Your message dated Sun, 16 Jun 2024 20:33:56 +0000
with message-id <e1siwzy-00dpgp...@fasolo.debian.org>
and subject line Bug#825438: fixed in systemd 252.26-1~deb12u2
has caused the Debian Bug report #825438,
regarding nss-mymachines: /etc/nsswitch.conf ordering
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
825438: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=825438
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---
Package: libnss-mymachines
Version: 239-6
Severity: important


Hi.

When libnss-mymachines it automatically adds the respective
entries to /etc/nsswitch.conf and it seems to place
"mymachines" after "dns".

This is IMO bad (and actually even a security hole), as it would
resolve DNS names before the mymachine names.

The security hole lies in the fact that people will easily trust
what runs locally in a VM/container, and e.g. not check SSH keys
when connecting to that... however, if dns is resolved first
it could point to any machine on the net.


The libnss-mymachines itself suggests:
       It is recommended to place "mymachines" after the "files" or "compat"
       entry of the /etc/nsswitch.conf lines to make sure that its mappings
       are preferred over other resolvers such as DNS, but so that /etc/hosts,
       /etc/passwd and /etc/group based mappings take precedence.



Could you please change that and add a NEWS.Debian entry so that
people have the chance to catch up?


Thanks,
Chris.

--- End Message ---
--- Begin Message ---
Source: systemd
Source-Version: 252.26-1~deb12u2
Done: Luca Boccassi <bl...@debian.org>

We believe that the bug you reported is fixed in the latest version of
systemd, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 825...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Luca Boccassi <bl...@debian.org> (supplier of updated systemd package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Sun, 16 Jun 2024 10:44:31 +0100
Source: systemd
Architecture: source
Version: 252.26-1~deb12u2
Distribution: bookworm
Urgency: medium
Maintainer: Debian systemd Maintainers 
<pkg-systemd-maintain...@lists.alioth.debian.org>
Changed-By: Luca Boccassi <bl...@debian.org>
Closes: 825438 851314 1072380
Changes:
 systemd (252.26-1~deb12u2) bookworm; urgency=medium
 .
   [ Gioele Barabucci ]
   * d/libnss-myhostname.nss: Install after `files` (Closes: #1072380)
   * d/libnss-mymachines.nss: Install before `resolve` and `dns` Installing
     `mymachines` before `dns` and `resolve` (whatever comes first) is
     suggested in the manpage. It also avoids leaking information about
     local machines to the DNS resolver. (Closes: #825438, #851314)
Checksums-Sha1:
 8f5c6ec661c2799fb977c91f90f695a128032108 6618 systemd_252.26-1~deb12u2.dsc
 80206797d3537860341eb6ab04c9ba9d25e08d67 171184 
systemd_252.26-1~deb12u2.debian.tar.xz
 b17d252f6e76bde84ac71b28adb975a5408b0e41 11785 
systemd_252.26-1~deb12u2_source.buildinfo
Checksums-Sha256:
 3d392278d93e03561f0875c61dbd83f05c4e1082ea6572fc13248f7cc8d2232a 6618 
systemd_252.26-1~deb12u2.dsc
 099d888066d506a9625bbc04cffbaa5cbe483d8cbe33e19cae5f8ea3c165f59c 171184 
systemd_252.26-1~deb12u2.debian.tar.xz
 749ab2b0d598571a230f8774e1de100ef6dc07728ab4a80bc842a5bc09059ad5 11785 
systemd_252.26-1~deb12u2_source.buildinfo
Files:
 a8e1d437bc7a6e2d9c3b74dd76c307ec 6618 admin optional 
systemd_252.26-1~deb12u2.dsc
 eadc641c2c9838ca8fa6742736328f7f 171184 admin optional 
systemd_252.26-1~deb12u2.debian.tar.xz
 d9becf3badaad0535d3b7c280ade8331 11785 admin optional 
systemd_252.26-1~deb12u2_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQJFBAEBCgAvFiEErCSqx93EIPGOymuRKGv37813JB4FAmZutFMRHGJsdWNhQGRl
Ymlhbi5vcmcACgkQKGv37813JB5Ydg/9ERtEXYIuXw0AFY0ptkUMUzxcGvqyiJUU
xWMY6SNuVT2JyzB/qnUA0JDiTjCnFh1GHZDYxPCKgCmz2wZQSkrQvtqwiKCdE4iY
m0r8s/69Q0068Qy2EFmvOLRcwKx5MKXVWCcp03G9PE3i4H7INN+C+pBGyNCulDM6
np3AuXIpxFruNcHfu2Sgm2c4AjCc6pqeIdVMcriLz3wBLoQhDjFNOh5IqrsZsrVI
qGFFTKBkAX0vELEbppiWfBIFN1NjRNNg8Du4eeLCM9GSrxuR/iAkMKyk/PcWIwjQ
1beN3ChDQHHPVfKZvzpiolXSx6KA1nJiMyDdagBiKJqSoFE3BUbJHpwUdhRxNGNP
7PZXaXQOMWUVh+nA3xqsEbvwR3ULWQ2v7upZM3MsgMTLSQ1YOHQGbKUldwF12SAE
uhUQoFnuioSOByB5xZt5BWvcY8+bMhOsDb6zisv5RACh9faD4QsxbTTrxLRvhNkj
gGHQPaHrUHrB3NcPy6dvOjjjrIQdbVU0XEd5Y1KB0pXMR6KX1Fb/P5g3BLZ6krAL
JGEvlaZlxZOXEk+aUWJst8FVuWOTEHZX3cqT9jDmn31YKi9Hbln5u6sG8PMdRZA0
N3DvpUeE3p6Zrd1cimB8fAYzH5vPSngPaKU/8EduLtwe3YMD/S56IsCnMCBy03Kc
nvTKVcycFL0=
=9zzN
-----END PGP SIGNATURE-----

Attachment: pgpWR04Etjoae.pgp
Description: PGP signature


--- End Message ---

Reply via email to