Re: Authenticated TLS contraints in ntpd(8)

2015-02-11 Thread Carlin Bingham
On Wed, 11 Feb 2015, at 12:32 AM, Reyk Floeter wrote: Let me share the answer to a question that I got in a private mail: On Tue, Feb 10, 2015 at 10:55:53AM +0100, Reyk Floeter wrote: ---snip--- servers pool.ntp.org constraints from https://www.google.com/search?q=openntpd;

Re: Authenticated TLS contraints in ntpd(8)

2015-02-11 Thread Reyk Floeter
On Thu, Feb 12, 2015 at 02:05:59AM +1300, Carlin Bingham wrote: On Wed, 11 Feb 2015, at 12:32 AM, Reyk Floeter wrote: Let me share the answer to a question that I got in a private mail: On Tue, Feb 10, 2015 at 10:55:53AM +0100, Reyk Floeter wrote: ---snip--- servers pool.ntp.org

Re: Authenticated TLS contraints in ntpd(8)

2015-02-11 Thread Renaud Allard
On 02/10/2015 12:43 PM, Stuart Henderson wrote: On 2015/02/10 12:32, Reyk Floeter wrote: Let me share the answer to a question that I got in a private mail: On Tue, Feb 10, 2015 at 10:55:53AM +0100, Reyk Floeter wrote: ---snip--- servers pool.ntp.org constraints from

Re: Authenticated TLS contraints in ntpd(8)

2015-02-10 Thread Kevin Chadwick
On Tue, 10 Feb 2015 10:55:53 +0100 Reyk Floeter wrote: The standardized attempts to add authentication to NTP are a) fairly horrible (ASN.1 etc.) and b) rarely deployed. When ntpd acts as a server, could the package signing code be of use with ntpd keys?

Re: Authenticated TLS contraints in ntpd(8)

2015-02-10 Thread Stuart Henderson
On 2015/02/10 12:32, Reyk Floeter wrote: Let me share the answer to a question that I got in a private mail: On Tue, Feb 10, 2015 at 10:55:53AM +0100, Reyk Floeter wrote: ---snip--- servers pool.ntp.org constraints from https://www.google.com/search?q=openntpd; Cue google turning on

Re: Authenticated TLS contraints in ntpd(8)

2015-02-10 Thread Kevin Chadwick
On Tue, 10 Feb 2015 13:03:27 + David Dahlberg wrote: The standardized attempts to add authentication to NTP are a) fairly horrible (ASN.1 etc.) and b) rarely deployed. When ntpd acts as a server, could the package signing code be of use with ntpd keys? How exactly? You

Re: Authenticated TLS contraints in ntpd(8)

2015-02-10 Thread Reyk Floeter
On Tue, Feb 10, 2015 at 10:51:12PM -0700, Theo de Raadt wrote: So I gave Reyk some beer, and he did the impossible :-) I sense a pattern here. Reyk

Re: Authenticated TLS contraints in ntpd(8)

2015-02-10 Thread Bob Beck
On Tue, Feb 10, 2015 at 11:19 PM, Reyk Floeter r...@openbsd.org wrote: On Tue, Feb 10, 2015 at 10:51:12PM -0700, Theo de Raadt wrote: So I gave Reyk some beer, and he did the impossible :-) I sense a pattern here. Reyk Not enough samples to be a pattern yet.. You shouldn't worry.. It's

Re: Authenticated TLS contraints in ntpd(8)

2015-02-10 Thread Henning Brauer
* Henning Brauer hb-openbsdt...@ml.bsws.de [2015-02-10 13:21]: * Kevin Chadwick ma1l1i...@yahoo.co.uk [2015-02-10 13:14]: On Tue, 10 Feb 2015 10:55:53 +0100 Reyk Floeter wrote: The standardized attempts to add authentication to NTP are a) fairly horrible (ASN.1 etc.) and b) rarely

Re: Authenticated TLS contraints in ntpd(8)

2015-02-10 Thread Theo de Raadt
* Henning Brauer hb-openbsdt...@ml.bsws.de [2015-02-10 13:21]: * Kevin Chadwick ma1l1i...@yahoo.co.uk [2015-02-10 13:14]: On Tue, 10 Feb 2015 10:55:53 +0100 Reyk Floeter wrote: The standardized attempts to add authentication to NTP are a) fairly horrible (ASN.1 etc.) and b) rarely

Re: Authenticated TLS contraints in ntpd(8)

2015-02-10 Thread David Dahlberg
Am Dienstag, den 10.02.2015, 12:35 + schrieb Kevin Chadwick: On Tue, 10 Feb 2015 10:55:53 +0100 Reyk Floeter wrote: The standardized attempts to add authentication to NTP are a) fairly horrible (ASN.1 etc.) and b) rarely deployed. When ntpd acts as a server, could the package

Re: Authenticated TLS contraints in ntpd(8)

2015-02-10 Thread Henning Brauer
* Kevin Chadwick ma1l1i...@yahoo.co.uk [2015-02-10 13:14]: On Tue, 10 Feb 2015 10:55:53 +0100 Reyk Floeter wrote: The standardized attempts to add authentication to NTP are a) fairly horrible (ASN.1 etc.) and b) rarely deployed. When ntpd acts as a server, could the package signing code be