Re: Fwd: [leaf:bering-uclibc] New commit [42635b] by kapeka
Erich Titl <[email protected]> Sat, 24 Feb 2018 14:02:13 +0000
| Newsgroups | gmane.linux.leaf.devel |
|---|---|
| Message-ID | <[email protected]> |
This is a cryptographically signed message in MIME format.
--===============0579723038154903351==
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg=sha-256; boundary="------------ms060308050906050504040802"
This is a cryptographically signed message in MIME format.
--------------ms060308050906050504040802
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable
Hi KP
Am 24.02.2018 um 01:16 schrieb KP Kirchdoerfer via leaf-devel:
> Hi Erich;
>=20
> On Fr, 2018-02-23 at 21:27 +0000, Erich Titl wrote:
>> Hi KP
>>
=2E..
>>> (see the buildtool.cfg for mini_httpd and lighttpd)
>>
>> I just _believe_ that something _named_ in a config file as a _file_
>> with a _source_ should exist. But this may be just a naming
>> convention.
>=20
> The definition in buildtool.cfg is like
>=20
> <File>
> Filename =3D etc/mini_httpd.pem
> Type =3D local
> </File>
>=20
> You can read this as "There is no Source, but there may be Local File
> named etc/mini_httpd.pem, which we shall save if it's there".
Well, I was looking at
<File>
Source =3D var/webconf/www/.htpasswd
Filename =3D var/webconf/www/.htpasswd
Type =3D binary
Type =3D local
</File>
>=20
>=20
> It is a convention.
>=20
> My proposal is to go with an 6.1.2-rc2 with the changes in git and see,=
> igf it works as I do expect based on the experience with mini_httpd in
> the past years and see if we need to come up with something better.
> At least it will improve security.
I don't buy that. I made quite extensive tests with 6.1.2-rc last night.
- lighttpd when configured with authentication will not work without a
=2Ehtpasswd file.
- if there was a .htpasswd file in configdb it might work
- we can configure a .htpasswd file at first login using the .profile
aproach, but then .profile must be configurable anyway.
- I can check if a .htpasswd file contains an empty password or
something reasonable, but to check this requires a running .htpasswd,
not a crippled one like mini-httpd was happy with.
I believe we should roll out these checks ( I will try to commit a new
passcheck.sh ) in a 6.1.2-rc3 or beta or whatever and once we now there
are no known defects move this _without_other_modifications_ to 6.1.2
(just for the beauty of a release process)
The passcheck method must be built into .profile too.
Plase be patient I have a very limited internet access right now.
cheers
ET
--------------ms060308050906050504040802
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"
Content-Description: S/MIME Cryptographic Signature
MIAGCSqGSIb3DQEHAqCAMIACAQExDzANBglghkgBZQMEAgEFADCABgkqhkiG9w0BBwEAAKCC
A6wwggOoMIICkKADAgECAgEoMA0GCSqGSIb3DQEBBQUAMHUxCzAJBgNVBAYTAkNIMRIwEAYD
VQQHEwlTdGFsbGlrb24xDjAMBgNVBAoTBVRISU5LMRMwEQYDVQQLEwpDQSBTZWN0aW9uMREw
DwYDVQQDEwhUaGluayBDQTEaMBgGCSqGSIb3DQEJARYLY2FAdGhpbmsuY2gwHhcNMTQwMjI0
MDAwMDAwWhcNMTkwMjI0MjM1OTU5WjB/MQswCQYDVQQGEwJDSDESMBAGA1UEBxMJU3RhbGxp
a29uMQ4wDAYDVQQKEwVUSElOSzETMBEGA1UECxMKQ0EgU2VjdGlvbjETMBEGA1UEAxMKRXJp
Y2ggVGl0bDEiMCAGCSqGSIb3DQEJARYTZXJpY2gudGl0bEB0aGluay5jaDCCASIwDQYJKoZI
hvcNAQEBBQADggEPADCCAQoCggEBAMyJFgDhrDejCcqDw4qrn/PJrlyqJycEFBO8HH/Eme7Q
WShwskTLfs3b9vFyNy76H4Kd3q+uxb5UpibExFK9n/1l/YYobKXbL1SKAJGImOe5RyBigcMW
9qkbeb3tfdaj+JaNTCwpA2XiiMU2zSHHm8M7iu6rFNyx/mpbPyVZz1YmbO6ZN6Fzjj/LwAvb
VNKPrfFjjERDAENIZXj8c3OUVI67/lDbgRgLfea/7ovXPIby2hszTISjUEmqie9XjkeFK8Lf
iL2Fh6ui7d4qp7096DeZADqxWMwGj4lWvVcmIpMvLUJHga88j/ziJT0Fy1DDJX4ULX2ZyFgq
pY+PrMAc9VcCAwEAAaM5MDcwCQYDVR0TBAIwADALBgNVHQ8EBAMCBeAwHQYDVR0lBBYwFAYI
KwYBBQUHAwMGCCsGAQUFBwMEMA0GCSqGSIb3DQEBBQUAA4IBAQC++xQWbBXJFP9tHl+Q+oTP
Tkkdp8xom3jdieVTHxKoqV7BD255GoyVu0nu4Y5ZgZxecMm9tuTx3yqJ56oKD2QCwSzewjee
SW27QKmku4+1NVTGCl9dljuKsOCVnw/3MrQDzii2BcpE23MJFOK/mthYP7wB0M0F5kQf/5mH
QukyNj1RFyuY2sFDMH9ZNkw7LluJcxL6iPhZp5yxHell9Qsd+uJwIgPfIKof79CqA0ZYhXum
GrVeS7RsyuRRev+eWwWvF2ntJjpI5O6SHZ8QBTg9AmM92Fev5OszY9v3xH582+Twl8Nl543U
kV9PDLtzCHueowguWdQB5n6LQqgADQBZMYIDmjCCA5YCAQEwejB1MQswCQYDVQQGEwJDSDES
MBAGA1UEBxMJU3RhbGxpa29uMQ4wDAYDVQQKEwVUSElOSzETMBEGA1UECxMKQ0EgU2VjdGlv
bjERMA8GA1UEAxMIVGhpbmsgQ0ExGjAYBgkqhkiG9w0BCQEWC2NhQHRoaW5rLmNoAgEoMA0G
CWCGSAFlAwQCAQUAoIIB8TAYBgkqhkiG9w0BCQMxCwYJKoZIhvcNAQcBMBwGCSqGSIb3DQEJ
BTEPFw0xODAyMjQxNDAyMTNaMC8GCSqGSIb3DQEJBDEiBCADiWORpHOJOrpi6tDN5/W+gHkQ
j/d7WX/p91inzxQ8GzBsBgkqhkiG9w0BCQ8xXzBdMAsGCWCGSAFlAwQBKjALBglghkgBZQME
AQIwCgYIKoZIhvcNAwcwDgYIKoZIhvcNAwICAgCAMA0GCCqGSIb3DQMCAgFAMAcGBSsOAwIH
MA0GCCqGSIb3DQMCAgEoMIGJBgkrBgEEAYI3EAQxfDB6MHUxCzAJBgNVBAYTAkNIMRIwEAYD
VQQHEwlTdGFsbGlrb24xDjAMBgNVBAoTBVRISU5LMRMwEQYDVQQLEwpDQSBTZWN0aW9uMREw
DwYDVQQDEwhUaGluayBDQTEaMBgGCSqGSIb3DQEJARYLY2FAdGhpbmsuY2gCASgwgYsGCyqG
SIb3DQEJEAILMXygejB1MQswCQYDVQQGEwJDSDESMBAGA1UEBxMJU3RhbGxpa29uMQ4wDAYD
VQQKEwVUSElOSzETMBEGA1UECxMKQ0EgU2VjdGlvbjERMA8GA1UEAxMIVGhpbmsgQ0ExGjAY
BgkqhkiG9w0BCQEWC2NhQHRoaW5rLmNoAgEoMA0GCSqGSIb3DQEBAQUABIIBAAez3iHPO9W/
NavPsiPZlh6JWGITZFiPwPOpmg97xuNfQmaheAoIR5wOyzg0XxBIhTS48dmzJ8vCqdvtlcgS
/8dE0qNtRZnCufM+/y+gAvkdK/2cKZCoKFFhOVcBAy+s5vct527M5/brYYsmscOykdGLas8m
837OsCu//faO/NOZol7raShAJVUMNYcu0EaiKcOgB3fL3n+5A7v3PfuWC8r8DtTIdugUaGvm
/ZEF7M/oykkou2UfKRRNGM9eAqS03i/+nrhdQiMqPf56WvNmBP0vCzFakUXCCakhK2yQHsjW
oVr8R6ePvAOYARkBfMUK7dU2ra6upfkgv18MsnPpS6UAAAAAAAA=
--------------ms060308050906050504040802--
--===============0579723038154903351==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
------------------------------------------------------------------------------
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot
--===============0579723038154903351==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
_______________________________________________
leaf-devel mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/leaf-devel
--===============0579723038154903351==--