From Newsgroup: comp.protocols.time.ntp
--0000000000007ec27f063e86fab3
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
Hello,
ntpd is supposed to support SHA256, but there was a bug in version
4.2.8.p18.
See the ticket:
https://bugs.ntp.org/show_bug.cgi?id=3D3954
A temporary patch has been created, and the fix is expected to be included
in the next release.
BR,
Samir
Le jeu. 11 sept. 2025 =C3=A0 14:18, Martin Burnicki <
[email protected]=
a
=C3=A9crit :
Hi Murugesh,
As far as I know, ntpd from ntp.org doesn't really support SHA256.
Would it be possible to use AES128CMAC instead? That's supported well by ntpd.
Regards,
Martin
murugesh pitchaiah wrote:
Hi James,
Thanks for your reply.
Initially I had 4.2.8.p12 client. It was sending MAC of size 20 bytes
along with keyid 4 bytes. But for that, the p18 server reported error
"MAC length error, received 24 not 36".
Assuming the p18 expects MAC without truncation I tried p18 for client.
Now having p18 client and p18 server.
P18 client sending 32 plus 4. But p18 server reporting "bad EF length".
Thanks,
Murugesh
On Wed, 3 Sept, 2025, 5:32=E2=80=AFam James Browning, <pessimus192@gmai=
l.com
<mailto:[email protected]>> wrote:
On Mon, Sep 1, 2025, 03:21 murugesh pitchaiah
<[email protected] <mailto:[email protected]>=
wrote:
Why is the server rejecting this mac ? should MAC be reduced to
20 bytes ?
The MAC is too long and it should be trucated to 16 or 20 bytes lon=
g.
Why is the same p18 version in client and server not compatible=
?
I do not know, my best guess is that the code missed a truncation.
--
Martin Burnicki
Senior Software Engineer
Email: [email protected]
Phone: +49 5281 9309-414
Linkedin: https://www.linkedin.com/in/martinburnicki/
MEINBERG Funkuhren GmbH & Co. KG
Lange Wand 9
31812 Bad Pyrmont, Germany
Registry Court: Amtsgericht Hannover 17 HRA 100322
Managing Directors: Natalie Meinberg, Daniel Boldt, Andre Hartmann,
Heiko Gerstung
Websites: https://www.meinberg.de https://www.meinbergglobal.com
Meinberg - The Synchronization Experts.
--=20
*Cordialement,*
*Samir MOUHOUNE*
--0000000000007ec27f063e86fab3
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
<div dir=3D"ltr"><p>Hello,</p>
<p>ntpd is supposed to support SHA256, but there was a bug in version 4.2.8= .p18.</p>
<p>See the ticket: <a rel=3D"noopener" class=3D"gmail-decorated-link" href= =3D"
https://bugs.ntp.org/show_bug.cgi?id=3D3954">https://bugs.ntp.org/show_= bug.cgi?id=3D3954<span aria-hidden=3D"true" class=3D"gmail-ms-0.5 gmail-inl= ine-block gmail-align-middle gmail-leading-none"></span></a></p>
<p>A temporary patch has been created, and the fix is expected to be includ=
ed in the next release.<br><br>BR,<br>Samir</p></div><br><div class=3D"gmai= l_quote gmail_quote_container"><div dir=3D"ltr" class=3D"gmail_attr">Le=C2= =A0jeu. 11 sept. 2025 =C3=A0=C2=A014:18, Martin Burnicki <<a href=3D"mai= lto:
[email protected]">
[email protected]</a>> a =C3=A9crit= =C2=A0:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px = 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">Hi Murug= esh,<br>
As far as I know, ntpd from <a href=3D"
http://ntp.org" rel=3D"noreferrer" t= arget=3D"_blank">ntp.org</a> doesn't really support SHA256.<br>
Would it be possible to use AES128CMAC instead? That's supported well b=
y <br>
ntpd.<br>
Regards,<br>
Martin<br>
murugesh pitchaiah wrote:<br>
> Hi James,<br>
> <br>
> Thanks for your reply.<br>
> <br>
> Initially I had 4.2.8.p12 client. It was sending MAC of size 20 bytes =
> along with keyid 4 bytes.=C2=A0 But for that, the p18 server reported = error <br>
> "MAC length error, received 24 not 36".<br>
> <br>
> Assuming the p18 expects MAC without truncation I tried p18 for client=
. <br>
> Now having p18 client and p18 server.<br>
> <br>
> P18 client sending 32 plus 4. But p18 server reporting "bad EF le= ngth".<br>
> <br>
> Thanks,<br>
> Murugesh<br>
> <br>
> On Wed, 3 Sept, 2025, 5:32=E2=80=AFam James Browning, <<a href=3D"m= ailto:
[email protected]" target=3D"_blank">
[email protected]</a> <b=
> <mailto:<a href=3D"mailto:
[email protected]" target=3D"_blank">=
[email protected]</a>>> wrote:<br>
> <br>
>=C2=A0 =C2=A0 =C2=A0On Mon, Sep 1, 2025, 03:21 murugesh pitchaiah<br> >=C2=A0 =C2=A0 =C2=A0<<a href=3D"mailto:
[email protected]"=
target=3D"_blank">
[email protected]</a> <mailto:<a href=3D"m= ailto:
[email protected]" target=3D"_blank">murugesh.pitchaiah@gm= ail.com</a>>><br>
>=C2=A0 =C2=A0 =C2=A0wrote:<br>
> <br>
>=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Why is the server rejecting this mac =
? should MAC be reduced to<br>
>=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A020 bytes ?<br>
> <br>
> <br>
>=C2=A0 =C2=A0 =C2=A0The MAC is too long and it should be trucated to 16=
or 20 bytes long.<br>
> <br>
>=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Why is the same p18 version in client=
and server not compatible ?<br>
> <br>
> <br>
>=C2=A0 =C2=A0 =C2=A0I do not know, my best guess is that the code misse=
d a truncation.<br>
> <br>
-- <br>
Martin Burnicki<br>
Senior Software Engineer<br>
Email: <a href=3D"mailto:
[email protected]" target=3D"_blank">mar=
[email protected]</a><br>
Phone: +49 5281 9309-414<br>
Linkedin: <a href=3D"
https://www.linkedin.com/in/martinburnicki/" rel=3D"no= referrer" target=3D"_blank">
https://www.linkedin.com/in/martinburnicki/</a>=
MEINBERG Funkuhren GmbH & Co. KG<br>
Lange Wand 9<br>
31812 Bad Pyrmont, Germany<br>
Registry Court: Amtsgericht Hannover 17 HRA 100322<br>
Managing Directors: Natalie Meinberg, Daniel Boldt, Andre Hartmann, <br>
Heiko Gerstung<br>
Websites: <a href=3D"
https://www.meinberg.de" rel=3D"noreferrer" target=3D"= _blank">
https://www.meinberg.de</a>=C2=A0 <a href=3D"
https://www.meinberggl= obal.com" rel=3D"noreferrer" target=3D"_blank">
https://www.meinbergglobal.c= om</a><br>
Meinberg - The Synchronization Experts.<br>
</blockquote></div><div><br clear=3D"all"></div><div><br></div><span class= =3D"gmail_signature_prefix">-- </span><br><div dir=3D"ltr" class=3D"gmail_s= ignature"><div dir=3D"ltr"><div><b><font size=3D"2"><i><span style=3D"font-= family:"arial black",sans-serif">Cordialement,<br></span></i></fo= nt></b></div><b><font size=3D"2"><i><span style=3D"font-family:"arial = black",sans-serif">Samir MOUHOUNE</span></i></font></b><br></div></div=
--0000000000007ec27f063e86fab3--
--- Synchronet 3.21a-Linux NewsLink 1.2