LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware
User Name
Password
Slackware This Forum is for the discussion of Slackware Linux.

Notices


Reply
  Search this Thread
Old 02-12-2020, 08:01 AM   #16
Tonus
Senior Member
 
Registered: Jan 2007
Location: Paris, France
Distribution: Slackware-15.0
Posts: 1,405
Blog Entries: 3

Rep: Reputation: 514Reputation: 514Reputation: 514Reputation: 514Reputation: 514Reputation: 514
The day Slackware meets PAM: Wed Feb 12 05:05:50 UTC 2020


First problem to report : our friends Pamela will have some trouble with their own packages naming.
 
Old 02-12-2020, 08:44 AM   #17
orbea
Senior Member
 
Registered: Feb 2015
Distribution: Slackware64-current
Posts: 1,950

Rep: Reputation: Disabled
Just a word of advice, its pretty terrible idea for security to hook pam into everything. Like the changelog says, this is a much bigger attack surface and doesn't really gain anything for most users. If it really must be added it should be done only where absolutely necessary, but even then I doubt most users will gain any benefits.
 
4 members found this post helpful.
Old 02-12-2020, 08:46 AM   #18
hua
Member
 
Registered: Oct 2006
Location: Slovak Republic
Distribution: Slackware 14.2, current
Posts: 461

Rep: Reputation: 78
Quote:
Next we need to be looking at Xfce 4.14 and Plasma 5.18 LTS
Yes, good news. Getting closer definitely
 
1 members found this post helpful.
Old 02-12-2020, 09:06 AM   #19
Gerard Lally
Senior Member
 
Registered: Sep 2009
Location: Leinster, IE
Distribution: Slackware, NetBSD
Posts: 2,177

Rep: Reputation: 1761Reputation: 1761Reputation: 1761Reputation: 1761Reputation: 1761Reputation: 1761Reputation: 1761Reputation: 1761Reputation: 1761Reputation: 1761Reputation: 1761
Quote:
Originally Posted by orbea View Post
Just a word of advice, its pretty terrible idea for security to hook pam into everything. Like the changelog says, this is a much bigger attack surface and doesn't really gain anything for most users. If it really must be added it should be done only where absolutely necessary, but even then I doubt most users will gain any benefits.
I'm not familiar with PAM. Can you be more specific? I use SSH, OpenVPN and StrongSwan. Does the inclusion of PAM compromise them, or render them less secure? Does it make these specific targets bigger and easier to hit?
 
Old 02-12-2020, 09:17 AM   #20
hitest
Guru
 
Registered: Mar 2004
Location: Canada
Distribution: Void, Debian, Slackware
Posts: 7,342

Rep: Reputation: 3746Reputation: 3746Reputation: 3746Reputation: 3746Reputation: 3746Reputation: 3746Reputation: 3746Reputation: 3746Reputation: 3746Reputation: 3746Reputation: 3746
Cool

Quote:
Originally Posted by hua View Post
Yes, good news. Getting closer definitely
Absolutely! Many thanks to Mr. Volkerding and the Slackware Team.
 
2 members found this post helpful.
Old 02-12-2020, 10:02 AM   #21
kikinovak
MLED Founder
 
Registered: Jun 2011
Location: Montpezat (South France)
Distribution: CentOS, OpenSUSE
Posts: 3,453

Rep: Reputation: 2154Reputation: 2154Reputation: 2154Reputation: 2154Reputation: 2154Reputation: 2154Reputation: 2154Reputation: 2154Reputation: 2154Reputation: 2154Reputation: 2154
Quote:
Originally Posted by orbea View Post
Just a word of advice, its pretty terrible idea for security to hook pam into everything. Like the changelog says, this is a much bigger attack surface and doesn't really gain anything for most users. If it really must be added it should be done only where absolutely necessary, but even then I doubt most users will gain any benefits.
Three technologies with a very reduced attack surface:
  • Pocket calculator
  • Abacus
  • Letter opener

 
1 members found this post helpful.
Old 02-12-2020, 10:22 AM   #22
cwizardone
LQ Veteran
 
Registered: Feb 2007
Distribution: Slackware64-current with "True Multilib" and KDE4Town.
Posts: 9,097

Rep: Reputation: 7275Reputation: 7275Reputation: 7275Reputation: 7275Reputation: 7275Reputation: 7275Reputation: 7275Reputation: 7275Reputation: 7275Reputation: 7275Reputation: 7275
Quote:
Originally Posted by GazL View Post
Just installed them all. Nothing obvious broke here.........
Ditto.
It seems to be completely transparent (to this "end user").
 
Old 02-12-2020, 10:49 AM   #23
chemfire
Member
 
Registered: Sep 2012
Posts: 422

Rep: Reputation: Disabled
Quote:
Originally Posted by orbea View Post
Just a word of advice, its pretty terrible idea for security to hook pam into everything. Like the changelog says, this is a much bigger attack surface and doesn't really gain anything for most users. If it really must be added it should be done only where absolutely necessary, but even then I doubt most users will gain any benefits.
PAM is not all that complex a beast; in fact the code to check authorization against PAM is in most cases simpler than other means. PAM has been around a long time and has had a lot of eyes. Remember it stands for Pluggable Authentication Modules, I will grant you if you start using lots of low-quality modules and make highly complex rules about them, you might end up less secure. If you are using Pat's out of box config (I have not looked yet but I assume) that is just going after local files passwd/group/shadow than I really don't see how you can make a credible claim the security posture is appreciably different, at least in a negative way, than the way things were before yesterday.
 
6 members found this post helpful.
Old 02-12-2020, 10:49 AM   #24
denydias
Member
 
Registered: Dec 2013
Distribution: Slackware
Posts: 297

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by hua View Post
Yes, good news. Getting closer definitely
Eric has also made his move:

Quote:
Tue Feb 11 19:33:45 UTC 2020
Here is KDE 5_20.02 for Slackware, consisting of the KDE Frameworks 5.67.0,
Plasma 5.18.0 and Applications 19.12.2. All this on top of Qt 5.13.2.
The ktown updates are targeting Slackware -current only.
Updates of the KDE 5 package sets for Slackware 14.2 have come to an end.
Upgrading from the previous 5_20.01 is straight-forward.
Read the accompanying README file for detailed installation and
upgrade instructions!
Note: the KDE 5_20.02 'testing' repository contains PAM support and is
meant to be used with the PAM packages in Slackware-current's '/testing'!
Upgrading now, but I'll left tests for the time when they reach -current tree (can't break anything now as I'm too busy with work).
 
2 members found this post helpful.
Old 02-12-2020, 11:48 AM   #25
bw42
Member
 
Registered: Feb 2011
Distribution: Slackware
Posts: 65

Rep: Reputation: 51
This is great.

Will cut down on the number of packages I have to maintain my own builds of to use Slackware with my domain at home.

Just kicked off upgrade-all on my desktop at home, hopefully it works when I get out of work.
 
Old 02-12-2020, 12:49 PM   #26
upnort
Senior Member
 
Registered: Oct 2014
Distribution: Slackware
Posts: 1,893

Rep: Reputation: 1161Reputation: 1161Reputation: 1161Reputation: 1161Reputation: 1161Reputation: 1161Reputation: 1161Reputation: 1161Reputation: 1161
So it begins....

Excited to see the watershed moment arrive!
 
5 members found this post helpful.
Old 02-12-2020, 01:29 PM   #27
ChuangTzu
Senior Member
 
Registered: May 2015
Location: Where ever needed
Distribution: Slackware/Salix while testing others
Posts: 1,718

Rep: Reputation: 1857Reputation: 1857Reputation: 1857Reputation: 1857Reputation: 1857Reputation: 1857Reputation: 1857Reputation: 1857Reputation: 1857Reputation: 1857Reputation: 1857
Quote:
Originally Posted by upnort View Post
So it begins....

Excited to see the watershed moment arrive!
Didn't know PAM was so beastly looking...now the unmentionable daemon to rule them all, well.....
 
Old 02-12-2020, 01:54 PM   #28
volkerdi
Slackware Maintainer
 
Registered: Dec 2002
Location: Minnesota
Distribution: Slackware! :-)
Posts: 2,504

Rep: Reputation: 8461Reputation: 8461Reputation: 8461Reputation: 8461Reputation: 8461Reputation: 8461Reputation: 8461Reputation: 8461Reputation: 8461Reputation: 8461Reputation: 8461
Quote:
Originally Posted by ChuangTzu View Post
Didn't know PAM was so beastly looking...now the unmentionable daemon to rule them all, well.....
If our adoption of PAM is any indication, you won't need to worry about that for 23 years.
 
27 members found this post helpful.
Old 02-12-2020, 02:15 PM   #29
denydias
Member
 
Registered: Dec 2013
Distribution: Slackware
Posts: 297

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by volkerdi View Post
If our adoption of PAM is any indication, you won't need to worry about that for 23 years.
Touché, Monsieur PV.
 
1 members found this post helpful.
Old 02-12-2020, 02:37 PM   #30
GazL
LQ Veteran
 
Registered: May 2008
Posts: 6,897

Rep: Reputation: 5019Reputation: 5019Reputation: 5019Reputation: 5019Reputation: 5019Reputation: 5019Reputation: 5019Reputation: 5019Reputation: 5019Reputation: 5019Reputation: 5019
Quote:
Originally Posted by upnort View Post
I see your Theoden and raise you a Kosh:
And so it begins

Last edited by GazL; 02-12-2020 at 02:38 PM.
 
3 members found this post helpful.
  


Reply

Tags
kde, pam, slackware, xfce



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Current64 - Changes Wed Jan 9 03:21:06 UTC 2019 - cups and gutenprint burdi01 Slackware 1 01-11-2019 04:02 AM
[SOLVED] Wed Jun 13 05:43:00 UTC 2018 and Newer Current bare metal install? AlleyTrotter Slackware 28 06-24-2018 02:36 PM
slackware-current breakage of MTP after [Wed May 23 04:42:29 UTC 2018] update lord_ Slackware 6 06-13-2018 05:34 AM
[SOLVED] Centos7, invalid offset for UTC for Sweden, says UTC+00 Basher52 CentOS 14 02-09-2018 10:10 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware

All times are GMT -5. The time now is 12:08 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration