Re: Bug#509063: ITP: libproxy -- automatic proxy configuration management library

2009-01-08 Thread Bastien ROUCARIES
On Thu, Jan 8, 2009 at 12:46 AM, Emilio Pozuelo Monfort wrote: > Hi Florian, and sorry for the long delay. > > Florian Weimer wrote: >> Well, it's not my package, so you don't have to listen to me. I'm >> also not speaking for the security team. > > Oh, should you have said that before, I'd have

Re: Bug#509063: ITP: libproxy -- automatic proxy configuration management library

2009-01-07 Thread Emilio Pozuelo Monfort
Hi Florian, and sorry for the long delay. Florian Weimer wrote: > Well, it's not my package, so you don't have to listen to me. I'm > also not speaking for the security team. Oh, should you have said that before, I'd have ignored all your comments :P > But I appreciate your > efforts to address

Re: Bug#509063: ITP: libproxy -- automatic proxy configuration management library

2008-12-21 Thread Florian Weimer
* Emilio Pozuelo Monfort: > Florian Weimer wrote: >> Not enabling WPAD with DNS devolution goes a long way towards dealing >> with this mess. > > Would you be fine if libproxy disabled WPAD by default? I think libproxy's > developers are willing to do that, according to [1]. Well, it's not my pac

Re: Bug#509063: ITP: libproxy -- automatic proxy configuration management library

2008-12-21 Thread Bastien ROUCARIES
On Sun, Dec 21, 2008 at 9:30 PM, Emilio Pozuelo Monfort wrote: > Hi Florian, > > Thanks for your concerns. I appreciate it. > > Florian Weimer wrote: >> Not enabling WPAD with DNS devolution goes a long way towards dealing >> with this mess. > > Would you be fine if libproxy disabled WPAD by defau

Re: Bug#509063: ITP: libproxy -- automatic proxy configuration management library

2008-12-21 Thread Emilio Pozuelo Monfort
Hi Florian, Thanks for your concerns. I appreciate it. Florian Weimer wrote: > Not enabling WPAD with DNS devolution goes a long way towards dealing > with this mess. Would you be fine if libproxy disabled WPAD by default? I think libproxy's developers are willing to do that, according to [1].

Re: Bug#509063: ITP: libproxy -- automatic proxy configuration management library

2008-12-19 Thread Florian Weimer
* Michael Banck: >> WPAD is a broken protocol with security issues inherent to the DNS >> devolution mechanism (which is also performed by libproxy). Please >> don't add implementations to the Debian archive. > > As I understand it, this library is made so that application writers > don't duplica

Re: Bug#509063: ITP: libproxy -- automatic proxy configuration management library

2008-12-19 Thread Florian Weimer
* Michael Banck: > On Thu, Dec 18, 2008 at 12:51:34PM +0100, Bastien ROUCARIES wrote: >> On Thu, Dec 18, 2008 at 12:35 PM, Bjørn Mork wrote: >> > Florian Weimer writes: >> >> > I would very much like this library to become the *only* WPAD >> > implementation anywhere. Hopefully eventually with

Re: Bug#509063: ITP: libproxy -- automatic proxy configuration management library

2008-12-18 Thread Bastien ROUCARIES
On Thu, Dec 18, 2008 at 6:13 PM, Michael Banck wrote: > On Thu, Dec 18, 2008 at 12:51:34PM +0100, Bastien ROUCARIES wrote: >> On Thu, Dec 18, 2008 at 12:35 PM, Bjørn Mork wrote: >> > Florian Weimer writes: >> >> > I would very much like this library to become the *only* WPAD >> > implementation

Re: Bug#509063: ITP: libproxy -- automatic proxy configuration management library

2008-12-18 Thread Michael Banck
On Thu, Dec 18, 2008 at 12:51:34PM +0100, Bastien ROUCARIES wrote: > On Thu, Dec 18, 2008 at 12:35 PM, Bjørn Mork wrote: > > Florian Weimer writes: > > > I would very much like this library to become the *only* WPAD > > implementation anywhere. Hopefully eventually with some ability to > > defi

Re: Bug#509063: ITP: libproxy -- automatic proxy configuration management library

2008-12-18 Thread Bastien ROUCARIES
On Thu, Dec 18, 2008 at 12:35 PM, Bjørn Mork wrote: > Florian Weimer writes: > I would very much like this library to become the *only* WPAD > implementation anywhere. Hopefully eventually with some ability to > define local policies, where the default Debian policy could be very > strict. E.g

Re: Bug#509063: ITP: libproxy -- automatic proxy configuration management library

2008-12-18 Thread Bjørn Mork
Florian Weimer writes: > * Emilio Pozuelo Monfort: > >> Description : automatic proxy configuration management library >> >> libproxy is a lightweight library which makes it easy to develop >> applications proxy-aware with a simple and stable API. > > WPAD is a broken protocol with securit

Re: Bug#509063: ITP: libproxy -- automatic proxy configuration management library

2008-12-18 Thread Michael Banck
On Thu, Dec 18, 2008 at 09:30:21AM +0100, Florian Weimer wrote: > * Emilio Pozuelo Monfort: > > > Description : automatic proxy configuration management library > > > > libproxy is a lightweight library which makes it easy to develop > > applications proxy-aware with a simple and stable AP

Re: Bug#509063: ITP: libproxy -- automatic proxy configuration management library

2008-12-18 Thread Florian Weimer
* Emilio Pozuelo Monfort: > Description : automatic proxy configuration management library > > libproxy is a lightweight library which makes it easy to develop > applications proxy-aware with a simple and stable API. WPAD is a broken protocol with security issues inherent to the DNS devol