From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from eggs.gnu.org ([208.118.235.92]:33510) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1SbcZK-00016e-1S for qemu-devel@nongnu.org; Mon, 04 Jun 2012 15:03:59 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1SbcZI-0007yM-Bk for qemu-devel@nongnu.org; Mon, 04 Jun 2012 15:03:57 -0400 Received: from mx1.redhat.com ([209.132.183.28]:26762) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1SbcZI-0007xs-2v for qemu-devel@nongnu.org; Mon, 04 Jun 2012 15:03:56 -0400 From: Paul Moore Date: Mon, 04 Jun 2012 14:16:15 -0400 Message-ID: <10302697.mednriu9QL@sifl> In-Reply-To: <4FCAB60E.1070107@codemonkey.ws> References: <20120502193256.6508.86360.stgit@sifl> <4FCAB60E.1070107@codemonkey.ws> MIME-Version: 1.0 Content-Transfer-Encoding: 7Bit Content-Type: text/plain; charset="us-ascii" Subject: Re: [Qemu-devel] [PATCH v2] vnc: disable VNC password authentication (security type 2) when in FIPS mode List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: Anthony Liguori Cc: qemu-devel@nongnu.org On Sunday, June 03, 2012 08:55:42 AM Anthony Liguori wrote: > This needs to be optional and disabled by default I think. I strongly > dislike disabling a feature when a user isn't asking for it. You can > introduce a global -enable-fips-mode or something like that. I'll resend the patch, but before I do I want to make sure the defaults are set to whatever you find acceptable to merging and the second sentence above has me a little confused; do you mean "... dislike _enabling_ a feature when a user isn't asking for it."? -- paul moore security and virtualization @ redhat