|
Revision tags: release/13.4.0-p5, release/13.5.0-p1, release/14.2.0-p3, release/13.5.0, release/14.2.0-p2, release/14.1.0-p8, release/13.4.0-p4, release/14.1.0-p7, release/14.2.0-p1, release/13.4.0-p3, release/14.2.0, release/13.4.0, release/14.1.0, release/13.3.0, release/14.0.0 |
|
| #
d0b2dbfa |
| 16-Aug-2023 |
Warner Losh <[email protected]> |
Remove $FreeBSD$: one-line sh pattern
Remove /^\s*#[#!]?\s*\$FreeBSD\$.*$\n/
|
|
Revision tags: release/13.2.0, release/12.4.0, release/13.1.0, release/12.3.0, release/13.0.0, release/12.2.0, release/11.4.0, release/12.1.0, release/11.3.0, release/12.0.0 |
|
| #
d83db3fb |
| 04-Nov-2018 |
Conrad Meyer <[email protected]> |
Drop ed(1) "crypto"
You should not be using DES. You should not have been using DES for the past 30 years.
The ed DES-CBC scheme lacked several desirable properties of a sealed document system, ev
Drop ed(1) "crypto"
You should not be using DES. You should not have been using DES for the past 30 years.
The ed DES-CBC scheme lacked several desirable properties of a sealed document system, even ignoring DES itself. In particular, it did not provide the "integrity" cryptographic property (detection of tampering), and it treated ASCII passwords as 64-bit keys (instead of using a KDF like scrypt or PBKDF2).
Some general approaches ed(1) users might consider to replace the removed DES mode:
1. Full disk encryption with something like AES-XTS. This is easy to conceptualize, design, and implement, and it provides confidentiality for data at rest. Like CBC, it lacks tampering protection. Examples include GELI, LUKS, FileVault2.
2. Encrypted overlay ("stackable") filesystems (EncFS, PEFS?, CryptoFS, others).
3. Native encryption at the filesystem layer. Ext4/F2FS, ZFS, APFS, and NTFS all have some flavor of this.
4. Storing your files unencrypted. It's not like DES was doing you much good.
If you have DES-CBC scrambled files produced by ed(1) prior to this change, you may decrypt them with:
openssl des-cbc -d -iv 0 -K <key in hex> -in <inputfile> -out <plaintext>
Reviewed by: allanjude, bapt, emaste Sponsored by: Dell EMC Isilon Differential Revision: https://reviews.freebsd.org/D17829
show more ...
|
|
Revision tags: release/11.2.0, release/10.4.0, release/11.1.0 |
|
| #
b4b4b530 |
| 28-Jan-2017 |
Baptiste Daroussin <[email protected]> |
Revert crap accidentally committed
|
| #
814aaaa7 |
| 28-Jan-2017 |
Baptiste Daroussin <[email protected]> |
Revert r312923 a better approach will be taken later
|
|
Revision tags: release/11.0.1, release/11.0.0, release/10.3.0 |
|
| #
ac2875fa |
| 09-Feb-2016 |
Glen Barber <[email protected]> |
Explicitly add unmarked bin/ binaries to the runtime package. Note: tcsh(1) has a MK_TCSH=no test, so this should be a separate package, which requires pre-install/post-install scripts, to be added l
Explicitly add unmarked bin/ binaries to the runtime package. Note: tcsh(1) has a MK_TCSH=no test, so this should be a separate package, which requires pre-install/post-install scripts, to be added later.
Sponsored by: The FreeBSD Foundation
show more ...
|
|
Revision tags: release/10.2.0 |
|
| #
12cd1730 |
| 25-Nov-2014 |
Baptiste Daroussin <[email protected]> |
Convert bin/ to LIBADD, reduce overlinking allow to build all components as static
|
|
Revision tags: release/10.1.0, release/9.3.0 |
|
| #
04efeffe |
| 06-Jun-2014 |
Warner Losh <[email protected]> |
When building picobsd, define WITHOUT_OPENSSL and WITHOUT_KERBEROS and remove the now-redundant checks for RELEASE_CRUNCH. This originally was defined for building smaller sysinstall images, but was
When building picobsd, define WITHOUT_OPENSSL and WITHOUT_KERBEROS and remove the now-redundant checks for RELEASE_CRUNCH. This originally was defined for building smaller sysinstall images, but was later also used by picobsd builds for a similar purpose. Now that we've moved away from sysinstall, picobsd is the only remaining consumer of this interface. Adding these two options reduces the RELEASE_CRUNCH special cases in the tree by half.
show more ...
|
| #
c6063d0d |
| 06-May-2014 |
Warner Losh <[email protected]> |
Use src.opts.mk in preference to bsd.own.mk except where we need stuff from the latter.
|
|
Revision tags: release/10.0.0, release/9.2.0, release/8.4.0, release/9.1.0 |
|
| #
aa39c447 |
| 19-May-2012 |
Marcel Moolenaar <[email protected]> |
Add build option MK_ED_CRYPTO to control whether ed(1) is to have the ability to encrypt/decrypt files. Embedded systems can typically have OpenSSL, but not for ed(1) to use it.
Obtained from: Junip
Add build option MK_ED_CRYPTO to control whether ed(1) is to have the ability to encrypt/decrypt files. Embedded systems can typically have OpenSSL, but not for ed(1) to use it.
Obtained from: Juniper Networks, Inc.
show more ...
|
|
Revision tags: release/8.3.0_cvs, release/8.3.0, release/9.0.0, release/7.4.0_cvs, release/8.2.0_cvs, release/7.4.0, release/8.2.0, release/8.1.0_cvs, release/8.1.0, release/7.3.0_cvs, release/7.3.0 |
|
| #
55fa734d |
| 04-Mar-2010 |
Ulrich Spörlein <[email protected]> |
ed(1): make WARNS=6 clean
Although argc and argv are never read after the longjmp is complete, gcc is not clever enough to see that and needlessly warns about it. So add volatile to silence the comp
ed(1): make WARNS=6 clean
Although argc and argv are never read after the longjmp is complete, gcc is not clever enough to see that and needlessly warns about it. So add volatile to silence the compiler.
Approved by: ed (the co-mentor, not ed(1))
show more ...
|
|
Revision tags: release/8.0.0_cvs, release/8.0.0, release/7.2.0_cvs, release/7.2.0, release/7.1.0_cvs, release/7.1.0, release/6.4.0_cvs, release/6.4.0, release/7.0.0_cvs, release/7.0.0, release/6.3.0_cvs, release/6.3.0 |
|
| #
ea7f7bde |
| 09-Dec-2007 |
Marius Strobl <[email protected]> |
Move WARNS as ed(1) also is only WARNS = 2 clean in the !DES case. This fixes its compilation if MK_OPENSSL == no and also obsoletes release/Makefile rev. 1.192. The latter isn't reverted though as s
Move WARNS as ed(1) also is only WARNS = 2 clean in the !DES case. This fixes its compilation if MK_OPENSSL == no and also obsoletes release/Makefile rev. 1.192. The latter isn't reverted though as support for the fixit floppy and the rest of the boot floppies is scheduled to be deorbited anyway.
Discussed with: kensmith
show more ...
|
| #
0c0146f0 |
| 02-Jul-2007 |
Ken Smith <[email protected]> |
Don't include encryption features of ed(1) when building for the "rescue media" bundled with releases.
Suggested by: ru Approved by: re (hrs)
|
|
Revision tags: release/6.2.0_cvs, release/6.2.0, release/5.5.0_cvs, release/5.5.0, release/6.1.0_cvs, release/6.1.0 |
|
| #
e1fe3dba |
| 17-Mar-2006 |
Ruslan Ermilov <[email protected]> |
Reimplementation of world/kernel build options. For details, see:
http://lists.freebsd.org/pipermail/freebsd-current/2006-March/061725.html
The src.conf(5) manpage is to follow in a few days.
Bro
Reimplementation of world/kernel build options. For details, see:
http://lists.freebsd.org/pipermail/freebsd-current/2006-March/061725.html
The src.conf(5) manpage is to follow in a few days.
Brought to you by: imp, jhb, kris, phk, ru (all bugs are mine)
show more ...
|
|
Revision tags: release/6.0.0_cvs, release/6.0.0, release/5.4.0_cvs, release/5.4.0, release/4.11.0_cvs, release/4.11.0 |
|
| #
a2161735 |
| 21-Dec-2004 |
Ruslan Ermilov <[email protected]> |
NOCRYPT -> NO_CRYPT
|
|
Revision tags: release/5.3.0_cvs, release/5.3.0 |
|
| #
d37df47d |
| 06-Aug-2004 |
Colin Percival <[email protected]> |
Join the 21st century: Cryptography is no longer an optional component of releases. The -DNOCRYPT build option still exists for anyone who really wants to build non-cryptographic binaries, but the "
Join the 21st century: Cryptography is no longer an optional component of releases. The -DNOCRYPT build option still exists for anyone who really wants to build non-cryptographic binaries, but the "crypto" release distribution is now part of "base", and anyone installing from a release will get cryptographic binaries.
Approved by: re (scottl), markm Discussed on: freebsd-current, in late April 2004
show more ...
|
|
Revision tags: release/4.10.0_cvs, release/4.10.0, release/5.2.1_cvs, release/5.2.1, release/5.2.0_cvs, release/5.2.0, release/4.9.0_cvs, release/4.9.0 |
|
| #
ebb9f0ef |
| 24-Jul-2003 |
Mark Murray <[email protected]> |
Don't check for the existance of src/crypto/ for building items that may contain crypto. The days of ITAR paranoia are over, and the simple macro tests that remain are sufficient.
|
| #
8fe29a4f |
| 20-Jul-2003 |
Ruslan Ermilov <[email protected]> |
This code isn't WARNS=6 clean in the standard (crypto) case due to bugs in OpenSSL headers. I was testing in the wrong environmement: standalone build without crypto/ sources.
|
| #
ff572a5e |
| 20-Jul-2003 |
Ruslan Ermilov <[email protected]> |
Make this code WARNS=6 clean again (after GCC 3.1.1 import).
Submitted by: Marius Strobl <[email protected]>
|
| #
ce17762f |
| 29-Jun-2003 |
Ruslan Ermilov <[email protected]> |
Unbreak NOCRYPT buildworld.
Reviewed by: markm
|
| #
eac4bdcc |
| 13-Jun-2003 |
Mark Murray <[email protected]> |
Get this area compiling with the highest WARNS= that it works with. Obsolete WFORMAT= junk also removed where possible.
OK'ed by: obrien Tested on: sparc64, alpha, i386
|
| #
8027fe39 |
| 08-Jun-2003 |
Mark Murray <[email protected]> |
Fix for the NO_OPENSSL case.
Reported by: Marius Strobl <[email protected]>
|
|
Revision tags: release/5.1.0_cvs, release/5.1.0 |
|
| #
eb338d36 |
| 02-Jun-2003 |
Mark Murray <[email protected]> |
Modernise. Use libcrypto for DES instead of libcipher.
|
| #
7691f66a |
| 19-May-2003 |
Dag-Erling Smørgrav <[email protected]> |
Retire the useless NOSECURE knob.
Approved by: re (scottl)
|
|
Revision tags: release/4.8.0_cvs, release/4.8.0, release/5.0.0_cvs, release/5.0.0, release/4.7.0_cvs, release/4.6.2_cvs, release/4.6.2, release/4.6.1, release/4.6.0_cvs, release/4.5.0_cvs, release/4.4.0_cvs |
|
| #
aa70e98b |
| 06-Dec-2001 |
Ruslan Ermilov <[email protected]> |
-lcipher is an installable library.
|
| #
a7482907 |
| 04-Dec-2001 |
David E. O'Brien <[email protected]> |
Default to WARNS=2. Binary builds that cannot handle this must explicitly set WARNS=0.
Reviewed by: mike
|