All of lore.kernel.org
 help / color / mirror / Atom feed
From: "Peter A. Bigot" <pab@pabigot.com>
To: openembedded-devel@lists.openembedded.org
Subject: Re: Question about ntp build option
Date: Fri, 16 Jan 2015 06:52:33 -0600	[thread overview]
Message-ID: <54B90991.7090807@pabigot.com> (raw)
In-Reply-To: <1564018.h6sptGTLbK@peggleto-mobl5.ger.corp.intel.com>

On 01/16/2015 05:54 AM, Paul Eggleton wrote:
> On Friday 16 January 2015 02:05:27 Fan, Xin wrote:
>>> There will always be differences in how people expect software to be
>>> configured for whatever target and application they are building for,
>>> hence why we make it fairly easy to adjust the configuration.
>> Actually, I had the same opinion with you at the beginning.
>>
>> But in last December, the ntp published 4 serious
>> vulnerabilities(CVE-2014-9293, CVE-2014-9294,CVE-2014-9295,CVE-2014-9296).
>> So I think even the display a clock function, it should also be protected
>> by openssl for the safety connection.
> I'm not sure this follows. Correct me if I'm wrong, but SSL doesn't actually
> prevent me as an unauthorised user from making a connection - it just ensures
> that when I connect to a server that firstly the data sent over the connection
> is encrypted, and furthermore that the connection is directly to the server I
> think it is and not someone else masquerading as that server.

Though this is the common mode of operation, ssl also permits client 
authentication through certificates, so the server knows that the client 
is who it says it is.  I generally run public-facing restricted access 
web servers this way, in addition to using HTTP authentication.  I don't 
know but would assume ntp would support the same capability through 
configuration files if ssl is enabled in the build.

I doubt the number of people in the world that would configure ntp that 
way is very large, though. As long as it's available through 
PACKAGECONFIG (and it is) I'm not convinced changing the default is 
critical, but it's probably not a big deal either unless the added 
dependencies are a burden for somebody's small-footprint installation. 
(In which case they could override PACKAGECONFIG. That's what I love 
about Yocto.)

Peter

>   This would mean
> that for example any buffer overflows such as the ones in the vulnerabilities
> you point to would still be accessible and potentially exploitable even if the
> connection were only available as encrypted using SSL, at least as far as I
> can tell.
>
>> And I find more packages in Yocto which also use the openssl as the
>> default option, so I think ntp also should set the openssl option as default
>> setting.
> In a lot of other cases SSL is on by default because it really makes sense;
> for example it's common to want to fetch files from https servers so in the
> general case you would want curl to be built with SSL support by default. I'm
> not sure the same can be said of ntp. Again, I'm happy to be corrected though.
>
> Cheers,
> Paul
>



  reply	other threads:[~2015-01-16 12:59 UTC|newest]

Thread overview: 7+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2014-11-28  6:05 Question about ntp build option Fan, Xin
2015-01-05 14:33 ` Paul Eggleton
2015-01-05 14:39   ` Paul Eggleton
2015-01-16  2:05   ` Fan, Xin
2015-01-16 11:54     ` Paul Eggleton
2015-01-16 12:52       ` Peter A. Bigot [this message]
2015-01-27  9:42       ` Fan, Xin

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=54B90991.7090807@pabigot.com \
    --to=pab@pabigot.com \
    --cc=openembedded-devel@lists.openembedded.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.