Bug#687166: [pkg-ntp-maintainers] Bug#687166: ntp: NTP security vulnerability because not using authentication by default

2012-09-11 Thread Nico Golde
Hi, * Ask Bjørn Hansen a...@ntppool.org [2012-09-11 01:01]: On Sep 10, 2012, at 15:07, Kurt Roeckx k...@roeckx.be wrote: [...] So my understanding of things is that even if we also had a way to distribute all the public keys, you still can't get it to work as you need to provide each

Bug#687166: [pkg-ntp-maintainers] Bug#687166: ntp: NTP security vulnerability because not using authentication by default

2012-09-11 Thread Kurt Roeckx
On Tue, Sep 11, 2012 at 12:49:09PM +0200, Nico Golde wrote: Hi, * Ask Bjørn Hansen a...@ntppool.org [2012-09-11 01:01]: On Sep 10, 2012, at 15:07, Kurt Roeckx k...@roeckx.be wrote: [...] So my understanding of things is that even if we also had a way to distribute all the public keys,

Bug#687166: [pkg-ntp-maintainers] Bug#687166: ntp: NTP security vulnerability because not using authentication by default

2012-09-10 Thread Kurt Roeckx
On Mon, Sep 10, 2012 at 06:18:42PM +0200, Nico Golde wrote: Hi, * Ask Bjørn Hansen a...@ntppool.org [2012-09-10 18:03]: On Sep 10, 2012, at 8:13, Nico Golde n...@debian.org wrote: [Adding NTP authentication] We could setup a set of servers with authentication, but that'd be a much

Bug#687166: [pkg-ntp-maintainers] Bug#687166: ntp: NTP security vulnerability because not using authentication by default

2012-09-10 Thread Ask Bjørn Hansen
Hi Kurt, Of course you are right. DNSSEC will help a different use case. That leaves us the first problem of the keys having to be secret which is impossible if random servers are hosting them. If the Debian project had a set of servers with autokey configured that should be used for

Bug#687166: [pkg-ntp-maintainers] Bug#687166: ntp: NTP security vulnerability because not using authentication by default

2012-09-10 Thread Kurt Roeckx
On Mon, Sep 10, 2012 at 02:06:52PM -0700, Ask Bjørn Hansen wrote: Hi Kurt, Of course you are right. DNSSEC will help a different use case. That leaves us the first problem of the keys having to be secret which is impossible if random servers are hosting them. If the Debian project had

Bug#687166: [pkg-ntp-maintainers] Bug#687166: ntp: NTP security vulnerability because not using authentication by default

2012-09-10 Thread Ask Bjørn Hansen
On Sep 10, 2012, at 15:07, Kurt Roeckx k...@roeckx.be wrote: I'm not sure Debian wants to run ntp.debian.org. We would need to ask people to donate resources for that, and the pool project already exists for that. Indeed! Sorry I wasn't clear. The NTP Pool system can work on other domains