Subject: Re: icmp patches
To: None <tech-security@netbsd.org>
From: Christos Zoulas <christos@astron.com>
List: tech-security
Date: 07/10/2005 07:29:08
In article <6.2.0.14.0.20050709234152.0342aa10@pop.frh.utn.edu.ar>,
Fernando Gont <fernando@gont.com.ar> wrote:
>At 12:32 a.m. 09/07/2005, Christos Zoulas wrote:
>
>>I ported the icmp patches from OpenBSD that fix the problems described in:
>>
>> http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html
>>
>>Please let me know what you think.
>
>I see he fixes are within ifdefs. What will be the default? i.e., the fixes
>will be "on" by default, or not?
>
>I strongly recommend that the fix is on by default, unless you expect the
>users to read a 20-page internet-draft just to make an informed decision
>themselves.
Hi Fernando,
The changes are within ifdefs so that it is easy to turn them on and off
during testing. The ifdefs will go away once the code is committed.
Regards,
christos