Re: Updating parts of the system..

2003-03-03 Thread Toomas Aas
Hi!

 I was wondering if it was feasible to update just parts of the FreeBSD
 system without updating the whole thing...for instance the recent OpenSSL
 update - is it possible to update just OpenSSL on say a FreeBSD 4.3 box
 without updating the whole system? 

If the update is w.r.t a FreeBSD security advisory, then it is 
generally possible to update just the faulty part of the system. This 
involves downloading a patch from FreeBSD FTP server, applying it to 
your existing sources and rebuilding the necessary parts of the system. 
The exact instructions are given within the security advisory itself.

HOWEVER: the patches are not guaranteed to work on a version as old as 
4.3. The oldest version which seems to be currently supported by 
FreeBSD security officer is 4.6.

Another thing to consider is that sometimes you'll need to build the 
entire world + kernel after applying the patch anyway. This is the case 
with FreeBSD-SA-03:02 (the recent OpenSSL advisory). In such case I 
personally find it more sensible to cvsup the sources to latest 
RELENG_4_X and rebuild the world + kernel from there.
--
Toomas Aas | [EMAIL PROTECTED] | http://www.raad.tartu.ee/~toomas/
* Someday we'll look back on all this and plow into a parked car.


To Unsubscribe: send mail to [EMAIL PROTECTED]
with unsubscribe freebsd-questions in the body of the message


Updating parts of the system..

2003-02-28 Thread Stephen Hoover
I was wondering if it was feasible to update just parts of the FreeBSD
system without updating the whole thing...for instance the recent OpenSSL
update - is it possible to update just OpenSSL on say a FreeBSD 4.3 box
without updating the whole system? From what I have read it doesn't look to
be possible, (outside of installing from ports, but I want to upgrade what
actually came with the FreeBSD install) but I just wanted to check with the
experts.

Thanks!
Stephen Hoover
Dallas, Texas


To Unsubscribe: send mail to [EMAIL PROTECTED]
with unsubscribe freebsd-questions in the body of the message


Re: Updating parts of the system..

2003-02-28 Thread Kris Kennaway
On Fri, Feb 28, 2003 at 03:33:21PM -0600, Stephen Hoover wrote:
 I was wondering if it was feasible to update just parts of the FreeBSD
 system without updating the whole thing...for instance the recent OpenSSL
 update - is it possible to update just OpenSSL on say a FreeBSD 4.3 box
 without updating the whole system? From what I have read it doesn't look to
 be possible, (outside of installing from ports, but I want to upgrade what
 actually came with the FreeBSD install) but I just wanted to check with the
 experts.

It's not supported in general, but if you know what you're doing you
can often do it.  The upgrade instructions in the security advisory
may be useful.

Kris


pgp0.pgp
Description: PGP signature