Bug 6510 - HMACSHA512 >> Invalid ComputeHash calculation
Summary: HMACSHA512 >> Invalid ComputeHash calculation
Status: RESOLVED FIXED
Alias: None
Product: iOS
Classification: Xamarin
Component: XI runtime ()
Version: 5.2
Hardware: Macintosh Mac OS
: --- normal
Target Milestone: Untriaged
Assignee: Sebastien Pouliot
URL:
: 13486 ()
Depends on:
Blocks:
 
Reported: 2012-08-12 14:15 UTC by Sergey
Modified: 2013-07-25 16:38 UTC (History)
3 users (show)

Tags:
Is this bug a regression?: ---
Last known good build:

Notice (2018-05-24): bugzilla.xamarin.com is now in read-only mode.

Please join us on Visual Studio Developer Community and in the Xamarin and Mono organizations on GitHub to continue tracking issues. Bugzilla will remain available for reference in read-only mode. We will continue to work on open Bugzilla bugs, copy them to the new locations as needed for follow-up, and add the new items under Related Links.

Our sincere thanks to everyone who has contributed on this bug tracker over the years. Thanks also for your understanding as we make these adjustments and improvements for the future.


Please create a new report on Developer Community or GitHub with your current version information, steps to reproduce, and relevant error messages or log files if you are hitting an issue that looks similar to this resolved bug and you do not yet see a matching new report.

Related Links:
Status:
RESOLVED FIXED

Description Sergey 2012-08-12 14:15:58 UTC
ComputeHash function result does not match with the same implementation on windows if secret key is more than 64 char.

Here is my code

Token - secret key

        private static void CalculateDigest(string token)
        {
            string stringToSign = "123456789";
            Console.WriteLine("Token: {0}", token);
            using (var hmac = new HMACSHA512(Encoding.UTF8.GetBytes(token)))
            {
                byte[] rawHash = hmac.ComputeHash(Encoding.UTF8.GetBytes(stringToSign));
                Console.WriteLine("ByteArray: {0}", ArrayToString(rawHash));
                Console.WriteLine("Hex: {0}", ToHexString(rawHash));
            }
        }

        private static string ArrayToString(IEnumerable<byte> array)
        {
            var result = new StringBuilder();

            foreach (byte element in array)
            {
                if (result.Length > 0)
                {
                    result.Append(", ");
                }

                result.Append(element);
            }
            result.Insert(0, "{");
            result.Append("}");
            return result.ToString();
        }

        private static string ToHexString(IEnumerable<byte> bytes)
        {
            if (bytes == null)
            {
                return string.Empty;
            }
            var stringBuilder = new StringBuilder();
            foreach (byte value in bytes)
            {
                stringBuilder.AppendFormat("{0:X2}", value);
            }
            return stringBuilder.ToString();
        }

here is examples:

Example 1 Does not match

Token(Length 69): CA61A777DC1041B2FDCC354820F7F83CE0530C0E019A29BF576F175D314A6D891B35F

Windows

ByteArray: {147, 50, 79, 211, 70, 90, 205, 252, 100, 25, 50, 209, 254, 157, 154, 12, 132, 205, 113, 59, 97, 216, 252, 94, 43, 126, 207, 140, 137, 60, 227, 82, 82, 240, 9, 15, 166, 167, 110, 85, 217, 245, 250, 169, 189, 138, 55, 197, 146, 192, 96, 20, 249, 95, 130, 163, 147, 82, 71, 244, 139, 76, 45, 75}
Hex: 93324FD3465ACDFC641932D1FE9D9A0C84CD713B61D8FC5E2B7ECF8C893CE35252F0090FA6A76E55D9F5FAA9BD8A37C592C06014F95F82A3935247F48B4C2D4B

Monotouch

ByteArray: {78, 250, 127, 96, 118, 95, 152, 119, 156, 19, 125, 222, 254, 37, 80, 232, 64, 92, 235, 209, 48, 148, 120, 138, 113, 9, 186, 47, 156, 18, 115, 188, 25, 194, 170, 255, 5, 196, 179, 164, 157, 3, 4, 177, 191, 166, 210, 111, 180, 189, 36, 228, 241, 170, 148, 103, 184, 190, 48, 164, 54, 213, 154, 20}
Hex: 4EFA7F60765F98779C137DDEFE2550E8405CEBD13094788A7109BA2F9C1273BC19C2AAFF05C4B3A49D0304B1BFA6D26FB4BD24E4F1AA9467B8BE30A436D59A14
Hex: 50CD00C554E217049FAC76006F02CEA15ED0007D50514E9AC9D2F690B09FBD70EFF0D32224D95EEA84F8EE99BF2E4DA75F3CFE9C24D79727D15D2A1E17268A18

Example 2 Does not match

Token (Length 65): CA61A777DC1041B2FDCC354820F7F83CE0530C0E019A29BF576F175D314A6D891

Windows

ByteArray: {254, 159, 56, 218, 66, 110, 74, 135, 209, 81, 166, 150, 241, 194, 171, 228, 143, 228, 16, 198, 171, 53, 40, 211, 229, 160, 158, 2, 102, 99, 11, 49, 70, 53, 70, 32, 32, 219, 119, 14, 2, 149, 197, 220, 166, 38, 128, 25, 255, 227, 25, 20, 229, 54, 217, 57, 143, 224, 251, 1, 202, 24, 245, 133}
Hex: FE9F38DA426E4A87D151A696F1C2ABE48FE410C6AB3528D3E5A09E0266630B314635462020DB770E0295C5DCA6268019FFE31914E536D9398FE0FB01CA18F585

Monotouch

ByteArray: {146, 18, 27, 37, 137, 224, 64, 134, 164, 207, 46, 164, 39, 244, 5, 92, 99, 80, 206, 58, 237, 130, 223, 148, 141, 203, 250, 21, 48, 246, 54, 44, 11, 6, 252, 108, 250, 6, 149, 201, 85, 94, 10, 0, 104, 163, 58, 218, 195, 108, 38, 180, 89, 20, 147, 185, 195, 245, 135, 98, 70, 222, 77, 87}
Hex: 92121B2589E04086A4CF2EA427F4055C6350CE3AED82DF948DCBFA1530F6362C0B06FC6CFA0695C9555E0A0068A33ADAC36C26B4591493B9C3F5876246DE4D57

Example 3 MATCH :)

Token (Length 64): CA61A777DC1041B2FDCC354820F7F83CE0530C0E019A29BF576F175D314A6D89

Windows

ByteArray: {62, 100, 150, 7, 105, 44, 56, 193, 125, 113, 74, 125, 189, 0, 200, 0, 172, 15, 20, 166, 158, 114, 47, 198, 108, 28, 11, 80, 100, 42, 148, 106, 211, 211, 191, 245, 254, 129, 75, 34, 113, 35, 35, 44, 86, 239, 10, 134, 145, 214, 20, 203, 54, 218, 8, 67, 161, 124, 59, 195, 146, 18, 142, 172}
Hex: 3E649607692C38C17D714A7DBD00C800AC0F14A69E722FC66C1C0B50642A946AD3D3BFF5FE814B227123232C56EF0A8691D614CB36DA0843A17C3BC392128EAC

Monotouch

ByteArray: {62, 100, 150, 7, 105, 44, 56, 193, 125, 113, 74, 125, 189, 0, 200, 0, 172, 15, 20, 166, 158, 114, 47, 198, 108, 28, 11, 80, 100, 42, 148, 106, 211, 211, 191, 245, 254, 129, 75, 34, 113, 35, 35, 44, 86, 239, 10, 134, 145, 214, 20, 203, 54, 218, 8, 67, 161, 124, 59, 195, 146, 18, 142, 172}
Hex: 3E649607692C38C17D714A7DBD00C800AC0F14A69E722FC66C1C0B50642A946AD3D3BFF5FE814B227123232C56EF0A8691D614CB36DA0843A17C3BC392128EAC

Any work around are welcome, I should implement digest authentication.

Please let me know if i can help you somehow.
Comment 1 Sergey 2012-08-12 14:43:56 UTC
Please not the same behavior with HMACSHA384, i.e. ComputeHash value doesn't match
Comment 2 Sebastien Pouliot 2012-08-13 11:23:42 UTC
This works fine in Mono master (2.11). 

It looks like part of the blocksize [1] fix was not backported to mono-2-10 (on which MonoTouch is based).

$ diff -u mcs/class/corlib/System.Security.Cryptography/HMAC.cs ~/git/mono/mcs/class/corlib/System.Security.Cryptography/HMAC.cs 
--- mcs/class/corlib/System.Security.Cryptography/HMAC.cs	2012-05-09 16:02:53.000000000 -0400
+++ /Users/sebastienpouliot/git/mono/mcs/class/corlib/System.Security.Cryptography/HMAC.cs	2012-08-13 09:11:43.000000000 -0400
@@ -83,7 +83,7 @@
 		public override byte[] Key { 
 			get { return (byte[]) base.Key.Clone (); }
 			set { 
-				if ((value != null) && (value.Length > 64))
+				if ((value != null) && (value.Length > BlockSizeValue))
 					base.Key = _algo.ComputeHash (value);
 				else
 					base.Key = (byte[]) value.Clone();


[1] http://blogs.msdn.com/b/shawnfa/archive/2007/01/31/please-do-not-use-the-net-2-0-hmacsha512-and-hmacsha384-classes.aspx
Comment 4 Sebastien Pouliot 2012-08-13 14:43:52 UTC
backported ecb05bdde0336e589994db646e2628ed6ae83bc7

Future versions of MonoTouch will include this fix. 

If this is blocking you (and you're using 5.2.12) then I can provide you with an hotfix. Just ask on the bug report and I'll attach the binaries later.
Comment 8 Jonathan Pryor 2013-07-25 16:38:01 UTC
*** Bug 13486 has been marked as a duplicate of this bug. ***