Re: Oaf default build...



On 29 May 2000, Miguel de Icaza wrote:

> The other security concern is that in the past a connection was tagged
> as hostile until the client authenticated itself.  ORBit would run in
> prevent-hostility mode until the cookie was received.
> 
> This mode basically meant that data and messages were limited in the
> size that ORBit would accept.  Like for instance, until a client is
> authenticated, we did not allow buffers bigger than 128k to be
> transfered.

(Addendum to previous message - UNIX socket connections are always marked
authenticated.)

Nobody has come up with a better solution, and I do not feel comfortable
removing this solution (perfect or not) to a known problem.

-- Elliot
"Moron of the week" for four years running





[Date Prev][Date Next]   [Thread Prev][Thread Next]   [Thread Index] [Date Index] [Author Index]