Skip to content

[release/8.0] Fix implementation of NegotiateAuthentication.Wrap for Kerberos on Windows - #91311

Merged
carlossanlop merged 2 commits into
release/8.0from
backport/pr-91152-to-release/8.0
Sep 11, 2023
Merged

[release/8.0] Fix implementation of NegotiateAuthentication.Wrap for Kerberos on Windows#91311
carlossanlop merged 2 commits into
release/8.0from
backport/pr-91152-to-release/8.0

Conversation

@github-actions

@github-actionsgithub-actionsBot commented Aug 30, 2023

Copy link
Copy Markdown
Contributor

Backport of #91152 to release/8.0

FixesPowerShell/PowerShell#20168

/cc @rzikm@filipnavara

Customer Impact

Regression against 7.0 - Establishing NTLM (Kerberos) authenticated connection can fail with "The encryption operation failed" (see PowerShell/PowerShell#20168).

The story behind the regression:

The regression is caused by changes in .NET Kerberos/NTLM authentication which started in 7.0 and which are finishing now in 8.0. The goal was to introduce public Kerberos/NTLM authentication APIs (NegotiateAuthenticaton) for higher-level frameworks and applications (e.g. ASP.NET needed it to avoid using private Reflection - see #29270).
In 6.0 and earlier, the Kerberos/NTLM authentication (NTAuthentication) was internal only code and was compiled into multiple Networking assemblies (e.g. System.Net.Security, System.Net.Mail, etc.) to avoid using Reflection. Therefore, it also had negative impact on .NET binaries size due to compiled code duplication (while the source code was shared).

In 7.0, we introduced the new public API NegotiateAuthenticaton and we migrated a few internal usages of NTAuthentication to the new public API (e.g. Mail), but not all of them.
One of the public APIs (NegotiateAuthentication.Wrap) had a bug on Windows only that was not exposed until 8.0, when we migrated also NegotiateStream to the public APIs in PR #86948. NegotiateStream support of Kerberos requires more flexibility in encryption padding, which NTLM didn't need, and the new API didn't fully provide it.

This PR brings parity of old internal functionality in NegotiateStreamPal.Encrypt to the new public API NegotiateAuthentication.Wrap.

Testing

The change was tested on affected scenario reported in PowerShell/PowerShell#20168.
Additional validation was performed using a custom/manual NegotiateStream client-server setup between Windows Server 2019 server machine and Windows 11 client machine.

Note: NTLM has good unit test coverage. Kerberos has also good unit test coverage on Linux via Kerberos.NET. However, Kerberos on Windows requires complicated multi-machine setup, therefore it is not automated. We will evaluate feasibility of adding Kerberos test endpoint for CI during 9.0 to address the test gap.

Risk

Low to Medium.

The change affects encryption and signing of data transferred through NegotiateStream. There's no other internal consumer of the NegotiateAuthentication.Wrap API (with exception of single message in SMTP GSSAPI authentication which is covered by tests). Given that this is very advanced API introduced in 7.0, we do not expect there to be any external usages of the API either. And if they are, they would not be ok with the buggy behavior in 7.0.
Only two encryption protocols are supported - NTLM and Kerberos, and NTLM is covered by tests. The Kerberos use case was reported to be broken, and this restores the affected code to mimic the .NET 7 behavior.

@ghost

Copy link
Copy Markdown

Tagging subscribers to this area: @dotnet/ncl, @bartonjs, @vcsjones
See info in area-owners.md if you want to be subscribed.

Issue Details

Backport of #91152 to release/8.0

/cc @rzikm@filipnavara

Customer Impact

Testing

Risk

IMPORTANT: If this backport is for a servicing release, please verify that:

  • The PR target branch is release/X.0-staging, not release/X.0.

  • If the change touches code that ships in a NuGet package, you have added the necessary package authoring and gotten it explicitly reviewed.

Author:github-actions[bot]
Assignees:-
Labels:

area-System.Net.Security

Milestone:-

@rzikm

Copy link
Copy Markdown
Member

@filipnavara would you be able to provide text for the Testing and Risk sections as well?

cc: @karelz

@filipnavara

This comment was marked as duplicate.

@wfurtwfurt left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. Thanks @filipnavara

@carlossanlopcarlossanlop added the Servicing-consider Issue for next servicing release review label Aug 30, 2023
@carlossanlopcarlossanlop added this to the 8.0.0 milestone Aug 30, 2023
@carlossanlop

Copy link
Copy Markdown
Contributor

@karelz do you approve this for RC2?

@karelz

Copy link
Copy Markdown
Member

I approve, it is E2E regression - @artl93 it is ready for you

@artl93

Copy link
Copy Markdown
Member

M2 approved.

@artl93artl93 added Servicing-approved Approved for servicing release and removed Servicing-consider Issue for next servicing release review labels Sep 7, 2023
@carlossanlop
carlossanlop merged commit 217be6c into release/8.0Sep 11, 2023
@carlossanlop
carlossanlop deleted the backport/pr-91152-to-release/8.0 branch September 11, 2023 23:09
@radicalradical mentioned this pull request Sep 26, 2023
@radicalradical mentioned this pull request Oct 3, 2023
@ghostghost locked as resolved and limited conversation to collaborators Oct 12, 2023
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@rzikm@filipnavara@carlossanlop@karelz@artl93@wfurt
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
[release/8.0] Fix implementation of NegotiateAuthentication.Wrap for Kerberos on Windows by github-actions[bot] · Pull Request #91311 · dotnet/runtime · GitHub
Skip to content

[release/8.0] Fix implementation of NegotiateAuthentication.Wrap for Kerberos on Windows - #91311

Merged
carlossanlop merged 2 commits into
release/8.0from
backport/pr-91152-to-release/8.0
Sep 11, 2023
Merged

[release/8.0] Fix implementation of NegotiateAuthentication.Wrap for Kerberos on Windows#91311
carlossanlop merged 2 commits into
release/8.0from
backport/pr-91152-to-release/8.0

Conversation

@github-actions

@github-actionsgithub-actionsBot commented Aug 30, 2023

Copy link
Copy Markdown
Contributor

Backport of #91152 to release/8.0

FixesPowerShell/PowerShell#20168

/cc @rzikm@filipnavara

Customer Impact

Regression against 7.0 - Establishing NTLM (Kerberos) authenticated connection can fail with "The encryption operation failed" (see PowerShell/PowerShell#20168).

The story behind the regression:

The regression is caused by changes in .NET Kerberos/NTLM authentication which started in 7.0 and which are finishing now in 8.0. The goal was to introduce public Kerberos/NTLM authentication APIs (NegotiateAuthenticaton) for higher-level frameworks and applications (e.g. ASP.NET needed it to avoid using private Reflection - see #29270).
In 6.0 and earlier, the Kerberos/NTLM authentication (NTAuthentication) was internal only code and was compiled into multiple Networking assemblies (e.g. System.Net.Security, System.Net.Mail, etc.) to avoid using Reflection. Therefore, it also had negative impact on .NET binaries size due to compiled code duplication (while the source code was shared).

In 7.0, we introduced the new public API NegotiateAuthenticaton and we migrated a few internal usages of NTAuthentication to the new public API (e.g. Mail), but not all of them.
One of the public APIs (NegotiateAuthentication.Wrap) had a bug on Windows only that was not exposed until 8.0, when we migrated also NegotiateStream to the public APIs in PR #86948. NegotiateStream support of Kerberos requires more flexibility in encryption padding, which NTLM didn't need, and the new API didn't fully provide it.

This PR brings parity of old internal functionality in NegotiateStreamPal.Encrypt to the new public API NegotiateAuthentication.Wrap.

Testing

The change was tested on affected scenario reported in PowerShell/PowerShell#20168.
Additional validation was performed using a custom/manual NegotiateStream client-server setup between Windows Server 2019 server machine and Windows 11 client machine.

Note: NTLM has good unit test coverage. Kerberos has also good unit test coverage on Linux via Kerberos.NET. However, Kerberos on Windows requires complicated multi-machine setup, therefore it is not automated. We will evaluate feasibility of adding Kerberos test endpoint for CI during 9.0 to address the test gap.

Risk

Low to Medium.

The change affects encryption and signing of data transferred through NegotiateStream. There's no other internal consumer of the NegotiateAuthentication.Wrap API (with exception of single message in SMTP GSSAPI authentication which is covered by tests). Given that this is very advanced API introduced in 7.0, we do not expect there to be any external usages of the API either. And if they are, they would not be ok with the buggy behavior in 7.0.
Only two encryption protocols are supported - NTLM and Kerberos, and NTLM is covered by tests. The Kerberos use case was reported to be broken, and this restores the affected code to mimic the .NET 7 behavior.

@ghost

Copy link
Copy Markdown

Tagging subscribers to this area: @dotnet/ncl, @bartonjs, @vcsjones
See info in area-owners.md if you want to be subscribed.

Issue Details

Backport of #91152 to release/8.0

/cc @rzikm@filipnavara

Customer Impact

Testing

Risk

IMPORTANT: If this backport is for a servicing release, please verify that:

  • The PR target branch is release/X.0-staging, not release/X.0.

  • If the change touches code that ships in a NuGet package, you have added the necessary package authoring and gotten it explicitly reviewed.

Author:github-actions[bot]
Assignees:-
Labels:

area-System.Net.Security

Milestone:-

@rzikm

Copy link
Copy Markdown
Member

@filipnavara would you be able to provide text for the Testing and Risk sections as well?

cc: @karelz

@filipnavara

This comment was marked as duplicate.

@wfurtwfurt left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. Thanks @filipnavara

@carlossanlopcarlossanlop added the Servicing-consider Issue for next servicing release review label Aug 30, 2023
@carlossanlopcarlossanlop added this to the 8.0.0 milestone Aug 30, 2023
@carlossanlop

Copy link
Copy Markdown
Contributor

@karelz do you approve this for RC2?

@karelz

Copy link
Copy Markdown
Member

I approve, it is E2E regression - @artl93 it is ready for you

@artl93

Copy link
Copy Markdown
Member

M2 approved.

@artl93artl93 added Servicing-approved Approved for servicing release and removed Servicing-consider Issue for next servicing release review labels Sep 7, 2023
@carlossanlop
carlossanlop merged commit 217be6c into release/8.0Sep 11, 2023
@carlossanlop
carlossanlop deleted the backport/pr-91152-to-release/8.0 branch September 11, 2023 23:09
@radicalradical mentioned this pull request Sep 26, 2023
@radicalradical mentioned this pull request Oct 3, 2023
@ghostghost locked as resolved and limited conversation to collaborators Oct 12, 2023
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@rzikm@filipnavara@carlossanlop@karelz@artl93@wfurt
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' [release/8.0] Fix implementation of NegotiateAuthentication.Wrap for Kerberos on Windows by github-actions[bot] · Pull Request #91311 · dotnet/runtime · GitHub
Skip to content

[release/8.0] Fix implementation of NegotiateAuthentication.Wrap for Kerberos on Windows - #91311

Merged
carlossanlop merged 2 commits into
release/8.0from
backport/pr-91152-to-release/8.0
Sep 11, 2023
Merged

[release/8.0] Fix implementation of NegotiateAuthentication.Wrap for Kerberos on Windows#91311
carlossanlop merged 2 commits into
release/8.0from
backport/pr-91152-to-release/8.0

Conversation

@github-actions

@github-actionsgithub-actionsBot commented Aug 30, 2023

Copy link
Copy Markdown
Contributor

Backport of #91152 to release/8.0

FixesPowerShell/PowerShell#20168

/cc @rzikm@filipnavara

Customer Impact

Regression against 7.0 - Establishing NTLM (Kerberos) authenticated connection can fail with "The encryption operation failed" (see PowerShell/PowerShell#20168).

The story behind the regression:

The regression is caused by changes in .NET Kerberos/NTLM authentication which started in 7.0 and which are finishing now in 8.0. The goal was to introduce public Kerberos/NTLM authentication APIs (NegotiateAuthenticaton) for higher-level frameworks and applications (e.g. ASP.NET needed it to avoid using private Reflection - see #29270).
In 6.0 and earlier, the Kerberos/NTLM authentication (NTAuthentication) was internal only code and was compiled into multiple Networking assemblies (e.g. System.Net.Security, System.Net.Mail, etc.) to avoid using Reflection. Therefore, it also had negative impact on .NET binaries size due to compiled code duplication (while the source code was shared).

In 7.0, we introduced the new public API NegotiateAuthenticaton and we migrated a few internal usages of NTAuthentication to the new public API (e.g. Mail), but not all of them.
One of the public APIs (NegotiateAuthentication.Wrap) had a bug on Windows only that was not exposed until 8.0, when we migrated also NegotiateStream to the public APIs in PR #86948. NegotiateStream support of Kerberos requires more flexibility in encryption padding, which NTLM didn't need, and the new API didn't fully provide it.

This PR brings parity of old internal functionality in NegotiateStreamPal.Encrypt to the new public API NegotiateAuthentication.Wrap.

Testing

The change was tested on affected scenario reported in PowerShell/PowerShell#20168.
Additional validation was performed using a custom/manual NegotiateStream client-server setup between Windows Server 2019 server machine and Windows 11 client machine.

Note: NTLM has good unit test coverage. Kerberos has also good unit test coverage on Linux via Kerberos.NET. However, Kerberos on Windows requires complicated multi-machine setup, therefore it is not automated. We will evaluate feasibility of adding Kerberos test endpoint for CI during 9.0 to address the test gap.

Risk

Low to Medium.

The change affects encryption and signing of data transferred through NegotiateStream. There's no other internal consumer of the NegotiateAuthentication.Wrap API (with exception of single message in SMTP GSSAPI authentication which is covered by tests). Given that this is very advanced API introduced in 7.0, we do not expect there to be any external usages of the API either. And if they are, they would not be ok with the buggy behavior in 7.0.
Only two encryption protocols are supported - NTLM and Kerberos, and NTLM is covered by tests. The Kerberos use case was reported to be broken, and this restores the affected code to mimic the .NET 7 behavior.

@ghost

Copy link
Copy Markdown

Tagging subscribers to this area: @dotnet/ncl, @bartonjs, @vcsjones
See info in area-owners.md if you want to be subscribed.

Issue Details

Backport of #91152 to release/8.0

/cc @rzikm@filipnavara

Customer Impact

Testing

Risk

IMPORTANT: If this backport is for a servicing release, please verify that:

  • The PR target branch is release/X.0-staging, not release/X.0.

  • If the change touches code that ships in a NuGet package, you have added the necessary package authoring and gotten it explicitly reviewed.

Author:github-actions[bot]
Assignees:-
Labels:

area-System.Net.Security

Milestone:-

@rzikm

Copy link
Copy Markdown
Member

@filipnavara would you be able to provide text for the Testing and Risk sections as well?

cc: @karelz

@filipnavara

This comment was marked as duplicate.

@wfurtwfurt left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. Thanks @filipnavara

@carlossanlopcarlossanlop added the Servicing-consider Issue for next servicing release review label Aug 30, 2023
@carlossanlopcarlossanlop added this to the 8.0.0 milestone Aug 30, 2023
@carlossanlop

Copy link
Copy Markdown
Contributor

@karelz do you approve this for RC2?

@karelz

Copy link
Copy Markdown
Member

I approve, it is E2E regression - @artl93 it is ready for you

@artl93

Copy link
Copy Markdown
Member

M2 approved.

@artl93artl93 added Servicing-approved Approved for servicing release and removed Servicing-consider Issue for next servicing release review labels Sep 7, 2023
@carlossanlop
carlossanlop merged commit 217be6c into release/8.0Sep 11, 2023
@carlossanlop
carlossanlop deleted the backport/pr-91152-to-release/8.0 branch September 11, 2023 23:09
@radicalradical mentioned this pull request Sep 26, 2023
@radicalradical mentioned this pull request Oct 3, 2023
@ghostghost locked as resolved and limited conversation to collaborators Oct 12, 2023
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@rzikm@filipnavara@carlossanlop@karelz@artl93@wfurt
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' [release/8.0] Fix implementation of NegotiateAuthentication.Wrap for Kerberos on Windows by github-actions[bot] · Pull Request #91311 · dotnet/runtime · GitHub
Skip to content

[release/8.0] Fix implementation of NegotiateAuthentication.Wrap for Kerberos on Windows - #91311

Merged
carlossanlop merged 2 commits into
release/8.0from
backport/pr-91152-to-release/8.0
Sep 11, 2023
Merged

[release/8.0] Fix implementation of NegotiateAuthentication.Wrap for Kerberos on Windows#91311
carlossanlop merged 2 commits into
release/8.0from
backport/pr-91152-to-release/8.0

Conversation

@github-actions

@github-actionsgithub-actionsBot commented Aug 30, 2023

Copy link
Copy Markdown
Contributor

Backport of #91152 to release/8.0

FixesPowerShell/PowerShell#20168

/cc @rzikm@filipnavara

Customer Impact

Regression against 7.0 - Establishing NTLM (Kerberos) authenticated connection can fail with "The encryption operation failed" (see PowerShell/PowerShell#20168).

The story behind the regression:

The regression is caused by changes in .NET Kerberos/NTLM authentication which started in 7.0 and which are finishing now in 8.0. The goal was to introduce public Kerberos/NTLM authentication APIs (NegotiateAuthenticaton) for higher-level frameworks and applications (e.g. ASP.NET needed it to avoid using private Reflection - see #29270).
In 6.0 and earlier, the Kerberos/NTLM authentication (NTAuthentication) was internal only code and was compiled into multiple Networking assemblies (e.g. System.Net.Security, System.Net.Mail, etc.) to avoid using Reflection. Therefore, it also had negative impact on .NET binaries size due to compiled code duplication (while the source code was shared).

In 7.0, we introduced the new public API NegotiateAuthenticaton and we migrated a few internal usages of NTAuthentication to the new public API (e.g. Mail), but not all of them.
One of the public APIs (NegotiateAuthentication.Wrap) had a bug on Windows only that was not exposed until 8.0, when we migrated also NegotiateStream to the public APIs in PR #86948. NegotiateStream support of Kerberos requires more flexibility in encryption padding, which NTLM didn't need, and the new API didn't fully provide it.

This PR brings parity of old internal functionality in NegotiateStreamPal.Encrypt to the new public API NegotiateAuthentication.Wrap.

Testing

The change was tested on affected scenario reported in PowerShell/PowerShell#20168.
Additional validation was performed using a custom/manual NegotiateStream client-server setup between Windows Server 2019 server machine and Windows 11 client machine.

Note: NTLM has good unit test coverage. Kerberos has also good unit test coverage on Linux via Kerberos.NET. However, Kerberos on Windows requires complicated multi-machine setup, therefore it is not automated. We will evaluate feasibility of adding Kerberos test endpoint for CI during 9.0 to address the test gap.

Risk

Low to Medium.

The change affects encryption and signing of data transferred through NegotiateStream. There's no other internal consumer of the NegotiateAuthentication.Wrap API (with exception of single message in SMTP GSSAPI authentication which is covered by tests). Given that this is very advanced API introduced in 7.0, we do not expect there to be any external usages of the API either. And if they are, they would not be ok with the buggy behavior in 7.0.
Only two encryption protocols are supported - NTLM and Kerberos, and NTLM is covered by tests. The Kerberos use case was reported to be broken, and this restores the affected code to mimic the .NET 7 behavior.

@ghost

Copy link
Copy Markdown

Tagging subscribers to this area: @dotnet/ncl, @bartonjs, @vcsjones
See info in area-owners.md if you want to be subscribed.

Issue Details

Backport of #91152 to release/8.0

/cc @rzikm@filipnavara

Customer Impact

Testing

Risk

IMPORTANT: If this backport is for a servicing release, please verify that:

  • The PR target branch is release/X.0-staging, not release/X.0.

  • If the change touches code that ships in a NuGet package, you have added the necessary package authoring and gotten it explicitly reviewed.

Author:github-actions[bot]
Assignees:-
Labels:

area-System.Net.Security

Milestone:-

@rzikm

Copy link
Copy Markdown
Member

@filipnavara would you be able to provide text for the Testing and Risk sections as well?

cc: @karelz

@filipnavara

This comment was marked as duplicate.

@wfurtwfurt left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. Thanks @filipnavara

@carlossanlopcarlossanlop added the Servicing-consider Issue for next servicing release review label Aug 30, 2023
@carlossanlopcarlossanlop added this to the 8.0.0 milestone Aug 30, 2023
@carlossanlop

Copy link
Copy Markdown
Contributor

@karelz do you approve this for RC2?

@karelz

Copy link
Copy Markdown
Member

I approve, it is E2E regression - @artl93 it is ready for you

@artl93

Copy link
Copy Markdown
Member

M2 approved.

@artl93artl93 added Servicing-approved Approved for servicing release and removed Servicing-consider Issue for next servicing release review labels Sep 7, 2023
@carlossanlop
carlossanlop merged commit 217be6c into release/8.0Sep 11, 2023
@carlossanlop
carlossanlop deleted the backport/pr-91152-to-release/8.0 branch September 11, 2023 23:09
@radicalradical mentioned this pull request Sep 26, 2023
@radicalradical mentioned this pull request Oct 3, 2023
@ghostghost locked as resolved and limited conversation to collaborators Oct 12, 2023
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@rzikm@filipnavara@carlossanlop@karelz@artl93@wfurt
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' [release/8.0] Fix implementation of NegotiateAuthentication.Wrap for Kerberos on Windows by github-actions[bot] · Pull Request #91311 · dotnet/runtime · GitHub
Skip to content

[release/8.0] Fix implementation of NegotiateAuthentication.Wrap for Kerberos on Windows - #91311

Merged
carlossanlop merged 2 commits into
release/8.0from
backport/pr-91152-to-release/8.0
Sep 11, 2023
Merged

[release/8.0] Fix implementation of NegotiateAuthentication.Wrap for Kerberos on Windows#91311
carlossanlop merged 2 commits into
release/8.0from
backport/pr-91152-to-release/8.0

Conversation

@github-actions

@github-actionsgithub-actionsBot commented Aug 30, 2023

Copy link
Copy Markdown
Contributor

Backport of #91152 to release/8.0

FixesPowerShell/PowerShell#20168

/cc @rzikm@filipnavara

Customer Impact

Regression against 7.0 - Establishing NTLM (Kerberos) authenticated connection can fail with "The encryption operation failed" (see PowerShell/PowerShell#20168).

The story behind the regression:

The regression is caused by changes in .NET Kerberos/NTLM authentication which started in 7.0 and which are finishing now in 8.0. The goal was to introduce public Kerberos/NTLM authentication APIs (NegotiateAuthenticaton) for higher-level frameworks and applications (e.g. ASP.NET needed it to avoid using private Reflection - see #29270).
In 6.0 and earlier, the Kerberos/NTLM authentication (NTAuthentication) was internal only code and was compiled into multiple Networking assemblies (e.g. System.Net.Security, System.Net.Mail, etc.) to avoid using Reflection. Therefore, it also had negative impact on .NET binaries size due to compiled code duplication (while the source code was shared).

In 7.0, we introduced the new public API NegotiateAuthenticaton and we migrated a few internal usages of NTAuthentication to the new public API (e.g. Mail), but not all of them.
One of the public APIs (NegotiateAuthentication.Wrap) had a bug on Windows only that was not exposed until 8.0, when we migrated also NegotiateStream to the public APIs in PR #86948. NegotiateStream support of Kerberos requires more flexibility in encryption padding, which NTLM didn't need, and the new API didn't fully provide it.

This PR brings parity of old internal functionality in NegotiateStreamPal.Encrypt to the new public API NegotiateAuthentication.Wrap.

Testing

The change was tested on affected scenario reported in PowerShell/PowerShell#20168.
Additional validation was performed using a custom/manual NegotiateStream client-server setup between Windows Server 2019 server machine and Windows 11 client machine.

Note: NTLM has good unit test coverage. Kerberos has also good unit test coverage on Linux via Kerberos.NET. However, Kerberos on Windows requires complicated multi-machine setup, therefore it is not automated. We will evaluate feasibility of adding Kerberos test endpoint for CI during 9.0 to address the test gap.

Risk

Low to Medium.

The change affects encryption and signing of data transferred through NegotiateStream. There's no other internal consumer of the NegotiateAuthentication.Wrap API (with exception of single message in SMTP GSSAPI authentication which is covered by tests). Given that this is very advanced API introduced in 7.0, we do not expect there to be any external usages of the API either. And if they are, they would not be ok with the buggy behavior in 7.0.
Only two encryption protocols are supported - NTLM and Kerberos, and NTLM is covered by tests. The Kerberos use case was reported to be broken, and this restores the affected code to mimic the .NET 7 behavior.

@ghost

Copy link
Copy Markdown

Tagging subscribers to this area: @dotnet/ncl, @bartonjs, @vcsjones
See info in area-owners.md if you want to be subscribed.

Issue Details

Backport of #91152 to release/8.0

/cc @rzikm@filipnavara

Customer Impact

Testing

Risk

IMPORTANT: If this backport is for a servicing release, please verify that:

  • The PR target branch is release/X.0-staging, not release/X.0.

  • If the change touches code that ships in a NuGet package, you have added the necessary package authoring and gotten it explicitly reviewed.

Author:github-actions[bot]
Assignees:-
Labels:

area-System.Net.Security

Milestone:-

@rzikm

Copy link
Copy Markdown
Member

@filipnavara would you be able to provide text for the Testing and Risk sections as well?

cc: @karelz

@filipnavara

This comment was marked as duplicate.

@wfurtwfurt left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. Thanks @filipnavara

@carlossanlopcarlossanlop added the Servicing-consider Issue for next servicing release review label Aug 30, 2023
@carlossanlopcarlossanlop added this to the 8.0.0 milestone Aug 30, 2023
@carlossanlop

Copy link
Copy Markdown
Contributor

@karelz do you approve this for RC2?

@karelz

Copy link
Copy Markdown
Member

I approve, it is E2E regression - @artl93 it is ready for you

@artl93

Copy link
Copy Markdown
Member

M2 approved.

@artl93artl93 added Servicing-approved Approved for servicing release and removed Servicing-consider Issue for next servicing release review labels Sep 7, 2023
@carlossanlop
carlossanlop merged commit 217be6c into release/8.0Sep 11, 2023
@carlossanlop
carlossanlop deleted the backport/pr-91152-to-release/8.0 branch September 11, 2023 23:09
@radicalradical mentioned this pull request Sep 26, 2023
@radicalradical mentioned this pull request Oct 3, 2023
@ghostghost locked as resolved and limited conversation to collaborators Oct 12, 2023
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@rzikm@filipnavara@carlossanlop@karelz@artl93@wfurt
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' [release/8.0] Fix implementation of NegotiateAuthentication.Wrap for Kerberos on Windows by github-actions[bot] · Pull Request #91311 · dotnet/runtime · GitHub
Skip to content

[release/8.0] Fix implementation of NegotiateAuthentication.Wrap for Kerberos on Windows - #91311

Merged
carlossanlop merged 2 commits into
release/8.0from
backport/pr-91152-to-release/8.0
Sep 11, 2023
Merged

[release/8.0] Fix implementation of NegotiateAuthentication.Wrap for Kerberos on Windows#91311
carlossanlop merged 2 commits into
release/8.0from
backport/pr-91152-to-release/8.0

Conversation

@github-actions

@github-actionsgithub-actionsBot commented Aug 30, 2023

Copy link
Copy Markdown
Contributor

Backport of #91152 to release/8.0

FixesPowerShell/PowerShell#20168

/cc @rzikm@filipnavara

Customer Impact

Regression against 7.0 - Establishing NTLM (Kerberos) authenticated connection can fail with "The encryption operation failed" (see PowerShell/PowerShell#20168).

The story behind the regression:

The regression is caused by changes in .NET Kerberos/NTLM authentication which started in 7.0 and which are finishing now in 8.0. The goal was to introduce public Kerberos/NTLM authentication APIs (NegotiateAuthenticaton) for higher-level frameworks and applications (e.g. ASP.NET needed it to avoid using private Reflection - see #29270).
In 6.0 and earlier, the Kerberos/NTLM authentication (NTAuthentication) was internal only code and was compiled into multiple Networking assemblies (e.g. System.Net.Security, System.Net.Mail, etc.) to avoid using Reflection. Therefore, it also had negative impact on .NET binaries size due to compiled code duplication (while the source code was shared).

In 7.0, we introduced the new public API NegotiateAuthenticaton and we migrated a few internal usages of NTAuthentication to the new public API (e.g. Mail), but not all of them.
One of the public APIs (NegotiateAuthentication.Wrap) had a bug on Windows only that was not exposed until 8.0, when we migrated also NegotiateStream to the public APIs in PR #86948. NegotiateStream support of Kerberos requires more flexibility in encryption padding, which NTLM didn't need, and the new API didn't fully provide it.

This PR brings parity of old internal functionality in NegotiateStreamPal.Encrypt to the new public API NegotiateAuthentication.Wrap.

Testing

The change was tested on affected scenario reported in PowerShell/PowerShell#20168.
Additional validation was performed using a custom/manual NegotiateStream client-server setup between Windows Server 2019 server machine and Windows 11 client machine.

Note: NTLM has good unit test coverage. Kerberos has also good unit test coverage on Linux via Kerberos.NET. However, Kerberos on Windows requires complicated multi-machine setup, therefore it is not automated. We will evaluate feasibility of adding Kerberos test endpoint for CI during 9.0 to address the test gap.

Risk

Low to Medium.

The change affects encryption and signing of data transferred through NegotiateStream. There's no other internal consumer of the NegotiateAuthentication.Wrap API (with exception of single message in SMTP GSSAPI authentication which is covered by tests). Given that this is very advanced API introduced in 7.0, we do not expect there to be any external usages of the API either. And if they are, they would not be ok with the buggy behavior in 7.0.
Only two encryption protocols are supported - NTLM and Kerberos, and NTLM is covered by tests. The Kerberos use case was reported to be broken, and this restores the affected code to mimic the .NET 7 behavior.

@ghost

Copy link
Copy Markdown

Tagging subscribers to this area: @dotnet/ncl, @bartonjs, @vcsjones
See info in area-owners.md if you want to be subscribed.

Issue Details

Backport of #91152 to release/8.0

/cc @rzikm@filipnavara

Customer Impact

Testing

Risk

IMPORTANT: If this backport is for a servicing release, please verify that:

  • The PR target branch is release/X.0-staging, not release/X.0.

  • If the change touches code that ships in a NuGet package, you have added the necessary package authoring and gotten it explicitly reviewed.

Author:github-actions[bot]
Assignees:-
Labels:

area-System.Net.Security

Milestone:-

@rzikm

Copy link
Copy Markdown
Member

@filipnavara would you be able to provide text for the Testing and Risk sections as well?

cc: @karelz

@filipnavara

This comment was marked as duplicate.

@wfurtwfurt left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. Thanks @filipnavara

@carlossanlopcarlossanlop added the Servicing-consider Issue for next servicing release review label Aug 30, 2023
@carlossanlopcarlossanlop added this to the 8.0.0 milestone Aug 30, 2023
@carlossanlop

Copy link
Copy Markdown
Contributor

@karelz do you approve this for RC2?

@karelz

Copy link
Copy Markdown
Member

I approve, it is E2E regression - @artl93 it is ready for you

@artl93

Copy link
Copy Markdown
Member

M2 approved.

@artl93artl93 added Servicing-approved Approved for servicing release and removed Servicing-consider Issue for next servicing release review labels Sep 7, 2023
@carlossanlop
carlossanlop merged commit 217be6c into release/8.0Sep 11, 2023
@carlossanlop
carlossanlop deleted the backport/pr-91152-to-release/8.0 branch September 11, 2023 23:09
@radicalradical mentioned this pull request Sep 26, 2023
@radicalradical mentioned this pull request Oct 3, 2023
@ghostghost locked as resolved and limited conversation to collaborators Oct 12, 2023
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@rzikm@filipnavara@carlossanlop@karelz@artl93@wfurt
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); })(); [release/8.0] Fix implementation of NegotiateAuthentication.Wrap for Kerberos on Windows by github-actions[bot] · Pull Request #91311 · dotnet/runtime · GitHub
Skip to content

[release/8.0] Fix implementation of NegotiateAuthentication.Wrap for Kerberos on Windows - #91311

Merged
carlossanlop merged 2 commits into
release/8.0from
backport/pr-91152-to-release/8.0
Sep 11, 2023
Merged

[release/8.0] Fix implementation of NegotiateAuthentication.Wrap for Kerberos on Windows#91311
carlossanlop merged 2 commits into
release/8.0from
backport/pr-91152-to-release/8.0

Conversation

@github-actions

@github-actionsgithub-actionsBot commented Aug 30, 2023

Copy link
Copy Markdown
Contributor

Backport of #91152 to release/8.0

FixesPowerShell/PowerShell#20168

/cc @rzikm@filipnavara

Customer Impact

Regression against 7.0 - Establishing NTLM (Kerberos) authenticated connection can fail with "The encryption operation failed" (see PowerShell/PowerShell#20168).

The story behind the regression:

The regression is caused by changes in .NET Kerberos/NTLM authentication which started in 7.0 and which are finishing now in 8.0. The goal was to introduce public Kerberos/NTLM authentication APIs (NegotiateAuthenticaton) for higher-level frameworks and applications (e.g. ASP.NET needed it to avoid using private Reflection - see #29270).
In 6.0 and earlier, the Kerberos/NTLM authentication (NTAuthentication) was internal only code and was compiled into multiple Networking assemblies (e.g. System.Net.Security, System.Net.Mail, etc.) to avoid using Reflection. Therefore, it also had negative impact on .NET binaries size due to compiled code duplication (while the source code was shared).

In 7.0, we introduced the new public API NegotiateAuthenticaton and we migrated a few internal usages of NTAuthentication to the new public API (e.g. Mail), but not all of them.
One of the public APIs (NegotiateAuthentication.Wrap) had a bug on Windows only that was not exposed until 8.0, when we migrated also NegotiateStream to the public APIs in PR #86948. NegotiateStream support of Kerberos requires more flexibility in encryption padding, which NTLM didn't need, and the new API didn't fully provide it.

This PR brings parity of old internal functionality in NegotiateStreamPal.Encrypt to the new public API NegotiateAuthentication.Wrap.

Testing

The change was tested on affected scenario reported in PowerShell/PowerShell#20168.
Additional validation was performed using a custom/manual NegotiateStream client-server setup between Windows Server 2019 server machine and Windows 11 client machine.

Note: NTLM has good unit test coverage. Kerberos has also good unit test coverage on Linux via Kerberos.NET. However, Kerberos on Windows requires complicated multi-machine setup, therefore it is not automated. We will evaluate feasibility of adding Kerberos test endpoint for CI during 9.0 to address the test gap.

Risk

Low to Medium.

The change affects encryption and signing of data transferred through NegotiateStream. There's no other internal consumer of the NegotiateAuthentication.Wrap API (with exception of single message in SMTP GSSAPI authentication which is covered by tests). Given that this is very advanced API introduced in 7.0, we do not expect there to be any external usages of the API either. And if they are, they would not be ok with the buggy behavior in 7.0.
Only two encryption protocols are supported - NTLM and Kerberos, and NTLM is covered by tests. The Kerberos use case was reported to be broken, and this restores the affected code to mimic the .NET 7 behavior.

@ghost

Copy link
Copy Markdown

Tagging subscribers to this area: @dotnet/ncl, @bartonjs, @vcsjones
See info in area-owners.md if you want to be subscribed.

Issue Details

Backport of #91152 to release/8.0

/cc @rzikm@filipnavara

Customer Impact

Testing

Risk

IMPORTANT: If this backport is for a servicing release, please verify that:

  • The PR target branch is release/X.0-staging, not release/X.0.

  • If the change touches code that ships in a NuGet package, you have added the necessary package authoring and gotten it explicitly reviewed.

Author:github-actions[bot]
Assignees:-
Labels:

area-System.Net.Security

Milestone:-

@rzikm

Copy link
Copy Markdown
Member

@filipnavara would you be able to provide text for the Testing and Risk sections as well?

cc: @karelz

@filipnavara

This comment was marked as duplicate.

@wfurtwfurt left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. Thanks @filipnavara

@carlossanlopcarlossanlop added the Servicing-consider Issue for next servicing release review label Aug 30, 2023
@carlossanlopcarlossanlop added this to the 8.0.0 milestone Aug 30, 2023
@carlossanlop

Copy link
Copy Markdown
Contributor

@karelz do you approve this for RC2?

@karelz

Copy link
Copy Markdown
Member

I approve, it is E2E regression - @artl93 it is ready for you

@artl93

Copy link
Copy Markdown
Member

M2 approved.

@artl93artl93 added Servicing-approved Approved for servicing release and removed Servicing-consider Issue for next servicing release review labels Sep 7, 2023
@carlossanlop
carlossanlop merged commit 217be6c into release/8.0Sep 11, 2023
@carlossanlop
carlossanlop deleted the backport/pr-91152-to-release/8.0 branch September 11, 2023 23:09
@radicalradical mentioned this pull request Sep 26, 2023
@radicalradical mentioned this pull request Oct 3, 2023
@ghostghost locked as resolved and limited conversation to collaborators Oct 12, 2023
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@rzikm@filipnavara@carlossanlop@karelz@artl93@wfurt