Re: Retiring lpr and lpd

Rick Macklem <[email protected]> Thu, 26 Feb 2026 06:57:55 -0800
Newsgroups gmane.os.freebsd.architechture
Message-ID <CAM5tNy67+gp=OBMRJaBTWXv_K3axtHZ-cb3c8Xsq5N9JxXkwYQ@mail.gmail.com>
On Wed, Feb 25, 2026 at 10:25=E2=80=AFPM Marco Moock <[email protected]> wrote:
>
> CAUTION: This email originated from outside of the University of Guelph. =
Do not click links or open attachments unless you recognize the sender and =
know the content is safe. If in doubt, forward suspicious emails to IThelp@=
uoguelph.ca.
>
>
>
> ---------- Forwarded message ----------
> From: Marco Moock <[email protected]>
> To: [email protected]
> Cc:
> Bcc:
> Date: Thu, 26 Feb 2026 07:22:52 +0100
> Subject: Re: Retiring lpr and lpd
> On 26.02.2026 02:53 Sulev-Madis Silber
> <[email protected]> wrote:
>
> > On February 26, 2026 2:10:59 AM GMT+02:00, "Dag-Erling Sm=C3=B8rgrav"
> > <[email protected]> wrote:
> > >Either we clean up lpr and it can stay in base, or we don't and it
> > >doesn't belong in ports either.  I thought I had made that clear.
> >
> >
> > so what happens when people still need it and neither happens?
> >
> > do people need to fish it out of dark bowels of the internet or vcs
> > history? because users remain
>
> It it is a rather sane idea to not include or provide software with
> known security-relevant vulnerabilities, unless they are going to be
> fixed. This is a common process to reduce the vulnerability of the
> system at all. If people really have the need to run it, they need to
> compile from old sources.
I disagree. As Julian noted, some sort of warning w.r.t. known
security vulnerabilities is sufficient, I think.

Security, like safety, is not an absolute. It requires a user/sysadmin
to evaluate the risks and make an informed decision on what to run
and how to do it.
--> Firewalls were invented for a reason.

For example, if you want to secure it, NFS must be used with
either Kerberos or TLS. but almost no one does this, due to
administrative hassles and performance issues (encrypting/decrypting
all those messages results in a lot of overhead).
(For example, I use ftpd. I know there are security vulnerabilities, but
 they are not a concern in the environment I use it in.)

rick
ps: I don't have a strong opinion w.r.t. what should be done with lpr.

>
> --
> kind regards
> Marco
>
> Send spam to [email protected]