OpenSSH 8.7p1 in rawhide

2021-09-29 Thread Dmitry Belyavskiy
a security release) are expected to use SFTP protocol by default. This behavior (SFTP as a default transfer protocol for scp utility) is backported to rawhide. The same approach is planned for RHEL 9 GA, Please let me know if you have any questions/problems. Many thanks in advance! -- Dmitry

Re: OpenSSH 8.7p1 in rawhide

2021-10-04 Thread Dmitry Belyavskiy
Dear Richard, On Mon, Oct 4, 2021 at 10:23 AM Richard W.M. Jones wrote: > On Wed, Sep 29, 2021 at 04:48:43PM +0200, Dmitry Belyavskiy wrote: > > Dear colleagues, > > > > I recently added OpenSSH 8.7p1 to rawhide. > > This version includes implementation of th

Re: openssl maintainerships?

2022-03-16 Thread Dmitry Belyavskiy
gain > higher than in Fedora. > > -- > Miro Hrončok > -- > Phone: +420777974800 > IRC: mhroncok > > -- Dmitry Belyavskiy ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to devel-le...@lists.f

Re: openssl maintainerships?

2022-03-16 Thread Dmitry Belyavskiy
wrote: > On Wed, Mar 16, 2022 at 10:04 AM Dmitry Belyavskiy > wrote: > > > > Dear Peter, dear Miro, > > > > The immediate reason for the lack of update of OpenSSL in Fedora was a > problem with kTLS in avmv7. > > We tried to get some feedback but didn't

Re: Landing a larger-than-release change (distrusting SHA-1 signatures)

2022-03-09 Thread Dmitry Belyavskiy
project.org/wiki/Mailing_list_guidelines > List Archives: > https://lists.fedoraproject.org/archives/list/devel@lists.fedoraproject.org > Do not reply to spam on the list, report it: > https://pagure.io/fedora-infrastructure > -- Dmitry Belyavskiy __

Re: F37 Change: Curl-minimal as default (System-Wide Change proposal)

2022-02-23 Thread Dmitry Belyavskiy
n in an update of a stable Fedora release. So I do > not think we need to enable it proactively. > > Being from Russia and having several years of interacting with Universal Acceptance, I'd say IDN is a must nowadays. -- Dmitry Belyavskiy _

Re: kTLS related failures on rawhide in OpenSSL 3.0.1

2022-01-20 Thread Dmitry Belyavskiy
On Thu, Jan 20, 2022 at 6:49 PM Richard W.M. Jones wrote: > On Wed, Jan 19, 2022 at 01:30:54PM +0100, Dmitry Belyavskiy wrote: > > On Wed, Jan 19, 2022 at 1:24 PM Sahana Prasad wrote: > > > > Hello everyone, > > > > Could anyone kindly help wi

Re: kTLS related failures on rawhide in OpenSSL 3.0.1

2022-01-19 Thread Dmitry Belyavskiy
hives: > https://lists.fedoraproject.org/archives/list/devel@lists.fedoraproject.org > Do not reply to spam on the list, report it: > https://pagure.io/fedora-infrastructure > -- Dmitry Belyavskiy ___ devel mailing list -- deve

Re: status openssl1.1

2023-10-16 Thread Dmitry Belyavskiy
Dear Peter, On Mon, Oct 16, 2023 at 1:43 PM Peter Robinson wrote: > > On Mon, Oct 16, 2023 at 10:05 AM Dmitry Belyavskiy > wrote: > > > > On Mon, Oct 16, 2023 at 10:21 AM Petr Pisar wrote: > > > > > > V Mon, Oct 16, 2023 at 08:55:12AM +0200,

Re: status openssl1.1

2023-10-18 Thread Dmitry Belyavskiy
Dear Miro, On Tue, Oct 17, 2023 at 10:33 PM Miro Hrončok wrote: > > On 16. 10. 23 14:19, Dmitry Belyavskiy wrote: > >> Why is it too late for F-40? Do you mean F-39? > > > > Thanks! > > https://fedoraproject.org/wiki/Changes/RemoveOpensslCompat > > Could

Re: status openssl1.1

2023-10-16 Thread Dmitry Belyavskiy
n impact of the > removal are these 3 components: > > gloo-0.5.0^git20230824.01a0c81-6.fc40.src.rpm > opensmtpd-6.8.0p2-12.fc39.src.rpm > python3.6-3.6.15-20.fc39.src.rpm I'm afraid it's too late for removing the compat package in F40. If not, I can raise the change proposal, otherwi

Re: Dropping of sshd.socket unit

2023-08-15 Thread Dmitry Belyavskiy
an sshd server, configured using socket activation can cause the socket to be disabled permanently ("sshd.socket: Trigger limit hit, refusing further activation."). On Mon, Aug 7, 2023 at 11:48 AM Lennart Poettering wrote: > > On Do, 03.08.23 11:29, Dmitry Belyavskiy (dbel

Re: Self Introduction: Pavel Odintsov

2022-05-28 Thread Dmitry Belyavskiy
ist Archives: > https://lists.fedoraproject.org/archives/list/devel@lists.fedoraproject.org > Do not reply to spam on the list, report it: > https://pagure.io/fedora-infrastructure > -- Dmitry Belyavskiy ___ devel mailing list -- devel@lists.

Can't login into Wiki

2022-06-22 Thread Dmitry Belyavskiy
ystem-wide proposals deadline? Many thanks in advance! -- Dmitry Belyavskiy ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to devel-le...@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-

Re: F37 proposal: Deprecate openssl1.1 package (System-Wide Change)

2022-06-29 Thread Dmitry Belyavskiy
ct.org/wiki/Mailing_list_guidelines > List Archives: > https://lists.fedoraproject.org/archives/list/devel@lists.fedoraproject.org > Do not reply to spam on the list, report it: > https://pagure.io/fedora-infrastructure > -- Dmitry Belyavskiy _

Re: F37 proposal: Deprecate openssl1.1 package (System-Wide Change)

2022-06-29 Thread Dmitry Belyavskiy
Dear Miro, On Wed, Jun 29, 2022 at 5:27 PM Miro Hrončok wrote: > On 29. 06. 22 17:11, Dmitry Belyavskiy wrote: > > Dear colleagues, > > > > If I correctly follow the discussion, the biggest show-stopper is Python > 2.*, > > which has some incomplete patches to

Re: F37 proposal: Deprecate openssl1.1 package (System-Wide Change)

2022-06-24 Thread Dmitry Belyavskiy
ovide strong enough motivation to get rid of the deprecating packages. -- Dmitry Belyavskiy ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to devel-le...@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fe

Re: F37 proposal: Deprecate openssl1.1 package (System-Wide Change)

2022-06-24 Thread Dmitry Belyavskiy
/cpython-2.7/Lib/ssl.py", line 828, in do_handshake > self._sslobj.do_handshake() > SSLError: [SSL: TLSV1_ALERT_INTERNAL_ERROR] tlsv1 alert internal error > (_ssl.c:727) > > == > ERROR: test_starttls (test.te

Re: F37 proposal: Deprecate openssl1.1 package (System-Wide Change)

2022-06-24 Thread Dmitry Belyavskiy
On Fri, Jun 24, 2022 at 11:20 AM Daniel P. Berrangé wrote: > On Fri, Jun 24, 2022 at 11:13:13AM +0200, Dmitry Belyavskiy wrote: > > On Wed, Jun 22, 2022 at 11:02 PM Miro Hrončok > wrote: > > > > > On 22. 06. 22 21:05, Vipul Siddharth wrote: > > > > We ar

Re: help needed on AskFedora: OpenSSLv3 error when connecting to Eduroam

2022-06-30 Thread Dmitry Belyavskiy
rchives/list/devel@lists.fedoraproject.org > Do not reply to spam on the list, report it: > https://pagure.io/fedora-infrastructure > -- Dmitry Belyavskiy ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to deve

Heads-up: OpenSSL sync with RHEL

2022-09-05 Thread Dmitry Belyavskiy
in a similar way as it is done in RHEL. -- Dmitry Belyavskiy ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to devel-le...@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project

Re: Karma for OpenSSL needed

2022-11-01 Thread Dmitry Belyavskiy
e note rebasing to 3.0.7 or generally updating > in Fedora with 3.x? It looks like 3.0.6 had CVE-2022-3358 which hasn't > been addressed because we're still on .5 > Applying a separate patch takes several minutes, and rebasing is some process, usually much longer. The rebase is going to ha

Karma for OpenSSL needed

2022-11-01 Thread Dmitry Belyavskiy
Dear colleagues, I've just pushed the updates for OpenSSL fixing 2 CVEs evaluated as HIGH. Could you please check the freshly pushed builds to get necessary karma ASAP? Many thanks! -- Dmitry Belyavskiy ___ devel mailing list -- devel

Heads-up: new OpenSSL build changes

2023-01-13 Thread Dmitry Belyavskiy
PKCS#1 v1.5 decryption. This is a general protection against issues like CVE-2020-25659 and CVE-2020-25657. This protection can be disabled by calling `EVP_PKEY_CTX_ctrl_str(ctx, "rsa_pkcs1_implicit_rejection". "0")` in the RSA decryption context. -

Re: OpenSSH: hardening hostkeys permissions

2022-12-08 Thread Dmitry Belyavskiy
Dear Daniel, Thanks for your feedback! On Wed, Dec 7, 2022 at 2:55 PM Daniel P. Berrangé wrote: > On Wed, Dec 07, 2022 at 01:48:48PM +0100, Dmitry Belyavskiy wrote: > > The problem we expect is that after reverting the patch we can lose the > > remote access to the hos

Re: OpenSSH: hardening hostkeys permissions

2022-12-08 Thread Dmitry Belyavskiy
On Thu, Dec 8, 2022 at 3:51 PM Daniel P. Berrangé wrote: > On Thu, Dec 08, 2022 at 03:41:32PM +0100, Dmitry Belyavskiy wrote: > > Dear Daniel, > > Thanks for your feedback! > > > > On Wed, Dec 7, 2022 at 2:55 PM Daniel P. Berrangé > > wrote: > > > &g

OpenSSH: hardening hostkeys permissions

2022-12-07 Thread Dmitry Belyavskiy
://src.fedoraproject.org/rpms/openssh/pull-request/37 A separate question is whether we want to publish this announcement as a Fedora change and at what level. For me it looks like a self-contained change. -- Dmitry Belyavskiy ___ devel mailing list

Re: openldap: gdb: symbol lookup error: /lib64/libldap.so.2: undefined symbol: EVP_md2, version OPENSSL_3.0.0

2023-03-28 Thread Dmitry Belyavskiy
Which is better to fix the gdb or openldap? > > Jun > > On Mon, Mar 27, 2023 at 5:45 PM Dmitry Belyavskiy wrote: > > > > Dear Jan, > > > > Yes. gdb expects system openssl (providing this function) > > > > To workaround it, you have to provide the LD_SET_

Re: openldap: gdb: symbol lookup error: /lib64/libldap.so.2: undefined symbol: EVP_md2, version OPENSSL_3.0.0

2023-03-27 Thread Dmitry Belyavskiy
aproject.org > Fedora Code of Conduct: > https://docs.fedoraproject.org/en-US/project/code-of-conduct/ > List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines > List Archives: > https://lists.fedoraproject.org/archives/list/devel@lists.fedoraproject.org > Do not

Re: Heads-up: OpenSSL update

2023-02-09 Thread Dmitry Belyavskiy
Dear Paul On Thu, Feb 9, 2023 at 6:56 PM Paul Wouters wrote: > > On Thu, 9 Feb 2023, Dmitry Belyavskiy wrote: > > > I've just pushed updates of OpenSSL to the 3.0.8 version to f36/37. > > I will also push to f38 and rawhide later today. > > Why is f36/f37 the

Heads-up: OpenSSL update

2023-02-09 Thread Dmitry Belyavskiy
be rolled up earlier. Many thanks in advance! -- Dmitry Belyavskiy ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to devel-le...@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project

Re: Heads-up: OpenSSL update

2023-02-10 Thread Dmitry Belyavskiy
Alexandre Salim wrote: > > Hi Dmitry, > > On Thu, 2023-02-09 at 18:02 +0100, Dmitry Belyavskiy wrote: > > Dear colleagues, > > > > I've just pushed updates of OpenSSL to the 3.0.8 version to f36/37. > > I will also push to f38 and rawhide later today. > >

Adding liboqs to Rawhide

2023-02-13 Thread Dmitry Belyavskiy
/40b01fdbb270f8614fde30e65d30e9da18c02393/src/common/rand/rand_nist.c#L1-L15 What is the proper line for the spec file and what are my next steps to evaluate the licenses, if necessary? Many thanks in advance! -- Dmitry Belyavskiy ___ devel mailing list

Re: Heads-up: OpenSSL update

2023-02-10 Thread Dmitry Belyavskiy
Dear Michel, On Fri, Feb 10, 2023 at 7:06 PM Michel Alexandre Salim wrote: > > Dear Dmitry, > > On Fri, 2023-02-10 at 09:55 +0100, Dmitry Belyavskiy wrote: > > Dear Michel, > > > > In RHEL/CentOS we currently provide a double versioning for > > OPENSS

Heads-up: post-quantum libs landed in Fedora rawhide

2023-07-19 Thread Dmitry Belyavskiy
or at least raise bugs upstream. We also expect that there are both applications and protocol specifications that are not capable of dealing with the keys that are neither RSA nor EC/EdDDSA and also would like the issues to be raised. -- Dmitry Belyavskiy

Re: Managing multiple cross-dependent patches

2023-06-02 Thread Dmitry Belyavskiy
Dear Chris, On Fri, Jun 2, 2023 at 4:42 PM Chris Adams wrote: > > Once upon a time, Dmitry Belyavskiy said: > > I maintain OpenSSH that has a lot of heavy-interfering downstream > > patches. I’d like to reduce the burden of rebase by combining some of > > them. > &g

Re: Managing multiple cross-dependent patches

2023-06-02 Thread Dmitry Belyavskiy
Dear Daniel, On Fri, Jun 2, 2023 at 4:57 PM Daniel P. Berrangé wrote: > > On Fri, Jun 02, 2023 at 04:27:37PM +0200, Dmitry Belyavskiy wrote: > > Dear colleagues, > > > > I maintain OpenSSH that has a lot of heavy-interfering downstream > > patches. I’d like

Managing multiple cross-dependent patches

2023-06-02 Thread Dmitry Belyavskiy
? I’m aware of quilt and git-absorb but it looks like they don’t help me much. Many thanks! -- Dmitry Belyavskiy ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to devel-le...@lists.fedoraproject.org Fedora Code

Dropping of sshd.socket unit

2023-08-03 Thread Dmitry Belyavskiy
. -- Dmitry Belyavskiy ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to devel-le...@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https

Re: Changes to build environment

2023-06-22 Thread Dmitry Belyavskiy
elines > List Archives: > https://lists.fedoraproject.org/archives/list/devel@lists.fedoraproject.org > Do not reply to spam, report it: > https://pagure.io/fedora-infrastructure/new_issue -- Dmitry Belyavskiy ___ de

How to get a rawhide i686 VM?

2023-05-15 Thread Dmitry Belyavskiy
choice. Any advice would be appreciated! -- Dmitry Belyavskiy ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to devel-le...@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project

Re: How to get a rawhide i686 VM?

2023-05-15 Thread Dmitry Belyavskiy
Dear Peter, On Mon, May 15, 2023 at 1:06 PM Peter Robinson wrote: > > On Mon, May 15, 2023 at 11:39 AM Dmitry Belyavskiy > wrote: > > > > Dear colleagues, > > > > What is the simplest way to get a rawhide i686 VM? I came across a > > nasty architecture-s

Re: OpenSSL 3.2.1 available in rawhide

2024-02-09 Thread Dmitry Belyavskiy
taskID=113198856 > > The tests pass locally in mock with openssl 3.1.4. I can imagine the situation where upgrading to 3.2 could cause this failure but the logs are too vague. Could you please provide more details (e.g. openssl low-level diagnostics) or even better a minimal repro

Re: F41 Change Proposal: Disable openSSL Engine Support (system-wide)

2024-03-21 Thread Dmitry Belyavskiy
Dear Jun, On Thu, Mar 21, 2024 at 11:04 AM Jun Aruga (he / him) wrote: > On Wed, Mar 20, 2024 at 2:36 PM Dmitry Belyavskiy > wrote: > > > ... > >> > == Detailed Description == > >> > We are going to build OpenSSL without engine support.

Re: F41 Change Proposal: Disable openSSL Engine Support (system-wide)

2024-03-21 Thread Dmitry Belyavskiy
Dear Jun, On Thu, Mar 21, 2024 at 2:29 PM Jun Aruga (he / him) wrote: > On Thu, Mar 21, 2024 at 12:16 PM Dmitry Belyavskiy > wrote: > > > > Dear Jun, > > > > > > > > On Thu, Mar 21, 2024 at 11:04 AM Jun Aruga (he / him) > wrote: > >>

Re: F41 Change Proposal: Disable openSSL Engine Support (system-wide)

2024-03-21 Thread Dmitry Belyavskiy
Dear Zbyszek, On Thu, Mar 21, 2024 at 12:41 PM Zbigniew Jędrzejewski-Szmek < zbys...@in.waw.pl> wrote: > On Thu, Mar 21, 2024 at 12:15:43PM +0100, Dmitry Belyavskiy wrote: > > > > Hi Dmitry, > > > Could you provide the upstream OpenSSL project's issue ticket(s)

Re: F41 Change Proposal: Disable openSSL Engine Support (system-wide)

2024-03-20 Thread Dmitry Belyavskiy
> > > == Summary == > > We disable support of engines in OpenSSL > > > > == Owner == > > * Name: [[User:Dbelyavs| Dmitry Belyavskiy]] > > * Email: dbely...@redhat.com > > > > == Detailed Description == > > We are going to build OpenSSL wi

Re: F41 Change Proposal: Disable openSSL Engine Support (system-wide)

2024-03-20 Thread Dmitry Belyavskiy
= Summary == > > We disable support of engines in OpenSSL > > > > == Owner == > > * Name: [[User:Dbelyavs| Dmitry Belyavskiy]] > > * Email: dbely...@redhat.com > > > > == Detailed Description == > > We are going to build OpenSSL without engine support.

Re: F41 Change Proposal: Disable openSSL Engine Support (system-wide)

2024-03-20 Thread Dmitry Belyavskiy
Dear Fabio, On Wed, Mar 20, 2024 at 3:18 PM Fabio Valentini wrote: > On Wed, Mar 20, 2024 at 3:06 PM Daniel P. Berrangé > wrote: > > > > On Wed, Mar 20, 2024 at 02:35:21PM +0100, Dmitry Belyavskiy wrote: > > (...) > > > > As I understand, upstream is goi

Re: F41 Change Proposal: Disable openSSL Engine Support (system-wide)

2024-03-20 Thread Dmitry Belyavskiy
Dear Daniel, On Wed, Mar 20, 2024 at 3:06 PM Daniel P. Berrangé wrote: > On Wed, Mar 20, 2024 at 02:35:21PM +0100, Dmitry Belyavskiy wrote: > > Dear Daniel, > > > > On Wed, Mar 20, 2024 at 1:44 PM Daniel P. Berrangé > > wrote: > > > > > On Fri, Mar 0

Re: xz backdoor

2024-03-29 Thread Dmitry Belyavskiy
raproject.org > To unsubscribe send an email to devel-le...@lists.fedoraproject.org > Fedora Code of Conduct: > https://docs.fedoraproject.org/en-US/project/code-of-conduct/ > List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines > List Archives: > https:/

Re: Three steps we could take to make supply chain attacks a bit harder

2024-03-30 Thread Dmitry Belyavskiy
is completely wrong. Having, say, a 30+ downstream patches and declining to run upstream tests is the most effective way to break a gazillion use-cases. But the fuzzing tests look quite dangerous to me here and now. No one can review a corpse of binary files :( -- Dmitry Belyavskiy

Re: Three steps we could take to make supply chain attacks a bit harder

2024-03-30 Thread Dmitry Belyavskiy
of the other available approaches. Arch Linux is also systemd-based > nowadays, but still does not link OpenSSH against libsystemd. We have an upstream-adjusted version of this patch, see https://bugzilla.mindrot.org/show_bug.cgi?id=2641 I'm OK to bring the updated version of th

Re: F41 Change Proposal: OpenSSL Deprecate Engine (system-wide)

2024-04-03 Thread Dmitry Belyavskiy
Dear Zbyszek, Thanks, I updated the Wiki page correspondingly. On Wed, Apr 3, 2024 at 5:56 PM Zbigniew Jędrzejewski-Szmek < zbys...@in.waw.pl> wrote: > [Replying to two mails at once to conserve some electrons.] > > On Tue, Apr 02, 2024 at 04:03:31PM +0200, Dmitry Belyavskiy wr

Re: F41 Change Proposal: OpenSSL Deprecate Engine (system-wide)

2024-04-03 Thread Dmitry Belyavskiy
reventing "providers" from working in all use cases in which > "engines" work) is NOT reasonable. > You are 100% correct. That's why disabling this API is not on the table for now anymore. -- Dmitry Belyavskiy -- ___ devel mai

Re: F41 Change Proposal: OpenSSL Deprecate Engine (system-wide)

2024-04-02 Thread Dmitry Belyavskiy
aware of any Yubikey issues, BTW. Third-party engines may be a problem but as we don't break ABI, it's not a problem of the moment. -- Dmitry Belyavskiy -- ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to deve

Re: F41 Change Proposal: OpenSSL Deprecate Engine (system-wide)

2024-04-02 Thread Dmitry Belyavskiy
Dear Gary, On Tue, Apr 2, 2024 at 5:39 PM Gary Buhrmaster wrote: > On Tue, Apr 2, 2024 at 3:12 PM Dmitry Belyavskiy > wrote: > > > Third-party engines may be a problem but as we don't break ABI, it's not > a problem of the moment. > > The fact you are re

Re: F41 Change Proposal: OpenSSL Deprecate Engine (system-wide)

2024-04-02 Thread Dmitry Belyavskiy
penssl-engine-devel, mark it as Provides: deprecated(). > Existing packages which need the engine headers can adjust to use the > new header and new packages are prevented by the Packaging Guidelines > from adding a dependency on deprecated packages. > Thanks! I like this idea and can