Bug#547092: [Pkg-nagios-devel] Bug#547092: Bug#547092: Bug#547092: Bug#547092: nrpe ssl security problem

2013-02-23 Thread Salvatore Bonaccorso
Hi Alex On Sat, Feb 23, 2013 at 01:17:03PM +0100, Alexander Wirt wrote: > On Sat, 23 Feb 2013, Salvatore Bonaccorso wrote: > > > Hi Alex, Hi Thijs > > > > I was looking trough the bugs for nagios-nrpe, and noticed #547092 > > where there was an upload to address it, but the bug was not closed. >

Bug#547092: [Pkg-nagios-devel] Bug#547092: Bug#547092: Bug#547092: Bug#547092: nrpe ssl security problem

2013-02-23 Thread Alexander Wirt
On Sat, 23 Feb 2013, Salvatore Bonaccorso wrote: > Hi Alex, Hi Thijs > > I was looking trough the bugs for nagios-nrpe, and noticed #547092 > where there was an upload to address it, but the bug was not closed. > > I wondered if this was intentional, als the original issue is "only" > addressed

Bug#547092: [Pkg-nagios-devel] Bug#547092: Bug#547092: Bug#547092: nrpe ssl security problem

2013-02-23 Thread Salvatore Bonaccorso
Hi Alex, Hi Thijs I was looking trough the bugs for nagios-nrpe, and noticed #547092 where there was an upload to address it, but the bug was not closed. I wondered if this was intentional, als the original issue is "only" addressed by making clear in the documentation where the issues are. Rega

Bug#547092: [Pkg-nagios-devel] Bug#547092: Bug#547092: Bug#547092: nrpe ssl security problem

2013-02-11 Thread Alexander Wirt
On Sun, 10 Feb 2013, Thijs Kinkhorst wrote: > Hi Alex, > > > > All agreed... but would you consider to add some big warnings about that > > > fact? :) > > Thats something for the release notes or readme.debian. Feel free to send a > > patch. > > I do not believe the issue should mean that NRPE

Bug#547092: [Pkg-nagios-devel] Bug#547092: Bug#547092: Bug#547092: nrpe ssl security problem

2013-02-10 Thread Alexander Wirt
On Sun, 10 Feb 2013, Thijs Kinkhorst wrote: > Hi Alex, > > > > All agreed... but would you consider to add some big warnings about that > > > fact? :) > > Thats something for the release notes or readme.debian. Feel free to send a > > patch. > > I do not believe the issue should mean that NRPE

Bug#547092: [Pkg-nagios-devel] Bug#547092: Bug#547092: nrpe ssl security problem

2013-02-10 Thread Thijs Kinkhorst
Hi Alex, > > All agreed... but would you consider to add some big warnings about that > > fact? :) > Thats something for the release notes or readme.debian. Feel free to send a > patch. I do not believe the issue should mean that NRPE is so critically flawed that it should be removed from Wheez

Bug#547092: [Pkg-nagios-devel] Bug#547092: Bug#547092: nrpe ssl security problem

2013-02-08 Thread Alexander Wirt
On Fri, 08 Feb 2013, Christoph Anton Mitterer wrote: > On Fri, 2013-02-08 at 00:26 +0100, Alexander Wirt wrote: > > In fact nothing is new here and security wouldn't change much with different > > keys. The implementation ist just broken. But if you have an idea to improve > > it, feel free to sen

Bug#547092: [Pkg-nagios-devel] Bug#547092: Bug#547092: nrpe ssl security problem

2013-02-07 Thread Christoph Anton Mitterer
Off topic but... Hi Michael On Fri, 2013-02-08 at 00:55 +0100, Michael Friedrich wrote: > i've tried the idea of the ssl x509 patch in an unofficial nrpe fork. > lives in git here, until it dies, and will never get released, so > beware: https://git.icinga.org/?p=icinga-irpe.git;a=summary If no

Bug#547092: [Pkg-nagios-devel] Bug#547092: nrpe ssl security problem

2013-02-07 Thread Christoph Anton Mitterer
On Fri, 2013-02-08 at 00:26 +0100, Alexander Wirt wrote: > In fact nothing is new here and security wouldn't change much with different > keys. The implementation ist just broken. But if you have an idea to improve > it, feel free to send a patch. (as long as it doesn't make nrpe incompatible > to

Bug#547092: [Pkg-nagios-devel] Bug#547092: Bug#547092: nrpe ssl security problem

2013-02-07 Thread Michael Friedrich
On 08.02.2013 00:31, Markus Frosch wrote: Just my 2 cents (without any hat on): TLS integration in NRPE was broken from the beginning and more or less by design. The "real" and only security feature is to configure a appropriate allowed_hosts list, which might be enough security for internal ne

Bug#547092: [Pkg-nagios-devel] Bug#547092: nrpe ssl security problem

2013-02-07 Thread Markus Frosch
Just my 2 cents (without any hat on): TLS integration in NRPE was broken from the beginning and more or less by design. The "real" and only security feature is to configure a appropriate allowed_hosts list, which might be enough security for internal networks in respect of TCP sessions. Question

Bug#547092: [Pkg-nagios-devel] Bug#547092: nrpe ssl security problem

2013-02-07 Thread Alexander Wirt
On Thu, 07 Feb 2013, Matt Taggart wrote: > As pointed out in a previous message to the bug, #547092 > "nagios-nrpe-server: Insecure 'SSL' option, key identical for all > debian systems" is severity grave due to the security problem it > introduces in the service (but not critical since the problem

Bug#547092: nrpe ssl security problem

2013-02-07 Thread Christoph Anton Mitterer
On Thu, 2013-02-07 at 14:13 -0800, Matt Taggart wrote: > If this can't be solved, maybe we could recommend better > alternatives? The better alternative is using ssh with control channel multiplexing,... which is as fast as nrpe. The only thing missing there was a restricted shell for the remote

Bug#547092: nrpe ssl security problem

2013-02-07 Thread Matt Taggart
As pointed out in a previous message to the bug, #547092 "nagios-nrpe-server: Insecure 'SSL' option, key identical for all debian systems" is severity grave due to the security problem it introduces in the service (but not critical since the problem is limited to the nrpe service). I have adjusted