Skip to content

fix(kerberos): recover from KDC clock skew during AS exchange - #757

Merged
Benoît Cortier (CBenoit) merged 2 commits into
masterfrom
copilot/fix-kerberos-clock-skew
Sep 28, 2026
Merged

Benoît Cortier (CBenoit) merged 2 commits into
masterfrom
copilot/fix-kerberos-clock-skew

Conversation

@mamoreau-devolutions

Copy link
Copy Markdown
Contributor

Summary

  • When a KDC rejects encrypted AS pre-authentication with KRB_AP_ERR_SKEW, derive a per-context time offset from the error's stime/susec and retry once. Propagate a second skew error or any other error without additional retries.
  • Apply the offset to password, keytab, and smart-card pre-authentication timestamps and to subsequent TGS, AP, and password-change authenticators. Existing public generator calls still use local time unless invoked through the corrected client context.
  • Fix the built-in KDC's skew check so timestamps slightly ahead of or behind its clock are accepted within max_time_skew.

Review and validation

  • End-to-end tests cover KDC clocks 15 seconds ahead and behind, a bounded second skew error, and an unrelated pre-authentication failure with no retry. A KDC test verifies both directions inside/outside the configured skew window; a keytab test decrypts and checks the encoded timestamp.
  • cargo test -q -p sspi -p kdc --features network_client,__test-data
  • cargo check -q -p sspi --all-features
  • cargo clippy -q -p sspi -p kdc --features network_client,__test-data --lib --tests -- -D warnings -A unreachable-pub -A clippy::non-ascii-literal (the two allowances are for pre-existing warnings outside this change)
  • cargo fmt --all

Scope: This addresses KDC AS pre-authentication skew. There is no trace from the original PSWSMan report to prove it is the exact failure; a separately skewed application server rejecting the AP exchange is not handled here (related: #83).

Retry pre-authentication once using KDC error time and use the corrected clock for later authenticators. Apply the configured skew window symmetrically in the built-in KDC and cover recovery, bounded retries, and unrelated errors.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings September 26, 2026 00:17

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The retry is bounded, error propagation is preserved, and the affected authentication paths have focused validation.

Review effort: Balanced
Findings: None

What changed in this PR

Adds per-context KDC clock-skew recovery during Kerberos AS pre-authentication and propagates corrected time to subsequent authenticators.

Changes:

  • Retries AS pre-authentication once after KRB_AP_ERR_SKEW.
  • Applies learned offsets across password, keytab, smart-card, TGS, AP, and password-change flows.
  • Corrects bidirectional KDC skew validation and adds tests.
File Description
tests/​sspi/​client_server/​kerberos/​mod.rs Tests recovery, retry limits, and unrelated errors.
tests/​sspi/​client_server/​kerberos/​kdc.rs Adds configurable mock clock skew.
src/​pk_init.rs Supports supplied smart-card timestamps.
src/​kerberos/​tests.rs Initializes the new context field.
src/​kerberos/​pa_datas.rs Routes corrected time through pre-auth generation.
src/​kerberos/​mod.rs Stores and applies the per-context offset.
src/​kerberos/​client/​mod.rs Uses corrected time for TGS and AP authenticators.
src/​kerberos/​client/​generators.rs Adds timestamp-aware generators and keytab coverage.
src/​kerberos/​client/​change_password.rs Corrects password-change authenticator time.
src/​kerberos/​client/​as_exchange.rs Parses skew errors and performs one retry.
crates/​kdc/​src/​as_exchange.rs Accepts skew within the configured window in either direction.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Decrypt the AP-REQ and assert its authenticator timestamp tracks the simulated KDC clock for positive and negative skew while preserving the full authentication checks.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@CBenoit
Benoît Cortier (CBenoit) merged commit 24c9c52 into master Sep 28, 2026
61 checks passed
@CBenoit
Benoît Cortier (CBenoit) deleted the copilot/fix-kerberos-clock-skew branch September 28, 2026 03:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

4 participants