Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 11 Nov 2015 10:18:08 -0800
From:      Bryan Drewery <bdrewery@FreeBSD.org>
To:        Slawa Olhovchenkov <slw@zxy.spb.ru>, =?UTF-8?Q?Dag-Erling_Sm=c3=b8rgrav?= <des@des.no>
Cc:        freebsd-security@freebsd.org, freebsd-current@freebsd.org
Subject:   Re: OpenSSH HPN
Message-ID:  <56438660.5010508@FreeBSD.org>
In-Reply-To: <20151111181339.GE48728@zxy.spb.ru>
References:  <86io5a9ome.fsf@desk.des.no> <56428E8A.3090201@FreeBSD.org> <56428F59.5010908@FreeBSD.org> <86y4e47uty.fsf@desk.des.no> <56436F4B.8050002@FreeBSD.org> <86r3jwfpiq.fsf@desk.des.no> <20151111181339.GE48728@zxy.spb.ru>

next in thread | previous in thread | raw e-mail | index | archive | help
This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--j39IxGt45jTNP1FSeKp3ncUsHHbfisRX5
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable

On 11/11/2015 10:13 AM, Slawa Olhovchenkov wrote:
> On Wed, Nov 11, 2015 at 05:51:25PM +0100, Dag-Erling Sm=C3=B8rgrav wrot=
e:
>=20
>> Bryan Drewery <bdrewery@FreeBSD.org> writes:
>>> Another thing that I did with the port was restore the tcpwrapper
>>> support that upstream removed. Again, if we decide it is not worth
>>> keeping in base I will remove it as default in the port.
>>
>> I want to keep tcpwrapper support - it is another reason why I still
>> haven't upgraded OpenSSH, but to the best of my knowledge, it is far
>> less intrusive than HPN.
>=20
> Can you explain what is problem?
> I am see openssh in base and openssh in ports (more recent version)
> with same functionaly patches.
> You talk about trouble to upgrade. What is root?
> openssh in base have different vendor and/or license?
> Or something else?
>=20
> PS: As I today know, kerberos heimdal is practicaly dead as opensource
> project. Have FreeBSD planed switch to MIT Kerberos?
> I am know about security/krb5.
>=20

IMHO the problem comes down to time. Patching an upstream project
increases maintenance cost for upgrading it. Every patch adds up. When
you become busy and don't have time to pay attention to every little
change made in a release, hearing 'removed tcpwrappers support' or
'refactored the code <more> for libssh usage' makes it sound like 1 more
thing you must deal with to upgrade that code base and more effort to
validate that your patches are right. We obviously don't want to just
drop in the latest code and throw it out there as broken. SSH is quite
critical and we want to ensure our changes are still right, and that
doing something like adding tcpwrappers back in won't introduce some
security bug that upstream was coy about.

--=20
Regards,
Bryan Drewery


--j39IxGt45jTNP1FSeKp3ncUsHHbfisRX5
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQEcBAEBAgAGBQJWQ4ZgAAoJEDXXcbtuRpfPTYgH/1eO6vEKoEcXft9AiFNnCq1o
VIa1laqZKZSmQiinwLYmt+eqbYBmgR4BW8YoWwUlPbIUT1A0xBQTPbl4BJN0nP29
eFwKtHebDV7Q86vHChT7HRzZA2PAjHc9cdSXg4PKAOpQ/pNJF0ywQFlb6ypeTRMa
hEvlSEn0wsSf4kJ7oiebwWQlP19C4VSkVA1UN2oCL5U6GS1RedgR8NosQ1NE4Pqd
rGAXlQKc5+aArKvZnnTa3xqizMRoKuoj8N7r6nkZbfXGRsIDUI2Su5br1MejlRnm
UnfcHt+1icoMoJ6yu9T5azl1xignuOpNgJ7IRxonukD2xj0htzU+tbfUOu9IjXk=
=T1Q8
-----END PGP SIGNATURE-----

--j39IxGt45jTNP1FSeKp3ncUsHHbfisRX5--



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?56438660.5010508>