Discussion:
[WBEL-devel] whitebox - security updates and mirror question
Paulo Matos
2004-03-19 17:58:46 UTC
Permalink
I already sent this message twice... hope I can get answer...

Regards,

Paulo Matos

---------- Forwarded message ----------
Date: Fri, 20 Feb 2004 18:13:06 +0000 (WET)
From: Paulo Matos <***@fct.unl.pt>
To: ***@beau.org
Subject: whitebox

Hi!

I'm considering to use WhiteBox on our production systems... but
there's a major concern on that which is the availability of updates
(specially security ones).

I have to convince my boss that those updates are guarenteed by
whitebox as soon as they appear on redhat...

If we start using whitebox, it won't be very hard to setup a
mirror here.

Regards,

--
Paulo Matos
----------------------------------- ----------------------------------
|Sys & Net Admin | Serviço de Informática |
|Faculdade de Ciências e Tecnologia | Tel: +351-21-2948596 |
|Universidade Nova de Lisboa | Fax: +351-21-2948548 |
|P-2829-516 Caparica | e-Mail: ***@fct.unl.pt |
----------------------------------- ----------------------------------
William Hooper
2004-03-19 18:33:54 UTC
Permalink
Post by Paulo Matos
I have to convince my boss that those updates are guarenteed by
whitebox as soon as they appear on redhat...
There are no guarentees of anything. As the web site says "In fact, if
you need a fully tested and supported OS you probably should go buy their
[Red Hat's] box set."

That said, John has been very good about getting updates out.
--
William Hooper
Jamey Fletcher
2004-03-19 20:53:33 UTC
Permalink
Post by William Hooper
Post by Paulo Matos
I have to convince my boss that those updates are guarenteed by
whitebox as soon as they appear on redhat...
There are no guarentees of anything. As the web site says "In fact, if
you need a fully tested and supported OS you probably should go buy their
[Red Hat's] box set."
That said, John has been very good about getting updates out.
As it happens, John is currently away at a Library-related convention.
However, he has high-speed internet in his hotel room; there's a fair
chance a package could show up tonight.

However, one guarantee you have for White Box is that the RedHat *source*
RPMs are freely available, and any WhiteBox installation with the build
chain installed *should* be able to rebuild the RH source package - the
advantage of John doing it is that it goes to the mirrors, and up2date
knows about it.

However, like any other security threat, each threat must be evaluated in
terms of *your* system, and your reaction should match - should you look
at the Security Alert and dive into the code yourself to fix it *NOW*, or
wait for the project managers to issue a fix, and build it into a package,
or wait for your distro vendor to release a package. Can you live with
that service running, or do you need to shut it down *NOW* - and if you do
shut it down, does it shut down your business?

One of these millennia, we'll have a one-size-fits-all distro - and I hope
I never see it - because it'll be the worst thing that could possibly
happen to Linux.
--
Jamey
----<--<@
***@beau.lib.la.us
Jeff Maze
2004-03-19 21:39:11 UTC
Permalink
But I see that OpenSSL 0.9.7d is out because of a security advisory with prior
0.9.7x versions. How soon do you think Red Hat will release SRPM's for
0.9.7d? Just was curious.
Post by Jamey Fletcher
Post by William Hooper
Post by Paulo Matos
I have to convince my boss that those updates are guarenteed by
whitebox as soon as they appear on redhat...
There are no guarentees of anything. As the web site says "In fact, if
you need a fully tested and supported OS you probably should go buy their
[Red Hat's] box set."
That said, John has been very good about getting updates out.
As it happens, John is currently away at a Library-related convention.
However, he has high-speed internet in his hotel room; there's a fair
chance a package could show up tonight.
However, one guarantee you have for White Box is that the RedHat *source*
RPMs are freely available, and any WhiteBox installation with the build
chain installed *should* be able to rebuild the RH source package - the
advantage of John doing it is that it goes to the mirrors, and up2date
knows about it.
However, like any other security threat, each threat must be evaluated in
terms of *your* system, and your reaction should match - should you look
at the Security Alert and dive into the code yourself to fix it *NOW*, or
wait for the project managers to issue a fix, and build it into a package,
or wait for your distro vendor to release a package. Can you live with
that service running, or do you need to shut it down *NOW* - and if you do
shut it down, does it shut down your business?
One of these millennia, we'll have a one-size-fits-all distro - and I hope
I never see it - because it'll be the worst thing that could possibly
happen to Linux.
William Hooper
2004-03-19 21:52:51 UTC
Permalink
Post by Jeff Maze
But I see that OpenSSL 0.9.7d is out because of a security advisory with prior
0.9.7x versions. How soon do you think Red Hat will release SRPM's for
0.9.7d? Just was curious.
Red Hat won't. They have already fixed their packages. See:
http://www.redhat.com/advice/speaks_backport.html
--
William Hooper
John A. Tamplin
2004-03-19 21:43:30 UTC
Permalink
Post by Jeff Maze
But I see that OpenSSL 0.9.7d is out because of a security advisory with prior
0.9.7x versions. How soon do you think Red Hat will release SRPM's for
0.9.7d? Just was curious.
First, that would be an issue to bring up with RedHat. Second, RedHat
usually backports security patches into the same version they are already
distributing rather than upgrading to fix the security hole. I haven't
looked at the details, but I would suspect RedHet's recent advisory on
OpenSSL includes the changes made in 0.9.7d.
--
John A. Tamplin ***@jaet.org
770/436-5387 HOME 4116 Manson Ave
Smyrna, GA 30082-3723
Loading...