Go Back   maemo.org - Talk > OS / Platform > Maemo 5 / Fremantle
 
Register FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools
  #1  
Old 2014-06-05, 22:36
jonwil jonwil is offline
 
Join Date: Oct 2009
Posts: 567
Thanks!: 0
Thanked 2,964 Times in 448 Posts
Default N900, CSSU and OpenSSL

In light of this new OpenSSL issue:
http://it.slashdot.org/story/14/06/0...ts-all-clients
Do we have OpenSSL in CSSU? Do we want to pull in all the fixes for OpenSSL for issues like this?

Also, it would be good to have a security examination of the N900 and identify all the packages that are important for security (so that we can keep them maintained in CSSU or if they are closed, look at how to replace them with something open)
Reply With Quote
The Following 10 Users Say Thank You to jonwil For This Useful Post:
  #2  
Old 2014-06-05, 22:48
sixwheeledbeast sixwheeledbeast is offline
 
Join Date: Apr 2010
Location: UK
Posts: 2,286
Thanks!: 4,586
Thanked 4,129 Times in 1,649 Posts
Default Re: N900, CSSU and OpenSSL

http://www.symantec.com/connect/blog...ter-heartbleed

It seems we avoided heartbleed issues by being on 0.9.8n, however, latest CVE's recommend updating 0.9.8 to 0.9.8za

I believe some of your question where discussed on the heartbleed thread http://talk.maemo.org/showthread.php?t=92998
__________________
The stable-beast currently runs...
21.2011.38-1Smaemo8 (CSSU Stable)
2.6.28.10power53 (125-600Mhz SR VDD1&2)

Wiki Admin
sixwheeledbeast's wiki
Testing Squad Subscriber
- mcallerx - tenminutecore - FlopSwap - Qnotted - zzztop - Bander - Fight2048 -


Before posting or starting a thread please try this.
Reply With Quote
The Following 4 Users Say Thank You to sixwheeledbeast For This Useful Post:
  #3  
Old 2014-06-06, 02:36
shawnjefferson shawnjefferson is offline
 
Join Date: Nov 2011
Location: Canada
Posts: 254
Thanks!: 187
Thanked 509 Times in 174 Posts
Default Re: N900, CSSU and OpenSSL

Sounds like someone should compile and release 0.9.8za for the n900 at least. Is that part of CSSU, or just generally available in the repos as a separate package?
Reply With Quote
The Following User Says Thank You to shawnjefferson For This Useful Post:
  #4  
Old 2014-06-06, 07:09
sixwheeledbeast sixwheeledbeast is offline
 
Join Date: Apr 2010
Location: UK
Posts: 2,286
Thanks!: 4,586
Thanked 4,129 Times in 1,649 Posts
Default Re: N900, CSSU and OpenSSL

http://maemo.org/packages/view/libssl0.9.8/
http://maemo.org/packages/view/openssl/
__________________
The stable-beast currently runs...
21.2011.38-1Smaemo8 (CSSU Stable)
2.6.28.10power53 (125-600Mhz SR VDD1&2)

Wiki Admin
sixwheeledbeast's wiki
Testing Squad Subscriber
- mcallerx - tenminutecore - FlopSwap - Qnotted - zzztop - Bander - Fight2048 -


Before posting or starting a thread please try this.
Reply With Quote
The Following 2 Users Say Thank You to sixwheeledbeast For This Useful Post:
  #5  
Old 2014-06-07, 05:56
shawnjefferson shawnjefferson is offline
 
Join Date: Nov 2011
Location: Canada
Posts: 254
Thanks!: 187
Thanked 509 Times in 174 Posts
Default Re: N900, CSSU and OpenSSL

Seems like it's in the SSU repository (among others too). On my device, it's thumb compiled by fmg, so hopefully he will compile the newest one. I guess it will have to pass through CSSU-dev first though... I'm not really up on how CSSU stuff works and it seems like a very small group of people own it.
Reply With Quote
  #6  
Old 2014-06-07, 08:29
sixwheeledbeast sixwheeledbeast is offline
 
Join Date: Apr 2010
Location: UK
Posts: 2,286
Thanks!: 4,586
Thanked 4,129 Times in 1,649 Posts
Default Re: N900, CSSU and OpenSSL

Quote:
Originally Posted by shawnjefferson View Post
I'm not really up on how CSSU stuff works and it seems like a very small group of people own it.
I wouldn't say "own" it.
More a small dedicated group of devs contribute to it as a team.
__________________
The stable-beast currently runs...
21.2011.38-1Smaemo8 (CSSU Stable)
2.6.28.10power53 (125-600Mhz SR VDD1&2)

Wiki Admin
sixwheeledbeast's wiki
Testing Squad Subscriber
- mcallerx - tenminutecore - FlopSwap - Qnotted - zzztop - Bander - Fight2048 -


Before posting or starting a thread please try this.
Reply With Quote
The Following 5 Users Say Thank You to sixwheeledbeast For This Useful Post:
  #7  
Old 2014-06-07, 09:13
xes xes is offline
 
Join Date: Aug 2009
Posts: 638
Thanks!: 797
Thanked 1,692 Times in 456 Posts
Default Re: N900, CSSU and OpenSSL

Community is not just ask and receive.

Everyone can contribute, maybe with small things, but the concept of community starts from this.

No one owns, everyone contributes to make it better
Reply With Quote
The Following 3 Users Say Thank You to xes For This Useful Post:
  #8  
Old 2014-06-07, 09:26
freemangordon freemangordon is offline
 
Join Date: Mar 2010
Location: Sofia,Bulgaria
Posts: 3,074
Thanks!: 2,415
Thanked 12,959 Times in 2,522 Posts
Default Re: N900, CSSU and OpenSSL

Quote:
Originally Posted by shawnjefferson View Post
Seems like it's in the SSU repository (among others too). On my device, it's thumb compiled by fmg, so hopefully he will compile the newest one. I guess it will have to pass through CSSU-dev first though... I'm not really up on how CSSU stuff works and it seems like a very small group of people own it.
The only option we have is to backport the needed patches, otherwise we'll break the ABI.

Point me to the patch that fixes that CVE and I'll see what I can do

EDIT:
"Pointing" is raising a bug on BMO, place a link to bug here
__________________
Never fear. I is here.

720p video support on N900,SmartReflex on N900,Keyboard and mouse support on N900
Nothing is impossible - Stable thumb2 on n900

Community SSU developer
kernel-power developer and maintainer

Reply With Quote
The Following 6 Users Say Thank You to freemangordon For This Useful Post:
  #9  
Old 2014-06-07, 12:26
xes xes is offline
 
Join Date: Aug 2009
Posts: 638
Thanks!: 797
Thanked 1,692 Times in 456 Posts
Default Re: N900, CSSU and OpenSSL

@fremangordon
maybe that rebase on 0.9.8za and apply nokia/maemo patches to that would require almost the same time.
For sure latest CVE 2014-0224 is really a pain for every mobile device using a vpn.
ref: http://www.openssl.org/news/secadv_20140605.txt
So also CVE 2014 0195/221/3470 affect the N900's openssl current version.

After this, we should expect many openssl updates in the next months since actually there is a massive bug hunting..

Last edited by xes; 2014-06-07 at 12:35.
Reply With Quote
The Following 3 Users Say Thank You to xes For This Useful Post:
  #10  
Old 2014-06-07, 18:41
freemangordon freemangordon is offline
 
Join Date: Mar 2010
Location: Sofia,Bulgaria
Posts: 3,074
Thanks!: 2,415
Thanked 12,959 Times in 2,522 Posts
Default Re: N900, CSSU and OpenSSL

Quote:
Originally Posted by xes View Post
@fremangordon
maybe that rebase on 0.9.8za and apply nokia/maemo patches to that would require almost the same time.
No, as it will break the ABI, the version in CSSU is the latest that don't break it.

So, if someone finds the relevant patches/commits, I'll backport them in CSSU
__________________
Never fear. I is here.

720p video support on N900,SmartReflex on N900,Keyboard and mouse support on N900
Nothing is impossible - Stable thumb2 on n900

Community SSU developer
kernel-power developer and maintainer

Reply With Quote
The Following 6 Users Say Thank You to freemangordon For This Useful Post:
Reply

Tags
maemo 5, sarcasm


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 17:58.