Re: YUM security issues...

2008-07-25 Thread Josh Bressers
On 21 July 2008, Josh Bressers wrote: On 19 July 2008, Justin Cappos wrote: By the way, did you remove the ability for mirror admins to select a subnet where they'll serve all of the traffic? We're particularly concerned about this issue in the short term. We took our mirror down

Re: YUM security issues...

2008-07-25 Thread Josh Bressers
On 25 July 2008, Mike McGrath wrote: On Fri, 25 Jul 2008, Mike McGrath wrote: On Fri, 25 Jul 2008, Josh Bressers wrote: On 21 July 2008, Josh Bressers wrote: On 19 July 2008, Justin Cappos wrote: By the way, did you remove the ability for mirror admins to select

Re: YUM security issues...

2008-07-25 Thread Josh Bressers
On 25 July 2008, Matt Domsch wrote: On Fri, Jul 25, 2008 at 12:46:15PM -0400, Josh Bressers wrote: On 25 July 2008, Matt Domsch wrote: Yes, this is a known challenge with subnet delegation in MirrorManager. We're trusting package signing (and soon, repodata signing) to prevent

Re: YUM security issues...

2008-07-25 Thread Josh Bressers
On 25 July 2008, Matt Domsch wrote: On Fri, Jul 25, 2008 at 01:52:26PM -0400, Josh Bressers wrote: That's a lot of IPs though. Can I request multiple /16s, or only one? As many as you like. And recall, such changes are made using your FAS credentials. Are these ever checked? Does say

Re: YUM security issues...

2008-07-26 Thread Josh Bressers
On 25 July 2008, seth vidal wrote: But as you've already mentioned we're stuck with the question of EOL'd releases and how to deal with things deeply out of date. I can make yum throw out warnings and alerts but at what point does it actually STOP doing anything and does that not open us

Re: YUM security issues...

2008-07-28 Thread Josh Bressers
On 28 July 2008, Matt Domsch wrote: Seth, James Antill, and I met a week ago to discuss. These are the steps we believe are necessary to resolve. I didn't realize this hadn't been posted yet. 1. repomd.xml needs to be signed. Either attached or detached sig (advice sought). If