From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from us-smtp-1.mimecast.com (us-smtp-delivery-1.mimecast.com [205.139.110.120]) by sourceware.org (Postfix) with ESMTP id 7274A3858D35 for ; Mon, 27 Jul 2020 06:17:18 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.3.2 sourceware.org 7274A3858D35 Received: from mimecast-mx01.redhat.com (mimecast-mx01.redhat.com [209.132.183.4]) (Using TLS) by relay.mimecast.com with ESMTP id us-mta-286-4bZKJ-koPwi0nkLHdVxUxQ-1; Mon, 27 Jul 2020 02:17:15 -0400 X-MC-Unique: 4bZKJ-koPwi0nkLHdVxUxQ-1 Received: from smtp.corp.redhat.com (int-mx06.intmail.prod.int.phx2.redhat.com [10.5.11.16]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by mimecast-mx01.redhat.com (Postfix) with ESMTPS id B187B8017FB for ; Mon, 27 Jul 2020 06:17:14 +0000 (UTC) Received: from oldenburg2.str.redhat.com (ovpn-112-104.ams2.redhat.com [10.36.112.104]) by smtp.corp.redhat.com (Postfix) with ESMTPS id 312E369327; Mon, 27 Jul 2020 06:17:10 +0000 (UTC) From: Florian Weimer To: Carlos O'Donell Cc: libc-alpha@sourceware.org Subject: Re: [PATCH] NEWS: Deprecate nss_hesiod References: <87a6zp7yxd.fsf@oldenburg2.str.redhat.com> <8720fa50-51ed-21c5-cc4e-8fc14fe84371@redhat.com> Date: Mon, 27 Jul 2020 08:17:08 +0200 In-Reply-To: <8720fa50-51ed-21c5-cc4e-8fc14fe84371@redhat.com> (Carlos O'Donell's message of "Fri, 24 Jul 2020 16:47:07 -0400") Message-ID: <87r1sx4h3v.fsf@oldenburg2.str.redhat.com> User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/26.3 (gnu/linux) MIME-Version: 1.0 X-Scanned-By: MIMEDefang 2.79 on 10.5.11.16 X-Mimecast-Spam-Score: 0 X-Mimecast-Originator: redhat.com Content-Type: text/plain X-Spam-Status: No, score=-7.2 required=5.0 tests=BAYES_00, DKIMWL_WL_HIGH, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, RCVD_IN_DNSWL_NONE, RCVD_IN_MSPIKE_H2, SPF_HELO_NONE, SPF_PASS, TXREP autolearn=ham autolearn_force=no version=3.4.2 X-Spam-Checker-Version: SpamAssassin 3.4.2 (2018-09-13) on server2.sourceware.org X-BeenThere: libc-alpha@sourceware.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: Libc-alpha mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 27 Jul 2020 06:17:19 -0000 * Carlos O'Donell: > On 7/24/20 10:47 AM, Florian Weimer via Libc-alpha wrote: >> Storing user databases in DNS, without client-side DNSSEC validation, >> is problematic from a security point of view. > > Hesiod could be handled as an external NSS module. Indeed, but we'll need a volunteer for that. > OK for 2.32. > > Reviewed-by: Carlos O'Donell Thanks, I will give others a day or two to comment on these deprecations, too. Florian