From bc7c644664c2896afc7eb64206068b3efcf6fe2d Mon Sep 17 00:00:00 2001 From: Quantum Date: Sat, 4 Jul 2020 15:40:06 -0400 Subject: [PATCH] Remove direct reference to SHA512 for HMAC verification --- nginx_krbauth.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/nginx_krbauth.py b/nginx_krbauth.py index 9b74f73..b56d2bd 100644 --- a/nginx_krbauth.py +++ b/nginx_krbauth.py @@ -73,7 +73,7 @@ def verify_cookie(cookie, context): return False if not hmac.compare_digest(message[timestamp.size + RANDOM_SIZE:], context.bytes()): return False - expected = hmac.new(HMAC_KEY, message, hashlib.sha512).digest() + expected = hmac.new(HMAC_KEY, message, hmac_digest).digest() return hmac.compare_digest(expected, signature)