<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>63995</bug_id>
          
          <creation_ts>2004-09-14 07:12 0000</creation_ts>
          <short_desc>app-admin/skey-1.1.5-r2: change of MD5 back to MD4</short_desc>
          <delta_ts>2004-09-22 20:51:06 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Linux</product>
          <component>Security</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          <status_whiteboard>B4 [glsa?]</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>minor</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>ulm@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>taviso@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>ulm@gentoo.org</who>
            <bug_when>2004-09-14 07:12:50 0000</bug_when>
            <thetext>I was wondering about the change of the default algorithm used
by S/Key introduced in version 1.1.5-r1: The algorithm used in
vanilla 1.1.5 is MD5, and that is what is suggested as the default
in RFC 2289, while MD4 is now purely optional:

| All conforming implementations of both server and generators MUST
| support MD5. They SHOULD support SHA and MAY also support MD4.

Now in -r1 (and still in -r2) the patch by skey-1.1.5-gentoo.diff
changes that default from MD5 (back?) to MD4.

I wonder if this isn&apos;t a step in the wrong direction, considering
RFC 2289 and &lt;http://www.rsasecurity.com/rsalabs/node.asp?id=2253&gt;:

| Dobbertin [Dob 95] has shown how collisions for the full version of
| MD4 can be found in under a minute on a typical PC. In recent work,
| Dobbertin (Fast Software Encryption, 1998) has shown that a reduced
| version of MD4 in which the third round of the compression function
| is not executed but everything else remains the same, is not
| one-way. Clearly, MD4 should now be considered broken.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2004-09-14 07:20:37 0000</bug_when>
            <thetext>Tavis, please comment, as you were the one that committed the changes in -r1 about... 1 year ago :)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>taviso@gentoo.org</who>
            <bug_when>2004-09-14 07:50:47 0000</bug_when>
            <thetext>I had completely forgotten about this, I think it was the reporter who emailed a few months ago about it. He&apos;s quite correct, the default should be changed to md5. it&apos;s a simple fix, and app-admin/skey-1.1.5-r3 includes it.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2004-09-14 08:20:49 0000</bug_when>
            <thetext>Does everyone agree with me it should be closed without GLSA ?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2004-09-14 08:31:22 0000</bug_when>
            <thetext>Ebuild should be stable before this is closed.

Target keywords : x86 ppc sparc mips alpha arm hppa amd64 ia64 s390 ppc64
Arches please test app-admin/skey-1.1.5-r3 and mark stable.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gmsoft@gentoo.org</who>
            <bug_when>2004-09-14 08:47:00 0000</bug_when>
            <thetext>Done on hppa.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>tester@gentoo.org</who>
            <bug_when>2004-09-14 16:12:14 0000</bug_when>
            <thetext>stable on x86
btw repoman reminds us that app-admin/skey/files/skey-1.1.5-gentoo.diff.gz is 37k.. that is bigger than 20k..</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>pvdabeel@gentoo.org</who>
            <bug_when>2004-09-14 17:29:34 0000</bug_when>
            <thetext>stable on ppc</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>weeve@gentoo.org</who>
            <bug_when>2004-09-15 05:14:38 0000</bug_when>
            <thetext>Stable on sparc</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>kloeri@gentoo.org</who>
            <bug_when>2004-09-15 17:34:17 0000</bug_when>
            <thetext>Stable on alpha.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vapier@gentoo.org</who>
            <bug_when>2004-09-19 17:53:52 0000</bug_when>
            <thetext>only s390 left ...</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2004-09-20 05:43:14 0000</bug_when>
            <thetext>Closing without GLSA</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vapier@gentoo.org</who>
            <bug_when>2004-09-22 20:51:06 0000</bug_when>
            <thetext>s390 is done</thetext>
          </long_desc>
      
    </bug>

</bugzilla>