2
0
mirror of https://github.com/xcat2/xcat-core.git synced 2026-10-06 17:46:55 +00:00

fix: fall back from sha256 to sha1 on RAKP2 auth rejection

Extend the existing sha256-to-sha1 fallback (already present in
got_rmcp_response for Open Session errors) to also cover RAKP2
rejections with "Unauthorized name" (0x0d) or "Invalid role" (0x09).

Ref: #7511
This commit is contained in:
Vinícius Ferrão
2026-05-06 01:26:29 -03:00
parent 86f6a12264
commit c0e8b1730e
+6
View File
@@ -973,6 +973,12 @@ sub got_rakp2 {
}
$byte = shift @data;
unless ($byte == 0x00) {
if (($byte == 0x9 or $byte == 0xd) and $self->{attempthash} == 256) {
$self->{attempthash} = 1;
$self->{sessionestablishmentcontext} = 0;
$self->open_rmcpplus_request();
return;
}
if (($byte == 0x9 or $byte == 0xd) and $self->{privlevel} == 4) {
# this is probably an environment that wants to give us only operator