Re: FreeBSD Security Advisory FreeBSD-SA-20:33.openssl

2020-12-12 Thread Benjamin Kaduk
On Sat, Dec 12, 2020 at 04:57:08PM -0800, John-Mark Gurney wrote: > > If FreeBSD is going to continue to use OpenSSL, better testing needs to > be done to figure out such breakage earliers, and how to not have them > go undetected for so long. I don't think anyone would argue against increasing te

Re: FreeBSD Security Advisory FreeBSD-SA-20:33.openssl

2020-12-12 Thread John-Mark Gurney
John Baldwin wrote this message on Sat, Dec 12, 2020 at 11:40 -0800: > On 12/10/20 10:46 PM, John-Mark Gurney wrote: > > FreeBSD Security Advisories wrote this message on Wed, Dec 09, 2020 at > > 23:03 +: > >> versions included in FreeBSD 12.x. This vulnerability is also known to > >> affect

Re: FreeBSD Security Advisory FreeBSD-SA-20:33.openssl

2020-12-12 Thread The Doctor via freebsd-security
On Sat, Dec 12, 2020 at 11:40:13AM -0800, John Baldwin wrote: > On 12/10/20 10:46 PM, John-Mark Gurney wrote: > > FreeBSD Security Advisories wrote this message on Wed, Dec 09, 2020 at > > 23:03 +: > >> versions included in FreeBSD 12.x. This vulnerability is also known to > >> affect OpenSSL

Re: FreeBSD Security Advisory FreeBSD-SA-20:33.openssl

2020-12-12 Thread John Baldwin
On 12/10/20 10:46 PM, John-Mark Gurney wrote: > FreeBSD Security Advisories wrote this message on Wed, Dec 09, 2020 at 23:03 > +: >> versions included in FreeBSD 12.x. This vulnerability is also known to >> affect OpenSSL versions included in FreeBSD 11.4. However, the OpenSSL >> project is

Re: Kerberos: base or port? [Was: FreeBSD Security Advisory FreeBSD-SA-20:33.openssl]

2020-12-12 Thread Benjamin Kaduk
On Sat, Dec 12, 2020 at 11:21:14AM +0100, Andrea Venturoli wrote: > On 12/11/20 9:23 PM, Benjamin Kaduk wrote: > > > It would be useful to give more specifics on the failures, as there's a few > > classes of things that can go wrong. > > I thought this would be OT in this thread, but I'll gladly

Re: FreeBSD Security Advisory FreeBSD-SA-20:33.openssl

2020-12-12 Thread The Doctor via freebsd-security
On Fri, Dec 11, 2020 at 01:36:13PM +0100, Tomasz CEDRO wrote: > On Fri, Dec 11, 2020 at 12:44 PM Franco Fichtner wrote: > > > On 11. Dec 2020, at 12:38 PM, Martin Simmons wrote: > > >> On Thu, 10 Dec 2020 22:46:28 -0800, John-Mark Gurney said: > > >> What are peoples thoughts on how to address

Kerberos: base or port? [Was: FreeBSD Security Advisory FreeBSD-SA-20:33.openssl]

2020-12-12 Thread Andrea Venturoli
On 12/11/20 9:23 PM, Benjamin Kaduk wrote: It would be useful to give more specifics on the failures, as there's a few classes of things that can go wrong. I thought this would be OT in this thread, but I'll gladly comply :) It doesn't look like openssl from ports attempts to support the T

Re: AMNESIA:33 and FreeBSD TCP/IP stack involvement

2020-12-12 Thread John Kennedy
On Wed, Dec 09, 2020 at 06:58:49AM +0100, Hartmann, O. wrote: > Hello, > I've got a question about recently discovered serious vulnerabilities > in certain TCP stack implementations, designated as AMNESIA:33 (as far > as I could follow the recently made announcements and statements, > please see, f

Re: FreeBSD Security Advisory FreeBSD-SA-20:33.openssl

2020-12-12 Thread Tomasz CEDRO
On Fri, Dec 11, 2020 at 1:57 PM Franco Fichtner wrote: > > On 11. Dec 2020, at 1:36 PM, Tomasz CEDRO wrote: > > On Fri, Dec 11, 2020 at 12:44 PM Franco Fichtner wrote: > >>> On 11. Dec 2020, at 12:38 PM, Martin Simmons wrote: > On Thu, 10 Dec 2020 22:46:28 -0800, John-Mark Gurney said: > >

Re: FreeBSD Security Advisory FreeBSD-SA-20:33.openssl

2020-12-12 Thread Tomasz CEDRO
On Fri, Dec 11, 2020 at 12:44 PM Franco Fichtner wrote: > > On 11. Dec 2020, at 12:38 PM, Martin Simmons wrote: > >> On Thu, 10 Dec 2020 22:46:28 -0800, John-Mark Gurney said: > >> What are peoples thoughts on how to address the support mismatch between > >> FreeBSD and OpenSSL? And how to ad