228 karma · joined June 10, 2010
https://www.cia.gov/library/readingroom/document/cia-rdp85-0...
https://github.com/nuxi/acme-tiny
For now I've just done enough to get a cert for a mail server.
I love it!
https://sourceware.org/bugzilla/show_bug.cgi?id=6527
Basically for many years now glibc has been knowingly doing the wrong thing just to keep malloc_set_state/malloc_get_state working. Which as far as anyone knows, is used only by emacs. Keeping this interface alive for the sole benefit of an emacs optimization when it is blocking the fixes for fairly serious bugs is a pretty big bar to meet for justification.
In the end this is largely a non-issue as an Emacs developer noted that their configure script probes for the special glibc malloc API and if it doesn't exist then emacs will use its own malloc implementation. The conclusion is that once the glibc devs get their changes up, everyone can meet up again to make sure existing emacs binaries still run and that the API detection in the emacs configure script works right.
So props to Paul Eggert for being the only sane man in the room and pointing out that the drama was all for nothing.
This is a fact often forgotten when projects switch to github and just start using the automated release tarballs github will make from the repo.
I would call this a bug fix since someone has found what is probably an unintended behavior in the cubic algorithm. The cubic algorithm itself though would be a feature improving on the original tcp algorithm (nagle, if I remember right)
Its not very useful if other machines can't talk to it.
Keep in mind, the decision to do this in Windows happened back when home computers were on dialup. (Even RFC 1918 and NAT were young at the time) The real question is why didn't Windows have a firewall that blocked it by default and the answer is that it has.... since XP SP2 was released in 2004.
I finally found the Mozilla bug entry for this, they've known of it since 2010 when they raised the minimums to 512-bit DH groups.
What they are refering to is the Key Exchange method named "diffie-hellman-group1-sha1" which uses a 1024-bit DH group. You can disable this with use of the KexAlgorithms parameter. Starting with OpenSSH 6.6 it is already disabled on the server side, but still allowed with the client. There are severe interoperability problems with embedded devices if disabled.
The real reason to disable them is because of how slow they are. The only thing that is gonna actually use 3DES for TLS is MSIE on XP, its the last remaining secure cipher.
This is a key you get re-signed every 1-3 years. You don't need it to last 10 years, you need it to last maybe a year longer than your SSL cert is actually good for. (Assuming your site is setup to have all the browsers do PFS)
It could be a student in the dorms who discovered metasploit though. Or someone in the computer lab who has a tool that doesn't need root. (or who rooted the lab computer)
PS: you're my hero for making this page to begin with. I often direct people to it who ask about SSL settings. Even if I have my own tweaks to the list. Its useful for more than just webservers too.
Bonus trivia: ssh-dss (SSH DSA keys) has vaguely similar problem, which they considered fixing but decided instead to simply not repeat the mistakes when writing the SSH ECDSA spec. This is why ssh-dss keys are effectively limited to 1024-bit.
if kernel_version.startswith('2.4.'): DO_A else: DO_B
On the other hand, if you check for 2.6 instead of checking for 2.4... Well when it encounters 3.0 the code falls back to 2.4 behavior.
if kernel_version.startswith('2.6.'): DO_B else: DO_A
Sadly a number of binary only RAID tools don't really get updated much and have these problems. There is a program in util-linux named uname26 that you can run these tools under which gives them the 2.6.40+ version numbers.
This is just one of those tricks operating systems have to resort to from time to time, its like how Microsoft is skipping Windows 9 because of how many programs execute version.startswith('Windows 9') and assuming that means Win95/Win98.
Congress and the President have now exempted unlocking with a new law, which is exactly what the librarian of congress said should be done if they want to create permanent public policy for that exemption. So they did not overtune a decision of his, he was in support of this, he just insisted it be done properly.