Repository navigation
fix(ntlm): preserve RC4 sealing state across mechListMIC - #753
Merged
Marc-André Moreau (mamoreau-devolutions) merged 1 commit intoSep 25, 2026
Merged
Marc-André Moreau (mamoreau-devolutions) merged 1 commit into
Marc-André Moreau (mamoreau-devolutions) merged 1 commit into
Conversation
Restore only the sealing handle used for MIC generation or verification so CredSSP wrapping between MIC exchanges stays in sync. Cover late verification and invalid signatures. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot started reviewing on behalf of
Marc-André Moreau (mamoreau-devolutions)
September 25, 2026 14:06
View session
Contributor
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The implementation matches the protocol requirement and includes focused regression coverage for the reported failure modes.
Review effort: Balanced
Findings: None
What changed in this PR
Preserves NTLM RC4 sealing state across SPNEGO mechListMIC operations, fixing subsequent CredSSP message wrapping.
Changes:
- Snapshot and restore only the MIC-related RC4 handle.
- Remove obsolete role-based cipher resets.
- Add regression coverage for ordering, direction, and invalid signatures.
| File | Description |
|---|---|
src/ntlm/mod.rs |
Implements targeted sealing-state preservation. |
src/ntlm/test.rs |
Adds RC4 state regression tests. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Pavlo Myroniuk (TheBestTvarynka)
approved these changes
Sep 25, 2026
Marc-André Moreau (mamoreau-devolutions)
merged commit Sep 25, 2026
5b2b137
into
master
62 checks passed
Marc-André Moreau (mamoreau-devolutions)
deleted the
copilot/mechlistmic-rc4-sealing-reset
branch
September 25, 2026 15:22
Contributor
|
Thanks for the changes, I can confirm that the changes here fix the underlying problem I was having. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
CredSSP can wrap
pubKeyAuthafter the initiator sends its mechListMIC but before it verifies the acceptor's MIC. Resetting both NTLM RC4 handles during verification loses the advanced send state and breaks the next wrapped message.Snapshot and restore only the sealing handle used for each MIC, including when verification fails. Remove the obsolete reset helper and add regression coverage for both directions, the CredSSP ordering, and invalid signatures. Sequence numbers remain unchanged.
Tests:
cargo test -p sspi --lib ntlm::test:: --quiet(36 passed);cargo test -p sspi --features network_client,__test-data --test sspi ntlm --quiet(14 passed);cargo check -p sspi --quiet;cargo fmt --all --check.Fixes: #752