qemu-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Qemu-devel] [PATCH v2 0/2] Try to fix problem with emulated smartcards


From: Ray Strode
Subject: [Qemu-devel] [PATCH v2 0/2] Try to fix problem with emulated smartcards where invalid PIN succeeds
Date: Wed, 11 Sep 2013 09:59:42 -0400

This updated patch series includes Reviewed-By lines from Alon Levy and Robert 
Relyea,
and also improves the accuracy of the second commit message. This set should be 
ready to merge.

Back story is that I started writing a blog post about virtualized smartcards 
here:

https://blogs.gnome.org/halfline/2013/09/08/another-smartcard-post/

and while testing what I was writing I noticed an invalid PIN worked when it
shouldn't have. It turns out that typing a valid PIN once in one program in the
guest, is enough to make all future programs in the guest ask for the PIN to
succeed regardless of what gets typed in for the PIN.

I did some digging through the libcacard code, and noticed it uses the
NSS PK11_Authenticate function which calls a function that has this comment 
above it:

    If we're already logged in and this function is called we
    will still prompt for a password, but we will probably succeed
    no matter what the password was.

Also, PK11_Authenticate short-circuits to an early "return SECSuccess" if the 
token
is already logged in.

The two patches in this series attempt to correct this problem by calling 
PK11_Logout.




reply via email to

[Prev in Thread] Current Thread [Next in Thread]