+userdir-ldap-cgi (0.3.22) unstable; urgency=low
+
+ * Verify confirmed hmac in web display, showing status as either 'confirmed'
+ (which now means also verified, i.e. it will make it to the host), or
+ 'invalid'.
+
+ -- Peter Palfrader <weasel@debian.org> Tue, 16 Sep 2008 22:10:27 +0200
+
userdir-ldap-cgi (0.3.21) unstable; urgency=low
* Slightly change find call in cronjob.
$sudopassword .= "<tr><td>Unparseable line!</td></tr>\n";
next;
}
- $status =~ s/:.*//; # remove verification hmac, it's just noise here.
+ if ($status =~ /^confirmed:/) {
+ my $data = join(':', 'password-is-confirmed', $uuid, $hosts, $crypted);
+ my $hmac = hmac_sha1_hex( $data, $hmac_key);
+ if ($status eq "confirmed:$hmac") {
+ $status = 'confirmed';
+ } else {
+ $status = 'INVALID';
+ }
+ }
my $e = "<tr><td>".CGI::escapeHTML($hosts)."</td>
<td>".CGI::escapeHTML($status)."</td>
<td><small>not shown</small></td>