* Jan-Oliver Wagner [ 9. Dec 2008]:
>  * if you are saying that according to FHS we want the NVTs directory
>  not writable, does this conflict with the aspect that we will have to write
>  new NVTs during a NVT Feed Sync?

I think the point is that this directory should be read-only from the
-server perspective. The server itself has no business writing there, it
is neither necessary nor desirable for the server to be able to modify
NVTs. 

The Feed Sync and possibly the server admin should be the only
ones who modify/create NVTs. While the files or the directory do not
need to be read-only on a filesystem level, the server should not be
able to do more than read from these directories.

>  *  last paragraph of rationale: I think this aspect is too ambitious for the
>  moment. Also, we have already a mechanism to switch on/off groups of
>  NVTs: via the detached signatures and trusted signatures.

Well, I guess I'm the one to blame for this paragraph. ;) I agree, this
functionality will likely require deeper changes and would probably be a
nice-to-have in the future, but is not necessary immediately.

Regards,

Michael

-- 
Michael Wiegand |  OpenPGP key: D7D049EC  |  http://www.intevation.de/
Intevation GmbH, Neuer Graben 17, 49074 Osnabrück | AG Osnabrück, HR B 18998
Geschäftsführer: Frank Koormann, Bernhard Reiter, Dr. Jan-Oliver Wagner

_______________________________________________
Openvas-devel mailing list
Openvas-devel@wald.intevation.org
http://lists.wald.intevation.org/mailman/listinfo/openvas-devel

Reply via email to