Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 28727 - pwgen-2.03-r1: more characters for --secure output
Summary: pwgen-2.03-r1: more characters for --secure output
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: New packages (show other bugs)
Hardware: All Linux
: High enhancement (vote)
Assignee: Gentoo LiveCD Package Maintainers
URL:
Whiteboard:
Keywords: EBUILD
Depends on:
Blocks:
 
Reported: 2003-09-14 13:17 UTC by Gontran Zepeda
Modified: 2005-06-15 10:00 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
pwgen-2.03-addl_pw_chars.patch (pwgen-2.03-addl_pw_chars.patch,430 bytes, patch)
2003-09-14 13:18 UTC, Gontran Zepeda
Details | Diff
pwgen-2.03-r1.ebuild (pwgen-2.03-r1.ebuild,836 bytes, text/plain)
2003-09-14 13:18 UTC, Gontran Zepeda
Details
pwgen_ebuild.diff (pwgen_ebuild.diff,442 bytes, text/plain)
2003-09-14 13:19 UTC, Gontran Zepeda
Details

Note You need to log in before you can comment on or make changes to this bug.
Description Gontran Zepeda 2003-09-14 13:17:15 UTC
Made a patch and revised ebuild to return behaviour of pwgen -s to that
of previous version.  Prevents loss of non alpha-numeric characters in
random selection of --secure type strings.
Comment 1 Gontran Zepeda 2003-09-14 13:18:17 UTC
Created attachment 17713 [details, diff]
pwgen-2.03-addl_pw_chars.patch
Comment 2 Gontran Zepeda 2003-09-14 13:18:55 UTC
Created attachment 17714 [details]
pwgen-2.03-r1.ebuild
Comment 3 Gontran Zepeda 2003-09-14 13:19:38 UTC
Created attachment 17715 [details]
pwgen_ebuild.diff

Differences in 2.03 and -r1 ebuilds.
Comment 4 Seemant Kulleen (RETIRED) gentoo-dev 2003-09-21 19:48:59 UTC
thanks Gontran
Comment 5 Wolfram Schlich (RETIRED) gentoo-dev 2003-10-29 14:16:21 UTC
Hmm, IMHO it's not ok to apply that patch by default, as there's a reason
not to have these non alnum-chars in the list (users given such a non-alnum
password tend to be very unhappy with it). Maybe we should add a local USE-flag,
like "pwgen-specialchars".
Comment 6 Wolfram Schlich (RETIRED) gentoo-dev 2003-10-29 14:18:36 UTC
An even better solution would be to contact the pwgen developer and ask him
for another command line switch to explicitly include/exclude non-alnum characters.
Comment 7 Gontran Zepeda 2003-10-30 02:21:08 UTC
OK.  The patch returns behaviour that was available in a previous version
of the software.  Further, this mini-patch enhances a quality piece of software.
 The additionale characters are only used when pwgen is invoked with the
--secure or -s option (did you read the original notice and try the program
before you decided to have an opinion? :)

So in conclusion, there is nothing wrong with the patch, we don't need another
use flag, pwgen is no less user friendly, and we most certainly should NOT
contact the author T Ts'o about this issue: he has better things to do.

Cheers!
Comment 8 Wolfram Schlich (RETIRED) gentoo-dev 2003-10-30 02:27:05 UTC
Bla.

Compared to the passwords spit out when *not* using the --secure option,
the password generated *with* the --secure option (dist behaviour) *are*
more secure, as they are *completely* random (have *you* ever compared the
outputs?).
And have you thought about *why* it has changed in the distribution? I guess
there's a reason tytso changed it.
Comment 9 Gontran Zepeda 2003-10-30 03:27:35 UTC
I think I see your point now, I don't care for it.  Maybe we could have a
long discussion about it on -dev.  I like the extra characters for improving
strength versus brute force attacks.
Comment 10 Chris Gianelloni (RETIRED) gentoo-dev 2005-06-15 10:00:06 UTC
This appears to have been resolved a long time ago.