From alanc@sac.sfbay.sun.com Mon Sep 14 18:57:42 2009
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n8F1vfVG014871
	for <LSARC-ext@sac.sfbay.sun.com>; Mon, 14 Sep 2009 18:57:42 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id n8F1vefD028907;
	Tue, 15 Sep 2009 02:57:40 +0100 (BST)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KPZ00201PG4YB00@nwk-avmta-1.sfbay.Sun.COM>; Mon,
 14 Sep 2009 18:57:40 -0700 (PDT)
Received: from dm-sfbay-02.sfbay.sun.com ([129.146.11.31])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KPZ00C3FPG41B60@nwk-avmta-1.sfbay.Sun.COM>; Mon,
 14 Sep 2009 18:57:40 -0700 (PDT)
Received: from sac.sfbay.sun.com (sac.SFBay.Sun.COM [129.146.226.132])
	by dm-sfbay-02.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id n8F1vdSm038836; Mon, 14 Sep 2009 18:57:39 -0700 (PDT)
Received: from sac.sfbay.sun.com (localhost [127.0.0.1])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n8F1vcc3014866; Mon,
 14 Sep 2009 18:57:38 -0700 (PDT)
Received: (from alanc@localhost)
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8/Submit) id n8F1vctH014862; Mon,
 14 Sep 2009 18:57:38 -0700 (PDT)
Date: Mon, 14 Sep 2009 18:57:38 -0700 (PDT)
From: Alan Coopersmith <alan.coopersmith@sun.com>
Subject: Synergy - Mouse/Keyboard sharing [LSARC/2009/489 FastTrack timeout
 09/21/2009]
To: LSARC-ext@sun.com
Cc: Stuart.Kreitman@sun.com
Message-id: <200909150157.n8F1vctH014862@sac.sfbay.sun.com>
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
Status: RO
Content-Length: 18617

I am sponsoring this case for Stuart Kreitman of the X team.
The timeout is set for next Monday, Sept. 21, 2009.

	-Alan Coopersmith-           alan.coopersmith@sun.com
	 Sun Microsystems, Inc. - X Window System Engineering

FCL--FOSS Check List
0.  Introduction
0.1 Document History
    Version   Author             Changes					Date
    0.1       John Fischer       Initial Draft					01/11/2008
    0.2       John Fischer       Modified based upon feedback from ARC members	01/29/2008
    0.3       John Fischer       Modified based upon feedback during committee 	02/12/2008
                                 review
    0.4       John Fischer       Modified based upon SAC review feedback	04/01/2008
    0.5	      John Fischer	 Modified based upon LSARC business meeting	06/10/2008
                                 adding familiarity question and mod dates.
    0.6       John Fischer       Modified based upon user feedback about        06/20/2008
                                 sections that were unanswerable.

0.2 Purpose
    Architecture review at Sun has allowed the company to evolve our projects
    within multiple disjoint groups while still maintaining a cohesive product
    line.  Each architecture review was conducted within Sun's control.  With
    the advent of Free Open Source Software processes the control that Sun as
    a company can wield has been diminished.  Now that Sun is moving to a more
    fluid delivery mechanism with project Indiana we need to evolve the 
    architecture review process.  This document is meant to aid in the 
    architecture review process.  Each new project must complete this check list 
    to help ensure that the overall resulting product conforms to Sun product 
    standards.  If the project deviates from these standards further review 
    would be necessary by an architecture review committee.
    
    After the check list is completed the project team should be able to 
    determine if a project can be automatically approved.  This will occur
    if all checks result in no "ARC review required" answers.  A committee
    member will assist the project team in filing the automatically approved 
    fast track.  An automatically approved fast track is still required in order
    to record the interfaces for future reference.  If the project needs to 
    have further review then follow the regular process for getting projects 
    reviewed.

1.0 Project Information
1.1 Name of project/component
	Synergy - Mouse/Keyboard sharing
	1.3.1, April 02-2006

1.2 Author of document
	Stuart Kreitman

2.0 Project Summary
  2.1 Project Description
	Synergy lets you easily share a single mouse and keyboard between multiple computers with different operating systems, each with its own display, without special hardware. It's intended for users with multiple computers on their desk since each system uses its own monitor(s).

Redirecting the mouse and keyboard is as simple as moving the mouse off the edge of your screen. Synergy also merges the clipboards of all the systems into one, allowing cut-and-paste between systems. Furthermore, it synchronizes screen savers so they all start and stop together and, if screen locking is enabled, only one screen requires a password to unlock them all. 
  
  2.2 Release binding
      What is is the release binding?
      (see http://opensolaris.org/os/community/arc/policies/release-taxonomy/)
      [ ] Major
      [X] Minor
      [ ] Patch or Micro
      [ ] Unknown -- ARC review required

  2.3 Type of project
      Is this case a Linux Familiarity project?
      [X] Yes
      [ ] No

  2.4 Originating Community
    2.4.1 Community Name
	Synergy is hosted on Sourceforge.  http://synergy2.sourceforge.net
    
    2.4.2 Community Involvement
      Indicate Sun's involvement in the community
      [ ] Maintainer
      [ ] Contributor
      [X] Monitoring
      
      Will the project team work with the upstream community to resolve
      architectural issues of interest to Sun?
      [X] Yes 
      [ ] No - briefly explain
      
      Will we or are we forking from the community?
      [ ] Yes - ARC review required prior to forking
      [X] No
      
3.0 Technical Description
  3.1 Installation & Sharable
    3.1.1S Solaris Installation - section only required for Solaris Software
      (see http://opensolaris.org/os/community/arc/policies/install-locations/ for details)
      Does this project follow the Install Locations best practice?
      [X] Yes 
      [ ] No - ARC review required
      
      Does this project install into /usr under [sbin|bin|lib|include|man|share]?
      [X] Yes
      [ ] No or N/A
      
      Does this project install into /opt?
      [ ] Yes - explain below
      [X] No or N/A
      
      Does this project install into a different directory structure?
      [ ] Yes - ARC review required
      [X] No or N/A
      
      Do any of the components of this project conflict with anything under /usr?
      (see http://opensolaris.org/os/community/arc/caselog/2007/047/ for details)
      [ ] Yes - explain below
      [X] No
      
      If conflicts exist then will this project install under /usr/gnu?
      [ ] Yes
      [ ] No - ARC review required
      [X] N/A
      
      Is this project installing into /usr/sfw?
      [ ] Yes - ARC review required
      [X] No
      
    3.1.1W Windows Installation - section only required for Windows Software
      (see http://sac.sfbay/WSARC/2002/494 for details)
      Does this project install software into a 
      <system drive>:\Program Files\Sun\<product> or <system drive>:\Sun\<product>
      directory?
      [ ] Yes
      [ ] No - ARC review required
      
      Does the project use the Windows registry?
      [ ] Yes
      [ ] No - ARC review required
      
      Does the project use 
      HKEY_LOCAL_MACHINE\SOFTWARE\Sun Microsystems\<product>\<version>
      for the registry key?
      [ ] Yes
      [ ] No - ARC review required
      
      Is the project's stored location
      HKEY_LOCAL_MACHINE\SOFTWARE\Sun Microsystems\<product id>\<version id>\Path?
      [ ] Yes
      [ ] No - ARC review required
      
    3.1.2 Share and Sharable
      Does the module include any components that are used or shared by 
      other projects?
      [ ] Yes
      [X] No
    
      If yes are these components packaged to be shared with the other FOSS?
      [ ] Yes
      [ ] No - ARC review required
      [ ] N/A
    
      Are these components already in the Solaris WOS?
      [ ] Yes
      [ ] No - continue with next section (section 3.2)
    
      If yes are these newer versions being delivered?
      [ ] Yes
      [ ] No - ARC review required
      
      If yes are the newer versions replacing the existing versions?
      [ ] Yes
      [ ] No - ARC review required

  3.2 Exported Libraries
      Are libraries being delivered by this project?
      [ ] Yes
      [X] No - continue with next section (section 3.3)
      
      Are 64-bit versions of the libraries being delivered?
      [ ] Yes
      [ ] No - ARC review required
    
      Are static versions of the libraries being delivered?
      [ ] Yes - ARC review required
      [ ] No 
      
  3.3 Services and the /etc Directory
      (see http://opensolaris.org/os/community/arc/policies/SMF-policy/)
      Does the project integrate anything into /etc/init.d or /etc/rc?.d?
      [ ] Yes - ARC review required
      [X] No
      
      Does the project integrate any new entries into /etc/inittab or
      /etc/inetd.conf?
      [ ] Yes - ARC review required
      [X] No
      
      Does the project integrate any private non-public files into /etc/default
      or /etc/ configuration files?
      [ ] Yes - ARC review required
      [X] No
      
      Does the service manifests method context grant rights above that
      of the noaccess user and basic privilege set?
      [ ] Yes - ARC review required
      [X] No
        
  3.4 Security
    3.4.1 Secure By Default 
      (see http://opensolaris.org/os/community/arc/policies/secure-by-default/ for details)
      (see http://www.opensolaris.org/os/community/arc/policies/NITS-policy/ for details)
      (see parts of http://opensolaris.org/os/community/arc/policies/SMF-policy/ for
       addtional details)
      Are there any network services provided by this project?
      [X] Yes
      [ ] No - continue with the next section (section 3.4.2)
      
      Are network services enabled by default?
      [ ] Yes - ARC review required
      [X] No
      [ ] N/A
      
      Are network services automatically enabled by the project during installation?
      [ ] Yes - ARC review required
      [X] No
      [ ] N/A
      
      Are inbound network communications denied by default?
      [ ] Yes
      [X] No - ARC review required
      [ ] N/A
      
      Is inbound data checked to prevent content-based attacks?
      [ ] Yes
      [X] No - ARC review required
      [ ] N/A
      
      Is the outbound receiver authenticated?
      [ ] Yes
      [X] No - ARC review required. 
		Synergy provides no security, but can be configured to run through ssh.
		See http://synergy2.sourceforge.net/security.html 
      [ ] N/A
      
      Is the receiver authenticated prior to receiving any sensitive outbound communication?
      [ ] Yes
      [X] No - ARC review required
		See above
      [ ] N/A
      
    3.4.2 Authorization
      (see http://opensolaris.org/os/community/arc/bestpractices/rbac-intro/ and
	   http://opensolaris.org/os/community/arc/bestpractices/rbac-profiles/ and
	   http://opensolaris.org/os/community/arc/bestpractices/rbac-profiles/
           for details)
      Are there any setuid/setgid privileged binaries in the project?
      [ ] Yes - ARC review required
      [X] No - continue with next section (section 3.4.3)
      
      If yes then are the setuid/setgid privileges handled by the use of roles?
      [ ] Yes
      [ ] No - ARC review required

    3.4.3 Auditing
      (see http://opensolaris.org/os/community/arc/policies/audit-policy/ for details)
      (see http://opensolaris.org/os/community/arc/caselog/2003/397 for details)
      Does this component contain administrative or security enforcing software?
      [ ] Yes - ARC review required
      [X] No - continue to next section (section 3.4.4)
      
      (see http://opensolaris.org/os/community/arc/caselog/2003/397 for details)
      Do the components create audit logs detailing what took place including what event
      took place, who was involved, when the event took place?
      [ ] Yes - ARC contract and Audit project team review required
      [ ] No - ARC review required
        
        
    3.4.4 Authentication
      (see http://opensolaris.org/os/community/arc/policies/PAM/)
      Do the components contain any authentication code?
      [ ] Yes
      [X] No - continue to next section (section 3.4.5)
      
      If yes do the components use PAM (plugable authentication modules) for authentication?
      [ ] Yes
      [ ] No - ARC review required
      
      If yes is a single PAM session maintained during authentication?
      [ ] Yes
      [ ] No - ARC review required
      
      If yes are the components sufficiently privileged to allow the requested 
      operations (authentication, password change, process credential manipulation, 
      audit state initialization)?
      [ ] Yes - briefly describe below
      [ ] No - ARC review required
      
    3.4.5 Passwords
      (see http://opensolaris.org/os/community/arc/bestpractices/passwords-cli/ and
           http://opensolaris.org/os/community/arc/bestpractices/passwords-files/ for details)
      Do any of the components for the project deal with passwords?
      [ ] Yes
      [X] No - continue to next section (section 3.4.6)
      
      If yes are these passwords entered via the CLI or environment?
      [ ] Yes - ARC review required
      [ ] No
      
      Are passwords stored within the file system for the component?
      [ ] Yes
      [ ] No - continue to next section (section 3.4.6)
      
      If yes are the permissions on the file such to protect exposing the password(s)?
      [ ] Yes
      [ ] No - ARC review required
      
    3.4.6 General Security Questions
      (see http://opensolaris.org/os/community/arc/bestpractices/security-questions/ for details)
      Are there any network protocols used by this project?
      [X] Yes
      [ ] No - continue with the next section (section 3.5)
      
      Do the components use standard network protocols?
      [X] Yes
      [ ] No - ARC review required
      
      Do network services for the project make decisions based upon user, host or 
      service identities?
      [ ] Yes - explain below
      [X] No
      [ ] N/A
      
      Do the components make use of secret information during authentication and/or
      authorization?
      [ ] Yes - explain below
      [X] No
      [ ] N/A
  
  3.5 Networking
      Do the components access the network?
      [X] Yes
      [ ] No - continue with the next section (section 3.6)
      
      If yes do the components support IPv6?
      [ ] Yes 
      [X] No - ARC review required
          
  3.6 Core Solaris Components
      Do the components of this project compete with or duplicate core 
      Solaris components?
      [ ] Yes - ARC review required
      [X] No 
      
      Examples of Core Solaris Components include but are not limited to:
      
        Secure By Default
        Authorizations
        PAM -- Plugable Authentication Module
        Privilege
        PRM -- Process Rights Management -- Privilege
        Audit
        xVm -- Virtualization
        zones / Solaris Containers
        PRM -- Process Rights Management
        RBAC -- Role Based Access Control
        TX / Trusted Extensions
        ZFS
        SMF -- Service Management Facility
        FMA -- Fault Management Architecture
        SCF -- Smart Card Facility
        IPsec
        
4.0 Interfaces
  (see http://www.opensolaris.org/os/community/arc/policies/interface-taxonomy/ for details)
  4.1 Exported Interfaces
  
    Interface Name		Classification      Comments
    --------------------------- ------------------- ---------------------------
    synergys(1)			Committed           version 1.3.1
    synergyc(1)			Committed           version 1.3.1
    
  4.2 Imported Interfaces
    Interface Name		Classification       Comments
    --------------------------- -------------------- --------------------------
    
    
  Brief Interface Classifications - See Appendix C for definitions
    Volatile - interfaces are fluid and will follow a rapidly changing community
    Uncommitted - interfaces are still evolving in the community and might follow
		  the community
    Committed - interfaces are stable in the community
    Project Private - no review required, just document in table
    Contracted (interface modifier) - further review required

Appendix A - References
  1.  Solaris Installation Locations Policy
      http://opensolaris.org/os/community/arc/policies/install-locations/
  2.  /usr/gnu Installation ARC case
      http://opensolaris.org/os/community/arc/caselog/2007/047/
  3.  Secure By Default Policy
      http://opensolaris.org/os/community/arc/policies/secure-by-default/
  4.  Network Install Time Securityuy Policy
      http://www.opensolaris.org/os/community/arc/policies/NITS-policy/
  5.  Adding RBAC Authorizations Policy
      http://opensolaris.org/os/community/arc/bestpractices/rbac-auths/
  6.  When to use setuid -vs- RBAC roles and profiles
      http://opensolaris.org/os/community/arc/bestpractices/rbac-intro/ and
  7.  Building RBAC Rights Profiles
      http://opensolaris.org/os/community/arc/bestpractices/rbac-profiles/
  8.  Solaris Audit Policy
      http://opensolaris.org/os/community/arc/policies/audit-policy/
  9.  Security questionaire
      http://opensolaris.org/os/community/arc/bestpractices/security-questions/
  10. Interface Taxonomy
      http://www.opensolaris.org/os/community/arc/policies/interface-taxonomy/
  11. Plugable Authentication Modules -- PAM
      http://opensolaris.org/os/community/arc/policies/PAM/
  12. Reusable Passwords In Command Line Arguments and Environment Variables
      http://opensolaris.org/os/community/arc/bestpractices/passwords-cli/
  13. Storing Reusable Passwords on a Filesystem
      http://opensolaris.org/os/community/arc/bestpractices/passwords-files/
  14. Release Taxonomy
      http://opensolaris.org/os/community/arc/policies/release-taxonomy/
  15. Service Management Facility (SMF) usage
      http://opensolaris.org/os/community/arc/policies/SMF-policy/

  
Appendix B - Suggested case materials
  1. man pages
  2. SMF manifests
  3. links to contracts
  
Appendix C - Definitions
Submitter
     an agent responsible for creation of an ARC project along with the
     materials describing that project.
Owner
     the ARC agent responsible for shepherding the case through review
     and ensuring a formal opinion is written where required.
Maintainer
     an agent responsible for releasing new versions of a program, typically
     the "main" contributor or person incharge of making Architectural
     decisions for the project
Contributor
     an agent who make contributions to a project, typically has a voice in
     making Architectural decisions for the project
Monitoring
     an agent who is only following the changes made in the community and
     has no Architectural input into the project
Volatile*
    interfaces that are very fluid and typically follow the originating 
    community.  Typically these interfaces can not be imported by other
    projects.
Uncommitted*
    interfaces that are still evolving but will most likely be present from
    release to release.
Committed*
    interfaces that are stable and with Sun guaranteeing some level of
    compatibility from release to release.
Project Private*
    interfaces that are exposed only to or intended to be used only by
    the project being reviewed.  These interfaces can not be imported by
    other projects.
Not-An-Interface*
    components that are not interfaces.
Contracted* (interface modifier) - ARC review of Contract required
    interfaces that do not allow another project to import can be 

*Note: see http://opensolaris.org/os/community/arc/policies/interface-taxonomy/ for details

6. Resources and Schedule
    6.4. Steering Committee requested information
   	6.4.1. Consolidation C-team Name:
		X Consolidation (Desktop C-Team)
    6.5. ARC review type: FastTrack
    6.6. ARC Exposure: open


From Darren.Moffat@sun.com Tue Sep 15 02:06:08 2009
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n8F96824019665
	for <LSARC-ext@sac.sfbay.sun.com>; Tue, 15 Sep 2009 02:06:08 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n8F966YH010474
	for <@sunmail2sca.sfbay.sun.com:LSARC-ext@sun.com>; Tue, 15 Sep 2009 03:06:08 -0600 (MDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KQ000K2X9A7OQ00@nwk-avmta-2.sfbay.sun.com> for LSARC-ext@sun.com
 (ORCPT LSARC-ext@sun.com); Tue, 15 Sep 2009 02:06:07 -0700 (PDT)
Received: from gmp-eb-inf-2.sun.com ([192.18.6.24])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KQ0004K79A5SZC0@nwk-avmta-2.sfbay.sun.com> for
 LSARC-ext@sun.com (ORCPT LSARC-ext@sun.com); Tue,
 15 Sep 2009 02:06:05 -0700 (PDT)
Received: from fe-emea-09.sun.com
 (gmp-eb-lb-1-fe1.eu.sun.com [192.18.6.7] (may be forged))
	by gmp-eb-inf-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id n8F962dY005629	for
 <LSARC-ext@sun.com>; Tue, 15 Sep 2009 09:06:04 +0000 (GMT)
Received: from conversion-daemon.fe-emea-09.sun.com by fe-emea-09.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.04 64bit (built Jul  2 2009))
 id <0KQ0007006XX2E00@fe-emea-09.sun.com> for LSARC-ext@sun.com
 (ORCPT LSARC-ext@sun.com); Tue, 15 Sep 2009 10:06:04 +0100 (BST)
Received: from [192.168.1.105]
 (cpc2-rdng20-2-0-cust917.15-3.cable.virginmedia.com [86.28.167.150])
 by fe-emea-09.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.04 64bit (built Jul  2 2009))
 with ESMTPSA id <0KQ000MJH99QF860@fe-emea-09.sun.com> for LSARC-ext@sun.com
 (ORCPT LSARC-ext@sun.com); Tue, 15 Sep 2009 10:05:50 +0100 (BST)
Date: Tue, 15 Sep 2009 10:05:49 +0100
From: Darren J Moffat <Darren.Moffat@sun.com>
Subject: Re: Synergy - Mouse/Keyboard sharing [LSARC/2009/489 FastTrack timeout
 09/21/2009]
In-reply-to: <200909150157.n8F1vctH014862@sac.sfbay.sun.com>
Sender: Darren.Moffat@sun.com
To: Alan Coopersmith <Alan.Coopersmith@sun.com>
Cc: LSARC-ext@sun.com, Stuart.Kreitman@sun.com
Message-id: <4AAF58ED.6080303@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; CHARSET=US-ASCII; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200909150157.n8F1vctH014862@sac.sfbay.sun.com>
User-Agent: Thunderbird 2.0.0.22 (X11/20090818)
Status: RO
Content-Length: 934

How does this work when the Solaris system is running with Trusted 
Extensions enabled ? In particular given that the screensaver is a 
trusted path concept and cut and paste is intercepted on trusted path 
and subject to authorisation.

I was surprised you said there was no authentication or authorisation, 
but then the upstream page on "Security" says this:

"Synergy does not do any authentication or encryption. Any computer can 
connect to the synergy server if it provides a screen name known to the 
server"

Scarey!  Does that really mean what it says ?  If I run synergy on my 
Solaris desktop anything that can make a network connection to it can 
grab the keyboard and mouse ?  That is scarey!   I can't find out from 
the project home page how port numbers are selected and if it is 
possible to force it to bind to localhost only (so that if can be run 
over SSH and not still exposed unencrypted).

--
Darren J Moffat

From cyril.plisko@gmail.com Tue Sep 15 02:21:45 2009
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n8F9LhOm019747
	for <LSARC-ext@sac.sfbay.sun.com>; Tue, 15 Sep 2009 02:21:44 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id n8F9LdQI020258;
	Tue, 15 Sep 2009 17:21:39 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KQ000L0NA01PD00@nwk-avmta-2.sfbay.sun.com>; Tue,
 15 Sep 2009 02:21:37 -0700 (PDT)
Received: from brmea-mail-4.sun.com ([192.18.98.36])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KQ000484A00T5E0@nwk-avmta-2.sfbay.sun.com>; Tue,
 15 Sep 2009 02:21:37 -0700 (PDT)
Received: from relay41i.sun.com ([192.5.209.70])
	by brmea-mail-4.sun.com (8.13.6+Sun/8.12.9) with ESMTP id n8F9KTHb012902; Tue,
 15 Sep 2009 09:21:36 +0000 (GMT)
Received: from mmp41es.mmp.us.syntegra.com ([160.41.221.10] [160.41.221.10])
 by relay41i.sun.com with ESMTP id BT-MMP-1157995; Tue,
 15 Sep 2009 09:21:36 +0000 (Z)
Received: from relay42i.sun.com (relay42i.sun.com [192.5.209.72])
 by mmp41es.mmp.us.syntegra.com with ESMTP id BT-MMP-9305011; Tue,
 15 Sep 2009 09:21:34 +0000 (Z)
Received: from mail-ew0-f210.google.com ([209.85.219.210] [209.85.219.210])
 by relay4i.sun.com with ESMTP id BT-MMP-23686564; Tue,
 15 Sep 2009 09:21:34 +0000 (Z)
Received: by ewy6 with SMTP id 6so1317395ewy.6 for <multiple recipients>; Tue,
 15 Sep 2009 02:20:43 -0700 (PDT)
Received: by 10.216.15.2 with SMTP id e2mr1592286wee.210.1253006443323; Tue,
 15 Sep 2009 02:20:43 -0700 (PDT)
Date: Tue, 15 Sep 2009 12:20:23 +0300
From: Cyril Plisko <cyril.plisko@mountall.com>
Subject: Re: Synergy - Mouse/Keyboard sharing [LSARC/2009/489 FastTrack	timeout
 09/21/2009]
In-reply-to: <4AAF58ED.6080303@Sun.COM>
Sender: cyril.plisko@gmail.com
To: Darren J Moffat <Darren.Moffat@sun.com>
Cc: Alan Coopersmith <Alan.Coopersmith@sun.com>, Stuart.Kreitman@sun.com,
        LSARC-ext@sun.com
Message-id: <c7dddeaa0909150220m256dfdc5re364ce574d15a759@mail.gmail.com>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;        d=gmail.com;
 s=gamma;        h=domainkey-signature:mime-version:sender:received:in-reply-to
         :references:from:date:x-google-sender-auth:message-id:subject:to:cc
 :content-type:content-transfer-encoding;
 bh=e2okxWnTPDayjKEX64lEqX3wDBxhMJBmx2mUNwmFk+E=;
 b=T/QnN+3rtwOV1r7h/4OF+kISM4GHMBvaUkbtibHnjccTat6ij8u5xbxvHMJWqHSuzq
 Z1NgwMd7mckU8ADUWIxOKwUPscHiXXXsfPenHv1qK5HWMe73gmD8WqIz4js15D9zA7mV
 Al6LFvuLX9Dt8PBDE3/bxlN1tAWof7bKLMGi4=
DomainKey-Signature: a=rsa-sha1; c=nofws;        d=gmail.com; s=gamma;
 h=mime-version:sender:in-reply-to:references:from:date
 :x-google-sender-auth:message-id:subject:to:cc:content-type
 :content-transfer-encoding;
 b=P8cR4hqCV1yPkl6uu0SEblnBsW31WRNZHRZATkQhERIwAlQz/Lr+zT3x4dvdVWgchX
 rUNSUusjq/jigysU1oG1AwteAafuw88zzp1mqc3jbKcouEHJnYSPqa9kpinUd4aFjGSe
 5mnt1P/VRCrFesqnyKgi5FJ/EPRC7JXWcweDk=
X-PMX-Version: 5.4.1.325704
X-Brightmail-Tracker: AAAAAA==
X-Google-Sender-Auth: 7edce37916fd4826
X-Antispam: No, score=-0.7/5.0, scanned in 0.135sec at (localhost [127.0.0.1])
	by smf-spamd v1.3.1 - http://smfs.sf.net/
References: <200909150157.n8F1vctH014862@sac.sfbay.sun.com>
 <4AAF58ED.6080303@Sun.COM>
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from quoted-printable to 8bit by sac.sfbay.sun.com id n8F9LhOm019747
Status: RO
Content-Length: 1544

On Tue, Sep 15, 2009 at 12:05 PM, Darren J Moffat <Darren.Moffat@sun.com> wrote:
> How does this work when the Solaris system is running with Trusted
> Extensions enabled ? In particular given that the screensaver is a trusted
> path concept and cut and paste is intercepted on trusted path and subject to
> authorisation.
>
> I was surprised you said there was no authentication or authorisation, but
> then the upstream page on "Security" says this:
>
> "Synergy does not do any authentication or encryption. Any computer can
> connect to the synergy server if it provides a screen name known to the
> server"
>
> Scarey!  Does that really mean what it says ?  If I run synergy on my
> Solaris desktop anything that can make a network connection to it can grab
> the keyboard and mouse ?  That is scarey!   I can't find out from the

Reality isn't that bad AFAIK. The server process (synergys) is run on
machine with you physical keyboard/mouse. And client processes
(synergyc) are connected to it from other machines. synergyc doesn't
grab you keyboard and mouse, but rather server injects events to the
client. So if anyone fakes a client identification and connect to you
machine with server running she becomes controlled by you, rather than
vice versa.

> project home page how port numbers are selected and if it is possible to
> force it to bind to localhost only (so that if can be run over SSH and not
> still exposed unencrypted).

synergy documentation provides a recipe on how to implement it via SSH

-- 
Regards,
        Cyril


From Darren.Moffat@Sun.COM Tue Sep 15 02:54:47 2009
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n8F9sj43020316
	for <LSARC-ext@sac.sfbay.sun.com>; Tue, 15 Sep 2009 02:54:45 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id n8F9sbTL001081
	for <@sunmail2sca.sfbay.sun.com:LSARC-ext@sun.com>; Tue, 15 Sep 2009 10:54:44 +0100 (BST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KQ000I0JBJ64B00@brm-avmta-1.central.sun.com> for LSARC-ext@sun.com
 (ORCPT LSARC-ext@sun.com); Tue, 15 Sep 2009 03:54:42 -0600 (MDT)
Received: from gmp-eb-inf-1.sun.com ([192.18.6.21])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KQ0006YJBJ43SA0@brm-avmta-1.central.sun.com> for
 LSARC-ext@sun.com (ORCPT LSARC-ext@sun.com); Tue,
 15 Sep 2009 03:54:41 -0600 (MDT)
Received: from fe-emea-10.sun.com
 (gmp-eb-lb-1-fe1.eu.sun.com [192.18.6.7] (may be forged))
	by gmp-eb-inf-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id n8F9senc016017	for
 <LSARC-ext@sun.com>; Tue, 15 Sep 2009 09:54:40 +0000 (GMT)
Received: from conversion-daemon.fe-emea-10.sun.com by fe-emea-10.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.04 64bit (built Jul  2 2009))
 id <0KQ000B00B4JLG00@fe-emea-10.sun.com> for LSARC-ext@sun.com
 (ORCPT LSARC-ext@sun.com); Tue, 15 Sep 2009 10:54:26 +0100 (BST)
Received: from [192.168.1.105]
 (cpc2-rdng20-2-0-cust917.15-3.cable.virginmedia.com [86.28.167.150])
 by fe-emea-10.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.04 64bit (built Jul  2 2009))
 with ESMTPSA id <0KQ000CWUBI4JB80@fe-emea-10.sun.com> for LSARC-ext@sun.com
 (ORCPT LSARC-ext@sun.com); Tue, 15 Sep 2009 10:54:04 +0100 (BST)
Date: Tue, 15 Sep 2009 10:54:04 +0100
From: Darren J Moffat <Darren.Moffat@Sun.COM>
Subject: Re: Synergy - Mouse/Keyboard sharing [LSARC/2009/489 FastTrack	timeout
 09/21/2009]
In-reply-to: <c7dddeaa0909150220m256dfdc5re364ce574d15a759@mail.gmail.com>
Sender: Darren.Moffat@Sun.COM
To: Cyril Plisko <cyril.plisko@mountall.com>
Cc: Alan Coopersmith <Alan.Coopersmith@Sun.COM>, Stuart.Kreitman@Sun.COM,
        LSARC-ext@Sun.COM
Message-id: <4AAF643C.9050500@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; CHARSET=US-ASCII; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200909150157.n8F1vctH014862@sac.sfbay.sun.com>
 <4AAF58ED.6080303@Sun.COM>
 <c7dddeaa0909150220m256dfdc5re364ce574d15a759@mail.gmail.com>
User-Agent: Thunderbird 2.0.0.22 (X11/20090818)
Status: RO
Content-Length: 1928

Cyril Plisko wrote:
> On Tue, Sep 15, 2009 at 12:05 PM, Darren J Moffat <Darren.Moffat@sun.com> wrote:
>> How does this work when the Solaris system is running with Trusted
>> Extensions enabled ? In particular given that the screensaver is a trusted
>> path concept and cut and paste is intercepted on trusted path and subject to
>> authorisation.
>>
>> I was surprised you said there was no authentication or authorisation, but
>> then the upstream page on "Security" says this:
>>
>> "Synergy does not do any authentication or encryption. Any computer can
>> connect to the synergy server if it provides a screen name known to the
>> server"
>>
>> Scarey!  Does that really mean what it says ?  If I run synergy on my
>> Solaris desktop anything that can make a network connection to it can grab
>> the keyboard and mouse ?  That is scarey!   I can't find out from the
> 
> Reality isn't that bad AFAIK. The server process (synergys) is run on
> machine with you physical keyboard/mouse. And client processes
> (synergyc) are connected to it from other machines.

So there is a process running on my machine listening for network 
connections.

 > synergyc doesn't
> grab you keyboard and mouse, but rather server injects events to the
> client. So if anyone fakes a client identification and connect to you
> machine with server running she becomes controlled by you, rather than
> vice versa.

Understood, but that doesn't answer my questions.

>> project home page how port numbers are selected and if it is possible to
>> force it to bind to localhost only (so that if can be run over SSH and not
>> still exposed unencrypted).
> 
> synergy documentation provides a recipe on how to implement it via SSH

I read that, what I couldn't find was how to force synergy to only bind 
to localhost.  If it doesn't bind to localhost then I need to ensure 
that there are ipfilter rules in place to block it.

-- 
Darren J Moffat

From Stuart.Kreitman@sun.com Tue Sep 15 08:01:26 2009
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n8FF1PQ1017917
	for <LSARC-ext@sac.sfbay.sun.com>; Tue, 15 Sep 2009 08:01:26 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id n8FF1KiQ023018
	for <@sunmail2sca.sfbay.sun.com:LSARC-ext@sun.com>; Tue, 15 Sep 2009 23:01:24 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KQ000K6BPQA3M00@nwk-avmta-2.sfbay.sun.com> for LSARC-ext@sun.com
 (ORCPT LSARC-ext@sun.com); Tue, 15 Sep 2009 08:01:22 -0700 (PDT)
Received: from sca-es-mail-2.sun.com ([192.18.43.133])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KQ000CVDPQ9JZE0@nwk-avmta-2.sfbay.sun.com> for
 LSARC-ext@sun.com (ORCPT LSARC-ext@sun.com); Tue,
 15 Sep 2009 08:01:21 -0700 (PDT)
Received: from fe-sfbay-09.sun.com ([192.18.43.129])
	by sca-es-mail-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id n8FF1Lqu013443	for
 <LSARC-ext@sun.com>; Tue, 15 Sep 2009 08:01:21 -0700 (PDT)
Received: from conversion-daemon.fe-sfbay-09.sun.com by fe-sfbay-09.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.04 64bit (built Jul  2 2009))
 id <0KQ000J00PM89B00@fe-sfbay-09.sun.com> for LSARC-ext@sun.com
 (ORCPT LSARC-ext@sun.com); Tue, 15 Sep 2009 08:01:20 -0700 (PDT)
Received: from lemforder.local ([unknown] [76.220.205.13])
 by fe-sfbay-09.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.04 64bit (built Jul  2 2009))
 with ESMTPSA id <0KQ0004LZPQ78VC0@fe-sfbay-09.sun.com> for LSARC-ext@sun.com
 (ORCPT LSARC-ext@sun.com); Tue, 15 Sep 2009 08:01:19 -0700 (PDT)
Date: Tue, 15 Sep 2009 08:01:15 -0700
From: Stuart Kreitman <Stuart.Kreitman@sun.com>
Subject: Re: Synergy - Mouse/Keyboard sharing [LSARC/2009/489 FastTrack	timeout
 09/21/2009]
In-reply-to: <4AAF643C.9050500@Sun.COM>
Sender: Stuart.Kreitman@sun.com
To: Darren J Moffat <Darren.Moffat@sun.com>
Cc: Cyril Plisko <cyril.plisko@mountall.com>,
        Alan Coopersmith <Alan.Coopersmith@sun.com>, LSARC-ext@sun.com
Message-id: <4AAFAC3B.3060307@sun.com>
MIME-version: 1.0
Content-type: text/plain; CHARSET=US-ASCII; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200909150157.n8F1vctH014862@sac.sfbay.sun.com>
 <4AAF58ED.6080303@Sun.COM>
 <c7dddeaa0909150220m256dfdc5re364ce574d15a759@mail.gmail.com>
 <4AAF643C.9050500@Sun.COM>
User-Agent: Thunderbird 2.0.0.23 (Macintosh/20090812)
Status: RO
Content-Length: 875

Darren J Moffat wrote:
> Cyril Plisko wrote:
>
>>
>> synergy documentation provides a recipe on how to implement it via SSH
>
> I read that, what I couldn't find was how to force synergy to only 
> bind to localhost.  If it doesn't bind to localhost then I need to 
> ensure that there are ipfilter rules in place to block it.
>
In its current rev. 1.3.1, synergy is just plain not secure. No bones 
about it.
Its pretty easy to get running, but by the time you've read 1/2 page of 
documentation, you know that its insecure.
We are not providing any tools or autorunning config for it.  Its 
apparent that this is an insufficient response.

I need guidance on making this palatable to ARC.  Does "forcing synergy 
to only bind to localhost" enforce only
SSH connections? If this is a sufficient response to the security 
concern, then I'm happy to oblige.


Stuart Kreitman

From Darren.Moffat@sun.com Tue Sep 15 08:08:00 2009
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n8FF7xWV011219
	for <LSARC-ext@sac.sfbay.sun.com>; Tue, 15 Sep 2009 08:07:59 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail3mpk.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id n8FF7wvL006438
	for <@sunmail2sca.sfbay.sun.com:LSARC-ext@sun.com>; Tue, 15 Sep 2009 08:07:59 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KQ000F2BQ1A5K00@nwk-avmta-1.sfbay.Sun.COM> for LSARC-ext@sun.com
 (ORCPT LSARC-ext@sun.com); Tue, 15 Sep 2009 08:07:58 -0700 (PDT)
Received: from gmp-eb-inf-1.sun.com ([192.18.6.21])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KQ0008BIQ19YR80@nwk-avmta-1.sfbay.Sun.COM> for
 LSARC-ext@sun.com (ORCPT LSARC-ext@sun.com); Tue,
 15 Sep 2009 08:07:58 -0700 (PDT)
Received: from fe-emea-09.sun.com
 (gmp-eb-lb-1-fe1.eu.sun.com [192.18.6.7] (may be forged))
	by gmp-eb-inf-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id n8FF7uB5009723	for
 <LSARC-ext@sun.com>; Tue, 15 Sep 2009 15:07:57 +0000 (GMT)
Received: from conversion-daemon.fe-emea-09.sun.com by fe-emea-09.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.04 64bit (built Jul  2 2009))
 id <0KQ000400O8LJI00@fe-emea-09.sun.com> for LSARC-ext@sun.com
 (ORCPT LSARC-ext@sun.com); Tue, 15 Sep 2009 16:07:47 +0100 (BST)
Received: from [192.168.1.105]
 (cpc2-rdng20-2-0-cust917.15-3.cable.virginmedia.com [86.28.167.150])
 by fe-emea-09.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.04 64bit (built Jul  2 2009))
 with ESMTPSA id <0KQ000LJJQ0WAXD0@fe-emea-09.sun.com> for LSARC-ext@sun.com
 (ORCPT LSARC-ext@sun.com); Tue, 15 Sep 2009 16:07:44 +0100 (BST)
Date: Tue, 15 Sep 2009 16:07:44 +0100
From: Darren J Moffat <Darren.Moffat@sun.com>
Subject: Re: Synergy - Mouse/Keyboard sharing [LSARC/2009/489 FastTrack	timeout
 09/21/2009]
In-reply-to: <4AAFAC3B.3060307@sun.com>
Sender: Darren.Moffat@sun.com
To: Stuart Kreitman <Stuart.Kreitman@sun.com>
Cc: Cyril Plisko <cyril.plisko@mountall.com>,
        Alan Coopersmith <Alan.Coopersmith@sun.com>, LSARC-ext@sun.com
Message-id: <4AAFADC0.1070907@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; CHARSET=US-ASCII; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200909150157.n8F1vctH014862@sac.sfbay.sun.com>
 <4AAF58ED.6080303@Sun.COM>
 <c7dddeaa0909150220m256dfdc5re364ce574d15a759@mail.gmail.com>
 <4AAF643C.9050500@Sun.COM> <4AAFAC3B.3060307@sun.com>
User-Agent: Thunderbird 2.0.0.22 (X11/20090818)
Status: RO
Content-Length: 1815

Stuart Kreitman wrote:
> Darren J Moffat wrote:
>> Cyril Plisko wrote:
>>
>>>
>>> synergy documentation provides a recipe on how to implement it via SSH
>>
>> I read that, what I couldn't find was how to force synergy to only 
>> bind to localhost.  If it doesn't bind to localhost then I need to 
>> ensure that there are ipfilter rules in place to block it.
>>
> In its current rev. 1.3.1, synergy is just plain not secure. No bones 
> about it.
> Its pretty easy to get running, but by the time you've read 1/2 page of 
> documentation, you know that its insecure.
> We are not providing any tools or autorunning config for it.  Its 
> apparent that this is an insufficient response.

Given it isn't enabled by default I guess it doesn't mater.

The bit that still isn't clear to me though is how I know what port 
numbers it is using - I couldn't work that out from the docs.  Is it a 
fixed port number or a dynamic one ?

> I need guidance on making this palatable to ARC.  Does "forcing synergy 
> to only bind to localhost" enforce only SSH connections? 

I would force you to use SSH port forwarding or something like it.

 > If this is a sufficient response to the security
> concern, then I'm happy to oblige.

At the moment I'm not actually suggesting you do anything, just trying 
to understand Synergy a bit better because the docs on its own site 
weren't helping me at all (and yes I read the FAQ and the "Security" 
page).   Once I understand it better I can formulate what I think the 
risks are and determine if I want to suggest anything or not (likely not 
in this case though).

I'd still like to know what happens with TX as a client and as a server 
(in synergy terms).  I think I know the answer though but I'd like 
someone actually familiar with synergy to confirm.


-- 
Darren J Moffat

From Alan.Coopersmith@sun.com Tue Sep 15 08:36:05 2009
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n8FFa4wT019262
	for <LSARC-ext@sac.sfbay.sun.com>; Tue, 15 Sep 2009 08:36:04 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id n8FFZn7p023167
	for <@sunmail2sca.sfbay.sun.com:LSARC-ext@sun.com>; Tue, 15 Sep 2009 16:36:03 +0100 (BST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KQ000509RC0ZX00@brm-avmta-1.central.sun.com> for LSARC-ext@sun.com
 (ORCPT LSARC-ext@sun.com); Tue, 15 Sep 2009 09:36:00 -0600 (MDT)
Received: from sca-es-mail-2.sun.com ([192.18.43.133])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KQ0002RNRBYBV20@brm-avmta-1.central.sun.com> for
 LSARC-ext@sun.com (ORCPT LSARC-ext@sun.com); Tue,
 15 Sep 2009 09:35:59 -0600 (MDT)
Received: from fe-sfbay-09.sun.com ([192.18.43.129])
	by sca-es-mail-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id n8FFZwtt017280	for
 <LSARC-ext@sun.com>; Tue, 15 Sep 2009 08:35:58 -0700 (PDT)
Received: from conversion-daemon.fe-sfbay-09.sun.com by fe-sfbay-09.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.04 64bit (built Jul  2 2009))
 id <0KQ000B00QW1GF00@fe-sfbay-09.sun.com> for LSARC-ext@sun.com
 (ORCPT LSARC-ext@sun.com); Tue, 15 Sep 2009 08:35:58 -0700 (PDT)
Received: from [129.145.155.53] ([unknown] [129.145.155.53])
 by fe-sfbay-09.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.04 64bit (built Jul  2 2009))
 with ESMTPSA id <0KQ000FRPRBAESA0@fe-sfbay-09.sun.com>; Tue,
 15 Sep 2009 08:35:34 -0700 (PDT)
Date: Tue, 15 Sep 2009 08:35:34 -0700
From: Alan Coopersmith <Alan.Coopersmith@sun.com>
Subject: Re: Synergy - Mouse/Keyboard sharing [LSARC/2009/489 FastTrack timeout
 09/21/2009]
In-reply-to: <4AAF58ED.6080303@Sun.COM>
Sender: Alan.Coopersmith@sun.com
To: Darren J Moffat <Darren.Moffat@sun.com>
Cc: LSARC-ext@sun.com, Stuart.Kreitman@sun.com,
        Glenn Faden <Glenn.Faden@sun.com>, Lokanath Das <Lokanath.Das@sun.com>
Message-id: <4AAFB446.1040501@sun.com>
MIME-version: 1.0
Content-type: text/plain; CHARSET=US-ASCII
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
X-Enigmail-Version: 0.95.1
References: <200909150157.n8F1vctH014862@sac.sfbay.sun.com>
 <4AAF58ED.6080303@Sun.COM>
User-Agent: Thunderbird 2.0.0.21 (X11/20090323)
Status: RO
Content-Length: 1739

[Added cc of the TX/Xtsol experts to confirm my understanding.  For
 their benefit, the proposal is to ship the synergy program to share
 keyboard, mouse & keyboard between X servers on multiple machines.
 For details, see http://synergy2.sourceforge.net/ and
 http://arc.opensolaris.org/caselog/LSARC/2009/489/20090914_stuart.kreitman ]

Darren J Moffat wrote:
> How does this work when the Solaris system is running with Trusted
> Extensions enabled ? In particular given that the screensaver is a
> trusted path concept and cut and paste is intercepted on trusted path
> and subject to authorisation.

I think the answer is "probably not well, and that's a good thing."
In order to control the mouse and keyboard on the machines in the
synergy group, synergy uses an X extension called "XTEST" which was
originally designed for test suites to simulate input devices.

The TX policy file for X will block usage of the XTEST extension
in order to prevent clients being able to take control of clients
with different security labels, so I don't think synergy will be
able to run in TX by default.

If it could run (such as if you modified the policy file, since it
is a plain text file a site could vi) it would probably need to run
in the global zone, and then since it's not label aware, it's
clipboard sharing would probably violate the protections for copy
and paste between differently labeled clients.

In short, I think the best answer is probably for us to add a note
to the man pages stating that synergy is not compatible with the
restrictions of the TX multi-label desktop, and is not recommended
for use there.

-- 
	-Alan Coopersmith-           alan.coopersmith@sun.com
	 Sun Microsystems, Inc. - X Window System Engineering


From Alan.Coopersmith@sun.com Tue Sep 15 08:43:40 2009
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n8FFhd8P019347
	for <LSARC-ext@sac.sfbay.sun.com>; Tue, 15 Sep 2009 08:43:39 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n8FFhcHU044248
	for <@sunmail2sca.sfbay.sun.com:LSARC-ext@sun.com>; Tue, 15 Sep 2009 09:43:38 -0600 (MDT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KQ00061ZROQOJ00@brm-avmta-1.central.sun.com> for LSARC-ext@sun.com
 (ORCPT LSARC-ext@sun.com); Tue, 15 Sep 2009 09:43:38 -0600 (MDT)
Received: from sca-es-mail-1.sun.com ([192.18.43.132])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KQ00025FROOBP40@brm-avmta-1.central.sun.com> for
 LSARC-ext@sun.com (ORCPT LSARC-ext@sun.com); Tue,
 15 Sep 2009 09:43:36 -0600 (MDT)
Received: from fe-sfbay-09.sun.com ([192.18.43.129])
	by sca-es-mail-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id n8FFhaEw009138	for
 <LSARC-ext@sun.com>; Tue, 15 Sep 2009 08:43:36 -0700 (PDT)
Received: from conversion-daemon.fe-sfbay-09.sun.com by fe-sfbay-09.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.04 64bit (built Jul  2 2009))
 id <0KQ000A00RLZN000@fe-sfbay-09.sun.com> for LSARC-ext@sun.com
 (ORCPT LSARC-ext@sun.com); Tue, 15 Sep 2009 08:43:36 -0700 (PDT)
Received: from [129.145.155.53] ([unknown] [129.145.155.53])
 by fe-sfbay-09.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.04 64bit (built Jul  2 2009))
 with ESMTPSA id <0KQ000FFRROMESE0@fe-sfbay-09.sun.com> for LSARC-ext@sun.com
 (ORCPT LSARC-ext@sun.com); Tue, 15 Sep 2009 08:43:35 -0700 (PDT)
Date: Tue, 15 Sep 2009 08:43:34 -0700
From: Alan Coopersmith <Alan.Coopersmith@sun.com>
Subject: Re: Synergy - Mouse/Keyboard sharing [LSARC/2009/489 FastTrack	timeout
 09/21/2009]
In-reply-to: <4AAFADC0.1070907@Sun.COM>
Sender: Alan.Coopersmith@sun.com
To: Darren J Moffat <Darren.Moffat@sun.com>
Cc: Stuart Kreitman <Stuart.Kreitman@sun.com>,
        Cyril Plisko <cyril.plisko@mountall.com>, LSARC-ext@sun.com
Message-id: <4AAFB626.5030500@sun.com>
MIME-version: 1.0
Content-type: text/plain; CHARSET=US-ASCII
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
X-Enigmail-Version: 0.95.1
References: <200909150157.n8F1vctH014862@sac.sfbay.sun.com>
 <4AAF58ED.6080303@Sun.COM>
 <c7dddeaa0909150220m256dfdc5re364ce574d15a759@mail.gmail.com>
 <4AAF643C.9050500@Sun.COM> <4AAFAC3B.3060307@sun.com>
 <4AAFADC0.1070907@Sun.COM>
User-Agent: Thunderbird 2.0.0.21 (X11/20090323)
Status: RO
Content-Length: 467

Darren J Moffat wrote:
> The bit that still isn't clear to me though is how I know what port
> numbers it is using - I couldn't work that out from the docs.  Is it a
> fixed port number or a dynamic one ?

The ssh port forwarding example on http://synergy2.sourceforge.net/security.html
states "The 24800 is the default network port used by synergy."

-- 
	-Alan Coopersmith-           alan.coopersmith@sun.com
	 Sun Microsystems, Inc. - X Window System Engineering


From Glenn.Faden@sun.com Tue Sep 15 08:58:05 2009
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n8FFw4ks019780
	for <LSARC-ext@sac.sfbay.sun.com>; Tue, 15 Sep 2009 08:58:04 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n8FFvsHV054313
	for <@sunmail2sca.sfbay.sun.com:LSARC-ext@sun.com>; Tue, 15 Sep 2009 09:58:04 -0600 (MDT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KQ000801SCK5200@brm-avmta-1.central.sun.com> for LSARC-ext@sun.com
 (ORCPT LSARC-ext@sun.com); Tue, 15 Sep 2009 09:57:56 -0600 (MDT)
Received: from sca-es-mail-1.sun.com ([192.18.43.132])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KQ00027LSCJC250@brm-avmta-1.central.sun.com> for
 LSARC-ext@sun.com (ORCPT LSARC-ext@sun.com); Tue,
 15 Sep 2009 09:57:56 -0600 (MDT)
Received: from fe-sfbay-10.sun.com ([192.18.43.129])
	by sca-es-mail-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id n8FFvt8b011041	for
 <LSARC-ext@sun.com>; Tue, 15 Sep 2009 08:57:55 -0700 (PDT)
Received: from conversion-daemon.fe-sfbay-10.sun.com by fe-sfbay-10.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.04 64bit (built Jul  2 2009))
 id <0KQ000K00SA4UN00@fe-sfbay-10.sun.com> for LSARC-ext@sun.com
 (ORCPT LSARC-ext@sun.com); Tue, 15 Sep 2009 08:57:55 -0700 (PDT)
Received: from vpn-129-150-220-116.central.sun.com
 ([unknown] [129.150.220.116]) by fe-sfbay-10.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.04 64bit (built Jul  2 2009))
 with ESMTPSA id <0KQ000AB8SC5Y4B0@fe-sfbay-10.sun.com>; Tue,
 15 Sep 2009 08:57:46 -0700 (PDT)
Date: Tue, 15 Sep 2009 08:57:39 -0700
From: Glenn Faden <Glenn.Faden@sun.com>
Subject: Re: Synergy - Mouse/Keyboard sharing [LSARC/2009/489 FastTrack timeout
 09/21/2009]
In-reply-to: <4AAFB446.1040501@sun.com>
Sender: Glenn.Faden@sun.com
To: Alan Coopersmith <Alan.Coopersmith@sun.com>
Cc: Darren J Moffat <Darren.Moffat@sun.com>, LSARC-ext@sun.com,
        Stuart.Kreitman@sun.com, Lokanath Das <Lokanath.Das@sun.com>
Message-id: <4AAFB973.2040104@sun.com>
MIME-version: 1.0
Content-type: text/plain; CHARSET=US-ASCII; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200909150157.n8F1vctH014862@sac.sfbay.sun.com>
 <4AAF58ED.6080303@Sun.COM> <4AAFB446.1040501@sun.com>
User-Agent: Thunderbird 2.0.0.23 (Macintosh/20090812)
Status: RO
Content-Length: 1766

Alan Coopersmith wrote:
> [Added cc of the TX/Xtsol experts to confirm my understanding.  For
>  their benefit, the proposal is to ship the synergy program to share
>  keyboard, mouse & keyboard between X servers on multiple machines.
>  For details, see http://synergy2.sourceforge.net/ and
>  http://arc.opensolaris.org/caselog/LSARC/2009/489/20090914_stuart.kreitman ]
>
> Darren J Moffat wrote:
>   
>> How does this work when the Solaris system is running with Trusted
>> Extensions enabled ? In particular given that the screensaver is a
>> trusted path concept and cut and paste is intercepted on trusted path
>> and subject to authorisation.
>>     
>
> I think the answer is "probably not well, and that's a good thing."
> In order to control the mouse and keyboard on the machines in the
> synergy group, synergy uses an X extension called "XTEST" which was
> originally designed for test suites to simulate input devices.
>
> The TX policy file for X will block usage of the XTEST extension
> in order to prevent clients being able to take control of clients
> with different security labels, so I don't think synergy will be
> able to run in TX by default.
>
> If it could run (such as if you modified the policy file, since it
> is a plain text file a site could vi) it would probably need to run
> in the global zone, and then since it's not label aware, it's
> clipboard sharing would probably violate the protections for copy
> and paste between differently labeled clients.
>
> In short, I think the best answer is probably for us to add a note
> to the man pages stating that synergy is not compatible with the
> restrictions of the TX multi-label desktop, and is not recommended
> for use there.
>   
Alan, I agree with your conclusion.

--Glenn


From Darren.Moffat@sun.com Tue Sep 15 08:59:48 2009
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n8FFxm6X019802
	for <LSARC-ext@sac.sfbay.sun.com>; Tue, 15 Sep 2009 08:59:48 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n8FFxk4N055956
	for <@sunmail2sca.sfbay.sun.com:LSARC-ext@sun.com>; Tue, 15 Sep 2009 09:59:48 -0600 (MDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KQ00000PSFOAJ00@nwk-avmta-2.sfbay.sun.com> for LSARC-ext@sun.com
 (ORCPT LSARC-ext@sun.com); Tue, 15 Sep 2009 08:59:48 -0700 (PDT)
Received: from gmp-eb-inf-1.sun.com ([192.18.6.21])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KQ000KUNSFMCK50@nwk-avmta-2.sfbay.sun.com> for
 LSARC-ext@sun.com (ORCPT LSARC-ext@sun.com); Tue,
 15 Sep 2009 08:59:47 -0700 (PDT)
Received: from fe-emea-10.sun.com
 (gmp-eb-lb-1-fe1.eu.sun.com [192.18.6.7] (may be forged))
	by gmp-eb-inf-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id n8FFxj0u016945	for
 <LSARC-ext@sun.com>; Tue, 15 Sep 2009 15:59:46 +0000 (GMT)
Received: from conversion-daemon.fe-emea-10.sun.com by fe-emea-10.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.04 64bit (built Jul  2 2009))
 id <0KQ000B00QBZFM00@fe-emea-10.sun.com> for LSARC-ext@sun.com
 (ORCPT LSARC-ext@sun.com); Tue, 15 Sep 2009 16:59:29 +0100 (BST)
Received: from [192.168.1.105]
 (cpc2-rdng20-2-0-cust917.15-3.cable.virginmedia.com [86.28.167.150])
 by fe-emea-10.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.04 64bit (built Jul  2 2009))
 with ESMTPSA id <0KQ000LLCSEYAJD0@fe-emea-10.sun.com>; Tue,
 15 Sep 2009 16:59:22 +0100 (BST)
Date: Tue, 15 Sep 2009 16:59:22 +0100
From: Darren J Moffat <Darren.Moffat@sun.com>
Subject: Re: Synergy - Mouse/Keyboard sharing [LSARC/2009/489 FastTrack timeout
 09/21/2009]
In-reply-to: <4AAFB446.1040501@sun.com>
Sender: Darren.Moffat@sun.com
To: Alan Coopersmith <Alan.Coopersmith@sun.com>
Cc: LSARC-ext@sun.com, Stuart.Kreitman@sun.com,
        Glenn Faden <Glenn.Faden@sun.com>, Lokanath Das <Lokanath.Das@sun.com>
Message-id: <4AAFB9DA.2060502@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; CHARSET=US-ASCII; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200909150157.n8F1vctH014862@sac.sfbay.sun.com>
 <4AAF58ED.6080303@Sun.COM> <4AAFB446.1040501@sun.com>
User-Agent: Thunderbird 2.0.0.22 (X11/20090818)
Status: RO
Content-Length: 2219

Alan Coopersmith wrote:
> [Added cc of the TX/Xtsol experts to confirm my understanding.  For
>  their benefit, the proposal is to ship the synergy program to share
>  keyboard, mouse & keyboard between X servers on multiple machines.
>  For details, see http://synergy2.sourceforge.net/ and
>  http://arc.opensolaris.org/caselog/LSARC/2009/489/20090914_stuart.kreitman ]
> 
> Darren J Moffat wrote:
>> How does this work when the Solaris system is running with Trusted
>> Extensions enabled ? In particular given that the screensaver is a
>> trusted path concept and cut and paste is intercepted on trusted path
>> and subject to authorisation.
> 
> I think the answer is "probably not well, and that's a good thing."
> In order to control the mouse and keyboard on the machines in the
> synergy group, synergy uses an X extension called "XTEST" which was
> originally designed for test suites to simulate input devices.
> 
> The TX policy file for X will block usage of the XTEST extension
> in order to prevent clients being able to take control of clients
> with different security labels, so I don't think synergy will be
> able to run in TX by default.

That is what I thought but I'm not familiar with XTEST so I wasn't sure. 
  Thanks for the detailed answer.

> If it could run (such as if you modified the policy file, since it
> is a plain text file a site could vi) it would probably need to run
> in the global zone, and then since it's not label aware, it's
> clipboard sharing would probably violate the protections for copy
> and paste between differently labeled clients.

Doing so would be clearly outside of the Common Criteria evaluated 
configuration so wither it violates or not doesn't mater - just like 
posting the root password on a postit note on the screen would be too. 
If you enable stuff like this we block by default you get what you get.

> In short, I think the best answer is probably for us to add a note
> to the man pages stating that synergy is not compatible with the
> restrictions of the TX multi-label desktop, and is not recommended
> for use there.

That would be nice but I wouldn't require it.

I have not further comments or questions on this case.

-- 
Darren J Moffat

From Darren.Moffat@sun.com Tue Sep 15 09:00:06 2009
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n8FG05SQ019865
	for <LSARC-ext@sac.sfbay.sun.com>; Tue, 15 Sep 2009 09:00:05 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id n8FFxunf006918
	for <@sunmail2sca.sfbay.sun.com:LSARC-ext@sun.com>; Tue, 15 Sep 2009 17:00:04 +0100 (BST)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KQ000L0DSG2BC00@nwk-avmta-1.sfbay.Sun.COM> for LSARC-ext@sun.com
 (ORCPT LSARC-ext@sun.com); Tue, 15 Sep 2009 09:00:02 -0700 (PDT)
Received: from gmp-eb-inf-2.sun.com ([192.18.6.24])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KQ000L59SFZ3E10@nwk-avmta-1.sfbay.Sun.COM> for
 LSARC-ext@sun.com (ORCPT LSARC-ext@sun.com); Tue,
 15 Sep 2009 09:00:00 -0700 (PDT)
Received: from fe-emea-09.sun.com
 (gmp-eb-lb-1-fe1.eu.sun.com [192.18.6.7] (may be forged))
	by gmp-eb-inf-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id n8FFxvR0014802	for
 <LSARC-ext@sun.com>; Tue, 15 Sep 2009 15:59:58 +0000 (GMT)
Received: from conversion-daemon.fe-emea-09.sun.com by fe-emea-09.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.04 64bit (built Jul  2 2009))
 id <0KQ000700SB7KG00@fe-emea-09.sun.com> for LSARC-ext@sun.com
 (ORCPT LSARC-ext@sun.com); Tue, 15 Sep 2009 16:59:53 +0100 (BST)
Received: from [192.168.1.105]
 (cpc2-rdng20-2-0-cust917.15-3.cable.virginmedia.com [86.28.167.150])
 by fe-emea-09.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.04 64bit (built Jul  2 2009))
 with ESMTPSA id <0KQ000BJLSFO6X00@fe-emea-09.sun.com> for LSARC-ext@sun.com
 (ORCPT LSARC-ext@sun.com); Tue, 15 Sep 2009 16:59:49 +0100 (BST)
Date: Tue, 15 Sep 2009 16:59:48 +0100
From: Darren J Moffat <Darren.Moffat@sun.com>
Subject: Re: Synergy - Mouse/Keyboard sharing [LSARC/2009/489 FastTrack	timeout
 09/21/2009]
In-reply-to: <4AAFB626.5030500@sun.com>
Sender: Darren.Moffat@sun.com
To: Alan Coopersmith <Alan.Coopersmith@sun.com>
Cc: Stuart Kreitman <Stuart.Kreitman@sun.com>,
        Cyril Plisko <cyril.plisko@mountall.com>, LSARC-ext@sun.com
Message-id: <4AAFB9F4.4090702@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; CHARSET=US-ASCII; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200909150157.n8F1vctH014862@sac.sfbay.sun.com>
 <4AAF58ED.6080303@Sun.COM>
 <c7dddeaa0909150220m256dfdc5re364ce574d15a759@mail.gmail.com>
 <4AAF643C.9050500@Sun.COM> <4AAFAC3B.3060307@sun.com>
 <4AAFADC0.1070907@Sun.COM> <4AAFB626.5030500@sun.com>
User-Agent: Thunderbird 2.0.0.22 (X11/20090818)
Status: RO
Content-Length: 434

Alan Coopersmith wrote:
> Darren J Moffat wrote:
>> The bit that still isn't clear to me though is how I know what port
>> numbers it is using - I couldn't work that out from the docs.  Is it a
>> fixed port number or a dynamic one ?
> 
> The ssh port forwarding example on http://synergy2.sourceforge.net/security.html
> states "The 24800 is the default network port used by synergy."

Thanks I missed that bit.

-- 
Darren J Moffat

From John.Fischer@sun.com Wed Sep 23 11:19:52 2009
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n8NIJp3J019463
	for <LSARC-ext@sac.sfbay.sun.com>; Wed, 23 Sep 2009 11:19:51 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail2sca.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id n8NIJpRt012610
	for <@sunmail2sca.sfbay.sun.com:LSARC-ext@sun.com>; Wed, 23 Sep 2009 11:19:51 -0700 (PDT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KQF00105S93ES00@brm-avmta-1.central.sun.com> for LSARC-ext@sun.com
 (ORCPT LSARC-ext@Sun.Com); Wed, 23 Sep 2009 12:19:51 -0600 (MDT)
Received: from brmea-mail-4.sun.com ([192.18.98.36])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KQF0049JS93SHF0@brm-avmta-1.central.sun.com> for
 LSARC-ext@sun.com (ORCPT LSARC-ext@Sun.Com); Wed,
 23 Sep 2009 12:19:51 -0600 (MDT)
Received: from fe-amer-09.sun.com ([192.18.109.79])
	by brmea-mail-4.sun.com (8.13.6+Sun/8.12.9) with ESMTP id n8NIJpZj022697	for
 <LSARC-ext@Sun.Com>; Wed, 23 Sep 2009 18:19:51 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.04 64bit (built Jul  2 2009))
 id <0KQF00400S10RJ00@mail-amer.sun.com> for LSARC-ext@Sun.Com
 (ORCPT LSARC-ext@Sun.Com); Wed, 23 Sep 2009 12:19:51 -0600 (MDT)
Received: from [192.168.10.6] ([unknown] [76.20.56.47])
 by mail-amer.sun.com (Sun Java(tm) System Messaging Server 7u2-7.04 64bit
 (built Jul  2 2009)) with ESMTPSA id <0KQF004JZS90VW20@mail-amer.sun.com> for
 LSARC-ext@Sun.Com (ORCPT LSARC-ext@Sun.Com); Wed,
 23 Sep 2009 12:19:48 -0600 (MDT)
Date: Wed, 23 Sep 2009 11:17:11 -0700
From: John Fischer <John.Fischer@sun.com>
Subject: Re: Synergy - Mouse/Keyboard sharing [LSARC/2009/489 FastTrack timeout
 09/21/2009]
In-reply-to: <200909150157.n8F1vctH014862@sac.sfbay.sun.com>
Sender: John.Fischer@sun.com
To: Alan Coopersmith <Alan.Coopersmith@sun.com>
Cc: LSARC-ext@sun.com, Stuart.Kreitman@sun.com
Reply-to: John.Fischer@sun.com
Message-id: <4ABA6627.8050903@sun.com>
MIME-version: 1.0
Content-type: text/plain; CHARSET=US-ASCII; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200909150157.n8F1vctH014862@sac.sfbay.sun.com>
User-Agent: Thunderbird 2.0.0.22 (X11/20090818)
Status: RO
Content-Length: 19802

LSARC,

This case could have been automatically approved as a Familiarity case
if it hadn't been for the fact that it does not support IPv6.  Is the
committee OK with the project not supporting IPv6?

Thanks,

John


Alan Coopersmith wrote:
> I am sponsoring this case for Stuart Kreitman of the X team.
> The timeout is set for next Monday, Sept. 21, 2009.
> 
> 	-Alan Coopersmith-           alan.coopersmith@sun.com
> 	 Sun Microsystems, Inc. - X Window System Engineering
> 
> FCL--FOSS Check List
> 0.  Introduction
> 0.1 Document History
>     Version   Author             Changes					Date
>     0.1       John Fischer       Initial Draft					01/11/2008
>     0.2       John Fischer       Modified based upon feedback from ARC members	01/29/2008
>     0.3       John Fischer       Modified based upon feedback during committee 	02/12/2008
>                                  review
>     0.4       John Fischer       Modified based upon SAC review feedback	04/01/2008
>     0.5	      John Fischer	 Modified based upon LSARC business meeting	06/10/2008
>                                  adding familiarity question and mod dates.
>     0.6       John Fischer       Modified based upon user feedback about        06/20/2008
>                                  sections that were unanswerable.
> 
> 0.2 Purpose
>     Architecture review at Sun has allowed the company to evolve our projects
>     within multiple disjoint groups while still maintaining a cohesive product
>     line.  Each architecture review was conducted within Sun's control.  With
>     the advent of Free Open Source Software processes the control that Sun as
>     a company can wield has been diminished.  Now that Sun is moving to a more
>     fluid delivery mechanism with project Indiana we need to evolve the 
>     architecture review process.  This document is meant to aid in the 
>     architecture review process.  Each new project must complete this check list 
>     to help ensure that the overall resulting product conforms to Sun product 
>     standards.  If the project deviates from these standards further review 
>     would be necessary by an architecture review committee.
>     
>     After the check list is completed the project team should be able to 
>     determine if a project can be automatically approved.  This will occur
>     if all checks result in no "ARC review required" answers.  A committee
>     member will assist the project team in filing the automatically approved 
>     fast track.  An automatically approved fast track is still required in order
>     to record the interfaces for future reference.  If the project needs to 
>     have further review then follow the regular process for getting projects 
>     reviewed.
> 
> 1.0 Project Information
> 1.1 Name of project/component
> 	Synergy - Mouse/Keyboard sharing
> 	1.3.1, April 02-2006
> 
> 1.2 Author of document
> 	Stuart Kreitman
> 
> 2.0 Project Summary
>   2.1 Project Description
> 	Synergy lets you easily share a single mouse and keyboard between multiple computers with different operating systems, each with its own display, without special hardware. It's intended for users with multiple computers on their desk since each system uses its own monitor(s).
> 
> Redirecting the mouse and keyboard is as simple as moving the mouse off the edge of your screen. Synergy also merges the clipboards of all the systems into one, allowing cut-and-paste between systems. Furthermore, it synchronizes screen savers so they all start and stop together and, if screen locking is enabled, only one screen requires a password to unlock them all. 
>   
>   2.2 Release binding
>       What is is the release binding?
>       (see http://opensolaris.org/os/community/arc/policies/release-taxonomy/)
>       [ ] Major
>       [X] Minor
>       [ ] Patch or Micro
>       [ ] Unknown -- ARC review required
> 
>   2.3 Type of project
>       Is this case a Linux Familiarity project?
>       [X] Yes
>       [ ] No
> 
>   2.4 Originating Community
>     2.4.1 Community Name
> 	Synergy is hosted on Sourceforge.  http://synergy2.sourceforge.net
>     
>     2.4.2 Community Involvement
>       Indicate Sun's involvement in the community
>       [ ] Maintainer
>       [ ] Contributor
>       [X] Monitoring
>       
>       Will the project team work with the upstream community to resolve
>       architectural issues of interest to Sun?
>       [X] Yes 
>       [ ] No - briefly explain
>       
>       Will we or are we forking from the community?
>       [ ] Yes - ARC review required prior to forking
>       [X] No
>       
> 3.0 Technical Description
>   3.1 Installation & Sharable
>     3.1.1S Solaris Installation - section only required for Solaris Software
>       (see http://opensolaris.org/os/community/arc/policies/install-locations/ for details)
>       Does this project follow the Install Locations best practice?
>       [X] Yes 
>       [ ] No - ARC review required
>       
>       Does this project install into /usr under [sbin|bin|lib|include|man|share]?
>       [X] Yes
>       [ ] No or N/A
>       
>       Does this project install into /opt?
>       [ ] Yes - explain below
>       [X] No or N/A
>       
>       Does this project install into a different directory structure?
>       [ ] Yes - ARC review required
>       [X] No or N/A
>       
>       Do any of the components of this project conflict with anything under /usr?
>       (see http://opensolaris.org/os/community/arc/caselog/2007/047/ for details)
>       [ ] Yes - explain below
>       [X] No
>       
>       If conflicts exist then will this project install under /usr/gnu?
>       [ ] Yes
>       [ ] No - ARC review required
>       [X] N/A
>       
>       Is this project installing into /usr/sfw?
>       [ ] Yes - ARC review required
>       [X] No
>       
>     3.1.1W Windows Installation - section only required for Windows Software
>       (see http://sac.sfbay/WSARC/2002/494 for details)
>       Does this project install software into a 
>       <system drive>:\Program Files\Sun\<product> or <system drive>:\Sun\<product>
>       directory?
>       [ ] Yes
>       [ ] No - ARC review required
>       
>       Does the project use the Windows registry?
>       [ ] Yes
>       [ ] No - ARC review required
>       
>       Does the project use 
>       HKEY_LOCAL_MACHINE\SOFTWARE\Sun Microsystems\<product>\<version>
>       for the registry key?
>       [ ] Yes
>       [ ] No - ARC review required
>       
>       Is the project's stored location
>       HKEY_LOCAL_MACHINE\SOFTWARE\Sun Microsystems\<product id>\<version id>\Path?
>       [ ] Yes
>       [ ] No - ARC review required
>       
>     3.1.2 Share and Sharable
>       Does the module include any components that are used or shared by 
>       other projects?
>       [ ] Yes
>       [X] No
>     
>       If yes are these components packaged to be shared with the other FOSS?
>       [ ] Yes
>       [ ] No - ARC review required
>       [ ] N/A
>     
>       Are these components already in the Solaris WOS?
>       [ ] Yes
>       [ ] No - continue with next section (section 3.2)
>     
>       If yes are these newer versions being delivered?
>       [ ] Yes
>       [ ] No - ARC review required
>       
>       If yes are the newer versions replacing the existing versions?
>       [ ] Yes
>       [ ] No - ARC review required
> 
>   3.2 Exported Libraries
>       Are libraries being delivered by this project?
>       [ ] Yes
>       [X] No - continue with next section (section 3.3)
>       
>       Are 64-bit versions of the libraries being delivered?
>       [ ] Yes
>       [ ] No - ARC review required
>     
>       Are static versions of the libraries being delivered?
>       [ ] Yes - ARC review required
>       [ ] No 
>       
>   3.3 Services and the /etc Directory
>       (see http://opensolaris.org/os/community/arc/policies/SMF-policy/)
>       Does the project integrate anything into /etc/init.d or /etc/rc?.d?
>       [ ] Yes - ARC review required
>       [X] No
>       
>       Does the project integrate any new entries into /etc/inittab or
>       /etc/inetd.conf?
>       [ ] Yes - ARC review required
>       [X] No
>       
>       Does the project integrate any private non-public files into /etc/default
>       or /etc/ configuration files?
>       [ ] Yes - ARC review required
>       [X] No
>       
>       Does the service manifests method context grant rights above that
>       of the noaccess user and basic privilege set?
>       [ ] Yes - ARC review required
>       [X] No
>         
>   3.4 Security
>     3.4.1 Secure By Default 
>       (see http://opensolaris.org/os/community/arc/policies/secure-by-default/ for details)
>       (see http://www.opensolaris.org/os/community/arc/policies/NITS-policy/ for details)
>       (see parts of http://opensolaris.org/os/community/arc/policies/SMF-policy/ for
>        addtional details)
>       Are there any network services provided by this project?
>       [X] Yes
>       [ ] No - continue with the next section (section 3.4.2)
>       
>       Are network services enabled by default?
>       [ ] Yes - ARC review required
>       [X] No
>       [ ] N/A
>       
>       Are network services automatically enabled by the project during installation?
>       [ ] Yes - ARC review required
>       [X] No
>       [ ] N/A
>       
>       Are inbound network communications denied by default?
>       [ ] Yes
>       [X] No - ARC review required
>       [ ] N/A
>       
>       Is inbound data checked to prevent content-based attacks?
>       [ ] Yes
>       [X] No - ARC review required
>       [ ] N/A
>       
>       Is the outbound receiver authenticated?
>       [ ] Yes
>       [X] No - ARC review required. 
> 		Synergy provides no security, but can be configured to run through ssh.
> 		See http://synergy2.sourceforge.net/security.html 
>       [ ] N/A
>       
>       Is the receiver authenticated prior to receiving any sensitive outbound communication?
>       [ ] Yes
>       [X] No - ARC review required
> 		See above
>       [ ] N/A
>       
>     3.4.2 Authorization
>       (see http://opensolaris.org/os/community/arc/bestpractices/rbac-intro/ and
> 	   http://opensolaris.org/os/community/arc/bestpractices/rbac-profiles/ and
> 	   http://opensolaris.org/os/community/arc/bestpractices/rbac-profiles/
>            for details)
>       Are there any setuid/setgid privileged binaries in the project?
>       [ ] Yes - ARC review required
>       [X] No - continue with next section (section 3.4.3)
>       
>       If yes then are the setuid/setgid privileges handled by the use of roles?
>       [ ] Yes
>       [ ] No - ARC review required
> 
>     3.4.3 Auditing
>       (see http://opensolaris.org/os/community/arc/policies/audit-policy/ for details)
>       (see http://opensolaris.org/os/community/arc/caselog/2003/397 for details)
>       Does this component contain administrative or security enforcing software?
>       [ ] Yes - ARC review required
>       [X] No - continue to next section (section 3.4.4)
>       
>       (see http://opensolaris.org/os/community/arc/caselog/2003/397 for details)
>       Do the components create audit logs detailing what took place including what event
>       took place, who was involved, when the event took place?
>       [ ] Yes - ARC contract and Audit project team review required
>       [ ] No - ARC review required
>         
>         
>     3.4.4 Authentication
>       (see http://opensolaris.org/os/community/arc/policies/PAM/)
>       Do the components contain any authentication code?
>       [ ] Yes
>       [X] No - continue to next section (section 3.4.5)
>       
>       If yes do the components use PAM (plugable authentication modules) for authentication?
>       [ ] Yes
>       [ ] No - ARC review required
>       
>       If yes is a single PAM session maintained during authentication?
>       [ ] Yes
>       [ ] No - ARC review required
>       
>       If yes are the components sufficiently privileged to allow the requested 
>       operations (authentication, password change, process credential manipulation, 
>       audit state initialization)?
>       [ ] Yes - briefly describe below
>       [ ] No - ARC review required
>       
>     3.4.5 Passwords
>       (see http://opensolaris.org/os/community/arc/bestpractices/passwords-cli/ and
>            http://opensolaris.org/os/community/arc/bestpractices/passwords-files/ for details)
>       Do any of the components for the project deal with passwords?
>       [ ] Yes
>       [X] No - continue to next section (section 3.4.6)
>       
>       If yes are these passwords entered via the CLI or environment?
>       [ ] Yes - ARC review required
>       [ ] No
>       
>       Are passwords stored within the file system for the component?
>       [ ] Yes
>       [ ] No - continue to next section (section 3.4.6)
>       
>       If yes are the permissions on the file such to protect exposing the password(s)?
>       [ ] Yes
>       [ ] No - ARC review required
>       
>     3.4.6 General Security Questions
>       (see http://opensolaris.org/os/community/arc/bestpractices/security-questions/ for details)
>       Are there any network protocols used by this project?
>       [X] Yes
>       [ ] No - continue with the next section (section 3.5)
>       
>       Do the components use standard network protocols?
>       [X] Yes
>       [ ] No - ARC review required
>       
>       Do network services for the project make decisions based upon user, host or 
>       service identities?
>       [ ] Yes - explain below
>       [X] No
>       [ ] N/A
>       
>       Do the components make use of secret information during authentication and/or
>       authorization?
>       [ ] Yes - explain below
>       [X] No
>       [ ] N/A
>   
>   3.5 Networking
>       Do the components access the network?
>       [X] Yes
>       [ ] No - continue with the next section (section 3.6)
>       
>       If yes do the components support IPv6?
>       [ ] Yes 
>       [X] No - ARC review required
>           
>   3.6 Core Solaris Components
>       Do the components of this project compete with or duplicate core 
>       Solaris components?
>       [ ] Yes - ARC review required
>       [X] No 
>       
>       Examples of Core Solaris Components include but are not limited to:
>       
>         Secure By Default
>         Authorizations
>         PAM -- Plugable Authentication Module
>         Privilege
>         PRM -- Process Rights Management -- Privilege
>         Audit
>         xVm -- Virtualization
>         zones / Solaris Containers
>         PRM -- Process Rights Management
>         RBAC -- Role Based Access Control
>         TX / Trusted Extensions
>         ZFS
>         SMF -- Service Management Facility
>         FMA -- Fault Management Architecture
>         SCF -- Smart Card Facility
>         IPsec
>         
> 4.0 Interfaces
>   (see http://www.opensolaris.org/os/community/arc/policies/interface-taxonomy/ for details)
>   4.1 Exported Interfaces
>   
>     Interface Name		Classification      Comments
>     --------------------------- ------------------- ---------------------------
>     synergys(1)			Committed           version 1.3.1
>     synergyc(1)			Committed           version 1.3.1
>     
>   4.2 Imported Interfaces
>     Interface Name		Classification       Comments
>     --------------------------- -------------------- --------------------------
>     
>     
>   Brief Interface Classifications - See Appendix C for definitions
>     Volatile - interfaces are fluid and will follow a rapidly changing community
>     Uncommitted - interfaces are still evolving in the community and might follow
> 		  the community
>     Committed - interfaces are stable in the community
>     Project Private - no review required, just document in table
>     Contracted (interface modifier) - further review required
> 
> Appendix A - References
>   1.  Solaris Installation Locations Policy
>       http://opensolaris.org/os/community/arc/policies/install-locations/
>   2.  /usr/gnu Installation ARC case
>       http://opensolaris.org/os/community/arc/caselog/2007/047/
>   3.  Secure By Default Policy
>       http://opensolaris.org/os/community/arc/policies/secure-by-default/
>   4.  Network Install Time Securityuy Policy
>       http://www.opensolaris.org/os/community/arc/policies/NITS-policy/
>   5.  Adding RBAC Authorizations Policy
>       http://opensolaris.org/os/community/arc/bestpractices/rbac-auths/
>   6.  When to use setuid -vs- RBAC roles and profiles
>       http://opensolaris.org/os/community/arc/bestpractices/rbac-intro/ and
>   7.  Building RBAC Rights Profiles
>       http://opensolaris.org/os/community/arc/bestpractices/rbac-profiles/
>   8.  Solaris Audit Policy
>       http://opensolaris.org/os/community/arc/policies/audit-policy/
>   9.  Security questionaire
>       http://opensolaris.org/os/community/arc/bestpractices/security-questions/
>   10. Interface Taxonomy
>       http://www.opensolaris.org/os/community/arc/policies/interface-taxonomy/
>   11. Plugable Authentication Modules -- PAM
>       http://opensolaris.org/os/community/arc/policies/PAM/
>   12. Reusable Passwords In Command Line Arguments and Environment Variables
>       http://opensolaris.org/os/community/arc/bestpractices/passwords-cli/
>   13. Storing Reusable Passwords on a Filesystem
>       http://opensolaris.org/os/community/arc/bestpractices/passwords-files/
>   14. Release Taxonomy
>       http://opensolaris.org/os/community/arc/policies/release-taxonomy/
>   15. Service Management Facility (SMF) usage
>       http://opensolaris.org/os/community/arc/policies/SMF-policy/
> 
>   
> Appendix B - Suggested case materials
>   1. man pages
>   2. SMF manifests
>   3. links to contracts
>   
> Appendix C - Definitions
> Submitter
>      an agent responsible for creation of an ARC project along with the
>      materials describing that project.
> Owner
>      the ARC agent responsible for shepherding the case through review
>      and ensuring a formal opinion is written where required.
> Maintainer
>      an agent responsible for releasing new versions of a program, typically
>      the "main" contributor or person incharge of making Architectural
>      decisions for the project
> Contributor
>      an agent who make contributions to a project, typically has a voice in
>      making Architectural decisions for the project
> Monitoring
>      an agent who is only following the changes made in the community and
>      has no Architectural input into the project
> Volatile*
>     interfaces that are very fluid and typically follow the originating 
>     community.  Typically these interfaces can not be imported by other
>     projects.
> Uncommitted*
>     interfaces that are still evolving but will most likely be present from
>     release to release.
> Committed*
>     interfaces that are stable and with Sun guaranteeing some level of
>     compatibility from release to release.
> Project Private*
>     interfaces that are exposed only to or intended to be used only by
>     the project being reviewed.  These interfaces can not be imported by
>     other projects.
> Not-An-Interface*
>     components that are not interfaces.
> Contracted* (interface modifier) - ARC review of Contract required
>     interfaces that do not allow another project to import can be 
> 
> *Note: see http://opensolaris.org/os/community/arc/policies/interface-taxonomy/ for details
> 
> 6. Resources and Schedule
>     6.4. Steering Committee requested information
>    	6.4.1. Consolidation C-team Name:
> 		X Consolidation (Desktop C-Team)
>     6.5. ARC review type: FastTrack
>     6.6. ARC Exposure: open
> 

From Alan.Coopersmith@sun.com Tue Oct  6 10:30:38 2009
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n96HUbCw013180
	for <LSARC-ext@sac.sfbay.sun.com>; Tue, 6 Oct 2009 10:30:38 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id n96HT3wm026670
	for <@sunmail2sca.sfbay.sun.com:LSARC-ext@sun.com>; Tue, 6 Oct 2009 18:30:37 +0100 (BST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KR30090DSMUIQ00@brm-avmta-1.central.sun.com> for LSARC-ext@sun.com
 (ORCPT LSARC-ext@Sun.Com); Tue, 06 Oct 2009 11:30:30 -0600 (MDT)
Received: from sca-es-mail-1.sun.com ([192.18.43.132])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KR300MTUSMUHG60@brm-avmta-1.central.sun.com> for
 LSARC-ext@sun.com (ORCPT LSARC-ext@Sun.Com); Tue,
 06 Oct 2009 11:30:30 -0600 (MDT)
Received: from fe-sfbay-09.sun.com ([192.18.43.129])
	by sca-es-mail-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id n96HUUEl011054	for
 <LSARC-ext@Sun.Com>; Tue, 06 Oct 2009 10:30:30 -0700 (PDT)
Received: from conversion-daemon.fe-sfbay-09.sun.com by fe-sfbay-09.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.04 64bit (built Jul  2 2009))
 id <0KR300L00SEA9V00@fe-sfbay-09.sun.com> for LSARC-ext@Sun.Com
 (ORCPT LSARC-ext@Sun.Com); Tue, 06 Oct 2009 10:30:30 -0700 (PDT)
Received: from [129.145.155.53] ([unknown] [129.145.155.53])
 by fe-sfbay-09.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.04 64bit (built Jul  2 2009))
 with ESMTPSA id <0KR300HS4SMFJD30@fe-sfbay-09.sun.com> for LSARC-ext@Sun.Com
 (ORCPT LSARC-ext@Sun.Com); Tue, 06 Oct 2009 10:30:15 -0700 (PDT)
Date: Tue, 06 Oct 2009 10:30:15 -0700
From: Alan Coopersmith <Alan.Coopersmith@sun.com>
Subject: Re: Synergy - Mouse/Keyboard sharing [LSARC/2009/489 FastTrack timeout
 09/21/2009]
In-reply-to: <200909150157.n8F1vctH014862@sac.sfbay.sun.com>
Sender: Alan.Coopersmith@sun.com
To: LSARC-ext@sun.com
Cc: Stuart.Kreitman@sun.com
Message-id: <4ACB7EA7.10000@sun.com>
MIME-version: 1.0
Content-type: text/plain; CHARSET=US-ASCII
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
X-Enigmail-Version: 0.95.1
References: <200909150157.n8F1vctH014862@sac.sfbay.sun.com>
User-Agent: Thunderbird 2.0.0.22 (X11/20090720)
Status: RO
Content-Length: 464

Alan Coopersmith wrote:
> I am sponsoring this case for Stuart Kreitman of the X team.
> The timeout is set for next Monday, Sept. 21, 2009.

I'm told LSARC approved this at last week's meeting (Stuart & I were
at the X.Org conference so were unable to attend ourselves), so have
marked the case closed approved.

Thank you for your consideration.

-- 
	-Alan Coopersmith-           alan.coopersmith@sun.com
	 Sun Microsystems, Inc. - X Window System Engineering


