|
From: SourceForge.net <no...@so...> - 2003-10-10 12:37:13
|
Feature Requests item #821176, was opened at 2003-10-10 07:37 Message generated for change (Tracker Item Submitted) made by Item Submitter You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=410646&aid=821176&group_id=34096 Category: Base System Group: None Status: Open Priority: 5 Submitted By: Heiko Zuerker (smiley73) Assigned to: Nobody/Anonymous (nobody) Summary: add setserial Initial Comment: http://setserial.sourceforge.net/ setserial is a program designed to set and/or report the configuration information associated with a serial port. ---------------------------------------------------------------------- You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=410646&aid=821176&group_id=34096 |
|
From: SourceForge.net <no...@so...> - 2003-10-10 18:27:09
|
Bugs item #821176, was opened at 2003-10-10 07:37 Message generated for change (Settings changed) made by smiley73 You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=410643&aid=821176&group_id=34096 >Category: None Group: None Status: Open Resolution: None Priority: 5 Submitted By: Heiko Zuerker (smiley73) Assigned to: Nobody/Anonymous (nobody) Summary: add setserial Initial Comment: http://setserial.sourceforge.net/ setserial is a program designed to set and/or report the configuration information associated with a serial port. ---------------------------------------------------------------------- You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=410643&aid=821176&group_id=34096 |
|
From: SourceForge.net <no...@so...> - 2003-10-10 21:22:18
|
Bugs item #821176, was opened at 2003-10-10 07:37 Message generated for change (Settings changed) made by smiley73 You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=410643&aid=821176&group_id=34096 >Category: Base System Group: None >Status: Closed >Resolution: Fixed Priority: 5 Submitted By: Heiko Zuerker (smiley73) >Assigned to: Heiko Zuerker (smiley73) Summary: add setserial Initial Comment: http://setserial.sourceforge.net/ setserial is a program designed to set and/or report the configuration information associated with a serial port. ---------------------------------------------------------------------- You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=410643&aid=821176&group_id=34096 |
|
From: Bruce S. <bw...@ar...> - 2003-10-10 21:26:05
|
> >Status: Closed > >Resolution: Fixed > >Assigned to: Heiko Zuerker (smiley73) > Summary: add setserial Now wait a minute. I thought 1.0 was frozen to new additions? :-) - BS |
|
From: Friedrich L. <fl...@fl...> - 2003-10-10 21:42:16
|
Bruce Smith wrote: >>>Status: Closed >>>Resolution: Fixed >>>Assigned to: Heiko Zuerker (smiley73) >> >>Summary: add setserial > > > Now wait a minute. I thought 1.0 was frozen to new additions? :-) Standards - you might say damned standards ;-) -------- Original Message -------- Subject: Re: [Devil-Linux-discuss] Re: Serial add-on card Date: Fri, 10 Oct 2003 14:26:49 -0400 From: Heiko Zuerker <hz...@pr...> Reply-To: dev...@li... To: dev...@li... On 10/10/2003 01:47:15 PM Friedrich Lobenstock wrote: >Heiko Zuerker wrote: >> On 10/10/2003 05:41:43 AM "ferris bueller" wrote: >> >>>Is it possible to add setserial to the distrib? >> >> sure >> I add it to the feature requests. But it won't be in 1.0 ! > >http://www.pathname.com/fhs/2.2/fhs-6.1.html >see 6.1.2 OK got the message. ;-) I'll classify it as a bug and add it to 1.0. cya Heiko -------- /Original Message -------- -- MfG / Regards Friedrich Lobenstock ____________________________________________________________________ Friedrich Lobenstock Linux Services Lobenstock URL: http://www.lsl.at/ Email: fl...@fl... ____________________________________________________________________ |
|
From: Bruce S. <br...@ar...> - 2003-10-11 00:14:59
|
> > Now wait a minute. I thought 1.0 was frozen to new additions? :-) > > Standards - you might say damned standards ;-) > > >http://www.pathname.com/fhs/2.2/fhs-6.1.html > >see 6.1.2 Now wait another minute. They have an entire section just to say that ONE binary should be included as a standard on the Linux filesystem? Sounds fishy to me!!! ;-) I can point you to a web page that says rc.local is a standard, and my squid enhancements should be included too! (give me a minute, I have to write those pages! ;->>>) Should I shut up now? Sorry, one too many beers with dinner ... :-) - BS |
|
From: Heiko Z. <he...@zu...> - 2003-10-11 00:31:21
|
Bruce Smith wrote: >>>Now wait a minute. I thought 1.0 was frozen to new additions? :-) >>> >>> >>Standards - you might say damned standards ;-) >> >> >http://www.pathname.com/fhs/2.2/fhs-6.1.html >> >see 6.1.2 >> >> > >Now wait another minute. They have an entire section just to say that >ONE binary should be included as a standard on the Linux filesystem? >Sounds fishy to me!!! ;-) > >I can point you to a web page that says rc.local is a standard, and my >squid enhancements should be included too! (give me a minute, I have to >write those pages! ;->>>) > >Should I shut up now? Sorry, one too many beers with dinner ... :-) > > > That would have been my next question, you seem to be in a really good mood. ;-) Heiko |
|
From: Friedrich L. <fl...@fl...> - 2003-10-11 13:07:37
|
Bruce Smith wrote: > > I can point you to a web page that says rc.local is a standard, and my > squid enhancements should be included too! (give me a minute, I have to > write those pages! ;->>>) > > Should I shut up now? Sorry, one too many beers with dinner ... :-) > If you really need a rc.local if you can please write an init script which eventually calls this file but don't modify the /etc/init.d/rc file (runlevel controller) to call this file. -- MfG / Regards Friedrich Lobenstock ____________________________________________________________________ Friedrich Lobenstock Linux Services Lobenstock URL: http://www.lsl.at/ Email: fl...@fl... ____________________________________________________________________ |
|
From: Heiko Z. <he...@zu...> - 2003-10-10 21:46:20
|
Bruce Smith wrote: >>>Status: Closed >>>Resolution: Fixed >>>Assigned to: Heiko Zuerker (smiley73) >>> >>> >>Summary: add setserial >> >> > >Now wait a minute. I thought 1.0 was frozen to new additions? :-) > > Yeah it is. But Friedrich (he again...) send out this email with the this link.... http://www.pathname.com/fhs/2.2/fhs-6.1.html see 6.1.2 So I classified it as bug., because I got the message. ;-) cya Heiko |
|
From: Bruce S. <br...@ar...> - 2003-10-11 00:07:01
|
> >Now wait a minute. I thought 1.0 was frozen to new additions? :-) > > > Yeah it is. > But Friedrich (he again...) send out this email with the this link.... > http://www.pathname.com/fhs/2.2/fhs-6.1.html > see 6.1.2 > > So I classified it as bug., because I got the message. ;-) In that sense, all the stuff I've been doing in 1.1 are really bug fixes. I can rationalize too, check this out: :-) It started out with the squid authorization modules not working. (because they were not being compiled). Then I tried the yp_auth module and it didn't run because it needed ypbind to be running. So I added ypbind, but it wouldn't compile without yp-tools, so I added it. Then ypbind didn't run because it needed the RPC portmapper. So I added the portmapper, but it wouldn't compile because it needed tcp_wrappers, so I added it ... (talk about dependency hell! :) You see, all one big BUG FIX!!! ;-) (and the most amazing thing is it even works!) Feel free to back port the changes to 1.0! (or not :) BTW, while I was adding all the NIS crap, I also added ypserv so it's all there, also a bug fix since we don't want only part of the yp crap. And I also wrote some enhancements to yp_auth.c, now a patch on DL. (I'll spare you the details unless you really want to hear about it) Maybe I should submit that patch to the squid people ... - BS |
|
From: Friedrich L. <fl...@fl...> - 2003-10-11 00:17:52
|
Bruce Smith wrote: > In that sense, all the stuff I've been doing in 1.1 are really bug > fixes. I can rationalize too, check this out: :-) > > It started out with the squid authorization modules not working. > (because they were not being compiled). Then I tried the yp_auth module > and it didn't run because it needed ypbind to be running. So I added > ypbind, but it wouldn't compile without yp-tools, so I added it. Then > ypbind didn't run because it needed the RPC portmapper. So I added the > portmapper, but it wouldn't compile because it needed tcp_wrappers, so I > added it ... (talk about dependency hell! :) > > You see, all one big BUG FIX!!! ;-) > (and the most amazing thing is it even works!) > Feel free to back port the changes to 1.0! (or not :) > > BTW, while I was adding all the NIS crap, I also added ypserv so it's > all there, also a bug fix since we don't want only part of the yp crap. > > And I also wrote some enhancements to yp_auth.c, now a patch on DL. > (I'll spare you the details unless you really want to hear about it) > Maybe I should submit that patch to the squid people ... Isn't there a patch or config option where you could disable the nis support in squid's authorization module? I would not really want to run a bloated squid on a caching firewall. -- MfG / Regards Friedrich Lobenstock ____________________________________________________________________ Friedrich Lobenstock Linux Services Lobenstock URL: http://www.lsl.at/ Email: fl...@fl... ____________________________________________________________________ |
|
From: Bruce S. <bw...@ar...> - 2003-10-11 00:22:07
|
> Isn't there a patch or config option where you could disable the > nis support in squid's authorization module? I would not really > want to run a bloated squid on a caching firewall. Not necessary. All the squid authorization modules are completely stand alone binaries. They only take up a little space on the CD. They are not run unless you add a line in /etc/squid.conf something like: auth_param basic program /usr/sbin/yp_auth ... - BS |
|
From: Friedrich L. <fl...@fl...> - 2003-10-11 00:29:29
|
Bruce Smith wrote: >>Isn't there a patch or config option where you could disable the >>nis support in squid's authorization module? I would not really >>want to run a bloated squid on a caching firewall. > > > Not necessary. All the squid authorization modules are completely stand > alone binaries. They only take up a little space on the CD. They are > not run unless you add a line in /etc/squid.conf something like: > > auth_param basic program /usr/sbin/yp_auth ... Ok, good, but for a real firewall can we offer a configure option so those modules can be selected on an per module basis or just "auth modules yes or no"? So the security consious people can create their own stripped down firewall only version. Just a thought. -- MfG / Regards Friedrich Lobenstock ____________________________________________________________________ Friedrich Lobenstock Linux Services Lobenstock URL: http://www.lsl.at/ Email: fl...@fl... ____________________________________________________________________ |
|
From: Heiko Z. <he...@zu...> - 2003-10-11 00:46:18
|
Friedrich Lobenstock wrote: > Bruce Smith wrote: > >>> Isn't there a patch or config option where you could disable the >>> nis support in squid's authorization module? I would not really >>> want to run a bloated squid on a caching firewall. >> >> >> >> Not necessary. All the squid authorization modules are completely stand >> alone binaries. They only take up a little space on the CD. They are >> not run unless you add a line in /etc/squid.conf something like: >> >> auth_param basic program /usr/sbin/yp_auth ... > > > Ok, good, but for a real firewall can we offer a configure option so > those modules can be selected on an per module basis or just "auth > modules yes or no"? So the security consious people can create their > own stripped down firewall only version. Just a thought. > He got a point again.... Bruce already added the option to (de-)select the nis and port mapper stuff. I would suggest that you (Bruce) add some more intelligence to the squid script. This should make everybody happy. cya Heiko |
|
From: Bruce S. <bw...@ar...> - 2003-10-11 01:03:26
|
> >> Not necessary. All the squid authorization modules are completely stand > >> alone binaries. They only take up a little space on the CD. They are > >> not run unless you add a line in /etc/squid.conf something like: > >> > >> auth_param basic program /usr/sbin/yp_auth ... > > > > Ok, good, but for a real firewall can we offer a configure option so > > those modules can be selected on an per module basis or just "auth > > modules yes or no"? So the security consious people can create their > > own stripped down firewall only version. Just a thought. > > > He got a point again.... > > Bruce already added the option to (de-)select the nis and port mapper stuff. > I would suggest that you (Bruce) add some more intelligence to the squid > script. This should make everybody happy. I'm sorry, but this is crazy. These are small stand alone programs which are part the squid package, and should be included. All they do is check a password crypt and send "OK" or "ERR" to stdout. There are tons of other non-optional programs that are just as much of a security risk (none) as these are. We could go crazy making every binary optional. - BS |
|
From: Heiko Z. <he...@zu...> - 2003-10-11 01:15:19
|
Bruce Smith wrote: >>>>Not necessary. All the squid authorization modules are completely stand >>>>alone binaries. They only take up a little space on the CD. They are >>>>not run unless you add a line in /etc/squid.conf something like: >>>> >>>> auth_param basic program /usr/sbin/yp_auth ... >>>> >>>> >>>Ok, good, but for a real firewall can we offer a configure option so >>>those modules can be selected on an per module basis or just "auth >>>modules yes or no"? So the security consious people can create their >>>own stripped down firewall only version. Just a thought. >>> >>> >>> >>He got a point again.... >> >>Bruce already added the option to (de-)select the nis and port mapper stuff. >>I would suggest that you (Bruce) add some more intelligence to the squid >>script. This should make everybody happy. >> >> > >I'm sorry, but this is crazy. These are small stand alone programs >which are part the squid package, and should be included. All they do >is check a password crypt and send "OK" or "ERR" to stdout. > >There are tons of other non-optional programs that are just as much of a >security risk (none) as these are. We could go crazy making every >binary optional. > > I'm trying to find a solution which makes everybody ( a kind of ) happy. But there's probably a bug anyway: when you don't select the yp stuff, the squid compile should actually fail since it's specified as a required module. Heiko |
|
From: Bruce S. <bw...@ar...> - 2003-10-11 01:23:45
|
> >I'm sorry, but this is crazy. These are small stand alone programs > >which are part the squid package, and should be included. All they do > >is check a password crypt and send "OK" or "ERR" to stdout. > > > >There are tons of other non-optional programs that are just as much of a > >security risk (none) as these are. We could go crazy making every > >binary optional. > > I'm trying to find a solution which makes everybody ( a kind of ) happy. I understand, and it's a good idea in general. I'm trying to explain that this isn't necessary in this particular case. > But there's probably a bug anyway: when you don't select the yp stuff, > the squid compile should actually fail since it's specified as a > required module. No, that isn't a bug in this case. It compiles fine without the YP stuff, it just doesn't run. I was surprised that it compiled too, but I know this for a fact because the first CD I tried built fine, and it took me awhile to figure out why yp_auth wouldn't run. (before I added ANY of the yp programs) - BS |
|
From: Heiko Z. <he...@zu...> - 2003-10-11 01:31:19
|
Bruce Smith wrote: >>>I'm sorry, but this is crazy. These are small stand alone programs >>>which are part the squid package, and should be included. All they do >>>is check a password crypt and send "OK" or "ERR" to stdout. >>> >>>There are tons of other non-optional programs that are just as much of a >>>security risk (none) as these are. We could go crazy making every >>>binary optional. >>> >>> >>I'm trying to find a solution which makes everybody ( a kind of ) happy. >> >> > >I understand, and it's a good idea in general. I'm trying to explain >that this isn't necessary in this particular case. > > I personally don't care.... >>But there's probably a bug anyway: when you don't select the yp stuff, >>the squid compile should actually fail since it's specified as a >>required module. >> >> > >No, that isn't a bug in this case. It compiles fine without the YP >stuff, it just doesn't run. I was surprised that it compiled too, but I >know this for a fact because the first CD I tried built fine, and it >took me awhile to figure out why yp_auth wouldn't run. (before I added >ANY of the yp programs) > > Oh ok, then never mind. Heiko |
|
From: Heiko Z. <he...@zu...> - 2003-10-11 00:31:21
|
Bruce Smith wrote: >>Isn't there a patch or config option where you could disable the >>nis support in squid's authorization module? I would not really >>want to run a bloated squid on a caching firewall. >> >> > >Not necessary. All the squid authorization modules are completely stand >alone binaries. They only take up a little space on the CD. They are >not run unless you add a line in /etc/squid.conf something like: > > auth_param basic program /usr/sbin/yp_auth ... > > *and* they're compiled with the stack smashing protector *and* grsecurity watches over all that stuff too. Don't you just love Devil-Linux ? cya Heiko |
|
From: Heiko Z. <he...@zu...> - 2003-10-11 00:21:18
|
Bruce Smith wrote: >>>Now wait a minute. I thought 1.0 was frozen to new additions? :-) >>> >>> >>> >>Yeah it is. >>But Friedrich (he again...) send out this email with the this link.... >>http://www.pathname.com/fhs/2.2/fhs-6.1.html >>see 6.1.2 >> >>So I classified it as bug., because I got the message. ;-) >> >> > >In that sense, all the stuff I've been doing in 1.1 are really bug >fixes. I can rationalize too, check this out: :-) > >It started out with the squid authorization modules not working. >(because they were not being compiled). Then I tried the yp_auth module >and it didn't run because it needed ypbind to be running. So I added >ypbind, but it wouldn't compile without yp-tools, so I added it. Then >ypbind didn't run because it needed the RPC portmapper. So I added the >portmapper, but it wouldn't compile because it needed tcp_wrappers, so I >added it ... (talk about dependency hell! :) > >You see, all one big BUG FIX!!! ;-) >(and the most amazing thing is it even works!) >Feel free to back port the changes to 1.0! (or not :) > You'll use a CVS version anyway, so I don't even argument with you. >BTW, while I was adding all the NIS crap, I also added ypserv so it's >all there, also a bug fix since we don't want only part of the yp crap. > > You're so full of shit sometimes ! But that's why I like you. ;-) >And I also wrote some enhancements to yp_auth.c, now a patch on DL. >(I'll spare you the details unless you really want to hear about it) >Maybe I should submit that patch to the squid people ... > > Yes please submit the patch, so others can benefit from it to. cya Heiko |
|
From: Bruce S. <bw...@ar...> - 2003-10-11 01:16:40
|
> >And I also wrote some enhancements to yp_auth.c, now a patch on DL. > >(I'll spare you the details unless you really want to hear about it) > >Maybe I should submit that patch to the squid people ... > > > Yes please submit the patch, so others can benefit from it to. OK, I sent them a link and a description of my patch. It'll be interesting to see if I get a reply ... - BS |