Giovanni,
> On Sep 13, 2018, at 3:12 AM, Giovanni Bracco <giovanni.bra...@enea.it> wrote: > I have read about the butc & backup security update. > > We run daily the AFS backup and I would like to understand if I need just to > update the backup server with the new butc/backup modules or I need also to > update all our file servers in order to match the new security improvements > connected to backup. Your question seems to be mostly concerned with securing your backups, so I'll answer that specific question first. If we just consider the OpenAFS backup system in isolation, I'm pretty sure you do not need to make changes to your fileservers in order to pick up the butc security fixes. (Ben, please chime in if you disagree). I believe you only _need_ to update butc, but of course it's good practice for all the backup system components to have the same version: - butc - backup (client) - buserver However, the other security fixes in this release do include updates to non-backup OpenAFS components, including several volserver fixes (which would require updating your fileservers). There are also important client and DB server security fixes in this release. Therefore, I think it's fine if you just update your backup components for now. However, since some of these vulnerabilities are remotely exploitable, I recommend updating the rest of your cell to the current release as soon as you can manage it. Regards, -- Mark Vitale OpenAFS release team _______________________________________________ OpenAFS-info mailing list OpenAFS-info@openafs.org https://lists.openafs.org/mailman/listinfo/openafs-info