<?xml version="1.0" encoding="UTF-8" ?>

<bugzilla version="5.2"
          urlbase="https://bugzilla.altlinux.org/"
          
          maintainer="jenya@basealt.ru"
>

    <bug>
          <bug_id>3094</bug_id>
          
          <creation_ts>2003-10-03 13:09:18 +0400</creation_ts>
          <short_desc>Unable to build many Kerberos-aware programs without KerberosIV support</short_desc>
          <delta_ts>2005-09-13 15:42:49 +0400</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>4</classification_id>
          <classification>Development</classification>
          <product>Sisyphus</product>
          <component>libkrb5</component>
          <version>unstable</version>
          <rep_platform>all</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>CLOSED</bug_status>
          <resolution>WONTFIX</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>P1</priority>
          <bug_severity>enhancement</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Yurix">yurix</reporter>
          <assigned_to name="Alexander Bokovoy">ab</assigned_to>
          <cc>iv</cc>
    
    <cc>shaba</cc>
          
          <qa_contact>qa-sisyphus</qa_contact>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>9976</commentid>
    <comment_count>0</comment_count>
    <who name="Yurix">yurix</who>
    <bug_when>2003-10-03 13:09:19 +0400</bug_when>
    <thetext>Disabling support for KerberosIV in 3.1.3 make nearly impossible to 
build other Kerberos-based software for Sisyphus, since majority of them 
do not provide any simple way to disable Kv4 functionality. So in many cases 
removing kerberosIV dependencies requires to much work to be done hacking the 
source code of the software. 
 Please, return KerberosIV support.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>9977</commentid>
    <comment_count>1</comment_count>
    <who name="Dmitry V. Levin">ldv</who>
    <bug_when>2003-10-03 13:27:40 +0400</bug_when>
    <thetext>I&apos;d vote against this suggestion. </thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>9980</commentid>
    <comment_count>2</comment_count>
    <who name="Yurix">yurix</who>
    <bug_when>2003-10-03 15:02:43 +0400</bug_when>
    <thetext> Well, I have to make it clear for myself. As far as i understand, building 
krb5 with --disable-kerberosIV prevents installing krb4 libraries and headers, 
so it simply could not affect system security in any way, on other hand, it 
makes it possible to build and use other (optional) software, witch may use 
legacy (surely, much less secure) krb4 method. Such a software may or may not 
be included in major distributions depending on security-team decision. 
 Not including krb4 soft cannot compromise system security in any manner, 
as it were when complitely disabling krb4 support. So the choice is &quot;prevent 
anything KerberosIV-aware because user could use its krb4 functionality, and 
it&apos;s bad&quot;  and &quot;Provide user with a choice to use or not to use krb4-based 
soft with no potential risk for system by default (since no app use krb4 
libs)&quot;. 
 Also I have to note, that many programs, I&apos;m talking about, would use 
Kerberos5 method by default, but have support for krb4 as well. As I already 
said, majority of them could not be configured at build-time to not to use 
krb4 libraries. 
 I whould like to know the policy of security-team concerning support for 
Kerberos technology in Sisyphus repository. 
 </thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>13278</commentid>
    <comment_count>3</comment_count>
    <who name="inger@altlinux.org">inger</who>
    <bug_when>2004-05-05 16:01:02 +0400</bug_when>
    <thetext>перевешено на новый пакет 
 </thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>24537</commentid>
    <comment_count>4</comment_count>
    <who name="Yurix">yurix</who>
    <bug_when>2005-05-14 15:35:03 +0400</bug_when>
    <thetext>No more demand 
 </thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>