1 |
On Wed, Sep 03, 2003 at 09:55:36AM +0300, Petre Rodan wrote: |
2 |
> I'm sorry to disturb you, but I couldn't help noticing that currently |
3 |
> there are 15 patches to qmail, and this number has the tendency to |
4 |
> rise with every ebuild. |
5 |
I expect it to be around 20 when I'm done with the ebuild. |
6 |
|
7 |
> I feel that DJ Bernstein did a great job creating the world's safest |
8 |
> MTA. This is one of the main reasons sysadmins use it. My point is |
9 |
> that even if there are reasons for upgrading the product (to add new |
10 |
> features and such) the issues with not doing it are considerable and |
11 |
> will likely out-weigh them. |
12 |
DJB himself has mentioned that he uses some of the patches in some |
13 |
cases, and just for the most part does not have time to contribute to |
14 |
maintaining qmail anymore. |
15 |
|
16 |
I have personally considered forking qmail in the past, simply to |
17 |
go thru a validation of the security of the patches and distribute them |
18 |
officially integrated. I simply do not have enough time to attempt this |
19 |
until I am finished university, unless somebody is willing to sponsor me |
20 |
to do it as some part-time work (I presently work part time at the |
21 |
university to cover some of my tuition). |
22 |
|
23 |
> The commotion generated by smtp-auth patch is an example. |
24 |
SMTP AUTH (both directions) and STARTTLS both require more setup than |
25 |
just emerging the package. If you don't set them up, then qmail behaves |
26 |
in a functionally identical way to how it did before. |
27 |
|
28 |
The security hole (bugtraq id 8196) is caused solely by |
29 |
misconfiguration. I've put code into place (not yet committed to CVS) in |
30 |
the startup scripts for qmail-smtpd that will detect the possible |
31 |
misconfiguration and error out. |
32 |
|
33 |
> Now please don't get me wrong, I appreciate your work, I simply fell |
34 |
> in love with Gentoo but I think that those who would like to emerge |
35 |
> qmail should have the choice of selecting the exact features that can |
36 |
> make them happy. Simply masking versions doesn't sound to good, maybe |
37 |
> some USE switches would ease the way. I'm wondering maybe |
38 |
> qmail-1.03-x.ebuild can be made to inherit some patch related switches |
39 |
> from a file that is system-specific. |
40 |
I will definetly look at an optional flag to disable the majority of the |
41 |
patches that could have security issues anyway. |
42 |
|
43 |
-- |
44 |
Robin Hugh Johnson |
45 |
E-Mail : robbat2@××××××××××××××.net |
46 |
Home Page : http://www.orbis-terrarum.net/?l=people.robbat2 |
47 |
ICQ# : 30269588 or 41961639 |
48 |
GnuPG FP : 11AC BA4F 4778 E3F6 E4ED F38E B27B 944E 3488 4E85 |