Package: sudo
Version: 1.9.16p2-1
Severity: important

We have been shipping sudo_logsrvd by accident as we were not aware of
that program existing. I would like to apologize for that.

sudo is a complicated beast and a suid binary to make it worse. Hence,
the sudo maintainers would like to keep sudo's complexity as little as
possible. Especially, we would like to avoid depending on a library with
such a horrible track record as OpenSSL. Since OpenSSL is needed to
transmit the log trail securely, the SSL dependency is closely tied to
sudo_logsrvd.

I would like to ask the users of sudo_logsrvd about the importance of
having sudo_logsrvd. The sudo team is currently not in a position that
it is possible to seriously test and support input/output plugins and
log shipping. Therefore, if nobody steps up to help, the features are
going to be removed during the trixie cycle, making trixie the last
version of Debian that might support input/output logging and logsrvd.

Please note that willingness to help is a long-term commitment on an
understaffed team. We are not looking for a person who drops two --enable
lines into debian/rules, tries two experimental calls of sudo and the
vanishes again.

Greetings
Marc

Reply via email to