public inbox for linux-bluetooth@vger.kernel.org
 help / color / mirror / Atom feed
From: Marcel Holtmann <marcel@holtmann.org>
To: BlueZ development <bluez-devel@lists.sourceforge.net>
Subject: Re: [Bluez-devel] Pin for an outgoing connection
Date: Mon, 23 Oct 2006 17:08:57 +0200	[thread overview]
Message-ID: <1161616137.10866.98.camel@aeonflux.holtmann.net> (raw)
In-Reply-To: <7aabaf0e0610230427m2f8bfa5ekcfe2ce2fc9f165f1@mail.gmail.com>

Hi Valentine,

> I'm currently trying bluez-utils 3.7 (D-BUS interface is really sweet
> thing and a must for all so called desktop Linux components) but
> unfortunately I've came across the following problem: pin code I
> specify in hcid.conf via "passphrase" option is never used for
> outgoing connections. It's clear from the code in hcid/security.c but
> man pages are somewhat misleading at this point - they state pin code
> specified in hcid.conf will be used if I set security to "auto".
> 
> Apparently, "if" condition at security.c:386 will never be true -
> pinlen is read from "pincodes" file in storage at line 364 but this
> file is never created or stored through all the bluez-utils code.
> 
> The question is: is it intended behaviour or it's a bug and should be fixed?

if the manual pages are misleading, then this is a bug. The pincodes
file is meant to be kinda secret. The code in the CVS will also use it
in case of security user, but it will still ask the passkey agent. From
a security perspective, any automatic pairing with a default PIN is a
security risk and by default we don't allow that anymore. The passkey in
the hcid.conf is only used for incoming connection btw.

Regards

Marcel



-------------------------------------------------------------------------
Using Tomcat but need to do more? Need to support web services, security?
Get stuff done quickly with pre-integrated technology to make your job easier
Download IBM WebSphere Application Server v.1.0.1 based on Apache Geronimo
http://sel.as-us.falkag.net/sel?cmd=lnk&kid=120709&bid=263057&dat=121642
_______________________________________________
Bluez-devel mailing list
Bluez-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/bluez-devel

  reply	other threads:[~2006-10-23 15:08 UTC|newest]

Thread overview: 10+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2006-10-23 11:27 [Bluez-devel] Pin for an outgoing connection Valentine Sinitsyn
2006-10-23 15:08 ` Marcel Holtmann [this message]
2006-10-23 13:40   ` Valentine Sinitsyn
2006-10-23 15:44     ` Marcel Holtmann
2006-10-23 14:02       ` Valentine Sinitsyn
2006-10-23 16:06         ` Marcel Holtmann
2006-10-23 20:50         ` Daniel Gollub
2006-10-24  3:51           ` Valentine Sinitsyn
2006-10-24  8:04           ` Marcel Holtmann
2006-10-29 10:01           ` Valentine Sinitsyn

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1161616137.10866.98.camel@aeonflux.holtmann.net \
    --to=marcel@holtmann.org \
    --cc=bluez-devel@lists.sourceforge.net \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox