• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 939
  • Last Modified:

SSPI encryption/decryption problem

I have a client/server system that uses the Windows SSPI interface to authenticate NT user accounts and allow encrypted data to be passed across the network (via NTLM / Kerberos). It all works fine but there is a problem with the encrypted data transfer.

If a encrypt a message on the client side and then decrypt it on the server everything is ok. If I encrypt the data on the client side, then encrypt another message on the server side and try to decrypt the original message, I get SEC_E_MESSAGE_ALTERED returned from both DecryptMessage calls. Obviously it doesn't like the fact that the message Encrypt / Decrypt sequence is not in order, but I need to send encrypted messages in both directions at any time.

I have tried removing the ISC_REQ_SEQUENCE_DETECT and ISC_REQ_REPLAY_DETECT flags in InitializeSecurityContext but this has no effect. I've also tried jst about everything else I can think of.

Happens under NT4 and Win2K.

Thanks,

Jamie
0
JamieR
Asked:
JamieR
  • 3
  • 2
1 Solution
 
DanRollinsCommented:
What parameters are you using in EncryptMessage and DecryptMessage?  The MessageSeqNo might be critical.  Perhaps you need to get a second SecurityContext

Q245565 mentions a problem encountered by MsExchange in which two packets are processed in a single I/O operation, so when it tries to process the second block there is no data and it fails with that error.  Maybe you are hitting the same sort of thing.  Have you verified that there is good, decryptable data in the buffer when you call DecrpytMessage?

-- Dan  

0
 
JamieRAuthor Commented:
Actually I figured it out. Thanks for the help anyway.
0
 
DanRollinsCommented:
I'd rather that you not sully my grading record with a C, and I'm certain that most Experts here feel the same.  Please refer to the grading guidelines:

   http://www.experts-exchange.com/jsp/cmtyQuestAnswer.jsp#3

It is your responsibility to provide feedback to the Expert.  For instance, you could say "Shall I delete this, or do you want to me stick you with a C?"  Then when the experts replies with "You can stick that C where the sun don't shine" then you'll know the way the wind is blowing.

On another matter:
When you grade a question it gets saved into the PAQ database.  When someone later searches with keywords such as SEC_E_MESSAGE_ALTERED or DecryptMessage, then this question will be listed.  They might then purchase this question (50 points) and be rather unsatisfied since there is no answer here (C-level or otherwise).  

So could you please post a brief synopsis of what you did to solve this problem?  Thanks!

-- Dan
0
 
JamieRAuthor Commented:
Dan,

We resolved the issue before I had the opportunity to read your response. I started to describe the solution, but decided not to post it since there were several obscure issues in our code (not the CryptoAPI) and it would have been of little benefit to anyone else. It's also not my property.

I thought your reply was intelligent and helpful. I assumed you'd be grateful for the easy 500 points, not offended!

Jamie
0
 
DanRollinsCommented:
>>I assumed you'd be grateful for the easy 500 points, not offended!

Then this is a pivotal moment for you as you learn how Experts feel about getting bad grades.  Looking at your grading histroy I see that you have even given D's to experts who help you!  Nobody likes to be told that they are a third-class expert and nobody want s C or a D tarnishing their record.  If you want to thank an expert, you can post a 500-point question "Points For..." (and please, give an A!) but don't accept a non-answer as a low-grade answer.

Please review the grading guidelines carefully and please follow them in the future.  Thanks!

-- Dan
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Cloud Class® Course: C++ 11 Fundamentals

This course will introduce you to C++ 11 and teach you about syntax fundamentals.

  • 3
  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now