Bug#387448: empty entropy pool leads to DOS

2007-06-10 Thread Marc Haber
user [EMAIL PROTECTED] usertags #387448 close-20070831 thanks On Thu, Sep 14, 2006 at 02:57:38PM +0200, Yuri D'Elia wrote: I know this has been reported before to death [since gnutls is being used], but I will just add another twist, since I'm tired of rebuilding exim with OpenSSL manually.

Bug#387448: empty entropy pool leads to DOS

2006-10-07 Thread Marc Haber
On Mon, Sep 18, 2006 at 09:58:39PM +0200, Yuri D'Elia wrote: On 18 Sep 2006, at 12:53, Marc Haber wrote: I'm not native english speaker, so I did my best. Thanks. I will commit some changes to the docs, but am not going to make it sound like using the gnutls-bin/openssl based approach is

Bug#387448: empty entropy pool leads to DOS

2006-09-18 Thread Marc Haber
On Sun, Sep 17, 2006 at 05:26:04PM +0200, Yuri D'Elia wrote: On 16 Sep 2006, at 23:48, Marc Haber wrote: Upstream quickly tagged as this as can't be done: I'd say this simply wrong. Everything can be done, provided enough time is given. Do you really think that it should be exim's job to

Bug#387448: empty entropy pool leads to DOS

2006-09-18 Thread Marc Haber
On Sun, Sep 17, 2006 at 06:14:07PM +0200, Andreas Metzler wrote: Thanks, I have commited the fallback-to-openssl stuff to SVN (I have changed preferences to still prefer gnutls, though). May I ask why you hae gnutls preferred? openssl is more economically handling entropy, and if both are

Bug#387448: empty entropy pool leads to DOS

2006-09-18 Thread Andreas Metzler
On 2006-09-18 Marc Haber [EMAIL PROTECTED] wrote: [...] Thanks. I will commit some changes to the docs, but am not going to make it sound like using the gnutls-bin/openssl based approach is mandatory. I think both of us agree that generating the parameters offline is indeed superior and there

Bug#387448: empty entropy pool leads to DOS

2006-09-18 Thread Andreas Metzler
On 2006-09-18 Marc Haber [EMAIL PROTECTED] wrote: On Sun, Sep 17, 2006 at 06:14:07PM +0200, Andreas Metzler wrote: Thanks, I have commited the fallback-to-openssl stuff to SVN (I have changed preferences to still prefer gnutls, though). May I ask why you hae gnutls preferred? Linking

Bug#387448: empty entropy pool leads to DOS

2006-09-18 Thread Yuri D'Elia
On 18 Sep 2006, at 12:53, Marc Haber wrote: I'm not native english speaker, so I did my best. Thanks. I will commit some changes to the docs, but am not going to make it sound like using the gnutls-bin/openssl based approach is mandatory. Of course, but please emphasize that it's

Bug#387448: empty entropy pool leads to DOS

2006-09-17 Thread Yuri D'Elia
On 16 Sep 2006, at 23:48, Marc Haber wrote: Upstream quickly tagged as this as can't be done: I'd say this simply wrong. Everything can be done, provided enough time is given. Do you really think that it should be exim's job to re-implement a good part of a TLS library? Please take this up

Bug#387448: empty entropy pool leads to DOS

2006-09-17 Thread Andreas Metzler
On 2006-09-17 Yuri D'Elia [EMAIL PROTECTED] wrote: [...] Ok. If you plan to incorporate the use of openssl in cron.daily/exim4- base, change this to a gnutls-bin | openssl then. Patches attached. Thanks, I have commited the fallback-to-openssl stuff to SVN (I have changed preferences to

Bug#387448: empty entropy pool leads to DOS

2006-09-16 Thread Andreas Metzler
On 2006-09-14 Yuri D'Elia [EMAIL PROTECTED] wrote: Package: exim4 Version: 4.63-3 Severity: important I know this has been reported before to death [since gnutls is being used], but I will just add another twist, since I'm tired of rebuilding exim with OpenSSL manually. GnuTLS drains the

Bug#387448: empty entropy pool leads to DOS

2006-09-16 Thread Yuri D'Elia
On 16 Sep 2006, at 15:39, Andreas Metzler wrote: Hello, Do you have gnutls-bin installed at all? The only thing causing exim to block on STARTTLS is key and dh-param generation. Both is done offline (/etc/cron.daily/exim4-base invoking /usr/share/exim4/exim4_refresh_gnutls-params which uses

Bug#387448: empty entropy pool leads to DOS

2006-09-16 Thread Marc Haber
On Sat, Sep 16, 2006 at 06:09:35PM +0200, Yuri D'Elia wrote: On 16 Sep 2006, at 15:39, Andreas Metzler wrote: The only thing causing exim to block on STARTTLS is key and dh-param generation. Both is done offline (/etc/cron.daily/exim4-base invoking /usr/share/exim4/exim4_refresh_gnutls-params

Bug#387448: empty entropy pool leads to DOS

2006-09-14 Thread Yuri D'Elia
Package: exim4 Version: 4.63-3 Severity: important I know this has been reported before to death [since gnutls is being used], but I will just add another twist, since I'm tired of rebuilding exim with OpenSSL manually. GnuTLS drains the entropy pool much more quickly than OpenSSL. On server

Bug#387448: empty entropy pool leads to DOS

2006-09-14 Thread Marc Haber
reassign #387448 exim4-daemon-light,exim4-daemon-heavy tags #387448 confirmed upstream help user [EMAIL PROTECTED] usertags #387448 gnutls forwarded #387448 http://www.exim.org/bugzilla/show_bug.cgi?id=390 thanks On Thu, Sep 14, 2006 at 02:57:38PM +0200, Yuri D'Elia wrote: I know this has been

Bug#387448: empty entropy pool leads to DOS

2006-09-14 Thread Marc Haber
tags #387448 wontfix thanks Upstream has indicated that this is impossible to fix in exim. Please look in upstream's bugzilla, verify their arguments and take up the argument with them. Greetings Marc -- - Marc Haber