|
ok,that key hardcoding issue is resolved now thanks much but regarding
those DLEs as i have shared sample
On Fri, Nov 22, 2019 at 5:01 PM Bruce Vining <bruce.vining@xxxxxxxxx>
wrote:
-- cmd = 'echo ' + '''' + encodedExchangeToken + ''' ! openssl +
-- enc -d -aes-128-ecb -K 363631653237354f494d31554c594c4a +
-- -nopad -nosalt -base64 -A';
The above does NOT represent the changes suggested in my previous reply.
I
would have expected to see something like
...-K ' + KEY + ' -nopad...
The provided text still has the key value as a literal.
--
<encodedExchangeToken>u3VtNgfyWU9faZc3Iaa8ZWbE5UZCfmC17yA4MyW0ghflt9dNQNDpCcgMZiG/kXPE4vv2CHL93B4iKiODHxxdVA==---
</encodedExchangeToken>
You have confirmed that the XML file contains the "extra" 16 bytes.
Who/what provided this value? This line indicates to ship those 16 bytes,
which are being decoded and decrypted into DLEs. From what I can see
everything is working just like one would expect given this source...
On Fri, Nov 22, 2019 at 10:42 AM Rishi Seth <rishiseth99@xxxxxxxxx>
wrote:
ok,thanks tried as per below now and when ran it got below errors:-is
cmd = 'echo ' + '''' + encodedExchangeToken + ''' ! openssl +
enc -d -aes-128-ecb -K 363631653237354f494d31554c594c4a +
-nopad -nosalt -base64 -A';
**************************************************************
Additional Message Information
Message ID . . . . . . : RNQ0103 Severity . . . . . . . : 99
Message type . . . . . : Inquiry
Date sent . . . . . . : 19-11-22 Time sent . . . . . . :
15:40:09
Message . . . . : The target for a numeric operation is too small to
hold
the result (C G D F).
Cause . . . . . : RPG procedure DCR19 in program RISHI/DCR19 at
statement
113 performed an arithmetic operation which resulted in a value that
toomaintenance
large to fit in the target. If this is a numeric expression, the
overflow
could be the result of the calculation of some intermediate result.
Recovery . . . : Contact the person responsible for program
to:
determine the cause of the problem.
Possible choices for replying to message . . . . . . . . . . . . . . .
level
D -- Obtain RPG formatted dump.
S -- Obtain system dump.
F -- Obtain full formatted dump.
More...
Press Enter to continue.
F3=Exit F6=Print F9=Display message details
F10=Display messages in job log F12=Cancel F21=Select assistance
which
***********************************************************
Additional Message Information
Message ID . . . . . . : CPF9999 Severity . . . . . . . : 40
Message type . . . . . : Escape
Date sent . . . . . . : 19-11-22 Time sent . . . . . . :
15:40:09
Message . . . . : Function check. MCH1210 unmonitored by DCR19 at
statement
0000000113, instruction X'0000'.
Cause . . . . . : An escape exception message was sent to a program
which
did not monitor for that message. The full name of the program to
theactual
unmonitored message was sent is DCR19 DCR19 DCR19. At the time the
message
was sent the program was stopped at higher level language statement
number(s) 0000000113. If more than one statement number is shown, the
program was a bound program. Optimization does not allow a single
statement
number to be determined. If *N is shown as a value, it means the
locate
value was not available.
Recovery . . . : See the low level messages previously listed to
thehttp://schemas.nav.gov.hu/OSA/1.0/data"
cause of the function check. Correct any errors, and then try the
request
More...
Press Enter to continue.
*********
And if XML is causing those DLEs then I think i need not to bother as we
have put below changes so i think it will take care care of all those
unforeseen junk(DLEs).
pos2 = %scan(x'10' :record);
Record = %subst(Record :1 :(Pos2 - 1));
please correct me if i am wrong and below is requested xml for DLEs
analysis>/
<?xml version="1.0" encoding="UTF-8" standalone="true"?>
-<TokenExchangeResponse xmlns:ns2="
xmlns="http://schemas.nav.gov.hu/OSA/1.0/api"><encodedExchangeToken>u3VtNgfyWU9faZc3Iaa8ZWbE5UZCfmC17yA4MyW0ghflt9dNQNDpCcgMZiG/kXPE4vv2CHL93B4iKiODHxxdVA==</encodedExchangeToken>
-<header>
<requestId>XXXXXXX6614</requestId>
<timestamp>2019-10-22T09:53:40.541Z</timestamp>
<requestVersion>1.1</requestVersion>
<headerVersion>1.0</headerVersion>
</header>
-<result>
<funcCode>OK</funcCode>
</result>
-<software>
<softwareId>R1RL002AAAAAAAAAAA</softwareId>
<softwareName>string</softwareName>
<softwareOperation>LOCAL_SOFTWARE</softwareOperation>
<softwareMainVersion>string</softwareMainVersion>
<softwareDevName>string</softwareDevName>
<softwareDevContact>string</softwareDevContact>
<softwareDevCountryCode>HU</softwareDevCountryCode>
<softwareDevTaxNumber>string</softwareDevTaxNumber>
</software>
ending
<tokenValidityFrom>2019-10-22T11:57:16.646+02:00</tokenValidityFrom>
<tokenValidityTo>2019-10-22T12:02:16.646+02:00</tokenValidityTo>
</TokenExchangeResponse>
Thanks
On Fri, Nov 22, 2019 at 3:00 PM Bruce Vining <bruce.vining@xxxxxxxxx>
wrote:
You have KEY within the quoted string starting with ! openssl and
(andwith -A';
End the quoted string prior to KEY and then resume it following KEY
assumeadd + before and after so everything is nicely concatenated...)
As for the DLEs, again I have to, based on provided information,
theprogram
XML file is the source -- that is, whoever is writing/construction theXML.
wrote:
On Fri, Nov 22, 2019 at 8:20 AM Rishi Seth <rishiseth99@xxxxxxxxx>
called
Hi,
I tried below code in which i have kept hex value of key in a file
k1 and field called key in this file but the problem is that my
....5...10...15...20...25...30...35...40...45...50...55...60isvalue
able to read key value from this file but the moment
i try to execute this cmd command inside my program and check the
of
cmd field in debug mode i get it like below :-
EVAL cmd
CMD =
'jkYrd7QTBwv6ghTV0SnrqCdwJ8TnpZAk8+oVlNXwt7aDHoJSQWBsh4'1 'echo
-aes-12'61 'R7cggjSc+34vv2CHL93B4iKiODHxxdVA==' ! openssl enc -d
'121 '8-ecb -K key -nopad -nosalt -base64 -A
'181 '
'241 '
valuethat
i was expecting like it took encodedexchangetoken field value from
xml file using xml into builtin function and showing it's value in
encodedexchangetoken field.
but when i read file in my code it does not pick the key field's
value tofrom
this below code i am just wondering how can i pass key field's
+openssl command rather than hardcoding inside my program.
*******
FUNIX IF F 1000 SPECIAL PGMNAME('UNIXCMD')
F PLIST(UNIXPARM) USROPN
fk1 if e disk
F*QSYSPRT O F 1000 PRINTER
dencodedExcha...
dngeToken s 500 VARYING
DPOS2 S 5U 0
D cmd s 5000a
D mode s 1A inz('P')
DN1 S 2P 0
D Åcommand s 512a
d QCMDEXC PR ExtPgm('QCMDEXC')
d command 500a const
d clength 15p 5 const
D record ds 1000
D outrec s 1000 varying inz
C UNIXPARM PLIST
C PARM CMD
C PARM MODE
/free
RECORD = *BLANKS;
OUTREC = *BLANKS;
XML-INTO encodedExchangeToken %XML('/home/I0RS01HU/+
IN2.xml':'doc=file case=any path=+
TokenExchangeResponse/encodedExchangeToken');
eval encodedExchangeToken =%trimr(encodedExchangeToken);
READ rec;
dsply key;
cmd = 'echo ' + '''' + encodedExchangeToken + ''' ! openssl
%char(N1) +enc -d -aes-128-ecb -K KEY +
-nopad -nosalt -base64 -A';
open UNIX;
read UNIX record;
dow not %eof(UNIX);
pos2 = %scan(x'10' :record);
Record = %subst(Record :1 :(Pos2 - 1));
eval outrec = %trimr(record);
EVAL N1 = %LEN(OUTREC);
DSPLY N1;
//Delete the TESTFILE
Åcommand = 'DLTF FILE(rishi/TESTFILE)';
QCMDEXC(%trim(Åcommand): %len(%trim(Åcommand)));
Åcommand = *blanks;
Åcommand = 'CRTPF FILE(RISHI/TESTFILE) RCDLEN(' +
as')';wrote:
QCMDEXC(%trim(Åcommand): %len(%trim(Åcommand)));
//Write into file
EXEC SQL
INSERT INTO rishi/TESTFILE VALUES (:outrec);
// dsply %subst(outrec:1:48);
read UNIX record;
enddo;
close UNIX;
return;
/end-free
Thanks
On Thu, Nov 21, 2019 at 11:38 PM Rishi Seth <rishiseth99@xxxxxxxxx>
Ok, thanks for these details,
Is it possible not to hardcode the key value used here and use it
akey
variable field like field of some file etc.so that each time once
need tois
changed we may not have to change the program code and do not
filewasrecompile it?
Also in input XML we were not focused on other field's only target
just to fetch this 'encodedexchangetoken' field out of that XML
decryptedand
whatever data comes inside this field that should have been
onlyusing
AES 128 Algorithm so far this program seems to be working fine
valuesthing i
was worried because of DLEs but could there be some more junk
all Ihavemightimagine
come like these DLEs in decrypted value, Which currently we can't
and låter on this program might crash as we have not thought of or
callednot
considered handling regarding those probable junk values (Or so
wrote:some other type of DLEs etc.) as of now?
Thanks much.....
On Thu, Nov 21, 2019, 21:17 Bruce Vining <bruce.vining@xxxxxxxxx>
I did not get around to actually trying out Qc3DecryptData.
Yesterday the DLEs in the debug eval of record really told me
lasthadneeded
to know. This morning I looked more at the debug eval
of encodedExchangeToken, saw the leading x'0058' and realized you
itreturned
defined as varying length. That value tells me that XML-INTO
indicating88
bytes and the -base64 argument to enc told me it was base64
thetrailing
actual length received (based64 decoded) was 66 bytes with two
pad
characters (the == from record) leaving 64 "real" bytes. The
16AES
bytes
(the DLEs) then must have been in the original stream (OK, maybe
itthoughdecryption and base64 decoding uses DLEs for errors or somesuch
"someone"I've
never seen that behavior or found it documented). In any case
is
adding 16 bytes to encodedExchangeToken prior to your receiving
with 8.with
XML-INTO. As you did not provide the XML file (as requested
there inPost
the contents of /home/I0RS01HU/INPUT.xml) I'm assuming it's
seenthe
file and that XML-INTO didn't add it (an add which I've never
lotand Itake a
changing.have played with it, XML-INTO, in the past).
As you now have it working with openssl enc I wouldn't bother
biased
Personally I use the i cryptographic APIs (but I'm also somewhat
when it comes to system APIs) when doing development.
When the SQL encrypt and decrypt functions first came out I did
quick look at them and immediately saw that there were a whole
ofrun
support.features (that I sometimes use) that the SQL interfaces do not
sendingSo
I would not use them unless forced to -- meaning that someone was
me data encrypted using say ENCRYPT_AES. To date I have never
multipleintotext
that situation.
I do however wonder why base64 is being used as it appears to be
datamight
being exchanged (with the exception of the DLEs) and what padding
be
done if say the "real" data was only 45 bytes rather than a
rishiseth99@xxxxxxxxx>of
16
such as 48.
Hope this helps,
On Thu, Nov 21, 2019 at 10:09 AM Rishi Seth <
interactivelywrote:
Hi,
How could we say or conclude so because whenever i
wellcall
openssl command the same DLE seems to be coming that time as
isin
the
result of pase ?
so does this mean xml itself is faulty i mean the value which
thatsupplied
in XML (specially data in that encodedexchangetoken field in
(UsingXMLcurrent
file
itself is faulty ?)
secondly were you able to run that 'Qc3DecryptData' API program
successfully could you please share your program example for
case
as i tried to use Qc3DecryptData API for same decryption
dataAES128
Algorithm) but it did not work because i did not know how the
functionwasknow
encrypted only decryption thing i was focused on, as i did not
how
the
data was encoded so may be those sql encrypt and decrypt
Qc3DecryptData'alsofiles
did
not work for this case also when you would have used thatQc3DecryptData
API was your program capable to handle each time different XML
data
like the one which i shared was having XML into kind of builtinfunctions
so it was capable to handle those different XMLs.
1) If same decrypted value could be achived using
wellAPI
Could you please share that program code example ?
2) Can same result be achieved using SQL Decrypt function as
ifinterface...
I'll,yesbruce.vining@xxxxxxxxx>
then could you please share that as well?approaches
3) Which way should be best technically among of all these 3
in case same decrypted value could be achieved using openssl,
Qc3DecryptData API,SQL Decrypt function ?
Thanks much...
On Thu, Nov 21, 2019 at 1:44 PM Bruce Vining <
bruce.vining@xxxxxxxxx>wrote:
The DLEs are in the original XML stream being received.
On Wed, Nov 20, 2019 at 3:17 PM Bruce Vining <
wrote:
Since Rishi has provided the encrypted stream and the key
streamif Ipossible),
find
the time (which as I'm currently free of work should be
decrypt
using Qc3DecryptData and at least find out if it's in the
or
being
added later when running cmd through the UNIXCMD
listthem,sk@xxxxxxxxxxxxxxxx>
On Wed, Nov 20, 2019 at 1:12 PM Scott Klement <
wrote:
The other possibility is that the PASE shell is inserting
terminal?maybe
thinking it needs to escape something for the sake of a
assume
On 11/20/2019 9:32 AM, Bruce Vining wrote:
As I cannot imagine Scott inserting those DLEs I have to
they
are in
the XML document.--
This is the RPG programming on IBM i (RPG400-L) mailing
https://lists.midrange.com/mailman/listinfo/rpg400-lTo post a message email: RPG400-L@xxxxxxxxxxxxxxxxxx
To subscribe, unsubscribe, or change list options,
visit:
archivesor email: RPG400-L-request@xxxxxxxxxxxxxxxxxx
Before posting, please take a moment to review the
ourrelatedat https://archive.midrange.com/rpg400-l.
Please contact support@xxxxxxxxxxxx for any subscription
questions.
Help support midrange.com by shopping at amazon.com with
relatedrelatedaffiliate
link: https://amazon.midrange.com
--
Thanks and Regards,
Bruce
931-505-1915
--
Thanks and Regards,
Bruce
931-505-1915
--
This is the RPG programming on IBM i (RPG400-L) mailing list
To post a message email: RPG400-L@xxxxxxxxxxxxxxxxxx
To subscribe, unsubscribe, or change list options,
visit: https://lists.midrange.com/mailman/listinfo/rpg400-l
or email: RPG400-L-request@xxxxxxxxxxxxxxxxxx
Before posting, please take a moment to review the archives
at https://archive.midrange.com/rpg400-l.
Please contact support@xxxxxxxxxxxx for any subscription
affiliatequestions.
Help support midrange.com by shopping at amazon.com with our
link: https://amazon.midrange.com--
This is the RPG programming on IBM i (RPG400-L) mailing list
To post a message email: RPG400-L@xxxxxxxxxxxxxxxxxx
To subscribe, unsubscribe, or change list options,
visit: https://lists.midrange.com/mailman/listinfo/rpg400-l
or email: RPG400-L-request@xxxxxxxxxxxxxxxxxx
Before posting, please take a moment to review the archives
at https://archive.midrange.com/rpg400-l.
Please contact support@xxxxxxxxxxxx for any subscription
affiliateaffiliateaffiliatequestions.
Help support midrange.com by shopping at amazon.com with our
link: https://amazon.midrange.com
--
Thanks and Regards,
Bruce
931-505-1915
--
This is the RPG programming on IBM i (RPG400-L) mailing list
To post a message email: RPG400-L@xxxxxxxxxxxxxxxxxx
To subscribe, unsubscribe, or change list options,
visit: https://lists.midrange.com/mailman/listinfo/rpg400-l
or email: RPG400-L-request@xxxxxxxxxxxxxxxxxx
Before posting, please take a moment to review the archives
at https://archive.midrange.com/rpg400-l.
Please contact support@xxxxxxxxxxxx for any subscription related
questions.
Help support midrange.com by shopping at amazon.com with our
--link: https://amazon.midrange.com
This is the RPG programming on IBM i (RPG400-L) mailing list
To post a message email: RPG400-L@xxxxxxxxxxxxxxxxxx
To subscribe, unsubscribe, or change list options,
visit: https://lists.midrange.com/mailman/listinfo/rpg400-l
or email: RPG400-L-request@xxxxxxxxxxxxxxxxxx
Before posting, please take a moment to review the archives
at https://archive.midrange.com/rpg400-l.
Please contact support@xxxxxxxxxxxx for any subscription related
questions.
Help support midrange.com by shopping at amazon.com with our
affiliatelink: https://amazon.midrange.com
--
Thanks and Regards,
Bruce
931-505-1915
--
This is the RPG programming on IBM i (RPG400-L) mailing list
To post a message email: RPG400-L@xxxxxxxxxxxxxxxxxx
To subscribe, unsubscribe, or change list options,
visit: https://lists.midrange.com/mailman/listinfo/rpg400-l
or email: RPG400-L-request@xxxxxxxxxxxxxxxxxx
Before posting, please take a moment to review the archives
at https://archive.midrange.com/rpg400-l.
Please contact support@xxxxxxxxxxxx for any subscription related
questions.
Help support midrange.com by shopping at amazon.com with our
link: https://amazon.midrange.com--
This is the RPG programming on IBM i (RPG400-L) mailing list
To post a message email: RPG400-L@xxxxxxxxxxxxxxxxxx
To subscribe, unsubscribe, or change list options,
visit: https://lists.midrange.com/mailman/listinfo/rpg400-l
or email: RPG400-L-request@xxxxxxxxxxxxxxxxxx
Before posting, please take a moment to review the archives
at https://archive.midrange.com/rpg400-l.
Please contact support@xxxxxxxxxxxx for any subscription related
questions.
Help support midrange.com by shopping at amazon.com with our affiliate
link: https://amazon.midrange.com
--
Thanks and Regards,
Bruce
931-505-1915
--
This is the RPG programming on IBM i (RPG400-L) mailing list
To post a message email: RPG400-L@xxxxxxxxxxxxxxxxxx
To subscribe, unsubscribe, or change list options,
visit: https://lists.midrange.com/mailman/listinfo/rpg400-l
or email: RPG400-L-request@xxxxxxxxxxxxxxxxxx
Before posting, please take a moment to review the archives
at https://archive.midrange.com/rpg400-l.
Please contact support@xxxxxxxxxxxx for any subscription related
questions.
Help support midrange.com by shopping at amazon.com with our affiliate
link: https://amazon.midrange.com
As an Amazon Associate we earn from qualifying purchases.
This mailing list archive is Copyright 1997-2024 by midrange.com and David Gibbs as a compilation work. Use of the archive is restricted to research of a business or technical nature. Any other uses are prohibited. Full details are available on our policy page. If you have questions about this, please contact [javascript protected email address].
Operating expenses for this site are earned using the Amazon Associate program and Google Adsense.