| Commit message (Collapse) | Author | Age | Files | Lines |
| |
|
|
| |
MFC After: 1 week
|
| |
|
|
|
|
|
| |
This is a residual of the $FreeBSD$ removal.
MFC After: 3 days (though I'll just run the command on the branches)
Sponsored by: Netflix
|
| |
|
|
| |
Remove /^\s*#[#!]?\s*\$FreeBSD\$.*$\n/
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
You should not be using DES. You should not have been using DES for the
past 30 years.
The ed DES-CBC scheme lacked several desirable properties of a sealed
document system, even ignoring DES itself. In particular, it did not
provide the "integrity" cryptographic property (detection of tampering), and
it treated ASCII passwords as 64-bit keys (instead of using a KDF like
scrypt or PBKDF2).
Some general approaches ed(1) users might consider to replace the removed
DES mode:
1. Full disk encryption with something like AES-XTS. This is easy to
conceptualize, design, and implement, and it provides confidentiality for
data at rest. Like CBC, it lacks tampering protection. Examples include
GELI, LUKS, FileVault2.
2. Encrypted overlay ("stackable") filesystems (EncFS, PEFS?, CryptoFS,
others).
3. Native encryption at the filesystem layer. Ext4/F2FS, ZFS, APFS, and
NTFS all have some flavor of this.
4. Storing your files unencrypted. It's not like DES was doing you much
good.
If you have DES-CBC scrambled files produced by ed(1) prior to this change,
you may decrypt them with:
openssl des-cbc -d -iv 0 -K <key in hex> -in <inputfile> -out <plaintext>
Reviewed by: allanjude, bapt, emaste
Sponsored by: Dell EMC Isilon
Differential Revision: https://reviews.freebsd.org/D17829
Notes:
svn path=/head/; revision=340132
|
| |
|
|
| |
Notes:
svn path=/head/; revision=312927
|
| |
|
|
| |
Notes:
svn path=/head/; revision=312926
|
| |
|
|
|
|
|
|
|
|
|
| |
Note: tcsh(1) has a MK_TCSH=no test, so this should be a separate
package, which requires pre-install/post-install scripts, to be
added later.
Sponsored by: The FreeBSD Foundation
Notes:
svn path=/projects/release-pkg/; revision=295439
|
| |
|
|
|
|
|
| |
static
Notes:
svn path=/head/; revision=275028
|
| |
|
|
|
|
|
|
|
|
|
|
| |
remove the now-redundant checks for RELEASE_CRUNCH. This originally
was defined for building smaller sysinstall images, but was later also
used by picobsd builds for a similar purpose. Now that we've moved
away from sysinstall, picobsd is the only remaining consumer of this
interface. Adding these two options reduces the RELEASE_CRUNCH
special cases in the tree by half.
Notes:
svn path=/head/; revision=267147
|
| |
|
|
|
|
|
| |
from the latter.
Notes:
svn path=/head/; revision=265420
|
| |
|
|
|
|
|
|
|
|
| |
ability to encrypt/decrypt files. Embedded systems can typically have
OpenSSL, but not for ed(1) to use it.
Obtained from: Juniper Networks, Inc.
Notes:
svn path=/head/; revision=235654
|
| |
|
|
|
|
|
|
|
|
|
| |
Although argc and argv are never read after the longjmp is complete,
gcc is not clever enough to see that and needlessly warns about it.
So add volatile to silence the compiler.
Approved by: ed (the co-mentor, not ed(1))
Notes:
svn path=/head/; revision=204711
|
| |
|
|
|
|
|
|
|
|
|
|
| |
This fixes its compilation if MK_OPENSSL == no and also obsoletes
release/Makefile rev. 1.192. The latter isn't reverted though as
support for the fixit floppy and the rest of the boot floppies is
scheduled to be deorbited anyway.
Discussed with: kensmith
Notes:
svn path=/head/; revision=174469
|
| |
|
|
|
|
|
|
|
|
| |
"rescue media" bundled with releases.
Suggested by: ru
Approved by: re (hrs)
Notes:
svn path=/head/; revision=171154
|
| |
|
|
|
|
|
|
|
|
|
| |
http://lists.freebsd.org/pipermail/freebsd-current/2006-March/061725.html
The src.conf(5) manpage is to follow in a few days.
Brought to you by: imp, jhb, kris, phk, ru (all bugs are mine)
Notes:
svn path=/head/; revision=156813
|
| |
|
|
| |
Notes:
svn path=/head/; revision=139113
|
| |
|
|
|
|
|
|
|
|
|
|
|
| |
of releases. The -DNOCRYPT build option still exists for anyone who
really wants to build non-cryptographic binaries, but the "crypto"
release distribution is now part of "base", and anyone installing from a
release will get cryptographic binaries.
Approved by: re (scottl), markm
Discussed on: freebsd-current, in late April 2004
Notes:
svn path=/head/; revision=133196
|
| |
|
|
|
|
|
|
| |
may contain crypto. The days of ITAR paranoia are over, and the simple
macro tests that remain are sufficient.
Notes:
svn path=/head/; revision=117978
|
| |
|
|
|
|
|
|
| |
due to bugs in OpenSSL headers. I was testing in the wrong
environmement: standalone build without crypto/ sources.
Notes:
svn path=/head/; revision=117805
|
| |
|
|
|
|
|
| |
Submitted by: Marius Strobl <marius@alchemy.franken.de>
Notes:
svn path=/head/; revision=117803
|
| |
|
|
|
|
|
| |
Reviewed by: markm
Notes:
svn path=/head/; revision=117023
|
| |
|
|
|
|
|
|
|
|
| |
Obsolete WFORMAT= junk also removed where possible.
OK'ed by: obrien
Tested on: sparc64, alpha, i386
Notes:
svn path=/head/; revision=116282
|
| |
|
|
|
|
|
| |
Reported by: Marius Strobl <marius@alchemy.franken.de>
Notes:
svn path=/head/; revision=116015
|
| |
|
|
| |
Notes:
svn path=/head/; revision=115717
|
| |
|
|
|
|
|
| |
Approved by: re (scottl)
Notes:
svn path=/head/; revision=115157
|
| |
|
|
| |
Notes:
svn path=/head/; revision=87444
|
| |
|
|
|
|
|
|
|
| |
set WARNS=0.
Reviewed by: mike
Notes:
svn path=/head/; revision=87323
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
| |
o Add consts where appropriate.
o Rename some variables that were shadowing global declarations.
o Remove register storage-classes.
o Make errmsg a const, so we can just set error messages instead
of using sprintf/strcpy.
o Set WARNS=2
Reviewed by: bde, des
Notes:
svn path=/head/; revision=81220
|
| |
|
|
| |
Notes:
svn path=/head/; revision=57622
|
| |
|
|
| |
Notes:
svn path=/head/; revision=50471
|
| |
|
|
|
|
|
| |
Fixed some formatting.
Notes:
svn path=/head/; revision=34135
|
| |
|
|
| |
Notes:
svn path=/head/; revision=22988
|
| |
|
|
|
|
|
|
|
|
|
| |
This will make a number of things easier in the future, as well as (finally!)
avoiding the Id-smashing problem which has plagued developers for so long.
Boy, I'm glad we're not using sup anymore. This update would have been
insane otherwise.
Notes:
svn path=/head/; revision=21673
|
| |
|
|
| |
Notes:
svn path=/head/; revision=11684
|
| |
|
|
|
|
|
| |
Pointed out by: bde
Notes:
svn path=/head/; revision=11149
|
| |
|
|
|
|
|
|
| |
will allow the secure/bin/ed directory to be cleaned out and the bin/Makefile
to be cleaned up.
Notes:
svn path=/head/; revision=11106
|
| |
|
|
|
|
|
| |
for secure/bin/ed ...
Notes:
svn path=/head/; revision=5155
|
| |
|
|
|
|
|
| |
instead check that "NOCRYPT" isn't defined.
Notes:
svn path=/head/; revision=3989
|
| |
|
|
| |
Notes:
svn path=/head/; revision=3044
|
| |
|
|
| |
Notes:
svn path=/head/; revision=1297
|
| |
|
|
|
|
|
|
| |
Overhauled the name space, reworked some modules and removed the
obsolescent Addison-Wesley copyright.
Notes:
svn path=/head/; revision=1057
|
| |
|
|
|
|
|
| |
removed REGEX directive
Notes:
svn path=/head/; revision=268
|
| |
|
|
| |
Notes:
svn path=/head/; revision=229
|
| |
|
|
| |
Notes:
svn path=/head/; revision=227
|
| |
|
|
| |
Notes:
svn path=/head/; revision=171
|
|
|
Notes:
svn path=/cvs2svn/branches/unlabeled-1.1.1/; revision=16
|