From be5bc3cbdf14eaf9c461315c126f0dbd06be3a40 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Markus=20Bl=C3=B6chl?= Date: Sun, 5 Apr 2020 15:10:05 +0200 Subject: [PATCH 1/2] Clarify the key pair usages in the prodocol description --- keepassxc-protocol.md | 21 +++++++++++++-------- 1 file changed, 13 insertions(+), 8 deletions(-) diff --git a/keepassxc-protocol.md b/keepassxc-protocol.md index edfc09d..e242fce 100644 --- a/keepassxc-protocol.md +++ b/keepassxc-protocol.md @@ -10,11 +10,16 @@ Now the requests are encrypted by [TweetNaCl.js](https://github.com/dchest/tweet 5. When KeePassXC sends a message it is encrypted with keepassxc-browser's public key and an incremented nonce. 6. Databases are stored with newly created public key used with `associate`. A new key pair for data transfer is generated each time keepassxc-browser is launched. This saved key is not used again, as it's only used for identification. +Thus there are three key pairs involved in every communication: +- `host key` - A temporary key pair created by KeePassXC to encrypt the communication of the current session. +- `client key` - A temporary key pair created by keepassxc-browser to encrypt the communication of the current session. +- `identification key` - A permanent key pair created by keepassxc-browser used to authenticate the browser in later sessions after it was successfully *associated* with a database. This one should be stored safely by the browser. Note that only the public key part is ever used which might be a tiny flaw in the protocol since that part is also stored in the database. + Encrypted messages are built with these JSON parameters: - action - `test-associate`, `associate`, `get-logins`, `get-logins-count`, `set-login`... - message - Encrypted message, base64 encoded - nonce - 24 bytes long random data, base64 encoded. This is incremented to the response. -- clientID - 24 bytes long random data, base64 encoded. This is used to identify different browsers if multiple are used with proxy application. +- clientID - 24 bytes long random data, base64 encoded. This is used for a single session to identify different browsers if multiple are used with proxy application. Currently these messages are implemented: - `change-public-keys`: Request for passing public keys from client to server and back. @@ -33,7 +38,7 @@ Request: ```javascript { "action": "change-public-keys", - "publicKey": "", + "publicKey": "", "nonce": "tZvLrBzkQ9GxXq9PvKJj4iAnfPT0VZ3Q", "clientID": "" } @@ -81,8 +86,8 @@ Unencrypted message: ```javascript { "action": "associate", - "key": "", - "idKey": "" + "key": "", + "idKey": "" } ``` @@ -112,8 +117,8 @@ Unencrypted message: ```javascript { "action": "test-associate", - "id": "", - "key": "" + "id": "", + "key": "" } ``` @@ -173,8 +178,8 @@ Unencrypted message: "httpAuth": optional, "keys": [ { - "id": , - "key": + "id": "", + "key": "" }, ... ] From 51c40edf66a6c35457c22af316d442f0278ba900 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Markus=20Bl=C3=B6chl?= Date: Sun, 5 Apr 2020 15:11:06 +0200 Subject: [PATCH 2/2] Use json for all syntax blocks --- keepassxc-protocol.md | 56 +++++++++++++++++++++---------------------- 1 file changed, 28 insertions(+), 28 deletions(-) diff --git a/keepassxc-protocol.md b/keepassxc-protocol.md index e242fce..0dae010 100644 --- a/keepassxc-protocol.md +++ b/keepassxc-protocol.md @@ -35,7 +35,7 @@ Currently these messages are implemented: ### change-public-keys Request: -```javascript +```json { "action": "change-public-keys", "publicKey": "", @@ -45,7 +45,7 @@ Request: ``` Response (success): -```javascript +```json { "action": "change-public-keys", "version": "2.2.0", @@ -56,14 +56,14 @@ Response (success): ### get-databasehash Unencrypted message: -```javascript +```json { "action": "get-databasehash" } ``` Request: -```javascript +```json { "action": "get-databasehash", "message": "", @@ -73,7 +73,7 @@ Request: ``` Response message data (success, decrypted): -```javascript +```json { "action": "hash", "hash": "29234e32274a32276e25666a42", @@ -83,7 +83,7 @@ Response message data (success, decrypted): ### associate Unencrypted message: -```javascript +```json { "action": "associate", "key": "", @@ -92,7 +92,7 @@ Unencrypted message: ``` Request: -```javascript +```json { "action": "associate", "message": "", @@ -102,7 +102,7 @@ Request: ``` Response message data (success, decrypted): -```javascript +```json { "hash": "29234e32274a32276e25666a42", "version": "2.2.0", @@ -114,7 +114,7 @@ Response message data (success, decrypted): ### test-associate Unencrypted message: -```javascript +```json { "action": "test-associate", "id": "", @@ -123,7 +123,7 @@ Unencrypted message: ``` Request: -```javascript +```json { "action": "test-associate", "message": "", @@ -133,7 +133,7 @@ Request: ``` Response message data (success, decrypted): -```javascript +```json { "version": "2.2.0", "nonce": "tZvLrBzkQ9GxXq9PvKJj4iAnfPT0VZ3Q", @@ -145,7 +145,7 @@ Response message data (success, decrypted): ### generate-password Request (no unencrypted message is needed): -```javascript +```json { "action": "generate-password", "nonce": "tZvLrBzkQ9GxXq9PvKJj4iAnfPT0VZ3Q", @@ -154,7 +154,7 @@ Request (no unencrypted message is needed): ``` Response message data (success, decrypted): -```javascript +```json { "version": "2.2.0", "entries": [ @@ -170,12 +170,12 @@ Response message data (success, decrypted): ### get-logins Unencrypted message: -```javascript +```json { "action": "get-logins", "url": "", - "submitUrl": optional, - "httpAuth": optional, + "submitUrl": "", + "httpAuth": "", "keys": [ { "id": "", @@ -187,7 +187,7 @@ Unencrypted message: ``` Request: -```javascript +```json { "action": "get-logins", "message": "", @@ -197,7 +197,7 @@ Request: ``` Response message data (success, decrypted): -```javascript +```json { "count": "2", "entries" : [ @@ -221,7 +221,7 @@ Response message data (success, decrypted): ### set-login Unencrypted message: -```javascript +```json { "action": "set-login", "url": "", @@ -237,7 +237,7 @@ Unencrypted message: ``` Request: -```javascript +```json { "action": "set-login", "message": "", @@ -247,7 +247,7 @@ Request: ``` Response message data (success, decrypted): -```javascript +```json { "count": null, "entries" : null, @@ -261,14 +261,14 @@ Response message data (success, decrypted): ### lock-database Unencrypted message: -```javascript +```json { "action": "lock-database" } ``` Request: -```javascript +```json { "action": "lock-database", "message": "", @@ -278,7 +278,7 @@ Request: ``` Response message data (success always returns an error, decrypted): -```javascript +```json { "action": "lock-database", "errorCode": 1, @@ -289,14 +289,14 @@ Response message data (success always returns an error, decrypted): ### get-database-groups Unencrypted message: -```javascript +```json { "action": "get-database-groups" } ``` Request: -```javascript +```json { "action": "get-database-groups", "message": "", @@ -360,7 +360,7 @@ Response message data (success, decrypted): ``` ### create-new-group Unencrypted message: -```javascript +```json { "action": "create-new-group", "groupName": "" @@ -368,7 +368,7 @@ Unencrypted message: ``` Request: -```javascript +```json { "action": "create-new-group", "message": "",