-
jfqd1jperkin: dnssec signing with algo 13 (ECDSAP256SHA256) with latest trunk powerdns update is now failimng with the following message:
-
jfqd1Exception building answer packet for example.com/SOA (Request to create key object for unknown algorithm number 13) sending out servfail
-
jfqd1Any idea what is causing this issue?
-
jfqd1The powerdns-4.6.4 package is nb9 so for me it is not clear what changed?!
-
jfqd1The last powerdns-4.6.4 package before the update was nb7.
-
jperkinopenssl 3.3.1 probably
-
jfqd1jperkin: ok, will try to move back to openssl 3.3.0. What is the best way to only uninstall openssl (nad not the dependencies) to pkg_add another version?
-
jperkinpkg_add -U /path/to/old/openssl.tgz
-
jfqd1jperkin: did a pkg_add -Dfu openssl-3.3.0nb1.tgz. But the problem with powerdns is still present (after the retart of the app).
-
jperkinok, must be something else then ;)
-
jesse_in other news, qualys.com/2024/07/01/cve-2024-6387/regresshion.txt
-
jesse_(remote exploit in openssh, poc for 32bit, no 64bit available yet)
-
neuroservebugzilla.redhat.com/show_bug.cgi?id=2294879#c0 <- openssh-server
-
bahamatYeah, we'll have a new PI coming up soon.
-
bahamatIt's worth noting "Exploitation on non-glibc systems is conceivable but has not been examined", and SmartOS is non-glibc.
-
bahamatSo it's currently not known to be vulnerable, but we're still assuming that it is and it's only a matter of time before someone figures it out. We'll likely have an updated PI out before a successful attack vector becomes known, even if someone is actively working on it now.
-
jperkinfwiw pkgsrc trunk is currently rebuilding with 9.8p1, I'll backport to LTS in turn
-
jperkinthough nobody in reality should be using openssh from pkgsrc
-
bahamatAnd if you're using LX or HVM, whatever goes on inside there is independent of the platform image. Follow your distro's guidance.
-
danmcdI'm trying to dig into it right now.
-
danmcdHey folks, We're respinning the platform image for 20240627 to #if-0-out the async-unsafe code like OmniOS. We hope to have 9.8 in 20240711.