Re: [RFC] Ideas and Questions in security updates ( portaudit, freebsd-update)



On Mon, 2006-04-10 at 16:03 -0300, Ricardo A. Reis wrote:
Hi all,
<snip>
About Ports security issues, one idea is integrate portaudit and
portupgrade or create another tool for update ports,
this ideia is based in Gentoo glsa-check
( http://www.gentoo.org/doc/en/security/security-handbook.xml?part=1&chap=14
)


I recently saw glsa-check while talking to a Gentoo dev at Linux World
this past week. It's very nice but does not fit in with our tree and
updating model. Gentoo supports updating individual ports while leaving
other ports on the system untouched. We do not support this sort of
updating model. To get security updates for the FreeBSD collection you
have one of two options. Either A) follow the recommended procedure and
update all ports when a security issue for one arises or B) backport
patches yourself and support all potential problems yourself.

Tom


Thanks for Attention and sorry for my bad english.

Ricardo A. Reis
UNIFESP
Unix and Network Admin

--
| tmclaugh at sdf.lonestar.org tmclaugh at FreeBSD.org |
| FreeBSD http://www.FreeBSD.org |
| BSD# http://www.mono-project.com/Mono:FreeBSD |

_______________________________________________
freebsd-security@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-security-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • OT: What will he do next?
    ... That was National Security. ... President Bush said Tuesday that a deal allowing an Arab company to take ... Senate Republican Leader Bill Frist urged the administration to ... Ports World, a state-owned business in the United Arab Emirates. ...
    (comp.sys.hp.mpe)
  • Re: Political Analysis of Security Products
    ... > bee collected nor has any evidence of such a backdoor ever really been ... send several packets to ports on the target system. ... be used for booth sides of the security game. ...
    (Pen-Test)
  • Re: Finally, a secure computer
    ... paranoia in the security aspects of IIS administration. ... security at the IBM website is compromised, ... I ran a port check on 10,000 plus ports (I ... > trouble downloading updates [I'm not sure about AVG pro, ...
    (microsoft.public.inetserver.iis.security)
  • Re: Port security, continued
    ... CITING NATIONAL SECURITY, ... WASHINGTON - PRESIDENT BUSH WAS UNAWARE OF THE PENDING SALE ... THE WHITE HOUSE SAID WEDNESDAY. ... EMERGENCY LEGISLATION TO SUSPEND THE PORTS DEAL. ...
    (sci.med.transcription)
  • Re: How you can help
    ... pleased to have you here as I sign a bill that will help protect the ... American people and our ports. ... Homeland Security, Michael Chertoff, for his service to the country. ... appreciate that Senate Majority Leader Bill Frist has joined us. ...
    (rec.gambling.poker)