Subject: Re: security/21983: [RFE] install /etc/moduli utilities qsieve + qsafe
To: William Allen Simpson <wsimpson@greendragon.com>
From: Luke Mewburn <lukem@netbsd.org>
List: tech-security
Date: 07/01/2003 10:31:08
On Mon, Jun 30, 2003 at 04:12:55AM -0400, William Allen Simpson wrote:
  | Luke Mewburn wrote:
  | > 
  | > On Sun, Jun 29, 2003 at 02:38:12PM -0400, William Allen Simpson wrote:
  | >   | Since I haven't heard anything from filing the PR, I'll try an open
  | >   | list.  The file /etc/moduli was/is generated by a couple of programs,
  | >   | originally part of Photuris.  The file is still used by OpenSSH.
  | >   |
  | >   | Technically, they are homeless.  Where should they be housed?
  | >   |
  | >   | They should be used from time to time to update the moduli.  They
  | >   | aren't actually "crypto".  But the moduli.5 definition is with ssh.
  | > 
  | > Is there a current canonical location for the source to these two programs?
  | > 
  | As I mentioned in the PR, they've been posted to Perry's Cryptography 
  | list, and were used to generate the existing OpenSSH /etc/moduli file
  | (used to be in OpenBSD's /etc/photuris/primes some time ago).  But the 
  | utilities themselves were just tools, never part of the OpenSSH package.  
  | Although I originally wrote the moduli.5 man page for them, and that 
  | *has* been added to OpenSSH (by Provos).

Can you provide a canonical location (or even better, a uu- or base64-
encoded .tar.gz file) with these?

Statements such as "I posted these to a mailing list a few years ago"
doesn't really inspire us to spend a chunk of time to run around looking
for the software;  as you know this is a volunteer project, and we only
have so many hours in the day to work on this stuff, so making it
easier for us to perform your request significantly increases the
likelyhood we'll work on it sooner :-)

Thanks,
Luke.