[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: heimdal-0.7.1rc2

On Thu, 11 Aug 2005, Love Hörnquist Åstrand wrote:

> Hello


> I'll preparing to make a Heimdal-0.7.1 release for early next week. There
> will be only bugfixes in this release. If you have found any bugs that you
> want to have fixed, now would be a good time to tell us about them
> (hopefully with patches :)

I found two things:

1. configure cannot detect OpenSSL 0.9.8. At least openssl/md4.h contains
    a variable of size_t which is defined in stdio.h. But the test program
    does not include stdio.h so the check fails.

2. Did someone manage to get OpenSSH 4.x gssapi-with-mic authentication
    running when linked against heimdal 0.7x? When linked against heimdal
    0.6.x everything runs fine. I did not really look deeply at the code
    but it seems to me the function gss_verify_mic does not work properly.

    I also have to mention that heimdal 0.6.x is linked against OpenSSL
    0.9.6x and heimdal 0.7 uses OpenSSL 0.9.7 here.

Another question: How long will you provide security fixes for the 0.6.x 
heimdal branch?


| Andreas Haupt                      | E-Mail:  andreas.haupt@desy.de
|  DESY Zeuthen                      | WWW:     http://www.desy.de/~ahaupt
|  Platanenallee 6                   | Phone:   +49/33762/7-7359
|  D-15738 Zeuthen                   | Fax:     +49/33762/7-7216