mirror of
https://salsa.debian.org/freeipa-team/freeipa.git
synced 2024-12-25 16:31:08 -06:00
bc05ab9922
For some unknown reason, when I wrote the ipa-otptoken-import script I used bad input data which had the PBKDF2 parameters in the wrong XML namespace. I have corrected this input data to match RFC 6030. https://pagure.io/freeipa/issue/7035 Signed-off-by: Nathaniel McCallum <npmccallum@redhat.com> Reviewed-By: Martin Basti <mbasti@redhat.com> Reviewed-By: Stanislav Laznicka <slaznick@redhat.com>
69 lines
2.4 KiB
XML
69 lines
2.4 KiB
XML
<?xml version="1.0" encoding="UTF-8"?>
|
|
<pskc:KeyContainer
|
|
xmlns:pskc="urn:ietf:params:xml:ns:keyprov:pskc"
|
|
xmlns:xenc11="http://www.w3.org/2009/xmlenc11#"
|
|
xmlns:pkcs5="http://www.rsasecurity.com/rsalabs/pkcs/schemas/pkcs-5v2-0#"
|
|
xmlns:xenc="http://www.w3.org/2001/04/xmlenc#" Version="1.0">
|
|
<pskc:EncryptionKey>
|
|
<xenc11:DerivedKey>
|
|
<xenc11:KeyDerivationMethod
|
|
Algorithm="http://www.rsasecurity.com/rsalabs/pkcs/schemas/pkcs-5v2-0#pbkdf2">
|
|
<pkcs5:PBKDF2-params>
|
|
<Salt>
|
|
<Specified>Ej7/PEpyEpw=</Specified>
|
|
</Salt>
|
|
<IterationCount>1000</IterationCount>
|
|
<KeyLength>16</KeyLength>
|
|
<PRF/>
|
|
</pkcs5:PBKDF2-params>
|
|
</xenc11:KeyDerivationMethod>
|
|
<xenc:ReferenceList>
|
|
<xenc:DataReference URI="#ED"/>
|
|
</xenc:ReferenceList>
|
|
<xenc11:MasterKeyName>My Password 1</xenc11:MasterKeyName>
|
|
</xenc11:DerivedKey>
|
|
</pskc:EncryptionKey>
|
|
<pskc:MACMethod
|
|
Algorithm="http://www.w3.org/2000/09/xmldsig#hmac-sha1">
|
|
<pskc:MACKey>
|
|
<xenc:EncryptionMethod
|
|
Algorithm="http://www.w3.org/2001/04/xmlenc#aes128-cbc"/>
|
|
<xenc:CipherData>
|
|
<xenc:CipherValue>
|
|
2GTTnLwM3I4e5IO5FkufoOEiOhNj91fhKRQBtBJYluUDsPOLTfUvoU2dStyOwYZx
|
|
</xenc:CipherValue>
|
|
</xenc:CipherData>
|
|
</pskc:MACKey>
|
|
</pskc:MACMethod>
|
|
<pskc:KeyPackage>
|
|
<pskc:DeviceInfo>
|
|
<pskc:Manufacturer>TokenVendorAcme</pskc:Manufacturer>
|
|
<pskc:SerialNo>987654321</pskc:SerialNo>
|
|
</pskc:DeviceInfo>
|
|
<pskc:CryptoModuleInfo>
|
|
<pskc:Id>CM_ID_001</pskc:Id>
|
|
</pskc:CryptoModuleInfo>
|
|
<pskc:Key Algorithm="urn:ietf:params:xml:ns:keyprov:pskc:hotp" Id="123456">
|
|
<pskc:Issuer>Example-Issuer</pskc:Issuer>
|
|
<pskc:AlgorithmParameters>
|
|
<pskc:ResponseFormat Length="8" Encoding="DECIMAL"/>
|
|
</pskc:AlgorithmParameters>
|
|
<pskc:Data>
|
|
<pskc:Secret>
|
|
<pskc:EncryptedValue Id="ED">
|
|
<xenc:EncryptionMethod
|
|
Algorithm="http://www.w3.org/2001/04/xmlenc#aes128-cbc"/>
|
|
<xenc:CipherData>
|
|
<xenc:CipherValue>
|
|
oTvo+S22nsmS2Z/RtcoF8Hfh+jzMe0RkiafpoDpnoZTjPYZu6V+A4aEn032yCr4f
|
|
</xenc:CipherValue>
|
|
</xenc:CipherData>
|
|
</pskc:EncryptedValue>
|
|
<pskc:ValueMAC>LP6xMvjtypbfT9PdkJhBZ+D6O4w=
|
|
</pskc:ValueMAC>
|
|
</pskc:Secret>
|
|
</pskc:Data>
|
|
</pskc:Key>
|
|
</pskc:KeyPackage>
|
|
</pskc:KeyContainer>
|