Hi, On Tue, Jan 07, 2014 at 05:54:28PM -0500, Chris Marget wrote: > FWIW, it seems that the security fixes might be available for free, so long > as Cisco PSIRT recognizes a vulnerability in a particular bit of software. > ...But the document describing that process suggests calling TAC, which > doesn't usually go well if the serial number of the device isn't covered by > a support contract... > http://www.cisco.com/web/about/security/psirt/security_vulnerability_policy.html
It actually works out. We've done it a few times for devices that have
no contract anymore (because they are old and we have enough spares, like
for 7200/NPE-G1). Sometimes you have to beat them a few times with the
advisory and the sentence "free software for all" in it, but eventually
they get it.
So applause to Cisco PSIRT for making this happen.
OTOHO, the whole way Cisco treats the folks that have paid lots of money
for their hardware ("they are all lying software thieves, and we need
to invest lots of energy into our download portal to ensure that people
will never ever download a single image that we have not personally
cleared for them!") sucks.
I can see that they do not want to sell a box with "ip only" and have
the customer run "advanced enterprise plus" on it, without paying for
the extra license - but making software *updates* complicated and
restrictive is not the way to solve *that*...
gert
--
USENET is *not* the non-clickable part of WWW!
//www.muc.de/~gert/
Gert Doering - Munich, Germany [email protected]
fax: +49-89-35655025 [email protected]
pgp0HOUz2I5Nc.pgp
Description: PGP signature
_______________________________________________ cisco-nsp mailing list [email protected] https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/
