|
From: Heiko Z. <he...@zu...> - 2001-11-29 14:41:58
|
Hi, I have vacation starting from today until 12/10/01. I try to read my email and check the webpage, but I can't promise anything. I would appreciate it, when you guys could help others and answer questions for me. Thanks. -- cu Heiko I am root, resistance is futile! http://www.devil-linux.org |
|
From: Heiko Z. <he...@zu...> - 2003-08-13 14:03:25
|
Hey guys, I will be out for vacation for a couple of days. Please watch the mailinglists and help eachother. cya Heiko |
|
From: Heiko Z. <he...@zu...> - 2003-11-27 14:46:15
|
Hey Folks, I will be on vacation until Dec 14th and won't be able to read my email very often. So please help each other as much as possible. Regards Heiko |
|
From: Diego T. <dt...@co...> - 2003-11-29 17:17:41
|
On Thu, Nov 27, 2003 at 09:43:10AM -0500, Heiko Zuerker wrote: > I will be on vacation until Dec 14th and won't be able to read my email > very often. as you'll probably see when you return, 2.4.23 is out. so, are we going to migrate to 2.4.23? btw, i'm interested in this patch: http://loop-aes.sourceforge.net/loop-AES.README it provides a secure loopback system, so you could use the aes modules from kernel to have an encrypted loop device. it is backwards compatible with the classic loop command. install procedure is like this: loop support has to be disabled from kernel. a new loop.o module capable of aes is build. then, a new mount/losetup is needed, so util-linux-2.12 has to be patched. so, because this is a big change, and its compatible, it won't have a configurable entry on make menuconfig, and installed always on dl... anyone/someone/everyone against? agree? opinions? -- -- gnupg keyfingerprint -- 48AF 5BF9 8F54 2966 64CC 2327 7CD0 DD91 B09D 5799 -- Use of a keyboard or mouse may be linked to serious injuries or disorders. Diego Torres - dt...@co... - Madrid / España |
|
From: Dean N. <di...@ti...> - 2003-11-29 21:32:04
|
>[...] > > btw, i'm interested in this patch: > > http://loop-aes.sourceforge.net/loop-AES.README > > it provides a secure loopback system, so you could use the aes modules from > kernel to have an encrypted loop device. it is backwards compatible with > the classic loop command. >[...] > > anyone/someone/everyone against? agree? opinions? I would vote against the idea. While AES is a very good encryption system, I would have to reasons against integrating it into DL (for the loopback): o Extra CPU power would be required to handle the AES decryption - and that is on top of the CPU power required to handle the decompression that is already required! Remember - a lot of people run DL on some very old (and slow) processors. o Not sure I understand the need. What is it about the ISO image that you believe requires the encryption? I.e., what are you trying to protect? Of course, those are just my thoughts.... Dean Nedelman TimeLord Consulting |
|
From: Bruce S. <bw...@ar...> - 2003-11-29 21:42:12
|
> > btw, i'm interested in this patch: > > > > http://loop-aes.sourceforge.net/loop-AES.README > > > > it provides a secure loopback system, so you could use the aes modules > from > > kernel to have an encrypted loop device. it is backwards compatible with > > the classic loop command. > >[...] > > > > anyone/someone/everyone against? agree? opinions? > > I would vote against the idea. > > While AES is a very good encryption system, I would have to reasons against > integrating it into DL (for the loopback): > o Extra CPU power would be required to handle the AES decryption - and that > is on top of the CPU power required to handle the decompression that is > already required! Remember - a lot of people run DL on some very old (and > slow) processors. > o Not sure I understand the need. What is it about the ISO image that you > believe requires the encryption? I.e., what are you trying to protect? I don't think you understand. (or maybe I don't understand :) I believe it's for creating encrypted filesystems, on a hard drive. I don't think it has anything to do with the DL ISO image. I also think it's completely optional, so no extra CPU power is required unless you actually setup an encrypted filesystem (in a loopback file). - BS |
|
From: Dean N. <di...@ti...> - 2003-11-29 22:56:44
|
>> > btw, i'm interested in this patch: >> > >> > http://loop-aes.sourceforge.net/loop-AES.README >> > >> > it provides a secure loopback system, so you could use the aes modules >> from >> > kernel to have an encrypted loop device. it is backwards compatible with >> > the classic loop command. >> >[...] >> > >> > anyone/someone/everyone against? agree? opinions? >> >> I would vote against the idea. >> >> While AES is a very good encryption system, I would have to reasons against >> integrating it into DL (for the loopback): >> o Extra CPU power would be required to handle the AES decryption - and that >> is on top of the CPU power required to handle the decompression that is >> already required! Remember - a lot of people run DL on some very old (and >> slow) processors. >> o Not sure I understand the need. What is it about the ISO image that you >> believe requires the encryption? I.e., what are you trying to protect? > > I don't think you understand. (or maybe I don't understand :) Well, it certainly wouldn't be the first time I didn't understand something! > > I believe it's for creating encrypted filesystems, on a hard drive. > I don't think it has anything to do with the DL ISO image. > I also think it's completely optional, so no extra CPU power is required > unless you actually setup an encrypted filesystem (in a loopback file). From Diego's original message: :loop support has to be disabled from kernel. a new loop.o module capable of aes :is build. : :then, a new mount/losetup is needed, so util-linux-2.12 has to be patched. : :so, because this is a big change, and its compatible, it won't have a configurable :entry on make menuconfig, and installed always on dl... Since he says that "loop support has to be disabled" and "a new loop.o module", I took this to mean it is a REPLACEMENT for the existing loop support. And since we now use the existing loop driver for the ISO image (or at least we will with V1.1 were it is already in place), that means that we would end up using the AES encrypted loopback file for the base DL ISO image (or at least that is what I took "...because this is a big change..." to also imply). And yes - I may completely misunderstand Diego's meaning. So let me respond this way: Diego - what are you proposing? To have the DL ISO image be AES encrypted, or to allow users to create AES encrypted file systems? Diego: Your turn! Dean Nedelman TimeLord Consulting |
|
From: Diego T. <dt...@co...> - 2003-11-30 02:58:15
|
On Sat, Nov 29, 2003 at 02:56:33PM -0800, Dean Nedelman wrote: > Diego - what are you proposing? To have the DL ISO image be AES encrypted, > or to allow users to create AES encrypted file systems? hope this clarifies some points about AES. the loop-aes module is built instead the loop kernel module. it has the same functionality PLUS being capable supporting AES encryption calls. (so it can be used for encrypting filesystems also). i don't want to make the dl iso aes encrypted. this won't add any value to dl. i want loop-aes so i may create encrypted filesystems on a hard disk (through a loopback module or on the whole filesystem). for example, per user encrypted home directories. -- -- gnupg keyfingerprint -- 48AF 5BF9 8F54 2966 64CC 2327 7CD0 DD91 B09D 5799 -- Use of a keyboard or mouse may be linked to serious injuries or disorders. Diego Torres - dt...@co... - Madrid / España |
|
From: Friedrich L. <fl...@fl...> - 2003-11-29 21:46:40
|
Dean Nedelman wrote on 29.11.2003 22:31 MET: >>[...] >> >>btw, i'm interested in this patch: >> >>http://loop-aes.sourceforge.net/loop-AES.README >> >>it provides a secure loopback system, so you could use the aes modules > > from > >>kernel to have an encrypted loop device. it is backwards compatible with >>the classic loop command. >>[...] >> >>anyone/someone/everyone against? agree? opinions? > > > I would vote against the idea. > > While AES is a very good encryption system, I would have to reasons against > integrating it into DL (for the loopback): > o Extra CPU power would be required to handle the AES decryption - and that > is on top of the CPU power required to handle the decompression that is > already required! Remember - a lot of people run DL on some very old (and > slow) processors. When you don't configure it to be used it takes 0% of your CPU. I'm neutral as I think I will never need it but others might. -- MfG / Regards Friedrich Lobenstock ____________________________________________________________________ Friedrich Lobenstock Linux Services Lobenstock URL: http://www.lsl.at/ Email: fl...@fl... ____________________________________________________________________ |
|
From: Diego T. <dt...@co...> - 2003-11-30 23:23:47
|
if [ "$CONFIG_GCC_STACK_PROTECTOR" = "y" ]; then
FLAGS="CFLAGS_KERNEL=-fno-stack-protector"
fi
i've found this on some script files... is it ok? sounds strange...
for me this looks better:
if [ "$CONFIG_GCC_STACK_PROTECTOR" != "y" ]; then
FLAGS="CFLAGS_KERNEL=-fno-stack-protector"
fi
heiko?
--
-- gnupg keyfingerprint -- 48AF 5BF9 8F54 2966 64CC 2327 7CD0 DD91 B09D 5799
-- Use of a keyboard or mouse may be linked to serious injuries or disorders.
Diego Torres - dt...@co... - Madrid / España
|