Gentoo Archives: gentoo-dev

From: "Robin H. Johnson" <robbat2@g.o>
To: Petre Rodan <petre.rodan@××××××××××××.com>
Cc: gentoo-dev@g.o, "Robin H. Johnson" <robbat2@g.o>
Subject: Re: [gentoo-dev] qmail testing again
Date: Wed, 03 Sep 2003 08:29:08
Message-Id: 20030903092915.GA5985@curie-int.orbis-terrarum.net
In Reply to: Re: [gentoo-dev] qmail testing again by Petre Rodan
1 On Wed, Sep 03, 2003 at 09:55:36AM +0300, Petre Rodan wrote:
2 > I'm sorry to disturb you, but I couldn't help noticing that currently
3 > there are 15 patches to qmail, and this number has the tendency to
4 > rise with every ebuild.
5 I expect it to be around 20 when I'm done with the ebuild.
6
7 > I feel that DJ Bernstein did a great job creating the world's safest
8 > MTA. This is one of the main reasons sysadmins use it. My point is
9 > that even if there are reasons for upgrading the product (to add new
10 > features and such) the issues with not doing it are considerable and
11 > will likely out-weigh them.
12 DJB himself has mentioned that he uses some of the patches in some
13 cases, and just for the most part does not have time to contribute to
14 maintaining qmail anymore.
15
16 I have personally considered forking qmail in the past, simply to
17 go thru a validation of the security of the patches and distribute them
18 officially integrated. I simply do not have enough time to attempt this
19 until I am finished university, unless somebody is willing to sponsor me
20 to do it as some part-time work (I presently work part time at the
21 university to cover some of my tuition).
22
23 > The commotion generated by smtp-auth patch is an example.
24 SMTP AUTH (both directions) and STARTTLS both require more setup than
25 just emerging the package. If you don't set them up, then qmail behaves
26 in a functionally identical way to how it did before.
27
28 The security hole (bugtraq id 8196) is caused solely by
29 misconfiguration. I've put code into place (not yet committed to CVS) in
30 the startup scripts for qmail-smtpd that will detect the possible
31 misconfiguration and error out.
32
33 > Now please don't get me wrong, I appreciate your work, I simply fell
34 > in love with Gentoo but I think that those who would like to emerge
35 > qmail should have the choice of selecting the exact features that can
36 > make them happy. Simply masking versions doesn't sound to good, maybe
37 > some USE switches would ease the way. I'm wondering maybe
38 > qmail-1.03-x.ebuild can be made to inherit some patch related switches
39 > from a file that is system-specific.
40 I will definetly look at an optional flag to disable the majority of the
41 patches that could have security issues anyway.
42
43 --
44 Robin Hugh Johnson
45 E-Mail : robbat2@××××××××××××××.net
46 Home Page : http://www.orbis-terrarum.net/?l=people.robbat2
47 ICQ# : 30269588 or 41961639
48 GnuPG FP : 11AC BA4F 4778 E3F6 E4ED F38E B27B 944E 3488 4E85