Gentoo Archives: gentoo-user

From: Rich Freeman <rich0@g.o>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] is the X11 Security extension required for xauth?
Date: Mon, 23 Dec 2019 02:45:11
Message-Id: CAGfcS_nRToj_SKyTka7ubvdgfSmUHT_+-6_cX0dRpDdNdii1Wg@mail.gmail.com
In Reply to: Re: [gentoo-user] is the X11 Security extension required for xauth? by Adam Carter
1 On Sun, Dec 22, 2019 at 8:27 PM Adam Carter <adamcarter3@×××××.com> wrote:
2 >
3 > But -X produces
4 > "Warning: untrusted X11 forwarding setup failed: xauth key data not generated"
5 >
6 > but the server has an ~/.Xauthority file, which oddly gets created by an ssh -Y session....
7
8 -Y still uses an .Xauthority so that isn't a surprise.
9 MIT-MAGIC-COOKIE security is used by both -X and -Y, which is what
10 this file is used for.
11
12 The difference between -X and -Y is in providing a layer of security
13 so that remote clients can't play games like keyboard sniffing with
14 your local X server.
15
16 Whether this ought to be a default was apparently a debate over a
17 decade ago, when the USE flag was at least added to make it possible.
18 I haven't used it in a while though so I can't vouch for whether there
19 are any issues with -X when the USE flag is enabled to build the
20 extension.
21
22 https://bugs.gentoo.org/237778
23
24 --
25 Rich

Replies

Subject Author
Re: [gentoo-user] is the X11 Security extension required for xauth? Adam Carter <adamcarter3@×××××.com>