Re: Red Hat Network updates

From: Ali-Reza Anghaie (ali@packetknife.com)
Date: 02/28/03

  • Next message: Seth Arnold: "Re: Red Hat Network updates"
    From: Ali-Reza Anghaie <ali@packetknife.com>
    To: <focus-linux@securityfocus.com>
    Date: Fri, 28 Feb 2003 13:49:49 -0500
    
    

    On Thursday 27 February 2003 12:33, Jennifer Fountain wrote:
    > I wanted your opinion about retrieving updates from the red hat network
    > via the rh agent. I absolutely love the fact that Red hat emails you
    > with updates and the agent (acting like the windows update agent or did
    > windows steal this from rh:)) can retrieve these updates. However, I am
    > not sure how "secure" or if I should be concerned about this process.
    > What is the consensus from everyone? Good tool? Shouldn't use it
    > because...?

    The default settings for up2date/RHN ask it to check against GPG. And it
    uses a certificate for the HTTPS connection albeit it is RH's own CA. So
    from an ~architecture~ standpoint it isn't bone-headed. I don't know if the
    client, rhnd, etc. have been extensively audited or not though.

    Cheers, -Ali

    -- 
    OpenPGP Key: 030E44E6
    --
    Was I helpful?:  http://svcs.affero.net/rm.php?r=packetknife
    --
    I consider forced-full-duplex to be a serious issue somewhere
    between "..and these cars have the brake pedal on the right" and "we
    decided to put the drinking water in the brown jugs, and the 'other'
    water in blue". You won't necessarily die right away, but it isn't
    healthy. -- Donald Becker
    


    Relevant Pages

    • PathInstall log.
      ... Failsafe Timeout Period supplied with value = ... Unable to get path for scan program, Agent will not evaluate software ... Software updates evaluation failed. ... InstallStatusMIFEx() Called with ProgramReboot = ...
      (microsoft.public.sms.admin)
    • Re: Patch Managment
      ... > I am seeking information on how to build a Patch Managment Solution. ... > I am a consultant who has an agent on all of my clients machines. ... > way to check a remote machine for any critical updates. ... > if I could push the updates to the user, ...
      (microsoft.public.windowsupdate)
    • Immediately after initializing a merge subscription, why would the subscriber send back updates?
      ... merge agent ran for the first time and the snapshot was applied I ran it ... merge agent a third time and there were yet more updates downloaded. ... I am sure no-one was updating the subscriber so where were these coming ...
      (microsoft.public.sqlserver.replication)
    • Re: Red Hat Network updates
      ... We have been using redhats network agent for two years now and have found it ... > I wanted your opinion about retrieving updates from the red hat ... I absolutely love the fact that Red hat ...
      (Focus-Linux)
    • Security updates are too slow or none existant
      ... updates at all seems to have greatly changed with time between Red Hat ... If you compare the Red Hat Linux 9 errata list over the last few months ... Core 1 that were made for Red Hat Linux 9. ... Fedora Core 1 updates testing), slocate, mc, ...
      (Fedora)