Re: Checking for services to be restarted on a default Debian installation

2014-09-10 Thread David Prévot
[ Still replying on security since that’s where the thread started, but feel free to follow up on private maintainer’s list since it becomes off topic for security. ] Hi Thomas, Le 10/09/2014 14:29, Thomas Liske a écrit : The debconf stuff is upstream and IMHO *not* a 3.9.1 Prompting in

Re: Checking for services to be restarted on a default Debian installation

2014-09-07 Thread David Prévot
Le 07/09/2014 02:07, Paul Wise a écrit : On Tue, Sep 2, 2014 at 2:48 AM, Thijs Kinkhorst wrote: In jessie there is also whatmaps. The results from checkrestart seem to be different to needrestart in many cases, since the latter ignores some services that are problematic/impossible to restart

Re: Checking for services to be restarted on a default Debian installation

2014-09-07 Thread David Prévot
Le 07/09/2014 10:54, Paul Wise a écrit : On Sun, Sep 7, 2014 at 9:30 PM, David Prévot wrote: How does it work if the upgrade run in the background? Will all needed service be restarted without asking? (If so, the gdm3 restart issue may be a blocker). Not sure what you mean

Re: Checking for services to be restarted on a default Debian installation

2014-09-02 Thread David Prévot
Hi, Le 02/09/2014 04:05, Yves-Alexis Perez a écrit : It's quite certain that about nobody know about debian-goodies or checkrestart. The Securing Debian Manual recommends it, so hopefully you’re wrong. https://www.debian.org/doc/manuals/securing-debian-howto/ch4#s-lib-security-update

Re: Use of DSA number for general announcements

2012-09-15 Thread David Prévot
Hi, Le 14/09/2012 01:47, Thijs Kinkhorst a écrit : On Fri, September 14, 2012 03:28, David Prevot wrote: This is a notice to inform you, that our previous PGP/GPG key expired. Thanks for notifying us on debian-security-announce@l.d.o, but I disagree that such an announcement deserves a DSA

Use of DSA number for general announcements (was: [DSA 2548-1] Debian Security Team PGP/GPG key change notice)

2012-09-13 Thread David Prévot
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi, Le 13/09/2012 06:33, Nico Golde a écrit : - Debian Security Advisory DSA-2548-1 secur...@debian.org http://www.debian.org/security/

Bug#685646: Please advise a reliable version scheme for {stable,testing}{,-security}

2012-08-22 Thread David Prévot
Package: developers-reference Version: 3.4.9 Severity: normal Tags: patch Hi, As discussed on #d-release, the version scheme advice could be improved, so should the distribution declared in changelog, for the testing and {old,}stable upload (including the -security ones), in order to have only

Re: [SECURITY] [DSA 2523-1] globus-gridftp-server security update

2012-08-08 Thread David Prévot
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Le 08/08/2012 20:25, Mike Mestnik a écrit : On 08/06/12 22:47, maestro wrote: #please unsubscribe me from this list # i do not find any link to do so. # thank you. Instructions can be found at the bottom, there is no link or URL. Actually,

Re: Debian Oval definitions for 2011

2011-10-11 Thread David Prévot
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi, Le 11/10/2011 04:08, Pascal HERAUD a écrit : Is anybody knows why the 2011 oval file is empty ? Is Oval not supported anymore by debian ? http://www.debian.org/security/oval/ http://www.debian.org/security/oval/oval-definitions-2011.xml

No DSA for isc-dhcp

2011-03-04 Thread David Prévot
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 [ Please keep me CC ] Hi, Version 4.1.1-P1-15+squeeze1 of isc-dhcp was updated yesterday but no DSA were sent about it, and the security tracker [0] still marks this package vulnerable. [0] http://security-tracker.debian.org/tracker/CVE-2011-0413