[pkg-ntp-maintainers] Bug#687166: Bug#687166: Bug#687166: ntp: NTP security vulnerability because not using authentication by default

anotst01 at fastmail.fm anotst01 at fastmail.fm
Wed Sep 19 03:12:47 UTC 2012


On Tue, Sep 18, 2012, at 01:03 PM, Kurt Roeckx wrote:
> On Tue, Sep 11, 2012 at 09:23:45PM +0200, Kurt Roeckx wrote:
> > 
> > So after reading some more, I think the only option we have is
> > using the IFF identity scheme.
> > 
> > But I seem to be failing in getting it working.
> 
> So the problem is that autokey does not work over NAT.  So I don't
> think it's going to be a good idea to try to turn this on by
> default.

Agreed. What else could we do?

NTP upstream bug report?

Or a more general debian bug "need secure replacement for NTP"? Against
which component?

-- 
http://www.fastmail.fm - One of many happy users:
  http://www.fastmail.fm/docs/quotes.html



More information about the pkg-ntp-maintainers mailing list