1 |
On 4/16/07, Marius Mauch <genone@g.o> wrote: |
2 |
> |
3 |
> Not directly related, but you might be interested in the "affected" |
4 |
> target or the --mail option of glsa-check. |
5 |
|
6 |
I am interested in that - but I don't think those options were there |
7 |
when I started putting those cronjobs on my servers many moons ago. |
8 |
Thanks though - I'll investigate. |
9 |
|
10 |
|
11 |
Sune: |
12 |
|
13 |
> emerge gentoo-sources won't magically fix your |
14 |
> machine and besides not everyone want to upgrade their kernel for every |
15 |
> small issue. |
16 |
|
17 |
Nope, of course. But those of us that used the GLSAs as a one-stop |
18 |
package security report were hung out to dry. |
19 |
(Talk about cold sweat when I found out....) |
20 |
|
21 |
>That's why plasmaroo wrote KISS, sadly he left before it went |
22 |
> public and now we waiting for another tool for kernel issues. It's not even on |
23 |
> the horizon yet (at least not to my knowledge). |
24 |
|
25 |
Yep, It sounds like it might have been promising. However, who on |
26 |
earth thought it would be a good idea to remove the functioning kernel |
27 |
security alert system **before** the replacement was written, working, |
28 |
heavily tested, and all the users given 12 months of notice? |
29 |
(The obvious method of notification would have been to create a fake |
30 |
GLSA for glsa-check.) |
31 |
|
32 |
|
33 |
> This started out as a small |
34 |
> problem that we thought would be temporary but has sadly turned kind of |
35 |
> permanent without us informing users properly. |
36 |
|
37 |
This is why, when people ask me if they can "temporarily" do things in |
38 |
my lab, I say no. |
39 |
Temporarily often has a habit of not being. |
40 |
|
41 |
|
42 |
Could we just get GLSAs going again for some of the most common |
43 |
sources for now then? Say gentoo, and hardened? x86, and AMD? |
44 |
Or some virtual ebuild that requires certain versions of kernels to be |
45 |
installed, that can be updated via Portage from time to time. |
46 |
Then you could script emerge -pv sys-kernel/secure-kernel-source, and |
47 |
when it said it would need to install hardened-sources 2.6.26, you'd |
48 |
know that there must have been a bug in <2.4.26. |
49 |
|
50 |
-- |
51 |
http://linuxvps.org/ |
52 |
-- |
53 |
gentoo-security@g.o mailing list |