the existing
crypt(3C) plugins.

+---------- Imported Interfaces ---------------------------+
| libmd(3LIB)               |  Committed | PSARC/2005/426  |
|  SHA2Init/Update/Final    |            |                 |
+----------------------------------------------------------+

+---------- Exported Interfaces ------------------------------------+
| crypt_sha256(5)           | Committed  | Implements:              | 
| crypt(3C) algname=$5      |            | crypt_genhash_impl(3C)   |
|                           |            | crypt_gensalt_impl(3C)   |
| Package: SUNWcsl          |            | As per PSARC/2000/510    |
+-------------------------------------------------------------------+
| crypt_sha512(5)           | Committed  | Implements:              | 
| crypt(3C) algname=$6      |            | crypt_genhash_impl(3C)   |
|                           |            | crypt_gensalt_impl(3C)   |
| Package: SUNWcsl          |            | As per PSARC/2000/510    |
+-------------------------------------------------------------------+

References
1]	materials/justification-sha-crypt.html
[2]	materials/algorithm-spec.txt
[3]	http://people.redhat.com/drepper/SHA-crypt.txt
[4]	http://people.redhat.com/drepper/sha-crypt.html

6. Resources and Schedule
    6.4. Steering Committee requested information
   	6.4.1. Consolidation C-team Name:
		ON
    6.5. ARC review type: FastTrack
    6.6. ARC Exposure: open


From Darren.Moffat@sun.com Thu Nov  8 04:39:39 2007
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id lA8CdcLh027743
	for <psarc-ext@sac.sfbay.sun.com>; Thu, 8 Nov 2007 04:39:39 -0800 (PST)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id lA8CZZ8o028380
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Thu, 8 Nov 2007 05:35:58 -0700 (MST)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0JR600203TNOG700@nwk-avmta-1.sfbay.Sun.COM> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Thu, 08 Nov 2007 04:35:48 -0800 (PST)
Received: from gmp-eb-mail-1.sun.com ([192.18.6.21])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0JR600DUJTNNOQC0@nwk-avmta-1.sfbay.Sun.COM> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Thu,
 08 Nov 2007 04:35:48 -0800 (PST)
Received: from fe-emea-09.sun.com (gmp-eb-lb-2-fe2.eu.sun.com [192.18.6.11])
	by gmp-eb-mail-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id lA8CZloc007143	for
 <psarc-ext@sun.com>; Thu, 08 Nov 2007 12:35:47 +0000 (GMT)
Received: from conversion-daemon.fe-emea-09.sun.com by fe-emea-09.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0JR600A01TD72400@fe-emea-09.sun.com>
 (original mail from Darren.Moffat@Sun.COM)
 for psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Thu,
 08 Nov 2007 12:35:47 +0000 (GMT)
Received: from [129.156.173.21] by fe-emea-09.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 with ESMTPSA id <0JR600AK2TNHJF10@fe-emea-09.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Thu, 08 Nov 2007 12:35:41 +0000 (GMT)
Date: Thu, 08 Nov 2007 12:35:41 +0000
From: Darren J Moffat <Darren.Moffat@sun.com>
Subject: [closed-approved] PSARC/2007/642 SHA256/SHA512 crypt(3C) plugins
Sender: Darren.Moffat@sun.com
To: psarc-ext@sun.com
Message-id: <4733029D.8080705@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.2.0.264296
User-Agent: Thunderbird 2.0.0.6 (X11/20070924)
Status: RO
Content-Length: 68

This case was approved in PSARC on 2007-11-07.

-- 
Darren J Moffat

From wyllys.ingersoll@sun.com Wed Apr 23 13:00:15 2008
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m3NK0FUB018411
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 23 Apr 2008 13:00:15 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail2sca.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m3NK0EDh003109
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Wed, 23 Apr 2008 13:00:15 -0700 (PDT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0JZS0030RNKEFC00@brm-avmta-1.central.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Wed, 23 Apr 2008 14:00:14 -0600 (MDT)
Received: from jurassic-x4600.sfbay.sun.com ([129.146.17.59])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0JZS00IWVNKDGX80@brm-avmta-1.central.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Wed,
 23 Apr 2008 14:00:13 -0600 (MDT)
Received: from [10.7.251.182] (punchin-wyllys.SFBay.Sun.COM [10.7.251.182])
	by jurassic-x4600.sfbay.sun.com (8.14.2+Sun/8.14.2)
 with ESMTP id m3NK0Cx6793590
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO)
	for <PSARC-ext@sun.com>; Wed, 23 Apr 2008 13:00:13 -0700 (PDT)
Date: Wed, 23 Apr 2008 16:00:12 -0400
From: Wyllys Ingersoll <wyllys.ingersoll@sun.com>
Subject: PSARC 2007/642  SHA256/SHA512 crypt(3C) plugins - man pages
To: PSARC-ext@sun.com
Message-id: <480F954C.2090902@sun.com>
MIME-version: 1.0
Content-type: multipart/mixed; boundary="Boundary_(ID_uhNlAPAV1SNDGBkGwwwSxA)"
X-PMX-Version: 5.4.1.325704
User-Agent: Thunderbird 2.0.0.12 (X11/20080325)
Status: RO
Content-Length: 6841

This is a multi-part message in MIME format.

--Boundary_(ID_uhNlAPAV1SNDGBkGwwwSxA)
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT

I'm attaching 2 man pages for crypt_sha256(5) and crypt_sha512(5) for 
the case logs.  I will file the
manpage request for both of these prior to putback of the code.  Please 
review and send comments,
I copied the format of the crypt_sunmd5(5) and just changed the relevant 
text for each sha
implementation.

-Wyllys Ingersoll




--Boundary_(ID_uhNlAPAV1SNDGBkGwwwSxA)
Content-type: text/plain; name=crypt_sha256.5
Content-transfer-encoding: 7BIT
Content-disposition: inline; filename=crypt_sha256.5

Standards, Environments, and Macros               crypt_sha256(5)


NAME
     crypt_sha256 - password hashing  module  using  MD5  message
     hash algorithm

SYNOPSIS
     /usr/lib/security/$ISA/crypt_sha256.so


DESCRIPTION
     The crypt_sha256 module is a one-way password hashing module
     for  use with crypt(3C) that uses the SHA-256 message hash algo-
     rithm.  The  algorithm  identifier  for  crypt.conf(4)   and
     policy.conf(4) is '5'.

     This module is designed to make it difficult to crack  pass-
     words  that  use brute force attacks based on high speed SHA-256
     implementations that use code inlining, unrolled loops,  and
     table lookup.

     The maximum password length for crypt_sha256 is 255  charac-
     ters.

     The following options can be passed to the module  by  means
     of crypt.conf(4):

     rounds=<positive_number>    Specifies the  number  of  rounds
                                 of SHA-256 to use in the
                                 generation  of  the  salt;   the
                                 default   number  of  rounds  is
                                 5000. Negative  values  have  no
                                 effect and are ignored. The minimum
                                 number of rounds cannot be below 1000.

                                 The number of additional  rounds
                                 is  stored  in  the  salt string
                                 returned  by  crypt_gensalt(3C).
                                 For example:

                                   $5,rounds=6000$nlxmTTpz$

                                 When crypt_gensalt(3C) is  being
                                 used  to generate a new salt, if
                                 the number of additional  rounds
                                 configured  in  crypt.conf(4) is
                                 greater than  that  in  the  old
                                 salt,     the     value     from
                                 crypt.conf(4) is  used  instead.
                                 This  allows  for  migration  to
                                 stronger   (but    more    time-
                                 consuming)   salts  on  password
                                 change.


ATTRIBUTES
     See attributes(5) for descriptions of the  following  attri-
     butes:



     ____________________________________________________________
    |       ATTRIBUTE TYPE        |       ATTRIBUTE VALUE       |
    |_____________________________|_____________________________|
    | MT-Level                    | Safe                        |
    |_____________________________|_____________________________|


SEE ALSO
     passwd(1),        crypt(3C),         crypt_genhash_impl(3C),
     crypt_gensalt(3C),                   crypt_gensalt_impl(3C),
     getpassphrase(3C), crypt.conf(4), passwd(4), policy.conf(4),
     attributes(5)

--Boundary_(ID_uhNlAPAV1SNDGBkGwwwSxA)
Content-type: text/plain; name=crypt_sha512.5
Content-transfer-encoding: 7BIT
Content-disposition: inline; filename=crypt_sha512.5

Standards, Environments, and Macros               crypt_sha512(5)



NAME
     crypt_sha512 - password hashing  module  using  MD5  message
     hash algorithm

SYNOPSIS
     /usr/lib/security/$ISA/crypt_sha512.so


DESCRIPTION
     The crypt_sha512 module is a one-way password hashing module
     for  use with crypt(3C) that uses the SHA-512 message hash algo-
     rithm.  The  algorithm  identifier  for  crypt.conf(4)   and
     policy.conf(4) is '6'.

     This module is designed to make it difficult to crack  pass-
     words  that  use brute force attacks based on high speed SHA-512
     implementations that use code inlining, unrolled loops,  and
     table lookup.

     The maximum password length for crypt_sha512 is 255  charac-
     ters.

     The following options can be passed to the module  by  means
     of crypt.conf(4):

     rounds=<positive_number>    Specifies the  number  of  rounds
                                 of SHA-512 to use in the
                                 generation  of  the  salt;   the
                                 default   number  of  rounds  is
                                 5000. Negative  values  have  no
                                 effect and are ignored. The minimum
                                 number of rounds cannot be below 1000.

                                 The number of additional  rounds
                                 is  stored  in  the  salt string
                                 returned  by  crypt_gensalt(3C).
                                 For example:

                                   $6,rounds=6000$nlxmTTpz$

                                 When crypt_gensalt(3C) is  being
                                 used  to generate a new salt, if
                                 the number of additional  rounds
                                 configured  in  crypt.conf(4) is
                                 greater than  that  in  the  old
                                 salt,     the     value     from
                                 crypt.conf(4) is  used  instead.
                                 This  allows  for  migration  to
                                 stronger   (but    more    time-
                                 consuming)   salts  on  password
                                 change.


ATTRIBUTES
     See attributes(5) for descriptions of the  following  attri-
     butes:



     ____________________________________________________________
    |       ATTRIBUTE TYPE        |       ATTRIBUTE VALUE       |
    |_____________________________|_____________________________|
    | MT-Level                    | Safe                        |
    |_____________________________|_____________________________|


SEE ALSO
     passwd(1),        crypt(3C),         crypt_genhash_impl(3C),
     crypt_gensalt(3C),                   crypt_gensalt_impl(3C),
     getpassphrase(3C), crypt.conf(4), passwd(4), policy.conf(4),
     attributes(5)

--Boundary_(ID_uhNlAPAV1SNDGBkGwwwSxA)--

