Re: Retiring lpr and lpd

Marco Moock <[email protected]> Fri, 27 Feb 2026 06:29:33 +0100
Newsgroups gmane.os.freebsd.architechture
Message-ID <[email protected]>
--Sig_/BIr7N1/byttQogHx1FbEyUK
Content-Type: text/plain; charset=US-ASCII
Content-Transfer-Encoding: quoted-printable

On 26.02.2026 14:29 Rick Macklem <[email protected]> wrote:

> If I followed this edict, I would only allow Kerberized NFS and
> NFS over TLS by default. Since 99.99999% of NFS mounts do
> not do the above, I think there would be some pushback.
> (The "bug" is in the original NFS design, using an RPC
> non-authentication mechanism called AUTH_SYS.)

NFS over TLS is possible and recommended. But even if it is not used,
the operator is aware that eavesdropping is possible, by the design.
This doesn't apply to the bugs (I have doubt that the bugs are
intended) in lpd.

--=20
kind regards
Marco

Send spam to [email protected]

--Sig_/BIr7N1/byttQogHx1FbEyUK
Content-Type: application/pgp-signature
Content-Description: Digitale Signatur von OpenPGP

-----BEGIN PGP SIGNATURE-----

iQJPBAEBCAA5FiEEpXefSZn9R6zNZtTQE76RLz2tRfAFAmmhK70bFIAAAAAABAAO
bWFudTIsMi41KzEuMTEsMiwyAAoJEBO+kS89rUXwo10P/0gxdR/WrXx6jwbVT1Q7
ej6rFgt/r69v9N9L+L+sR07GHacylem6KknV+C78mX56exKQ/hr/+qfPpO3ThKAC
E0NiucrptHxukWLBhaiB5uoq9aL2Pg9w2oOXen1XESQtjH7cjdnKzowogOdnbRu4
rHWhQRA6zRSjWo6Gw80Cywb0SweN7yL/60Rm9CbwUXVSF7kDgrsxPziGuOMc9mis
riNr2Kp/fi3UrfdOHnfi5aJgbXzEz3gxckYOpQjZmGOaS5i2AQ5i1im7vi3+pfkU
5BrczlY/nIno6o3Wtji59DBG9OPUp9ZZU4k4Z4HFcmC6+5Tezy5RFEIvWWeefwWV
TEf45FUqo4ZHbsTmLOx/6s2PWVQ/bAhCdIuTXSB0aDnRxNxk9s2pgPtNEIsXCcsi
v+sxWjI1APjtWLbxhoYuv0oO8p+Hk6qXPoEdeeT7cOs3bkyOmsu8gaNk0Z2E+8HN
AzXO97FlHxaRrw4RfuQLQ67TtAni8TVti7xoZtPwTC4ssl44xxciJ9tBW8YiuYUf
bFZwL9TT/TepyU1AZCsw/0rLhgDUMAdGAPw6mHOJMzWidVBAZKg8nC4/91b/guGW
Kr4G+PnTEZdQ1bOr4I3TP6uuvBV1eokZ2vx7KOOoNWdAbwxIAs8/drjfl2s5ZNts
LQlgv5UKTWjfSbI295TsbQQq
=CE2W
-----END PGP SIGNATURE-----

--Sig_/BIr7N1/byttQogHx1FbEyUK--