Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 29 May 2000 23:44:03 -0700
From:      Cy Schubert - ITSD Open Systems Group <Cy.Schubert@uumail.gov.bc.ca>
To:        itojun@iijlab.net
Cc:        Alexander Langer <alex@big.endian.de>, Hajimu UMEMOTO <ume@bisd.hitachi.co.jp>, andrews@technologist.com, Cy.Schubert@uumail.gov.bc.ca, stable@FreeBSD.ORG, current@FreeBSD.ORG
Subject:   Re: ftp(1) breakage w/ passive mode? 
Message-ID:  <200005300644.e4U6idT19592@cwsys.cwsent.com>
In-Reply-To: Your message of "Tue, 30 May 2000 14:07:07 %2B0900." <22780.959663227@coconut.itojun.org> 

next in thread | previous in thread | raw e-mail | index | archive | help
In message <22780.959663227@coconut.itojun.org>, itojun@iijlab.net 
writes:
> 
> >> IPv4 connection via mapped address is still IPv6 connection.  In this
> >> case, if ftp(1) doesn't have awareness of using mapped address, your
> >> problem will occur.  And, ftp(1) seems not aware about it.
> >Yes. NetBSD did that commit just right now.
> >I guess they obtained it from you, or it's just a BIG coincidence.
> 
> 	ume and I discussed it a little bit, directly.

Tested the patch on a 4.0S system against KRB5 tunnelled through VPN 
(pipsecd for now) then NATed (using IP Filter at the remote side) to my 
employer's network.  Kerberos rlogin and KRB5 telnet now work however 
KRB5 ftp still has problems.

KRB5 works nicely with or without the patch when directly connected via 
PPP to my employer's network, e.g. no VPN and no NAT.  (This opened up 
another can of worms when I disconnected PPP from work and tried to 
reestablish routes through VPN through the cable modem... but I digress 
onto a tangent of something else that might be broken when IPv6 is in 
the kernel and as it's late, I don't want to go there right now.  Maybe 
some other day.)

KRB5 works nicely through VPN and NATed without the patch without IPv6 
in the kernel.

As IPv6 is not an issue for me at this time I haven't aggressively 
pursued a solution, however I am willing to help out with testing and 
debugging when time permits.

In summary, the patch is a huge step in the right direction.  It could 
very well be that KRB5 ftp may be at fault, not IPv6 in FreeBSD.  I 
don't know at this time.


Regards,                       Phone:  (250)387-8437
Cy Schubert                      Fax:  (250)387-5766
Team Leader, Sun/DEC Team   Internet:  Cy.Schubert@osg.gov.bc.ca
Open Systems Group, ITSD, ISTA
Province of BC





To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-stable" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?200005300644.e4U6idT19592>