From dhain@sac.sfbay.sun.com Wed Jul 16 10:53:44 2008
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m6GHriOD002999
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 16 Jul 2008 10:53:44 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m6GHrhOj055743;
	Wed, 16 Jul 2008 11:53:44 -0600 (MDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K4400K0J1PJSC00@nwk-avmta-2.sfbay.sun.com>; Wed,
 16 Jul 2008 10:53:43 -0700 (PDT)
Received: from dm-sfbay-02.sfbay.sun.com ([129.146.11.31])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K4400JIY1PIQE10@nwk-avmta-2.sfbay.sun.com>; Wed,
 16 Jul 2008 10:53:42 -0700 (PDT)
Received: from sac.sfbay.sun.com (new-sac.SFBay.Sun.COM [129.146.175.65])
	by dm-sfbay-02.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id m6GHrfNL033745; Wed, 16 Jul 2008 10:53:41 -0700 (PDT)
Received: from sac.sfbay.sun.com (localhost [127.0.0.1])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m6GHrdwt002994; Wed,
 16 Jul 2008 10:53:39 -0700 (PDT)
Received: (from dhain@localhost)
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8/Submit) id m6GHrdR4002990; Wed,
 16 Jul 2008 10:53:39 -0700 (PDT)
Date: Wed, 16 Jul 2008 10:53:39 -0700 (PDT)
From: Daniel Hain <dhain@sac.sfbay.sun.com>
Subject: Integrate pwgen into Solaris. [PSARC/2008/453 FastTrack timeout
 07/23/2008]
To: PSARC-ext@sun.com
Cc: Martin.Rehak@sun.com
Message-id: <200807161753.m6GHrdR4002990@sac.sfbay.sun.com>
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
Status: RO
Content-Length: 2125

I am sponsoring the following fasttrack for Martin Rehak, requesting minor
binding and a timeout of 07/23/2008. Man page is in the case directory.

- Dan

Template Version: @(#)sac_nextcase 1.66 04/17/08 SMI
This information is Copyright 2008 Sun Microsystems
1. Introduction
    1.1. Project/Component Working Name:
	 Integrate pwgen into Solaris.
    1.2. Name of Document Author/Supplier:
	 Author:  Martin Rehak
    1.3  Date of This Document:
	16 July, 2008
4. Technical Description
Proposal:

        Integrate pwgen into Solaris.

Detail:

	pwgen is a tool which is able to create easily memorizable passwords
	while being as secure as possible. The tool is able to distinguish
	whether the output is a tty or a pipe. Single password will be written
	to a pipe. Screen full of passwords will be generated when the tool
	believes user is looking at the output. There are dozen of switches
	modifing it's behavior. It can produce wide range of passwords from
	those very simple but almost unsecure to those not being easily
	memorizable but far more secure. One can choose various modes enabling
	or disabling usage of capital letters, numbers, vowels or symbols. There
	is a possibility to specify the seed for pseudo random device.

        The current version of pwgen is 2.06 (05/05/2008).

Exported Interfaces:

        SUNWpwgen		Uncommited		Package name
	/usr/bin/pwgen		Commited		Executable location
	/usr/bin/amd64/pwgen	Commited		Executable location
	/usr/bin/sparcv9/pwgen	Commited		Executable location
	pwgen			Uncommited		Commandline syntax
	pwgen output		Uncommited

Deliverables:

	usr/bin/pwgen
	usr/man/man1/pwgen.1

Dependencies:

	libc.so.1 =>     /lib/libc.so.1
        libm.so.2 =>     /lib/libm.so.2

Documentation:

	man page: pwgen.1

References:

	[1] http://sourceforge.net/projects/pwgen/ - home page
	    Author(s) of pwgen: Theodore Ts'o.

	[2] 6670232 pwgen 2.06 to be integrated into SFW consolidation


6. Resources and Schedule
    6.4. Steering Committee requested information
   	6.4.1. Consolidation C-team Name:
		sfw
    6.5. ARC review type: FastTrack
    6.6. ARC Exposure: open


From Darren.Moffat@sun.com Wed Jul 16 13:28:58 2008
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m6GKSvpK009377
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 16 Jul 2008 13:28:58 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id m6GKSrF3029611
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Wed, 16 Jul 2008 21:28:56 +0100 (BST)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K4400F0T8W6KP00@nwk-avmta-1.sfbay.Sun.COM> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Wed, 16 Jul 2008 13:28:54 -0700 (PDT)
Received: from gmp-eb-inf-1.sun.com ([192.18.6.21])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K44001XM8W4VCD0@nwk-avmta-1.sfbay.Sun.COM> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Wed,
 16 Jul 2008 13:28:53 -0700 (PDT)
Received: from fe-emea-10.sun.com (gmp-eb-lb-2-fe3.eu.sun.com [192.18.6.12])
	by gmp-eb-inf-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id m6GKSqmY005030	for
 <PSARC-ext@sun.com>; Wed, 16 Jul 2008 20:28:52 +0000 (GMT)
Received: from conversion-daemon.fe-emea-10.sun.com by fe-emea-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0K44006018TW5600@fe-emea-10.sun.com>
 (original mail from Darren.Moffat@Sun.COM)
 for PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Wed,
 16 Jul 2008 21:28:52 +0100 (BST)
Received: from [129.146.109.170] by fe-emea-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 with ESMTPSA id <0K4400KEB8W16X70@fe-emea-10.sun.com>; Wed,
 16 Jul 2008 21:28:52 +0100 (BST)
Date: Wed, 16 Jul 2008 21:28:49 +0100
From: Darren J Moffat <Darren.Moffat@sun.com>
Subject: Re: Integrate pwgen into Solaris. [PSARC/2008/453 FastTrack timeout
 07/23/2008]
In-reply-to: <200807161753.m6GHrdR4002990@sac.sfbay.sun.com>
Sender: Darren.Moffat@sun.com
To: Daniel Hain <dhain@sac.sfbay.sun.com>
Cc: PSARC-ext@sun.com, Martin.Rehak@sun.com
Message-id: <487E5A01.1010308@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200807161753.m6GHrdR4002990@sac.sfbay.sun.com>
User-Agent: Thunderbird 2.0.0.14 (X11/20080519)
Status: RO
Content-Length: 632

Daniel Hain wrote:
> Exported Interfaces:
> 
>         SUNWpwgen		Uncommited		Package name
> 	/usr/bin/pwgen		Commited		Executable location
> 	/usr/bin/amd64/pwgen	Commited		Executable location
> 	/usr/bin/sparcv9/pwgen	Commited		Executable location

What is the rationale for having a 32 and 64 bit version of this program ?

Can this be built as a library (say libpwgen) so that we can implement a 
PAM module around this ?  I see value in it being a standalone program 
but even more value in also having a PAM module (this would be used 
instead of or stacked above pam_authtok_get in some configurations).

--
Darren J Moffat


From Daniel.Hain@Sun.COM Wed Jul 16 13:41:53 2008
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m6GKfqvi009502
	for <psarc-ext@sac.sfbay.Sun.COM>; Wed, 16 Jul 2008 13:41:53 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id m6GKfpHX002316
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Thu, 17 Jul 2008 04:41:52 +0800 (SGT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K440012T9HQAP00@brm-avmta-1.central.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Wed, 16 Jul 2008 14:41:50 -0600 (MDT)
Received: from sca-es-mail-1.sun.com ([192.18.43.132])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K4400DWR9HN50B0@brm-avmta-1.central.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Wed,
 16 Jul 2008 14:41:47 -0600 (MDT)
Received: from fe-sfbay-09.sun.com ([192.18.43.129])
	by sca-es-mail-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id m6GKflAV002197	for
 <PSARC-ext@sun.com>; Wed, 16 Jul 2008 13:41:47 -0700 (PDT)
Received: from conversion-daemon.fe-sfbay-09.sun.com by fe-sfbay-09.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0K44008019DM2Z00@fe-sfbay-09.sun.com>
 (original mail from Daniel.Hain@Sun.COM)
 for PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Wed,
 16 Jul 2008 13:41:47 -0700 (PDT)
Received: from [129.153.88.138] by fe-sfbay-09.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 with ESMTPSA id <0K44004TZ9HJ0080@fe-sfbay-09.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Wed, 16 Jul 2008 13:41:43 -0700 (PDT)
Date: Wed, 16 Jul 2008 13:42:10 -0700
From: Daniel Hain <Daniel.Hain@Sun.COM>
Subject: Re: Integrate pwgen into Solaris. [PSARC/2008/453 FastTrack timeout
 07/23/2008]
In-reply-to: <487E5A01.1010308@Sun.COM>
Sender: Daniel.Hain@Sun.COM
To: PSARC-ext@Sun.COM
Cc: Martin.Rehak@Sun.COM
Message-id: <487E5D22.2070100@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200807161753.m6GHrdR4002990@sac.sfbay.sun.com>
 <487E5A01.1010308@Sun.COM>
User-Agent: Thunderbird 2.0.0.12 (X11/20080310)
Status: RO
Content-Length: 1150

Darren J Moffat wrote:
> Daniel Hain wrote:
>> Exported Interfaces:
>>
>>         SUNWpwgen        Uncommited        Package name
>>     /usr/bin/pwgen        Commited        Executable location
>>     /usr/bin/amd64/pwgen    Commited        Executable location
>>     /usr/bin/sparcv9/pwgen    Commited        Executable location
>
> What is the rationale for having a 32 and 64 bit version of this 
> program ?

Mostly so we didn't have to explain why there wasn't a 64-bit version.  
No performance gains or special changes going to 64-bit.  They can be 
omitted if it is a concern.

-- 
Dan Hain 
Solaris Revenue Product Engineering (RPE)



From carlsonj@phorcys.east.sun.com Wed Jul 16 13:53:10 2008
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m6GKrAQi009794
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 16 Jul 2008 13:53:10 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m6GKr8Sp027240;
	Wed, 16 Jul 2008 13:53:08 -0700 (PDT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K440020ZA0J5B00@brm-avmta-1.central.sun.com>; Wed,
 16 Jul 2008 14:53:07 -0600 (MDT)
Received: from phorcys.east.sun.com ([129.148.174.143])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K4400D5VA0I58D0@brm-avmta-1.central.sun.com>; Wed,
 16 Jul 2008 14:53:06 -0600 (MDT)
Received: from phorcys.east.sun.com (localhost [127.0.0.1])
	by phorcys.east.sun.com (8.14.3+Sun/8.14.3) with ESMTP id m6GKr6Tm012822; Wed,
 16 Jul 2008 16:53:06 -0400 (EDT)
Received: (from carlsonj@localhost)
	by phorcys.east.sun.com (8.14.3+Sun/8.14.3/Submit) id m6GKr6M8012819; Wed,
 16 Jul 2008 16:53:06 -0400 (EDT)
Date: Wed, 16 Jul 2008 16:53:06 -0400
From: James Carlson <james.d.carlson@sun.com>
Subject: Re: Integrate pwgen into Solaris. [PSARC/2008/453 FastTrack timeout
	07/23/2008]
In-reply-to: <487E5D22.2070100@sun.com>
To: Daniel Hain <Daniel.Hain@sun.com>
Cc: PSARC-ext@sun.com, Martin.Rehak@sun.com
Message-id: <18558.24498.306742.880103@gargle.gargle.HOWL>
MIME-version: 1.0
X-Mailer: VM 7.01 under Emacs 21.3.1
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200807161753.m6GHrdR4002990@sac.sfbay.sun.com>
 <487E5A01.1010308@Sun.COM> <487E5D22.2070100@sun.com>
Status: RO
Content-Length: 983

Daniel Hain writes:
> Darren J Moffat wrote:
> > Daniel Hain wrote:
> >> Exported Interfaces:
> >>
> >>         SUNWpwgen        Uncommited        Package name
> >>     /usr/bin/pwgen        Commited        Executable location
> >>     /usr/bin/amd64/pwgen    Commited        Executable location
> >>     /usr/bin/sparcv9/pwgen    Commited        Executable location
> >
> > What is the rationale for having a 32 and 64 bit version of this 
> > program ?
> 
> Mostly so we didn't have to explain why there wasn't a 64-bit version.  
> No performance gains or special changes going to 64-bit.  They can be 
> omitted if it is a concern.

Unless they do something useful, I'd suggest ditching 'em.  Disk space
is cheap, but that's no reason to fill it up.  ;-}

-- 
James Carlson, Solaris Networking              <james.d.carlson@sun.com>
Sun Microsystems / 35 Network Drive        71.232W   Vox +1 781 442 2084
MS UBUR02-212 / Burlington MA 01803-2757   42.496N   Fax +1 781 442 1677

From Martin.Rehak@sun.com Thu Jul 17 00:56:01 2008
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m6H7u0St028006
	for <psarc-ext@sac.sfbay.Sun.COM>; Thu, 17 Jul 2008 00:56:00 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id m6H7ttLw024016
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Thu, 17 Jul 2008 15:55:59 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K450010D4P73500@nwk-avmta-1.sfbay.Sun.COM> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Thu, 17 Jul 2008 00:55:55 -0700 (PDT)
Received: from gmp-eb-inf-1.sun.com ([192.18.6.21])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K4500KGU4P60170@nwk-avmta-1.sfbay.Sun.COM> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Thu,
 17 Jul 2008 00:55:55 -0700 (PDT)
Received: from fe-emea-09.sun.com (gmp-eb-lb-2-fe2.eu.sun.com [192.18.6.11])
	by gmp-eb-inf-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id m6H7tsi1028072	for
 <PSARC-ext@sun.com>; Thu, 17 Jul 2008 07:55:54 +0000 (GMT)
Received: from conversion-daemon.fe-emea-09.sun.com by fe-emea-09.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0K4500J0140PD800@fe-emea-09.sun.com>
 (original mail from Martin.Rehak@Sun.COM)
 for PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Thu,
 17 Jul 2008 08:55:54 +0100 (BST)
Received: from marvin.tekkirk.org ([213.168.185.200])
 by fe-emea-09.sun.com (Sun Java System Messaging Server 6.2-8.04 (built Feb 28
 2007)) with ESMTPSA id <0K45004CD4OY2ZG0@fe-emea-09.sun.com>; Thu,
 17 Jul 2008 08:55:47 +0100 (BST)
Date: Thu, 17 Jul 2008 09:55:45 +0200
From: Martin Rehak <Martin.Rehak@sun.com>
Subject: Re: Integrate pwgen into Solaris. [PSARC/2008/453 FastTrack timeout
 07/23/2008]
In-reply-to: <487E5A01.1010308@Sun.COM>
Sender: Martin.Rehak@sun.com
To: Darren J Moffat <Darren.Moffat@sun.com>
Cc: Daniel Hain <dhain@sac.sfbay.sun.com>, PSARC-ext@sun.com
Message-id: <487EFB01.4040307@Sun.COM>
MIME-version: 1.0
Content-type: multipart/mixed; boundary="Boundary_(ID_Q/+yt30mxP/5qzSESsYE0Q)"
X-PMX-Version: 5.4.1.325704
References: <200807161753.m6GHrdR4002990@sac.sfbay.sun.com>
 <487E5A01.1010308@Sun.COM>
User-Agent: Thunderbird 2.0.0.14 (X11/20080507)
Status: RO
Content-Length: 2626

This is a multi-part message in MIME format.

--Boundary_(ID_Q/+yt30mxP/5qzSESsYE0Q)
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT

Hi Darren,

Darren J Moffat wrote:
> Daniel Hain wrote:
>> Exported Interfaces:
>>
>>         SUNWpwgen        Uncommited        Package name
>>     /usr/bin/pwgen        Commited        Executable location
>>     /usr/bin/amd64/pwgen    Commited        Executable location
>>     /usr/bin/sparcv9/pwgen    Commited        Executable location
> 
> What is the rationale for having a 32 and 64 bit version of this program ?
> 
> Can this be built as a library (say libpwgen) so that we can implement a 
> PAM module around this ?  I see value in it being a standalone program 
> but even more value in also having a PAM module (this would be used 
> instead of or stacked above pam_authtok_get in some configurations).

I think it is possible after slight code modification.

I have found that pwgen.c containing main() function just parses command 
line, sets up few variables indicating modes and conditions under which 
passwords will be generated and calls pwgen() function which finally 
does the work. I can imagine to make a library from objects. This 
library on one hand can be used to build a tool and to be ready for 
general use on the other hand. It would be necessary to update manual 
(man page) to document the interface.

This is how it gets compiled so far:
<snip>
ligi@marvin ~/doc/project/sun/oss/wrk/pwgen/pwgen-2.06 $ make
gcc -c  -DHAVE_DRAND48=1 -DHAVE_GETOPT_LONG=1 -DHAVE_GETOPT_H=1  -g -O2 
  pwgen.c -o pwgen.o
gcc -c  -DHAVE_DRAND48=1 -DHAVE_GETOPT_LONG=1 -DHAVE_GETOPT_H=1  -g -O2 
  pw_phonemes.c -o pw_phonemes.o
...
gcc -c  -DHAVE_DRAND48=1 -DHAVE_GETOPT_LONG=1 -DHAVE_GETOPT_H=1  -g -O2 
  sha1num.c -o sha1num.o
gcc  -o pwgen pwgen.o pw_phonemes.o pw_rand.o randnum.o sha1.o sha1num.o
</snip>

This is how the worker function gets called:
<snip>
                 pwgen(buf, pw_length, pwgen_flags);
</snip>
where buf is a buffer to which passwords will be generated and pw_length 
and pwgen_flags specifies the generation mode.

Would it usable?

Regards
Martin

> 
> -- 
> Darren J Moffat
> 

--Boundary_(ID_Q/+yt30mxP/5qzSESsYE0Q)
Content-type: text/x-vcard; name=martin_rehak.vcf; charset=utf-8
Content-transfer-encoding: 7BIT
Content-disposition: attachment; filename=martin_rehak.vcf

begin:vcard
fn:Martin Rehak
n:Rehak;Martin
org:;Solaris Revenue Product Engineer (RPE)
email;internet:martin.rehak@sun.com
title:Sun Microsystems Czech s.r.o.
version:2.1
end:vcard


--Boundary_(ID_Q/+yt30mxP/5qzSESsYE0Q)--

From gww@eng.sun.com Thu Jul 17 08:04:00 2008
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m6HF3xlX008046
	for <psarc-ext@sac.sfbay.sun.com>; Thu, 17 Jul 2008 08:04:00 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id m6HF3qoC011490
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Thu, 17 Jul 2008 16:03:59 +0100 (BST)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K4500805OIM0L00@nwk-avmta-2.sfbay.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Thu, 17 Jul 2008 08:03:58 -0700 (PDT)
Received: from dm-eng-02.sfbay.sun.com ([129.146.11.32])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K45003ALOILSGD0@nwk-avmta-2.sfbay.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Thu,
 17 Jul 2008 08:03:57 -0700 (PDT)
Received: from marduk.eng.sun.com (marduk.SFBay.Sun.COM [129.146.108.224])
	by dm-eng-02.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id m6HF3sdd031376; Thu, 17 Jul 2008 08:03:54 -0700 (PDT)
Received: from marduk.eng.sun.com (localhost [127.0.0.1])
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11) with ESMTP id m6HF5nna013697; Thu,
 17 Jul 2008 08:05:49 -0700 (PDT)
Received: (from gww@localhost)
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11/Submit) id m6HF5n90013696; Thu,
 17 Jul 2008 08:05:49 -0700 (PDT)
Date: Thu, 17 Jul 2008 08:05:49 -0700 (PDT)
From: Gary Winiger <gww@eng.sun.com>
Subject: Re: Integrate pwgen into Solaris. [PSARC/2008/453 FastTrack timeout
 07/23/2008]
To: Darren.Moffat@sun.com, Martin.Rehak@sun.com
Cc: dhain@sac.sfbay.sun.com, PSARC-ext@sun.com
Message-id: <200807171505.m6HF5n90013696@marduk.eng.sun.com>
Content-transfer-encoding: 7BIT
X-Sun-Charset: US-ASCII
X-PMX-Version: 5.4.1.325704
Status: RO
Content-Length: 721

> > Can this be built as a library (say libpwgen) so that we can implement a 
> > PAM module around this ?  I see value in it being a standalone program 
> > but even more value in also having a PAM module (this would be used 
> > instead of or stacked above pam_authtok_get in some configurations).

	I don't believe we want to provide such a module.  It has far
	broader implications than having a command.  What if the password
	generated conflicts with the password policies in /etc/default/....?
	It has been considered in the past particularly with the fips 181
	password generator (that as from their source, is crypto encumbered).

	If there's going to be a PAM module, that needs to be a separate
	case.

Gary..

From Darren.Moffat@sun.com Thu Jul 17 10:57:34 2008
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m6HHvXnT014693
	for <psarc-ext@sac.sfbay.Sun.COM>; Thu, 17 Jul 2008 10:57:33 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id m6HHvQfX018873
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Fri, 18 Jul 2008 01:57:32 +0800 (SGT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K450031DWJSLD00@brm-avmta-1.central.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Thu, 17 Jul 2008 11:57:28 -0600 (MDT)
Received: from gmp-eb-inf-2.sun.com ([192.18.6.24])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K4500G1IWJR3WD0@brm-avmta-1.central.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Thu,
 17 Jul 2008 11:57:28 -0600 (MDT)
Received: from fe-emea-10.sun.com (gmp-eb-lb-2-fe1.eu.sun.com [192.18.6.10])
	by gmp-eb-inf-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id m6HHvR0m024484	for
 <PSARC-ext@sun.com>; Thu, 17 Jul 2008 17:57:27 +0000 (GMT)
Received: from conversion-daemon.fe-emea-10.sun.com by fe-emea-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0K4500201WCVOD00@fe-emea-10.sun.com>
 (original mail from Darren.Moffat@Sun.COM)
 for PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Thu,
 17 Jul 2008 18:57:27 +0100 (BST)
Received: from [10.0.242.191] ([192.18.41.196])
 by fe-emea-10.sun.com (Sun Java System Messaging Server 6.2-8.04 (built Feb 28
 2007)) with ESMTPSA id <0K4500J2QWJOB490@fe-emea-10.sun.com>; Thu,
 17 Jul 2008 18:57:27 +0100 (BST)
Date: Thu, 17 Jul 2008 18:57:23 +0100
From: Darren J Moffat <Darren.Moffat@sun.com>
Subject: Re: Integrate pwgen into Solaris. [PSARC/2008/453 FastTrack timeout
 07/23/2008]
In-reply-to: <200807171505.m6HF5n90013696@marduk.eng.sun.com>
Sender: Darren.Moffat@sun.com
To: Gary Winiger <gww@eng.sun.com>
Cc: Martin.Rehak@sun.com, dhain@sac.sfbay.sun.com, PSARC-ext@sun.com
Message-id: <487F8803.20100@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200807171505.m6HF5n90013696@marduk.eng.sun.com>
User-Agent: Thunderbird 2.0.0.14 (X11/20080519)
Status: RO
Content-Length: 1426

Gary Winiger wrote:
>>> Can this be built as a library (say libpwgen) so that we can implement a 
>>> PAM module around this ?  I see value in it being a standalone program 
>>> but even more value in also having a PAM module (this would be used 
>>> instead of or stacked above pam_authtok_get in some configurations).
> 
> 	I don't believe we want to provide such a module.  It has far
> 	broader implications than having a command. 

Well I respectively disagree, I do want to provide such a module.

Yes it does have much broader implication and I wasn't suggesting that 
this case actually provide or design/architect the module.  I just 
wanted to know if this case could provide building blocks for some 
future case.

 >	 What if the password
> 	generated conflicts with the password policies in /etc/default/....?

IMO you wouldn't deploy a password generation module and the current 
pam_authtok_check in the same stack for exactly this reason.

> 	It has been considered in the past particularly with the fips 181
> 	password generator (that as from their source, is crypto encumbered).
> 
> 	If there's going to be a PAM module, that needs to be a separate
> 	case.

I agree but there seems to be interesting stuff in this case that could 
be used to build such a future case so I wanted to know if this case 
could be delivered to help.  I wasn't suggesting this case deliver the 
PAM module.

--
Darren J Moffat

From Daniel.Hain@sun.com Wed Jul 23 13:17:09 2008
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m6NKH92s007157
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 23 Jul 2008 13:17:09 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m6NKH3rv003144
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Wed, 23 Jul 2008 14:17:09 -0600 (MDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K4H00D0B70K0200@nwk-avmta-2.sfbay.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@Sun.COM); Wed, 23 Jul 2008 13:17:08 -0700 (PDT)
Received: from sca-es-mail-1.sun.com ([192.18.43.132])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K4H0085Z70K63D0@nwk-avmta-2.sfbay.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@Sun.COM); Wed,
 23 Jul 2008 13:17:08 -0700 (PDT)
Received: from fe-sfbay-09.sun.com ([192.18.43.129])
	by sca-es-mail-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id m6NKH8Ii024597	for
 <PSARC-ext@Sun.COM>; Wed, 23 Jul 2008 13:17:08 -0700 (PDT)
Received: from conversion-daemon.fe-sfbay-09.sun.com by fe-sfbay-09.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0K4H000016X5RH00@fe-sfbay-09.sun.com>
 (original mail from Daniel.Hain@Sun.COM)
 for PSARC-ext@Sun.COM (ORCPT PSARC-ext@Sun.COM); Wed,
 23 Jul 2008 13:17:07 -0700 (PDT)
Received: from [129.153.88.186] by fe-sfbay-09.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 with ESMTPSA id <0K4H00E3K70J4ZB0@fe-sfbay-09.sun.com> for PSARC-ext@Sun.COM
 (ORCPT PSARC-ext@Sun.COM); Wed, 23 Jul 2008 13:17:07 -0700 (PDT)
Date: Wed, 23 Jul 2008 13:17:29 -0700
From: Daniel Hain <Daniel.Hain@sun.com>
Subject: Re: Integrate pwgen into Solaris. [PSARC/2008/453 FastTrack timeout
 07/23/2008]
In-reply-to: <200807161753.m6GHrdR4002990@sac.sfbay.sun.com>
Sender: Daniel.Hain@sun.com
To: psarc-ext@sun.com
Cc: Martin.Rehak@sun.com
Message-id: <488791D9.1020206@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200807161753.m6GHrdR4002990@sac.sfbay.sun.com>
User-Agent: Thunderbird 2.0.0.12 (X11/20080310)
Status: RO
Content-Length: 2893

This case was approved at today's PSARC meeting.

Dan

Daniel Hain wrote:
> I am sponsoring the following fasttrack for Martin Rehak, requesting minor
> binding and a timeout of 07/23/2008. Man page is in the case directory.
>
> - Dan
>
> Template Version: @(#)sac_nextcase 1.66 04/17/08 SMI
> This information is Copyright 2008 Sun Microsystems
> 1. Introduction
>     1.1. Project/Component Working Name:
> 	 Integrate pwgen into Solaris.
>     1.2. Name of Document Author/Supplier:
> 	 Author:  Martin Rehak
>     1.3  Date of This Document:
> 	16 July, 2008
> 4. Technical Description
> Proposal:
>
>         Integrate pwgen into Solaris.
>
> Detail:
>
> 	pwgen is a tool which is able to create easily memorizable passwords
> 	while being as secure as possible. The tool is able to distinguish
> 	whether the output is a tty or a pipe. Single password will be written
> 	to a pipe. Screen full of passwords will be generated when the tool
> 	believes user is looking at the output. There are dozen of switches
> 	modifing it's behavior. It can produce wide range of passwords from
> 	those very simple but almost unsecure to those not being easily
> 	memorizable but far more secure. One can choose various modes enabling
> 	or disabling usage of capital letters, numbers, vowels or symbols. There
> 	is a possibility to specify the seed for pseudo random device.
>
>         The current version of pwgen is 2.06 (05/05/2008).
>
> Exported Interfaces:
>
>         SUNWpwgen		Uncommited		Package name
> 	/usr/bin/pwgen		Commited		Executable location
> 	/usr/bin/amd64/pwgen	Commited		Executable location
> 	/usr/bin/sparcv9/pwgen	Commited		Executable location
> 	pwgen			Uncommited		Commandline syntax
> 	pwgen output		Uncommited
>
> Deliverables:
>
> 	usr/bin/pwgen
> 	usr/man/man1/pwgen.1
>
> Dependencies:
>
> 	libc.so.1 =>     /lib/libc.so.1
>         libm.so.2 =>     /lib/libm.so.2
>
> Documentation:
>
> 	man page: pwgen.1
>
> References:
>
> 	[1] http://sourceforge.net/projects/pwgen/ - home page
> 	    Author(s) of pwgen: Theodore Ts'o.
>
> 	[2] 6670232 pwgen 2.06 to be integrated into SFW consolidation
>
>
> 6. Resources and Schedule
>     6.4. Steering Committee requested information
>    	6.4.1. Consolidation C-team Name:
> 		sfw
>     6.5. ARC review type: FastTrack
>     6.6. ARC Exposure: open
>
>   


-- 
Dan Hain 
Solaris Revenue Product Engineering (RPE)

