Re: FreeBSD Security Advisory FreeBSD-SA-05:21.openssl

jimmy_at_inet-solutions.be
Date: 10/11/05

  • Next message: Andrea Venturoli: "Re: FreeBSD Security Advisory FreeBSD-SA-05:21.openssl"
    Date: Tue, 11 Oct 2005 18:37:00 +0200
    To: jere <jere@htnet.hr>
    
    

    > jimmy@inet-solutions.be wrote:
    > > Quoting FreeBSD Security Advisories <security-advisories@freebsd.org>:
    > >
    > >
    >
    >>=============================================================================
    > >>FreeBSD-SA-05:21.openssl Security
    > Advisory
    > >> The FreeBSD
    > Project
    > >
    > > [..]
    > >
    > >>c) Recompile the operating system as described in
    > >><URL:
    > >>http://www.freebsd.org/doc/en_US.ISO8859-1/books/handbook/makeworld.html >.
    > >
    > >
    > > Is there any reason why one would need to compile the whole operating
    > system?
    > > I can understand that static linked apps need to be recompiled, but which
    > > are there actually any at all (and linked against openssl)?
    > >
    > > Kind regards,
    > > Jimmy Scott
    > >
    > > ----------------------------------------------------------------
    > > This message has been sent through ihosting.be
    > > To report spamming or other unaccepted behavior
    > > by a iHosting customer, please send a message
    > > to abuse@ihosting.be
    > > ----------------------------------------------------------------
    > > _______________________________________________
    > > freebsd-security@freebsd.org mailing list
    > > http://lists.freebsd.org/mailman/listinfo/freebsd-security
    > > To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
    > >
    >
    Quoting jere <jere@htnet.hr>:

    > unfortunately, this is the dark side of FreeBSD security patch
    > management :) and I think also the main reason FreeBSD isn't so widely
    > deployed into enterprise environments. It's ok for hacking or managing
    > few boxes but try to imagine how to manage security on hundreds of them
    > this way. :(
    >
    > on the other side (bright side :) you can try to use unofficial and
    > often somewhat slowly updating solutions such as bsdupdate
    > (www.bsdupdates.com) or freebsd-update (from ports tree).
    >
    > currently, FreeBSD just don't have a mechanism to handle security
    > advisories in quick way.
    >
    > any suggestions/corrections ?
    >
    > j.
    >

    What I meant was: "why compile everything instead of just openssl"
    I'm thinking about this question since the last openssl issue in FreeBSD.

    ----------------------------------------------------------------
    This message has been sent through ihosting.be
    To report spamming or other unaccepted behavior
    by a iHosting customer, please send a message
    to abuse@ihosting.be
    ----------------------------------------------------------------
    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"


  • Next message: Andrea Venturoli: "Re: FreeBSD Security Advisory FreeBSD-SA-05:21.openssl"

    Relevant Pages

    • Re: ax25 in kernel
      ... With good reason that its not there. ... need to be in the kernel." ... found in linux and be able to compile them to work in ... freebsd as I usually run a hamradio gateway. ...
      (freebsd-questions)
    • Re: Changes in 2005.
      ... VS.NET 2003 does not compile to unmanaged code. ... There is all the more reason for startups to write Web-based software now, ... are going to tell me that you would rather write an ASP.NET app ...
      (microsoft.public.dotnet.languages.csharp)
    • Re: Include Statement
      ... For the same reason conditional compilation directives were added to compile a block vs not to compile a block. ... For the same reason you have IMPORTS to reference an compiled object. ... Second, it is difficult to explain all the reason because they are VAST, every programmer has their reasons. ...
      (microsoft.public.dotnet.languages.vb)
    • Re: Include Statement
      ... For the same reason conditional compilation directives were added to compile a block vs not to compile a block. ... Second, it is difficult to explain all the reason because they are VAST, every programmer has their reasons. ... Like without out product line source codes, look at other large projects where the source code is LOADED with both imports and includes - because the language allowed it. ...
      (microsoft.public.dotnet.languages.vb)
    • Re: Disadvantages of Delphi.NET
      ... get a simple utility app to compile in D8, I ... TRecType1 = Packed Record ... Much of the reason the code constructs above are still this way, ... Now if all you know is Delphi, then I'd be fairly confident recoding in D8 ...
      (borland.public.delphi.non-technical)

  • Quantcast