[2380] in Kerberos

home help back first fref pref prev next nref lref last post

Re: telnet encryption option vs. Clarkson TCP

daemon@ATHENA.MIT.EDU (Patrick Herlihy)
Wed Nov 18 18:07:31 1992

Date: 18 Nov 92 21:38:56 GMT
From: P.Herlihy@ccsd.uts.edu.au (Patrick Herlihy)
To: kerberos@shelby.Stanford.EDU

alan@CURTA.CC.COLUMBIA.EDU (Alan Crosswell) writes:

>I wonder if you have heard of any interoperability problems between
>the Kerberized (version 4) telnetd that came with the first beta of
>MIT Kerberos 5 and Clarkson TCP for the PC (CUTE-2.2TN-D).

>The problem I have is the telnet session "freezes" right around the
>TELOPT_ENCRYPTION (option 38) negotiation.  Clarkson TCP is not
>capable of doing the auth or encrypt options (boy do I wish!) so it is
>just something messing up in the part where the unknown option is
>supposed to be rejected.  If I recompile telnetd with -UENCRYPT then
>Clarkson TCP is able to get in.  Other telnet clients like Unix and
>Kermit can get in just fine.

I figured that Clarkson TCP just doesn't handle the encryption option
properly:  telnetd says "WILL ENCRYPT", expecting a response from CUTCP
if it won't encrypt; CUTCP just ignores the option altogether.

Telnetd then assumes that the option has been accepted, and waits in a loop
expecting to get encryption key info.

If you make the initial telnetd option "DO ENCRYPT" instead of "WILL ENCRYPT",
and put a "WILL ENCRYPT" later on, CUTCP will respond properly in the
negative.

My diffs to telnetd/telnetd.c in the telnet.91.03.25 release follow:

*** telnetd.c.orig	Wed Nov 18 08:34:47 1992
--- telnetd.c	Wed Nov 18 08:34:51 1992
***************
*** 417,423 ****
  #endif
  
  #if	defined(ENCRYPT)
!     send_will(TELOPT_ENCRYPT, 1);
  #endif
      send_do(TELOPT_TTYPE, 1);
      send_do(TELOPT_TSPEED, 1);
--- 417,424 ----
  #endif
  
  #if	defined(ENCRYPT)
! /*    send_will(TELOPT_ENCRYPT, 1); */
!     send_do(TELOPT_ENCRYPT, 1);
  #endif
      send_do(TELOPT_TTYPE, 1);
      send_do(TELOPT_TSPEED, 1);
***************
*** 425,431 ****
      send_do(TELOPT_ENVIRON, 1);
      while (
  #if	defined(ENCRYPT)
! 	   his_do_dont_is_changing(TELOPT_ENCRYPT) ||
  #endif
  	   his_will_wont_is_changing(TELOPT_TTYPE) ||
  	   his_will_wont_is_changing(TELOPT_TSPEED) ||
--- 426,433 ----
      send_do(TELOPT_ENVIRON, 1);
      while (
  #if	defined(ENCRYPT)
! /* 	   his_do_dont_is_changing(TELOPT_ENCRYPT) || */
! 	   his_will_wont_is_changing(TELOPT_ENCRYPT) ||
  #endif
  	   his_will_wont_is_changing(TELOPT_TTYPE) ||
  	   his_will_wont_is_changing(TELOPT_TSPEED) ||
***************
*** 439,444 ****
--- 441,447 ----
       * send with.  If autoencrypt is not set, this will just return.
       */
      if (his_state_is_will(TELOPT_ENCRYPT)) {
+         send_will(TELOPT_ENCRYPT, 1);
  	encrypt_wait();
      }
  #endif
-- 
Patrick John Herlihy,                            P.Herlihy@ccsd.uts.EDU.AU
Communications Services Branch,		                Ph: +61 2 330 5162
University of Technology, Sydney,                      Fax: +61 2 330 5562
PO Box 123, Broadway, NSW, 2007, Australia.      

home help back first fref pref prev next nref lref last post