Wednesday, March 01, 2023

Re: UPDATE: security/libident

On 2/27/23 06:30, Michael wrote:
> Hi Stuart,
>
> thanks for looking into this.
>
> On Mon, Feb 27, 2023 at 10:03:47AM +0000, Stuart Henderson wrote:
>> On 2023/02/26 21:37, Michael wrote:
>>>>
>>>> -# Public Domain
>>>> +MAINTAINER= Michael <michi+openbsd@dataswamp.org>
>>>> +
>>>> +# Public Domain with exceptions
>>>> +# See https://www.remlab.net/files/libident/COPYING
>>>> PERMIT_PACKAGE= Yes
>> "Public domain with exceptions" doesn't make sense.
>>
>> I would either stick with the previous (preferred), or say something
>> like "public domain source code, plus autoconf-related files".
>>
> I guess we might as well keep the previous statement as long as the URL
> is provided as a hint. That still seems relevant to me.
>
> Updated patch below.
>
>
> Index: Makefile
> ===================================================================
> RCS file: /cvs/ports/security/libident/Makefile,v
> retrieving revision 1.23
> diff -u -p -r1.23 Makefile
> --- Makefile 11 Mar 2022 19:53:31 -0000 1.23
> +++ Makefile 27 Feb 2023 11:25:39 -0000
> @@ -3,13 +3,16 @@ COMMENT= library to interface the ident
> SHARED_LIBS += ident 0.0 # 0.0
>
> DISTNAME= libident-0.32
> -CATEGORIES= devel net security
> -MASTER_SITES= http://www.remlab.net/files/libident/
> -REVISION= 1
> +CATEGORIES= security devel net
> +MASTER_SITES= https://www.remlab.net/files/libident/
> +REVISION= 2
>
> -HOMEPAGE= http://www.remlab.net/libident/
> +HOMEPAGE= https://www.remlab.net/libident/
> +
> +MAINTAINER= Michael <michi+openbsd@dataswamp.org>
>
> # Public Domain
> +# See https://www.remlab.net/files/libident/COPYING
> PERMIT_PACKAGE= Yes
>
> CONFIGURE_STYLE= gnu
> Index: pkg/DESCR
> ===================================================================
> RCS file: /cvs/ports/security/libident/pkg/DESCR,v
> retrieving revision 1.1.1.1
> diff -u -p -r1.1.1.1 DESCR
> --- pkg/DESCR 29 Apr 1998 05:22:54 -0000 1.1.1.1
> +++ pkg/DESCR 27 Feb 2023 11:25:39 -0000
> @@ -1,21 +1,5 @@
> -COPYRIGHT ISSUES:
> -
> - This version of 'libident' is hereby released into the
> - Public Domain. It may be distributed for a fee or without
> - a fee. We only ask you not to pretend you wrote it.
> -
> -If you make any changes, please send sources or a diff of it to
> -us (pen@lysator.liu.se or pell@lysator.liu.se), so we can keep
> -_one_ unified version of libident available...
> -
> -COMMENTS:
> -
> -This is the second stab at a small library to interface to the Ident
> -protocol server. Maybe this will work correctly on some machines.. :-)
> -
> -The ident-tester.c file is a small daemon (to be started from Inetd)
> -that does an ident lookup on you if you telnet into it. Can be used
> -to verify that your Ident server is working correctly.
> -
> -I'm currently running this "ident-tester" on port 114 at lysator.liu.se
> -(130.236.254.1) if you wish to test your server.
> +This is a library which provides a simple interface to the Ident
Replace 'this' by libident.
> +protocol on the client side. It is meant to be used by daemons to try
> +to authenticate users using the Ident protocol. For this to work,
> +users need to have an Ident server running on the system from which
> +they are connected.
>
Looks fine otherwise.

Would be good if someone could actually check if there's any security
issues with the library though but meh.

No comments:

Post a Comment