Linux bluetooth development
 help / color / mirror / Atom feed
From: "Fred Schättgen" <bluez-devel@schaettgen.de>
To: BlueZ Mailing List <bluez-devel@lists.sourceforge.net>
Cc: Marcel Holtmann <marcel@holtmann.org>
Subject: Re: [Bluez-devel] Force pairing on single connection?
Date: Fri, 19 Mar 2004 18:06:21 +0100	[thread overview]
Message-ID: <200403191806.21101.bluez-devel@schaettgen.de> (raw)
In-Reply-To: <1079655201.3301.113.camel@pegasus>

On Friday 19 March 2004 01:13, Marcel Holtmann wrote:
> Hi Fred,
..
> > I don't understand why there should be an l2cap ioctl for it. Isn't it
> > enough to let everybody use HCI_AUTHENTICATION_REQUESTED, just like it's
> > the case for HCI_INQUIRY and add a helper function to hci_lib.h?
>
> the point for an ioctl is to make it easier for the programmer, because
> for the HCI command you need to find out the connection handle and the
> open L2CAP/RFCOMM socket already knows its handle.

I don't really care how to do it, if only it can be done as an ordinary 
user :) Otherwise we can't use authentication at all if only one service 
should work without it and if we don't want to bother the users with 
unnecessary PIN-popups.
Or is it a potential security hazard to allow everybody to request 
authentication? I don't think so, since the other device could ask for 
authentication itself.

...
> In the early days I had a long discussion about multi-user environments
> with Max. I hope everything of that is in the archive, but actually none
> of us had the right solution for it. The Bluetooth specification don't
> really talks about it, as it also don't talks about multiple dongles on
> the same host and the interface to the HCI, L2CAP and RFCOMM layers for
> userspace applications.

You're right, it's in the SF archive, sorry. I only searched in the gmane 
archive, but failed to realize that it doesn't contain everything from the 
beginning.
It looks like there is really no good way to associate link keys with users. 
But then it might be a good idea let only a selected group of users answer pin 
requests, because often link level authentication is the only option. Or you 
simply have to trust any other users of your system...

greetings
Fred

      reply	other threads:[~2004-03-19 17:06 UTC|newest]

Thread overview: 6+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2004-02-09 15:03 [Bluez-devel] Force pairing on single connection? Nils Faerber
2004-02-10 10:05 ` Marcel Holtmann
     [not found]   ` <1076408056.17071.53.camel@localhost>
2004-02-10 10:16     ` Marcel Holtmann
2004-03-17 14:23   ` Fred Schättgen
2004-03-19  0:13     ` Marcel Holtmann
2004-03-19 17:06       ` Fred Schättgen [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=200403191806.21101.bluez-devel@schaettgen.de \
    --to=bluez-devel@schaettgen.de \
    --cc=bluez-devel@lists.sourceforge.net \
    --cc=marcel@holtmann.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox