SRP patches (was: Re: SRP unencumbered license statement)

Tom Wu tom at arcot.com
Mon May 7 16:14:31 EST 2001


Tom Holroyd wrote:
> 
> On Wed, 2 May 2001, Tom Wu wrote:
> 
> > The patches look really good.  Everything built right out of the box on
> > Linux (glibc 2.1) and FreeBSD 4.2.  The only hiccup was the strict
> > permissions checking on /etc/tpasswd.conf, but that was easily
> > resolved.  Interoperation with EPS stuff looks clean.
> 
> Yes, currently the patch uses strict mode checking; after the patch is
> integrated it could be changed to use the StrictModes mechanism that's
> already in OpenSSH.  What was your specific problem?  .conf file not owned
> by root?  That could be relaxed by the above mechanism, I think.  The
> permission checking on the verifier files should remain strict, though,
> unless there is some issue on non-unix OSes that I'm not aware of.

My .conf file was group-writable.  Since there's no good reason for it
to be such, I changed its permissions.  That seemed to satisfy OpenSSH.

Tom
-- 
Tom Wu
Principal Software Engineer
Arcot Systems
(408) 969-6124



More information about the openssh-unix-dev mailing list