echolot terminates at expired DSA key
Peter Palfrader
peter@palfrader.org
Mon, 13 Jan 2003 01:39:48 +0100
--mYYhpFXgKVw71fwr
Content-Type: text/plain; charset=iso-8859-15
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable
On Mon, 13 Jan 2003, Peter Palfrader wrote:
> On Sun, 12 Jan 2003, Frell Remailer Admins wrote:
>=20
> > Echolot daemon terminates silently when it tries to ping a remailer wit=
h an=20
> > expired DSA-Key. Last line in the log is always:
> > "ping calling cpunk-dsa, remailer@shellgame.abditum.com, 1741C41DDA1D66=
31"
> >=20
> > This remailer holds expired keys and echolot probably doesn't cope with=
=20
> > GnuPGs warning message.
> >=20
> > I can reproduce this, though I don't get any error messages, neither fr=
om=20
> > echolot nor does the grsec-kernel log a segfault:
> >=20
> > echolot@drow:/var/lib/echolot# ps ux|grep pingd
> > echolot 2674 1.1 6.6 12076 10552 ? S 14:01 0:15 pingd [s=
leeping]
> > echolot 32695 0.0 0.3 1544 488 pts/10 S 14:23 0:00 grep pin=
gd
> >=20
> > echolot@drow:/var/lib/echolot# pingd sendpings remailer@shellgame.abdit=
um.com
> >=20
> > echolot@drow:/var/lib/echolot# ps ux|grep pingd
> > echolot 21162 0.0 0.3 1544 484 pts/10 S 14:23 0:00 grep pin=
gd
> >=20
> >=20
> > Has anyone seen the same behaviour?
>=20
> Yes, I did. But I've so far I haven't been able to find out when or why
> exactly it dies. Because sending to bad keys works most of the time,
> but not always. Echolot dies when printing messages to gnupg's stdin if
> it doesn't work. I blame GnuPG::Interface until I can prove its
> innocense :) I also hope to find a work around or fix soon - patches
> apprechiated.
I have checked in a workaround into CVS. If anybody wants to test it,
I'ld apprechiate the feedback.
yours,
peter
[If you've downloaded my PGP key before please redownload it for I've
changed cipher preferences: gpg --keyserver pgp.dtype.org --recv 94c09c7f]
--=20
PGP signed and encrypted | .''`. ** Debian GNU/Linux **
messages preferred. | : :' : The universal
| `. `' Operating System
http://www.palfrader.org/ | `- http://www.debian.org/
--mYYhpFXgKVw71fwr
Content-Type: application/pgp-signature
Content-Disposition: inline
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.2rc1 (GNU/Linux)
iD8DBQE+IgrU3nqvbpTAnH8RAow3AKDNPr9kUry2X4/yWUU9Q5kr7oMvvgCgvQCC
v2O9/2wDiArkI7qgnVAC4zs=
=fhFV
-----END PGP SIGNATURE-----
--mYYhpFXgKVw71fwr--