<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>83797</bug_id>
          
          <creation_ts>2005-03-02 03:30 0000</creation_ts>
          <short_desc>net-mail/{uw-imap|vimap} ebuild disables part of security with ssl</short_desc>
          <delta_ts>2005-06-26 06:16:08 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Default Configs</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>All</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          <status_whiteboard>[stable] jaervosz</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>minor</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>tpeland@tkukoulu.fi</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>net-mail@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>tpeland@tkukoulu.fi</who>
            <bug_when>2005-03-02 03:30:50 0000</bug_when>
            <thetext>When compiling uw-imap with ssl the ebuild specifically turns on support for clear text passwords in nonsecure transports. For real servers this is not a good thing.

I propose using local useflag to allow compiling with relaxed security. This way I can enjoy the uw-imap updates without always first fixing the ebuild to original security level.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>tpeland@tkukoulu.fi</who>
            <bug_when>2005-03-02 03:33:06 0000</bug_when>
            <thetext>Created an attachment (id=52443)
&quot;lowsecurity&quot; local flag
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2005-03-02 14:13:19 0000</bug_when>
            <thetext>net-mail please advise.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ticho@gentoo.org</who>
            <bug_when>2005-03-02 18:16:05 0000</bug_when>
            <thetext>I&apos;m all for it, with disabling cleartext passwords usage by default.

There&apos;s already a suitable local USE flag for this - &quot;clearpasswd&quot; - used by two other packages.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ticho@gentoo.org</who>
            <bug_when>2005-03-02 18:42:15 0000</bug_when>
            <thetext>uw-imap-2004c-r3.ebuild is in CVS portage, with added &quot;clearpasswd&quot; USE flag and an ewarn message for users in pkg_setup(). Thanks for suggesting this, it&apos;s a good idea.

security@, feel free to close this bug, as it&apos;s yours.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>tpeland@tkukoulu.fi</who>
            <bug_when>2005-03-02 23:22:38 0000</bug_when>
            <thetext>The clearpasswd notification should only be display if &quot;use ssl&quot; is true. That is the requirement for any sort of secure transport. Otherwise the uw-imap-2004c-r3.ebuild is excellent.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ticho@gentoo.org</who>
            <bug_when>2005-03-03 01:58:18 0000</bug_when>
            <thetext>Ah, sorry about that omission. Fixed in CVS now.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>tpeland@tkukoulu.fi</who>
            <bug_when>2005-03-03 03:16:16 0000</bug_when>
            <thetext>The warning for USE=&quot;-ssl -clearpassword&quot; case contains a typo.

Current..: Either enable &quot;ssl&quot; USE flag, or disable &quot;clearpasswd&quot; USE flag.
Should be: Either enable &quot;ssl&quot; or &quot;clearpasswd&quot; USE flag.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ticho@gentoo.org</who>
            <bug_when>2005-03-03 04:16:15 0000</bug_when>
            <thetext>Hm, I shouldn&apos;t commit after sleep deprivation. Sorry everyone.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ferdy@gentoo.org</who>
            <bug_when>2005-03-03 04:33:02 0000</bug_when>
            <thetext>I guess this one also affects to vimap, doesn&apos;t it?

Cheers,
Ferdy</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ticho@gentoo.org</who>
            <bug_when>2005-03-03 05:56:07 0000</bug_when>
            <thetext>Yup, vimap too. Fixed in 2002c-r3.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2005-03-03 06:01:01 0000</bug_when>
            <thetext>Arches please test and mark uw-imap-2004c-r3 and vimap-2002c-r3 stable.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ticho@gentoo.org</who>
            <bug_when>2005-03-03 09:02:00 0000</bug_when>
            <thetext>Both ebuilds stable on x86.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>hansmi@gentoo.org</who>
            <bug_when>2005-03-03 14:09:53 0000</bug_when>
            <thetext>Stable on ppc.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gustavoz@gentoo.org</who>
            <bug_when>2005-03-04 12:13:43 0000</bug_when>
            <thetext>sparc stable.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>cryos@gentoo.org</who>
            <bug_when>2005-03-05 06:39:44 0000</bug_when>
            <thetext>uw-imap-2004c-r3 stable on amd64, vimap is all ~amd64 and has not yet had much testing.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>kloeri@gentoo.org</who>
            <bug_when>2005-03-06 00:03:24 0000</bug_when>
            <thetext>Stable on alpha.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2005-03-09 12:31:35 0000</bug_when>
            <thetext>Thx everyone. Default Config issue -&gt; closing.

hppa please remember to mark stable.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>killerfox@gentoo.org</who>
            <bug_when>2005-06-26 06:16:08 0000</bug_when>
            <thetext>Already stable on hppa</thetext>
          </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>52443</attachid>
            <date>2005-03-02 03:33 0000</date>
            <desc>&quot;lowsecurity&quot; local flag</desc>
            <filename>2004c-r2.diff</filename>
            <type>text/plain</type>
            <data encoding="base64">LS0tIHV3LWltYXAtMjAwNGMtcjIuZWJ1aWxkLk9SSUcJMjAwNS0wMy0wMiAxMjoyNjo0Ni40MDIw
NzgxNzIgKzAyMDAKKysrIHV3LWltYXAtMjAwNGMtcjIuZWJ1aWxkCTIwMDUtMDMtMDIgMTI6Mjg6
NTIuNDc1NTAzMzU2ICswMjAwCkBAIC0xNCw3ICsxNCw3IEBACiBMSUNFTlNFPSJhcy1pcyIKIFNM
T1Q9IjAiCiBLRVlXT1JEUz0ifng4NiB+c3BhcmMgfnBwYyB+aHBwYSB+YWxwaGEgfmFtZDY0Igot
SVVTRT0iaXB2NiBzc2wgcGljIGtlcmJlcm9zIgorSVVTRT0iaXB2NiBzc2wgcGljIGtlcmJlcm9z
IGxvd3NlY3VyaXR5IgogCiBQUk9WSURFPSJ2aXJ0dWFsL2ltYXBkIgogUFJPVklERT0iJHtQUk9W
SURFfSB2aXJ0dWFsL2ltYXAtYy1jbGllbnQiCkBAIC05MSw3ICs5MSwxMSBAQAogCWlmIHVzZSBz
c2w7IHRoZW4KIAkJY2QgJHtTfQogCQllY2hvICR7bXltYWtlfQotCQl5ZXMgfCBtYWtlIGxucCAk
e215bWFrZX0gJHtpcHZlcn0gU1NMVFlQRT11bml4IEVYVFJBQ0ZMQUdTPSIke0NGTEFHU30iIHx8
IGRpZQorCQlpZiB1c2UgbG93c2VjdXJpdHkgOyB0aGVuCisJCQl5ZXMgfCBtYWtlIGxucCAke215
bWFrZX0gJHtpcHZlcn0gU1NMVFlQRT11bml4IEVYVFJBQ0ZMQUdTPSIke0NGTEFHU30iIHx8IGRp
ZQorCQllbHNlCisJCQltYWtlIGxucCAke215bWFrZX0gJHtpcHZlcn0gU1NMVFlQRT11bml4Lm5v
cHdkIEVYVFJBQ0ZMQUdTPSIke0NGTEFHU30iIHx8IGRpZQorCQlmaQogCiAJCWxvY2FsIGkKIAkJ
Zm9yIGkgaW4gaW1hcGQgaXBvcDNkOyBkbwo=
</data>        

          </attachment>
    </bug>

</bugzilla>