Re: Bug#590873: openconnect < 2.25 does not verify SSL server certificates

2010-08-30 Thread Adam D. Barratt
On Mon, 2010-08-30 at 17:34 +0100, Dominic Hargreaves wrote: > On Sun, Aug 29, 2010 at 10:42:28AM +0100, Adam D. Barratt wrote: > > > I have to admit I'm not hugely happy with the "CSD trojan" messages but, > > at least in terms of the configuration file setup, I'm not sure it's worth > > divergin

Re: Bug#590873: openconnect < 2.25 does not verify SSL server certificates

2010-08-30 Thread Dominic Hargreaves
On Sun, Aug 29, 2010 at 10:42:28AM +0100, Adam D. Barratt wrote: > I have to admit I'm not hugely happy with the "CSD trojan" messages but, > at least in terms of the configuration file setup, I'm not sure it's worth > diverging from upstream on. > > Please go ahead. Uploaded, please unblock ope

Re: Bug#590873: openconnect < 2.25 does not verify SSL server certificates

2010-08-29 Thread Adam D. Barratt
On Sat, August 28, 2010 12:59, Dominic Hargreaves wrote: > On Sat, Aug 28, 2010 at 01:16:29PM +0200, Julien Cristau wrote: >> On Sat, Aug 28, 2010 at 11:50:49 +0100, Dominic Hargreaves wrote: >> >> > On Sun, Aug 15, 2010 at 08:56:46PM +0100, Adam D. Barratt wrote: >> > > On Sun, 2010-08-15 at 16:13

Re: Bug#590873: openconnect < 2.25 does not verify SSL server certificates

2010-08-28 Thread Dominic Hargreaves
On Sat, Aug 28, 2010 at 01:16:29PM +0200, Julien Cristau wrote: > On Sat, Aug 28, 2010 at 11:50:49 +0100, Dominic Hargreaves wrote: > > > On Sun, Aug 15, 2010 at 08:56:46PM +0100, Adam D. Barratt wrote: > > > On Sun, 2010-08-15 at 16:13 +0100, Dominic Hargreaves wrote: > > > > To the untrained eye

Re: Bug#590873: openconnect < 2.25 does not verify SSL server certificates

2010-08-28 Thread Julien Cristau
On Sat, Aug 28, 2010 at 11:50:49 +0100, Dominic Hargreaves wrote: > On Sun, Aug 15, 2010 at 08:56:46PM +0100, Adam D. Barratt wrote: > > On Sun, 2010-08-15 at 16:13 +0100, Dominic Hargreaves wrote: > > > To the untrained eye, the diff between > > > 6732c0e8ccb4d57d6a970973f994a9d2d3509def > > > an

Re: Bug#590873: openconnect < 2.25 does not verify SSL server certificates

2010-08-28 Thread Dominic Hargreaves
On Sun, Aug 15, 2010 at 08:56:46PM +0100, Adam D. Barratt wrote: > On Sun, 2010-08-15 at 16:13 +0100, Dominic Hargreaves wrote: > > To the untrained eye, the diff between > > 6732c0e8ccb4d57d6a970973f994a9d2d3509def > > and > > 3b2738befa7fe934d0d55b77fe1fcf28aafbe424 > > > > in upstream git is wh

Re: Bug#590873: openconnect < 2.25 does not verify SSL server certificates

2010-08-24 Thread Dominic Hargreaves
On Sun, Aug 15, 2010 at 08:56:46PM +0100, Adam D. Barratt wrote: > On Sun, 2010-08-15 at 16:13 +0100, Dominic Hargreaves wrote: > > To the untrained eye, the diff between > > 6732c0e8ccb4d57d6a970973f994a9d2d3509def > > and > > 3b2738befa7fe934d0d55b77fe1fcf28aafbe424 > > > > in upstream git is wh

Re: Bug#590873: openconnect < 2.25 does not verify SSL server certificates

2010-08-15 Thread Adam D. Barratt
On Sun, 2010-08-15 at 16:13 +0100, Dominic Hargreaves wrote: > To the untrained eye, the diff between > 6732c0e8ccb4d57d6a970973f994a9d2d3509def > and > 3b2738befa7fe934d0d55b77fe1fcf28aafbe424 > > in upstream git is what's required for this, but the patch would need > a bit of work to apply clean

Re: Bug#590873: openconnect < 2.25 does not verify SSL server certificates

2010-08-15 Thread Dominic Hargreaves
On Thu, Jul 29, 2010 at 03:45:55PM -0400, Anders Kaseorg wrote: > Versions of OpenConnect before 2.25 do not verify that the server SSL > certificate matches the server hostname, which enables an attacker to > perform an MITM attack on the connection. This can be fixed by upgrading > to OpenCo