Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people, just like you, are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions

SSPI encryption/decryption problem

Posted on 2002-07-10
Last Modified: 2012-06-21
I have a client/server system that uses the Windows SSPI interface to authenticate NT user accounts and allow encrypted data to be passed across the network (via NTLM / Kerberos). It all works fine but there is a problem with the encrypted data transfer.

If a encrypt a message on the client side and then decrypt it on the server everything is ok. If I encrypt the data on the client side, then encrypt another message on the server side and try to decrypt the original message, I get SEC_E_MESSAGE_ALTERED returned from both DecryptMessage calls. Obviously it doesn't like the fact that the message Encrypt / Decrypt sequence is not in order, but I need to send encrypted messages in both directions at any time.

I have tried removing the ISC_REQ_SEQUENCE_DETECT and ISC_REQ_REPLAY_DETECT flags in InitializeSecurityContext but this has no effect. I've also tried jst about everything else I can think of.

Happens under NT4 and Win2K.


Question by:JamieR
  • 3
  • 2
LVL 49

Accepted Solution

DanRollins earned 500 total points
ID: 7148349
What parameters are you using in EncryptMessage and DecryptMessage?  The MessageSeqNo might be critical.  Perhaps you need to get a second SecurityContext

Q245565 mentions a problem encountered by MsExchange in which two packets are processed in a single I/O operation, so when it tries to process the second block there is no data and it fails with that error.  Maybe you are hitting the same sort of thing.  Have you verified that there is good, decryptable data in the buffer when you call DecrpytMessage?

-- Dan  


Author Comment

ID: 7151735
Actually I figured it out. Thanks for the help anyway.
LVL 49

Expert Comment

ID: 7151778
I'd rather that you not sully my grading record with a C, and I'm certain that most Experts here feel the same.  Please refer to the grading guidelines:


It is your responsibility to provide feedback to the Expert.  For instance, you could say "Shall I delete this, or do you want to me stick you with a C?"  Then when the experts replies with "You can stick that C where the sun don't shine" then you'll know the way the wind is blowing.

On another matter:
When you grade a question it gets saved into the PAQ database.  When someone later searches with keywords such as SEC_E_MESSAGE_ALTERED or DecryptMessage, then this question will be listed.  They might then purchase this question (50 points) and be rather unsatisfied since there is no answer here (C-level or otherwise).  

So could you please post a brief synopsis of what you did to solve this problem?  Thanks!

-- Dan

Author Comment

ID: 7152909

We resolved the issue before I had the opportunity to read your response. I started to describe the solution, but decided not to post it since there were several obscure issues in our code (not the CryptoAPI) and it would have been of little benefit to anyone else. It's also not my property.

I thought your reply was intelligent and helpful. I assumed you'd be grateful for the easy 500 points, not offended!

LVL 49

Expert Comment

ID: 7152986
>>I assumed you'd be grateful for the easy 500 points, not offended!

Then this is a pivotal moment for you as you learn how Experts feel about getting bad grades.  Looking at your grading histroy I see that you have even given D's to experts who help you!  Nobody likes to be told that they are a third-class expert and nobody want s C or a D tarnishing their record.  If you want to thank an expert, you can post a 500-point question "Points For..." (and please, give an A!) but don't accept a non-answer as a low-grade answer.

Please review the grading guidelines carefully and please follow them in the future.  Thanks!

-- Dan

Featured Post

Free Tool: Postgres Monitoring System

A PHP and Perl based system to collect and display usage statistics from PostgreSQL databases.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
C++ assignment question 7 236
Template syntax for variable length arrays 9 75
Need some help with Microsoft Visual Studio C++ 2003 5 65
No module found pypyodbc, 3 32
When writing generic code, using template meta-programming techniques, it is sometimes useful to know if a type is convertible to another type. A good example of when this might be is if you are writing diagnostic instrumentation for code to generat…
In days of old, returning something by value from a function in C++ was necessarily avoided because it would, invariably, involve one or even two copies of the object being created and potentially costly calls to a copy-constructor and destructor. A…
The goal of the tutorial is to teach the user how to use functions in C++. The video will cover how to define functions, how to call functions and how to create functions prototypes. Microsoft Visual C++ 2010 Express will be used as a text editor an…
The goal of the video will be to teach the user the concept of local variables and scope. An example of a locally defined variable will be given as well as an explanation of what scope is in C++. The local variable and concept of scope will be relat…

856 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question