Re: [PATCH] Check files' signatures before doing suid/sgid [2/4]

2007-06-25 Thread Satyam Sharma
On 6/26/07, Alexander Wuerstlein <[EMAIL PROTECTED]> wrote: [...] Nope. I unluckily wrote 'userspace' where I should have said something else: Chain-of-trust is handled in what I would label 'Adminspace' (Where we do the signing as in points 1 and 2). There is a very small number of signatures (i

Re: [PATCH] Check files' signatures before doing suid/sgid [2/4]

2007-06-25 Thread Alexander Wuerstlein
On 070626 01:56, Satyam Sharma <[EMAIL PROTECTED]> wrote: > On 6/25/07, Alexander Wuerstlein > <[EMAIL PROTECTED]> wrote: >> On 070622 21:40, Satyam Sharma <[EMAIL PROTECTED]> wrote: >> > [...] >> We decided against >> altering the file itself for that and some other reasons. >> The limitation to s

Re: [PATCH] Check files' signatures before doing suid/sgid [2/4]

2007-06-25 Thread Satyam Sharma
On 6/25/07, Alexander Wuerstlein <[EMAIL PROTECTED]> wrote: On 070622 21:40, Satyam Sharma <[EMAIL PROTECTED]> wrote: > [...] > But first: Have you checked the digsig project? It's been doing > (for some time) what your current patchset proposes -- and > it uses public key cryptosystems for the k

combined mode algorithms

2007-06-25 Thread Joy Latten
I have been reading IP Encapsulating Payload-(ESP) RFC4303 where use of combined mode algorithms are mentioned and accommodated for. In trying to determine how I should handle this, I examined the crypto code and could not readily recognize any combined mode algorithms. Are there any current plans