Re: FreeBSD Security Advisory FreeBSD-SA-05:21.openssl

2005-10-12 Thread Timothy Smith
jere wrote: unfortunately, this is the dark side of FreeBSD security patch management :) and I think also the main reason FreeBSD isn't so widely deployed into enterprise environments. It's ok for hacking or managing few boxes but try to imagine how to manage security on hundreds of them

Re: FreeBSD Security Advisory FreeBSD-SA-05:21.openssl

2005-10-12 Thread Yann Golanski
Quoth Timothy Smith on Wed, Oct 12, 2005 at 17:39:46 +1000 the make world documents mentioning backing up your system. it fails to give any preffered methods or utilites for doing this. anyone got some input on that. I find rdiff-backup to be very good indeed. It's in the port tree. --

Re: FreeBSD Security Advisory FreeBSD-SA-05:21.openssl

2005-10-12 Thread W�rner
--- Peter Jeremy [EMAIL PROTECTED] wrote: On Wed, 2005-Oct-12 00:12:35 -0700, Arne Wörner wrote: Btw: Why should the string OpenSSL be contained in each and every executable, that might use OpenSSL? OpenSSL has a version string of the form OpenSSL 0.9.7e 25 Oct 2004 embedded in it. As far

Re: FreeBSD Security Advisory FreeBSD-SA-05:21.openssl

2005-10-12 Thread Fernando Schapachnik
En un mensaje anterior, Timothy Smith escribió: your totally right, even though i hate to admit it. stuff like having to make world is a nightmare when admining lots of machines. i can't afford to make world only to find something screwed up, stuff like that would cost me a lot of time i

Re: FreeBSD Security Advisory FreeBSD-SA-05:21.openssl

2005-10-12 Thread Jacques Vidrine
[Trimmed cc: to just the appropriate public mailing list.] On Oct 11, 2005, at 7:25 AM, Ian G wrote: FreeBSD Security Advisories wrote: Applications which do not support SSLv2, have been configured to not permit the use of SSLv2, or do not use the SSL_OP_MSIE_SSLV2_RSA_PADDING or

Re: FreeBSD Security Advisory FreeBSD-SA-05:21.openssl

2005-10-12 Thread Giorgos Keramidas
On 2005-10-11 18:37, [EMAIL PROTECTED] wrote: Quoting jere [EMAIL PROTECTED]: unfortunately, this is the dark side of FreeBSD security patch management :) and I think also the main reason FreeBSD isn't so widely deployed into enterprise environments. It's ok for hacking or managing few boxes

Re: FreeBSD Security Advisory FreeBSD-SA-05:21.openssl

2005-10-12 Thread jere
Please read these articles/manuals: http://www.freebsd.org/doc/en_US.ISO8859-1/books/handbook/small-lan.html http://2004.eurobsdcon.org/uploads/media/EBSD04_27.pdf http://www.taosecurity.com/keeping_freebsd_applications_up-to-date.html http://www.taosecurity.com/keeping_freebsd_up-to-date.html

Re: FreeBSD Security Advisory FreeBSD-SA-05:21.openssl

2005-10-12 Thread Peter Jeremy
On Tue, 2005-Oct-11 09:45:53 -0700, Jacques Vidrine wrote: On Oct 11, 2005, at 7:25 AM, Ian G wrote: Isn't the workaround obviously to switch off V2? Yes. Sorry that wasn't mentioned. That sounds like a good workaround. How do I implement it? I've looked through the documentation and can't

Re: FreeBSD Security Advisory FreeBSD-SA-05:21.openssl

2005-10-12 Thread Timothy Smith
Matt Piechota wrote: On Wed, October 12, 2005 4:21 am, Yann Golanski wrote: Quoth Timothy Smith on Wed, Oct 12, 2005 at 17:39:46 +1000 the make world documents mentioning backing up your system. it fails to give any preffered methods or utilites for doing this. anyone got some input

FreeBSD Security Advisory FreeBSD-SA-05:21.openssl

2005-10-11 Thread FreeBSD Security Advisories
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 = FreeBSD-SA-05:21.opensslSecurity Advisory The FreeBSD Project Topic:

Re: FreeBSD Security Advisory FreeBSD-SA-05:21.openssl

2005-10-11 Thread Colin Percival
Ian G wrote: FreeBSD Security Advisories wrote: Applications which do not support SSLv2, have been configured to not permit the use of SSLv2, or do not use the SSL_OP_MSIE_SSLV2_RSA_PADDING or SSL_OP_ALL options are not affected. IV. Workaround No workaround is available. Isn't the

Re: FreeBSD Security Advisory FreeBSD-SA-05:21.openssl

2005-10-11 Thread jimmy
[EMAIL PROTECTED] wrote: Quoting FreeBSD Security Advisories [EMAIL PROTECTED]: = FreeBSD-SA-05:21.opensslSecurity Advisory

Re: FreeBSD Security Advisory FreeBSD-SA-05:21.openssl

2005-10-11 Thread Andrea Venturoli
FreeBSD Security Advisories wrote: Note that any statically linked applications that are not part of the base system (i.e. from the Ports Collection or other 3rd-party sources) must be recompiled. Ok, is there any way to list installed ports which are statically linked against OpenSSL?