From owner-freebsd-net@FreeBSD.ORG Tue Nov 6 16:25:54 2007 Return-Path: Delivered-To: freebsd-net@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id DA89F16A473 for ; Tue, 6 Nov 2007 16:25:54 +0000 (UTC) (envelope-from brooks@lor.one-eyed-alien.net) Received: from lor.one-eyed-alien.net (cl-162.ewr-01.us.sixxs.net [IPv6:2001:4830:1200:a1::2]) by mx1.freebsd.org (Postfix) with ESMTP id 76DDE13C4A7 for ; Tue, 6 Nov 2007 16:25:54 +0000 (UTC) (envelope-from brooks@lor.one-eyed-alien.net) Received: from lor.one-eyed-alien.net (localhost [127.0.0.1]) by lor.one-eyed-alien.net (8.14.1/8.13.8) with ESMTP id lA6GPrUr089244; Tue, 6 Nov 2007 10:25:53 -0600 (CST) (envelope-from brooks@lor.one-eyed-alien.net) Received: (from brooks@localhost) by lor.one-eyed-alien.net (8.14.1/8.13.8/Submit) id lA6GPrvH089243; Tue, 6 Nov 2007 10:25:53 -0600 (CST) (envelope-from brooks) Date: Tue, 6 Nov 2007 10:25:53 -0600 From: Brooks Davis To: Randy Bush Message-ID: <20071106162553.GE88328@lor.one-eyed-alien.net> References: <47309183.3030003@psg.com> MIME-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="7LkOrbQMr4cezO2T" Content-Disposition: inline In-Reply-To: <47309183.3030003@psg.com> User-Agent: Mutt/1.5.16 (2007-06-09) X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-3.0 (lor.one-eyed-alien.net [127.0.0.1]); Tue, 06 Nov 2007 10:25:53 -0600 (CST) Cc: FreeBSD Net Subject: Re: rh0 X-BeenThere: freebsd-net@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Networking and TCP/IP with FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 06 Nov 2007 16:25:54 -0000 --7LkOrbQMr4cezO2T Content-Type: text/plain; charset=us-ascii Content-Disposition: inline On Tue, Nov 06, 2007 at 08:08:35AM -0800, Randy Bush wrote: > it is alleged that rh0 is processed in 6.2 (< > http://www.6journal.org/archive/00000284/01/IPv6_RH_security-csw07.pdf>). > is this true. is rh0 processed in 7 and -current? 6.2-RELEASE with no patches does process rh0 like basicly every other IPv6 capable system released when it was. If you run 6.2-RELEASE with patches it does not unless the sysctl net.inet6.ip6.rthdr0_allowed is enabled. I believe the functionality was removed in from HEAD and thus was never in RELENG_7. http://security.freebsd.org/advisories/FreeBSD-SA-07:03.ipv6.asc -- Brooks --7LkOrbQMr4cezO2T Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (FreeBSD) iD8DBQFHMJWRXY6L6fI4GtQRAvUHAKDVqTZiPXvpMytkC0iUFKXakg9QPQCfbb9f zHXeyoii5DKr8aZwsA1ttW4= =HAvX -----END PGP SIGNATURE----- --7LkOrbQMr4cezO2T--