Gentoo Logo
Gentoo Spaceship




Note: Due to technical difficulties, the Archives are currently not up to date. GMANE provides an alternative service for most mailing lists.
c.f. bug 424647
List Archive: gentoo-security
Navigation:
Lists: gentoo-security: < Prev By Thread Next > < Prev By Date Next >
Headers:
To: Koon <koon@...>
From: Kurt Lieber <klieber@g.o>
Subject: Re: Gentoo security policy
Date: Thu, 18 Mar 2004 09:03:59 -0500
On Thu, Mar 18, 2004 at 02:57:14PM +0100 or thereabouts, Koon wrote:
> Could you detail in what areas help is needed, so that we can evaluate 
> if our profiles (free time and knowledge) can fit in ?

We need folks to monitor bugzilla for security-related postings and then
push valid postings through the GLSA process.

> However I had concern recently with the latest kernel GLSA which has 
> been over-delayed in my opinion. I've posted about this in this 
> mailing-list so that we can discuss steps to avoid such delays in the 
> future, but with no answer from the official people in charge.

Kernel GLSAs are difficult because we can't release the GLSA until all our
kernels have been patched.  Our kernel team is also short-staffed, so that
takes time.  Know any good kernel hackers that want to help out?  Send them
my way and I'll make sure they get put in touch with the right person.

> There is one point where I agree with Tobias : too many GLSA diffusion 
> channels might increase the potential sync problems. gentoo main page, 
> forums, mailing-list(s), GLSA-test hub... I think we have to be careful 
> about that.

gentoo-announce is *the* official means of distributing GLSAs.  If you want
to make sure you receive all GLSAs, sign up for that.  We also publish to
external lists as a "best practice" and a way to reach out to the larger
Linux community to ensure they're aware of vulnerabilities as well.

--kurt
Attachment:
pgpjGTeY0X9r5.pgp (PGP signature)
Replies:
Re: Gentoo security policy
-- Koon
Re: Gentoo security policy
-- Matthias F. Brandstetter
References:
Gentoo security policy
-- Tobias Weisserth
Re: Gentoo security policy
-- Kurt Lieber
Re: Gentoo security policy
-- Koon
Navigation:
Lists: gentoo-security: < Prev By Thread Next > < Prev By Date Next >
Previous by thread:
Re: Gentoo security policy
Next by thread:
Re: Gentoo security policy
Previous by date:
Re: Gentoo security policy
Next by date:
Re: Gentoo security policy


Updated Jun 17, 2009

Summary: Archive of the gentoo-security mailing list.

Donate to support our development efforts.

Copyright 2001-2013 Gentoo Foundation, Inc. Questions, Comments? Contact us.