X-Original-To: alpine-devel@lists.alpinelinux.org Received: from www.cioccolatai.it (www.cioccolatai.it [148.251.83.60]) by lists.alpinelinux.org (Postfix) with ESMTP id 6A7285C4403 for ; Sat, 4 Mar 2017 17:53:09 +0000 (GMT) Received: from 217-133-104-86.static.clienti.tiscali.it (HELO [192.168.0.5]) (217.133.104.86) by www.cioccolatai.it (qpsmtpd/0.93) with (AES128-SHA encrypted) ESMTPSA; Sat, 04 Mar 2017 18:53:08 +0100 Authentication-Results: www.cioccolatai.it; auth=pass (cram-md5) smtp.auth=auth_user@meow X-HELO: [192.168.0.5] Subject: Re: [alpine-devel] main/xorg-server: Enable xcsecurity to allow ssh X11 forwarding References: <20170304135150.GA5099@angua.1042.ch> <662e9ec7-a3d9-5f07-1646-a05cc409a046@cioccolatai.it> <20170304155400.GA25823@angua.1042.ch> From: "lists@cioccolatai.it" To: alpine-devel@lists.alpinelinux.org Message-ID: <288e9db1-2142-62fc-2974-9194bc8ac0f9@cioccolatai.it> Date: Sat, 4 Mar 2017 18:53:05 +0100 X-Mailinglist: alpine-devel Precedence: list List-Id: Alpine Development List-Unsubscribe: List-Post: List-Help: List-Subscribe: MIME-Version: 1.0 In-Reply-To: <20170304155400.GA25823@angua.1042.ch> Content-Type: text/plain; charset=windows-1252; format=flowed Content-Transfer-Encoding: 7bit X-Virus-Checked: Checked by ClamAV on www.cioccolatai.it On 03/04/2017 04:54 PM, Jean-Louis Fuchs wrote: >>> Could somebody take a look at this issue: >>> http://bugs.alpinelinux.org/issues/6696 NB: i'm not the/a mantainer of the xorg package (on any other package) >>> I know I should have sent a patch to the aports list, but I missed the >>> wiki-page about patches. I don't want to duplicate things, so I hope >>> we can solve this on the bug-tracker. >> >> AFAIK, XCSECURITY are disabled on most (linux) Xorg packages, and on freebsd >> and cygwin too (just search xcsecurity/xsecurity on google). > > ssh -X works on Debian, Arch, Ubuntu, Fedora, CentOS, SuSE. > The only distro that I know that has no xcsecurity is alpine. Ok, my fault, when I was researching on this subject some time ago, I found that these extension where disabled by default by the upstream (generic reasons like "obsolete" a/o "insecure") in favor of the new XACE extensions (which seems to be at least not used/incomplete, maybe someone has more updated infos?) After that various distro (debian, red-hat, ..) have re-enabled it, eg: https://www.redhat.com/archives/rhsa-announce/2013-November/msg00028.html http://metadata.ftp-master.debian.org/changelogs/main/x/xorg-server/stable_changelog but i'm on Slackware (and Alpine) so I didn't noticed it :) >> I just tried some weeks ago to use ssh -X on a OpenBSD X11 server, and many >> applications just crashes with "bad access" or similar, as noted in this >> mail: >> https://cygwin.com/ml/cygwin-xfree/2008-11/msg00154.html > > All my applications work without problems. We are using it since more > than 10 years, never had a single problem. > ssh -X is definitely nothing special, instable or esoteric. But I That's interesting, good to know; I was also using ssh -X a lot, but since it was disabled upstream I got this kind of troubles all the times I tried; probabily I have to test again, using the same distro/settings on both clients and server. > don't understand the security implications completely, so I can accept > a well-founded no. Did you already tried to recompile xorg on alpine with -xcsecurity enabled? ciao, I. --- Unsubscribe: alpine-devel+unsubscribe@lists.alpinelinux.org Help: alpine-devel+help@lists.alpinelinux.org ---