Produce something only you could have produced

short · 30 min · Objective 1.1

Task

Demonstrate the difference between integrity, authentication and non-repudiation by producing three artefacts over the same file and showing what each one does and does not prove.

Steps

  1. Create a document: printf 'Transfer 500 to account 4471\n' > /tmp/instruction.txt.
  2. Integrity only: sha256sum /tmp/instruction.txt > /tmp/digest.txt.
  3. Authentication between two parties sharing a secret: openssl dgst -sha256 -hmac 'shared-lab-secret' /tmp/instruction.txt > /tmp/hmac.txt.
  4. Non-repudiation: generate a key pair with openssl genpkey -algorithm RSA -out /tmp/priv.pem -pkeyopt rsa_keygen_bits:2048 and openssl rsa -in /tmp/priv.pem -pubout -out /tmp/pub.pem, then sign with openssl dgst -sha256 -sign /tmp/priv.pem -out /tmp/sig.bin /tmp/instruction.txt.
  5. Verify the signature with the PUBLIC key only: openssl dgst -sha256 -verify /tmp/pub.pem -signature /tmp/sig.bin /tmp/instruction.txt.
  6. Now produce the thing people mistake for non-repudiation: an accounting record. Run logger -t payments 'alice approved transfer 4471' as your own user, and again with sudo, then read both back with journalctl -t payments --since '5 min ago'. Neither line was produced by anything only Alice controls, which is why a log entry supports non-repudiation and never delivers it.
  7. Now alter the file — change 500 to 5000 — and re-run all three checks. Note which of them fail and write one sentence on what each failure does and does not tell you about who made the change.

Verify

openssl dgst -sha256 -verify /tmp/pub.pem -signature /tmp/sig.bin /tmp/instruction.txt
sha256sum -c /tmp/digest.txt 2>&1 | tail -1
test "$(openssl dgst -sha256 -hmac 'shared-lab-secret' /tmp/instruction.txt)" = "$(cat /tmp/hmac.txt)" && echo "HMAC OK" || echo "HMAC FAILED"

Before the edit, the first must print Verified OK, the second OK and the third HMAC OK. After the edit all three must fail. The third line recomputes the HMAC with the shared secret and compares it with the one you stored -- merely showing that /tmp/hmac.txt exists would print the same thing before and after the edit. The distinction to write down is that the digest and the HMAC prove the file changed, while only the signature proves who produced the original — because only you hold /tmp/priv.pem, and the verifier needed nothing secret at all. The two payments log lines from the extra step read identically whoever wrote them, which is the accounting record's limit.

Notes

Delete /tmp/priv.pem when you are done, and notice why that sentence exists: the entire non-repudiation claim rests on exactly one file being under your sole control. Key escrow, from the PKI lesson, is the business requirement that deliberately breaks it.

This is an independent study companion for CompTIA Security+ SY0-801 and is not produced by or endorsed by CompTIA.