Re: [open...@openssl.org: OpenSSL Security Advisory]

2023-02-08 Thread The Doctor
On Wed, Feb 08, 2023 at 05:41:12PM +0100, Trond Endrest??l wrote: > On Wed, 8 Feb 2023 08:35-0700, The Doctor wrote: > > > On Wed, Feb 08, 2023 at 02:32:24PM -, Christian Weisgerber wrote: > > > On 2023-02-08, The Doctor wrote: > > > > > > > Any concerns vis-a-vis FreeBSD? > > > > > > Yes,

Re: FreeBSD Security Advisory FreeBSD-SA-23:01.geli

2023-02-08 Thread Mariusz Zaborski
When I was working on the patch, I analyzed this situation. The issue with key files is that they can be arbitrary in size, and I think this caused this issue. The passfile/passwords are limited in size. Because they are limited, they are cached in the memory of geli and reused. My conclusion was

Re: FreeBSD Security Advisory FreeBSD-SA-23:01.geli

2023-02-08 Thread grarpamp
Did anyone check if -j/-J might have similar edge cases?

Re: FreeBSD Security Advisory FreeBSD-SA-23:01.geli

2023-02-08 Thread Mariusz Zaborski
No, each disk is encrypted/initialized separately: https://cgit.freebsd.org/src/tree/usr.sbin/bsdinstall/scripts/zfsboot#n1275 On Wed, 8 Feb 2023 at 20:42, Shawn Webb wrote: > On Wed, Feb 08, 2023 at 07:08:33PM +, FreeBSD Security Advisories > wrote: > > -BEGIN PGP SIGNED MESSAGE- >

Re: FreeBSD Security Advisory FreeBSD-SA-23:01.geli

2023-02-08 Thread Shawn Webb
On Wed, Feb 08, 2023 at 07:08:33PM +, FreeBSD Security Advisories wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA512 > > = > FreeBSD-SA-23:01.geli Security Advisory >

FreeBSD Security Advisory FreeBSD-SA-23:01.geli

2023-02-08 Thread FreeBSD Security Advisories
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 = FreeBSD-SA-23:01.geli Security Advisory The FreeBSD Project Topic:

Re: [open...@openssl.org: OpenSSL Security Advisory]

2023-02-08 Thread The Doctor
On Wed, Feb 08, 2023 at 02:32:24PM -, Christian Weisgerber wrote: > On 2023-02-08, The Doctor wrote: > > > Any concerns vis-a-vis FreeBSD? > > Yes, OpenSSL in base needs to be updated to 1.1.1t... *checks git* > ... which has already happened in main, stable/13 and stable/12. > > I assume a

Re: [open...@openssl.org: OpenSSL Security Advisory]

2023-02-08 Thread Christian Weisgerber
On 2023-02-08, The Doctor wrote: > Any concerns vis-a-vis FreeBSD? Yes, OpenSSL in base needs to be updated to 1.1.1t... *checks git* ... which has already happened in main, stable/13 and stable/12. I assume advisories will be forthcoming. -- Christian "naddy" Weisgerber