Your message dated Wed, 26 Mar 2014 18:09:40 +0200
with message-id <[email protected]>
and subject line closing
has caused the Debian Bug report #272119,
regarding creating a new harden-kernel package
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
272119: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=272119
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: harden
Version: 0.1.9
Severity: wishlist

I was thinking about this the other day when I read about
vulnerabilities in the Linux kernel.

We could have a package that conflicts with the kernel packages in
unstable that are known to have security bugs.  It is hard to keep track of 
that since
kernel packages in unstable are not always fixed but rather a new
package is uploaded which fixes the problem.

If we there was a "harden-kernel" package installed, it would conflict with 
some old
kernels that we have lying around.  So for example, if I am running
2.6.7 and it has security issues, then 2.6.8 would come out and
harden-kernel would conflict with 2.6.7.

Maybe there could be a harden-kernel-2.6 package and a
harden-kernel-2.4.  Or maybe a better name is harden-linux-2.4 and 2.6.

This is maybe something that the kernel maintainer team could help keep up to
date as well...


--- End Message ---
--- Begin Message ---
Closing as wontfix. I have followed Debian security for a while and this kind
of package would not be possible with current resources anyways.

Attachment: signature.asc
Description: Digital signature


--- End Message ---

Reply via email to