Comment 13 for bug 307019

Revision history for this message
Kees Cook (kees) wrote :

Milan: sorry I can cam eoff harsh, we've just had a lot of technical problems with g-s-t and how it handles passwords. James detailed the primary problem. As an earlier work-around, we had to force it to correctly select the system's password hashing algorithm, which it had not been doing correctly either.

As to how to pass the clear-text password, I like the idea of pipes or fds, as those are well-prove and light-weight. negotiating SSL over dbus seems over-engineered for this situation. If permissions to the pipe can be correctly managed by stb, the named pipe for gst to write to (with the name passed over dbus?) seems like the best match for this?