From owner-freebsd-current@FreeBSD.ORG Tue Jul 6 22:26:07 2010 Return-Path: Delivered-To: freebsd-current@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id DF0241065670 for ; Tue, 6 Jul 2010 22:26:07 +0000 (UTC) (envelope-from matthias.andree@gmx.de) Received: from mail.gmx.net (mail.gmx.net [213.165.64.20]) by mx1.freebsd.org (Postfix) with SMTP id 2A1A58FC17 for ; Tue, 6 Jul 2010 22:26:06 +0000 (UTC) Received: (qmail invoked by alias); 06 Jul 2010 22:26:05 -0000 Received: from g226236131.adsl.alicedsl.de (EHLO mandree.no-ip.org) [92.226.236.131] by mail.gmx.net (mp030) with SMTP; 07 Jul 2010 00:26:05 +0200 X-Authenticated: #428038 X-Provags-ID: V01U2FsdGVkX1/+FLpIQJ3+sKYHGWX9Sm+DSf/ApefR92Atb/vYQk SXozM25pyz7GaH Received: from merlin.emma.line.org (localhost [127.0.0.1]) by merlin.emma.line.org (Postfix) with ESMTP id E5F939444A; Wed, 7 Jul 2010 00:26:03 +0200 (CEST) Content-Type: text/plain; charset=utf-8; format=flowed; delsp=yes To: "Andrew Reilly" , "Matthew Seaman" References: <20100706085435.GC13238@deviant.kiev.zoral.com.ua> <4C3317C6.3020009@FreeBSD.org> <20100706123325.GF13238@deviant.kiev.zoral.com.ua> <457406E5-0E8C-4DB0-97B3-C8CAA7DD3AD0@bigpond.net.au> <20100706134636.GG13238@deviant.kiev.zoral.com.ua> <9BB48431-AF0F-4DEA-8F9F-35830E147E68@bigpond.net.au> <4C337D44.7070107@infracaninophile.co.uk> Date: Wed, 07 Jul 2010 00:26:03 +0200 MIME-Version: 1.0 Content-Transfer-Encoding: 8bit From: "Matthias Andree" Organization: Message-ID: In-Reply-To: <4C337D44.7070107@infracaninophile.co.uk> User-Agent: Opera Mail/10.60 (Linux) X-Y-GMX-Trusted: 0 Cc: Kostik Belousov , freebsd-current@freebsd.org Subject: Re: Regression in GSSAPI/libxh509 linking? [PR bin/147175] X-BeenThere: freebsd-current@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Discussions about the use of FreeBSD-current List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 06 Jul 2010 22:26:07 -0000 Am 06.07.2010, 21:00 Uhr, schrieb Matthew Seaman: > On 06/07/2010 15:14:28, Andrew Reilly wrote: >> So: how should I "fix" this, properly, on my -current system? Is it >> as simple as installing heimdal from ports? I can't remove openssl-1.0: >> that has 191 ports listed in its REQUIRED_BY file. > > Rebuild the port of openssl-1.0.0 after modifying the OPTIONS to include > MD2=on ? Not good given that MD2 is broken. Very broken, not just by a factor of 2^5 or something. Where upon rests the earlier assertion (not by Matthew) that Kerberos V needed MD2 checksums? I can't seem to find that in the KRB5 protocol and checksum RFCs. If it's not mandatory we may want to nuke MD2 from Kerberos to remedy a weakness... Chapter and Verse welcome. Thanks. -- Matthias Andree