smbencrypt calculates false hash for German umlauts and other non-ASCII letters

Alan DeKok aland at deployingradius.com
Sat Sep 7 18:10:38 CEST 2013


Arran Cudbard-Bell wrote:
> Can't we assume src as UTF8 for NAI (RFC4282)?

  Ha, ha, ha, ha  <cough>.  4282 is wrong.  And no one implements any of it.

  The MS-CHAP RFCs are silent on the subject of character encoding.  The
unofficial word from Microsoft is "MS-CHAP uses the local encoding".

  Ok... what's that?

  <hysterical laughter>  No one knows.  And there's no way to find out.

  And UTF-8 uses up to 5 octets for a character.  MS-CHAP requires no
more than 2.

  There is *no* way to do the right thing.  You can get close.
Sometimes.  Maybe.  But doing the right thing always?  Impossible.

  Alan DeKok.


More information about the Freeradius-Users mailing list