| Summary: | IPTABLES ignores local date/time | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | Michael McCarrey <wa7qzr> |
| Component: | Security | Assignee: | Mageia Bug Squad <bugsquad> |
| Status: | RESOLVED INVALID | QA Contact: | |
| Severity: | normal | ||
| Priority: | Normal | CC: | eatdirt, tmb |
| Version: | Cauldron | ||
| Target Milestone: | --- | ||
| Hardware: | i586 | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Source RPM: | iptables-1.4.7-2mnb2.src.rpm | CVE: | |
| Status comment: | |||
|
Description
Michael McCarrey
2011-09-28 06:53:39 CEST
Hi there,
I am a apprentice and my master asked me to have a look to security issues. So, big apologizes if I am saying trivialities. As far as I can see in the man iptables:
<< This matches if the packet arrival time/date is within a given range. All
options are optional, but are ANDed when specified. All times are interpreted as UTC by default>>
So, I would say that this is normal?
The man also claims that you can use --kerneltz to switch to local time, but that's highly discouraged.
Cheers,
Chris.CC:
(none) =>
dirteat Hello Chris, It's only normal if someone has decided to change the way IPTABLES has operated historically. That's possible. It was done to glib and that hosed-up many programs. Personally, I'm fed-up with "features" like that and similar "improvements". Regards, Mike It's an intended change from upstream. https://git.netfilter.org/cgi-bin/gitweb.cgi?p=iptables.git;a=commitdiff;h=db50b83bc3cd634beb71f38978ad7d035c88ff11 Status:
NEW =>
RESOLVED Hi Thomas, Well now, why doesn't that surprise me? Making everyone use UTC is a bit like trying to make everyone go metric from a few years back. Not a resolution in my book - just an explanation. |