From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from eggs.gnu.org ([208.118.235.92]:39418) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1SPVfZ-0007UL-IJ for qemu-devel@nongnu.org; Wed, 02 May 2012 05:16:27 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1SPVfX-0000q7-Fs for qemu-devel@nongnu.org; Wed, 02 May 2012 05:16:21 -0400 Received: from mx1.redhat.com ([209.132.183.28]:50168) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1SPVfX-0000pw-7z for qemu-devel@nongnu.org; Wed, 02 May 2012 05:16:19 -0400 Date: Wed, 2 May 2012 10:16:11 +0100 From: "Daniel P. Berrange" Message-ID: <20120502091611.GJ13336@redhat.com> References: <20120501212040.27850.27184.stgit@sifl> <4FA0710D.9070900@codemonkey.ws> MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline In-Reply-To: <4FA0710D.9070900@codemonkey.ws> Subject: Re: [Qemu-devel] [PATCH] vnc: disable VNC password authentication (security type 2) when in FIPS mode Reply-To: "Daniel P. Berrange" List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: Anthony Liguori Cc: Paul Moore , George Wilson , qemu-devel@nongnu.org On Tue, May 01, 2012 at 06:26:05PM -0500, Anthony Liguori wrote: > On 05/01/2012 04:20 PM, Paul Moore wrote: > >FIPS 140-2 requires disabling certain ciphers, including DES, which is used > >by VNC to obscure passwords when they are sent over the network. The > >solution for FIPS users is to disable the use of VNC password auth when the > >host system is operating in FIPS mode. > > Sorry, what? > > Does FIPS really require software to detect when FIPS is enabled and > actively disable features??? That's absurd. > > Can you point to another software package that does something like this? All the SSL libraries for a start (NSS, OpenSSL & GNUTLS). If we were using one of those for the VNC DES code we would be disabled. Regards, Daniel -- |: http://berrange.com -o- http://www.flickr.com/photos/dberrange/ :| |: http://libvirt.org -o- http://virt-manager.org :| |: http://autobuild.org -o- http://search.cpan.org/~danberr/ :| |: http://entangle-photo.org -o- http://live.gnome.org/gtk-vnc :|