From owner-freebsd-arch@freebsd.org Mon Nov 26 18:10:11 2018 Return-Path: Delivered-To: freebsd-arch@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id BCF5A113EFB1 for ; Mon, 26 Nov 2018 18:10:11 +0000 (UTC) (envelope-from yuripv@yuripv.net) Received: from out4-smtp.messagingengine.com (out4-smtp.messagingengine.com [66.111.4.28]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 1926E8075C for ; Mon, 26 Nov 2018 18:10:10 +0000 (UTC) (envelope-from yuripv@yuripv.net) Received: from compute5.internal (compute5.nyi.internal [10.202.2.45]) by mailout.nyi.internal (Postfix) with ESMTP id 7C3B222A81; Mon, 26 Nov 2018 13:10:10 -0500 (EST) Received: from mailfrontend1 ([10.202.2.162]) by compute5.internal (MEProxy); Mon, 26 Nov 2018 13:10:10 -0500 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yuripv.net; h= subject:to:references:from:message-id:date:mime-version :in-reply-to:content-type; s=fm3; bh=DW8/vxpAUBHpHku2lsVZneTl+Ed bShoegDiC7yru8os=; b=hKIHrFZBEyk1EhthSd2ePPgF1nTAYZiwEBHvJ13pNKA qTd52EMaRTehgX3R4J8QR2Fz230LrdPUxp2Y0Fhme5cxcb4ePXhaErsWxqxYJxNS G3rGzfckPbAtLmdxI+gsCIeNrRXSo3B4gV+4Ek/xRr601mAy02iIiENYtP/Fesqe jW223hoxeKXg9r/AJz11X/42SOhbePcXgyfzFChL49GY72LNbOKuJf03grSYm7PX v5eL0h0gin42GrrwR4S0TQFfMJfTIJ0rN11sYK+x1AERuyyAIXKjHLyb6Hq7JbGX aEaYdcHvv1WVU6i346E25Slab0O4matvejn8M02Cnzw== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to:x-me-proxy :x-me-proxy:x-me-sender:x-me-sender:x-sasl-enc; s=fm1; bh=DW8/vx pAUBHpHku2lsVZneTl+EdbShoegDiC7yru8os=; b=HdzfeMKAtAq16gbms8Hrtv /CwOHjrIqPtUsqCgHkKEaRRANO5gSYmct22UeUO8b/fgPGjy6jh5VodI+BQEp19O r2skstaGkPUjH+lLHOQHaq/mzTzPGmJsWSvOZDAEnZ2PC1MqluKsvzgdfahEksDP JCP0hjEmtKbSkdOsjaEXQdGJ5ZWyguQFYUnKVrrsCYrsN9whoHfYnYIAIDep3Mjm wqPDCJ3s9bbAbkHMD0LZDYIT5P3OHo0jVOVdP6WkoJBJwPWOS9E6cXCAmRyWyUYc KKcxgffXPiNhyenl0Ze83+S9yJZs9e81LIpjwH1JHdR1p+Z6RBhiycGTtNVDbdLg == X-ME-Sender: X-ME-Proxy: Received: from [192.168.1.2] (unknown [62.183.125.179]) by mail.messagingengine.com (Postfix) with ESMTPA id 1A3C9E49AD; Mon, 26 Nov 2018 13:10:07 -0500 (EST) Subject: Re: Removal or updating of "mount_smbfs" from FreeBSD operating system To: Gerard Seibert , freebsd-arch@freebsd.org References: <20181126121926.00007626@seibercom.net> From: Yuri Pankov Openpgp: preference=signencrypt Autocrypt: addr=yuripv@yuripv.net; keydata= xsBNBFu8u6IBCADB11gP0QwnorrHjqAtKLHKHNHskhy0s7jqJKfx0YqXgVBKGLJ9/mjLAz0F CBNvemHSDDTs0mEZ9cBKKi6cmsav6+UQgr//yai6hvXLBJqKchSFO4MhmdvBtsGFq1yKz5Zi uhjmimKyIpgBgvMdbgGbGq6cnSB2uEPmZuJr419SVRODOkXukU+F5WHgaHzDdHAIu1asCt2B +6msxqIqlFWcXyZyTGicTGGvC/PFIsVRUtD1dIJANTC876g7DTb7LZXWiWwJpSJ4GKMXMHVX Ct9BoQ4i3nhKbOxb6Io1wsy+NFyWsTJ9KYrxKKPJP3oG8BWb/cqlFqnE4eNSsiq2q7krABEB AAHNH1l1cmkgUGFua292IDx5dXJpcHZAeXVyaXB2Lm5ldD7CwJcEEwEIAEECGwMFCQWjmoAF CwkIBwMFFQoJCAsFFgMCAQACHgECF4AWIQT4arc+w94tPi0v/3CTi+B/sSrhbAUCW708wAIZ AQAKCRCTi+B/sSrhbPxBB/961alcU091O+yKT5/oReHVc/PX0Tz4sW3V44AcgLfYlrZavCro EFz90qmCrl0xqEwuAKcC4bjmL8SjPWAhSN6IH9nxdw+HeZnAPiHm/q679Bu47+nHBl3qD/9p +t1PkKeKZfaWToFMt1nq06ytSu6VLMCwLdlDNe6DReX0ex/afEqKsuaIZSKL4UYjRwklp8PU Uf98QkrfapyHB67hQMzfI4tPeJaYyv0cTgfq3kUWJx1V6Xi0b6Zxj4ZrB2TXvaMO5g7yhU9E E3WWAvoe4FgB3a7dHe8atnHhq5+Cuvm6+LD4Jh7jvMAE5UMN+xxQpnGpNghHjaCy4vXrLRBZ nhRYzsBNBFu8u6IBCADKih3Q933rDNj4ZA8FhBQ2RlmBgvwOLcDPIL3h0V7h38y3+HisgFSc XACDsdrTlYZ1bRXkD9FHENynBcv0l/3uGJDk8jaGIDE0TP8OQBRp+IaU9/BHnAqrKxTJGIol Dahy2m+yx2yhdc6B4ujWMDqCF1rWOD+ymOWw+VLllOkrHcZa5PJtX9UOGbApZl8ZTM8El4CA NN8F1bg9MWzUi+8LYoGWGc+BwsFS1OUB1c4SPgMu5fD4Wfsr9yRl06fdpEA2YT7B/j5/5RSC 0sE2Zs/tmJ/JRflHJ12ycj59ma2xQMfEJF40hZDpMFQmZvbVqgEg3ocQcltjbxlIKZ/mjC4z ABEBAAHCwHwEGAEKACYWIQT4arc+w94tPi0v/3CTi+B/sSrhbAUCW7y7ogIbDAUJBaOagAAK CRCTi+B/sSrhbIDcCACqAZMcoxUBLZa40a5b24j5i1jplvCYYb3h+Q5lt5+BFJ87kCb4dJuU D3kh2i29BrxWQWa9WNue9ozxeYkbkfXubQYXexVolRsnh64OdGsE8KvorBFBB3zdK/GRt2Jy +jsnTfUWuQllbzMP0MfhCDMk1Mo8WvDH2/cOEP/yLKf20a+cd6nLs7bidjmGXo9pyuBKAtV6 Kv+VRu54AL+A/UBYu/eB3Dtvzcnut+1Zq6KaP++kUwPwINLIk04OBDwN0zRNTiqMAFYYyz2v ZHBB6E1th/l//ZC5b9Dk0ZpFI1bYdL9ymnrZe1MqbGPnDCToQxu00T/pZCm6Z92YrZQYuNwl Message-ID: <70b84814-89a8-fdef-7092-1cb4a46785e1@yuripv.net> Date: Mon, 26 Nov 2018 21:09:57 +0300 User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:60.0) Gecko/20100101 Thunderbird/60.3.1 MIME-Version: 1.0 In-Reply-To: <20181126121926.00007626@seibercom.net> Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="OxsAe2UgGdIHRzPHmWIdYxHjJDWmf6UIB" X-Rspamd-Queue-Id: 1926E8075C X-Spamd-Result: default: False [-9.32 / 15.00]; ARC_NA(0.00)[]; RCVD_VIA_SMTP_AUTH(0.00)[]; R_DKIM_ALLOW(-0.20)[yuripv.net,messagingengine.com]; NEURAL_HAM_MEDIUM(-1.00)[-1.000,0]; FROM_HAS_DN(0.00)[]; TO_DN_SOME(0.00)[]; R_SPF_ALLOW(-0.20)[+ip4:66.111.4.28]; NEURAL_HAM_LONG(-1.00)[-1.000,0]; HAS_ATTACHMENT(0.00)[]; MIME_GOOD(-0.20)[multipart/signed,multipart/mixed,text/plain]; DMARC_NA(0.00)[yuripv.net]; RCVD_COUNT_THREE(0.00)[4]; TO_MATCH_ENVRCPT_SOME(0.00)[]; MX_GOOD(-0.01)[cached: in2-smtp.messagingengine.com]; DKIM_TRACE(0.00)[yuripv.net:+,messagingengine.com:+]; RCPT_COUNT_TWO(0.00)[2]; NEURAL_HAM_SHORT(-0.99)[-0.989,0]; SIGNED_PGP(-2.00)[]; RCVD_IN_DNSWL_LOW(-0.10)[28.4.111.66.list.dnswl.org : 127.0.5.1]; FROM_EQ_ENVFROM(0.00)[]; RCVD_TLS_LAST(0.00)[]; ASN(0.00)[asn:11403, ipnet:66.111.4.0/24, country:US]; MID_RHS_MATCH_FROM(0.00)[]; IP_SCORE(-3.62)[ip: (-9.46), ipnet: 66.111.4.0/24(-4.67), asn: 11403(-3.88), country: US(-0.09)] X-Rspamd-Server: mx1.freebsd.org X-BeenThere: freebsd-arch@freebsd.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: Discussion related to FreeBSD architecture List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 26 Nov 2018 18:10:12 -0000 This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --OxsAe2UgGdIHRzPHmWIdYxHjJDWmf6UIB Content-Type: multipart/mixed; boundary="IWk54rwCxnW4wHAFkbETbUapDxnamcowq"; protected-headers="v1" From: Yuri Pankov To: Gerard Seibert , freebsd-arch@freebsd.org Message-ID: <70b84814-89a8-fdef-7092-1cb4a46785e1@yuripv.net> Subject: Re: Removal or updating of "mount_smbfs" from FreeBSD operating system References: <20181126121926.00007626@seibercom.net> In-Reply-To: <20181126121926.00007626@seibercom.net> --IWk54rwCxnW4wHAFkbETbUapDxnamcowq Content-Type: text/plain; charset=utf-8 Content-Language: en-US Content-Transfer-Encoding: quoted-printable Gerard Seibert wrote: > TO WHOM IT MAY CONCERN >=20 > The =E2=80=9CSMBv1=E2=80=9D protocol is a security hazard and was depre= ciated by Microsoft in > 2014. There is virtually no use for it anymore. >=20 > The =E2=80=9Cmount_smbfs=E2=80=9D utility in FreeBSD only uses that pro= tocol, which results > in making it useless with newer versions of Microsoft=E2=80=99s operati= ng systems, as > well as other OS=E2=80=99s that have depreciated the use of SMBv1. >=20 > I would like to suggest that FreeBSD do one of the following: >=20 > 1) Remove =E2=80=9Cmount_smbfs=E2=80=9D from FreeBSD. This would probab= ly be in versions 12.1 > or 13. It is perhaps too late to get into FreeBSD 12. I don't think this is reasonable, more so in a hurry, as this is a client, and doesn't impose any security issues. > 2) Update =E2=80=9Cmount_smbfs=E2=80=9D so that it is compatible with v= ersions SMBv3 and > greater. While "SMBv2" is not dead, it is definitely comatose. This wou= ld be a > better idea if someone had the time to do it. There's an entry in https://wiki.freebsd.org/DevSummit/201810: ---------------------------------------------------------------------- updated mount SMBFS smbv3 support (iXsystems) ---------------------------------------------------------------------- I wonder if we could get a bit more information on this -- is this just a plan, or is it being actively worked on/ready for integration? --IWk54rwCxnW4wHAFkbETbUapDxnamcowq-- --OxsAe2UgGdIHRzPHmWIdYxHjJDWmf6UIB Content-Type: application/pgp-signature; name="signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="signature.asc" -----BEGIN PGP SIGNATURE----- iQEzBAEBCAAdFiEE+Gq3PsPeLT4tL/9wk4vgf7Eq4WwFAlv8Nv0ACgkQk4vgf7Eq 4WxvdAf+JFYubI6vGIeZ9LreW7CGlYolKtwZkkIT56854+kaNxTVidx9hDfefeRE fLXwmsrRUdh/V2SW5peESwaAVb48GmyX7eD3Hnq9Y1Pp0XomW7uhrHLHOMRfHWYi 0kwi8qW+G4a541JypK0nW5UpWeMPNkeTNwiDkqznM35GG9s6yLqAtJ3h9YcTXnpK jVYkfeUQ6itdbyaehFheF6UtR3ZxcnHNF0ruAPe1LTvdL+QpSu3Vf9V1B+XARtUj ZMwgMYhQ6Ichh08ZjA2nMSlkr37ug/tFyx9Aq9cGBzEoexvm/qY1njcV3v6k0FFw xYyRLJZpgf5v/36Mv6NQbot8ZHp4cg== =KVCN -----END PGP SIGNATURE----- --OxsAe2UgGdIHRzPHmWIdYxHjJDWmf6UIB--