Re: on the NTP security issues and fixes

2016-05-06 Thread Hal Murray
dfoxfra...@gmail.com said: > Mark, you're now "GO" from me for tagging a release, Please hang on a bit. Looks like reading the leap file is broken. More soon, I hope. -- These are my opinions. I hate spam. ___ devel mailing list devel@ntpsec.o

Re: on the NTP security issues and fixes

2016-05-06 Thread Eric S. Raymond
Gary E. Miller : > Don't you get auto notified from gitlab?? > > https://gitlab.com/NTPsec/ntpsec/issues/53 > https://gitlab.com/NTPsec/ntpsec/issues/54 > https://gitlab.com/NTPsec/ntpsec/issues/55 Oh yeah. 53 and 54 are build recipe problems. Amar's pigeon; I can't do everything. --

Re: on the NTP security issues and fixes

2016-05-06 Thread Daniel Franke
I've updated the NEWS file with security notes. Mark, you're now "GO" from me for tagging a release, though it sounds like others may still be getting last-minute fixes in. The release notes are currently dominated by discussion of bugs we've inherited and work we've forward-ported from Classic, bu

Re: on the NTP security issues and fixes

2016-05-06 Thread Gary E. Miller
Yo Eric! On Fri, 6 May 2016 15:56:20 -0400 "Eric S. Raymond" wrote: > Gary E. Miller : > > > That's valuable feedback, seeing as I just performed the major > > > surgery of removing Autokey. > > > > Yeah, and two new bugs in your queue... > > Eh? Which ones? Don't you get auto notified f

Re: on the NTP security issues and fixes

2016-05-06 Thread Eric S. Raymond
Gary E. Miller : > > That's valuable feedback, seeing as I just performed the major surgery > > of removing Autokey. > > Yeah, and two new bugs in your queue... Eh? Which ones? > But, more important things to do. Old teclo rule of thumb: fix bugs > first, then add features. Maybe fix #48. Ye

Re: on the NTP security issues and fixes

2016-05-06 Thread Gary E. Miller
Yo Daniel! On Fri, 6 May 2016 15:34:29 -0400 Daniel Franke wrote: > On 5/6/16, Gary E. Miller wrote: > >> Do we have to live with long convergence times? Do you have any > >> theory about what causes this and how it can be fixed? > > > > I have not gone deep into the PLL, grouping, and selec

Re: on the NTP security issues and fixes

2016-05-06 Thread Daniel Franke
On 5/6/16, Gary E. Miller wrote: >> Do we have to live with long convergence times? Do you have any >> theory about what causes this and how it can be fixed? > > I have not gone deep into the PLL, grouping, and selection layers. > Daniel Franke's talk at Penguicon leads me to believe he is starti

Re: on the NTP security issues and fixes

2016-05-06 Thread Gary E. Miller
Yo Hal! On Fri, 06 May 2016 12:08:14 -0700 Hal Murray wrote: > g...@rellim.com said: > > But, more important things to do. Old teclo rule of thumb: fix > > bugs first, then add features. Maybe fix #48. > > It's too late of "fix" #48. Why? Worst case we renumber it #49 and fix it. If peo

Re: on the NTP security issues and fixes

2016-05-06 Thread Hal Murray
g...@rellim.com said: > But, more important things to do. Old teclo rule of thumb: fix bugs first, > then add features. Maybe fix #48. It's too late of "fix" #48. g...@rellim.com said: > Plus the socket is extensible, whereas the SHM is currently very twitchy, > any change and binaries no lo

Re: on the NTP security issues and fixes

2016-05-06 Thread Gary E. Miller
Yo Eric! On Fri, 6 May 2016 08:39:55 -0400 "Eric S. Raymond" wrote: > Gary E. Miller : > > Yo All! > > > > I pulled git head, running it now on a server in place of chronyd. > > > > Seems to work OK. I'll keep an eye on it. > > That's valuable feedback, seeing as I just performed the major

Re: on the NTP security issues and fixes

2016-05-06 Thread Eric S. Raymond
Gary E. Miller : > Yo All! > > I pulled git head, running it now on a server in place of chronyd. > > Seems to work OK. I'll keep an eye on it. That's valuable feedback, seeing as I just performed the major surgery of removing Autokey. > I really like the chronyd socket interface over the SHM

Re: on the NTP security issues and fixes

2016-05-04 Thread Gary E. Miller
Yo All! I pulled git head, running it now on a server in place of chronyd. Seems to work OK. I'll keep an eye on it. A couple things I note right away, consider them non-critical feature requests. I really like the chronyd socket interface over the SHM one. The user is not playing with magic

Re: on the NTP security issues and fixes

2016-05-04 Thread Eric S. Raymond
Daniel Franke : > Well, that was scary and a little overwhelming but it turns out we're > in remarkably good shape: I've now merged patches for what look to be > the only three out of the eleven issues that impact us, and two of > those only dubiously qualify as vulnerabilities at all. Before I ask

Re: on the NTP security issues and fixes

2016-05-04 Thread Daniel Franke
Well, that was scary and a little overwhelming but it turns out we're in remarkably good shape: I've now merged patches for what look to be the only three out of the eleven issues that impact us, and two of those only dubiously qualify as vulnerabilities at all. Before I ask Mark to tag a release I

Re: on the NTP security issues and fixes

2016-05-02 Thread Mark Atwood
Tell me more about the fuzzing you are doing? Thanks for the work you are doing! ..m On Fri, Apr 29, 2016 at 9:16 AM Daniel Poirot wrote: > Hey boss, > > Is there anything for us in the field to do? > > I continue to cross compile, run static analysis on the source and fuzz > the binaries. > >

Re: on the NTP security issues and fixes

2016-04-29 Thread Daniel Poirot
Hey boss, Is there anything for us in the field to do? I continue to cross compile, run static analysis on the source and fuzz the binaries. Dan > On Apr 28, 2016, at 3:43 PM, Mark Atwood wrote: > > Folks, > > Late Tuesday night, NTP.org made a release containing 11 security fixes. Some

Re: on the NTP security issues and fixes

2016-04-29 Thread Hal Murray
Summary here: http://support.ntp.org/bin/view/Main/SecurityNotice#April_2016_NTP_4_2_8p7_S ecurity -- These are my opinions. I hate spam. ___ devel mailing list devel@ntpsec.org http://lists.ntpsec.org/mailman/listinfo/devel

Re: on the NTP security issues and fixes

2016-04-28 Thread Daniel Poirot
...see my email from yesterday for details from the Cisco disclosure reports. > On Apr 28, 2016, at 3:43 PM, Mark Atwood wrote: > > Folks, > > Late Tuesday night, NTP.org made a release containing 11 security fixes. Some > of these vulnerabilities were also reported to the NTPsec project, an

on the NTP security issues and fixes

2016-04-28 Thread Mark Atwood
Folks, Late Tuesday night, NTP.org made a release containing 11 security fixes. Some of these vulnerabilities were also reported to the NTPsec project, and we planned for a coordinated release and disclosure. Unfortunately, several others caught us by surprise, and this surprise comes at an inconv